ComboFix 08-11-11.01 - User 2008-11-12 18.35.10.2 - NTFSx86
Eseguito da: c:\documents and settings\User\Desktop\ComboFix.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\User\Preferiti\Videos.url
.
((((((((((((((((((((((((( Files Creati Da 2008-10-12 al 2008-11-12 )))))))))))))))))))))))))))))))))))
.
2008-11-10 16:49 . 2008-11-10 16:49 <DIR> d-------- c:\programmi\Lavasoft
2008-11-10 16:49 . 2008-11-10 16:50 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2008-11-10 16:48 . 2008-11-10 16:48 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2008-10-30 18:28 . 2008-10-30 18:28 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\Malwarebytes
2008-10-30 18:28 . 2008-10-30 18:28 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-10-27 18:50 . 2008-10-27 18:51 <DIR> d-------- c:\documents and settings\paola\Dati applicazioni\AVGTOOLBAR
2008-10-24 14:41 . 2008-10-24 14:41 <DIR> d-------- c:\programmi\Sacred Edizione Oro
2008-10-17 14:58 . 2008-10-17 14:58 <DIR> d-------- c:\documents and settings\paola\Dati applicazioni\PC Suite
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 14:40 --------- d-----w c:\programmi\Spybot - Search & Destroy
2008-11-10 14:40 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-11-09 09:18 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\avg8
2008-10-30 18:18 --------- d--h--w c:\programmi\FX Uninstall Information
2008-05-18 09:13 386,194 ----a-w c:\documents and settings\User\Dati applicazioni\serial2.dat
2008-05-16 17:26 54 ----a-w c:\programmi\inc1.bat
2008-05-16 17:26 41 ----a-w c:\programmi\sleep.bat
2008-05-16 17:25 386,194 ----a-w c:\documents and settings\User\Dati applicazioni\serial2.zip
2007-12-31 15:02 47,360 ----a-w c:\documents and settings\User\Dati applicazioni\pcouffin.sys
2006-12-18 18:55 149,560 -c--a-w c:\documents and settings\User\Dati applicazioni\GDIPFONTCACHEV1.DAT
1998-10-05 13:40 10,000 -c--a-w c:\windows\inf\unregpn.exe
.
Code:<pre>
----a-w 15,360 2004-08-19 22:39:35 c:\windows\system32\ctfmon .exe
</pre>
(((((((((((((((((((((((((((((
snapshot@2008-07-11_10.22.42,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 18:02:28 163,328 ----a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 06:00:00 89,504 ----a-w c:\windows\fdsv.exe
+ 2000-08-31 07:00:00 89,504 ----a-w c:\windows\fdsv.exe
- 2000-08-31 06:00:00 80,412 ----a-w c:\windows\grep.exe
+ 2000-08-31 07:00:00 80,412 ----a-w c:\windows\grep.exe
+ 2008-07-18 16:41:40 3,262 ----a-r c:\windows\Installer\{6882DD11-33B8-4DEA-8305-7E765BF74BD3}\ARPPRODUCTICON.exe
+ 2008-07-18 16:43:03 15,086 ----a-r c:\windows\Installer\{79880ACC-B5AB-486A-B95D-03F55DF3F9C6}\ARPPRODUCTICON.exe
+ 2008-07-18 16:43:03 53,248 ----a-r c:\windows\Installer\{79880ACC-B5AB-486A-B95D-03F55DF3F9C6}\NewShortcut1_686D32A3E0BF41B1A4513B59D52466AB.exe
+ 2008-07-18 16:43:03 53,248 ----a-r c:\windows\Installer\{79880ACC-B5AB-486A-B95D-03F55DF3F9C6}\NewShortcut1_F8354160C274433BBE3A7DFC0058E931.exe
+ 2008-07-18 16:43:03 53,248 ----a-r c:\windows\Installer\{79880ACC-B5AB-486A-B95D-03F55DF3F9C6}\NokiaPCSuite1_686D32A3E0BF41B1A4513B59D52466AB.exe
+ 2008-07-18 16:41:48 10,134 ----a-r c:\windows\Installer\{9F2BDC61-4D2D-47C0-BCB6-7D43D0EA7948}\ARPPRODUCTICON.exe
- 2000-08-31 06:00:00 28,672 ----a-w c:\windows\Nircmd.exe
+ 2000-08-31 07:00:00 28,672 ----a-w c:\windows\NIRCMD.exe
- 2000-08-31 06:00:00 98,816 ----a-w c:\windows\sed.exe
+ 2000-08-31 07:00:00 98,816 ----a-w c:\windows\sed.exe
- 2000-08-31 06:00:00 161,792 ----a-w c:\windows\swreg.exe
+ 2000-08-31 07:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2000-08-31 06:00:00 136,704 ----a-w c:\windows\swsc.exe
+ 2000-08-31 07:00:00 136,704 ----a-w c:\windows\SWSC.exe
