ComboFix 09-11-20.03 - Francesco 21/11/2009 15.52.37.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.2038.1536 [GMT 1:00]
Eseguito da: c:\documents and settings\Francesco\Documenti\Download\ComboFix.exe
Opzioni usate :: c:\documents and settings\Francesco\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {00000002-0002-0000-14EF-9D7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
FILE ::
"c:\windows\system32\inhrj.dll"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PVYZBAKPR
-------\Service_pvyzbakpr
((((((((((((((((((((((((( Files Creati Da 2009-10-21 al 2009-11-21 )))))))))))))))))))))))))))))))))))
.
2009-11-21 13:09 . 2009-11-21 13:09 -------- d-----w- c:\documents and settings\Francesco\Dati applicazioni\Malwarebytes
2009-11-21 13:08 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-21 13:08 . 2009-11-21 13:09 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-11-21 13:08 . 2009-11-21 13:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-11-21 13:08 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-05 12:58 . 1999-11-10 10:05 86016 ----a-w- c:\windows\unvise32qt.exe
2009-11-05 12:57 . 2009-11-05 12:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\QuickTime
2009-11-05 12:57 . 2009-11-05 12:57 28672 ----a-w- c:\windows\system32\qttask.exe
2009-11-02 14:31 . 2009-11-21 09:43 -------- d-----w- c:\documents and settings\Francesco\Impostazioni locali\Dati applicazioni\Temp
2009-10-27 22:11 . 2009-10-27 22:11 -------- d-----w- c:\documents and settings\Francesco\Dati applicazioni\Avira
2009-10-27 21:43 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-27 21:43 . 2009-02-13 11:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-27 21:43 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-27 21:43 . 2009-10-27 21:43 -------- d-----w- c:\programmi\Avira
2009-10-24 12:14 . 2009-10-24 12:14 -------- d-----w- C:\XCEEDZIP
2009-10-24 12:14 . 1996-11-16 22:00 27632 ----a-w- c:\windows\system\ctl3dv2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 14:20 . 2009-07-24 16:37 -------- d-----w- c:\documents and settings\Francesco\Dati applicazioni\vlc
2009-11-21 11:28 . 2009-05-02 18:23 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-11-21 11:14 . 2009-04-25 07:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-11-18 13:14 . 2009-04-19 19:14 -------- d-----w- c:\documents and settings\Francesco\Dati applicazioni\LimeWire
2009-11-18 13:13 . 2009-09-17 18:13 -------- d-----w- c:\documents and settings\Francesco\Dati applicazioni\dvdcss
2009-11-07 11:49 . 2009-06-18 16:57 -------- d-----w- c:\documents and settings\Francesco\Dati applicazioni\Nokia Multimedia Player
2009-11-05 16:48 . 2009-09-05 11:50 -------- d-----w- c:\programmi\PlotBaseGrafica
2009-11-05 16:48 . 2009-09-05 11:49 -------- d-----w- c:\programmi\duple1
2009-10-31 21:45 . 2009-08-21 12:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-10-27 21:43 . 2009-05-25 11:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-10-25 08:54 . 2004-08-30 20:00 69790 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 08:54 . 2004-08-30 20:00 437644 ----a-w- c:\windows\system32\perfh010.dat
2009-09-27 19:51 . 2009-09-22 19:32 -------- d-----w- c:\programmi\ewido anti-spyware 4.0
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\programmi\BillP Studios\WinPatrol\winpatrol.exe" [2007-08-06 292152]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-08 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-08 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-08 131072]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-07-23 16804864]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-04-03 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\programmi\Avira\AntiVir Desktop\avmailc.exe [27/10/2009 22.43.39 francesco 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmi\Avira\AntiVir Desktop\sched.exe [27/10/2009 22.43.40 francesco 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\programmi\Avira\AntiVir Desktop\avwebgrd.exe [27/10/2009 22.43.40 francesco 434945]
R2 VMCService;Vodafone Mobile Connect Service;c:\programmi\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [04/07/2008 11.52.18 francesco 14336]
S2 gupdate1c9e07828d000ec;Servizio di Google Update (gupdate1c9e07828d000ec);c:\programmi\Google\Update\GoogleUpdate.exe [29/05/2009 17.11.42 francesco 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-05-29 16:11]
2009-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-05-29 16:11]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://google/
uInternet Settings,ProxyServer = http=127.0.0.1:18935
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: c:\programmi\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\Francesco\Dati applicazioni\Mozilla\Firefox\Profiles\91i4yz7c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/ig
FF - plugin: c:\documents and settings\Francesco\Impostazioni locali\Dati applicazioni\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-21 15:56
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(764)
c:\programmi\Avira\AntiVir Desktop\avsda.dll
- - - - - - - > 'explorer.exe'(3076)
c:\programmi\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\ewido anti-spyware 4.0\guard.exe
c:\programmi\Nero\Nero 7\InCD\InCDsrv.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2009-11-21 15:57 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-11-21 14:57
ComboFix2.txt 2009-11-21 14:25
Pre-Run: 197.005.189.120 byte disponibili
Post-Run: 196.908.519.424 byte disponibili
- - End Of File - - 1CDAA7E1DB763450535F79108BBEAEC1