ComboFix 09-03-06.02 - DAVIDE LINARI 2009-03-08 15:01:55.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.511.169 [GMT 1:00]
Eseguito da: c:\documents and settings\DAVIDE LINARI\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: PC Tools Firewall Plus *enabled*
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-02-08 al 2009-03-08 )))))))))))))))))))))))))))))))))))
.
2009-03-07 20:42 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\20945743.sys
2009-03-07 20:40 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\59269943.sys
2009-03-07 14:35 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\66290674.sys
2009-03-07 14:30 . 2009-03-07 14:41 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-07 14:29 . 2009-03-08 15:08 11,831,392 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-03-07 14:29 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\62306766.sys
2009-03-07 14:29 . 2009-03-08 15:06 139,808 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-03-07 11:38 . 2009-03-07 11:38 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\Malwarebytes
2009-03-07 11:38 . 2009-03-07 11:38 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-03-07 09:54 . 2001-08-30 23:07 8,704 --a------ c:\windows\system32\kbdjpn.dll
2009-03-07 09:54 . 2001-08-30 23:07 8,704 --a--c--- c:\windows\system32\dllcache\kbdjpn.dll
2009-03-07 09:54 . 2001-08-30 23:07 8,192 --a------ c:\windows\system32\kbdkor.dll
2009-03-07 09:54 . 2001-08-30 23:07 8,192 --a--c--- c:\windows\system32\dllcache\kbdkor.dll
2009-03-07 09:54 . 2008-04-14 03:12 6,144 --a------ c:\windows\system32\kbd106.dll
2009-03-07 09:54 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101c.dll
2009-03-07 09:54 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101b.dll
2009-03-07 09:54 . 2008-04-14 03:12 6,144 --a--c--- c:\windows\system32\dllcache\kbd106.dll
2009-03-07 09:54 . 2001-08-17 22:55 6,144 --a--c--- c:\windows\system32\dllcache\kbd101c.dll
2009-03-07 09:54 . 2001-08-17 22:55 6,144 --a--c--- c:\windows\system32\dllcache\kbd101b.dll
2009-03-07 09:54 . 2001-08-17 22:55 5,632 --a------ c:\windows\system32\kbd103.dll
2009-03-07 09:54 . 2001-08-17 22:55 5,632 --a--c--- c:\windows\system32\dllcache\kbd103.dll
2009-03-01 14:11 . 2001-08-17 21:56 7,552 --a------ c:\windows\system32\drivers\SONYPVU1.SYS
2009-03-01 14:11 . 2001-08-17 21:56 7,552 --a--c--- c:\windows\system32\dllcache\sonypvu1.sys
2009-03-01 12:41 . 2008-03-21 13:57 14,640 --------- c:\windows\system32\spmsgXP_2k3.dll
2009-03-01 12:41 . 2009-03-01 12:41 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-03-01 12:41 . 2009-03-01 12:41 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2009-03-01 12:35 . 2009-03-01 12:32 1,107,296 --a------ c:\windows\system32\WdfCoInstaller01007.dll
2009-03-01 12:35 . 2009-03-01 12:32 24,616 --a------ c:\windows\system32\drivers\ggsemc.sys
2009-03-01 12:35 . 2009-03-01 12:32 13,224 --a------ c:\windows\system32\drivers\ggflt.sys
2009-03-01 12:24 . 2006-09-18 14:59 90,800 -ra------ c:\windows\system32\drivers\se27unic.sys
2009-03-01 12:24 . 2006-09-18 14:58 88,688 -ra------ c:\windows\system32\drivers\SE27mgmt.sys
2009-03-01 12:24 . 2006-09-18 14:59 18,704 -ra------ c:\windows\system32\drivers\se27nd5.sys
2009-03-01 12:24 . 2006-09-18 14:58 4,128 -ra------ c:\windows\system32\drivers\se27cr.sys
2009-03-01 12:23 . 2006-09-18 14:58 97,184 -ra------ c:\windows\system32\drivers\SE27mdm.sys
