ComboFix 09-06-10.02 - Admin 11/06/2009 10.47.07.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.512.184 [GMT 2:00]
Eseguito da: c:\documents and settings\Admin\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090610-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\QUAD Utilities
c:\documents and settings\Admin\ResErrors.log
.
((((((((((((((((((((((((( Files Creati Da 2009-05-11 al 2009-06-11 )))))))))))))))))))))))))))))))))))
.
2009-06-11 08:47 . 2009-06-11 08:47 -------- d-----w- c:\windows\LastGood
2009-06-09 13:09 . 2009-06-09 13:09 49152 ----a-r- c:\documents and settings\Admin\Dati applicazioni\Microsoft\Installer\{7C4196CA-CA41-4F34-9C08-7724E7705D52}\NewShortcut1_7C4196CACA414F349C087724E7705D52.exe
2009-06-09 13:09 . 2009-06-09 13:09 10134 ----a-r- c:\documents and settings\Admin\Dati applicazioni\Microsoft\Installer\{7C4196CA-CA41-4F34-9C08-7724E7705D52}\ARPPRODUCTICON.exe
2009-06-09 12:58 . 2009-06-09 12:58 -------- d-----w- c:\windows\system32\Librerie XP e Vista
2009-06-09 12:17 . 2009-06-09 12:17 -------- d-----w- c:\programmi\Jasc Software Inc
2009-06-05 09:00 . 2009-05-30 12:55 38208 ----a-w- c:\documents and settings\Admin\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-05-30 13:18 . 2009-05-30 13:18 -------- d-----w- c:\documents and settings\Admin\Dati applicazioni\GlarySoft
2009-05-30 12:58 . 2009-05-30 12:58 -------- d-----w- c:\documents and settings\Admin\Dati applicazioni\it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1
2009-05-30 12:56 . 2009-05-30 12:56 -------- d-----w- c:\programmi\File comuni\Adobe AIR
2009-05-27 12:35 . 2009-05-27 12:35 -------- d-----w- c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\Clock_22
2009-05-25 12:47 . 2009-05-25 12:47 2967799 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-25 12:40 . 2009-05-25 12:40 -------- d-----w- c:\windows\system32\PolarClock3 dir
2009-05-20 12:45 . 2009-05-20 12:45 -------- d-----w- c:\documents and settings\Admin\Dati applicazioni\Auslogics
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 09:37 . 2002-10-04 17:03 70964 ----a-w- c:\windows\system32\perfc010.dat
2009-06-10 09:37 . 2002-10-04 17:03 440738 ----a-w- c:\windows\system32\perfh010.dat
2009-05-22 08:29 . 2008-12-30 14:07 1 ----a-w- c:\documents and settings\Admin\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-05-07 09:26 . 2005-12-06 12:54 76875 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-04-20 12:26 . 2009-04-20 12:26 -------- d-----w- c:\programmi\File comuni\PCSuite
2009-04-20 12:25 . 2009-04-20 12:25 -------- d-----w- c:\programmi\File comuni\Nokia
2009-04-20 12:23 . 2009-04-20 12:22 -------- d-----w- c:\programmi\PC Connectivity Solution
2009-04-20 12:19 . 2009-04-20 12:19 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-04-20 12:19 . 2009-04-20 12:19 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-04-20 12:19 . 2009-04-20 12:19 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-04-20 12:19 . 2009-04-20 12:20 34447128 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_ita.exe
2009-04-20 12:11 . 2009-04-20 12:11 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-04-20 12:11 . 2009-04-20 12:11 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-04-06 13:32 . 2009-02-25 12:04 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2009-02-25 12:04 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-28 13:59 . 2009-03-28 13:59 27136 ----a-w- c:\windows\system32\drivers\nchssvad.sys
2009-03-19 11:48 . 2009-04-20 12:21 136704 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2009-03-19 11:48 . 2009-04-20 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2008-09-22 14:21 . 2008-08-27 09:47 7518 --sha-w- c:\windows\system32\KGyGaAvL.sys
2008-09-22 14:19 . 2008-08-27 09:47 88 --sh--r- c:\windows\system32\BCD1FABB0B.sys
2008-09-01 09:59 . 2008-08-30 15:42 56 --sh--r- c:\windows\system32\
0BBBFAD1BC.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-10 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="c:\windows\ATK0100\Hcontrol.exe" [2003-09-21 61440]
"ASUS Live Update"="c:\programmi\ASUS\ASUS Live Update\ALU.exe" [2003-09-19 172032]
"Power_Gear"="c:\progra~1\ASUS\Power4 Gear\BatteryLife.exe" [2002-11-29 73728]
"ATIPTA"="c:\progra~1\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-13 335872]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2003-12-03 110592]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2003-12-03 618496]
"Control Center"="c:\program files\ASUS\WLAN Card Utilities\Center.exe" [2003-09-19 1241088]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-10 136600]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2006-08-23 98304]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-12-01 57344]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2003-12-15 28672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Hotkey.lnk - c:\programmi\Asus\ASUS Hotkey\Hotkey.exe [2005-12-6 798208]
NkbMonitor.exe.lnk - c:\programmi\Nikon\PictureProject\NkbMonitor.exe [2006-8-23 118784]
hpoddt01.exe.lnk - c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-9 28672]
hp psc 2000 Series.lnk - c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-9 323646]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15867:TCP"= 15867:TCP:BitComet 15867 TCP
"15867:UDP"= 15867:UDP:BitComet 15867 UDP
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [07/03/2009 15.39.01 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07/03/2009 15.39.01 20560]
R3 ASNDIS5;ASNDIS5 Protocol Driver;c:\windows\ATK0100\ASNDIS5.sys [06/12/2005 12.10.01 16269]
R3 HSFHWSIS;HSFHWSIS;c:\windows\system32\drivers\HSFHWSIS.sys [06/12/2005 12.10.17 190080]
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;c:\windows\system32\drivers\wbms.sys [06/12/2005 12.10.18 35328]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [06/12/2005 12.10.19 26240]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\programmi\NOS\bin\getPlus_HelperSvc.exe [21/02/2009 16.12.00 33752]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [20/04/2009 14.21.52 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [20/04/2009 14.21.53 8320]
S3 o1394bul;o1394bul; [x]
.
Contenuto della cartella 'Scheduled Tasks'
2008-01-12 c:\windows\Tasks\FRU Task 2003-04-10 00:56ewlett-Packard2003-04-10 00:56p psc 2200 series272A572217594EBCF1CEE215E352B92AD073FDE4159871007.job
- c:\programmi\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 15:56]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.misteuro.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.asus.com.tw/
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\programmi\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-11 10:50
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr = "c:\programmi\Windows Live\Messenger\msnmsgr.exe" /background??e
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
Ora fine scansione: 2009-06-11 10.52.04
ComboFix-quarantined-files.txt 2009-06-11 08:52
Pre-Run: 22.046.965.760 byte disponibili
Post-Run: 22.210.248.704 byte disponibili
153 --- E O F --- 2009-05-13 09:56