ecco il log come mi hai chiesto
ComboFix 10-02-25.02 - Vanni Tortoli 04/03/2010 18.07.55.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.2047.1557 [GMT 1:00]
Eseguito da: c:\documents and settings\Vanni Tortoli\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Vanni Tortoli\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Firewall ESET *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Resident AV is active
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
FILE ::
"C:\fndxes.exe"
"c:\windows\system32\drivers\fxdsbdhy.sys"
"c:\windows\system32\ymrhvqnh.dll"
"c:\windows\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\fndxes.exe
c:\windows\system32\drivers\fxdsbdhy.sys
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FXDSBDHY
-------\Legacy_WGAVJFOT
-------\Service_fxdsbdhy
-------\Service_Hdatruev
-------\Service_wgavjfot
((((((((((((((((((((((((( Files Creati Da 2010-02-04 al 2010-03-04 )))))))))))))))))))))))))))))))))))
.
2010-02-26 12:05 . 2010-02-26 12:05 -------- d-----w- c:\documents and settings\Vanni Tortoli\Dati applicazioni\Malwarebytes
2010-02-26 12:05 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-26 12:04 . 2010-02-26 12:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-02-26 12:04 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-26 12:04 . 2010-02-26 12:05 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-02-26 11:36 . 2010-02-26 11:36 -------- d-----w- c:\programmi\Trend Micro
2010-02-25 13:56 . 2010-02-25 13:56 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\ESET
2010-02-25 13:55 . 2010-02-25 13:55 -------- d-----w- c:\documents and settings\Vanni Tortoli\Dati applicazioni\ESET
2010-02-25 13:55 . 2010-02-25 13:55 -------- d-----w- c:\documents and settings\Vanni Tortoli\Impostazioni locali\Dati applicazioni\ESET
2010-02-25 13:54 . 2010-02-25 13:54 -------- d-----w- c:\programmi\ESET
2010-02-25 13:54 . 2010-02-25 13:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ESET
2010-02-03 16:44 . 2009-12-16 13:42 43008 ----a-w- c:\documents and settings\Vanni Tortoli\Dati applicazioni\Mozilla\Firefox\Profiles\bludfozr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-02-03 16:44 . 2009-12-16 13:42 340480 ----a-w- c:\documents and settings\Vanni Tortoli\Dati applicazioni\Mozilla\Firefox\Profiles\bludfozr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-02-03 16:44 . 2009-12-16 13:41 346624 ----a-w- c:\documents and settings\Vanni Tortoli\Dati applicazioni\Mozilla\Firefox\Profiles\bludfozr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-02-03 16:44 . 2009-12-16 13:42 872960 ----a-w- c:\documents and settings\Vanni Tortoli\Dati applicazioni\Mozilla\Firefox\Profiles\bludfozr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-04 15:51 . 2007-01-02 16:01 -------- d-----w- c:\programmi\Creative
2010-03-04 15:48 . 2005-08-05 11:53 -------- d-----w- c:\programmi\Google
2010-03-04 15:44 . 2007-10-01 18:16 -------- d-----w- c:\programmi\Skype
2010-03-04 15:43 . 2007-01-16 12:52 -------- d-----w- c:\documents and settings\Vanni Tortoli\Dati applicazioni\Skype
2010-03-04 15:42 . 2005-08-05 11:54 -------- d-----w- c:\programmi\Yahoo!
