ComboFix 09-01-15.01 - gaetano 2009-01-16 17.04.41.1 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1040.18.1918.983 [GMT 1:00]
Eseguito da: c:\users\gaetano\Downloads\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Outdated)
FW: Norton Internet Security *disabled*
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\gaetano\AppData\Roaming\.#
c:\windows\system32\CNCFLdAR.DLL
c:\windows\system32\CNCFLdCN.DLL
c:\windows\system32\CNCFLdCZ.DLL
c:\windows\system32\CNCFLdDE.DLL
c:\windows\system32\CNCFLdDK.DLL
c:\windows\system32\CNCFLdES.DLL
c:\windows\system32\CNCFLdFI.DLL
c:\windows\system32\CNCFLdFR.DLL
c:\windows\system32\CNCFLdGR.DLL
c:\windows\system32\CNCFLdHU.DLL
c:\windows\system32\CNCFLdID.DLL
c:\windows\system32\CNCFLdIT.DLL
c:\windows\system32\CNCFLdKR.DLL
c:\windows\system32\CNCFLdNL.DLL
c:\windows\system32\CNCFLdNO.DLL
c:\windows\system32\CNCFLdPL.DLL
c:\windows\system32\CNCFLdPT.DLL
c:\windows\system32\CNCFLdRU.DLL
c:\windows\system32\CNCFLdSE.DLL
c:\windows\system32\CNCFLdTH.DLL
c:\windows\system32\CNCFLdTR.DLL
c:\windows\system32\CNCFLdTW.DLL
c:\windows\system32\drivers\RKHit.sys
c:\windows\system32\hpgt35.dll
c:\windows\system32\hpxp3500.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RKHIT
-------\Service_RkHit
((((((((((((((((((((((((( Files Creati Da 2008-12-16 al 2009-01-16 )))))))))))))))))))))))))))))))))))
.
2009-01-16 17:01 . 2009-01-16 17:01 <DIR> d-------- C:\32788R22FWJFW
2009-01-16 17:01 . 2009-01-16 17:01 6,736 --a------ c:\windows\System32\drivers\PROCEXP90.SYS
2009-01-15 22:07 . 2009-01-15 22:07 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-15 22:07 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-01-15 22:07 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-01-15 18:59 . 2009-01-16 12:01 <DIR> d-------- c:\program files\Navilog1
2009-01-15 17:05 . 2009-01-15 17:05 <DIR> d-------- c:\program files\Trend Micro
2009-01-15 15:05 . 2009-01-15 15:05 <DIR> d-------- C:\!KillBox
2009-01-14 20:23 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-13 14:56 . 2009-01-13 14:56 <DIR> d-------- c:\users\gaetano\AppData\Roaming\PC Tools
2009-01-13 14:56 . 2009-01-16 17:13 <DIR> d-a------ c:\users\All Users\TEMP
2009-01-13 14:56 . 2009-01-16 17:13 <DIR> d-a------ c:\programdata\TEMP
2009-01-13 14:56 . 2009-01-16 09:57 <DIR> d-------- c:\program files\Spyware Doctor
2009-01-13 14:56 . 2009-01-13 15:06 81,288 --a------ c:\windows\System32\drivers\iksyssec.sys
2009-01-13 14:56 . 2009-01-13 15:06 66,952 --a------ c:\windows\System32\drivers\iksysflt.sys
2009-01-13 14:56 . 2009-01-13 15:06 40,840 --a------ c:\windows\System32\drivers\ikfilesec.sys
2009-01-13 14:56 . 2008-06-02 15:19 29,576 --a------ c:\windows\System32\drivers\kcom.sys
2009-01-09 17:19 . 2009-01-09 17:20 <DIR> d-------- c:\program files\eMule
2009-01-09 17:02 . 2009-01-09 17:02 <DIR> d-------- c:\users\All Users\eMule
2009-01-09 17:02 . 2009-01-09 17:02 <DIR> d-------- c:\programdata\eMule
2009-01-09 13:05 . 2009-01-09 13:05 <DIR> d-------- c:\users\gaetano\AppData\Roaming\Template
2009-01-03 14:20 . 2009-01-03 14:24 <DIR> d-------- c:\users\gaetano\AppData\Roaming\Uniblue
2009-01-03 13:54 . 2009-01-03 13:54 <DIR> d-------- c:\program files\Tacmi
2009-01-03 13:49 . 2009-01-03 14:11 <DIR> d-------- c:\users\All Users\PrevxCSI
2009-01-03 13:49 . 2009-01-03 14:11 <DIR> d-------- c:\programdata\PrevxCSI
