ecco il log di combofix
ComboFix 10-01-13.0B - Luca 14/01/2010 16.02.44.1.2 - x86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.39.1040.18.2047.1270 [GMT 1:00]
Eseguito da: m:\documents\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Cheat Engine\dbk32.sys
c:\users\Luca\AppData\Local\gcimckw.dat
c:\users\Luca\AppData\Local\gcimckw_nav.dat
c:\users\Luca\AppData\Local\gcimckw_navps.dat
c:\windows\system32\reboot.txt
.
((((((((((((((((((((((((( Files Creati Da 2009-12-14 al 2010-01-14 )))))))))))))))))))))))))))))))))))
.
2010-01-14 15:13 . 2010-01-14 15:14 -------- d-----w- c:\users\Luca\AppData\Local\temp
2010-01-14 15:13 . 2010-01-14 15:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-14 11:58 . 2010-01-14 11:58 -------- d-----w- c:\users\Luca\AppData\Roaming\Malwarebytes
2010-01-14 11:58 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-14 11:58 . 2010-01-14 11:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-14 11:58 . 2010-01-14 11:58 -------- d-----w- c:\programdata\Malwarebytes
2010-01-14 11:58 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-14 11:24 . 2010-01-14 11:24 -------- d-----w- c:\program files\Trend Micro
2010-01-13 23:27 . 2010-01-14 00:06 -------- d-----w- c:\windows\35C03C043F1F42C2A989A757EE691F65.TMP
2010-01-13 20:44 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 20:44 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-09 12:40 . 2010-01-14 00:06 -------- d-----w- c:\program files\McAfee
2009-12-29 13:40 . 2009-12-29 13:36 761600 ----a-w- c:\programdata\avg8\update\backup\avgscanx.exe
2009-12-29 13:40 . 2009-12-29 13:36 340736 ----a-w- c:\programdata\avg8\update\backup\avgscanx.dll
2009-12-19 22:34 . 2009-12-19 22:34 407304 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-14 15:13 . 2009-07-22 13:29 -------- d-----w- c:\program files\Cheat Engine
2010-01-14 13:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Microsoft Games
2010-01-14 11:22 . 2008-08-18 17:42 1356 ----a-w- c:\users\Luca\AppData\Local\d3d9caps.dat
2010-01-13 23:25 . 2006-11-06 01:52 662608 ----a-w- c:\windows\system32\perfh010.dat
2010-01-13 23:25 . 2006-11-06 01:52 120120 ----a-w- c:\windows\system32\perfc010.dat
2010-01-13 23:24 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-13 20:36 . 2009-03-31 19:56 -------- d-----w- c:\programdata\Google Updater
2010-01-12 18:48 . 2008-09-21 11:42 -------- d-----w- c:\programdata\DVD Shrink
2010-01-11 00:55 . 2009-01-26 16:06 -------- d-----w- c:\programdata\HP Product Assistant
2010-01-11 00:55 . 2009-05-27 20:41 -------- d-----w- c:\programdata\avg8
2010-01-08 16:54 . 2008-08-18 19:36 -------- d-----w- c:\users\Luca\AppData\Roaming\uTorrent
2010-01-02 12:57 . 2008-10-16 15:31 -------- d-----w- c:\program files\Google
2009-12-23 08:47 . 2009-12-15 09:23 2066200 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-12-10 23:01 . 2009-12-10 23:01 -------- d-----w- c:\users\Luca\AppData\Roaming\U3
2009-12-10 20:54 . 2009-11-02 22:18 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-09 22:25 . 2007-05-06 12:07 -------- d-----w- c:\programdata\Microsoft Help
2009-11-21 23:51 . 2009-02-11 13:57 -------- d-----w- c:\program files\eMule
2009-11-21 06:40 . 2009-12-09 21:11 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 21:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-09 21:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-09 21:11 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 13:53 . 2009-11-18 13:53 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-18 13:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 13:52 . 2009-11-18 13:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-16 22:19 . 2009-11-16 19:26 43553792 ----a-w- c:\users\Luca\AppData\Roaming\Samsung\New PC Studio\LiveUpdate\Setup_For_Full_Update_IH2_6_4.exe
2009-11-15 18:44 . 2009-06-17 15:18 -------- d-----w- c:\programdata\Electronic Arts
2009-11-09 12:31 . 2009-12-12 01:14 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-12 01:14 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-12 01:14 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-11-04 21:14 . 2009-11-04 15:39 168090 ----a-w- c:\windows\hpoins29.dat
2009-11-02 19:42 . 2009-10-02 23:41 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-25 22:02 2048 ----a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2008-08-18 190024]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-04-24 251240]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-04-02 102400]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 4423680]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-01-24 319488]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"CnxDslTaskBar"="c:\program files\digicomt\Michelangelo USB ADSL\CnxDslTb.exe" [2003-10-29 462848]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"Skytel"="Skytel.exe" [2007-03-16 1822720]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-04-22 37888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Avvio veloce di Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-5-6 528384]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
PCM Media Sharing.lnk - c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2007-5-6 200812]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):31,d4,88,01,37,40,ca,01
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [27/05/2009 21.41.49 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [27/05/2009 21.42.04 108552]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [06/05/2007 13.21.46 266343]
R2 FsUsbExService;FsUsbExService;c:\windows\System32\FsUsbExService.Exe [06/07/2009 23.35.11 233472]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [24/04/2009 12.57.30 92008]
R3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;c:\windows\System32\drivers\CnxEtP.sys [18/08/2008 18.58.03 60288]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\System32\drivers\CnxEtU.sys [18/08/2008 18.58.03 646784]
R3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;c:\windows\System32\drivers\CnxTgN.sys [18/08/2008 18.58.03 108675]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\System32\FsUsbExDisk.Sys [06/07/2009 23.35.11 36608]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [13/04/2009 11.57.15 721904]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [27/05/2009 21.41.34 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [27/05/2009 21.41.32 297752]
S2 gupdate1c9b23b200aff05;Servizio di Google Update (gupdate1c9b23b200aff05);c:\program files\Google\Update\GoogleUpdate.exe [31/03/2009 20.58.54 133104]
S3 FontCache;Servizio cache tipi di carattere Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [26/08/2008 19.24.51 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [16/09/2009 12.07.29 54632]
S3 fsssvc;Servizio Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21.48.42 704864]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\System32\drivers\ss_bbus.sys [06/07/2009 23.36.53 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\System32\drivers\ss_bmdfl.sys [06/07/2009 23.36.53 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\System32\drivers\ss_bmdm.sys [06/07/2009 23.36.53 121856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-31 19:56]
2010-01-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-31 19:58]
2010-01-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-31 19:58]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://it.intl.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
HKLM-Run-zzzHPSETUP - E:\Setup.exe
HKLM-Run-NPSStartup - (no file)
HKLM-Run-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
AddRemove-eMule - c:\program files\eMule\Uninstall.exe
AddRemove-Lphant MediaBar - c:\program files\Lphant Applications\Lphant MediaBar\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-14 16:14
Windows 6.0.6002 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2010-01-14 16:18:57
ComboFix-quarantined-files.txt 2010-01-14 15:18
Pre-Run: 149.651.558.400 byte disponibili
Post-Run: 149.651.177.472 byte disponibili
- - End Of File - - E16F473BBA7CA1012912CDE4524A7ED3