ComboFix 10-07-23.04 - merco 24/07/2010 15.27.04.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1673 [GMT 2:00]
Eseguito da: c:\documents and settings\merco\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100724-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\merco\IMPOST~1\Temp\tmp1.tmp
c:\docume~1\merco\IMPOST~1\Temp\tmp2.tmp
c:\documents and settings\merco\Dati applicazioni\cmstp.exe
c:\documents and settings\merco\Dati applicazioni\logman.exe
c:\documents and settings\merco\Dati applicazioni\Microsoft\clipsrv.exe
c:\documents and settings\merco\Dati applicazioni\Microsoft\cmstp.exe
c:\documents and settings\merco\Dati applicazioni\Microsoft\comrepl.exe
c:\documents and settings\merco\Dati applicazioni\Microsoft\dllhst3g.exe
c:\documents and settings\merco\Dati applicazioni\Microsoft\mqtgsvc.exe
c:\documents and settings\merco\Dati applicazioni\Microsoft\sessmgr.exe
c:\documents and settings\merco\Dati applicazioni\Microsoft\spoolsv.exe
c:\documents and settings\merco\Dati applicazioni\mqtgsvc.exe
c:\documents and settings\merco\Dati applicazioni\rsvp.exe
c:\documents and settings\merco\mvlcqnva.exe
c:\windows\CISVC.exe
c:\windows\cmstp.exe
c:\windows\dllhst3g.exe
c:\windows\esentutl.exe
c:\windows\ieudinit.exe
c:\windows\logman.exe
c:\windows\mqtgsvc.exe
c:\windows\mstsc.exe
c:\windows\system\dllhst3g.exe
c:\windows\system\esentutl.exe
c:\windows\system\ieudinit.exe
c:\windows\system\mqtgsvc.exe
c:\windows\System\mstinit.exe
c:\windows\system\sessmgr.exe
c:\windows\system32\drivers\cisvc.exe
c:\windows\system32\drivers\cmstp.exe
c:\windows\system32\drivers\comrepl.exe
c:\windows\system32\drivers\dllhst3g.exe
c:\windows\system32\drivers\esentutl.exe
c:\windows\system32\drivers\logman.exe
c:\windows\system32\drivers\mstinit.exe
c:\windows\system32\vbzlib1.dll
E:\install.exe
.
((((((((((((((((((((((((( Files Creati Da 2010-06-24 al 2010-07-24 )))))))))))))))))))))))))))))))))))
.
2010-07-24 13:17 . 2010-07-23 14:53 91136 ----a-w- c:\windows\system\mstsc.exe
2010-07-24 13:11 . 2010-07-23 14:53 91136 ----a-w- c:\windows\clipsrv.exe
2010-07-24 12:14 . 2010-07-24 12:14 -------- d-----w- c:\documents and settings\merco\Impostazioni locali\Dati applicazioni\Conduit
2010-07-24 12:14 . 2010-07-24 12:14 -------- d-----w- c:\programmi\Conduit
2010-07-24 12:14 . 2010-07-24 12:14 -------- d-----w- c:\documents and settings\merco\Impostazioni locali\Dati applicazioni\Softonic-IT
2010-07-24 12:14 . 2010-07-24 12:14 -------- d-----w- c:\programmi\Softonic-IT
2010-07-24 11:29 . 2010-07-24 11:29 388096 ----a-r- c:\documents and settings\merco\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-24 08:41 . 2010-07-24 08:41 -------- d-----w- c:\documents and settings\merco\Dati applicazioni\fretsonfire
2010-07-23 19:02 . 2010-07-23 19:02 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-07-23 19:01 . 2009-05-27 15:31 584832 ----a-w- c:\windows\system32\drivers\RTL8192su.sys
2010-07-23 18:55 . 2010-07-23 18:55 -------- d-----w- c:\windows\system32\wbem\Repository
2010-07-23 17:13 . 2010-07-23 17:13 -------- d-----w- c:\programmi\Belkin
2010-07-23 15:43 . 2010-07-23 15:43 -------- d-----w- c:\programmi\Zuma Deluxe
2010-07-23 15:28 . 2010-07-23 17:30 22 ----a-w- c:\windows\popcinfot.dat
2010-07-20 21:03 . 2010-07-20 21:04 -------- d-----w- c:\windows\system32\NtmsData
2010-07-20 18:21 . 2010-07-20 18:22 -------- d-----w- c:\documents and settings\merco\Impostazioni locali\Dati applicazioni\Packard Bell
2010-07-20 18:21 . 2010-07-20 18:21 -------- d-----w- c:\programmi\Packard Bell
2010-07-20 18:18 . 2010-07-20 18:18 -------- d-----w- c:\programmi\Packard Bell External HDD
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-24 13:14 . 2001-08-31 10:00 70544 ----a-w- c:\windows\system32\perfc010.dat
2010-07-24 13:14 . 2001-08-31 10:00 440128 ----a-w- c:\windows\system32\perfh010.dat
2010-07-24 12:15 . 2009-08-02 22:35 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-07-24 12:10 . 2009-05-30 12:20 -------- d-----w- c:\documents and settings\merco\Dati applicazioni\DNA
2010-07-24 08:57 . 2009-07-01 14:34 -------- d-----w- c:\documents and settings\merco\Dati applicazioni\uTorrent
2010-07-24 07:59 . 2009-05-30 12:20 -------- d-----w- c:\programmi\DNA
2010-07-23 22:25 . 2009-07-01 14:35 -------- d-----w- c:\programmi\uTorrent
2010-07-23 20:34 . 2009-05-30 12:20 -------- d-----w- c:\documents and settings\merco\Dati applicazioni\BitTorrent
