R16 SP2=SERVICE PACK 2 ?ComboFix 09-05-22.08 - Fra 23/05/2009 19.02.47.10 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.511.169 [GMT 2:00]
Eseguito da: c:\documents and settings\Fra\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Outpost Firewall Pro *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Fra\IMPOST~1\Temp\catchme.dll
c:\documents and settings\Fra\Impostazioni locali\temp\catchme.dll
.
((((((((((((((((((((((((( Files Creati Da 2009-04-23 al 2009-05-23 )))))))))))))))))))))))))))))))))))
.
2009-05-20 12:51 . 2009-05-20 13:14 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\Orbit
2009-05-17 18:12 . 2009-05-17 18:12 7168 ----a-w c:\documents and settings\Fra\Dati applicazioni\Thinstall\ProxySwitcher Standard\4000002900002i\FireFox.exe
2009-05-17 18:06 . 2009-05-17 18:06 7168 ----a-w c:\documents and settings\Fra\Dati applicazioni\Thinstall\ProxySwitcher Standard\4000003af00002i\ProxySwitcher.exe
2009-05-17 18:06 . 2009-05-17 18:06 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\Thinstall
2009-05-14 12:47 . 2009-04-23 15:24 16640 ----a-w c:\windows\system32\drivers\WsAudio_DeviceS(1).sys
2009-05-07 15:58 . 2009-05-07 16:05 -------- d-----w c:\documents and settings\Fra\dwhelper
2009-05-02 21:18 . 2009-05-02 21:18 -------- d-----w c:\programmi\Easy Video Joiner
2009-05-01 19:47 . 2009-05-01 19:47 -------- d-----w c:\programmi\eMule
2009-04-28 11:03 . 2009-04-28 11:03 -------- d-----w c:\programmi\DAEMON Tools Lite
2009-04-25 21:02 . 2009-04-25 21:05 -------- d-----w c:\documents and settings\Fra\.housecall6.6
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-23 16:08 . 2009-03-21 15:16 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\Skype
2009-05-23 15:19 . 2009-01-02 17:09 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\skypePM
2009-05-23 15:15 . 2008-10-27 14:17 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\LimeWire
2009-05-23 13:21 . 2008-12-18 19:00 -------- d-----w c:\programmi\ESET
2009-05-23 12:27 . 2009-01-01 21:17 -------- d-----w c:\programmi\PokerStars.IT
2009-05-22 19:41 . 2008-06-29 12:21 -------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Spybot - Search & Destroy
2009-05-21 22:18 . 2008-05-31 20:58 -------- d-----w c:\programmi\PokerStars
2009-05-21 11:56 . 2009-01-28 15:18 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\dvdcss
2009-05-20 17:31 . 2007-12-03 14:16 -------- d-----w c:\programmi\File comuni\Adobe
2009-05-18 15:33 . 2009-02-15 22:14 -------- d-----w c:\programmi\Defraggler
2009-05-17 11:57 . 2008-06-07 15:26 -------- d-----w c:\programmi\Messenger Plus! Live
2009-05-14 12:47 . 2009-04-17 12:15 -------- d-----w c:\programmi\Wondershare
2009-05-12 21:05 . 2009-01-21 22:44 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\Babylon
2009-05-12 21:03 . 2009-01-21 22:44 -------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Babylon
2009-05-07 15:04 . 2009-04-10 10:26 -------- d-----w c:\programmi\Graffiti Studio 2.0
2009-05-06 14:46 . 2009-01-26 14:25 -------- d-----w c:\programmi\PeerGuardian2
2009-05-01 22:12 . 2009-03-25 13:52 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\Advanced Audio Recorder
2009-05-01 19:47 . 2009-04-15 15:04 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\eMule
2009-04-29 20:19 . 2008-10-16 20:01 290816 ------w c:\windows\Setup1.exe
2009-04-28 10:33 . 2008-06-21 12:11 721904 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-25 21:03 . 2008-12-23 19:29 102664 -c--a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-21 15:47 . 2008-06-15 14:15 -------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Apple Computer
2009-04-17 12:03 . 2004-08-19 12:00 85510 ----a-w c:\windows\system32\perfc010.dat
2009-04-17 12:03 . 2004-08-19 12:00 492784 ----a-w c:\windows\system32\perfh010.dat
2009-04-15 17:54 . 2008-12-13 13:46 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-04-15 17:53 . 2009-01-05 14:39 2967799 -c--a-w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-04-15 16:48 . 2009-04-15 16:47 -------- d-----w c:\programmi\iTunes
2009-04-15 16:48 . 2009-04-15 16:47 -------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-15 16:47 . 2009-04-15 16:47 -------- d-----w c:\programmi\iPod
2009-04-15 16:41 . 2009-04-15 16:41 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\vlc
2009-04-15 15:02 . 2008-07-27 09:39 -------- d-----w c:\programmi\eMule AdunanzA