- 2000-08-31 06:00:00 212,480 ----a-w c:\windows\swxcacls.exe
+ 2000-08-31 07:00:00 212,480 ----a-w c:\windows\SWXCACLS.exe
+ 2008-07-18 14:18:15 10,520 ----a-w c:\windows\system32\avgrsstx.dll
+ 2005-12-07 10:31:00 202,752 ----a-r c:\windows\system32\CddbCdda.dll
+ 2006-06-05 12:04:02 242,688 ----a-w c:\windows\system32\ConnAPI.dll
- 2008-05-19 13:39:51 3,580 ----a-w c:\windows\system32\d3d9caps.dat
+ 2008-07-18 17:09:01 3,580 ----a-w c:\windows\system32\d3d9caps.dat
+ 2006-06-26 08:55:48 699,392 ----a-w c:\windows\system32\DAAPI.dll
- 2007-03-08 15:37:44 578,560 -c----w c:\windows\system32\dllcache\user32.dll
+ 2004-08-19 22:39:29 578,048 -c--a-w c:\windows\system32\dllcache\user32.dll
+ 2008-09-05 14:48:55 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
+ 2008-07-18 14:18:11 26,824 ----a-w c:\windows\system32\drivers\avgmfx86.sys
+ 2008-04-29 10:19:50 12,960 ----a-w c:\windows\system32\drivers\Awrtpd.sys
+ 2008-04-29 10:19:54 15,648 ----a-w c:\windows\system32\drivers\Awrtrd.sys
+ 2006-05-29 06:26:38 127,488 ----a-w c:\windows\system32\drivers\nmwcd.sys
+ 2006-05-29 06:26:36 8,704 ----a-w c:\windows\system32\drivers\nmwcdc.sys
+ 2006-05-29 06:26:36 13,312 ----a-w c:\windows\system32\drivers\nmwcdcj.sys
+ 2006-05-29 06:26:36 13,312 ----a-w c:\windows\system32\drivers\nmwcdcm.sys
+ 2008-04-29 10:20:00 15,648 ----a-w c:\windows\system32\drivers\NSDriver.sys
- 2008-03-17 17:23:30 39,808 ----a-w c:\windows\system32\drivers\VIRAGTLT.SYS
+ 2008-08-29 12:15:22 39,808 ----a-w c:\windows\system32\drivers\VIRAGTLT.SYS
+ 2006-05-29 06:26:38 127,488 -c--a-w c:\windows\system32\DRVSTORE\nmwcd_1DF4D3C790F0E96AF6B05B76E7780D7770836172\nmwcd.sys
+ 2006-05-29 06:26:36 50,688 -c--a-w c:\windows\system32\DRVSTORE\nmwcd_1DF4D3C790F0E96AF6B05B76E7780D7770836172\nmwcdcls.dll
+ 2006-05-29 06:26:36 30,720 -c--a-w c:\windows\system32\DRVSTORE\nmwcd_1DF4D3C790F0E96AF6B05B76E7780D7770836172\nmwcdcocls.dll
+ 2006-05-29 06:26:34 4,608 -c--a-w c:\windows\system32\DRVSTORE\nmwcd_1DF4D3C790F0E96AF6B05B76E7780D7770836172\nmwcdlog.dll
+ 2006-05-29 06:26:36 8,704 -c--a-w c:\windows\system32\DRVSTORE\nmwcdc_1DF4D3C790F0E96AF6B05B76E7780D7770836172\nmwcdc.sys
+ 2006-05-29 06:26:36 13,312 -c--a-w c:\windows\system32\DRVSTORE\nmwcdcj_1DF4D3C790F0E96AF6B05B76E7780D7770836172\nmwcdcj.sys
+ 2006-05-29 06:26:36 13,312 -c--a-w c:\windows\system32\DRVSTORE\nmwcdm2k_1DF4D3C790F0E96AF6B05B76E7780D7770836172\nmwcdcm.sys
+ 2008-05-16 10:58:04 12,632 ----a-w c:\windows\system32\lsdelete.exe
+ 2006-06-20 12:22:00 131,072 ----a-w c:\windows\system32\NclAPI.dll
+ 2006-06-12 11:55:00 61,440 ----a-w c:\windows\system32\NclTools.dll
+ 2006-05-29 06:26:36 50,688 ----a-w c:\windows\system32\nmwcdcls.dll
+ 2006-05-29 06:26:36 30,720 ----a-w c:\windows\system32\nmwcdcocls.dll
+ 2006-05-29 06:26:34 4,608 ----a-w c:\windows\system32\nmwcdlog.dll
- 2007-03-08 15:37:44 578,560 ----a-w c:\windows\system32\user32.dll
+ 2004-08-19 22:39:29 578,048 ----a-w c:\windows\system32\user32.dll
+ 2006-06-22 11:09:12 245,760 ----a-w c:\windows\system32\VersitConverter.dll
+ 2008-09-05 14:15:32 4,212 ---h--w c:\windows\system32\zllictbl.dat
- 2000-08-31 06:00:00 49,152 ----a-w c:\windows\VFind.exe
+ 2000-08-31 07:00:00 49,152 ----a-w c:\windows\VFIND.exe
- 2000-08-31 06:00:00 68,096 ----a-w c:\windows\zip.exe
+ 2000-08-31 07:00:00 68,096 ----a-w c:\windows\zip.exe
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 313,472 2006-03-30 15:45:08 c:\programmi\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
----a-w 438,359 2006-04-21 14:41:20 c:\programmi\Alice ti aiuta\SmartBridge\bak\MotiveSB.exe
