ecco ora è fatto
ComboFix 09-04-15.01 - saretta 15/04/2009 19.08.54.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.510.140 [GMT 2:00]
Eseguito da: c:\documents and settings\saretta\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\saretta\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-03-15 al 2009-04-15 )))))))))))))))))))))))))))))))))))
.
2009-04-15 09:48 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 09:48 . 2009-03-06 14:19 286208 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-15 09:48 . 2009-02-09 11:22 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-15 09:48 . 2009-02-09 10:51 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 09:48 . 2009-02-09 10:51 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 09:48 . 2009-02-06 10:39 35328 -c----w c:\windows\system32\dllcache\sc.exe
2009-04-15 09:48 . 2009-02-09 10:51 734720 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 09:48 . 2009-02-09 10:51 683520 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 09:48 . 2009-02-09 10:51 736256 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 09:48 . 2009-02-09 10:51 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 09:47 . 2009-03-27 06:48 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-15 09:47 . 2008-04-21 21:14 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 09:38 . 2009-04-15 09:38 -------- d-----w c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Share_Accelerator_MM
2009-04-15 09:38 . 2009-04-15 09:38 -------- d-----w c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Apple
2009-04-14 21:23 . 2009-04-14 21:23 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\Malwarebytes
2009-04-14 21:23 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-14 21:23 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-14 21:23 . 2009-04-14 21:23 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-04-14 19:45 . 2009-04-15 08:57 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\dvdcss
2009-04-14 17:00 . 2009-04-14 17:00 -------- d-----w C:\CNYSELPHYCP
2009-04-13 21:17 . 2009-04-15 10:17 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-04-13 14:15 . 2009-04-13 14:15 -------- d-----w c:\windows\Sun
2009-04-13 14:04 . 2009-04-13 14:05 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-13 09:44 . 2009-04-15 11:41 69 ----a-w c:\windows\NeroDigital.ini
2009-04-13 09:43 . 2009-04-13 09:43 2332416 ----a-w c:\windows\system32\TUKernel.exe
2009-04-13 08:47 . 2008-06-14 17:32 272768 -c----w c:\windows\system32\dllcache\bthport.sys
2009-04-13 08:47 . 2009-02-20 08:09 668672 -c----w c:\windows\system32\dllcache\wininet.dll
2009-04-13 08:47 . 2009-03-02 23:10 1499648 -c----w c:\windows\system32\dllcache\shdocvw.dll
2009-04-13 08:47 . 2009-02-20 08:09 619520 -c----w c:\windows\system32\dllcache\urlmon.dll
2009-04-13 08:45 . 2008-05-08 14:02 203136 -c----w c:\windows\system32\dllcache\rmcast.sys
2009-04-13 08:45 . 2009-02-10 17:02 2069760 -c----w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-13 08:45 . 2009-02-09 11:22 2148864 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-13 08:45 . 2009-02-09 11:23 2192768 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-13 08:45 . 2009-02-09 11:23 2027520 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-13 08:45 . 2009-02-20 08:09 3089408 -c----w c:\windows\system32\dllcache\mshtml.dll
2009-04-13 08:45 . 2008-12-11 10:57 333952 -c----w c:\windows\system32\dllcache\srv.sys
2009-04-13 08:44 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-13 08:44 . 2008-04-11 19:04 691712 -c----w c:\windows\system32\dllcache\inetcomm.dll
2009-04-13 08:44 . 2008-10-15 16:36 337408 -c----w c:\windows\system32\dllcache\netapi32.dll
2009-04-12 20:35 . 2009-04-12 20:35 -------- d-----w c:\windows\l2schemas
2009-04-12 20:35 . 2009-04-12 20:35 -------- d-----w c:\windows\system32\it
2009-04-12 20:35 . 2009-04-12 20:35 -------- d-----w c:\windows\system32\bits