2009-04-15 14:02 . 2008-05-31 20:37 122136 -c--a-w c:\documents and settings\Fra\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-09 21:38 . 2009-04-09 21:38 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\TeamViewer
2009-04-09 16:00 . 2009-04-09 16:00 -------- d-----w c:\programmi\EA GAMES
2009-04-06 13:32 . 2008-12-13 13:46 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2008-12-13 13:46 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-03 18:02 . 2009-04-03 18:02 -------- d-----w c:\programmi\Pirelli
2009-04-03 15:39 . 2009-04-03 15:39 -------- d-----w c:\programmi\microsoft frontpage
2009-04-02 14:29 . 2009-04-02 14:29 75048 ----a-w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-01 18:27 . 2009-03-29 17:55 -------- d-----w c:\programmi\ManyCam 2.4
2009-03-31 14:45 . 2008-12-15 14:08 -------- d-----w c:\programmi\Metin2_Italiano
2009-03-29 18:16 . 2009-03-18 17:36 -------- d-----w c:\programmi\LimeWire
2009-03-29 17:56 . 2009-03-29 17:55 -------- d-----w c:\documents and settings\Fra\Dati applicazioni\ManyCam
2009-03-29 17:46 . 2009-03-29 17:46 4 --sh--r c:\documents and settings\All Users.WINDOWS\Dati applicazioni\sysqcl0.dat
2009-03-29 17:44 . 2009-03-29 17:44 -------- d-----w c:\programmi\plasq
2009-03-29 17:44 . 2008-05-25 16:22 -------- d-----w c:\programmi\File comuni\Wise Installation Wizard
2009-03-29 17:34 . 2009-01-09 19:44 -------- d-----w c:\programmi\Spybot - Search & Destroy
2009-03-29 10:37 . 2008-11-11 22:24 410984 -c--a-w c:\windows\system32\deploytk.dll
2009-03-29 10:36 . 2009-03-29 10:36 152576 ----a-w c:\documents and settings\Fra\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-27 16:43 . 2009-03-27 13:22 -------- d-----w c:\programmi\Wise Registry Cleaner
2009-03-25 13:51 . 2009-03-25 13:51 -------- d-----w c:\programmi\Advanced Audio Recorder
2009-03-20 22:27 . 2009-03-20 22:27 27136 ----a-w c:\windows\system32\drivers\tapvpn.sys
2009-03-19 14:32 . 2009-03-19 14:32 23400 ----a-w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 14:32 . 2008-01-29 10:01 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-06 13:59 . 2004-08-19 12:00 286208 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:03 . 2004-09-29 18:48 826368 ----a-w c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-05-23_16.57.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-09 11:45 . 2009-05-23 17:01 2072 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
- 2008-09-09 11:45 . 2009-04-12 18:35 2072 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\programmi\ESET\ESET NOD32 Antivirus\egui.exe" [2008-10-08 1451264]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-12-14 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonuiX.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Avvio^Programmi^Esecuzione automatica^Controllo del Calendario di Ulead Photo Express.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Avvio^Programmi^Esecuzione automatica^Orbit.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Avvio^Programmi^Esecuzione automatica^Privoxy.lnk]
backup=c:\windows\pss\Privoxy.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Fra^Menu Avvio^Programmi^Esecuzione automatica^Ritaglio schermata e avvio di OneNote 2007.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Fra^Menu Avvio^Programmi^Esecuzione automatica^Styler.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrA"=2 (0x2)
"Bonjour Service"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=2 (0x2)
"gupdate1c98b7678297c1a"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"HssSrv"=2 (0x2)
"HotspotShieldService"=2 (0x2)
"6to4"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Metin2_Italiano\\metin2.bin"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Porte Del Client
"4672:UDP"= 4672:UDP:Porte del client
R0 phmcd;phmcd;c:\windows\system32\drivers\phmcd.sys [08/04/2008 20.41.29 44696]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [08/10/2008 09.50.14 34312]
R1 TsMali;TsMali;c:\windows\system32\drivers\tsmali.sys [28/01/2009 15.54.20 38599]
R2 ekrn;Eset Service;c:\programmi\ESET\ESET NOD32 Antivirus\ekrn.exe [08/10/2008 09.47.58 468224]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 12.06.32 21632]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [27/09/2006 00.21.10 21920]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [14/05/2009 14.47.42 16640]
R3 ZSMC0305;VIMICRO USB PC Camera V;c:\windows\system32\drivers\usbVM305.sys [02/10/2008 19.23.25 391099]
S4 gupdate1c98b7678297c1a;Google Update Service (gupdate1c98b7678297c1a); [x]
.
