ComboFix 09-10-16.09 - Utente 18/10/2009 12.20.18.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.2047.1472 [GMT 2:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 091017-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Utente\Dati applicazioni\Desktopicon
c:\windows\Installer\2d28c8.msp
c:\windows\system32\Data
.
((((((((((((((((((((((((( Files Creati Da 2009-09-18 al 2009-10-18 )))))))))))))))))))))))))))))))))))
.
2009-10-18 08:58 . 2009-10-18 08:58 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\ATI
2009-10-18 08:58 . 2009-10-18 08:58 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Logitech-LS
2009-10-18 08:57 . 2009-10-18 08:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Motive
2009-10-18 08:28 . 2009-10-18 08:29 -------- d-----w- c:\programmi\Folderico
2009-10-18 08:09 . 2009-10-18 08:09 -------- d--h--w- c:\documents and settings\Utente\Risorse di rete
2009-10-15 16:09 . 2009-10-15 16:09 -------- d-----w- C:\mirc script
2009-10-10 12:21 . 2009-10-10 12:21 135 ----a-w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\fusioncache.dat
2009-10-10 12:21 . 2009-10-10 12:24 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\ApplicationHistory
2009-10-04 18:10 . 2009-10-04 18:10 -------- d-----w- c:\programmi\JRE
2009-09-27 08:29 . 2009-09-27 08:29 64 ----a-w- c:\windows\system32\BurnData.bin
2009-09-27 08:29 . 2009-09-27 08:29 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Roxio
2009-09-27 08:23 . 2009-09-27 08:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Napster
2009-09-27 08:23 . 2009-09-28 11:38 -------- d-----w- c:\programmi\Napster
2009-09-27 07:15 . 2009-10-18 07:59 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Apple Computer
2009-09-27 07:14 . 2009-09-27 07:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-27 07:13 . 2009-09-27 07:13 -------- d-----w- c:\programmi\Bonjour
2009-09-27 07:11 . 2009-09-27 07:11 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple
2009-09-26 20:44 . 2009-10-16 18:23 -------- d-----w- c:\programmi\Alice Messenger
2009-09-21 20:26 . 2009-09-21 20:26 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\com.maisonthe.VodafoneStationAssistant.B346B89D6616488DE8DCE4FEACC768D33B80ABC4.1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-18 10:17 . 2008-12-01 14:46 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Skype
2009-10-18 08:58 . 2009-01-29 19:20 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-10-18 07:59 . 2008-11-29 08:36 -------- d-----w- c:\programmi\Ahead
2009-10-18 07:59 . 2009-07-05 16:03 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Paltalk
2009-10-18 07:59 . 2008-12-13 12:04 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\dvdcss
2009-10-18 07:59 . 2009-01-18 14:57 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Creative
2009-10-18 07:58 . 2008-12-01 14:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\EPSON
2009-10-18 07:58 . 2008-11-29 08:40 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-10-18 07:20 . 2008-12-01 14:46 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\skypePM
2009-10-18 07:07 . 2009-02-01 21:33 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-10-17 18:56 . 2008-11-29 08:21 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-10-17 18:06 . 2008-12-09 07:12 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\DataCast
2009-10-14 09:43 . 2004-08-19 12:00 92638 ----a-w- c:\windows\system32\perfc010.dat
2009-10-14 09:43 . 2004-08-19 12:00 512194 ----a-w- c:\windows\system32\perfh010.dat
2009-10-10 16:05 . 2008-11-28 18:38 34352 ----a-w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-04 18:09 . 2008-12-11 19:51 -------- d-----w- c:\programmi\OpenOffice.org 3
2009-10-04 18:06 . 2008-12-03 20:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-27 07:14 . 2008-11-29 08:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2009-09-25 19:42 . 2009-09-16 17:53 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\vlc
2009-09-21 20:25 . 2008-12-03 20:31 -------- d-----w- c:\programmi\File comuni\Adobe AIR
2009-09-11 14:17 . 2004-08-19 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 12:54 . 2009-02-01 21:33 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-02-01 21:33 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2004-08-19 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 19:04 . 2009-09-01 19:04 -------- d-----w- c:\programmi\File comuni\DVDVideoSoft
2009-09-01 19:04 . 2009-09-01 19:04 -------- d-----w- c:\programmi\DVDVideoSoft
2009-08-31 17:15 . 2009-08-31 17:15 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\CoSoSys
2009-08-29 07:56 . 2004-08-19 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 15:41 . 2008-12-01 15:06 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\uTorrent
