ComboFix 10-11-22.05 - Antonella 23/11/2010 19.11.02.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2038.1570 [GMT 1:00]
Eseguito da: c:\documents and settings\Antonella\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-6C25-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.pif
c:\documents and settings\Antonella\Dati applicazioni\Desktopicon
c:\documents and settings\Antonella\Dati applicazioni\Desktopicon\eBay.ico
c:\documents and settings\Antonella\Dati applicazioni\Desktopicon\uninst.exe
c:\programmi\NavExcel
c:\windows\daemon.dll
c:\windows\system32\autorun.exe.exe
c:\windows\system32\autorun.ini
c:\windows\system32\vbzlib1.dll
.
((((((((((((((((((((((((( Files Creati Da 2010-10-23 al 2010-11-23 )))))))))))))))))))))))))))))))))))
.
2010-11-23 16:20 . 2010-11-23 16:20 -------- d-----w- c:\programmi\CCleaner
2010-11-22 19:54 . 2010-11-22 19:54 -------- d-----w- c:\documents and settings\Antonella\Dati applicazioni\Malwarebytes
2010-11-22 19:54 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-22 19:54 . 2010-11-22 19:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-11-22 19:54 . 2010-11-22 19:54 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-11-22 19:54 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-22 12:11 . 2010-11-22 12:11 388096 ----a-r- c:\documents and settings\Antonella\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-22 12:11 . 2010-11-22 12:11 -------- d-----w- c:\programmi\Trend Micro
2010-11-22 10:05 . 2010-11-22 10:10 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-22 10:05 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-22 10:05 . 2009-02-13 11:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-11-22 10:05 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-11-22 10:04 . 2010-11-22 10:04 -------- d-----w- c:\programmi\Avira
2010-11-22 10:04 . 2010-11-22 10:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-11-22 08:42 . 2010-11-22 09:48 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-11-22 08:42 . 2010-11-22 08:42 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-11-20 12:45 . 2010-11-20 12:45 -------- d-----w- c:\programmi\KONAMI
2010-11-19 15:45 . 2010-11-19 15:45 -------- d-----w- c:\programmi\Microsoft Windows Performance Toolkit
2010-11-19 15:45 . 2010-11-19 15:45 -------- d-----w- c:\programmi\Debugging Tools for Windows (x86)
2010-11-19 15:44 . 2010-11-19 15:44 -------- d-----w- c:\programmi\Application Verifier
2010-11-19 15:37 . 2010-11-19 15:37 -------- d-----w- c:\programmi\Microsoft SDKs
2010-11-19 15:34 . 2010-11-19 15:50 -------- d-----w- c:\programmi\WhoCrashed
2010-11-18 20:23 . 2010-11-18 21:28 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Temp
2010-11-18 14:00 . 2010-11-18 14:00 -------- d-----w- c:\windows\system32\wbem\Repository
2010-11-12 21:04 . 2010-11-12 21:04 -------- d-----w- c:\programmi\EA SPORTS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23 . 2007-04-02 18:14 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-13 17:13 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-13 17:13 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-18 06:53 . 2001-08-31 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-09 13:33 . 2008-04-27 13:24 832512 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 13:33 . 2008-04-27 13:24 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-09 13:33 . 2008-04-27 13:24 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-09-09 13:33 . 2008-04-27 13:23 17408 ----a-w- c:\windows\system32\corpol.dll
2010-09-08 15:57 . 2008-04-27 13:23 389120 ----a-w- c:\windows\system32\html.iec
2010-09-01 11:51 . 2008-04-13 17:11 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:54 . 2008-04-13 16:50 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2008-04-13 17:13 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2008-04-13 17:13 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2008-04-13 10:15 357248 ----a-w- c:\windows\system32\drivers\srv.sys
.
------- Sigcheck -------
[-] 2008-04-27 . D5E120A3BA164D2E7307A6688FEB26B2 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\programmi\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-08-15 30003200]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"WinampAgent"="c:\programmi\Winamp\winampa.exe" [2008-08-03 36352]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"UnlockerAssistant"="c:\programmi\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2010-08-10 421888]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2010-09-09 124928]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2009-12-20 110592]
McAfee Security Scan Plus.lnk - c:\programmi\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
TruDirectTray.lnk - c:\programmi\TruDirect\TruDirectTray.exe [2008-2-18 421888]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Hasbro Interactive\\Clue\\Clue.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"6901:TCP"= 6901:TCP:Services
"6900:TCP"= 6900:TCP:Services
"7726:TCP"= 7726:TCP:Services
"4613:TCP"= 4613:TCP:Services
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [13/09/2009 9.12.06 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [13/09/2009 9.12.06 5248]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [06/12/2005 16.11.18 35328]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.sys [24/02/2005 12.29.14 162176]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [13/09/2009 9.38.50 845184]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [27/03/2010 12.51.41 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\programmi\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 13.49.20 227232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenuto della cartella 'Scheduled Tasks'
2010-11-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-03-27 11:51]
2010-11-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-03-27 11:51]
2010-11-23 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-10-01 20:18]
2010-11-23 c:\windows\Tasks\Windows Codec Update Service.job
- c:\programmi\Essentials Codec Pack\WECPUpdate.exe [2010-09-27 08:30]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Antonella\Dati applicazioni\Mozilla\Firefox\Profiles\i7bhqn8v.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2405727&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage -
www.libero.itFF - plugin: c:\documents and settings\Antonella\Dati applicazioni\Mozilla\Firefox\Profiles\i7bhqn8v.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\Antonella\Dati applicazioni\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Veetle\Player\npvlc.dll
FF - plugin: c:\programmi\Veetle\plugins\npVeetle.dll
FF - plugin: c:\programmi\Veetle\VLCBroadcast\npvbp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-NWEReboot - (no file)
AddRemove-eBay Icon - c:\documents and settings\Antonella\Dati applicazioni\Desktopicon\uninst.exe
AddRemove-Kalender - c:\windows\Uninstall_tkexe -kalender
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-11-23 19:16
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\programmi\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1343024091-484763869-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ec,3d,52,de,5e,dd,f1,3e,4d,44,23,ce,f1,8b,8b,2e,72,8a,b1,12,3b,55,87,
b7,ed,7e,88,cd,9d,eb,6a,04,1c,77,42,01,a0,d8,c9,e2,0f,88,d9,9e,d0,28,d9,64,\
"??"=hex:63,7e,36,a1,9c,27,7f,3e,9b,ed,28,93,ef,2e,ea,00
.
Ora fine scansione: 2010-11-23 19:18:44
ComboFix-quarantined-files.txt 2010-11-23 18:18
Pre-Run: 32.031.670.272 byte disponibili
Post-Run: 32.086.781.952 byte disponibili
- - End Of File - - 45E6B50DD0C68B9E4FE6EDFF11129795