ComboFix 09-02-04.04 - Chico 2009-02-05 13.38.58.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.1535.917 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Documenti\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090204-0] *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-01-05 al 2009-02-05 )))))))))))))))))))))))))))))))))))
.
2009-02-05 13:23 . 2009-02-05 13:24 <DIR> d-------- c:\windows\LastGood
2009-02-05 13:21 . 2009-02-05 13:23 <DIR> d-------- c:\windows\AiOTemp
2009-02-05 12:38 . 2009-02-05 12:38 <DIR> d-------- c:\documents and settings\Utente\Dati applicazioni\Cartella di caricamento Share-to-Web
2009-02-05 12:38 . 2001-09-13 17:52 38,912 -ra------ c:\windows\system32\hh.exe
2009-02-05 12:38 . 2002-04-10 02:56 22,139 -ra------ c:\windows\system32\hpocoi08.dll
2009-02-05 12:38 . 2009-02-05 13:23 20 --a------ c:\windows\Hposcv07.INI
2009-02-05 12:36 . 2009-02-05 12:38 <DIR> d-------- c:\programmi\Hewlett-Packard
2009-02-05 00:46 . 2009-02-05 11:07 250 --a------ c:\windows\gmer.ini
2009-02-03 22:55 . 2008-08-30 12:11 40,960 --a------ c:\windows\system32\drivers\VIRAGTLT.SYS
2009-02-03 22:54 . 2009-02-05 13:29 <DIR> d-------- C:\VEXPLITE
2009-02-02 22:31 . 2009-02-02 22:31 <DIR> d-------- c:\programmi\CCleaner
2009-02-02 10:37 . 2009-02-02 10:37 <DIR> d-------- c:\programmi\Trend Micro
2009-02-01 20:27 . 2009-02-01 20:27 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-02-01 20:27 . 2009-02-01 20:27 <DIR> d-------- c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2009-02-01 20:27 . 2009-02-01 20:27 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-02-01 20:27 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-01 20:27 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-01 15:58 . 2009-02-02 21:45 <DIR> d-------- c:\programmi\Spybot - Search & Destroy
2009-02-01 15:58 . 2009-02-02 19:20 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-01-19 12:09 . 2009-02-05 12:54 <DIR> d-------- c:\windows\system32\NtmsData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-05 12:24 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\Skype
2009-02-05 11:44 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\skypePM
2009-02-05 11:38 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-04 15:45 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Yahoo!
2009-01-15 11:46 --------- d-----w c:\programmi\Messenger Plus! Live
2009-01-14 23:58 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-01-04 15:52 --------- d-----w c:\programmi\Java
2008-12-31 16:04 691,560 ----a-w c:\windows\system32\OGACheckControl.dll
2008-12-31 16:04 528,744 ----a-w c:\windows\system32\OGAVerify.exe
2008-12-31 16:04 502,120 ----a-w c:\windows\system32\OGAAddin.dll
2008-12-26 21:25 --------- d-----w c:\programmi\iTunes
2008-12-26 21:25 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\Apple Computer
2008-12-26 21:24 --------- d-----w c:\programmi\iPod
2008-12-26 21:24 --------- d-----w c:\programmi\File comuni\Apple
2008-12-26 21:24 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2008-12-26 21:23 --------- d-----w c:\programmi\QuickTime
2008-12-26 21:22 --------- d-----w c:\programmi\Apple Software Update
2008-12-26 19:11 5,632 ----a-w c:\windows\system32\drivers\StarOpen.sys
2008-12-26 18:02 --------- d-----w c:\programmi\Samsung
2008-12-22 15:32 --------- d-----w c:\programmi\Windows Live SkyDrive
2008-12-22 15:32 --------- d-----w c:\programmi\Microsoft
2008-12-22 15:31 --------- d-----w c:\programmi\Windows Live
2008-12-22 15:24 --------- d-----w c:\programmi\File comuni\Windows Live
2008-12-18 14:36 --------- d-----w c:\programmi\Warcraft III
2008-12-17 14:50 2,829 ----a-w c:\windows\War3Unin.pif
2008-12-17 14:50 139,264 ----a-w c:\windows\War3Unin.exe
2008-12-16 09:26 --------- d-----w c:\programmi\eMule AdunanzA
2008-12-15 21:54 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\uTorrent
2008-12-15 08:59 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\Samsung
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-09 13:44 --------- d-----w c:\programmi\SlySoft
2008-12-02 21:37 49,480 ----a-w c:\windows\system32\sirenacm.dll
2008-11-10 04:43 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-04-22 11:57 32 ----a-w c:\documents and settings\All Users\Dati applicazioni\ezsid.dat
2007-11-16 09:44 62,328 ----a-w c:\documents and settings\Utente\Dati applicazioni\GDIPFONTCACHEV1.DAT
2006-03-02 12:00 94,816 --sh--w c:\windows\twain.dll
2008-04-14 02:13 50,688 --sh--w c:\windows\twain_32.dll
2008-04-14 02:13 1,028,096 --sh--w c:\windows\system32\mfc42.dll
2008-04-14 02:13 57,344 --sh--w c:\windows\system32\msvcirt.dll
2008-04-14 02:13 413,696 --sh--w c:\windows\system32\msvcp60.dll
2008-04-14 02:13 343,040 --sh--w c:\windows\system32\msvcrt.dll
2008-04-14 02:13 551,936 --sh--w c:\windows\system32\oleaut32.dll
2008-04-14 02:13 84,992 --sh--w c:\windows\system32\olepro32.dll
2008-04-14 02:14 12,288 --sh--w c:\windows\system32\regsvr32.exe
2008-09-08 09:06 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008090820080909\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-25 68856]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2008-02-29 21898024]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"Philips Intelligent Agent"="c:\programmi\Philips\Intelligent Agent\Philips Intelligent Agent.exe" [2008-02-21 613792]
"LightScribe Control Panel"="c:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-17 81920]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 63712]
"DAEMON Tools"="c:\programmi\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"Acrobat Assistant 8.0"="c:\programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992]
"WinampAgent"="c:\programmi\Winamp\winampa.exe" [2008-08-04 36352]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Share-to-Web Namespace Daemon"="c:\programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"nwiz"="nwiz.exe" [2007-09-17 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-10-24 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HPAiODevice(hp psc 700 series) - 1.lnk - c:\programmi\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe [2002-04-24 487484]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-04 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-04 20560]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.sys [2005-02-24 162176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-02-01 38496]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'
2009-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-02-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-Ad-Watch - c:\programmi\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.juventus.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: Append to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-05 13:41:18
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2009-02-05 13.43.46
ComboFix-quarantined-files.txt 2009-02-05 12:43:00
Pre-Run: 13.984.989.184 byte disponibili
Post-Run: 14,196,830,208 byte disponibili
178 --- E O F --- 2009-02-05 10:06:35