2009-03-01 12:23 . 2006-09-18 14:59 86,560 -ra------ c:\windows\system32\drivers\SE27obex.sys
2009-03-01 12:23 . 2006-09-18 14:58 61,600 -ra------ c:\windows\system32\drivers\SE27bus.sys
2009-03-01 12:23 . 2006-09-18 14:58 9,360 -ra------ c:\windows\system32\drivers\SE27mdfl.sys
2009-03-01 12:23 . 2006-09-18 14:58 6,240 -ra------ c:\windows\system32\drivers\SE27cmnt.sys
2009-03-01 12:23 . 2006-09-18 14:58 6,240 -ra------ c:\windows\system32\drivers\SE27cm.sys
2009-03-01 12:23 . 2006-09-18 14:59 5,872 -ra------ c:\windows\system32\drivers\SE27whnt.sys
2009-03-01 12:23 . 2006-09-18 14:59 5,872 -ra------ c:\windows\system32\drivers\SE27wh.sys
2009-03-01 12:13 . 2009-03-01 12:24 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\Teleca
2009-03-01 12:12 . 2009-03-01 12:12 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\Sony Ericsson
2009-03-01 12:09 . 2009-03-01 17:11 <DIR> d-------- c:\programmi\Sony Ericsson
2009-03-01 12:09 . 2009-03-01 17:11 <DIR> d-------- c:\programmi\File comuni\Teleca Shared
2009-02-27 20:00 . 2009-03-08 09:33 69 --a------ c:\windows\NeroDigital.ini
2009-02-26 23:23 . 2009-02-26 23:23 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\Apple Computer
2009-02-26 23:22 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2009-02-26 23:22 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2009-02-26 23:21 . 2009-02-26 23:22 <DIR> d-------- c:\programmi\iTunes
2009-02-26 23:21 . 2009-02-26 23:21 <DIR> d-------- c:\programmi\iPod
2009-02-26 23:21 . 2009-02-26 23:21 <DIR> d-------- c:\programmi\Bonjour
2009-02-26 23:21 . 2009-02-26 23:22 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-26 23:20 . 2009-02-26 23:20 <DIR> d-------- c:\programmi\Apple Software Update
2009-02-26 23:20 . 2009-02-26 23:21 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2009-02-26 23:19 . 2009-03-07 11:59 <DIR> d-------- c:\programmi\File comuni\Apple
2009-02-26 23:19 . 2009-02-26 23:19 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Apple
2009-02-24 21:23 . 2009-02-24 21:23 1,374 --a------ c:\windows\imsins.BAK
2009-02-15 16:14 . 2008-12-11 08:38 159,600 --a------ c:\windows\system32\drivers\pctgntdi.sys
2009-02-15 16:14 . 2008-12-11 12:32 132,976 --a------ c:\windows\system32\drivers\PCTCore.sys
2009-02-15 16:14 . 2009-02-26 21:01 95,640 --a------ c:\windows\system32\drivers\pctplfw.sys
2009-02-15 16:14 . 2009-02-26 21:01 73,840 --a------ c:\windows\system32\drivers\PCTAppEvent.sys
2009-02-15 14:47 . 2009-02-15 14:47 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2009-02-15 14:32 . 2009-02-15 14:32 <DIR> d-------- c:\programmi\Chami
2009-02-15 14:13 . 2009-02-15 14:13 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Acronis
2009-02-15 14:11 . 2009-02-15 14:37 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\Ahead
2009-02-15 14:10 . 2009-02-15 14:10 <DIR> d-------- c:\programmi\Nero
2009-02-15 14:10 . 2009-02-15 14:12 <DIR> d-------- c:\programmi\File comuni\Ahead
2009-02-15 14:10 . 2009-02-15 14:10 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Nero
2009-02-15 14:04 . 2009-02-15 14:04 392,320 --a------ c:\windows\system32\drivers\timntr.sys
2009-02-15 14:04 . 2009-02-15 14:04 32,768 --a------ c:\windows\system32\drivers\tifsfilt.sys
2009-02-15 14:03 . 2009-02-15 14:03 114,048 --a------ c:\windows\system32\drivers\snapman.sys
2009-02-15 14:02 . 2009-02-15 14:03 <DIR> d-------- c:\programmi\File comuni\Acronis
2009-02-15 14:02 . 2009-02-15 14:02 <DIR> d-------- c:\programmi\Acronis
