Ecco il log di combofix
ComboFix 10-02-03.04 - Aldo 03/02/2010 22.03.34.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.991.648 [GMT 1:00]
Eseguito da: f:\documents and settings\Aldo\Documenti\Download\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
f:\windows\system32\winlogon.bak
.
((((((((((((((((((((((((( Files Creati Da 2010-01-03 al 2010-02-03 )))))))))))))))))))))))))))))))))))
.
2010-02-01 22:02 . 2010-02-01 22:02 -------- d-----w- f:\documents and settings\Aldo\Dati applicazioni\Malwarebytes
2010-02-01 22:02 . 2010-01-07 15:07 38224 ----a-w- f:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 22:02 . 2010-02-01 22:02 -------- d-----w- f:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-02-01 22:02 . 2010-02-01 22:02 -------- d-----w- f:\programmi\Malwarebytes' Anti-Malware
2010-02-01 22:02 . 2010-01-07 15:07 19160 ----a-w- f:\windows\system32\drivers\mbam.sys
2010-02-01 21:52 . 2010-02-02 20:55 -------- d-----w- f:\programmi\Navilog1
2010-02-01 21:13 . 2010-02-01 21:13 -------- d-----w- f:\programmi\Trend Micro
2010-01-27 21:08 . 2010-01-27 21:16 -------- d-----w- f:\documents and settings\Aldo\Dati applicazioni\VSO
2010-01-27 21:07 . 2010-01-27 21:07 -------- d-----w- f:\programmi\VSO
2010-01-27 11:12 . 2010-01-18 20:30 1260800 ----a-w- f:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgfrw.exe
2010-01-27 11:12 . 2010-01-18 20:30 3777280 ----a-w- f:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\setup.exe
2010-01-11 21:39 . 2010-01-11 21:40 -------- d-----w- f:\documents and settings\Aldo\dwhelper
2010-01-07 21:59 . 2010-01-07 21:59 -------- d-----w- f:\programmi\CCleaner
2010-01-05 15:20 . 2010-01-31 18:30 -------- d-----w- f:\documents and settings\Aldo\Dati applicazioni\vlc
2010-01-05 14:47 . 2001-08-17 20:51 19584 -c--a-w- f:\windows\system32\dllcache\rasirda.sys
2010-01-05 14:47 . 2001-08-17 20:51 19584 ----a-w- f:\windows\system32\drivers\rasirda.sys
2010-01-05 14:47 . 2008-04-13 18:54 88192 -c--a-w- f:\windows\system32\dllcache\irda.sys
2010-01-05 14:47 . 2008-04-13 18:54 88192 ----a-w- f:\windows\system32\drivers\irda.sys
2010-01-05 14:47 . 2005-09-05 01:59 19034 ----a-r- f:\windows\system32\drivers\KS-959.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-03 18:44 . 2006-03-02 12:00 53820 ----a-w- f:\windows\system32\perfc010.dat
2010-01-03 18:44 . 2006-03-02 12:00 405948 ----a-w- f:\windows\system32\perfh010.dat
2010-01-02 22:17 . 2009-12-27 18:17 -------- d-----w- f:\programmi\File comuni\Real
2010-01-02 22:17 . 2010-01-02 22:17 -------- d-----w- f:\programmi\File comuni\xing shared
2010-01-02 22:16 . 2010-01-02 21:38 499712 ----a-w- f:\windows\system32\msvcp71.dll
2010-01-02 22:16 . 2009-12-27 18:17 348160 ----a-w- f:\windows\system32\msvcr71.dll
2010-01-02 22:02 . 2010-01-02 22:02 -------- d-----w- f:\programmi\S3Inc
2010-01-02 21:38 . 2010-01-02 21:38 -------- d-----w- f:\programmi\Real
2010-01-02 16:00 . 2010-01-02 16:00 -------- d-----w- f:\documents and settings\All Users\Dati applicazioni\Bluetooth
2010-01-02 15:58 . 2010-01-02 15:58 -------- d-----w- f:\programmi\IVT Corporation
2010-01-01 17:48 . 2009-12-28 11:01 664 ----a-w- f:\windows\system32\d3d9caps.dat
2010-01-01 11:24 . 2010-01-01 11:24 -------- d-----w- f:\documents and settings\Aldo\Dati applicazioni\gnupg
2010-01-01 10:43 . 2010-01-01 10:41 -------- d-----w- f:\programmi\Power Translator 12
2009-12-31 21:36 . 2009-12-31 21:35 -------- d-----w- f:\documents and settings\Aldo\Dati applicazioni\dvdcss
2009-12-28 10:15 . 2009-12-28 10:15 -------- d-----w- f:\programmi\Alcohol Soft
2009-12-27 23:34 . 2009-12-27 23:34 902592 ----a-w- f:\windows\system32\drivers\tdrpm228.sys
2009-12-27 23:34 . 2009-12-27 22:45 540000 ----a-w- f:\windows\system32\drivers\timntr.sys
2009-12-27 23:34 . 2009-12-27 22:45 44704 ----a-w- f:\windows\system32\drivers\tifsfilt.sys
