Ecco il LOG di Combofix
ComboFix 09-04-23.A3 - Tascapane 23/04/2009 22.10.38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1407.900 [GMT 2:00]
Eseguito da: c:\documents and settings\Tascapane\Desktop\ComboFix.exe
AV: Sistema Antivirus NOD32 2.70 *On-access scanning enabled* (Updated)
FW: ActiveArmor Firewall *disabled*
FW: Outpost Firewall Pro *disabled*
* Creato nuovo punto di ripristino
* Resident AV is active
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Tascapane\Impostazioni locali\Dati applicazioni\wwwiuwq.dat
c:\documents and settings\Tascapane\Impostazioni locali\Dati applicazioni\wwwiuwq.exe
c:\documents and settings\Tascapane\Impostazioni locali\Dati applicazioni\wwwiuwq_nav.dat
c:\documents and settings\Tascapane\Impostazioni locali\Dati applicazioni\wwwiuwq_navps.dat
c:\windows\system32\javan.exe
.
((((((((((((((((((((((((( Files Creati Da 2009-05-23 al 2009-4-23 )))))))))))))))))))))))))))))))))))
.
2009-04-23 12:53 . 2009-04-23 12:53 -------- d-----w c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
2009-04-22 19:52 . 2009-04-22 19:52 -------- d-----w c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Google
2009-04-22 19:52 . 2009-04-22 19:52 -------- d-----w c:\documents and settings\Tascapane\Impostazioni locali\Dati applicazioni\Google
2009-04-22 19:44 . 2009-04-22 19:52 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-04-21 10:04 . 2009-04-22 17:30 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\dvdcss
2009-04-20 17:30 . 2009-04-20 17:30 0 ----a-w c:\windows\nsreg.dat
2009-04-20 17:30 . 2009-04-20 17:30 -------- d-----w c:\documents and settings\Tascapane\Impostazioni locali\Dati applicazioni\Mozilla
2009-04-20 17:15 . 2009-04-20 17:15 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\Sonic
2009-04-20 16:58 . 2009-04-20 16:58 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\Ahead
2009-04-20 02:18 . 2009-04-20 02:19 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\vlc
2009-04-20 01:50 . 2009-04-22 19:36 116 ----a-w c:\windows\NeroDigital.ini
2009-04-20 01:33 . 2008-04-13 18:45 15104 -c--a-w c:\windows\system32\dllcache\usbscan.sys
2009-04-20 01:33 . 2008-04-13 18:45 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-04-20 01:33 . 2000-03-24 16:18 13824 ----a-r c:\windows\system32\FB63UCPL.DLL
2009-04-20 01:33 . 2000-03-24 16:10 271872 ----a-r c:\windows\system32\UCS32P.DLL
2009-04-20 01:33 . 2000-03-24 16:08 98816 ----a-r c:\windows\system32\FB63UUSD.dll
2009-04-20 01:33 . 2000-03-24 16:08 155648 ----a-r c:\windows\system32\MG600.DLL
2009-04-20 01:31 . 2003-01-10 19:52 13997 ----a-w c:\windows\system32\ssgb7mon.dll
2009-04-20 01:31 . 2003-11-17 18:24 208896 ------w c:\windows\system32\SSRemove.exe
2009-04-20 01:31 . 2003-07-21 18:50 8478 ------w c:\windows\system32\SP119.ICO
2009-04-20 01:31 . 2004-05-17 20:04 41984 ------w c:\windows\system32\drivers\DGIVECP.SYS
2009-04-20 01:31 . 2009-04-20 01:31 -------- d-----w c:\windows\Samsung
2009-04-20 01:29 . 2008-04-13 18:47 25856 -c--a-w c:\windows\system32\dllcache\usbprint.sys
2009-04-20 01:29 . 2008-04-13 18:47 25856 ----a-w c:\windows\system32\drivers\usbprint.sys
2009-04-20 01:20 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-20 01:20 . 2009-03-06 14:19 286208 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-20 01:20 . 2009-02-09 11:22 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-20 01:20 . 2009-02-09 10:51 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-20 01:20 . 2009-02-09 10:51 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-20 01:20 . 2009-02-09 10:51 683520 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-20 01:20 . 2009-02-09 10:51 734720 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-20 01:20 . 2009-02-09 10:51 736256 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-20 01:20 . 2009-02-09 10:51 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-20 01:19 . 2009-03-27 06:48 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-20 01:19 . 2008-04-21 21:14 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-12 08:00 . 2004-08-20 09:41 86092 ----a-w c:\windows\system32\ImageDrive.cpl
