report.txtMalwarebytes' Anti-Malware 1.36
Versione del database: 1986
Windows 5.1.2600 Service Pack 2
2009-04-15 14:34:24
mbam-log-2009-04-15 (14-34-24).txt
Tipo di scansione: Scansione rapida
Elementi scansionati: 119721
Tempo trascorso: 3 minute(s), 46 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 1
Chiavi di registro infette: 3
Valori di registro infetti: 2
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 2
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
C:\WINDOWS\system32\zfgh83jg3.dll (Trojan.Agent) -> Delete on reboot.
Chiavi di registro infette:
HKEY_CLASSES_ROOT\CLSID\{d5bf49a0-94f3-42bd-f434-3604812c8955} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d5bf49a0-94f3-42bd-f434-3604812c8955} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d5bf49a0-94f3-42bd-f434-3604812c8955} (Trojan.Agent) -> Quarantined and deleted successfully.
Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{d5bf49a0-94f3-42bd-f434-3604812c8955} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\adsltaskbar (Trojan.Agent) -> Quarantined and deleted successfully.
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
C:\WINDOWS\system32\zfgh83jg3.dll (Trojan.Zlob.H) -> Delete on reboot.
C:\WINDOWS\Temp\winlognn.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
ComboFix 09-04-15.08 - antonio_old 2009-04-15 14:39.11 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.510.178 [GMT 2:00]
Eseguito da: c:\documents and settings\antonio_old\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Cache
c:\windows\Temp\33.exe
c:\windows\system32\userinit.exe . . . è infetto!!.
((((((((((((((((((((((((( Files Creati Da 2009-03-15 al 2009-04-15 )))))))))))))))))))))))))))))))))))
.
2009-04-15 12:34 . 2009-04-15 12:34 61440 ----a-w c:\windows\system32\drivers\oreeno.sys
2009-04-15 10:48 . 2009-04-15 10:48 15000 ------w c:\windows\system32\zfgh83jg3.dll
2009-04-15 10:46 . 2009-04-15 10:46 -------- d-----w c:\windows\LastGood
2009-04-15 10:43 . 2009-04-15 10:43 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-15 10:43 . 2009-04-15 10:43 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-15 10:43 . 2009-04-15 10:43 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-15 10:43 . 2009-04-15 10:49 -------- d-----w c:\windows\system32\drivers\Avg
2009-04-15 10:43 . 2009-04-15 10:43 -------- d-----w c:\programmi\AVG
2009-04-14 20:16 . 2006-03-02 12:00 76288 -c--a-w c:\windows\system32\dllcache\uniime.dll
2009-04-14 20:15 . 2006-03-02 12:00 98304 -c--a-w c:\windows\system32\dllcache\msir3jp.dll
2009-04-14 20:14 . 2006-03-02 12:00 128512 -c--a-w c:\windows\system32\dllcache\ftpsv251.dll
2009-04-14 20:10 . 2009-04-14 20:10 488 ---ha-r c:\windows\system32\logonui.exe.manifest
2009-04-14 20:10 . 2009-04-14 20:10 749 ---ha-r c:\windows\WindowsShell.Manifest
2009-04-14 20:10 . 2009-04-14 20:10 749 ---ha-r c:\windows\system32\wuaucpl.cpl.manifest
2009-04-14 20:10 . 2009-04-14 20:10 749 ---ha-r c:\windows\system32\sapi.cpl.manifest
2009-04-14 20:10 . 2009-04-14 20:10 749 ---ha-r c:\windows\system32\nwc.cpl.manifest
2009-04-14 20:10 . 2009-04-14 20:10 749 ---ha-r c:\windows\system32\ncpa.cpl.manifest
2009-04-14 20:06 . 2006-03-02 12:00 16384 -c--a-w c:\windows\system32\dllcache\isignup.exe
2009-04-14 20:05 . 2006-03-02 12:00 32768 -c--a-w c:\windows\system32\dllcache\icwdl.dll
2009-04-14 20:04 . 2006-03-02 12:00 20480 -c--a-w c:\windows\system32\dllcache\inetwiz.exe
2009-04-14 20:04 . 2006-03-02 12:00 86016 -c--a-w c:\windows\system32\dllcache\icwconn2.exe
2009-04-14 20:04 . 2006-03-02 12:00 216576 -c--a-w c:\windows\system32\dllcache\icwconn1.exe
2009-04-14 19:21 . 2001-08-17 18:13 27165 ----a-w c:\windows\system32\drivers\fetnd5.sys
2009-04-14 19:15 . 2006-03-02 12:00 24661 -c--a-w c:\windows\system32\dllcache\spxcoins.dll
2009-04-14 19:15 . 2006-03-02 12:00 24661 ----a-w c:\windows\system32\spxcoins.dll
