ComboFix 09-01-16.03 - Paolo 2009-01-17 15.51.50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1022.680 [GMT 1:00]
Eseguito da: c:\documents and settings\Paolo\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090116-1] *On-access scanning disabled* (Outdated)
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\wmemsae.dat
c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\wmemsae.exe
c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\wmemsae_nav.dat
c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\wmemsae_navps.dat
----- BITS: Possibili siti infetti -----
hxxp://blog.roodo.com
.
((((((((((((((((((((((((( Files Creati Da 2008-12-17 al 2009-01-17 )))))))))))))))))))))))))))))))))))
.
2009-01-16 22:03 . 2009-01-16 22:25 4,700,372,992 --a------ C:\Foto ultimi album.mdf
2009-01-16 22:03 . 2009-01-16 22:25 4,314 --a------ C:\Foto ultimi album.mds
2009-01-16 14:15 . 2009-01-16 14:15 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-16 14:15 . 2009-01-16 14:15 1,409 --a------ c:\windows\QTFont.for
2009-01-16 02:33 . 2009-01-16 02:33 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-01-16 02:33 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-16 02:33 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-16 02:23 . 2009-01-16 02:23 66,048 --a------ C:\mbr.exe
2009-01-15 02:34 . 2009-01-15 02:34 <DIR> d-------- c:\documents and settings\Paolo\Dati applicazioni\Malwarebytes
2009-01-15 02:34 . 2009-01-15 02:34 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-01-15 02:21 . 2009-01-17 11:26 <DIR> d-------- c:\programmi\Enigma Software Group
2009-01-14 19:26 . 2009-01-14 19:45 <DIR> d-------- c:\programmi\Anti Trojan Elite
2009-01-14 16:03 . 2009-01-14 19:17 <DIR> d-------- c:\programmi\Fighters
2009-01-14 16:03 . 2009-01-14 16:03 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Fighters
2009-01-06 13:49 . 2009-01-06 13:49 <DIR> d-------- c:\documents and settings\Attilio\Contacts
2008-12-29 20:03 . 2008-12-29 20:03 <DIR> d-------- c:\programmi\IrfanView
2008-12-27 01:35 . 2008-12-27 01:35 <DIR> d-------- c:\programmi\Blaze Audio
2008-12-26 22:28 . 2008-12-29 12:54 73 --ahs---- c:\windows\system32\SYSDRV004.SYS
2008-12-26 22:28 . 2008-12-26 22:28 61 --a------ c:\windows\system32\SYSTMBXNDRV.SYS
2008-12-26 16:10 . 2008-12-26 16:10 0 --a------ c:\windows\RealOrch.INI
2008-12-26 16:06 . 2008-12-26 16:06 <DIR> d-------- c:\documents and settings\Paolo\WINDOWS
2008-12-26 16:06 . 1995-11-28 02:42 283,648 --a------ c:\windows\uninst.exe
2008-12-26 15:53 . 2008-12-26 15:55 <DIR> d-------- c:\programmi\REAPER
2008-12-26 15:53 . 2008-12-26 15:53 <DIR> d-------- c:\documents and settings\Paolo\Dati applicazioni\REAPER
2008-12-26 15:42 . 2008-12-26 15:44 265 --a------ c:\windows\ar.INI
2008-12-26 15:18 . 2008-12-26 15:18 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\NCH Swift Sound
2008-12-26 14:18 . 2008-10-16 21:04 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-12-26 14:18 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-12-26 14:18 . 2007-03-08 06:11 1,032,192 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-26 14:18 . 2008-10-16 21:04 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-12-26 14:18 . 2008-10-16 21:04 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-12-26 14:18 . 2008-10-16 21:04 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-12-26 14:18 . 2008-10-16 21:04 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-12-26 14:18 . 2008-10-16 21:04 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-26 14:18 . 2008-10-16 14:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-12-26 02:46 . 2008-12-26 15:29 <DIR> d-------- c:\programmi\Karaoke Star
2008-12-26 02:46 . 2008-12-26 02:46 253,952 --------- c:\windows\Setup1.exe
2008-12-26 02:46 . 2008-12-26 02:46 74,752 --a------ c:\windows\ST6UNST.EXE
2008-12-25 20:42 . 2008-12-25 20:42 <DIR> d-------- c:\documents and settings\Attilio\Dati applicazioni\Yahoo!