2009-04-12 20:31 . 2009-04-12 20:36 -------- d-----w c:\windows\ServicePackFiles
2009-04-12 20:21 . 2009-04-12 20:21 -------- d-----w c:\windows\EHome
2009-04-12 15:12 . 2009-04-13 12:44 -------- d--h--w c:\windows\Icons
2009-04-12 14:36 . 2004-08-19 13:23 701440 ------w c:\windows\system32\drivers\ati2mtag.sys
2009-04-12 14:03 . 2009-04-12 14:03 -------- d-----w c:\documents and settings\saretta\Impostazioni locali\Dati applicazioni\Innovative Solutions
2009-04-12 13:59 . 2009-04-12 13:59 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\TeamViewer
2009-04-12 13:58 . 2009-04-12 13:58 -------- d-----w c:\documents and settings\saretta\temp
2009-04-11 16:51 . 2009-04-13 09:49 -------- d-----w c:\documents and settings\saretta\Impostazioni locali\Dati applicazioni\Lphant
2009-04-11 16:30 . 2006-06-29 11:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-04-11 16:23 . 2009-04-11 16:29 -------- d-----w c:\windows\system32\XPSViewer
2009-04-11 16:20 . 2008-07-06 12:06 89088 -c----w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-11 16:20 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-04-11 16:20 . 2008-07-06 12:06 575488 -c----w c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-11 16:20 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-04-11 16:20 . 2008-07-06 10:50 597504 -c----w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-11 16:20 . 2008-07-06 12:06 1676288 -c----w c:\windows\system32\dllcache\xpssvcs.dll
2009-04-11 16:20 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-04-11 14:21 . 2006-03-17 13:49 368640 ----a-w c:\windows\system32\TwnLib4.dll
2009-04-11 14:21 . 2006-03-17 10:45 802816 ----a-w c:\windows\system32\imagXRA7.dll
2009-04-11 14:21 . 2006-03-17 10:45 497296 ----a-w c:\windows\system32\imagXpr7.dll
2009-04-11 14:21 . 2006-03-17 10:45 258048 ----a-w c:\windows\system32\imagXR7.dll
2009-04-11 14:21 . 2006-03-17 10:45 1757184 ----a-w c:\windows\system32\imagX7.dll
2009-04-11 14:21 . 2009-04-11 14:21 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Nero
2009-04-11 14:05 . 2009-04-11 14:05 603904 ----a-w c:\windows\system32\TUProgSt.exe
2009-04-11 14:05 . 2008-12-11 12:31 27904 ----a-w c:\windows\system32\uxtuneup.dll
2009-04-11 14:05 . 2009-04-11 14:05 360192 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-04-11 14:03 . 2009-04-11 14:03 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\TuneUp Software
2009-04-11 14:03 . 2009-04-11 14:03 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\TuneUp Software
2009-04-11 14:02 . 2009-04-11 14:02 -------- d-sh--w c:\documents and settings\All Users\Dati applicazioni\{55A29068-F2CE-456C-9148-C869879E2357}
2009-04-11 13:42 . 2009-04-11 13:48 -------- d-----w c:\windows\SHELLNEW
2009-04-11 13:42 . 2009-04-11 13:42 -------- d-----w c:\documents and settings\saretta\Impostazioni locali\Dati applicazioni\Microsoft Help
2009-04-11 13:38 . 2009-04-11 13:51 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-04-11 13:36 . 2009-04-11 13:36 -------- d--h--r C:\MSOCache
2009-04-11 13:15 . 2009-04-11 13:15 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\vlc
2009-04-11 12:49 . 2009-04-13 14:34 -------- d--h--w C:\$AVG8.VAULT$
2009-04-11 12:42 . 2009-04-11 12:42 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-11 12:42 . 2009-04-11 12:42 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-11 12:42 . 2009-04-11 12:42 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-11 12:41 . 2009-04-15 10:11 -------- d-----w c:\windows\system32\drivers\Avg
2009-04-11 12:41 . 2009-04-11 12:41 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\avg8
2009-04-11 12:01 . 2009-04-11 12:01 -------- d-----w c:\documents and settings\saretta\Impostazioni locali\Dati applicazioni\Cooliris
2009-04-11 11:54 . 2009-04-11 11:54 -------- d-----w c:\documents and settings\saretta\Impostazioni locali\Dati applicazioni\Google
2009-04-11 09:49 . 2009-04-11 09:49 73728 ----a-w c:\windows\system32\javacpl.cpl
