ComboFix 08-03-14.4 - Utente 2008-03-15 15.21.25.2 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.1754 [GMT 1:00]
Eseguito da: H:\Documents and Settings\Utente\Desktop\varie\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Creati Da 2008-02-15 al 2008-03-15 )))))))))))))))))))))))))))))))))))
.
2008-03-11 19:51 . 2008-03-11 19:51 <DIR> d-------- H:\Programmi\CCleaner
2008-03-11 19:48 . 2008-03-14 15:11 <DIR> d-------- H:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-03-11 19:38 . 2008-03-11 19:38 <DIR> d-------- H:\Programmi\Trend Micro
2008-03-11 00:37 . 2008-03-11 00:37 250 --a------ H:\WINDOWS\gmer.ini
2008-03-10 23:04 . 2008-03-12 19:35 <DIR> d-------- H:\VEXPLITE
2008-03-10 23:04 . 2008-02-14 21:04 39,808 --a------ H:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-03-10 22:42 . 2007-11-16 22:15 <DIR> d--h----- H:\Documents and Settings\Administrator\Risorse di stampa
2008-03-10 22:42 . 2007-11-16 22:15 <DIR> d--h----- H:\Documents and Settings\Administrator\Risorse di rete
2008-03-10 22:42 . 2007-11-16 22:15 <DIR> d-------- H:\Documents and Settings\Administrator\Preferiti
2008-03-10 22:42 . 2007-11-16 21:20 <DIR> d--h----- H:\Documents and Settings\Administrator\Modelli
2008-03-10 22:42 . 2007-11-16 22:15 <DIR> dr------- H:\Documents and Settings\Administrator\Menu Avvio
2008-03-10 22:42 . 2008-03-15 15:05 <DIR> d--h----- H:\Documents and Settings\Administrator\Impostazioni locali
2008-03-10 22:42 . 2007-11-16 22:15 <DIR> d-------- H:\Documents and Settings\Administrator\Documenti
2008-03-10 22:42 . 2007-11-16 22:15 <DIR> dr-h----- H:\Documents and Settings\Administrator\Dati applicazioni
2008-03-10 22:23 . 2008-03-10 22:25 <DIR> d-------- H:\WINDOWS\BDOSCAN8
2008-03-07 22:44 . 2008-03-12 20:45 116 --a------ H:\WINDOWS\NeroDigital.ini
2008-03-07 21:09 . 2008-03-07 21:09 <DIR> d-------- H:\Documents and Settings\Utente\Dati applicazioni\Ahead
2008-03-07 21:07 . 2008-03-07 21:07 <DIR> d-------- H:\Programmi\Nero
2008-03-07 21:07 . 2008-03-07 21:07 <DIR> d-------- H:\Programmi\File comuni\Ahead
2008-03-05 19:46 . 2008-03-01 14:44 35,610,387 --a------ H:\biglvisita.rtf
2008-03-01 13:32 . 2008-03-01 13:32 <DIR> dr------- H:\Documents and Settings\Utente\Dati applicazioni\Brother
2008-03-01 13:29 . 2008-03-01 13:29 <DIR> d-------- H:\Programmi\Softinterface, Inc
2008-02-21 20:06 . 2008-02-21 21:23 77 --a------ H:\WINDOWS\Preview.ini
2008-02-21 19:58 . 2008-02-21 21:24 <DIR> d-------- H:\WSIOTEMP
2008-02-21 19:58 . 2004-06-21 13:48 188,416 --a------ H:\WINDOWS\system32\tx_png32.flt
2008-02-21 19:58 . 2004-06-21 13:48 172,032 --a------ H:\WINDOWS\system32\tx_jpg32.flt
2008-02-21 19:58 . 2004-06-21 13:48 61,440 --a------ H:\WINDOWS\system32\tx_tif32.flt
2008-02-21 19:58 . 2004-06-21 13:48 53,248 --a------ H:\WINDOWS\system32\tx_bmp32.flt
2008-02-21 19:58 . 2007-07-20 11:49 49,152 --a------ H:\WINDOWS\system32\wkiconf.new
2008-02-21 19:58 . 2004-06-21 13:48 49,152 --a------ H:\WINDOWS\system32\tx_wmf32.flt
2008-02-21 19:58 . 2000-10-10 16:42 24,064 --a------ H:\WINDOWS\system32\tx_gif32.flt
2008-02-21 19:58 . 2004-06-21 13:48 466 --a------ H:\WINDOWS\system32\ic32.ini
2008-02-21 19:58 . 2008-02-21 19:58 0 --a------ H:\WINDOWS\system32\wkiconf.770
2008-02-21 19:53 . 2008-02-21 19:58 <DIR> d-------- H:\Programmi\WKICosimi
2008-02-21 19:42 . 2002-10-15 17:29 98,304 --a------ H:\WINDOWS\system32\skeylink.dll
2008-02-21 19:42 . 2002-09-25 15:58 10,286 --a------ H:\WINDOWS\system32\drivers\keyp.sys
2008-02-21 19:41 . 1996-10-16 11:49 301,568 --a------ H:\WINDOWS\unin0410.exe
