ComboFix 09-11-21.03 - David 22/11/2009 19.42.19.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.503.180 [GMT 1:00]
Eseguito da: c:\documents and settings\David\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-10-22 al 2009-11-22 )))))))))))))))))))))))))))))))))))
.
2009-11-21 07:50 . 2009-11-21 07:50 -------- d-----w- c:\windows\system32\XPSViewer
2009-11-21 07:50 . 2009-11-21 07:50 -------- d-----w- c:\programmi\Reference Assemblies
2009-11-21 07:48 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-11-21 07:48 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-11-21 07:48 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-11-21 07:48 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-11-21 07:48 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-11-21 07:48 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-11-21 07:48 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-11-21 07:48 . 2009-11-21 07:49 -------- d-----w- C:\8f1020cb72886b35e98f10379c919c64
2009-11-21 07:35 . 2009-11-21 07:35 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-11-18 19:19 . 2009-11-18 19:19 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-11-17 01:04 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2009-11-17 01:04 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-11-06 16:45 . 2009-11-06 16:42 2064152 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgcorex.dll
2009-11-02 08:37 . 2009-11-02 08:37 -------- d-----w- c:\documents and settings\David\Impostazioni locali\Dati applicazioni\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-22 18:36 . 2009-02-02 00:13 68448 ----a-w- c:\documents and settings\David\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-11-22 14:26 . 2004-09-16 14:31 81756 ----a-w- c:\windows\system32\perfc010.dat
2009-11-22 14:26 . 2004-09-16 14:31 484210 ----a-w- c:\windows\system32\perfh010.dat
2009-11-22 14:16 . 2009-09-23 18:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-11-22 13:50 . 2009-01-26 14:49 -------- d-----w- c:\programmi\Microsoft Works
2009-11-22 13:11 . 2009-02-12 18:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-11-21 07:50 . 2009-09-23 18:41 -------- d-----w- c:\programmi\MSBuild
2009-11-19 22:22 . 2009-02-09 18:42 -------- d-----w- c:\documents and settings\David\Dati applicazioni\uTorrent
2009-11-19 17:56 . 2009-01-26 16:43 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-16 20:17 . 2009-01-26 12:57 -------- d-----w- c:\programmi\File comuni\Adobe
2009-11-06 17:13 . 2009-02-23 21:42 -------- d-----w- c:\programmi\PoigpsGo
2009-10-12 18:40 . 2009-10-12 18:40 -------- d-----w- c:\programmi\B2BPOKER
2009-10-02 18:47 . 2009-10-02 18:47 -------- d-----w- c:\documents and settings\David\Dati applicazioni\Malwarebytes
2009-10-02 18:47 . 2009-10-02 18:47 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-10-02 18:47 . 2009-10-02 18:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-09-30 17:42 . 2009-08-08 16:20 -------- d-----w- c:\documents and settings\David\Dati applicazioni\TeamViewer
2009-09-28 19:44 . 2009-09-28 19:44 -------- d-----w- c:\programmi\Business Objects
2009-09-28 19:30 . 2009-09-28 19:30 516096 ----a-w- c:\windows\iwexec.exe
2009-09-28 18:58 . 2009-09-28 18:52 -------- d-----w- c:\programmi\Date Cracker 2000
2009-09-28 18:52 . 2009-09-28 18:52 249856 ------w- c:\windows\Setup1.exe
2009-09-28 18:52 . 2009-09-28 18:52 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-09-11 14:34 . 2004-09-16 14:31 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 12:54 . 2009-10-02 18:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-10-02 18:47 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 20:45 . 2004-09-16 14:31 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-09-16 14:31 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:14 . 2004-09-16 14:31 247326 ----a-w- c:\windows\system32\strmdll.dll
2007-03-11 04:58 . 2009-02-01 22:08 1197796 ----a-w- c:\programmi\WinRAR-ITA v3.62+Crack.rar
1990-10-27 04:02 . 2009-02-01 22:07 189695112 ----a-w- c:\programmi\NERO_8.1_ITA+KEYGEN.rar
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="c:\programmi\TomTom HOME 2\TomTomHOMERunner.exe" [2009-08-27 247144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-10-29 98394]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-10-29 688218]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-04 2028312]
"ZCfgSvc.exe"="c:\windows\system32\ZCfgSvc.exe" [2004-09-06 417856]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-09-06 04:29 180290 ----a-w- c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 07:13 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Asus\\ASUS Live Update\\LiveUpdt.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\B2BPOKER\\AssoKappa\\jre\\bin\\javaw.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/04/2009 20.39.13 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/04/2009 20.39.21 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/04/2009 20.38.45 297752]
R2 TeamViewer4;TeamViewer 4;c:\programmi\TeamViewer\Version4\TeamViewer_Service.exe [30/07/2009 16.29.42 185640]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmi\TomTom HOME 2\TomTomHOMEService.exe [27/08/2009 16.05.04 92008]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/01/2009 17.43.40 721904]
S2 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\SupportAppMH\cdrom_mon.exe [27/01/2009 16.44.14 81920]
S2 gupdate1c98d3f1537111a;Google Update Service (gupdate1c98d3f1537111a);c:\programmi\Google\Update\GoogleUpdate.exe [12/02/2009 19.24.00 133104]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [07/02/2009 21.39.14 8192]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys --> c:\windows\system32\drivers\nmwcdnsu.sys [?]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys --> c:\windows\system32\drivers\nmwcdnsuc.sys [?]
S3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\drivers\ONDAusbmdm6k.sys [27/01/2009 16.45.00 100352]
S3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\drivers\ONDAusbnmea.sys [27/01/2009 16.45.00 100352]
S3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\drivers\ONDAusbser6k.sys [27/01/2009 16.45.00 100352]
S3 ZD1211BU(Atheros);IEEE 802.11 Wireless LAN Driver (USB)(Atheros);c:\windows\system32\drivers\ZD1211BU.sys [12/02/2009 19.02.03 712704]
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-22 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-12 18:15]
2009-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-12 18:23]
2009-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-12 18:23]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 192.169.0.1:2939
uInternet Settings,ProxyOverride = 127.0.0.1;<local>
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\David\Dati applicazioni\Mozilla\Firefox\Profiles\vi76p9je.default\
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\programmi\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-22 19:59
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ñw*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\LgNotify.dll
.
Ora fine scansione: 2009-11-22 20:08
ComboFix-quarantined-files.txt 2009-11-22 19:08
Pre-Run: 24.641.951.232 byte disponibili
Post-Run: 24.806.561.792 byte disponibili
- - End Of File - - 3660A8D3A45FCCB5559EFFBE4E23E0E5