2009-04-11 09:49 . 2009-04-11 09:49 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-11 08:45 . 2009-04-11 08:45 0 ----a-w c:\windows\nsreg.dat
2009-04-11 08:45 . 2009-04-11 08:45 -------- d-----w c:\documents and settings\saretta\Impostazioni locali\Dati applicazioni\Mozilla
2009-04-11 08:26 . 2009-04-11 08:26 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\sony
2009-04-08 20:09 . 2009-04-08 20:09 0 ----a-w C:\winamp.ini
2009-04-05 16:36 . 2009-04-05 16:36 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\HTML Executable
2009-04-05 14:59 . 2009-04-05 14:59 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-04-05 14:54 . 2009-03-05 21:59 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-03-29 16:31 . 2009-04-15 11:22 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\Skype
2009-03-29 16:31 . 2009-04-11 15:23 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Skype
2009-03-29 12:42 . 2009-03-29 12:42 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\Smart-Ads-Solutions
2009-03-22 17:41 . 2009-03-22 17:41 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Adobe Systems
2009-03-22 17:37 . 2009-04-07 19:07 57421 ----a-w c:\windows\system32\lqxchrypmhx.dll-uninst.exe
2009-03-21 17:07 . 2009-04-07 19:10 48267 ----a-w c:\windows\system32\asddlccmhhncj.exe
2009-03-21 14:06 . 2009-03-21 14:06 1033728 -c----w c:\windows\system32\dllcache\kernel32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 11:05 . 2009-03-13 20:13 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\uTorrent
2009-04-14 22:19 . 2009-03-15 21:01 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\Messenger
2009-04-14 21:23 . 2009-04-14 21:23 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-04-14 20:43 . 2009-04-14 20:43 -------- d-----w c:\programmi\Trend Micro
2009-04-14 19:30 . 2009-03-21 16:39 -------- d-----w c:\programmi\GooglePlusVideos
2009-04-13 21:21 . 2009-04-13 21:17 -------- d-----w c:\programmi\Spybot - Search & Destroy
2009-04-13 21:08 . 2005-07-14 08:39 89094 ----a-w c:\windows\system32\perfc010.dat
2009-04-13 21:08 . 2005-07-14 08:39 500302 ----a-w c:\windows\system32\perfh010.dat
2009-04-13 14:05 . 2009-04-13 14:04 -------- d-----w c:\programmi\iTunes
2009-04-13 14:04 . 2009-04-13 14:04 -------- d-----w c:\programmi\iPod
2009-04-13 14:04 . 2008-12-18 22:39 -------- d-----w c:\programmi\File comuni\Apple
2009-04-13 13:16 . 2008-08-17 19:08 -------- d-----w c:\programmi\Collegamenti programmi
2009-04-13 12:29 . 2005-07-15 08:15 -------- d--h--w c:\programmi\InstallShield Installation Information
2009-04-13 08:43 . 2008-08-17 19:09 73104 ----a-w c:\documents and settings\saretta\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-12 20:38 . 2005-07-14 15:52 76875 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-12 20:26 . 2005-07-14 08:39 251600 --sha-r C:\ntldr
2009-04-12 13:59 . 2009-04-12 13:59 -------- d-----w c:\programmi\TeamViewer
2009-04-11 16:51 . 2009-04-11 16:51 -------- d-----w c:\programmi\Lphant
2009-04-11 16:23 . 2009-04-11 16:23 -------- d-----w c:\programmi\MSBuild
2009-04-11 16:22 . 2009-04-11 16:22 -------- d-----w c:\programmi\Reference Assemblies
2009-04-11 16:12 . 2009-04-11 16:12 -------- d-----w c:\programmi\MSXML 6.0
2009-04-11 15:23 . 2009-04-11 15:23 -------- d-----r c:\programmi\Skype
2009-04-11 14:22 . 2009-04-11 14:21 -------- d-----w c:\programmi\Nero
2009-04-11 14:21 . 2009-04-11 14:21 -------- d-----w c:\programmi\File comuni\Nero
2009-04-11 14:05 . 2009-04-11 14:03 -------- d-----w c:\programmi\TuneUp Utilities 2009
2009-04-11 13:59 . 2005-07-15 11:45 -------- d-----w c:\programmi\Sony
2009-04-11 13:57 . 2008-08-17 19:24 -------- d-----w c:\programmi\Microsoft Works
2009-04-11 13:18 . 2008-12-18 22:42 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\Apple Computer
2009-04-11 13:10 . 2009-04-11 13:10 -------- d-----w c:\programmi\VideoLAN
2009-04-11 12:52 . 2009-04-11 12:52 -------- d-----w c:\programmi\RocketDock