2008-12-24 01:15 . 2009-01-16 14:09 <DIR> d-------- c:\programmi\PhotoScape
2008-12-23 23:30 . 2008-12-23 23:54 <DIR> d-------- c:\programmi\Collage Maker
2008-12-23 15:16 . 2008-12-23 15:16 <DIR> d-------- c:\programmi\FirmTools
2008-12-23 15:05 . 2008-12-24 01:01 <DIR> d-------- c:\programmi\webGobbler
2008-12-23 14:28 . 2008-12-23 14:42 1,553 --a------ C:\Lotto avorio A.dbr
2008-12-18 19:58 . 2008-12-18 19:58 <DIR> d-------- c:\programmi\Trend Micro
2008-12-18 14:47 . 2008-12-02 11:20 102,479 --------- c:\windows\hpoins05.dat.temp
2008-12-18 14:47 . 2005-06-22 08:47 17,505 --------- c:\windows\hpomdl07.dat
2008-12-17 14:04 . 2008-12-17 14:04 <DIR> d-------- c:\programmi\XnView
2008-12-17 14:04 . 2009-01-11 23:46 <DIR> d-------- c:\documents and settings\Paolo\Dati applicazioni\XnView
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-17 13:03 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Ulead Systems
2009-01-16 20:56 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\dvdcss
2009-01-08 21:40 --------- d-----w c:\programmi\eMule
2009-01-05 09:11 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\Arcsoft
2008-12-30 03:11 --------- d-----w c:\programmi\Google
2008-12-15 11:53 --------- d-----w c:\programmi\Picasa2
2008-12-15 11:04 --------- d-----w c:\programmi\Slideshow pro
2008-12-15 10:54 --------- d-----w c:\programmi\mresreg
2008-12-15 10:50 --------- d--h--w c:\programmi\InstallShield Installation Information
2008-12-15 10:50 --------- d-----w c:\programmi\CyberLink
2008-12-15 10:49 --------- d-----w c:\programmi\DivX
2008-12-15 10:05 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\SmartSound Software Inc
2008-12-15 10:01 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\CyberLink
2008-12-15 09:48 4,704 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-12-15 09:15 --------- d-----w c:\programmi\File comuni\ACD Systems
2008-12-15 03:07 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\ACD Systems
2008-12-15 00:56 --------- d-----w c:\programmi\Extra Photo SlideShow Free
2008-12-15 00:32 --------- d-----w c:\programmi\Photo Story 3 for Windows
2008-12-14 11:08 --------- d-----w c:\programmi\Microsoft Calculator Plus
2008-12-12 00:06 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\Pegasys Inc
2008-12-12 00:00 --------- d-----w c:\programmi\Pegasys Inc
2008-12-11 14:28 --------- d-----w c:\programmi\Acoolsoft
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-09 20:13 223,128 ----a-w c:\windows\system32\drivers\vaxscsi.sys
2008-12-09 20:07 --------- d-----w c:\programmi\Alcohol Soft
2008-12-09 20:05 96,384 ----a-w c:\windows\system32\drivers\sptd1133.sys
2008-12-09 20:05 642,560 ----a-w c:\windows\system32\drivers\sptd.sys
2008-12-06 09:48 164,352 ----a-w c:\windows\system32\SpoonUninstall.exe
2008-12-06 09:48 --------- d-----w c:\programmi\Illustrate
2008-12-06 09:32 --------- d-----w c:\programmi\MP3Gain
2008-12-06 09:28 --------- d-----w c:\programmi\Java
2008-12-04 22:30 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\Ahead
2008-12-04 22:28 --------- d-----w c:\programmi\File comuni\Ahead
2008-12-04 22:28 --------- d-----w c:\programmi\Ahead
2008-12-04 22:28 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Ahead
2008-12-04 22:22 --------- d-----w c:\programmi\ArcSoft
2008-12-04 22:10 4,608 ----a-w c:\windows\system32\w95inf32.dll
2008-12-04 22:10 2,272 ----a-w c:\windows\system32\w95inf16.dll
2008-12-04 09:40 --------- d-----w c:\programmi\Windows Live
2008-12-04 00:08 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\Ulead Systems
2008-12-04 00:07 --------- d-----w c:\programmi\File comuni\InstallShield
2008-12-04 00:06 --------- d-----w c:\programmi\File comuni\SONY Digital Images
2008-12-04 00:05 --------- d-----w c:\programmi\Windows Media Components
2008-12-04 00:05 --------- d-----w c:\programmi\Ulead Systems
2008-12-04 00:05 --------- d-----w c:\programmi\File comuni\Ulead Systems
2008-12-03 22:19 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\Windows Live Writer
2008-12-03 22:12 --------- d-----w c:\programmi\Microsoft SQL Server Compact Edition
2008-12-03 22:05 --------- dcsh--w c:\programmi\File comuni\WindowsLiveInstaller
2008-12-03 22:03 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\WLInstaller
2008-12-03 08:38 --------- d-----w c:\programmi\Unlocker
2008-12-02 22:46 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Yahoo!
2008-12-02 22:39 --------- d-----w c:\programmi\Yahoo!