2009-01-03 13:38 . 2009-01-03 13:39 <DIR> d-------- c:\windows\Internet Logs
2009-01-02 13:51 . 2009-01-02 13:51 <DIR> d-------- c:\users\Public\CyberLink
2009-01-02 13:51 . 2009-01-02 13:51 <DIR> d-------- c:\users\gaetano\AppData\Roaming\CyberLink
2009-01-02 13:51 . 2009-01-02 13:51 <DIR> d-------- c:\users\All Users\CyberLink
2009-01-02 13:51 . 2009-01-02 13:51 <DIR> d-------- c:\programdata\CyberLink
2009-01-02 10:14 . 2009-01-02 10:14 <DIR> d-------- c:\program files\MSXML 4.0
2008-12-31 21:24 . 2008-12-31 21:24 <DIR> d-------- c:\users\gaetano\AppData\Roaming\NewSoft
2008-12-31 21:23 . 2008-12-31 21:23 <DIR> d-------- c:\program files\Common Files\NewSoft
2008-12-31 21:23 . 1997-10-14 05:19 11,776 --a------ c:\windows\System32\pmsbfn32.dll
2008-12-31 21:23 . 2005-06-01 00:28 9,606 --a------ c:\windows\System32\NEWSOFT
2008-12-31 21:23 . 2008-12-31 21:23 264 --a------ c:\windows\setup.iss
2008-12-31 21:22 . 2008-12-31 21:22 <DIR> d-------- c:\windows\System32\Color
2008-12-31 21:22 . 2008-12-31 21:22 <DIR> d-------- c:\program files\NewSoft
2008-12-31 21:22 . 2008-12-31 21:22 <DIR> d-------- c:\program files\Common Files\PDFView
2008-12-31 21:21 . 2008-12-31 21:21 <DIR> d-------- c:\users\gaetano\AppData\Roaming\ScanSoft
2008-12-31 21:21 . 2008-12-31 21:21 <DIR> d-------- c:\users\All Users\ScanSoft
2008-12-31 21:21 . 2008-12-31 21:21 <DIR> d-------- c:\users\All Users\InstallShield
2008-12-31 21:21 . 2008-12-31 21:21 <DIR> d-------- c:\programdata\ScanSoft
2008-12-31 21:21 . 2008-12-31 21:21 <DIR> d-------- c:\programdata\InstallShield
2008-12-31 21:21 . 2008-12-31 21:21 <DIR> d-------- c:\program files\Common Files\ScanSoft Shared
2008-12-31 21:21 . 2008-12-31 21:21 412 --a------ c:\windows\MAXLINK.INI
2008-12-31 21:20 . 2008-12-31 21:20 <DIR> d-------- c:\program files\ScanSoft
2008-12-31 18:06 . 2009-01-02 15:44 <DIR> d-------- c:\users\gaetano\AppData\Roaming\Canon
2008-12-31 16:59 . 2008-12-31 16:59 <DIR> d-------- c:\users\All Users\CanonIJPLM
2008-12-31 16:59 . 2008-12-31 16:59 <DIR> d-------- c:\programdata\CanonIJPLM
2008-12-31 16:53 . 2008-12-31 16:53 <DIR> d-------- c:\program files\Common Files\CANON
2008-12-31 16:50 . 2008-12-31 16:50 <DIR> d--h----- c:\users\All Users\CanonBJ
2008-12-31 16:50 . 2008-12-31 16:50 <DIR> d--h----- c:\programdata\CanonBJ
2008-12-31 16:49 . 2008-12-31 16:49 <DIR> d--h----- c:\windows\System32\CanonIJ Uninstaller Information
2008-12-31 16:48 . 2008-12-31 16:48 <DIR> d-------- c:\users\gaetano\{42f783aa-fb51-4134-bc1e-f445c58e65bf}
2008-12-31 16:47 . 2007-03-23 08:30 1,400,832 --a------ c:\windows\System32\CNC310C.DLL
2008-12-31 16:47 . 2007-04-15 21:00 215,040 --a------ c:\windows\System32\CNMLM8Z.DLL
2008-12-31 16:47 . 2007-03-19 02:39 200,704 --a------ c:\windows\System32\CNC310L.DLL
2008-12-31 16:47 . 2007-03-15 06:12 188,416 --a------ c:\windows\System32\CNC310O.DLL
2008-12-31 16:47 . 2007-04-25 11:02 106,496 --a------ c:\windows\System32\CNCFMSd.EXE
2008-12-31 16:47 . 2007-03-23 08:29 98,304 --a------ c:\windows\System32\CNC310I.DLL
2008-12-31 16:47 . 2007-04-25 11:06 3,584 --a------ c:\windows\System32\CNCFLdUS.DLL
2008-12-31 16:47 . 2007-04-25 11:06 3,072 --a------ c:\windows\System32\CNCFLdJP.DLL
2008-12-31 16:46 . 2008-12-31 16:46 <DIR> d--h----- c:\program files\CanonBJ
2008-12-31 16:46 . 2007-04-25 11:09 151,552 --a------ c:\windows\System32\CNCF2Ld.DLL