2009-04-11 12:47 . 2009-03-13 19:55 -------- d-----w c:\programmi\CCleaner
2009-04-11 12:41 . 2009-04-11 12:41 -------- d-----w c:\programmi\AVG
2009-04-11 11:54 . 2005-07-15 11:47 -------- d-----w c:\programmi\InterVideo
2009-04-11 11:53 . 2005-07-15 12:00 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Sony Corporation
2009-04-11 11:39 . 2005-07-15 11:52 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Symantec
2009-04-11 09:49 . 2005-07-15 11:44 -------- d-----w c:\programmi\Java
2009-04-11 08:26 . 2009-04-11 08:26 -------- d-----w c:\programmi\File comuni\SWF Studio
2009-04-08 20:09 . 2008-08-17 19:17 -------- d-----w c:\programmi\MoodLogic
2009-04-08 19:52 . 2005-07-15 11:45 -------- d-----w c:\programmi\File comuni\Adobe
2009-04-08 19:49 . 2009-04-08 19:49 -------- d-----w c:\programmi\Foxit Software
2009-04-05 14:56 . 2009-04-05 14:56 -------- d-----w c:\programmi\QuickTime
2009-04-05 14:19 . 2009-04-05 14:18 -------- d-----w c:\programmi\Safari
2009-04-05 14:10 . 2009-04-05 14:10 -------- d-----w c:\programmi\Bonjour
2009-03-29 15:16 . 2009-03-13 20:13 -------- d-----w c:\programmi\uTorrent
2009-03-29 12:42 . 2009-03-29 12:42 -------- d-----w c:\programmi\Smart-Ads-Solutions
2009-03-22 17:41 . 2009-03-22 17:41 -------- d-----w c:\programmi\File comuni\Adobe Systems Shared
2009-03-19 14:32 . 2008-12-18 22:41 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-14 13:05 . 2009-03-14 13:05 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\Yahoo!
2009-03-14 12:24 . 2008-08-29 16:58 -------- d-----w c:\programmi\Canon
2009-03-13 21:47 . 2009-03-13 21:47 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\FLEXnet
2009-03-13 21:24 . 2009-03-13 21:24 -------- d-----w c:\programmi\File comuni\Adobe AIR
2009-03-13 21:18 . 2009-03-13 21:18 -------- d-----w c:\programmi\File comuni\Macrovision Shared
2009-03-13 20:17 . 2009-03-13 20:17 -------- d-----w c:\documents and settings\saretta\Dati applicazioni\U3
2009-03-07 14:40 . 2009-03-07 14:29 -------- d-----w c:\programmi\Arteferro CAD 3D
2009-03-06 14:19 . 2005-07-14 08:39 286208 ----a-w c:\windows\system32\pdh.dll
2009-03-05 21:59 . 2008-12-18 22:39 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-02-20 08:09 . 2005-07-14 08:39 668672 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:09 . 2005-07-14 08:38 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-10 17:02 . 2004-08-19 15:34 2069760 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 14:04 . 2005-07-14 08:39 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:23 . 2005-07-14 08:39 2192768 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:22 . 2005-07-14 08:39 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 2005-07-14 08:38 734720 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2005-07-14 08:39 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 2005-07-14 08:38 683520 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 2005-07-14 08:39 736256 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 2005-07-14 08:39 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:57 . 2005-07-14 08:39 56832 ----a-w c:\windows\system32\secur32.dll
2005-07-14 15:57 . 2009-04-13 20:27 12328 ----a-w c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((
SnapShot@2009-04-14_22.16.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-15 13:36 . 2009-04-15 13:36 16384 c:\windows\Temp\Perflib_Perfdata_728.dat
+ 2009-04-15 13:36 . 2009-04-15 13:36 16384 c:\windows\Temp\Perflib_Perfdata_288.dat
+ 2005-07-15 11:42 . 2008-07-09 07:42 26488 c:\windows\system32\spupdsvc.exe
- 2005-07-15 11:42 . 2007-08-10 06:20 26488 c:\windows\system32\spupdsvc.exe
+ 2005-07-14 15:53 . 2008-07-09 07:42 18808 c:\windows\system32\spmsg.dll
- 2005-07-14 15:53 . 2007-11-30 11:19 18808 c:\windows\system32\spmsg.dll
+ 2005-07-14 08:39 . 2009-02-03 19:57 56832 c:\windows\system32\secur32.dll
+ 2005-07-14 08:39 . 2009-02-06 10:39 35328 c:\windows\system32\sc.exe
- 2005-07-14 15:50 . 2008-04-14 02:13 91648 c:\windows\system32\mtxoci.dll