2010-03-04 15:41 . 2007-09-12 23:00 -------- d-----w- c:\programmi\Windows Live Toolbar
2010-03-04 13:26 . 2007-12-17 15:15 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-03-04 13:26 . 2007-12-17 15:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-03-04 10:47 . 2007-12-10 14:06 -------- d-----w- c:\programmi\LogMeIn
2010-03-04 10:46 . 2009-09-10 21:51 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-03-03 17:36 . 2007-02-23 08:41 -------- d-----w- c:\programmi\AdunanzA
2010-02-17 12:30 . 2006-01-10 20:24 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Sony Corporation
2009-12-31 16:14 . 2005-08-04 07:44 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 22:20 . 2005-08-04 07:45 57394 ----a-w- c:\windows\system32\perfc010.dat
2009-12-30 22:20 . 2005-08-04 07:45 366504 ----a-w- c:\windows\system32\perfh010.dat
2009-12-22 05:34 . 2005-08-04 07:44 671232 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:34 . 2005-08-04 07:44 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-17 07:58 . 2005-08-04 14:55 346112 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2005-08-04 07:44 33280 ----a-w- c:\windows\system32\csrsrv.dll
2007-11-16 23:32 . 2006-01-11 21:53 1890 -csha-w- c:\windows\system32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((
SnapShot@2010-02-26_15.23.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-04 17:16 . 2010-03-04 17:16 16384 c:\windows\temp\Perflib_Perfdata_464.dat
- 2007-01-29 08:58 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
+ 2007-01-29 08:58 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
- 2005-08-04 07:44 . 2009-10-29 05:19 39424 c:\windows\system32\pngfilt.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 39424 c:\windows\system32\pngfilt.dll
+ 2004-08-19 15:39 . 2009-11-27 17:33 17920 c:\windows\system32\msyuv.dll
+ 2005-08-04 07:44 . 2009-11-27 16:38 28672 c:\windows\system32\msvidc32.dll
+ 2005-08-04 07:44 . 2009-11-27 16:38 11264 c:\windows\system32\msrle32.dll
- 2005-08-04 07:44 . 2004-08-19 12:00 11264 c:\windows\system32\msrle32.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 16384 c:\windows\system32\jsproxy.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 16384 c:\windows\system32\jsproxy.dll
+ 2004-08-19 15:39 . 2009-11-27 16:38 48128 c:\windows\system32\iyuv_32.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 96768 c:\windows\system32\inseng.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 96768 c:\windows\system32\inseng.dll
- 2005-08-04 07:44 . 2009-06-16 14:53 82432 c:\windows\system32\fontsub.dll
+ 2005-08-04 07:44 . 2009-10-15 17:20 82432 c:\windows\system32\fontsub.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 55808 c:\windows\system32\extmgr.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 55808 c:\windows\system32\extmgr.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 39424 c:\windows\system32\dllcache\pngfilt.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 39424 c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-19 15:39 . 2009-11-27 17:33 17920 c:\windows\system32\dllcache\msyuv.dll
+ 2009-11-27 16:38 . 2009-11-27 16:38 28672 c:\windows\system32\dllcache\msvidc32.dll
+ 2009-11-27 16:38 . 2009-11-27 16:38 11264 c:\windows\system32\dllcache\msrle32.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 16384 c:\windows\system32\dllcache\jsproxy.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 16384 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-19 15:39 . 2009-11-27 16:38 48128 c:\windows\system32\dllcache\iyuv_32.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 96768 c:\windows\system32\dllcache\inseng.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 96768 c:\windows\system32\dllcache\inseng.dll
- 2005-08-04 07:44 . 2009-09-25 05:48 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 81920 c:\windows\system32\dllcache\ieencode.dll
- 2007-04-18 10:42 . 2009-10-27 11:01 18432 c:\windows\system32\dllcache\iedw.exe
+ 2007-04-18 10:42 . 2009-12-16 13:35 18432 c:\windows\system32\dllcache\iedw.exe
- 2009-06-16 14:53 . 2009-06-16 14:53 82432 c:\windows\system32\dllcache\fontsub.dll
+ 2009-06-16 14:53 . 2009-10-15 17:20 82432 c:\windows\system32\dllcache\fontsub.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 55808 c:\windows\system32\dllcache\extmgr.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 55808 c:\windows\system32\dllcache\extmgr.dll
+ 2009-12-14 07:35 . 2009-12-14 07:35 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-06-10 14:23 . 2009-11-27 16:38 85504 c:\windows\system32\dllcache\avifil32.dll
- 2009-06-10 14:23 . 2009-06-10 14:23 85504 c:\windows\system32\dllcache\avifil32.dll
+ 2005-08-04 07:44 . 2009-11-27 16:38 85504 c:\windows\system32\avifil32.dll
- 2005-08-04 07:44 . 2009-06-10 14:23 85504 c:\windows\system32\avifil32.dll
