ComboFix 12-07-30.03 - Joe 31/07/2012 20.39.08.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1014.396 [GMT 2:00]
Eseguito da: c:\documents and settings\Joe\desktop\combofix.exe
Opzioni usate :: /killall
AV: Avira Desktop *Disabled/Updated* {00000000-0715-0000-08F2-12003094807C}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((( Files Creati Da 2012-06-28 al 2012-07-31 )))))))))))))))))))))))))))))))))))
.
.
2012-07-31 13:28 . 2012-07-31 13:29 -------- d-----w- c:\documents and settings\Joe\Impostazioni locali\Dati applicazioni\Deployment
2012-07-31 13:19 . 2012-07-31 13:19 -------- d-----w- c:\documents and settings\Joe\Dati applicazioni\Avira
2012-07-31 13:17 . 2012-07-31 14:48 -------- d-----w- c:\windows\system32\NtmsData
2012-07-31 13:07 . 2012-02-03 13:26 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-07-31 13:07 . 2012-02-03 13:26 137416 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-07-31 13:07 . 2012-02-03 13:26 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-07-31 13:07 . 2012-07-31 13:07 -------- d-----w- c:\programmi\Avira
2012-07-31 13:07 . 2012-07-31 13:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2012-07-31 12:09 . 2012-07-31 12:07 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-07-31 12:09 . 2012-07-31 12:07 476976 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-07-31 12:07 . 2012-07-31 12:07 -------- d-----w- c:\programmi\Java
2012-07-31 00:15 . 2012-07-31 00:15 -------- d-----w- c:\documents and settings\Joe\Dati applicazioni\Malwarebytes
2012-07-31 00:15 . 2012-07-31 00:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2012-07-31 00:14 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-31 00:14 . 2012-07-31 00:15 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2012-07-30 18:27 . 2012-07-30 18:27 574 ----a-w- C:\cleanup.bat
2012-07-30 08:40 . 2012-07-30 08:40 -------- d-----w- c:\programmi\Trend Micro
2012-07-14 16:00 . 2012-07-14 16:00 -------- d-----w- c:\programmi\File comuni\Skype
2012-07-09 19:12 . 2012-07-09 19:12 -------- d-----w- c:\documents and settings\Joe\Impostazioni locali\Dati applicazioni\Real
2012-07-09 19:09 . 2012-07-09 19:09 -------- d-----w- c:\programmi\File comuni\xing shared
2012-07-09 19:06 . 2012-07-09 19:06 499712 ----a-w- c:\windows\system32\msvcp71.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-31 12:07 . 2011-10-06 18:59 472880 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-30 08:53 . 2012-04-10 18:44 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-30 08:53 . 2011-06-02 19:26 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:55 . 2009-04-16 03:38 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2009-04-16 03:38 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2009-04-16 03:38 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2009-04-16 03:38 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-04-15 17:58 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-04-15 17:58 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-04-15 17:58 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-08-06 17:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-04-16 03:38 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-04-15 17:58 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-04-15 17:58 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-08-06 17:23 15896 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2009-08-06 17:23 24088 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-08-06 17:23 18968 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2009-08-06 17:23 15896 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2009-04-15 17:58 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-04-15 17:58 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2010-05-27 18:31 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 13:18 . 2010-05-27 18:31 18672 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2010-05-27 18:31 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:21 . 2009-04-16 03:38 603136 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:06 . 2009-04-16 03:38 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:40 . 2009-04-16 03:38 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:40 . 2009-04-16 03:38 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2009-04-16 03:38 385024 ----a-w- c:\windows\system32\html.iec
2012-05-05 03:14 . 2008-04-13 18:55 2030080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-05 03:14 . 2008-04-13 18:54 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-07-30 21:04 . 2010-07-30 21:04 4938120 ----a-w- c:\programmi\Silverlight.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-31_18.29.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-31 18:47 . 2012-07-31 18:47 16384 c:\windows\Temp\Perflib_Perfdata_7d4.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-24 17567744]
"AzMixerSel"="c:\programmi\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-17 53248]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-05-01 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-05-01 354840]
"PersistenceThread"="c:\windows\system32\PersistenceThread.exe" [2009-05-01 92696]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2009-02-27 1434920]
"LManager"="c:\programmi\Launch Manager\LManager.exe" [2009-02-20 817672]
"RemoteControl8"="c:\programmi\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-10-17 91432]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"TkBellExe"="c:\programmi\real\realplayer\update\realsched.exe" [2012-07-09 296096]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-01-18 254696]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2012-02-03 258512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igdlogin]
2009-04-28 03:44 65536 ----a-w- c:\windows\system32\igdlogin.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
2007-12-14 09:36 50472 ------w- c:\programmi\CyberLink\PowerDVD8\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [29/05/2010 14.47.15 685816]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [31/07/2012 15.07.06 36000]
R2 AntiVirSchedulerService;Avira Pianificatore;c:\programmi\Avira\AntiVir Desktop\sched.exe [31/07/2012 15.07.08 86224]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmi\TomTom HOME 2\TomTomHOMEService.exe [22/04/2011 14.21.10 92592]
R3 igd;igd;c:\windows\system32\drivers\igxpmp32.sys [15/04/2009 21.03.05 5096544]
S2 SkypeUpdate;Skype Updater;c:\programmi\Skype\Updater\Updater.exe [03/07/2012 13.19.28 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [10/04/2012 20.44.08 250056]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [15/04/2009 21.06.33 1684736]
S3 GTUHSBUS;GT UHS BUS;c:\windows\system32\drivers\gtuhsbus.sys [16/04/2009 5.38.46 62592]
S3 GTUHSNDISIPXP;GT UHS IP NDIS;c:\windows\system32\drivers\gtuhs51.sys [16/04/2009 5.38.45 105984]
S3 GTUHSSER;GT UHS SER;c:\windows\system32\drivers\gtuhsser.sys [16/04/2009 5.38.46 8064]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [08/06/2010 10.01.08 102656]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [15/04/2009 21.08.00 164864]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - WS2IFSL
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-07-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-10 08:53]
.
2012-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2589800181-3091673561-677485609-1005Core.job
- c:\documents and settings\Joe\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2012-07-31 13:29]
.
2012-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2589800181-3091673561-677485609-1005UA.job
- c:\documents and settings\Joe\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2012-07-31 13:29]
.
2012-07-31 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2589800181-3091673561-677485609-1005.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2012-06-21 10:00]
.
2012-07-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2589800181-3091673561-677485609-1005.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2012-06-21 10:00]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-07-31 20:49
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"01403E1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(3308)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\programmi\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2012-07-31 20:54:11 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-07-31 18:54
ComboFix2.txt 2012-07-31 18:32
.
Pre-Run: 108.003.155.968 byte disponibili
Post-Run: 107.989.467.136 byte disponibili
.
- - End Of File - - D274CE0F2F77298F48C4D00427C5EF3C