+ 2005-07-14 15:50 . 2008-06-12 14:21 91648 c:\windows\system32\mtxoci.dll
- 2005-07-14 08:39 . 2008-04-14 02:13 66560 c:\windows\system32\mtxclu.dll
+ 2005-07-14 08:39 . 2008-06-12 14:21 66560 c:\windows\system32\mtxclu.dll
+ 2005-07-14 15:50 . 2008-06-12 14:21 58880 c:\windows\system32\msdtclog.dll
- 2005-07-14 15:50 . 2008-04-14 02:13 58880 c:\windows\system32\msdtclog.dll
+ 2005-07-14 08:38 . 2009-02-20 08:09 81920 c:\windows\system32\ieencode.dll
- 2005-07-14 08:38 . 2008-04-14 02:13 81920 c:\windows\system32\ieencode.dll
+ 2009-02-03 19:57 . 2009-02-03 19:57 56832 c:\windows\system32\dllcache\secur32.dll
+ 2009-04-15 09:48 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
+ 2008-06-12 14:21 . 2008-06-12 14:21 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:21 . 2008-06-12 14:21 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2008-06-12 14:21 . 2008-06-12 14:21 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2009-02-20 08:09 . 2009-02-20 08:09 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2008-05-05 05:25 . 2008-05-05 05:25 3072 c:\windows\system32\xpsp4res.dll
- 2005-07-14 08:39 . 2008-10-16 01:00 668672 c:\windows\system32\wininet.dll
+ 2005-07-14 08:39 . 2009-02-20 08:09 668672 c:\windows\system32\wininet.dll
- 2005-07-14 08:39 . 2008-04-14 02:13 354304 c:\windows\system32\winhttp.dll
+ 2005-07-14 08:39 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
+ 2005-07-14 15:50 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2005-07-14 15:50 . 2009-02-09 10:51 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2005-07-14 15:49 . 2009-02-09 10:51 473600 c:\windows\system32\wbem\fastprox.dll
+ 2005-07-14 08:39 . 2009-02-20 08:09 619520 c:\windows\system32\urlmon.dll
- 2005-07-14 08:39 . 2008-10-16 01:00 619520 c:\windows\system32\urlmon.dll
+ 2005-07-14 08:39 . 2009-02-09 11:22 111104 c:\windows\system32\services.exe
+ 2005-07-14 08:39 . 2009-02-09 10:51 401408 c:\windows\system32\rpcss.dll
+ 2005-07-14 08:39 . 2009-03-06 14:19 286208 c:\windows\system32\pdh.dll
- 2005-07-14 08:39 . 2008-04-14 02:13 286208 c:\windows\system32\pdh.dll
+ 2005-07-14 08:39 . 2009-02-09 10:51 736256 c:\windows\system32\ntdll.dll
+ 2005-07-14 15:50 . 2008-06-12 14:21 161792 c:\windows\system32\msdtcuiu.dll
- 2005-07-14 15:50 . 2008-04-14 02:13 161792 c:\windows\system32\msdtcuiu.dll
- 2005-07-14 15:50 . 2008-04-14 02:13 956928 c:\windows\system32\msdtctm.dll
+ 2005-07-14 15:50 . 2008-06-12 14:21 956928 c:\windows\system32\msdtctm.dll
+ 2005-07-14 15:50 . 2008-06-12 14:21 428032 c:\windows\system32\msdtcprx.dll
+ 2005-07-14 08:38 . 2009-02-09 10:51 734720 c:\windows\system32\lsasrv.dll
+ 2009-04-15 09:47 . 2008-04-21 21:14 219136 c:\windows\system32\dllcache\wordpad.exe
+ 2009-04-15 09:48 . 2009-02-06 10:10 227840 c:\windows\system32\dllcache\wmiprvse.exe
+ 2009-04-15 09:48 . 2009-02-09 10:51 453120 c:\windows\system32\dllcache\wmiprvsd.dll
- 2009-04-13 08:47 . 2008-10-16 01:00 668672 c:\windows\system32\dllcache\wininet.dll
+ 2009-04-13 08:47 . 2009-02-20 08:09 668672 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
- 2009-04-13 08:47 . 2008-10-16 01:00 619520 c:\windows\system32\dllcache\urlmon.dll
+ 2009-04-13 08:47 . 2009-02-20 08:09 619520 c:\windows\system32\dllcache\urlmon.dll
+ 2009-04-15 09:48 . 2009-02-09 11:22 111104 c:\windows\system32\dllcache\services.exe
+ 2009-04-15 09:48 . 2009-02-09 10:51 401408 c:\windows\system32\dllcache\rpcss.dll
+ 2009-04-15 09:48 . 2009-03-06 14:19 286208 c:\windows\system32\dllcache\pdh.dll
+ 2009-04-15 09:48 . 2009-02-09 10:51 736256 c:\windows\system32\dllcache\ntdll.dll
+ 2008-06-12 14:21 . 2008-06-12 14:21 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:21 . 2008-06-12 14:21 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:21 . 2008-06-12 14:21 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2009-04-15 09:48 . 2009-02-09 10:51 734720 c:\windows\system32\dllcache\lsasrv.dll