2009-04-12 07:53 . 2004-09-08 19:00 52447 ------w c:\windows\UNNMP.cfg
2009-04-12 07:53 . 2004-09-02 12:43 2142208 ------w c:\windows\UNNMP.exe
2009-04-12 07:52 . 2004-03-02 15:37 125184 ------w c:\windows\system32\drivers\imagesrv.sys
2009-04-12 07:52 . 2004-03-02 15:37 5504 ------w c:\windows\system32\drivers\imagedrv.sys
2009-04-12 07:51 . 2001-07-09 09:50 155648 ----a-w c:\windows\system32\NeroCheck.exe
2009-04-12 07:49 . 2004-09-08 19:00 147046 ------w c:\windows\UNNeroVision.cfg
2009-04-12 07:49 . 2004-09-08 18:33 2142208 ------w c:\windows\UNNeroVision.exe
2009-04-12 07:49 . 2001-03-08 17:30 24064 ------w c:\windows\system32\msxml3a.dll
2009-04-12 07:48 . 2009-04-12 07:48 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Ahead
2009-04-12 07:48 . 2004-07-26 15:16 471040 ------w c:\windows\system32\ImagXRA7.dll
2009-04-12 07:48 . 2004-07-09 07:43 364544 ------w c:\windows\system32\TwnLib4.dll
2009-04-12 07:48 . 2004-07-26 15:16 476320 ------w c:\windows\system32\ImagXpr7.dll
2009-04-12 07:48 . 2004-07-26 15:16 262144 ------w c:\windows\system32\ImagXR7.dll
2009-04-12 07:48 . 2004-07-26 15:16 1568768 ------w c:\windows\system32\ImagX7.dll
2009-04-12 07:48 . 2001-06-26 06:15 38912 ------w c:\windows\system32\picn20.dll
2009-04-12 07:48 . 2000-06-26 09:45 106496 ----a-w c:\windows\system32\TwnLib20.dll
2009-04-12 07:40 . 2003-06-18 23:31 17920 ----a-w c:\windows\system32\mdimon.dll
2009-04-12 07:36 . 2009-04-12 07:38 -------- d-----w c:\windows\SHELLNEW
2009-04-11 19:46 . 2009-04-11 19:46 -------- d-----w c:\documents and settings\Tascapane\Impostazioni locali\Dati applicazioni\Identities
2009-04-11 19:44 . 2009-04-11 19:44 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\Yahoo!
2009-04-11 19:40 . 2009-04-11 19:40 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-11 19:40 . 2009-04-11 19:40 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-11 19:36 . 2009-04-11 19:38 28276 ----a-w c:\windows\system32\drivers\MxlW2k.sys
2009-04-11 19:31 . 2009-04-20 02:23 775 ----a-w c:\windows\CLARIS.INI
2009-04-11 19:31 . 2009-04-20 02:22 -------- d-----w c:\windows\CLARIS
2009-04-11 19:31 . 2009-04-11 19:31 -------- d-----w C:\FMPRO
2009-04-11 19:30 . 2005-10-15 10:32 196608 ----a-w c:\windows\system32\pdfcmnnt.dll
2009-04-11 19:30 . 2005-04-15 17:58 1071088 ----a-w c:\windows\system32\MSCOMCTL.OCX
2009-04-11 19:30 . 2004-03-08 22:00 662288 ----a-w c:\windows\system32\MSCOMCT2.OCX
2009-04-11 19:30 . 1998-06-23 22:00 137000 ----a-w c:\windows\system32\MSMAPI32.OCX
2009-04-11 19:30 . 1998-08-05 05:45 122128 ----a-w c:\windows\system32\VB6IT.DLL
2009-04-11 19:30 . 1998-08-05 05:45 150528 ----a-w c:\windows\system32\MSCMCIT.DLL
2009-04-11 19:30 . 1998-08-05 05:45 63488 ----a-w c:\windows\system32\MSCC2IT.DLL
2009-04-11 19:30 . 1998-07-05 22:00 23552 ----a-w c:\windows\system32\MSMPIDE.DLL
2009-04-11 19:18 . 2009-04-23 20:08 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\uTorrent
2009-04-11 19:16 . 2008-06-14 17:32 272768 -c----w c:\windows\system32\dllcache\bthport.sys
2009-04-11 19:16 . 2009-02-20 08:09 668672 -c----w c:\windows\system32\dllcache\wininet.dll
2009-04-11 19:16 . 2009-03-02 23:10 1499648 -c----w c:\windows\system32\dllcache\shdocvw.dll
2009-04-11 19:16 . 2009-02-20 08:09 619520 -c----w c:\windows\system32\dllcache\urlmon.dll