- 2008-10-15 23:44 . 2009-12-23 15:32 23040 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 23040 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 61440 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 61440 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 27136 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 27136 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 11264 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 11264 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 12288 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 12288 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 90112 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 90112 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 45056 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 45056 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2006-01-17 17:45 . 2010-03-03 17:48 22528 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 22528 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 30720 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 30720 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 16384 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 16384 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 34304 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 34304 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 81920 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\fpicon.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 81920 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\fpicon.exe
+ 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\Driver Cache\i386\msyuv.dll
+ 2009-11-27 16:38 . 2009-11-27 16:38 48128 c:\windows\Driver Cache\i386\iyuv_32.dll
+ 2001-08-30 23:08 . 2009-11-27 16:38 8704 c:\windows\system32\tsbyuv.dll
+ 2001-08-30 23:08 . 2009-11-27 16:38 8704 c:\windows\system32\dllcache\tsbyuv.dll
+ 2008-10-15 23:44 . 2010-03-03 18:04 4096 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 4096 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 3584 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 3584 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 8192 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 8192 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 2560 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 2560 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2009-11-27 16:38 . 2009-11-27 16:38 8704 c:\windows\Driver Cache\i386\tsbyuv.dll
- 2004-12-18 12:07 . 2009-10-28 00:43 368640 c:\windows\system32\xpsp3res.dll
+ 2004-12-18 12:07 . 2009-12-16 14:00 368640 c:\windows\system32\xpsp3res.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 629248 c:\windows\system32\urlmon.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 629248 c:\windows\system32\urlmon.dll
- 2005-08-04 07:44 . 2009-06-16 14:53 119808 c:\windows\system32\t2embed.dll
+ 2005-08-04 07:44 . 2009-10-15 21:50 119808 c:\windows\system32\t2embed.dll
+ 2005-08-04 07:44 . 2009-12-08 09:00 474624 c:\windows\system32\shlwapi.dll
- 2005-08-04 07:44 . 2009-09-25 05:48 474624 c:\windows\system32\shlwapi.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 532480 c:\windows\system32\mstime.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 532480 c:\windows\system32\mstime.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 146432 c:\windows\system32\msrating.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 146432 c:\windows\system32\msrating.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 449024 c:\windows\system32\mshtmled.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 449024 c:\windows\system32\mshtmled.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 251904 c:\windows\system32\iepeers.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 251904 c:\windows\system32\iepeers.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 205312 c:\windows\system32\dxtrans.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 205312 c:\windows\system32\dxtrans.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 357888 c:\windows\system32\dxtmsft.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 357888 c:\windows\system32\dxtmsft.dll
+ 2005-08-04 07:44 . 2009-12-04 14:41 453760 c:\windows\system32\drivers\mrxsmb.sys
- 2007-04-18 12:46 . 2009-10-29 05:19 671232 c:\windows\system32\dllcache\wininet.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 671232 c:\windows\system32\dllcache\wininet.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 629248 c:\windows\system32\dllcache\urlmon.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 629248 c:\windows\system32\dllcache\urlmon.dll
- 2009-06-16 14:53 . 2009-06-16 14:53 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2009-06-16 14:53 . 2009-10-15 21:50 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2006-08-14 10:34 . 2009-12-31 16:14 352640 c:\windows\system32\dllcache\srv.sys
- 2007-04-18 12:46 . 2009-09-25 05:48 474624 c:\windows\system32\dllcache\shlwapi.dll
+ 2007-04-18 12:46 . 2009-12-08 09:00 474624 c:\windows\system32\dllcache\shlwapi.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 532480 c:\windows\system32\dllcache\mstime.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 532480 c:\windows\system32\dllcache\mstime.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 146432 c:\windows\system32\dllcache\msrating.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 146432 c:\windows\system32\dllcache\msrating.dll