+ 2009-04-15 09:48 . 2009-02-09 10:51 473600 c:\windows\system32\dllcache\fastprox.dll
+ 2009-04-15 09:48 . 2009-02-09 10:51 683520 c:\windows\system32\dllcache\advapi32.dll
+ 2005-07-14 08:38 . 2009-02-09 10:51 683520 c:\windows\system32\advapi32.dll
- 2005-07-14 08:38 . 2008-04-14 02:13 683520 c:\windows\system32\advapi32.dll
+ 2005-07-14 08:39 . 2009-03-02 23:10 1499648 c:\windows\system32\shdocvw.dll
- 2005-07-14 08:39 . 2008-10-16 01:00 1499648 c:\windows\system32\shdocvw.dll
- 2005-07-14 08:39 . 2008-05-07 05:10 1293312 c:\windows\system32\quartz.dll
+ 2005-07-14 08:39 . 2008-12-20 22:13 1293312 c:\windows\system32\quartz.dll
+ 2005-07-14 08:39 . 2009-02-09 11:23 2192768 c:\windows\system32\ntoskrnl.exe
+ 2004-08-19 15:34 . 2009-02-10 17:02 2069760 c:\windows\system32\ntkrnlpa.exe
- 2004-08-19 15:34 . 2008-08-14 13:22 2069760 c:\windows\system32\ntkrnlpa.exe
+ 2005-07-14 08:39 . 2009-02-20 08:09 3089408 c:\windows\system32\mshtml.dll
- 2005-07-14 08:38 . 2008-04-14 02:13 1033728 c:\windows\system32\kernel32.dll
+ 2005-07-14 08:38 . 2009-03-21 14:06 1033728 c:\windows\system32\kernel32.dll
- 2009-04-13 08:47 . 2008-10-16 01:00 1499648 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-04-13 08:47 . 2009-03-02 23:10 1499648 c:\windows\system32\dllcache\shdocvw.dll
- 2008-05-07 05:10 . 2008-05-07 05:10 1293312 c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:10 . 2008-12-20 22:13 1293312 c:\windows\system32\dllcache\quartz.dll
+ 2009-04-13 08:45 . 2009-02-09 11:23 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
- 2009-04-13 08:45 . 2008-08-14 13:22 2027520 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-04-13 08:45 . 2009-02-09 11:23 2027520 c:\windows\system32\dllcache\ntkrpamp.exe
- 2009-04-13 08:45 . 2008-08-14 13:22 2069760 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-04-13 08:45 . 2009-02-10 17:02 2069760 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-04-13 08:45 . 2009-02-09 11:22 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2009-04-13 08:45 . 2008-08-14 13:22 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-04-13 08:45 . 2009-02-20 08:09 3089408 c:\windows\system32\dllcache\mshtml.dll
+ 2009-03-21 14:06 . 2009-03-21 14:06 1033728 c:\windows\system32\dllcache\kernel32.dll
+ 2009-04-13 08:45 . 2009-02-09 11:23 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2009-04-13 08:45 . 2008-08-14 13:22 2027520 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-04-13 08:45 . 2009-02-09 11:23 2027520 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-04-13 08:45 . 2009-02-10 17:02 2069760 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-04-13 08:45 . 2008-08-14 13:22 2069760 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-04-13 08:45 . 2008-08-14 13:22 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-04-13 08:45 . 2009-02-09 11:22 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-01-18 14:36 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RocketDock"="c:\programmi\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISBMgr.exe"="c:\programmi\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-06-09 6746112]
"AppleSyncNotifier"="c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-05 177472]
"SonyPowerCfg"="c:\programmi\Sony\VAIO Power Management\SPMgr.exe" [2005-05-15 184320]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-29 114688]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-29 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-29 77824]
"AzMixerSel"="c:\programmi\Realtek\InstallShield\AzMixerSel.exe" [2005-04-29 45056]
"Apoint"="c:\programmi\Apoint\Apoint.exe" [2003-11-07 114688]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-11 1932568]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-04-11 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-06-29 14720000]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-11 12:42 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 15:42 73728 ----a-w c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\FILECO~1\SONYSH~1\VideoLib\sonydv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 ----a-w c:\programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-04-11 09:49 148888 ----a-w c:\programmi\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
