ComboFix 11-01-22.03 - Adriano 23/01/2011 15.29.21.2.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.894.500 [GMT 1:00]
Eseguito da: e:\documents and settings\Adriano\Desktop\ComboFix.exe
Opzioni usate :: e:\documents and settings\Adriano\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
FILE ::
"e:\documents and settings\Adriano\Dati applicazioni\Crtlink\msd3d.exe"
"e:\documents and settings\Adriano\Impostazioni locali\Dati applicazioni\icwycnq.dat.vir"
"e:\documents and settings\Adriano\Impostazioni locali\Dati applicazioni\icwycnq_nav.dat.vir"
"e:\documents and settings\Adriano\Impostazioni locali\Dati applicazioni\icwycnq_navps.dat.vir"
"e:\windows\system32\gjtfymok.dll"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\documents and settings\Adriano\Dati applicazioni\Crtlink
e:\documents and settings\Adriano\Dati applicazioni\Crtlink\msd3d.exe
e:\documents and settings\Adriano\Impostazioni locali\Dati applicazioni\icwycnq.dat.vir
e:\documents and settings\Adriano\Impostazioni locali\Dati applicazioni\icwycnq_nav.dat.vir
e:\documents and settings\Adriano\Impostazioni locali\Dati applicazioni\icwycnq_navps.dat.vir
e:\windows\system32\gjtfymok.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BUFFLCVU
-------\Service_bufflcvu
((((((((((((((((((((((((( Files Creati Da 2010-12-23 al 2011-01-23 )))))))))))))))))))))))))))))))))))
.
2011-01-22 19:48 . 2011-01-22 19:48 -------- d-sh--w- e:\documents and settings\Adriano\IECompatCache
2011-01-22 19:47 . 2011-01-22 19:47 -------- d-sh--w- e:\documents and settings\Adriano\PrivacIE
2011-01-22 19:45 . 2011-01-22 19:45 -------- d-sh--w- e:\documents and settings\Adriano\IETldCache
2011-01-22 19:43 . 2011-01-22 19:43 -------- d-----w- e:\documents and settings\Adriano\Impostazioni locali\Dati applicazioni\PCHealth
2011-01-22 19:42 . 2011-01-22 19:42 -------- d--h--w- e:\windows\ie8
2011-01-22 19:26 . 2010-10-18 11:10 7680 ------w- e:\windows\system32\dllcache\iecompat.dll
2011-01-22 19:25 . 2010-11-06 00:21 602112 ------w- e:\windows\system32\dllcache\msfeeds.dll
2011-01-22 19:25 . 2010-11-06 00:21 55296 ------w- e:\windows\system32\dllcache\msfeedsbs.dll
2011-01-22 19:25 . 2010-11-06 00:21 12800 ------w- e:\windows\system32\dllcache\xpshims.dll
2011-01-22 19:25 . 2010-11-06 00:21 247808 ------w- e:\windows\system32\dllcache\ieproxy.dll
2011-01-22 19:25 . 2010-11-06 00:21 1991680 ------w- e:\windows\system32\dllcache\iertutil.dll
2011-01-22 19:25 . 2010-11-06 00:21 743424 ------w- e:\windows\system32\dllcache\iedvtool.dll
2011-01-22 19:25 . 2010-11-06 00:21 11080704 ------w- e:\windows\system32\dllcache\ieframe.dll
2011-01-22 19:23 . 2011-01-22 19:23 -------- d-----w- E:\1baab6882542c23641ba39eb
2011-01-22 18:58 . 2008-04-13 18:14 294912 ------w- e:\programmi\Windows Media Player\dlimport.exe
2011-01-22 18:57 . 2006-12-28 11:01 19569 ----a-w- e:\windows\002918_.tmp