2010-07-23 19:35 . 2009-08-25 22:27 10 ----a-w- c:\windows\popcinfo.dat
2010-07-23 17:13 . 2009-05-29 17:57 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-07-18 21:55 . 2010-04-04 21:35 -------- d-----w- c:\programmi\Nokia
2010-07-05 17:50 . 2009-09-25 18:00 -------- d-----w- c:\documents and settings\merco\Dati applicazioni\gtk-2.0
2010-06-19 21:34 . 2009-05-29 23:05 -------- d-----w- c:\programmi\Metin2_Italiano
2010-06-13 17:06 . 2010-06-13 17:06 503808 ----a-w- c:\documents and settings\merco\Dati applicazioni\Sun\Java\Deployment\cache\6.0\46\f84c6ae-10e315dd-n\msvcp71.dll
2010-06-13 17:06 . 2010-06-13 17:06 499712 ----a-w- c:\documents and settings\merco\Dati applicazioni\Sun\Java\Deployment\cache\6.0\46\f84c6ae-10e315dd-n\jmc.dll
2010-06-13 17:06 . 2010-06-13 17:06 348160 ----a-w- c:\documents and settings\merco\Dati applicazioni\Sun\Java\Deployment\cache\6.0\46\f84c6ae-10e315dd-n\msvcr71.dll
2010-06-06 20:57 . 2009-05-29 23:09 -------- d-----w- c:\documents and settings\merco\Dati applicazioni\Skype
2010-04-29 13:39 . 2009-08-02 22:35 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2009-08-02 22:35 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-06-03 2736736]
[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e3393495-8103-46a0-8181-270273eddd60}]
2010-06-03 16:24 2736736 ----a-w- c:\programmi\Softonic-IT\tbSoft.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-06-03 2736736]
[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Sitecom\\IVT BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\DNA\\btdna.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Metin2_Italiano\\metin2.bin"=
"c:\\Programmi\\Hercules\\Deluxe Optical Glass\\Station2.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [29/05/2009 20.16.36 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29/05/2009 20.16.36 20560]
R2 Belkin Wifi Service;Belkin Wifi Service;c:\programmi\Belkin\F5D8053\v6\WifiSvc.exe [23/07/2010 21.01.54 274432]
R2 PowerSave;PowerSave Service;c:\programmi\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe [06/04/2009 11.35.46 1002016]
R3 camfilt2;camfilt2;c:\windows\system32\drivers\camfilt2.sys [29/05/2009 20.34.22 94720]
S2 FlexService;Remote Connections Service;"c:\programmi\RapidBIT\cisvc.exe" --> c:\programmi\RapidBIT\cisvc.exe [?]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [23/07/2010 21.01.56 584832]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {ACAD3C7B-F2E8-46BB-B4FD-FBB169DA75D0} = 193.70.152.15,193.70.152.25
FF - ProfilePath - c:\documents and settings\merco\Dati applicazioni\Mozilla\Firefox\Profiles\2srz2fid.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - google.it
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - plugin: c:\documents and settings\merco\Dati applicazioni\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Explorer_Run-Logman - c:\docume~1\merco\DATIAP~1\logman.exe
HKU-Default-Explorer_Run-IEudinit - c:\windows\System\ieudinit.exe
HKU-Default-Explorer_Run-MqtgSVC - c:\docume~1\merco\DATIAP~1\mqtgsvc.exe
HKU-Default-Explorer_Run-ComRepl - c:\docume~1\merco\DATIAP~1\MICROS~1\comrepl.exe
HKU-Default-Explorer_Run-Mstsc - c:\documents and settings\merco\LOCALS~1\APPLIC~1\mstsc.exe
HKU-Default-Explorer_Run-rsvp - c:\docume~1\merco\DATIAP~1\rsvp.exe
HKU-Default-Explorer_Run-Spool - c:\documents and settings\merco\LOCALS~1\APPLIC~1\spoolsv.exe
HKU-Default-Explorer_Run-MstInit - c:\windows\System\mstinit.exe
HKU-Default-Explorer_Run-SessMgr - c:\windows\System\sessmgr.exe
HKU-Default-Explorer_Run-Logman - c:\windows\System32\drivers\logman.exe
HKU-Default-Explorer_Run-Esent Utl - c:\windows\esentutl.exe
HKU-Default-Explorer_Run-DllHst - c:\windows\System32\drivers\dllhst3g.exe
HKU-Default-Explorer_Run-CmSTP - c:\windows\cmstp.exe
HKU-Default-Explorer_Run-Cisvc - c:\documents and settings\merco\LOCALS~1\APPLIC~1\cisvc.exe
AddRemove-Zuma Deluxe 1.0 - c:\programmi\PopCap Games\Zuma Deluxe\PopUninstall.exe
AddRemove-Zuma's Revenge! - c:\programmi\PopCap Games\Zuma's Revenge\PopUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-24 15:32
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2010-07-24 15:34:28
ComboFix-quarantined-files.txt 2010-07-24 13:34
Pre-Run: 10.463.023.104 byte disponibili
Post-Run: 13.031.657.472 byte disponibili
- - End Of File - - 850409ACF0AA785698D040B1E13A41AE