2009-04-14 19:15 . 2006-03-02 12:00 13312 -c--a-w c:\windows\system32\dllcache\irclass.dll
2009-04-14 19:15 . 2006-03-02 12:00 13312 ----a-w c:\windows\system32\irclass.dll
2009-04-14 17:33 . 2009-04-14 17:38 4524 ----a-w c:\windows\setupapi.old
2009-04-14 06:13 . 2009-04-14 11:09 2652 ----a-w C:\rollback.ini
2009-04-14 06:05 . 2009-04-14 13:27 6584 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-14 06:05 . 2009-04-14 13:27 333344 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-14 06:05 . 2009-04-14 13:27 2900 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-14 06:05 . 2009-04-14 13:27 20000 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-14 05:57 . 2009-04-14 11:27 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\ParetoLogic
2009-04-14 05:57 . 2009-04-14 11:27 -------- d-----w c:\programmi\File comuni\ParetoLogic
2009-04-14 05:57 . 2009-04-14 05:57 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\ParetoLogic Anti-Virus PLUS
2009-04-14 05:56 . 2009-04-14 05:56 -------- dc----w c:\documents and settings\antonio_old\Impostazioni locali\Dati applicazioni\Downloaded Installations
2009-04-13 22:20 . 2009-04-13 22:20 -------- d-----w c:\windows\system32\KB905474
2009-04-13 22:20 . 2009-03-10 20:26 1437568 ----a-w c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-04-13 22:20 . 2009-03-10 20:18 454016 ----a-w c:\windows\system32\KB905474\wgasetup.exe
2009-04-13 22:20 . 2009-02-09 16:51 17140 ----a-w c:\windows\system32\KB905474\wga_eula.txt
2009-04-13 16:51 . 2009-04-13 16:51 -------- d-----w c:\programmi\SDHelper (Spybot - Search & Destroy)
2009-04-13 16:51 . 2009-04-13 16:51 -------- d-----w c:\programmi\Misc. Support Library (Spybot - Search & Destroy)
2009-04-13 16:51 . 2009-04-13 16:58 -------- d-----w c:\programmi\TeaTimer (Spybot - Search & Destroy)
2009-04-13 16:51 . 2009-04-13 16:51 -------- d-----w c:\programmi\File Scanner Library (Spybot - Search & Destroy)
2009-04-13 14:53 . 2009-04-13 14:53 44 ----a-w c:\windows\system32\76.tmp
2009-04-13 08:27 . 2009-04-13 08:27 44 ----a-w c:\windows\system32\72.tmp
2009-04-12 14:34 . 2009-04-12 14:34 -------- dc----w c:\documents and settings\antonio_old\Dati applicazioni\IObit
2009-04-12 14:34 . 2009-04-12 14:34 -------- d-----w c:\programmi\IObit
2009-04-12 13:20 . 2009-04-12 13:20 67 ----a-w c:\windows\wininit.ini
2009-04-11 22:56 . 2009-04-11 22:56 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\AcrobatInstall
2009-04-11 21:08 . 2009-04-11 21:08 0 ----a-w c:\windows\system32\3C.tmp
2009-04-11 21:08 . 2009-04-11 21:08 44 ----a-w c:\windows\system32\3A.tmp
2009-04-11 20:14 . 2009-04-10 13:00 21704 ----a-w c:\windows\system32\kk.exe
2009-04-11 19:51 . 2009-04-11 19:51 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\FLEXnet
2009-04-11 19:51 . 2009-04-11 19:51 -------- d-----w c:\programmi\File comuni\Macrovision Shared
2009-03-30 10:42 . 2009-03-30 10:42 -------- dc----w c:\documents and settings\vale.FISSO\Impostazioni locali\Dati applicazioni\Apple
2009-03-25 21:17 . 2009-03-25 21:17 -------- dc----w c:\documents and settings\antonio_old\Dati applicazioni\AVS4YOU
2009-03-25 21:17 . 2009-03-25 21:17 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\AVS4YOU
2009-03-25 21:15 . 2009-03-25 21:42 -------- d-----w c:\programmi\File comuni\AVSMedia
2009-03-25 21:15 . 2009-03-25 21:42 -------- d-----w c:\programmi\AVS4YOU
2009-03-25 21:15 . 2007-03-01 10:08 974848 ----a-w c:\windows\system32\mfc70.dll
2009-03-25 21:15 . 2007-03-01 10:08 487424 ----a-w c:\windows\system32\msvcp70.dll
2009-03-25 21:15 . 2007-03-01 10:08 344064 ----a-w c:\windows\system32\msvcr70.dll
2009-03-25 21:15 . 2007-03-01 10:08 24576 ----a-w c:\windows\system32\msxml3a.dll
2009-03-25 19:02 . 2009-03-25 19:02 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Ahead
2009-03-25 18:57 . 2009-03-25 18:57 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Nero