2009-12-27 23:34 . 2009-12-27 22:45 138208 ----a-w- f:\windows\system32\drivers\snapman.sys
2009-12-27 23:34 . 2009-12-27 23:34 -------- d-----w- f:\programmi\File comuni\Acronis
2009-12-27 23:34 . 2009-12-27 23:34 -------- d-----w- f:\programmi\Acronis
2009-12-27 23:29 . 2009-12-27 23:29 69224 ----a-w- f:\documents and settings\Aldo\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-12-27 21:21 . 2009-12-27 21:21 -------- d-----w- f:\programmi\eMule
2009-12-27 21:14 . 2009-12-27 18:17 -------- d-----w- f:\programmi\converter
2009-12-27 21:10 . 2009-12-27 20:58 -------- d-----w- f:\programmi\VideoLAN
2009-12-27 20:48 . 2009-12-27 20:48 -------- d-----w- f:\programmi\VS Revo Group
2009-12-27 17:06 . 2009-12-27 17:06 -------- d-----w- f:\programmi\Polar
2009-12-27 17:06 . 2009-12-24 18:13 -------- d--h--w- f:\programmi\InstallShield Installation Information
2009-12-26 19:04 . 2009-12-26 19:04 -------- d-----w- f:\documents and settings\Aldo\Dati applicazioni\EPSON
2009-12-26 16:49 . 2009-12-26 16:49 -------- d-----w- f:\documents and settings\Aldo\Dati applicazioni\ACD Systems
2009-12-26 16:48 . 2009-12-26 16:48 -------- d-----w- f:\programmi\File comuni\ACD Systems
2009-12-26 16:48 . 2009-12-26 16:48 -------- d-----w- f:\documents and settings\All Users\Dati applicazioni\ACD Systems
2009-12-26 16:48 . 2009-12-26 16:48 -------- d-----w- f:\programmi\ACD Systems
2009-12-26 14:53 . 2009-12-26 14:53 0 ----a-w- f:\windows\nsreg.dat
2009-12-25 22:32 . 2009-12-25 22:29 -------- d-----w- f:\programmi\Canon
2009-12-25 22:18 . 2009-12-25 22:18 -------- d-----w- f:\programmi\File comuni\Adobe
2009-12-25 18:23 . 2009-12-24 08:51 86327 ----a-w- f:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-25 17:46 . 2009-12-25 17:46 -------- d-----w- f:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2009-12-25 10:46 . 2009-12-25 10:46 12464 ----a-w- f:\windows\system32\avgrsstx.dll
2009-12-25 10:46 . 2009-12-25 10:46 360584 ----a-w- f:\windows\system32\drivers\avgtdix.sys
2009-12-25 10:46 . 2009-12-25 10:46 333192 ----a-w- f:\windows\system32\drivers\avgldx86.sys
2009-12-25 10:46 . 2009-12-25 10:46 28424 ----a-w- f:\windows\system32\drivers\avgmfx86.sys
2009-12-25 10:46 . 2009-12-25 10:46 -------- d-----w- f:\documents and settings\All Users\Dati applicazioni\AVG Security Toolbar
2009-12-25 10:46 . 2009-12-25 10:46 -------- d-----w- f:\programmi\AVG
2009-12-25 10:46 . 2009-12-25 10:46 -------- d-----w- f:\documents and settings\All Users\Dati applicazioni\avg9
2009-12-24 18:15 . 2009-12-24 18:12 -------- d-----w- f:\programmi\File comuni\InstallShield
2009-12-24 18:14 . 2009-12-24 18:14 -------- d-----w- f:\documents and settings\All Users\Dati applicazioni\UDL
2009-12-24 18:14 . 2009-12-24 18:12 -------- d-----w- f:\programmi\EPSON
2009-12-24 16:20 . 2009-12-24 16:20 69632 ----a-r- f:\documents and settings\Aldo\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\NewShortcut2_B358DA4D0918436EA0E64813B1E5965A.exe
2009-12-24 16:20 . 2009-12-24 16:20 69632 ----a-r- f:\documents and settings\Aldo\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\NewShortcut1_B358DA4D0918436EA0E64813B1E5965A.exe
2009-12-24 16:20 . 2009-12-24 16:20 10134 ----a-r- f:\documents and settings\Aldo\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\ARPPRODUCTICON.exe
2009-12-24 15:03 . 2009-12-24 14:59 -------- d-----w- f:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-12-24 15:02 . 2009-12-24 15:02 -------- d-----w- f:\programmi\Microsoft Works
2009-12-24 15:02 . 2009-12-24 15:02 -------- d-----w- f:\programmi\MSBuild
2009-12-24 08:52 . 2009-12-24 08:52 -------- d-----w- f:\programmi\microsoft frontpage
2009-12-24 08:50 . 2009-12-24 08:50 -------- d-----w- f:\programmi\Servizi in linea
2009-12-24 08:49 . 2009-12-24 08:49 21840 ----a-w- f:\windows\system32\emptyregdb.dat