2009-08-26 08:00 . 2004-08-19 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-22 08:53 . 2009-01-17 14:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MAGIX
2009-08-22 08:45 . 2009-08-22 08:45 -------- d-----w- c:\programmi\MAGIX
2009-08-17 16:10 . 2009-04-11 08:07 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-04-11 08:08 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-04-11 08:08 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-04-11 08:08 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-04-11 08:08 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-04-11 08:08 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-04-11 08:08 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-04-11 08:08 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-04-11 08:08 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-07 19:11 . 2009-08-07 19:11 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-08-05 08:59 . 2004-08-19 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 17:26 . 2004-08-19 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:26 . 2004-08-19 15:34 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\programmi\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
"CreativeTaskScheduler"="c:\programmi\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="c:\programmi\Logitech\Video\ISStart.exe" [2004-10-08 458752]
"LogitechVideoTray"="c:\programmi\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
"CTSysVol"="c:\programmi\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-04 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2005-05-03 64512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Windows Search.lnk - c:\programmi\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-30 19:40 10520 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\programmi\\u torrent\\uTorrent.exe"=
"e:\\programmi\\voipe stunt\\VoipStunt\\VoipStunt.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Programmi\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImpCnt.exe"=
"e:\\programmi\\camfrog5.1\\Camfrog Video Chat\\Camfrog Video Chat.exe"=
"c:\\Programmi\\TeamViewer3\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Project_Dream\\ProjectDream.exe"=
"c:\\Programmi\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\mirc script\\programma mirc\\mIRCGFind\\mIRC.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:UDP"= 443:UDP:*:Disabled:Porta UDP ooVoo 443
"37674:TCP"= 37674:TCP:*:Disabled:Porta TCP ooVoo 37674
"37674:UDP"= 37674:UDP:*:Disabled:Porta UDP ooVoo 37674
"37675:UDP"= 37675:UDP:*:Disabled:Porta UDP ooVoo 37675
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [29/11/2008 10.20.39 11264]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11/04/2009 10.08.02 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [29/11/2008 10.40.34 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [29/11/2008 10.40.38 107272]
R2 ACEDRV09;ACEDRV09;c:\windows\system32\drivers\ACEDRV09.sys [17/01/2009 16.37.17 110304]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/04/2009 10.08.02 20560]
R2 CAMTHWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CAMTHWDM.sys [18/08/2009 20.05.58 941784]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [30/10/2008 1.05.58 31896]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe --> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe --> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;e:\programmi\Common\Database\bin\fbserver.exe [17/01/2009 16.34.17 1527900]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [31/05/2009 10.36.07 36608]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys --> c:\windows\system32\DRIVERS\ManyCam.sys [?]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [20/03/2006 19.34.56 1452032]
S3 TipCtrl;TipCtrl;c:\programmi\uTIPu\TipCtrl.exe [03/02/2009 21.15.06 314504]
S3 UPnPService;UPnPService;c:\programmi\File comuni\MAGIX Shared\UPnPService\UPnPService.exe [17/01/2009 16.35.44 544768]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [14/05/2009 19.11.29 79888]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://it.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local;*.local
IE: Save YouTube Video as MP3 - c:\programmi\File comuni\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://87.29.157.20:8081/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\4qtyy51s.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\programmi\File comuni\DVDVideoSoft\Dll\FFContextMenuY\components\FFContextMenu.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-18 12:23
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-10-18 12.25.14
ComboFix-quarantined-files.txt 2009-10-18 10:25
Pre-Run: 59.911.438.336 byte disponibili
Post-Run: 59.927.097.344 byte disponibili
201 --- E O F --- 2009-10-14 09:44