2009-02-15 12:08 . 2009-02-15 12:08 82,380 --a------ c:\windows\system32\drivers\AFS2K.SYS
2009-02-15 11:53 . 2009-02-15 11:53 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\Hewlett-Packard
2009-02-15 11:25 . 2009-02-15 11:25 <DIR> d-------- c:\programmi\File comuni\Hewlett-Packard
2009-02-15 11:24 . 2009-02-15 11:25 <DIR> d-------- C:\col3927
2009-02-15 06:58 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-15 06:58 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-02-15 06:58 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-15 01:56 . 2009-03-07 11:59 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-02-15 01:54 . 2009-02-15 01:55 <DIR> d-------- c:\programmi\Microsoft LifeCam
2009-02-15 01:53 . 2006-09-28 16:05 2,414,360 --a------ c:\windows\system32\d3dx9_31.dll
2009-02-14 19:43 . 2009-02-14 19:43 1,409 --a------ c:\windows\system32\tmpF7AE0.FOT
2009-02-14 19:43 . 2009-02-14 19:43 1,409 --a------ c:\windows\system32\tmpCEAE0.FOT
2009-02-14 19:43 . 2009-02-14 19:43 1,409 --a------ c:\windows\system32\tmpAA8E0.FOT
2009-02-14 19:43 . 2009-02-14 19:43 1,409 --a------ c:\windows\system32\tmpA3BE0.FOT
2009-02-14 19:43 . 2009-02-14 19:43 1,409 --a------ c:\windows\system32\tmp3C9E0.FOT
2009-02-14 19:43 . 2009-02-14 19:43 1,409 --a------ c:\windows\system32\tmp0B7E0.FOT
2009-02-14 19:38 . 2009-02-14 19:38 1,409 --a------ c:\windows\system32\tmpF5EE5.FOT
2009-02-14 19:38 . 2009-02-14 19:38 1,409 --a------ c:\windows\system32\tmp8ECE5.FOT
2009-02-14 19:38 . 2009-02-14 19:38 1,409 --a------ c:\windows\system32\tmp62DE5.FOT
2009-02-14 19:38 . 2009-02-14 19:38 1,409 --a------ c:\windows\system32\tmp3BDE5.FOT
2009-02-14 19:38 . 2009-02-14 19:38 1,409 --a------ c:\windows\system32\tmp2EDE5.FOT
2009-02-14 19:38 . 2009-02-14 19:38 1,409 --a------ c:\windows\system32\tmp02EE5.FOT
2009-02-14 18:28 . 2009-02-14 18:28 <DIR> d-------- c:\programmi\eMule
2009-02-14 18:14 . 2009-03-08 14:14 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Tracing
2009-02-14 18:13 . 2009-02-14 18:13 <DIR> d-------- c:\programmi\Microsoft
2009-02-14 18:12 . 2009-02-14 18:13 <DIR> d-------- c:\programmi\Windows Live
2009-02-14 18:05 . 2009-02-14 18:05 <DIR> d-------- c:\programmi\File comuni\Windows Live
2009-02-14 17:26 . 2009-02-14 17:26 1,409 --a------ c:\windows\system32\tmp916A2.FOT
2009-02-14 17:26 . 2009-02-14 17:26 1,409 --a------ c:\windows\system32\tmp856A2.FOT
2009-02-14 17:26 . 2009-02-14 17:26 1,409 --a------ c:\windows\system32\tmp4F6A2.FOT
2009-02-14 17:26 . 2009-02-14 17:26 1,409 --a------ c:\windows\system32\tmp327A2.FOT
2009-02-14 17:26 . 2009-02-14 17:26 1,409 --a------ c:\windows\system32\tmp167A2.FOT
2009-02-14 17:26 . 2009-02-14 17:26 1,409 --a------ c:\windows\system32\tmp0A7A2.FOT
2009-02-14 17:19 . 2009-02-14 17:19 <DIR> d-------- c:\programmi\Google
2009-02-14 17:17 . 2009-02-14 17:17 <DIR> d-------- c:\programmi\Windows Media Connect 2
2009-02-14 17:15 . 2009-02-14 17:15 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-14 17:15 . 2009-02-14 17:16 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-02-14 17:14 . 2009-02-14 17:14 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\vlc
2009-02-14 17:13 . 2009-02-14 17:24 <DIR> d-------- c:\programmi\Yahoo!
2009-02-14 17:13 . 2009-02-14 17:13 <DIR> d-------- c:\programmi\VideoLAN
2009-02-14 17:13 . 2009-02-14 17:13 <DIR> d-------- c:\programmi\CCleaner
2009-02-14 17:13 . 2009-02-14 17:13 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\Yahoo!
