ComboFix 09-05-09.04 - DAVIDE 10/05/2009 17.17.13.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.767.520 [GMT 2:00]
Eseguito da: c:\documents and settings\DAVIDE\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated)
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\DAVIDE\Preferiti\Attivazione immagini.exe
c:\documents and settings\DAVIDE\Preferiti\Ricerca rapida.exe
.
((((((((((((((((((((((((( Files Creati Da 2009-04-10 al 2009-05-10 )))))))))))))))))))))))))))))))))))
.
2009-05-10 14:20 . 2009-05-10 14:20 -------- d-----w c:\programmi\SpywareBlaster
2009-05-10 14:19 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-10 14:19 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-10 14:19 . 2009-05-10 14:19 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-05-10 14:19 . 2009-05-10 14:19 -------- d-----w c:\programmi\Spybot - Search & Destroy
2009-05-05 20:55 . 2009-05-05 20:55 -------- d-----w c:\documents and settings\DAVIDE\DoctorWeb
2009-05-03 11:44 . 2009-05-03 11:44 -------- d-----w c:\documents and settings\DAVIDE\Dati applicazioni\Ashampoo
2009-05-03 09:22 . 2009-05-03 09:22 -------- d-----w c:\programmi\Ashampoo
2009-05-03 09:04 . 2009-05-03 09:04 -------- d-----w c:\programmi\CDBurnerXP
2009-05-03 08:46 . 2009-05-03 08:46 -------- d-----w c:\documents and settings\DAVIDE\Impostazioni locali\Dati applicazioni\ashampoo
2009-05-03 08:46 . 2009-05-03 08:46 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\ashampoo
2009-04-29 20:31 . 2009-04-29 20:31 -------- d-----w c:\documents and settings\DAVIDE\Dati applicazioni\dvdcss
2009-04-22 19:36 . 2009-04-22 19:36 -------- d-----w c:\documents and settings\DAVIDE\Dati applicazioni\vlc
2009-04-22 19:29 . 2009-04-22 19:29 -------- d-----w c:\programmi\VideoLAN
2009-04-22 17:58 . 2008-05-29 07:28 28416 ----a-w c:\windows\system32\uxtuneup.dll
2009-04-22 17:57 . 2009-04-22 17:58 355584 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-04-22 17:57 . 2009-04-22 17:57 -------- d-----w c:\documents and settings\DAVIDE\Dati applicazioni\TuneUp Software
2009-04-22 17:57 . 2009-04-22 17:57 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\TuneUp Software
2009-04-22 17:57 . 2009-04-22 17:57 -------- d-----w c:\programmi\TuneUp Utilities 2008
2009-04-19 10:52 . 2009-04-19 10:52 -------- d-----w c:\documents and settings\DAVIDE\advfn
2009-04-15 19:00 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 19:00 . 2009-03-06 14:19 286208 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-15 19:00 . 2009-02-09 11:22 111104 ------w c:\windows\system32\dllcache\services.exe
2009-04-15 19:00 . 2009-02-09 10:51 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 19:00 . 2009-02-09 10:51 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 19:00 . 2009-02-09 10:51 683520 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 19:00 . 2009-02-09 10:51 734720 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 19:00 . 2009-02-09 10:51 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 19:00 . 2009-02-09 10:51 736256 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 19:00 . 2008-04-21 21:14 219136 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-12 05:46 . 2008-10-16 12:06 208744 ----a-w c:\windows\system32\muweb.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 11:11 . 2009-04-03 20:33 55640 ----a-w c:\windows\system32\drivers\AVGNTFLT.SYS
2009-04-26 05:41 . 1979-12-31 22:00 558548 ----a-w c:\windows\system32\perfh010.dat
2009-04-26 05:41 . 1979-12-31 22:00 116608 ----a-w c:\windows\system32\perfc010.dat
2009-04-22 18:16 . 2005-09-24 15:21 53296 ----a-w c:\documents and settings\DAVIDE\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-02 19:43 . 2008-12-20 06:33 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-02 19:43 . 2009-04-02 19:43 -------- d-----w c:\programmi\Java
2009-04-02 19:25 . 2009-04-02 19:25 0 ----a-w c:\windows\system32\RENC8.tmp
2009-04-02 19:25 . 2009-04-02 19:25 0 ----a-w c:\windows\system32\RENC7.tmp
2009-04-02 19:25 . 2009-04-02 19:25 0 ----a-w c:\windows\system32\RENC6.tmp
2009-04-01 17:57 . 2009-04-01 17:57 0 ----a-w c:\windows\system32\REN43.tmp
2009-03-06 14:19 . 1979-12-31 22:00 286208 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:03 . 1979-12-31 22:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 17:08 . 1979-12-31 22:00 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-10 17:02 . 2004-08-19 13:34 2069760 ----a-w c:\windows\system32\ntkrnlpa.exe