2009-11-25 12:01 . 2009-12-25 10:49 1230080 ----a-w- f:\documents and settings\All Users\Dati applicazioni\AVG Security Toolbar\IEToolbar.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "f:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 12:01 1230080 ----a-w- f:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "f:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "f:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="f:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo R240 Series"="f:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE" [2005-04-25 98304]
"TrueImageMonitor.exe"="f:\programmi\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-05-19 4386216]
"AcronisTimounterMonitor"="f:\programmi\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-05-19 961080]
"Servizio Acronis Scheduler2"="f:\programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2009-05-19 377472]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"VTTimer"="VTTimer.exe" [2004-01-15 49152]
"TkBellExe"="f:\programmi\File comuni\Real\Update_OB\realsched.exe" [2010-01-02 198160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="f:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
f:\documents and settings\Aldo\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - f:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-25 10:46 12464 ----a-w- f:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Device Detector]
DevDetect.exe -autorun [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- f:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- f:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 23:47 31016 ----a-w- f:\programmi\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-02-09 08:54 65024 ----a-r- f:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"f:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"f:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"f:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"f:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\Programmi\\eMule\\emule.exe"=
"f:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
R0 a347scsi;a347scsi;f:\windows\system32\drivers\a347scsi.sys [28/12/2009 11.15.59 5248]
R0 tdrpman228;Acronis Try&Decide and Restore Points filter (build 228);f:\windows\system32\drivers\tdrpm228.sys [28/12/2009 0.34.46 902592]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;f:\windows\system32\drivers\avgldx86.sys [25/12/2009 11.46.33 333192]
R1 AvgTdiX;AVG Free Network Redirector;f:\windows\system32\drivers\avgtdix.sys [25/12/2009 11.46.41 360584]
R2 avg9wd;AVG Free WatchDog;f:\programmi\AVG\AVG9\avgwdsvc.exe [25/12/2009 11.46.24 285392]
R2 Start BT in service;Start BT in service;f:\programmi\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [19/03/2008 16.52.38 51816]
S0 a347bus;a347bus;f:\windows\system32\drivers\a347bus.sys [28/12/2009 11.15.59 160640]
S3 KS-959;Kingsun KS-959 USB Infrared Adapter;f:\windows\system32\drivers\KS-959.sys [05/01/2010 15.47.24 19034]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.repubblica.it/
IE: E&sporta in Microsoft Excel - f:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {775B47A9-11BD-4D18-9136-35F8B4A869F3} = 208.67.222.222,208.67.220.220
FF - ProfilePath - f:\documents and settings\Aldo\Dati applicazioni\Mozilla\Firefox\Profiles\yvkenyyp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.repubblica.it/
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-Polar Sync - (no file)
Notify-WgaLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-03 22:06
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Polar Sync = ?:\program files\polar\polar sync\?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2010-02-03 22:07:47
ComboFix-quarantined-files.txt 2010-02-03 21:07
Pre-Run: 56.048.906.240 byte disponibili
Post-Run: 56.027.598.848 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 6009DEBF9485E45D1CE617DC96E1D965