2008-02-21 19:41 . 2008-02-21 19:45 14 --a------ H:\prog.bat
2008-02-21 19:40 . 2008-02-21 19:40 <DIR> d-------- H:\Programmi\SwiftView
2008-02-18 23:39 . 2008-03-11 19:54 <DIR> d-------- H:\Programmi\Briscola
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-15 14:08 --------- d-----w H:\Documents and Settings\All Users\Dati applicazioni\Google Updater
2008-03-11 18:54 --------- d-----w H:\Programmi\Java
2008-03-07 20:04 --------- d-----w H:\Programmi\Ahead
2008-03-07 19:48 --------- d-----w H:\Documents and Settings\Utente\Dati applicazioni\LimeWire
2008-03-01 12:18 196,608 ----a-w H:\WINDOWS\system32\drivers\aStandard.bin
2008-02-28 14:18 --------- d-----w H:\Programmi\Windows Live
2008-02-12 18:38 --------- d-----w H:\Documents and Settings\All Users\Dati applicazioni\DVD Shrink
2008-02-12 18:37 --------- d-----w H:\Programmi\DVD Shrink
2008-02-12 00:03 --------- d-----w H:\Programmi\Video DVD Maker
2008-02-12 00:03 --------- d-----w H:\Documents and Settings\Utente\Dati applicazioni\Video DVD Maker FREE
2008-02-11 23:51 --------- d-----w H:\Programmi\DVDStyler
2008-02-11 21:00 --------- d-----w H:\Documents and Settings\Utente\Dati applicazioni\Wireshark
2008-02-11 20:58 --------- d-----w H:\Programmi\Wireshark
2008-02-11 20:43 --------- d-----w H:\Programmi\NAI
2008-02-11 20:03 --------- d-----w H:\Documents and Settings\Utente\Dati applicazioni\gtk-2.0
2008-02-11 20:01 --------- d-----w H:\Programmi\WinPcap
2008-02-11 20:01 --------- d-----w H:\Programmi\Nmap
2008-02-05 19:20 --------- d-----w H:\Programmi\File comuni\Adobe
2008-02-05 17:34 --------- d-----w H:\Programmi\MSXML 6.0
2008-02-04 22:55 --------- d-----w H:\Programmi\BIAS
2008-02-04 21:55 --------- d-----w H:\Programmi\mp3DirectCut
2008-02-04 20:55 --------- d-----w H:\Programmi\SureThing Express Labeler
2008-02-04 20:52 --------- d-----w H:\Programmi\File comuni\SureThing Shared
2008-02-04 20:51 --------- d--h--w H:\Programmi\InstallShield Installation Information
2008-02-04 20:51 --------- d-----w H:\Programmi\proDAD
2008-02-04 20:51 --------- d-----w H:\Programmi\Pinnacle
2008-02-04 20:51 --------- d-----w H:\Documents and Settings\Utente\Dati applicazioni\proDAD
2008-02-04 19:30 --------- d-----w H:\Programmi\LimeWire
2008-02-03 13:45 --------- d-----w H:\Programmi\Direct MIDI to MP3 Converter
2008-02-02 12:22 --------- d-----w H:\Programmi\MSXML 4.0
2008-02-01 20:22 --------- d-----w H:\Documents and Settings\All Users\Dati applicazioni\Pinnacle
2008-02-01 20:15 --------- d-----w H:\Documents and Settings\All Users\Dati applicazioni\Pinnacle Studio
2008-02-01 20:12 --------- d-----w H:\Documents and Settings\Utente\Dati applicazioni\InstallShield
2008-02-01 10:17 586,752 ----a-w H:\WINDOWS\WLXPGSS.SCR
2008-01-31 19:08 --------- d-----w H:\Programmi\SWiSHmax
2008-01-31 14:28 --------- d-----w H:\Documents and Settings\Utente\Dati applicazioni\dvdcss
2008-01-30 23:51 --------- d-----w H:\Programmi\Windows Media Connect 2
2008-01-29 18:46 --------- d-----w H:\Programmi\WinHTTrack
2008-01-24 19:46 --------- d-----w H:\Programmi\FileZilla
2008-01-23 21:04 --------- d-----w H:\Documents and Settings\Gli altri\Dati applicazioni\ATI
2008-01-22 13:00 765,952 ----a-w H:\WINDOWS\system32\tx14.dll
2008-01-22 00:00 1,056,768 ----a-w H:\WINDOWS\system32\tx14_dox.dll
2008-01-21 04:20 552,960 ----a-w H:\WINDOWS\system32\tx14_rtf.dll
2008-01-18 01:36 249,856 ----a-w H:\WINDOWS\system32\tx14_htm.dll
2008-01-17 19:55 --------- d-----w H:\Programmi\Macromedia
2008-01-17 19:53 --------- d-----w H:\Programmi\File comuni\Macromedia
2008-01-17 19:34 --------- d-----w H:\Programmi\Microsoft.NET
