ecco il log di combofix
ComboFix 09-07-26.03 - Giampy 27/07/2009 20.13.44.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.895.487 [GMT 2:00]
Eseguito da: c:\documents and settings\Giampy\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ActiveArmor Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Giampy\Impostazioni locali\Dati applicazioni\akgoy.dat
c:\documents and settings\Giampy\Impostazioni locali\Dati applicazioni\akgoy_nav.dat
c:\documents and settings\Giampy\Impostazioni locali\Dati applicazioni\akgoy_navps.dat
c:\programmi\GooglePlusVideos
c:\programmi\GooglePlusVideos\DeploymentHelper.exe
c:\programmi\GooglePlusVideos\FFExt\chrome.manifest
c:\programmi\GooglePlusVideos\FFExt\chrome\content\googleplusvideos.xul
c:\programmi\GooglePlusVideos\FFExt\chrome\content\script-injector.js
c:\programmi\GooglePlusVideos\FFExt\install.rdf
c:\programmi\GooglePlusVideos\GooglePlusVideosLicense.txt
c:\programmi\GooglePlusVideos\GVConfig.ini
c:\programmi\GooglePlusVideos\MFC42U.DLL
c:\programmi\GooglePlusVideos\Uninstall.bat
c:\windows\Installer\225a541.msp
c:\windows\Installer\38f9e7.msp
c:\windows\Installer\39b979.msp
c:\windows\Installer\44da4e.msp
c:\windows\Installer\af49c.msp
c:\windows\Installer\af4b6.msp
.
((((((((((((((((((((((((( Files Creati Da 2009-06-27 al 2009-07-27 )))))))))))))))))))))))))))))))))))
.
2009-07-25 18:27 . 2009-07-25 18:39 -------- d-----w- c:\documents and settings\Giampy\Impostazioni locali\Dati applicazioni\DoubleD
2009-07-02 18:40 . 2009-07-02 18:40 2054424 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgcorex.dll
2009-07-02 18:40 . 2009-07-02 18:40 2167576 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgresf.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-27 16:52 . 2008-03-29 14:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-07-27 10:58 . 2009-01-04 12:02 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-07-27 10:57 . 2009-01-07 16:51 3775175 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-26 18:10 . 2009-05-21 20:55 -------- d-----w- c:\programmi\Burraconline
2009-07-19 19:34 . 2001-08-31 12:00 70886 ----a-w- c:\windows\system32\perfc010.dat
2009-07-19 19:34 . 2001-08-31 12:00 441202 ----a-w- c:\windows\system32\perfh010.dat
2009-07-13 11:36 . 2009-01-04 12:02 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2009-01-04 12:02 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-04 15:08 . 2007-05-23 21:22 -------- d-----w- c:\programmi\SpywareBlaster
2009-07-02 18:40 . 2009-02-06 19:06 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-25 18:43 . 2009-02-06 19:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-25 18:43 . 2009-02-06 19:06 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:36 . 2001-08-31 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2001-08-31 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-11 09:57 . 2009-06-11 09:57 -------- d-----w- c:\programmi\Mz_CpuAcc
2009-06-04 16:56 . 2009-06-04 16:56 -------- d-----w- c:\programmi\iTunes
2009-06-04 16:56 . 2009-06-04 16:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-04 16:56 . 2009-06-04 16:56 -------- d-----w- c:\programmi\iPod
2009-06-04 16:56 . 2009-06-04 16:56 -------- d-----w- c:\programmi\Bonjour
2009-06-04 16:55 . 2009-06-04 16:55 -------- d-----w- c:\programmi\File comuni\Apple
2009-06-04 16:53 . 2009-06-04 16:53 75048 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-04 16:52 . 2006-08-20 20:29 -------- d-----w- c:\programmi\QuickTime
2009-06-04 16:52 . 2009-06-04 16:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2009-06-03 19:09 . 2001-08-31 12:00 1296384 ----a-w- c:\windows\system32\quartz.dll
2009-05-21 20:55 . 2009-05-21 20:55 34494 ----a-r- c:\documents and settings\Giampy\Dati applicazioni\Microsoft\Installer\{082EA2B7-C14C-4D48-8527-EF8375E99EBE}\_F90371DFD12D98C031BC18.exe
2009-05-21 20:55 . 2009-05-21 20:55 34494 ----a-r- c:\documents and settings\Giampy\Dati applicazioni\Microsoft\Installer\{082EA2B7-C14C-4D48-8527-EF8375E99EBE}\_EE54C14E46DCA67484A433.exe
2009-05-18 22:36 . 2009-05-18 22:04 290816 ------w- c:\windows\Setup1.exe
2009-05-18 22:36 . 2009-05-18 22:04 74752 ----a-w- c:\windows\ST6UNST.EXE
