**NB***di seguito metto il log di combofix, prima volevo far sapere che c'è stato un disguido: quando ho avviato combofix dopo aver chiuso tutto, il pc si è riavviato e con esso il firewall (kerio personal f4) ma a quel punto combofix era gia partito e di tanto in tanto il firewall mi chiedeva se autorizzare o negare l'avvio di qualche applicazione. può aver falsato il risultato del log? devo rifarlo? i lfatto che ho autorizzato delle apllicazioni può essere un problema...
grazie mille!
ComboFix 10-06-09.01 - talo 09/06/2010 23.16.25.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1023.515 [GMT 2:00]
Eseguito da: c:\documents and settings\talo\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100609-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Kerio Personal Firewall *disabled* {A990EAA7-8941-4621-BC27-4F16261D3180}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\setup.exe
c:\temp\tmp1.tmp
.
((((((((((((((((((((((((( Files Creati Da 2010-05-09 al 2010-06-09 )))))))))))))))))))))))))))))))))))
.
2010-06-09 21:26 . 2010-06-09 21:26 53248 ----a-w- c:\temp\catchme.dll
2010-06-09 21:11 . 2010-06-09 21:11 16384 ----atw- c:\temp\Perflib_Perfdata_508.dat
2010-06-09 21:11 . 2010-06-09 21:11 16384 ----atw- c:\temp\Perflib_Perfdata_2a4.dat
2010-06-09 20:17 . 2010-06-09 20:17 -------- d-----w- c:\temp\WPDNSE
2010-06-07 23:44 . 2010-06-07 23:44 -------- d-----w- c:\temp\hsperfdata_talo
2010-06-07 22:39 . 2010-06-07 22:39 -------- d-----w- c:\programmi\Trend Micro
2010-06-07 19:28 . 2010-06-09 21:24 -------- d-----w- c:\temp\VIRIT
2010-06-07 19:23 . 2010-06-07 19:23 -------- d-----w- c:\documents and settings\talo\Impostazioni locali\Dati applicazioni\PackageAware
2010-06-07 19:17 . 2010-06-09 21:24 -------- d-----w- c:\temp\mia5.tmp
2010-06-07 19:12 . 2010-06-09 21:24 -------- d-----w- c:\temp\mia42.tmp
2010-06-07 19:10 . 2010-06-09 21:24 -------- d-----w- c:\temp\mia41.tmp
2010-06-05 09:27 . 2010-06-05 09:27 1024 ---h--r- c:\windows\system32\NTIBUN4.dll
2010-06-05 09:26 . 2004-12-17 14:14 13952 ------w- c:\windows\system32\drivers\UBHelper.sys
2010-06-05 09:26 . 2010-06-05 09:26 -------- d-----w- c:\temp\byeB5.tmp
2010-06-05 09:26 . 2010-06-05 09:26 -------- d-----w- c:\programmi\File comuni\NewTech Infosystems
2010-06-05 09:26 . 2010-06-05 09:27 -------- d-----w- c:\programmi\NewTech Infosystems
2010-06-05 09:25 . 2010-06-09 21:24 -------- d-----w- c:\temp\_is5
2010-06-05 09:25 . 2010-06-09 21:24 -------- d-----w- c:\temp\pft3.tmp
2010-06-05 08:54 . 2010-06-09 21:24 -------- d-----w- c:\temp\VBE
2010-06-05 08:43 . 2010-06-05 08:43 -------- d-----w- c:\programmi\File comuni\muvee Technologies
2010-06-05 08:43 . 2010-06-05 08:43 -------- d-----w- c:\temp\byeAD.tmp
2010-05-28 12:06 . 2010-05-28 12:06 503808 ----a-w- c:\documents and settings\talo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2f543c8a-n\msvcp71.dll
2010-05-28 12:06 . 2010-05-28 12:06 499712 ----a-w- c:\documents and settings\talo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2f543c8a-n\jmc.dll
2010-05-28 12:06 . 2010-05-28 12:06 348160 ----a-w- c:\documents and settings\talo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2f543c8a-n\msvcr71.dll
2010-05-28 12:06 . 2010-05-28 12:06 61440 ----a-w- c:\documents and settings\talo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5f0c99c2-n\decora-sse.dll
2010-05-28 12:06 . 2010-05-28 12:06 12800 ----a-w- c:\documents and settings\talo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5f0c99c2-n\decora-d3d.dll
2010-05-24 19:44 . 2010-05-24 19:46 -------- d-----w- c:\windows\system32\NtmsData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-09 21:09 . 2010-01-03 21:59 -------- d-----w- c:\documents and settings\talo\Dati applicazioni\uTorrent
2010-06-09 21:09 . 2009-12-09 23:14 -------- d-----w- c:\documents and settings\talo\Dati applicazioni\BitTorrent
