ecco il log di combofix r16
ComboFix 10-02-11.04 - User 12/02/2010 15.38.34.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1458 [GMT 1:00]
Eseguito da: c:\documents and settings\User\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-01-12 al 2010-02-12 )))))))))))))))))))))))))))))))))))
.
2010-02-09 16:38 . 2010-02-09 16:38 -------- d-----w- c:\documents and settings\User\Dati applicazioni\CyberLink
2010-02-09 16:06 . 2010-02-09 16:06 -------- d-----w- c:\documents and settings\User\Dati applicazioni\dvdcss
2010-02-06 11:35 . 2010-02-12 14:29 -------- d-----w- c:\programmi\Extension Changer
2010-01-27 08:26 . 2010-01-27 08:26 -------- d-----w- c:\programmi\Auslogics
2010-01-27 00:24 . 2010-01-14 16:06 3777280 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\setup.exe
2010-01-27 00:24 . 2010-01-14 16:06 1260800 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgfrw.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-12 14:38 . 2009-01-15 04:17 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-02-12 13:10 . 2009-01-12 05:54 -------- d-----w- c:\documents and settings\User\Dati applicazioni\uTorrent
2010-02-12 09:30 . 2009-02-14 08:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2010-02-07 05:55 . 2008-07-14 18:48 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-02-06 13:14 . 2009-02-13 12:42 -------- d-----w- c:\programmi\AVS4YOU
2010-02-06 12:20 . 2009-02-13 12:42 -------- d-----w- c:\programmi\File comuni\AVSMedia
2010-02-01 15:52 . 2009-02-14 08:19 -------- d-----w- c:\programmi\Google
2010-01-26 15:19 . 2009-01-12 05:44 -------- d-----w- c:\programmi\Defraggler
2010-01-25 14:32 . 2009-11-20 05:09 -------- d-----w- c:\programmi\Giorno per Giorno
2010-01-18 13:55 . 2009-12-09 03:58 -------- d-----w- c:\programmi\PC Tools Firewall Plus
2010-01-18 13:55 . 2009-12-09 03:58 115216 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2010-01-18 13:55 . 2009-12-09 03:58 58816 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2010-01-18 13:55 . 2009-12-09 03:58 70664 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2010-01-18 13:54 . 2009-12-09 03:58 32680 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2010-01-18 13:54 . 2009-12-09 03:59 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-08 17:21 . 2009-01-14 04:23 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-08 17:21 . 2009-01-15 09:30 5115824 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-07 15:07 . 2009-01-14 04:23 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-01-14 04:23 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 09:53 . 2007-10-29 12:00 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 09:53 . 2007-10-29 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 09:53 . 2007-10-29 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-01-04 13:18 . 2008-07-18 07:29 -------- d-----w- c:\documents and settings\User\Dati applicazioni\Vso
2010-01-04 12:42 . 2010-01-04 12:42 -------- d-----w- c:\programmi\VSO
2009-12-31 16:50 . 2007-10-29 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-25 15:32 . 2009-12-25 05:06 -------- d-----w- c:\programmi\Adobe(2)
2009-12-25 15:32 . 2008-07-14 14:51 -------- d-----w- c:\programmi\File comuni\Adobe
2009-12-24 06:19 . 2008-07-15 04:48 -------- d-----w- c:\programmi\ABBYY FineReader 6.0 Sprint
2009-12-22 04:03 . 2009-01-14 04:19 -------- d-----w- c:\documents and settings\User\Dati applicazioni\GlarySoft
2009-12-22 03:57 . 2008-07-14 18:35 -------- d-----w- c:\programmi\FileMaker Pro 6
2009-12-22 03:36 . 2009-01-13 04:01 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-22 03:36 . 2009-01-13 04:01 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-22 03:36 . 2009-01-13 04:01 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-22 03:36 . 2009-01-13 04:01 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-22 03:36 . 2009-01-13 04:01 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-12-17 07:40 . 2008-07-14 13:49 346112 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2007-10-29 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-11 06:03 . 2007-10-29 12:00 47814 ----a-w- c:\windows\system32\perfc010.dat
2009-12-11 06:03 . 2007-10-29 12:00 345382 ----a-w- c:\windows\system32\perfh010.dat
2009-12-09 10:07 . 2007-10-29 12:00 2148864 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-09 10:07 . 2004-08-19 15:34 2027520 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2007-10-29 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-04 05:59 . 2009-12-04 05:59 152576 ----a-w- c:\documents and settings\User\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-04 05:58 . 2009-12-04 05:58 79488 ----a-w- c:\documents and settings\User\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-27 17:12 . 2007-10-29 12:00 1296896 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:12 . 2004-08-19 15:39 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2001-08-30 23:08 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2007-10-29 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2007-10-29 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2007-10-29 12:00 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-19 15:39 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-26 04:25 . 2009-11-26 04:18 123611 ----a-w- c:\windows\hpoins11.dat
2009-11-23 12:54 . 2009-12-09 03:59 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-21 15:54 . 2007-10-29 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-18 15:23 . 2009-11-23 23:49 3775256 ----a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP\AVG\setup.exe
.