Contenuto della cartella 'Scheduled Tasks'
2009-03-29 c:\windows\Tasks\Wise Registry Cleaner 4.job
- c:\programmi\Wise Registry Cleaner\WiseRegistryCleaner.exe [2009-03-27 20:27]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.ask.com/?o=101764&l=dis
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Translate with &Babylon - c:\programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\programmi\PokerStars.IT\PokerStarsUpdate.exe
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\Fra\Dati applicazioni\Mozilla\Firefox\Profiles\zl0ttuob.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npigl.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-23 19:04
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="B30CD397FB772E7571828B9FEAE7BD61963605F8EE89324A0C203540BCA01B6807AAB772F8F2968FE614D4D382DF06A6EA415B62940B092239BBC6E42B9A4F92B0AFBD774A7B3DC48E7B5539FCC2D6EFE2D8A98041910370540B489E25149D1D3721E83B508BD29FECCA75B8C865D5E69E39DEA88F6A5D23BC114DD492F4F4D4D6EE125663BF1E6D3B79F0B9473EBF7AF4013D36918368E78436BCF3D0445CC8FC6A63E54DDB79BDE560DA2AD067E25CED335A07C9720831F14751EA31AFECCDCFFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6A0AC4980AC79338EDD5E5BE2F6E667A9C6AECB7A5D14074F6D002EA0F7AB6A58A4F991F43A87BC20AC73F3DECE443E730F680CBB1E2A0EA1EDE27A7B635A4064297D33607BE9B16CD7803EC480732D701102C0F8434F63CB851FDB2B06CBA8B5644457E38EFD8E8317811F11832147F8CA6F0F1CA104D8A9432B111B3B08227109558884852F3171E1AE8B01BDB9E4A195BDF8BC94D5647B8681C8DB72E0DEA01F3B416C872FA72784C56FF62AEE13E7A3F8F5168A98AEE207A02821306846AD7F877466CB70B6FA1E0727F8D73692297AB2710609DF1768CD8C45428DF472EA5ACB0864A02CD4A522B686B0E7485627F180C90FA5072EF7B9C9AEBB3623B00B32A1D1FBE65E2DC4D99CD1EB9122088838FBD15A8BACB8DF7BE4622EEAD10628DD24A165944720D9DE87431E9E8505584CC4D131F932B15318EB55DBFEA3A63E87F1B87CB26BC14AA2C6095A6CF65C0483F98381C53E44EAEBEFEEAD5B00FDAB2E304944DC12585F68AEC55DED40545E06C11660543BD5A1A10A0C307D912B38A405FEDFC748DF4747198F822AEEE29DD2462E042256F7D63D547C917248FE0A921D759835DC08122CE2EECD3BD2365D3835E0C6BD81F64C14EB832761D6032EF1A7BEDB8065B4B657E9E363CD02AF995CC03926CB74CE2CCE75D9E882B4ED9412585FBA15397C8CDA165F8E2755E1B7381D374802A83280EC952B70201DB11294E650E9F6F42CD29E4E47BC9AE996FA9705CD72ABDB85B9BEF818011C8E6E5FF08FFDC13978C1A9DF00F50093A04A909C36E310A911E229EACCB57C6ACCFC18F191CA3F06E7F1182D1BB90D119FAC06B9F1D42FED8C17876B44886B135E643DB6300B051B2B2406EB1554BFA4CFA2CBB9FD6F827EDA25EF8C9610F8328FE6B332B308D4C8EF73C1D1657C94F35D453B392375E1F949C1E2F17D3AF5F8ED75C2A9677D9975A32FFA6B8ADA2E3ABA618D28B01F488D69D5C110386CD5AA4EB596B89A1E60187DDB4918030E53459BF5E04C7718537C1100D43109FC30204783C1CEA10FD940732F258D55286BF77AB8373DCC7EC61E5C11C873B6B9C1C533EDB6AED368D98EC1"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(948)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-05-23 19.06.13
ComboFix-quarantined-files.txt 2009-05-23 17:05
ComboFix2.txt 2009-05-23 16:59
Pre-Run: 204.425.924.608 byte disponibili
Post-Run: 204.413.812.736 byte disponibili
197 --- E O F --- 2009-05-13 19:45