2008-12-31 16:45 . 2008-12-31 16:59 <DIR> d-------- c:\program files\Canon
2008-12-30 13:46 . 2008-12-30 13:46 1,409 --a------ c:\windows\System32\tmpEC6DD.FOT
2008-12-30 13:46 . 2008-12-30 13:46 1,409 --a------ c:\windows\System32\tmpE59DD.FOT
2008-12-30 13:46 . 2008-12-30 13:46 1,409 --a------ c:\windows\System32\tmpBC9DD.FOT
2008-12-30 13:46 . 2008-12-30 13:46 1,409 --a------ c:\windows\System32\tmpA67DD.FOT
2008-12-30 13:46 . 2008-12-30 13:46 1,409 --a------ c:\windows\System32\tmp628DD.FOT
2008-12-30 13:46 . 2008-12-30 13:46 1,409 --a------ c:\windows\System32\tmp2C8DD.FOT
2008-12-30 13:08 . 2008-12-30 13:08 1,409 --a------ c:\windows\System32\tmpE9D87.FOT
2008-12-30 13:08 . 2008-12-30 13:08 1,409 --a------ c:\windows\System32\tmpD4B87.FOT
2008-12-30 13:08 . 2008-12-30 13:08 1,409 --a------ c:\windows\System32\tmpACB87.FOT
2008-12-30 13:08 . 2008-12-30 13:08 1,409 --a------ c:\windows\System32\tmp66C87.FOT
2008-12-30 13:08 . 2008-12-30 13:08 1,409 --a------ c:\windows\System32\tmp4CC87.FOT
2008-12-30 13:08 . 2008-12-30 13:08 1,409 --a------ c:\windows\System32\tmp13D87.FOT
2008-12-30 13:06 . 2008-12-30 13:06 <DIR> d----c--- c:\windows\System32\DRVSTORE
2008-12-30 13:06 . 2008-12-30 13:06 <DIR> d-------- c:\program files\DIFX
2008-12-27 16:06 . 2005-06-14 11:05 104,576 --a------ c:\windows\System32\drivers\wceusbsh.sys
2008-12-27 13:16 . 2008-12-27 13:16 <DIR> d-------- c:\program files\Foxit Software
2008-12-27 10:35 . 2008-12-27 10:35 <DIR> d-------- c:\program files\Presence 1.0.2
2008-12-26 18:25 . 2009-01-07 15:38 <DIR> d-------- c:\users\gaetano\Posta elettronica
2008-12-26 13:06 . 2008-12-26 13:06 1,409 --a------ c:\windows\System32\tmpE4B8B.FOT
2008-12-26 13:06 . 2008-12-26 13:06 1,409 --a------ c:\windows\System32\tmpBCB8B.FOT
2008-12-26 13:06 . 2008-12-26 13:06 1,409 --a------ c:\windows\System32\tmp83C8B.FOT
2008-12-26 13:06 . 2008-12-26 13:06 1,409 --a------ c:\windows\System32\tmp5AC8B.FOT
2008-12-26 13:06 . 2008-12-26 13:06 1,409 --a------ c:\windows\System32\tmp46A8B.FOT
2008-12-26 13:06 . 2008-12-26 13:06 1,409 --a------ c:\windows\System32\tmp2CA8B.FOT
2008-12-26 12:14 . 2008-12-26 12:14 1,409 --a------ c:\windows\System32\tmpF6940.FOT
2008-12-26 12:14 . 2008-12-26 12:14 1,409 --a------ c:\windows\System32\tmpCE940.FOT
2008-12-26 12:14 . 2008-12-26 12:14 1,409 --a------ c:\windows\System32\tmp9D740.FOT
2008-12-26 12:14 . 2008-12-26 12:14 1,409 --a------ c:\windows\System32\tmp95A40.FOT
2008-12-26 12:14 . 2008-12-26 12:14 1,409 --a------ c:\windows\System32\tmp6DA40.FOT
2008-12-26 12:14 . 2008-12-26 12:14 1,409 --a------ c:\windows\System32\tmp58840.FOT
2008-12-26 12:11 . 2008-12-26 12:11 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2008-12-26 12:10 . 2008-12-26 12:10 <DIR> d-------- C:\col3927
2008-12-26 10:57 . 2008-12-26 10:57 1,409 --a------ c:\windows\System32\tmpFCAA8.FOT
2008-12-26 10:57 . 2008-12-26 10:57 1,409 --a------ c:\windows\System32\tmpE78A8.FOT
2008-12-26 10:57 . 2008-12-26 10:57 1,409 --a------ c:\windows\System32\tmpC4BA8.FOT
2008-12-26 10:57 . 2008-12-26 10:57 1,409 --a------ c:\windows\System32\tmpA29A8.FOT
2008-12-26 10:57 . 2008-12-26 10:57 1,409 --a------ c:\windows\System32\tmp5D9A8.FOT
2008-12-26 10:57 . 2008-12-26 10:57 1,409 --a------ c:\windows\System32\tmp25AA8.FOT
2008-12-26 10:35 . 2008-12-26 10:35 <DIR> d-------- c:\users\gaetano\AppData\Roaming\Cartella di caricamento Share-to-Web