2009-04-11 19:15 . 2009-02-09 11:22 2148864 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-11 19:15 . 2009-02-10 17:02 2069760 -c----w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-11 19:15 . 2009-02-09 11:23 2027520 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-11 19:15 . 2009-02-09 11:23 2192768 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-11 19:14 . 2009-02-20 08:09 3089408 -c----w c:\windows\system32\dllcache\mshtml.dll
2009-04-11 19:14 . 2008-05-08 14:02 203136 -c----w c:\windows\system32\dllcache\rmcast.sys
2009-04-11 19:14 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-11 19:14 . 2008-12-11 10:57 333952 -c----w c:\windows\system32\dllcache\srv.sys
2009-04-11 19:14 . 2008-05-01 14:34 331776 -c----w c:\windows\system32\dllcache\msadce.dll
2009-04-11 19:14 . 2008-04-11 19:04 691712 -c----w c:\windows\system32\dllcache\inetcomm.dll
2009-04-11 19:13 . 2008-10-15 16:36 337408 -c----w c:\windows\system32\dllcache\netapi32.dll
2009-04-11 19:13 . 2008-09-04 17:15 1106944 -c----w c:\windows\system32\dllcache\msxml3.dll
2009-04-11 18:15 . 2009-04-11 18:15 -------- d-----w c:\windows\system32\it-it
2009-04-11 18:15 . 2009-04-11 18:15 -------- d-----w c:\windows\l2schemas
2009-04-11 18:15 . 2009-04-11 18:15 -------- d-----w c:\windows\system32\it
2009-04-11 18:15 . 2009-04-11 18:15 -------- d-----w c:\windows\system32\bits
2009-04-11 18:13 . 2009-04-11 18:13 -------- d-----w c:\windows\ServicePackFiles
2009-04-11 17:14 . 2004-08-19 13:23 701440 ------w c:\windows\system32\drivers\ati2mtag.sys
2009-04-11 17:08 . 2009-04-20 20:01 -------- d--h--w c:\windows\$hf_mig$
2009-04-11 17:06 . 2001-08-17 21:59 3072 ----a-w c:\windows\system32\drivers\audstub.sys
2009-04-11 17:06 . 2008-04-14 01:49 58368 ----a-w c:\windows\system32\drivers\redbook.sys
2009-04-11 17:05 . 2008-04-13 18:45 10624 ----a-w c:\windows\system32\drivers\gameenum.sys
2009-04-11 17:05 . 2008-10-16 12:09 43544 ----a-w c:\windows\system32\wups2.dll
2009-04-11 17:05 . 2008-10-16 12:12 35864 ----a-w c:\windows\system32\wucltui.dll.mui
2009-04-11 17:05 . 2008-10-16 12:08 27672 ----a-w c:\windows\system32\wuapi.dll.mui
2009-04-11 17:05 . 2008-10-16 12:08 27672 ----a-w c:\windows\system32\wuaucpl.cpl.mui
2009-04-11 17:05 . 2008-10-16 12:07 19480 ----a-w c:\windows\system32\wuaueng.dll.mui
2009-04-11 17:04 . 2008-04-14 02:13 76800 ----a-w c:\windows\system32\usbui.dll
2009-04-11 17:04 . 2009-04-11 17:04 -------- d-s---w c:\documents and settings\Tascapane\UserData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 19:52 . 2009-04-22 19:32 -------- d-----w c:\programmi\Google
2009-04-22 13:20 . 2009-04-11 16:31 -------- d-----w c:\programmi\ESET
2009-04-20 20:53 . 2002-10-30 02:45 47592 ----a-w c:\windows\system32\perfc010.dat
2009-04-20 20:53 . 2002-10-30 02:45 345010 ----a-w c:\windows\system32\perfh010.dat
2009-04-20 01:57 . 2009-04-20 01:57 -------- d-----w c:\programmi\VideoLAN
2009-04-20 01:57 . 2009-04-20 01:57 -------- d-----w c:\programmi\File comuni\Sonic Shared
2009-04-20 01:57 . 2009-04-20 01:57 -------- d-----w c:\programmi\Sonic
2009-04-12 08:06 . 2009-04-11 15:49 42552 ----a-w c:\documents and settings\Tascapane\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-12 08:03 . 2009-04-12 08:03 -------- d-----w c:\programmi\File comuni\Kapitol
2009-04-12 08:03 . 2009-04-12 08:03 -------- d-----w c:\programmi\Finson Live Update
2009-04-12 08:03 . 2009-04-12 08:03 -------- d-----w c:\programmi\Finson
2009-04-12 07:53 . 2009-04-12 07:48 -------- d-----w c:\programmi\Ahead
2009-04-12 07:50 . 2009-04-12 07:48 -------- d-----w c:\programmi\File comuni\Ahead
2009-04-12 07:38 . 2009-04-12 07:38 -------- d-----w c:\programmi\Microsoft.NET
2009-04-11 20:51 . 2009-04-11 19:44 -------- d-----w c:\programmi\Yahoo!