+ 2009-12-17 07:58 . 2009-12-17 07:58 346112 c:\windows\system32\dllcache\mspaint.exe
- 2007-04-18 12:46 . 2009-10-29 05:19 449024 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 449024 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-05-05 09:41 . 2009-12-04 14:41 453760 c:\windows\system32\dllcache\mrxsmb.sys
+ 2007-04-18 12:46 . 2009-12-22 05:34 251904 c:\windows\system32\dllcache\iepeers.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 251904 c:\windows\system32\dllcache\iepeers.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 205312 c:\windows\system32\dllcache\dxtrans.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 205312 c:\windows\system32\dllcache\dxtrans.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 357888 c:\windows\system32\dllcache\dxtmsft.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 357888 c:\windows\system32\dllcache\dxtmsft.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 151552 c:\windows\system32\dllcache\cdfview.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 151552 c:\windows\system32\dllcache\cdfview.dll
+ 2005-08-04 07:44 . 2009-11-21 16:38 470528 c:\windows\system32\dllcache\aclayers.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 151552 c:\windows\system32\cdfview.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 151552 c:\windows\system32\cdfview.dll
- 2008-10-15 23:44 . 2009-12-23 15:32 409600 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 409600 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 286720 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 286720 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 249856 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 249856 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 794624 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 794624 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-10-15 23:44 . 2009-12-23 15:32 135168 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-10-15 23:44 . 2010-03-03 18:04 135168 c:\windows\Installer\{91CA0410-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 114688 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 114688 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2006-01-17 17:45 . 2010-03-03 17:47 167936 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\accicons.exe
- 2006-01-17 17:45 . 2009-12-23 15:31 167936 c:\windows\Installer\{90280410-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2005-08-04 15:15 . 2009-12-04 14:41 453760 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2005-08-04 07:44 . 2009-11-21 16:38 470528 c:\windows\AppPatch\aclayers.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 1510400 c:\windows\system32\shdocvw.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 1510400 c:\windows\system32\shdocvw.dll
+ 2005-08-04 07:44 . 2009-11-27 17:33 1296384 c:\windows\system32\quartz.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 3092480 c:\windows\system32\mshtml.dll
+ 2006-09-04 06:11 . 2009-12-22 05:34 1510400 c:\windows\system32\dllcache\shdocvw.dll
- 2006-09-04 06:11 . 2009-10-29 05:19 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2007-10-29 22:42 . 2009-11-27 17:33 1296384 c:\windows\system32\dllcache\quartz.dll
+ 2007-05-04 12:59 . 2009-12-22 05:34 3092480 c:\windows\system32\dllcache\mshtml.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 1056256 c:\windows\system32\dllcache\danim.dll
- 2007-04-18 12:46 . 2009-09-25 05:48 1056256 c:\windows\system32\dllcache\danim.dll
- 2007-04-18 12:46 . 2009-10-29 05:19 1024000 c:\windows\system32\dllcache\browseui.dll
+ 2007-04-18 12:46 . 2009-12-22 05:34 1024000 c:\windows\system32\dllcache\browseui.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 1056256 c:\windows\system32\danim.dll
- 2005-08-04 07:44 . 2009-09-25 05:48 1056256 c:\windows\system32\danim.dll
- 2005-08-04 07:44 . 2009-10-29 05:19 1024000 c:\windows\system32\browseui.dll
+ 2005-08-04 07:44 . 2009-12-22 05:34 1024000 c:\windows\system32\browseui.dll
+ 2010-01-19 16:51 . 2010-01-19 16:51 5524480 c:\windows\Installer\e2d8f2.msp
+ 2009-12-01 14:52 . 2009-12-01 14:52 7970816 c:\windows\Installer\cf6929.msp
+ 2009-12-01 14:52 . 2009-12-01 14:52 9630208 c:\windows\Installer\cf6914.msp
+ 2010-01-19 17:29 . 2010-01-19 17:29 5050368 c:\windows\Installer\cf68ff.msp
+ 2007-04-19 11:49 . 2007-04-19 11:49 1661280 c:\windows\Installer\$PatchCache$\Managed\0140AC1900063D11C8EF10054038389C\11.0.8173\PPTVIEW.EXE
+ 2007-09-14 15:04 . 2010-02-01 10:26 30364104 c:\windows\system32\MRT.exe
+ 2010-03-03 17:50 . 2010-03-03 17:50 15710720 c:\windows\Installer\cf6932.msp
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2005-10-06 278528]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920]
"LogMeIn GUI"="c:\programmi\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2006-09-01 282624]