2008-12-26 10:27 . 2008-12-26 10:27 1,409 --a------ c:\windows\System32\tmpF9B69.FOT
2008-12-26 10:27 . 2008-12-26 10:27 1,409 --a------ c:\windows\System32\tmpC0C69.FOT
2008-12-26 10:27 . 2008-12-26 10:27 1,409 --a------ c:\windows\System32\tmpA6C69.FOT
2008-12-26 10:27 . 2008-12-26 10:27 1,409 --a------ c:\windows\System32\tmp83A69.FOT
2008-12-26 10:27 . 2008-12-26 10:27 1,409 --a------ c:\windows\System32\tmp7DC69.FOT
2008-12-26 10:27 . 2008-12-26 10:27 1,409 --a------ c:\windows\System32\tmp4CA69.FOT
2008-12-26 10:23 . 2008-12-26 10:23 1,375 --a------ c:\windows\wininit.ini
2008-12-26 10:23 . 2008-12-26 10:23 726 --a------ c:\windows\reg.prm
2008-12-26 10:22 . 2001-05-15 20:04 114,765 --a------ c:\windows\System32\hpzlnt03.dll
2008-12-26 10:22 . 2008-12-26 10:22 376 --a------ c:\windows\mozregistry.dat
2008-12-26 10:13 . 2007-01-17 01:23 438,272 --a------ c:\windows\System32\hp3500co.dll
2008-12-24 18:01 . 2008-12-24 18:01 <DIR> d-------- c:\users\gaetano\AppData\Roaming\OpenOffice.org
2008-12-24 17:59 . 2009-01-09 20:31 <DIR> d-------- c:\program files\OpenOffice.org 3
2008-12-24 12:21 . 2008-12-24 12:21 8 --a------ c:\windows\mex.tdv
2008-12-23 15:04 . 2008-12-23 15:04 <DIR> d-------- c:\program files\CNS Manager
2008-12-23 13:59 . 2009-01-16 14:46 <DIR> d-------- c:\users\All Users\RFA_Backups
2008-12-23 13:59 . 2009-01-16 14:46 <DIR> d-------- c:\programdata\RFA_Backups
2008-12-23 13:59 . 2008-12-23 13:59 <DIR> d-------- c:\program files\RFA Platinum
2008-12-23 12:18 . 2009-01-14 15:49 <DIR> d-------- c:\users\All Users\Google
2008-12-23 12:16 . 2009-01-14 15:49 <DIR> d-------- c:\program files\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-15 08:28 --------- d-----w c:\program files\Windows Mail
2009-01-09 11:56 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-09 11:56 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-09 11:56 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-09 11:56 --------- d-----w c:\program files\Symantec
2009-01-03 12:54 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-01 10:05 --------- d-----w c:\program files\Hewlett-Packard
2008-12-31 20:21 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-24 16:58 --------- d-----w c:\program files\Java
2008-12-23 21:02 --------- d-----w c:\programdata\Symantec
2008-12-21 12:15 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-21 09:08 --------- d-----w c:\program files\Windows Sidebar
2008-12-21 09:07 --------- d-sh--w c:\programdata\Preferiti
2008-12-21 09:07 --------- d-sh--w c:\programdata\Modelli
2008-12-21 09:07 --------- d-sh--w c:\programdata\Menu Avvio
2008-12-21 09:07 --------- d-sh--w c:\programdata\Documenti
2008-12-21 09:07 --------- d-sh--w c:\programdata\Dati applicazioni
2008-12-21 09:07 --------- d-sh--w c:\program files\File comuni
2008-12-21 09:02 --------- d-----w c:\programdata\Hewlett-Packard
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 ----a-w c:\windows\System32\tzres.dll
2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-07-03 972080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-12-21 160592]
"MoneyAgent"="c:\program files\Microsoft Money\System\Money Express.exe" [1999-08-04 122944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15360]
"rfagent"="c:\program files\RFA Platinum\rfagent.exe" [2007-06-12 617088]