2009-03-20 19:11 . 2009-03-20 19:12 -------- d-----w c:\programmi\Microsoft LifeCam
2009-03-20 18:02 . 2009-03-31 14:07 115224 ----a-w C:\img2-001.raw
2009-03-20 18:00 . 2004-08-03 22:07 59264 ----a-w c:\windows\system32\drivers\USBAUDIO.sys
2009-03-20 17:55 . 2007-04-10 21:46 116072 ----a-w c:\windows\VX3000.dll
2009-03-20 17:55 . 2007-04-10 21:46 709992 ----a-w c:\windows\vVX3000.exe
2009-03-20 17:55 . 2007-04-10 21:46 476520 ----a-w c:\windows\vVX3000.dll
2009-03-20 17:55 . 2007-04-10 21:46 1966696 ----a-w c:\windows\system32\drivers\VX3000.sys
2009-03-20 17:55 . 2007-04-10 21:46 15498 ----a-w c:\windows\VX3000.ini
2009-03-20 17:55 . 2007-04-10 21:46 13023 ----a-w c:\windows\VX3000.src
2009-03-20 17:55 . 2007-04-10 21:46 202088 ----a-w c:\windows\system32\LCCoin14.dll
2009-03-20 17:55 . 2007-04-10 21:46 185704 ----a-w c:\windows\system32\cVX3000.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 12:34 . 2009-04-15 12:34 614 ----a-w c:\programmi\amkht.txt
2009-04-15 10:43 . 2009-02-03 22:44 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\avg8
2009-04-14 20:27 . 2006-03-02 12:00 68240 ----a-w c:\windows\system32\perfc010.dat
2009-04-14 20:27 . 2006-03-02 12:00 401654 ----a-w c:\windows\system32\perfh010.dat
2009-04-14 20:02 . 2008-08-01 21:39 25728 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-14 05:05 . 2008-08-15 09:57 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Spybot - Search & Destroy
2009-04-14 05:05 . 2006-09-18 07:02 -------- d-----w c:\programmi\Spybot - Search & Destroy
2009-04-13 22:13 . 2008-11-24 11:10 -------- dc--a-w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2009-04-13 15:26 . 2003-11-12 10:18 1891296 ----a-w C:\hpfr5600.log
2009-04-12 20:28 . 2008-08-02 04:19 2608 ----a-w c:\windows\system32\d3d9caps.dat
2009-04-12 13:31 . 2008-08-02 04:06 -------- dc----w c:\documents and settings\antonio_old\Dati applicazioni\Skype
2009-04-12 06:22 . 2008-08-02 04:06 -------- dc----w c:\documents and settings\antonio_old\Dati applicazioni\skypePM
2009-04-12 06:10 . 2008-08-02 04:13 64728 -c--a-w c:\documents and settings\antonio_old\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-12 05:41 . 2007-12-24 17:06 -------- d-----w c:\programmi\Trust
2009-04-11 22:02 . 2004-12-04 15:45 -------- d-----w c:\programmi\eMule
2009-04-11 20:51 . 2008-08-16 09:43 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-04-11 19:35 . 2000-11-19 15:49 -------- d-----w c:\programmi\File comuni\Adobe
2009-04-11 06:09 . 2005-03-03 07:18 -------- d-----w c:\programmi\Mozilla Thunderbird
2009-04-06 13:32 . 2008-08-16 09:43 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2008-08-16 09:43 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-27 06:36 . 2005-08-27 06:46 -------- d-----w c:\programmi\Java
2009-03-26 01:44 . 2008-08-02 04:12 -------- dc----w c:\documents and settings\antonio_old\Dati applicazioni\Ahead
2009-03-25 19:01 . 2004-10-14 08:57 -------- d-----w c:\programmi\File comuni\Ahead
2009-03-23 13:54 . 2008-10-14 19:26 -------- dc----w c:\documents and settings\antonio_old\Dati applicazioni\dvdcss
2009-03-20 18:32 . 2008-11-28 16:34 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Skype
2009-03-20 18:32 . 2005-09-09 22:16 -------- d-----r c:\programmi\Skype
2009-03-20 18:32 . 2008-06-16 10:56 -------- d-----w c:\programmi\File comuni\Skype
2009-03-15 21:29 . 2009-03-15 20:46 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\PPLiveVA
2009-03-15 20:49 . 2009-03-15 20:49 -------- dc----w c:\documents and settings\antonio_old\Dati applicazioni\PPLiveVA
2009-03-15 20:19 . 2009-03-15 20:19 -------- dc----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\TVU Networks
2009-03-09 04:19 . 2008-12-08 11:43 410984 ----a-w c:\windows\system32\deploytk.dll
2009-01-12 14:02 . 2009-01-12 14:02 2608 -c--a-w c:\documents and settings\vale.FISSO\Impostazioni locali\Dati applicazioni\d3d9caps.tmp