2009-04-11 19:46 . 2009-04-11 19:45 -------- d-----w c:\programmi\RegCleaner
2009-04-11 19:44 . 2009-04-11 19:44 -------- d-----w c:\programmi\CCleaner
2009-04-11 19:41 . 2009-04-11 19:41 -------- d-----w c:\programmi\File comuni\xing shared
2009-04-11 19:41 . 2009-04-11 19:40 -------- d-----w c:\programmi\File comuni\Real
2009-04-11 19:40 . 2009-04-11 19:40 -------- d-----w c:\programmi\Real
2009-04-11 19:36 . 2009-04-11 19:36 -------- d-----w c:\programmi\MUSICMATCH
2009-04-11 19:36 . 2009-04-11 15:42 -------- d--h--w c:\programmi\InstallShield Installation Information
2009-04-11 19:35 . 2009-04-11 15:42 -------- d-----w c:\programmi\File comuni\InstallShield
2009-04-11 19:31 . 2009-04-11 19:30 -------- d-----w c:\programmi\PDFCreator
2009-04-11 19:26 . 2009-04-11 19:26 -------- d-----w c:\programmi\uTorrent
2009-04-11 19:13 . 2009-04-11 19:12 -------- d-----w c:\programmi\eMule
2009-04-11 18:17 . 2009-04-11 15:19 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-11 18:11 . 2004-08-03 20:59 251600 --sha-r C:\ntldr
2009-04-11 16:58 . 2009-04-11 16:25 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-04-11 16:51 . 2009-04-11 16:51 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2009-04-11 16:39 . 2009-04-11 16:39 -------- d-----w c:\programmi\Foxit Software
2009-04-11 16:39 . 2009-04-11 16:39 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\Foxit
2009-04-11 16:35 . 2009-04-11 16:35 -------- d-----w c:\programmi\File comuni\Agnitum Shared
2009-04-11 16:35 . 2009-04-11 16:35 -------- d-----w c:\programmi\Agnitum
2009-04-11 16:31 . 2009-04-11 16:32 298104 ----a-w c:\windows\system32\imon.dll
2009-04-11 16:31 . 2009-04-11 16:32 512096 ----a-w c:\windows\system32\drivers\amon.sys
2009-04-11 16:31 . 2009-04-11 16:32 15424 ----a-w c:\windows\system32\drivers\nod32drv.sys
2009-04-11 16:25 . 2009-04-11 16:25 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\Malwarebytes
2009-04-11 16:25 . 2009-04-11 16:25 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-04-11 15:58 . 2009-04-11 15:58 -------- d-----w c:\documents and settings\Tascapane\Dati applicazioni\Acronis
2009-04-11 15:57 . 2009-04-11 15:57 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Acronis
2009-04-11 15:56 . 2009-04-11 15:56 45984 ----a-w c:\windows\system32\ins2.exe
2009-04-11 15:51 . 2009-04-11 15:51 971584 ----a-w c:\windows\system32\drivers\tdrpm147.sys
2009-04-11 15:51 . 2009-04-11 15:51 540000 ----a-w c:\windows\system32\drivers\timntr.sys
2009-04-11 15:51 . 2009-04-11 15:51 44704 ----a-w c:\windows\system32\drivers\tifsfilt.sys
2009-04-11 15:51 . 2009-04-11 15:51 134272 ----a-w c:\windows\system32\drivers\snman380.sys
2009-04-11 15:51 . 2009-04-11 15:51 -------- d-----w c:\programmi\File comuni\Acronis
2009-04-11 15:51 . 2009-04-11 15:51 -------- d-----w c:\programmi\Acronis
2009-04-11 15:47 . 2009-04-11 15:47 1024 ----a-w C:\.rnd
2009-04-11 15:46 . 2009-04-11 15:46 -------- d-----w c:\programmi\NVIDIA Corporation
2009-04-11 15:42 . 2009-04-11 15:42 -------- d-----w c:\programmi\Realtek
2009-04-11 15:22 . 2009-04-11 15:22 -------- d-----w c:\programmi\microsoft frontpage
2009-04-11 15:18 . 2009-04-11 15:18 -------- d-----w c:\programmi\Servizi in linea
2009-04-11 15:16 . 2009-04-11 15:16 21840 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-06 13:32 . 2009-04-11 16:25 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2009-04-11 16:25 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-06 14:19 . 2004-08-19 13:39 286208 ----a-w c:\windows\system32\pdh.dll
2009-02-20 08:09 . 2004-08-19 13:39 668672 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:09 . 2004-08-19 13:39 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-10 17:02 . 2004-08-19 15:34 2069760 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 14:04 . 2004-08-19 13:31 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:23 . 2004-08-19 13:34 2192768 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:22 . 2004-08-19 13:39 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 2004-08-19 13:39 734720 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2004-08-19 13:39 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 2004-08-19 13:39 683520 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 2004-08-19 13:38 736256 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 2002-10-30 02:45 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:57 . 2004-08-19 13:39 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"TrueImageMonitor.exe"="c:\programmi\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-11-21 4371440]