2005-01-14 11:43 151552 ----a-w c:\programmi\Sony\VAIO Update 2\VAIOUpdt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon]
2002-03-14 14:46 45056 ----a-w c:\windows\system32\ico.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\File comuni\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\TeamViewer\\Version4\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Lphant\\eLePhantClient.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"4509:UDP"= 4509:UDP:emule
R3 bsusbser;PHD USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\bsusbser.sys [2006-12-20 94848]
R3 eusk3usb;SmartKey 3 USB;c:\windows\system32\Drivers\eusk3usb.sys [2004-11-17 45534]
R3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 311872]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-11 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-11 108552]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-11 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-11 298264]
S2 eugss;EUTRON SmartKey GSS2 Driver;c:\windows\system32\Drivers\eugssxp.sys [2004-11-17 57951]
S2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 7520337]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-04-11 603904]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0df9b811-7c20-11dd-88fb-0013cead98b8}]
\Shell\AutoRun\command - H:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{605973ed-ceab-11dd-8923-0013cead98b8}]
\Shell\auto\command - Knight.exe open
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
\Shell\explore\command - Knight.exe open
\Shell\find\command - Knight.exe open
\Shell\install\command - Knight.exe open
\Shell\open\command - Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bcf244-1008-11de-8945-0013cead98b8}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d18119be-9d44-11dd-8903-0013cead98b8}]
\Shell\auto\command - G:\Knight.exe open
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
\Shell\explore\command - G:\Knight.exe open
\Shell\find\command - G:\Knight.exe open
\Shell\install\command - G:\Knight.exe open
\Shell\open\command - G:\Knight.exe open
.
Contenuto della cartella 'Scheduled Tasks'
2009-04-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-04-15 c:\windows\Tasks\Manutenzione in 1 clic.job
- c:\programmi\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 15:20]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://it.rd.yahoo.com/customize/ycomp/defaults/su/*http://it.yahoo.com
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Trasferimento tramite Image Converter 2 - c:\programmi\Sony\Image Converter 2\menu.htm
FF - ProfilePath - c:\documents and settings\saretta\Dati applicazioni\Mozilla\Firefox\Profiles\5whj6mu1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it
FF - component: c:\documents and settings\saretta\Dati applicazioni\Mozilla\Firefox\Profiles\5whj6mu1.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\programmi\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\programmi\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-15 19:14
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1892)
c:\windows\system32\VESWinlogon.dll
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(2616)
c:\programmi\RocketDock\RocketDock.dll
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Ora fine scansione: 2009-04-15 19.16.30
ComboFix-quarantined-files.txt 2009-04-15 17:16
ComboFix2.txt 2009-04-14 22:57
ComboFix3.txt 2009-04-14 22:29
ComboFix4.txt 2009-04-14 22:18
Pre-Run: 13.486.108.672 byte disponibili
Post-Run: 13.474.377.728 byte disponibili
428 --- E O F --- 2009-04-13 10:35
a tua disposizione
grazie r16