"CanonSolutionMenu"="c:\programmi\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\programmi\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"egui"="c:\programmi\ESET\ESET Smart Security\egui.exe" [2009-10-01 2054360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\Default User\Menu Avvio\Programmi\Esecuzione automatica\
VAIO Launcher.lnk - c:\programmi\Sony\VAIO Launcher\Launcher.exe [2003-10-2 778240]
c:\documents and settings\Administrator\Menu Avvio\Programmi\Esecuzione automatica\
VAIO Launcher.lnk - c:\programmi\Sony\VAIO Launcher\Launcher.exe [2003-10-2 778240]
c:\documents and settings\LogMeInRemoteUser\Menu Avvio\Programmi\Esecuzione automatica\
VAIO Launcher.lnk - c:\programmi\Sony\VAIO Launcher\Launcher.exe [2003-10-2 778240]
c:\documents and settings\Vanni Tortoli\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-20 113664]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-19 12:02 87352 ----a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 15:42 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Sony\\VAIO Media 4.0\\Vc.exe"=
"c:\\Programmi\\Sony\\VAIO Media Integrated Server\\Platform\\SV_Httpd.exe"=
"c:\\Programmi\\Sony\\VAIO Media Integrated Server\\Platform\\UPnPFramework.exe"=
"c:\\Programmi\\Sony\\VAIO Media Integrated Server\\Platform\\VMConsole.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\DNA\\btdna.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [23/01/2006 17.01.15 5248]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [01/10/2009 15.06.40 108792]
R1 PrivateDisk;PrivateDisk;c:\windows\system32\drivers\privatediskm.sys [06/07/2004 13.07.06 45627]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\programmi\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [20/10/2004 3.47.54 98304]
R2 ekrn;ESET Service;c:\programmi\ESET\ESET Smart Security\ekrn.exe [01/10/2009 15.06.52 735960]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\programmi\LogMeIn\x86\rainfo.sys [03/08/2007 15.09.34 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [10/12/2007 15.06.34 47640]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\programmi\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [20/10/2004 2.40.46 118784]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [04/08/2005 8.45.38 71961]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
S3 V0250Dev;Live! Cam Notebook Pro;c:\windows\system32\drivers\V0250Dev.sys [02/01/2007 17.23.56 163840]
S4 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [23/01/2006 17.01.15 160640]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://google.it/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Trasferimento tramite Image Converter 2 - c:\programmi\Sony\Image Converter 2\menu.htm
FF - ProfilePath - c:\documents and settings\Vanni Tortoli\Dati applicazioni\Mozilla\Firefox\Profiles\bludfozr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://it.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:it:official
FF - component: c:\documents and settings\Vanni Tortoli\Dati applicazioni\Mozilla\Firefox\Profiles\bludfozr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npbittorrent.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{A3BA40A2-74F0-42BD-F434-00B15A2C8953} - (no file)
HKCU-Run-Yahoo! Pager - c:\programmi\Yahoo!\Messenger\ypager.exe
HKCU-Run-FreeCall - c:\programmi\freecall.com\freecall\freecall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-04 18:17
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:8d,d4,c6,25,09,44,24,e5,0c,46,7f,ae,77,5e,2b,03,4e,30,f8,fa,ad,
53,01,54,49,bc,08,76,24,7c,36,ff,f1,22,6a,d8,81,2c,8a,ec,18,22,8f,19,fc,fd,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140AC1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:8d,d4,c6,25,09,44,24,e5,0c,46,7f,ae,77,5e,2b,03,4e,30,f8,fa,ad,
53,01,54,49,bc,08,76,24,7c,36,ff,f1,22,6a,d8,81,2c,8a,ec,18,22,8f,19,fc,fd,\
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1452)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\VESWinlogon.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(3168)
c:\programmi\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\AvidSDMService.exe
c:\programmi\LogMeIn\x86\RaMaint.exe
c:\programmi\LogMeIn\x86\LogMeIn.exe
c:\programmi\LogMeIn\x86\LMIGuardian.exe
c:\programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\programmi\Sony\VAIO Event Service\VESMgr.exe
c:\programmi\Sony\VAIO Media Integrated Server\VMISrv.exe
c:\programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
c:\programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
c:\programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\spool\drivers\w32x86\3\WrtProc.exe
c:\programmi\LogMeIn\x86\LMIGuardian.exe
c:\programmi\File comuni\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
.
**************************************************************************
.
Ora fine scansione: 2010-03-04 18:21:44 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-03-04 17:21
ComboFix2.txt 2010-02-26 15:30
Pre-Run: 11.395.686.400 byte disponibili
Post-Run: 11.268.780.032 byte disponibili
- - End Of File - - A555A3B5D40F4B2524D5CDC5615B5B85