"AcronisTimounterMonitor"="c:\programmi\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-11-21 961208]
"Acronis Scheduler2 Service"="c:\programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2008-11-21 165144]
"nod32kui"="c:\programmi\Eset\nod32kui.exe" [2009-04-11 949376]
"Outpost Firewall"="c:\programmi\Agnitum\Outpost Firewall\outpost.exe" [2007-04-05 94720]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2007-06-28 335872]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2009-04-11 198160]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-08-01 16049664]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-31 1622016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Google Updater.lnk - c:\programmi\Google\Google Updater\GoogleUpdater.exe [2009-4-22 124912]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
R2 gupdate1c9c383d9272c48;Servizio di Google Update (gupdate1c9c383d9272c48);c:\programmi\Google\Update\GoogleUpdate.exe [2009-04-22 133104]
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL [2007-04-05 33568]
R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\ARP.DLL [2007-04-05 17632]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\CONTENT.DLL [2007-04-05 4896]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL [2007-04-05 14656]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL [2007-04-05 9248]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL [2007-04-05 11552]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL [2007-04-05 13216]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL [2007-04-05 7168]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL [2007-04-05 14880]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL [2007-04-05 6752]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL [2007-04-05 10048]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\PROTECT.DLL [2007-04-05 15200]
R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);c:\programmi\Agnitum\Outpost Firewall\kernel\SECRET.DLL [2007-04-05 13056]
S0 snapman380;Acronis Snapshots Manager (Build 380);c:\windows\system32\DRIVERS\snman380.sys [2009-04-11 134272]
S0 tdrpman147;Acronis Try&Decide and Restore Points filter (build 147);c:\windows\system32\DRIVERS\tdrpm147.sys [2009-04-11 971584]
S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-04-11 15424]
S1 SandBox;Outpost Firewall Sandbox Driver;c:\programmi\Agnitum\Outpost Firewall\kernel\Sandbox.SYS [2007-06-26 408352]
S1 VFILT;Outpost Firewall Kernel Driver;c:\programmi\Agnitum\Outpost Firewall\kernel\FILTNT.SYS [2007-04-05 163840]
.
Contenuto della cartella 'Scheduled Tasks'
2009-04-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-04-22 19:52]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-wwwiuwq - c:\documents and settings\tascapane\impostazioni locali\dati applicazioni\wwwiuwq.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
TCP: {5FC698AD-972E-434D-AD94-E8526C8D5F62} = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Tascapane\Dati applicazioni\Mozilla\Firefox\Profiles\nv2qgmx7.default\
FF - prefs.js: browser.startup.homepage -
www.google.itFF - component: c:\programmi\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\programmi\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-23 22:13
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1052)
c:\programmi\Agnitum\Outpost Firewall\wl_hook.dll
- - - - - - - > 'lsass.exe'(1108)
c:\windows\system32\imon.dll
c:\programmi\Eset\pr_imon.dll
.
Ora fine scansione: 2009-04-23 22.15.10
ComboFix-quarantined-files.txt 2009-04-23 20:15
Pre-Run: 43.488.935.936 byte disponibili
Post-Run: 43.528.368.128 byte disponibili
289 --- E O F --- 2009-04-22 17:31