2009-02-14 17:12 . 2009-02-14 17:12 <DIR> d-------- c:\programmi\Trend Micro
2009-02-14 17:10 . 2009-02-15 01:49 294 --a------ c:\windows\hpqcopy.INI
2009-02-14 13:06 . 2007-04-09 13:23 28,040 --a------ c:\windows\system32\mdimon.dll
2009-02-14 13:06 . 2009-02-14 13:06 424 --a------ c:\windows\ODBC.INI
2009-02-14 13:04 . 2009-02-14 13:05 <DIR> d-------- c:\windows\SHELLNEW
2009-02-14 12:56 . 2009-02-14 12:56 <DIR> dr-h----- C:\MSOCache
2009-02-14 12:51 . 2009-02-14 12:51 <DIR> d-------- c:\documents and settings\DAVIDE LINARI\Dati applicazioni\Cartella di caricamento Share-to-Web
2009-02-14 12:51 . 2008-04-13 19:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-02-14 12:51 . 2008-04-13 19:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-08 14:08 --------- d---a-w c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-03-07 15:57 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\avg8
2009-03-01 11:08 --------- d-----w c:\programmi\File comuni\InstallShield
2009-02-26 22:04 --------- d-----w c:\programmi\PC Tools Firewall Plus
2009-02-22 17:53 --------- d-----w c:\programmi\File comuni\PC Tools
2009-02-15 07:23 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-15 07:23 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-02-15 07:23 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2009-02-14 08:45 --------- d-----w c:\documents and settings\DAVIDE LINARI\Dati applicazioni\PCToolsFirewallPlus
2009-02-14 08:43 --------- d-----w c:\programmi\AVG
2009-02-14 08:39 --------- d-----w c:\programmi\Trust
2009-02-14 08:38 646,400 ----a-w c:\windows\system32\drivers\CnxEtU.sys
2009-02-14 08:38 60,288 ----a-w c:\windows\system32\drivers\CnxEtP.sys
2009-02-14 08:38 163,840 ----a-w c:\windows\system32\CnxHwIo.dll
2009-02-14 08:38 118,784 ----a-w c:\windows\system32\CnxMfdCo.dll
2009-02-14 08:38 118,784 ----a-w c:\windows\system32\CnxClsCo.dll
2009-02-14 08:38 108,771 ----a-w c:\windows\system32\drivers\CnxTgN.sys
2009-02-14 07:45 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-14 07:45 --------- d-----w c:\programmi\C-Media 3D Audio
2009-02-14 07:43 --------- d-----w c:\programmi\Intel
2009-02-14 07:27 --------- d-----w c:\programmi\microsoft frontpage
2009-02-14 07:26 --------- d-----w c:\programmi\Servizi in linea
2009-02-06 17:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2008-12-31 16:04 691,560 ----a-w c:\windows\system32\OGACheckControl.dll
2008-12-31 16:04 528,744 ----a-w c:\windows\system32\OGAVerify.exe
2008-12-31 16:04 502,120 ----a-w c:\windows\system32\OGAAddin.dll
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"EPSON Stylus D92 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE" [2006-09-27 139264]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-14 39408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CnxDslTaskBar"="c:\programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2009-02-14 462848]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-26 2652056]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-15 1601304]
"LifeCam"="c:\programmi\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"Share-to-Web Namespace Daemon"="c:\programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"TrueImageMonitor.exe"="c:\programmi\Acronis\TrueImage\TrueImageMonitor.exe" [2007-03-02 1165288]
"AcronisTimounterMonitor"="c:\programmi\Acronis\TrueImage\TimounterMonitor.exe" [2007-03-02 1945904]
"Acronis Scheduler2 Service"="c:\programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2007-03-02 149024]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-01-06 290088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-15 08:23 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Programmi\\eMule\\eMule.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-14 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-14 107272]
R1 is-0RLU5drv;is-0RLU5drv;c:\windows\system32\drivers\62306766.sys [2009-03-07 148496]
R1 is-AAUJMdrv;is-AAUJMdrv;c:\windows\system32\drivers\20945743.sys [2009-03-07 148496]
R1 is-M8OGKdrv;is-M8OGKdrv;c:\windows\system32\drivers\66290674.sys [2009-03-07 148496]
R1 is-UEMMNdrv;is-UEMMNdrv;c:\windows\system32\drivers\59269943.sys [2009-03-07 148496]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-02-15 159600]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-14 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-14 298264]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-02-15 73840]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [2009-02-14 60288]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [2009-02-14 646400]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [2009-02-14 108771]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-02-15 95640]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-03-01 13224]
.
Contenuto della cartella 'Scheduled Tasks'
2009-03-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {83DFAA43-6D08-42EB-8256-C1E033205823} = 85.37.17.47 85.38.28.82
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-08 15:08:02
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(956)
c:\windows\system32\relog_ap.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\Acronis\Schedule2\schedul2.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Microsoft LifeCam\MSCamS32.exe
c:\programmi\PC Tools Firewall Plus\FWService.exe
c:\programmi\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\programmi\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
c:\programmi\File comuni\Ahead\Lib\NMIndexingService.exe
.
**************************************************************************
.
Ora fine scansione: 2009-03-08 15:11:03 - Il pc è stato riavviato [DAVIDE LINARI]
ComboFix-quarantined-files.txt 2009-03-08 14:10:57
Pre-Run: 14,647,029,760 byte disponibili
Post-Run: 14,898,802,688 byte disponibili
276 --- E O F --- 2009-02-24 20:23:14