2011-01-22 13:59 . 2011-01-22 13:59 -------- d-----w- e:\documents and settings\Adriano\Dati applicazioni\Malwarebytes
2011-01-22 13:58 . 2010-12-20 17:09 38224 ----a-w- e:\windows\system32\drivers\mbamswissarmy.sys
2011-01-22 13:58 . 2011-01-22 13:58 -------- d-----w- e:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-01-22 13:58 . 2010-12-20 17:08 20952 ----a-w- e:\windows\system32\drivers\mbam.sys
2011-01-22 11:28 . 2011-01-22 11:28 -------- d-----w- e:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2011-01-19 21:49 . 2011-01-19 21:49 388096 ----a-r- e:\documents and settings\Adriano\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-01-19 15:41 . 2011-01-19 15:41 -------- d-----w- e:\programmi\MSXML 6.0
2011-01-19 14:37 . 2006-06-19 12:01 69632 ----a-w- e:\windows\system32\ztvcabinet.dll
2011-01-19 14:37 . 2006-05-25 14:52 162304 ----a-w- e:\windows\system32\ztvunrar36.dll
2011-01-19 14:37 . 2005-08-26 00:50 77312 ----a-w- e:\windows\system32\ztvunace26.dll
2011-01-19 14:37 . 2003-02-02 19:06 153088 ----a-w- e:\windows\system32\UNRAR3.dll
2011-01-19 14:37 . 2002-03-06 00:00 75264 ----a-w- e:\windows\system32\unacev2.dll
2011-01-19 14:37 . 2011-01-19 14:37 -------- d-----w- e:\documents and settings\All Users\Dati applicazioni\Simply Super Software
2011-01-19 14:37 . 2011-01-19 14:37 -------- d-----w- e:\documents and settings\Adriano\Dati applicazioni\Simply Super Software
2011-01-19 14:12 . 2011-01-19 14:12 -------- d-----w- e:\programmi\File comuni\Java
2011-01-19 14:12 . 2010-11-12 17:53 472808 ----a-w- e:\windows\system32\deployJava1.dll
2011-01-19 14:12 . 2010-11-12 17:53 472808 ----a-w- e:\programmi\Mozilla Firefox\plugins\npdeployJava1.dll
2011-01-18 07:46 . 2011-01-18 07:46 -------- d-----w- e:\programmi\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-25 10:08 . 2010-11-25 10:08 49152 ----a-r- e:\documents and settings\Adriano\Dati applicazioni\Microsoft\Installer\{E51E4E3E-62B9-4A99-868D-B05B2DA3F4BF}\NewShortcut1_E51E4E3E62B94A99868DB05B2DA3F4BF.exe
2010-11-23 12:36 . 2010-11-23 12:36 40960 ----a-r- e:\documents and settings\Adriano\Dati applicazioni\Microsoft\Installer\{E389880B-EE4B-4C63-87D4-6B5086F49315}\NewShortcut1_E389880BEE4B4C6387D46B5086F49315.exe
2010-11-12 15:34 . 2010-02-16 14:25 73728 ----a-w- e:\windows\system32\javacpl.cpl
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- e:\windows\system32\dpl100.dll
2010-11-08 22:57 . 2010-11-08 22:57 353592 ----a-w- e:\windows\system32\DivXControlPanelApplet.cpl
2010-11-06 00:21 . 2004-08-30 19:00 916480 ----a-w- e:\windows\system32\wininet.dll
2010-11-06 00:21 . 2004-08-30 19:00 43520 ------w- e:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2004-08-30 19:00 1469440 ------w- e:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2004-08-30 19:00 385024 ------w- e:\windows\system32\html.iec
.