----a-w 335,872 2003-06-05 11:35:00 c:\programmi\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
----a-w 356,728 2000-07-24 21:47:16 c:\programmi\Aveo\Attune\bin\bak\attune_ce.exe
----a-w 462,848 2003-10-29 13:11:30 c:\programmi\digicomt\Michelangelo USB ADSL\bak\CnxDslTb.exe
----a-w 81,920 2005-08-11 14:30:30 c:\programmi\File comuni\InstallShield\UpdateService\bak\issch.exe
----a-w 221,184 2005-02-16 15:15:22 c:\programmi\File comuni\InstallShield\UpdateService\bak\ISUSPM.exe
----a-w 53,408 2006-03-24 16:14:48 c:\programmi\File comuni\Symantec Shared\bak\ccApp.exe
----a-w 171,448 2007-01-27 06:38:03 c:\programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe
----a-w 257,088 2007-04-27 09:25:58 c:\programmi\iTunes\bak\iTunesHelper.exe
----a-w 257,088 2007-04-27 09:25:58 c:\programmi\iTunes\iTunesHelper.exe
----a-w 73,728 2002-11-22 17:22:56 c:\programmi\Keyboard\bak\Ikeymain.exe
----a-w 98,304 2004-01-23 15:38:10 c:\programmi\QuickTime\bak\bak\qttask.exe
----a-w 98,304 2004-01-23 15:38:10 c:\programmi\QuickTime\bak\bak\qttask.exe
----a-w 49,152 2002-06-03 10:38:12 c:\programmi\ScanSoft\OmniPageSE\bak\opware32.exe
----a-w 124,656 2006-06-15 00:40:34 c:\programmi\Symantec AntiVirus\bak\VPTray.exe
----a-w 15,360 2004-08-19 22:39:35 c:\windows\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-19 22:39:35 c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Free Download Manager"="c:\programmi\Free Download Manager\fdm.exe" [N/A]
"MsnMsgr"="c:\programmi\MSN Messenger\MsnMsgr.Exe" [N/A]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [N/A]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"PcSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-19 1449984]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iKeyWorks"="c:\progra~1\Keyboard\Ikeymain.exe" [N/A]
"QuickTime Task"="c:\programmi\QuickTime\bak\bak\qttask.exe" [2004-01-23 98304]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2007-04-27 257088]
"UnlockerAssistant"="c:\programmi\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"CanonSolutionMenu"="c:\programmi\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-03 644696]
"CanonMyPrinter"="c:\programmi\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-01 1234712]
"PCSuiteTrayApplication"="c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
"Corel Reminder"="" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
"ALUAlert"="c:\programmi\Symantec\LiveUpdate\ALUNotify.exe" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-19 c:\windows\system32\narrator.exe]
c:\docume~1\ALLUSE~1\MENUAV~1\PROGRA~1\ESECUZ~1\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2007-02-16 217088]
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Logitech SetPoint.lnk - c:\programmi\Logitech\SetPoint\SetPoint.exe [2007-12-19 528384]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\FreeFTP\\FreeFTP.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\italian\\setup.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
.
.
------- Supplementare di scansione -------
.
FireFox -: Profile - c:\documents and settings\User\Dati applicazioni\Mozilla\Firefox\Profiles\xfoxql6t.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://italian.eazel.com/it/index.php?rvs=hompag&d=79919283
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-12 18:38:06
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
PROCESSO: c:\windows\system32\winlogon.exe
-> c:\windows\system32\tsd32.dll
.
Ora fine scansione: 2008-11-12 18.41.32
ComboFix-quarantined-files.txt 2008-11-12 17:40:32
ComboFix2.txt 2008-07-11 08:24:17
Pre-Run: 89.629.958.144 byte disponibili
Post-Run: 89,654,947,840 byte disponibili
204 --- E O F --- 2008-06-11 12:57:45