2010-06-09 20:53 . 2006-10-05 20:24 -------- d-----w- c:\programmi\Mozilla Thunderbird
2010-06-08 17:44 . 2010-03-14 22:31 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-06-08 17:28 . 2010-02-21 13:02 32492 ----a-w- c:\windows\SCHEDLGU.TXT.TMP
2010-06-07 22:16 . 2010-06-07 21:12 717296 ----a-w- c:\windows\system32\drivers\SPTD.SYS.TMP
2010-06-07 22:16 . 2007-02-17 17:21 16149679 ----a-w- c:\windows\system32\drivers\fwdrv.err
2010-06-07 18:44 . 2010-02-06 03:01 -------- d-----w- c:\programmi\QuickTime
2010-06-07 00:07 . 2006-10-05 20:09 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-06-06 11:47 . 2007-02-02 19:17 -------- d-----w- c:\documents and settings\talo\Dati applicazioni\Skype
2010-06-06 11:46 . 2009-03-19 22:58 -------- d-----w- c:\documents and settings\talo\Dati applicazioni\skypePM
2010-06-05 09:28 . 2006-08-21 09:21 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-06-05 09:26 . 2010-04-19 08:15 1024 ---h--r- c:\windows\system32\NTICDMK7.dll
2010-06-05 09:25 . 2010-04-19 08:15 1024 ---h--r- c:\windows\system32\NTIFCD3.dll
2010-06-05 09:25 . 2010-04-19 08:15 1024 ---h--r- c:\windows\system32\NTIMPEG2.dll
2010-06-05 09:25 . 2010-04-19 08:15 1024 ---h--r- c:\windows\system32\NTIMP3.dll
2010-06-05 09:25 . 2010-04-19 08:15 6144 ----a-w- c:\windows\system32\drivers\NTIDrvr.sys
2010-06-01 06:36 . 2006-10-05 20:09 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-05-06 19:51 . 2010-05-06 19:51 -------- d-----w- c:\documents and settings\talo\Dati applicazioni\AVS4YOU
2010-05-06 19:51 . 2010-05-06 19:48 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AVS4YOU
2010-05-06 19:50 . 2010-05-06 19:48 -------- d-----w- c:\programmi\AVS4YOU
2010-05-06 19:50 . 2010-05-06 19:49 -------- d-----w- c:\programmi\File comuni\AVSMedia
2010-05-05 18:03 . 2010-01-03 22:08 -------- d-----w- c:\programmi\uTorrent
2010-04-29 13:39 . 2010-03-14 22:31 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-03-14 22:31 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-19 08:16 . 2010-04-19 08:16 -------- d-----w- c:\programmi\File comuni\LightScribe
2010-04-19 08:11 . 2010-01-17 01:21 -------- d-----w- c:\programmi\Amazonia
2010-04-14 20:47 . 2007-11-14 19:29 -------- d-----w- c:\documents and settings\talo\Dati applicazioni\teamspeak2
2010-04-14 00:02 . 2008-02-14 19:09 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2010-04-13 20:48 . 2008-05-11 19:58 -------- d-----w- c:\programmi\Opera
2010-03-28 10:17 . 2006-04-21 20:56 84996 ------w- c:\windows\system32\perfc010.dat
2010-03-28 10:17 . 2006-04-21 20:56 491438 ------w- c:\windows\system32\perfh010.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ISUSPM"="c:\programmi\File comuni\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-08-11 1124352]
"uTorrent"="c:\programmi\uTorrent\uTorrent.exe" [2010-05-15 322352]
"BitTorrent"="c:\programmi\BitTorrent\bittorrent.exe" [2010-02-23 654648]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-03-17 421888]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"nwiz"="nwiz.exe" [2006-06-01 1519616]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 86016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"DSLSTATEXE"="c:\program files\D-Link\DSL-200\dslstat.exe" [2005-12-12 344064]
"DSLAGENTEXE"="c:\program files\D-Link\DSL-200\dslagent.exe" [2005-08-25 65536]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2010-03-17 421888]
"PCMService"="c:\programmi\CyberLink\PowerCinema\PCMService.exe" [2006-04-04 147456]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BlueSoleil.lnk - c:\programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe [2008-10-9 1183744]
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
NETGEAR WG111v3 Smart Wizard.lnk - c:\programmi\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 2326528]