2009-05-15 22:02 . 2009-02-06 19:06 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-07 15:32 . 2001-08-31 12:00 347648 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:45 . 2001-08-31 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:44 . 2006-03-16 16:58 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-27 18:00 . 2009-01-18 13:06 134648 ----a-w- c:\programmi\mozilla firefox\components\brwsrcmp.dll
2009-01-25 12:57 . 2009-01-25 12:57 28672 ----a-w- c:\programmi\mozilla firefox\components\GooglePlusVideosXPCOM.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
2009-03-26 20:56 . 2009-03-25 16:17 4948000 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-16 7630848]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-25 18:43 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Alice ti aiuta.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Alice ti aiuta.lnk
backup=c:\windows\pss\Alice ti aiuta.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^NkbMonitor.exe.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\NkbMonitor.exe.lnk
backup=c:\windows\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Mediacenter\\Mediacenter0.4-by Coolstreaming.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Giampy\\Dati applicazioni\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\TVAnts\\Tvants.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\PPLive\\PPLive.exe"=
"d:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Secured eMule\\light_mule.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16525:UDP"= 16525:UDP:*:Disabled:Rosso Alice UDP
"19967:TCP"= 19967:TCP:TCP INGRESSO EMULE
"19977:UDP"= 19977:UDP:UDP E MULE
"16429:TCP"= 16429:TCP:BitComet 16429 TCP
"16429:UDP"= 16429:UDP:BitComet 16429 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [30/12/2008 20.22.19 28544]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [06/02/2009 21.06.05 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [06/02/2009 21.06.12 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [06/02/2009 21.05.45 298776]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [11/12/2008 12.33.55 8192]
S2 MDM_Untrusted_BZ;Machine Debug Manager_Untrusted_BZ;c:\virtual\Untrusted\C_\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE [20/06/2003 0.25.00 322120]
.
Contenuto della cartella 'Scheduled Tasks'
2009-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-07-26 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-07-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-07-26 c:\windows\Tasks\User_Feed_Synchronization-{A06C4F15-344E-47A7-85D1-D2385706C63B}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 16:36]
2009-07-27 c:\windows\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- c:\programmi\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
.
------- Scansione supplementare -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.virgilio.it/
uInternet Settings,ProxyOverride = 127.0.0.1;<local>;*.local
uSearchURL,(Default) = hxxp://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\programmi\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: rossoalice.it
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Giampy\Dati applicazioni\Mozilla\Firefox\Profiles\s4t5lnpf.default\
FF - prefs.js: browser.startup.homepage - hxxps://login.libero.it/?service_id=old_email&ret_url=http%3A%2F%2Fwpop14.libero.it%2Femail.php
FF - component: c:\programmi\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\programmi\Mozilla Firefox\components\GooglePlusVideosXPCOM.dll
.
**************************************************************************
driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-27 20:20
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\BufferZone\Virtual\Untrusted\Machine\System\CurrentControlSet]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
[HKEY_LOCAL_MACHINE\software\BufferZone\Virtual\Untrusted\USER\LocalSystem]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2009-07-27 20.23.50
ComboFix-quarantined-files.txt 2009-07-27 18:23
ComboFix2.txt 2009-03-18 22:16
Pre-Run: 34.162.008.064 byte disponibili
Post-Run: 34.270.216.192 byte disponibili
183 --- E O F --- 2009-07-22 16:25