"Certificate Synchronizer"="c:\windows\OcsCertSynchronizer.exe" [2006-06-07 24576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-01-13 1168264]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
Presence.lnk - c:\program files\Presence 1.0.2\Presence.exe [2008-12-27 1519104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{073F96F4-E78F-452B-BE18-9CC29BAD7A8D}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{67FFD49D-8D64-4203-848A-7A851DE4DA30}"= UDP:c:\program files\deepinvent\MailStore Home\MailStoreLocal.exe:MailStore Home
"{C4B8ED0F-657A-438D-BA0D-D78B356839F2}"= TCP:c:\program files\deepinvent\MailStore Home\MailStoreLocal.exe:MailStore Home
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090113.002\IDSvix86.sys [2009-01-15 270384]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-21 99376]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2008-06-13 41008]
R4 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [2008-01-21 21504]
R4 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2008-02-06 149352]
R4 OCSCryptolibService;Oberthur Cryptolib Service;c:\windows\OCSCryptolib_Server.exe [2008-12-23 139264]
R4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-13 356920]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2008-01-12 23888]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - COMHOST
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contenuto della cartella 'Scheduled Tasks'
2008-12-21 c:\windows\Tasks\HPCeeScheduleForgaetano.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2007-12-17 19:03]
2008-12-22 c:\windows\Tasks\Norton Internet Security - Scansione completa sistema - gaetano.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 01:05]
2009-01-13 c:\windows\Tasks\Schedule Task Weekly.job
- c:\program files\Registry Easy\RE.exe []
2009-01-14 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2009-01-03 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2009-01-16 c:\windows\Tasks\User_Feed_Synchronization-{99597633-B38F-475C-8F91-18CB504975A7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 03:24]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://virgilio.alice.it/
uLocal Page = c:\program files\Hewlett-Packard\HP Software UI\Easy Internet Signup\Common\templates\general\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=84&bd=Presario&pf=cndt
mLocal Page = c:\program files\Hewlett-Packard\HP Software UI\Easy Internet Signup\Common\templates\general\blank.htm
IE: Compila Modulo - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Personalizza - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: RF Barra strumenti - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Salva Moduli - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-16 17:12:26
Windows 6.0.6001 Service Pack 1 NTFS
detected NTDLL code modification:
ZwClose
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\combofix\hidec.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\spool\drivers\w32x86\3\WrtProc.exe
c:\windows\System32\WerFault.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\combofix\Catchme.tmp
.
**************************************************************************
.
Ora fine scansione: 2009-01-16 17:17:31 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-01-16 16:15:56
Pre-Run: 232.937.676.800 byte disponibili
Post-Run: 232,993,472,512 byte disponibili
338 --- E O F --- 2009-01-15 08:28:22