2008-09-24 13:40 . 2008-09-24 13:40 64272 -c--a-w c:\documents and settings\vale.FISSO\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-07-26 20:44 . 2004-01-24 19:11 426096 -c--a-w c:\documents and settings\Gianni.FISSO\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-07-26 19:56 . 2004-01-08 07:15 426096 -c--a-w c:\documents and settings\Antonio\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-01-17 19:39 . 2008-08-02 04:13 136 -c--a-w c:\documents and settings\antonio_old\Impostazioni locali\Dati applicazioni\fusioncache.dat
2008-01-17 19:39 . 2008-01-17 19:39 136 -c--a-w c:\documents and settings\Antonio\Impostazioni locali\Dati applicazioni\fusioncache.dat
2006-08-19 08:30 . 2008-08-02 04:17 24192 -c--a-w c:\documents and settings\antonio_old\usbsermptxp.sys
2006-08-19 08:30 . 2008-08-02 04:17 22768 -c--a-w c:\documents and settings\antonio_old\usbsermpt.sys
2006-08-19 08:30 . 2006-08-19 08:27 24192 -c--a-w c:\documents and settings\Antonio\usbsermptxp.sys
2006-08-19 08:30 . 2006-08-19 08:27 22768 -c--a-w c:\documents and settings\Antonio\usbsermpt.sys
.
------- Sigcheck -------
[-] 2006-03-02 12:00 1053696 693752B58368B62EB7D54EEB76546B56 c:\windows\explorer.exe
[-] 2007-06-13 13:10 1054720 2EE5EFA6DBD9EF94D464555CF50F3652 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2008-04-14 02:14 1055232 0C5AE1639EB39141615284598AE40F36 c:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\explorer.exe
[-] 2006-03-02 12:00 1034752 2A0D0B4F3B902E3A8E9EA11675BF33E9 c:\windows\system32\dllcache\explorer.exe
[-] 2008-04-14 02:14 34304 AF85D22B99FBC029767C0054F99E4A1A c:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ctfmon.exe
[-] 2006-03-02 12:00 34304 445080EFFE4E29375C1C87D5104DB82C c:\windows\system32\ctfmon.exe
[-] 2006-03-02 12:00 15360 9487B77AFED5EC40202502C55C806A33 c:\windows\system32\dllcache\ctfmon.exe
[-] 2005-06-11 00:17 76800 B5A08E64DD59303D75C52FF57605A304 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2008-04-14 02:14 76800 333EA292FC212ED21CDFF90C682D69CF c:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spoolsv.exe
[-] 2006-03-02 12:00 76800 79FEF2C09270B8DB5727E5CE46A1B6BF c:\windows\system32\spoolsv.exe
[-] 2006-03-02 12:00 57856 C3D2BBF2E5C9F7251FCBD4CAFF7C3199 c:\windows\system32\dllcache\spoolsv.exe
[-] 2008-04-14 02:14 130560 B7A0A27627B981DD7F7BE9D224E9E61B c:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wuauclt.exe
[7] 2008-10-16 12:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows\SoftwareDistribution\SelfUpdate\wuauclt.exe
[-] 2006-03-02 12:00 130560 396BE4368918325979ADEF4DF6825EDC c:\windows\system32\wuauclt.exe
[-] 2006-03-02 12:00 111616 508D6DCA41752B4B3F2E195C54674BD2 c:\windows\system32\dllcache\wuauclt.exe
[-] 2008-04-14 02:14 45568 91FAAF871992780744F3A086998970BC c:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\userinit.exe
[-] 2006-03-02 12:00 44032 77CEF5853980AB6784C7BED665898AC3 c:\windows\system32\userinit.exe
[-] 2006-03-02 12:00 44032 5BE451A99C91A3426478ED694499EF20 c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-03-02 34304]
"Advanced SystemCare 3"="c:\programmi\IObit\Advanced SystemCare 3\AWC.exe" [2009-02-22 2272592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-26 192512]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2008-08-02 176128]
"Matrox Powerdesk"="c:\windows\system32\PDesk\PDesk.exe" [2002-02-14 671744]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-05-27 434176]
"zBrowser Launcher"="c:\progra~1\Logitech\iTouch\iTouch.exe" [2002-11-23 650306]
"EM_EXEC"="c:\progra~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2001-12-20 54272]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"LifeCam"="c:\programmi\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Acrobat Assistant 8.0"="c:\programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"HP Software Update"="c:\programmi\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2002-12-17 69632]