(((((((((((((((((((((((((((((
SnapShot@2010-02-12_14.29.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-12 14:36 . 2010-02-12 14:36 16384 c:\windows\Temp\Perflib_Perfdata_328.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="c:\programmi\CCleaner\CCleaner.exe" [2009-11-24 1738040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\programmi\BillP Studios\WinPatrol\winpatrol.exe" [2007-08-06 292152]
"AcronisTimounterMonitor"="c:\programmi\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-03-10 909592]
"Acronis Scheduler2 Service"="c:\programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2008-03-10 140568]
"SmartDefrag"="c:\programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-11-21 2386960]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-09 8523776]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2010-01-18 3168216]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-22 03:36 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 18:43 69632 ------r- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-03-12 11:49 153136 ----a-w- c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
2007-08-21 19:05 73728 ----a-w- c:\programmi\ClamWin\bin\ClamTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-13 18:14 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-02-19 11:10 267048 ----a-w- c:\programmi\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-09 16:53 153136 ----a-w- c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-01-09 07:23 8523776 ----a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-01-09 07:23 81920 ----a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-01-09 07:23 1626112 ----a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-01-31 21:13 385024 ----a-w- c:\programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-03-21 14:49 16126464 ------r- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2006-09-07 17:19 15872 ----a-w- c:\programmi\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\programmi\HP\HP Software Update\HPWuSchd2.exe
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"SmartDefrag"="c:\programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
"TrueImageMonitor.exe"=c:\programmi\Acronis\TrueImageHome\TrueImageMonitor.exe
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe"
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Marvell\\61xx\\Apache2\\bin\\Apache.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgam.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [13/01/2009 5.01.28 161800]
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [15/06/2007 8.52.02 143256]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/01/2009 5.01.27 333192]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/01/2009 5.01.28 360584]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [09/12/2009 4.59.09 233136]
R2 avg9emc;AVG E-mail Scanner;c:\programmi\AVG\AVG9\avgemc.exe [22/12/2009 4.36.33 906520]
R2 avg9wd;AVG WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [22/12/2009 4.36.35 285392]
R2 MRUWebService;MRU Web Service;c:\programmi\Marvell\61xx\Apache2\bin\Apache.exe [23/05/2007 1.17.02 20539]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [09/12/2009 4.59.13 88040]
R3 bsusbser;H3G USB Device for Legacy Serial Communication;c:\windows\system32\drivers\bsusbser.sys [14/07/2008 20.13.14 94848]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [09/12/2009 4.58.50 70664]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [09/12/2009 4.58.50 58816]
S2 gupdate1c98e8487ce2592;Servizio di Google Update (gupdate1c98e8487ce2592);c:\programmi\Google\Update\GoogleUpdate.exe [14/02/2009 10.13.41 133104]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [14/07/2008 15.13.34 36864]
S3 Marvell RAID;Marvell RAID Event Agent;c:\programmi\Marvell\61xx\svc\mvraidsvc.exe [12/06/2007 19.54.12 61440]
S3 PCTFW-DNS;PCTools Firewall - DNS driver;c:\windows\system32\drivers\pctNdis-DNS.sys [09/12/2009 4.58.50 32680]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [09/12/2009 4.58.49 115216]
.
Contenuto della cartella 'Scheduled Tasks'
2010-02-12 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-14 13:36]
2010-02-12 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-14 09:13]
2010-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-14 09:13]
2010-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-14 09:13]
.
.
------- Scansione supplementare -------
.
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\User\Dati applicazioni\Mozilla\Firefox\Profiles\6t2aa4dq.default\
FF - component: c:\programmi\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-12 15:40
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(944)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(4208)
c:\windows\system32\WININET.dll
c:\programmi\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-02-12 15:41:50
ComboFix-quarantined-files.txt 2010-02-12 14:41
ComboFix2.txt 2010-02-12 14:30
Pre-Run: 436.985.757.696 byte disponibili
Post-Run: 436.950.343.680 byte disponibili
- - End Of File - - 0E1310F9FA499C486C1B3DDDE9671673