2007-06-04 22:58 . 2007-06-04 22:58 16 ----a-w c:\programmi\File comuni\dht342126
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\programmi\Microsoft ActiveSync\wcescomm.exe" [2006-06-21 1211176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"preload"="c:\windows\RUNXMLPL.exe" [2004-04-20 40960]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 98304]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 536576]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2004-08-06 32768]
"PowerKey"="c:\program files\Launch Manager\PowerKey.exe" [2002-08-30 94208]
"LManager"="c:\program files\Launch Manager\HotkeyApp.exe" [2004-07-15 49152]
"CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2004-01-28 184320]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2004-09-08 245760]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2004-08-13 73728]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-13 4141056]
"PCMService"="c:\program files\Arcade\PCMService.exe" [2004-08-27 81920]
"LtMoh"="c:\programmi\ltmoh\Ltmoh.exe" [2003-04-28 184320]
"CameraFixer"="c:\windows\CameraFixer.exe" [2006-12-05 20480]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-09-26 270336]
"mxomssmenu"="c:\programmi\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-04-02 148888]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2004-06-22 143360]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2004-09-01 53248]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-07-13 880640]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-12-03 88358]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^LUMIX Simple Viewer.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\LUMIX Simple Viewer.lnk
backup=c:\windows\pss\LUMIX Simple Viewer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\dbMaster\\dbMaster.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\programmi\Microsoft ActiveSync\rapimgr.exe"= c:\programmi\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programmi\Microsoft ActiveSync\wcescomm.exe"= c:\programmi\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programmi\Microsoft ActiveSync\WCESMgr.exe"= c:\programmi\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 Hotkey;Hotkey;c:\windows\system32\drivers\HOTKEY.sys [02/01/2003 2.44.25 9867]
R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [20/09/2004 17.37.24 10363]
R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [01/06/2004 11.50.50 4054]
R3 POWERKEY;POWERKEY;c:\program files\Launch Manager\POWERKEY.SYS [02/01/2003 2.44.25 2343]
S1 mailKmd;mailKmd; [x]
S1 Wbutton;Wbutton;c:\windows\system32\drivers\Wbutton.sys --> c:\windows\system32\drivers\Wbutton.sys [?]
S3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [17/09/2004 4.15.56 140288]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce64f77a-6eb4-11dd-8721-000ae4a71155}]
\Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://investitoreaccorto.investireoggi.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
DPF: Microsoft XML Parser for Java
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-10 17:18
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-2565205313-2169451094-2625584673-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4984C1BD-A071-EDD8-4F51-0D959B4755F1}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-2565205313-2169451094-2625584673-1005\Software\Microsoft\Windows Mobile Disc\W*i*n*d*o*w*s* *M*o*b*i*l*e*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2565205313-2169451094-2625584673-1005\Software\Microsoft\Windows Mobile Disc\W*i*n*d*o*w*s* *M*o*b*i*l*e*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2565205313-2169451094-2625584673-1005\Software\Microsoft\Windows Mobile Disc\W*i*n*d*o*w*s* *M*o*b*i*l*e*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2565205313-2169451094-2625584673-1005\Software\Microsoft\Windows Mobile Disc\W*i*n*d*o*w*s* *M*o*b*i*l*e*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2565205313-2169451094-2625584673-1005\Software\Microsoft\Windows Mobile Disc\W*i*n*d*o*w*s* *M*o*b*i*l*e*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b
.
Ora fine scansione: 2009-05-10 17.20.04
ComboFix-quarantined-files.txt 2009-05-10 15:20
Pre-Run: 10.630.905.856 byte disponibili
Post-Run: 10.657.398.784 byte disponibili
191 --- E O F --- 2009-03-11 06:44