"DeviceDiscovery"="c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2002-12-02 61440]
"Adobe Version Cue CS2"="c:\programmi\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-06 876544]
"Acrobat Assistant 7.0"="c:\programmi\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 503808]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-15 1932568]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 34304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-19 63488]
c:\documents and settings\antonio_old\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2003-1-6 131072]
c:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2003-1-6 131072]
Adobe Reader Synchronizer.lnk - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
Avvio veloce di Adobe Acrobat.lnk - c:\windows\Installer\{AC76BA86-1040-7D00-7760-000000000003}\_SC_Acrobat.exe [2009-4-11 295606]
BTTray.lnk - c:\programmi\WIDCOMM\Bluetooth Software\BTTray.exe [2006-4-12 663613]
Monitor Apache Servers.lnk - c:\programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe [2008-6-13 61521]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-15 10:43 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Programmi\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"c:\\Programmi\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Programmi\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\File comuni\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:eMule: TCP in ingresso
"4672:UDP"= 4672:UDP:eMule: UPD in ingresso
R1 kfa5516;kfa5516; [x]
R1 lkbdhlpr;Logitech Keyboard Class Helper Driver; [x]
R1 toj186b;toj186b; [x]
R3 PAC207;Trust WB-1400T Webcam; [x]
S0 viasraid;viasraid;c:\windows\system32\DRIVERS\viasraid.sys [2003-06-12 75904]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-15 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-15 108552]
S2 Apache2.2;Apache2.2;c:\programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe [2008-06-13 45115]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-15 298264]
S3 Stmatm;ATM/ADSL miniport;c:\windows\system32\DRIVERS\stmatm.sys [2002-09-25 59338]
S3 TaurusUsb;ADSL Modem USB Service 1.09a;c:\windows\system32\DRIVERS\torususb.sys [2003-01-09 527980]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - AVG8WD
*NewlyCreated* - AVGLDX86
*NewlyCreated* - AVGMFX86
*NewlyCreated* - BITS
*NewlyCreated* - MSISERVER
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa30c494-e6f1-11dd-99fb-00e098b9901e}]
\Shell\AutoRun\command - .\run\autorun.exe
\Shell\open\Command - .\run\autorun.exe
.
Contenuto della cartella 'Scheduled Tasks'
2009-03-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
2009-04-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-606747145-839522115-1004.job
- c:\documents and settings\antonio_old\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2008-09-02 21:26]
2009-04-14 c:\windows\Tasks\Microsoft_Hardware_Launch_vVX3000_exe.job
- c:\windows\vVX3000.exe [2009-03-20 21:46]
2009-04-15 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-13 20:18]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: Aggiungi a PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti nel file PDF esistente - c:\programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {6D8F4672-3AE9-4938-B3DB-19C264F1758D} = 151.99.125.1,151.99.250.2
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-15 14:47
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL]
"ImagePath"="\"c:\programmi\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\programmi\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
Ora fine scansione: 2009-04-15 14:51
ComboFix-quarantined-files.txt 2009-04-15 12:50
ComboFix2.txt 2009-04-14 05:30
Pre-Run: 19.167.910.912 byte disponibili
Post-Run: 19.158.362.624 byte disponibili
287 --- E O F --- 2009-04-13 22:20