2008-12-02 20:23 --------- d-----w c:\programmi\MailNavigator
2008-12-02 10:42 --------- d-----w c:\programmi\Spybot - Search & Destroy
2008-12-02 10:41 --------- d-----w c:\programmi\CyberLink DVD Solution
2008-12-02 10:22 --------- d-----w c:\programmi\File comuni\Adobe
2008-12-02 10:16 --------- d-----w c:\programmi\File comuni\Hewlett-Packard
2008-12-02 10:15 --------- d-----w c:\programmi\HP
2008-12-02 09:43 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-12-02 02:35 82,464 ----a-w c:\windows\system32\drivers\snapman.sys
2008-12-02 02:35 37,888 ----a-w c:\windows\system32\setupnt.dll
2008-12-02 02:35 28,896 ----a-w c:\windows\system32\drivers\tifsfilt.sys
2008-12-02 02:35 211,520 ----a-w c:\windows\system32\drivers\timntr.sys
2008-12-02 02:35 126,976 ----a-w c:\windows\system32\snapapi.dll
2008-12-02 02:35 --------- d-----w c:\programmi\File comuni\Acronis
2008-12-02 02:35 --------- d-----w c:\programmi\Acronis
2008-12-02 02:25 --------- d-----w c:\programmi\TeaTimer (Spybot - Search & Destroy)
2008-12-02 02:25 --------- d-----w c:\programmi\SDHelper (Spybot - Search & Destroy)
2008-12-02 02:25 --------- d-----w c:\programmi\Misc. Support Library (Spybot - Search & Destroy)
2008-12-02 02:25 --------- d-----w c:\programmi\File Scanner Library (Spybot - Search & Destroy)
2008-12-02 01:51 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\Yahoo!
2008-12-02 01:51 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2008-12-02 01:10 --------- d-----w c:\programmi\ATI Technologies
2008-12-02 00:58 --------- d-----w c:\programmi\Analog Devices
2008-12-02 00:05 --------- d-----w c:\programmi\RegSeeker
2008-12-02 00:00 --------- d-----w c:\programmi\Lavasoft
2008-12-01 23:56 --------- d-----w c:\programmi\Riva
2008-12-01 23:56 --------- d-----w c:\programmi\File comuni\SWF Studio
2008-12-01 23:53 --------- d-----w c:\programmi\VideoLAN
2008-12-01 23:53 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\vlc
2008-12-01 23:52 --------- d-----w c:\programmi\Lavalys
2008-12-01 23:51 --------- d-----w c:\programmi\ToniArts
2008-12-01 23:51 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\DeepBurner
2008-12-01 23:50 --------- d-----w c:\programmi\Astonsoft
2008-12-01 23:50 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\Media Player Classic
2008-12-01 23:49 --------- d-----w c:\programmi\K-Lite Codec Pack
2008-12-01 23:49 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2008-12-01 23:48 --------- d-----w c:\documents and settings\Paolo\Dati applicazioni\Lavasoft
2008-12-01 23:29 --------- d-----w c:\programmi\Alwil Software
2008-12-01 23:16 --------- d-----w c:\programmi\Thomson
2008-12-01 23:16 --------- d-----w c:\programmi\Telecom Italia
2008-12-01 22:55 --------- d-----w c:\programmi\microsoft frontpage
2008-12-01 22:53 --------- d-----w c:\programmi\Servizi in linea
2008-11-10 04:43 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2006-10-19 15:30 533,574 ----a-w c:\programmi\pllangs.exe
2006-10-19 15:28 2,855,080 ----a-w c:\programmi\aawsepersonal.exe
2006-10-16 16:04 2,958 ----a-w c:\programmi\LEGGIMI.htm
2004-03-18 16:00 40,960 ----a-w c:\programmi\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-01 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="c:\programmi\Thomson\SpeedTouch USB\Dragdiag.exe" [2003-09-05 878080]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"msacm.dvacm"= c:\progra~1\FILECO~1\ULEADS~1\Vio\Dvacm.acm
"VIDC.ACDV"= ACDV.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 111184]
R3 VAD_DEV;Virtual Audio Service;c:\windows\system32\drivers\vad.sys [2008-12-11 16384]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-02 20560]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\programmi\Anti Trojan Elite\ATEPMon.sys --> c:\programmi\Anti Trojan Elite\ATEPMon.sys [?]
.
.
------- Scansione supplementare -------
.
uStart Page =
www.libero.it/uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Paolo\Dati applicazioni\Mozilla\Firefox\Profiles\zo9mrluv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2120366&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Nova-IT Customized Web Search
FF - prefs.js: browser.startup.homepage -
www.libero.itFF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2120366&SearchSource=2&q=
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\programmi\Picasa2\npPicasa2.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-17 15:53:34
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-01-17 15.54.51
ComboFix-quarantined-files.txt 2009-01-17 14:54:49
Pre-Run: 7.071.154.176 byte disponibili
Post-Run: 9,394,180,096 byte disponibili
240 --- E O F --- 2009-01-14 02:00:16