2008-01-17 19:26 --------- d---a-w H:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-01-15 04:10 667,648 ----a-w H:\WINDOWS\system32\tx14_doc.dll
2008-01-15 02:31 131,072 ----a-w H:\WINDOWS\system32\tx14_ic.dll
2008-01-15 02:01 217,088 ----a-w H:\WINDOWS\system32\tx14_tls.dll
2008-01-05 09:56 1 ----a-w H:\Documents and Settings\Utente\SI.bin
.
(((((((((((((((((((((((((((((
snapshot@2008-03-15_15.04.56,40 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-15 13:22:24 58,732 ----a-w H:\WINDOWS\system32\perfc009.dat
+ 2008-03-15 14:19:54 58,596 ----a-w H:\WINDOWS\system32\perfc009.dat
- 2008-03-15 13:22:24 69,790 ----a-w H:\WINDOWS\system32\perfc010.dat
+ 2008-03-15 14:19:55 69,568 ----a-w H:\WINDOWS\system32\perfc010.dat
- 2008-03-15 13:22:24 392,432 ----a-w H:\WINDOWS\system32\perfh009.dat
+ 2008-03-15 14:19:55 392,296 ----a-w H:\WINDOWS\system32\perfh009.dat
- 2008-03-15 13:22:24 437,644 ----a-w H:\WINDOWS\system32\perfh010.dat
+ 2008-03-15 14:19:55 437,272 ----a-w H:\WINDOWS\system32\perfh010.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="H:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00 15360]
"swg"="H:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"LaunchList"="H:\Programmi\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 15:41 145496]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="H:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-03 15:18 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 08:28 16126464 H:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 10:22 1822720 H:\WINDOWS\SkyTel.exe]
"ATICCC"="H:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 09:12 90112]
"Sunkist2k"="H:\Programmi\Multimedia Card Reader\shwicon2k.exe" [2005-02-25 16:54 131072]
"avast!"="H:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"iKeyWorks"="H:\PROGRA~1\Keyboard\Ikeymain.exe" [2002-11-22 11:22 73728]
"Adobe Reader Speed Launcher"="H:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"NeroFilterCheck"="H:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"SunJavaUpdateSched"="H:\Programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="H:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 13:00 15360]
H:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Google Updater.lnk - H:\Programmi\Google\Google Updater\GoogleUpdater.exe [2007-12-16 00:58:46 124400]
Microsoft Office.lnk - H:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"H:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"H:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"H:\\Programmi\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"H:\\Programmi\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"H:\\Programmi\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"H:\\Programmi\\Pinnacle\\Studio 11\\programs\\umi.exe"=
"H:\\Programmi\\Internet Explorer\\iexplore.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20:TCP"= 20:TCP:filezilla tcp 20
"20:UDP"= 20:UDP:filezilla udp 20
"21:TCP"= 21:TCP:filezilla tcp 21
"21:UDP"= 21:UDP:filezilla udp 21
S2 KeyP;KeyP;H:\WINDOWS\system32\DRIVERS\KeyP.sys [2002-09-25 15:58]
S3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;H:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-06-21 03:44]
S3 Video3D;ASUS Video3D Service;H:\WINDOWS\system32\Drivers\Video3D32.sys [2006-09-29 10:06]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-15 15:22:17
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-03-15 15.22.52
ComboFix-quarantined-files.txt 2008-03-15 14:22:44
ComboFix2.txt 2008-03-15 14:05:06
.
2008-03-11 22:21:36 --- E O F ---