(((((((((((((((((((((((((((((
SnapShot@2011-01-23_13.13.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-23 14:33 . 2011-01-23 14:33 16384 e:\windows\temp\Perflib_Perfdata_5e0.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2010-03-22 22:43 2349080 ----a-w- e:\programmi\BS_Player\tbBS_1.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "e:\programmi\BS_Player\tbBS_1.dll" [2010-03-22 2349080]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="e:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"DAEMON Tools Lite"="f:\programmi scaricati\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"="e:\programmi\PDF Complete\pdfsty.exe" [2007-08-07 331288]
"NeroFilterCheck"="e:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="e:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="e:\programmi\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"BDRegion"="e:\programmi\Cyberlink\Shared files\brs.exe" [2010-06-28 75048]
"DivXUpdate"="e:\programmi\DivX\DivX Update\DivXUpdate.exe" [2011-01-10 1230704]
"DivX Download Manager"="e:\programmi\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"SunJavaUpdateSched"="e:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
e:\documents and settings\Adriano\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.2.lnk - e:\programmi\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Programmi\\uTorrent\\uTorrent.exe"=
"f:\\Programmi scaricati\\eMule AdunanzA\\eMule_AdnzA.exe"=
"e:\\Programmi\\Messenger\\msmsgs.exe"=
"f:\\Programmi scaricati\\VLC\\vlc.exe"=
"e:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"e:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"e:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"f:\\Programmi scaricati\\Office12\\OUTLOOK.EXE"=
"e:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"f:\\Programmi scaricati\\iTunes.exe"=
"e:\\Programmi\\Google\\Google Earth\\client\\googleearth.exe"=
"f:\\Programmi scaricati\\MediaManager.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 sptd;sptd;e:\windows\system32\drivers\sptd.sys [03/10/2010 13.39.23 691696]
R2 pdfcDispatcher;PDF Document Manager;e:\programmi\PDF Complete\pdfsvc.exe [27/10/2009 13.41.25 540184]
S0 ilcfrs;ilcfrs;e:\windows\system32\drivers\iactob.sys --> e:\windows\system32\drivers\iactob.sys [?]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/10/14 22:59];\??\f:\programmi scaricati\PowerDVD10\NavFilter\000.fcl --> f:\programmi scaricati\PowerDVD10\NavFilter\000.fcl [?]
S2 gupdate;Servizio di Google Update (gupdate);e:\programmi\Google\Update\GoogleUpdate.exe [07/09/2010 17.32.42 136176]
S3 jgameenp;jgameenp;\??\e:\docume~1\Adriano\IMPOST~1\Temp\jgameenp.sys --> e:\docume~1\Adriano\IMPOST~1\Temp\jgameenp.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
2011-01-23 e:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- e:\programmi\Ask.com\UpdateTask.exe [2010-02-04 15:50]
2011-01-23 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\programmi\Google\Update\GoogleUpdate.exe [2010-09-07 16:32]
2011-01-23 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\programmi\Google\Update\GoogleUpdate.exe [2010-09-07 16:32]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - e:\documents and settings\Adriano\Dati applicazioni\Mozilla\Firefox\Profiles\tha2l4b1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2530241&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://it.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - e:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - e:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - e:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Softonic-IT Toolbar: {e3393495-8103-46a0-8181-270273eddd60} - %profile%\extensions\{e3393495-8103-46a0-8181-270273eddd60}
FF - Ext: DAEMON Tools Toolbar:
DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Java Quick Starter:
jqs@sun.com - e:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - e:\programmi\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - e:\programmi\DivX\DivX Plus Web Player\firefox\wpa
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKU-Default-Run-Kbnew - e:\documents and settings\Adriano\Dati applicazioni\Crtlink\msd3d.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-23 15:33
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="e:\programmi\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\f:\programmi scaricati\PowerDVD10\NavFilter\000.fcl"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-117609710-1935655697-725345543-1003\Software\Sony Creative Software\M*e*d*i*a* *M*a*n*a*g*e*r* *f*o*r* *P*S*P*"!\2.5]
"Percents"=""
"Increment"=".000886"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(240)
e:\windows\system32\WININET.dll
e:\windows\system32\webcheck.dll
e:\windows\system32\WPDShServiceObj.dll
e:\windows\system32\PortableDeviceTypes.dll
e:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
e:\windows\system32\nvsvc32.exe
e:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
e:\programmi\Bonjour\mDNSResponder.exe
f:\programmi scaricati\security suite\ewidoctrl.exe
e:\programmi\Java\jre6\bin\jqs.exe
e:\programmi\CyberLink\Shared files\RichVideo.exe
e:\windows\system32\wscntfy.exe
e:\windows\system32\RUNDLL32.EXE
e:\programmi\File comuni\Ahead\Lib\NMIndexingService.exe
e:\programmi\OpenOffice.org 3\program\soffice.exe
e:\programmi\OpenOffice.org 3\program\soffice.bin
e:\programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Ora fine scansione: 2011-01-23 15:34:58 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-01-23 14:34
ComboFix2.txt 2011-01-23 13:15
Pre-Run: 18.205.573.120 byte disponibili
Post-Run: 18.103.812.096 byte disponibili
- - End Of File - - 57918EC6F861A17BCE48DA60A4E9CDE7