NkbMonitor.exe.lnk - c:\programmi\Nikon\PictureProject\NkbMonitor.exe [2006-9-24 118784]
SimHID.lnk - c:\programmi\Remote\SimHID\SimHID.exe [2006-8-21 417792]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programmi\\Cyberlink\\PowerCinema\\PowerCinema.exe"=
"c:\\Programmi\\Cyberlink\\PowerCinema\\PCMService.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
"c:\\Programmi\\Sports Interactive\\Football Manager 2010\\fm.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Opera\\opera.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16525:UDP"= 16525:UDP:Rosso Alice UDP
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [01/04/2008 19.48.56 114768]
R1 fwdrv;Firewall Driver;c:\windows\system32\drivers\fwdrv.sys [15/12/2005 18.13.34 274432]
R1 khips;Kerio HIPS Driver;c:\windows\system32\drivers\khips.sys [15/12/2005 18.01.52 81920]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [01/04/2008 19.48.56 20560]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [09/10/2007 13.13.00 38144]
R2 PDSched;PDScheduler;c:\programmi\Raxco\PerfectDisk\PDSched.exe [01/11/2004 12.56.06 237635]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [01/10/2008 16.45.52 57440]
R3 OmniTV;Cx2388x AvStream Video Capture;c:\windows\system32\drivers\OmniTV.sys [21/08/2006 13.57.55 198528]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [05/10/2006 22.42.56 717296]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [09/10/2009 15.28.23 8192]
S3 ALSysIO;ALSysIO;\??\c:\temp\ALSysIO.sys --> c:\temp\ALSysIO.sys [?]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\d:\programmi\everesthome\kerneld.wnt --> d:\programmi\everesthome\kerneld.wnt [?]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\programmi\NETGEAR\WN111v2\jswpsapi.exe --> c:\programmi\NETGEAR\WN111v2\jswpsapi.exe [?]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\DRIVERS\pfc027.sys --> c:\windows\system32\DRIVERS\pfc027.sys [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [22/02/2010 1.11.26 27064]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [28/12/2007 15.02.12 287232]
S3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [29/08/2002 2.17.58 208916]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [05/10/2006 22.44.48 223128]
.
Contenuto della cartella 'Scheduled Tasks'
2010-06-09 c:\windows\Tasks\HPpromotions journeysoftware.job
- c:\programmi\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe [2005-04-22 16:36]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://riobar.forumfree.net/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: rossoalice.it
Trusted Zone: virgilio.it\*.rossoalice
TCP: {3F83C739-EB05-4238-8EF3-291763567576} = 192.168.1.1
TCP: {FEFBAC45-8409-4E69-AA6C-74A94C913712} = 151.99.125.1,151.99.0.100
FF - ProfilePath - c:\documents and settings\talo\Dati applicazioni\Mozilla\Firefox\Profiles\p5ei3szy.default\
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=it-it&FORM=MICI05&q=
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\np32asw.dll
FF - plugin: c:\programmi\Opera\program\plugins\npqtplugin8.dll
FF - plugin: c:\programmi\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-Google Update - c:\documents and settings\talo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
HKLM-Run-tsnpstd3 - c:\windows\tsnpstd3.exe
HKLM-Run-snpstd3 - c:\windows\vsnpstd3.exe
HKLM-Run-CameraFixer - c:\windows\CameraFixer.exe
SafeBoot-AVG Anti-Spyware Driver
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-09 23:26
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\d:\programmi\everesthome\kerneld.wnt"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2010-06-09 23:30:23
ComboFix-quarantined-files.txt 2010-06-09 21:30
Pre-Run: 23.014.993.920 byte disponibili
Post-Run: 23.398.080.512 byte disponibili
- - End Of File - - 1A54730AAD24C4D909088AEA3A4D229B