ComboFix 08-12-13.03 - xp 2008-12-14 17:25:33.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.502.128 [GMT 1:00]
Eseguito da: c:\documents and settings\xp\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\Starware371
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\494_button_1b_def.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\494_button_1b_over.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\498_button_1b_def.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\498_button_1b_over.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\499_button_1b_def.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\499_button_1b_over.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\FindIt.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\FindItHot.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\findithotxp.png
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\finditxp.png
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\logo.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\buttons\logoxp.bmp
c:\documents and settings\All Users\Dati applicazioni\Starware371\contexts\error.xml
c:\documents and settings\All Users\Dati applicazioni\Starware371\contexts\related.xml
c:\documents and settings\All Users\Dati applicazioni\Starware371\contexts\travel.xml
c:\programmi\Starware371
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000011_.tmp.dll
c:\windows\system32\_000012_.tmp.dll
c:\windows\system32\_000021_.tmp.dll
c:\windows\system32\ciyhucfy.ini
c:\windows\system32\urlegtbw.ini
c:\windows\system32\xIiOrtwa.ini
c:\windows\system32\xIiOrtwa.ini2
c:\windows\system32\yfcuhyic.dll
c:\windows\Tasks\lfmmfood.job
.
((((((((((((((((((((((((( Files Creati Da 2008-11-14 al 2008-12-14 )))))))))))))))))))))))))))))))))))
.
2008-12-13 13:08 . 2008-12-13 13:08 <DIR> d-------- c:\programmi\Trend Micro
2008-12-08 11:12 . 2008-12-08 11:14 2 --a------ C:\1544808118
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-08 09:55 --------- d-----w c:\documents and settings\xp\Dati applicazioni\Azureus
2008-12-07 13:47 --------- d-----w c:\documents and settings\xp\Dati applicazioni\SmartShopper
2008-12-05 19:19 --------- d-----w c:\programmi\Vuze
2008-11-16 19:04 230,432 ----a-w C:\SPC220NC.DAT
2008-11-02 19:30 --------- d-----w c:\programmi\PowerISO
2008-11-02 15:43 --------- d-----w c:\documents and settings\xp\Dati applicazioni\BearShare
2008-11-02 13:39 --------- d-----w c:\programmi\Google
2008-10-26 13:58 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Autodesk
2008-10-26 13:54 --------- d-----w c:\programmi\File comuni\Autodesk Shared
2008-10-26 13:54 --------- d-----w c:\programmi\AutoCAD 2007
2008-10-26 13:52 --------- d-----w c:\programmi\AnswerWorks 4.0
2008-10-26 13:47 --------- d-----w c:\documents and settings\xp\Dati applicazioni\Autodesk
2008-10-26 13:43 --------- d-----w c:\programmi\Autodesk
2008-10-25 12:58 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Azureus
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-19 21:17 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Messenger Plus!
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:38 1,846,016 ----a-w c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2007-12-02 15:13 394680 --a------ c:\programmi\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"TOSCDSPD"="c:\programmi\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-12 65536]
"LaunchList"="c:\programmi\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]
"PcSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-08-26 860160]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-04 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-12-17 761945]
"THotkey"="c:\programmi\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"Tvs"="c:\programmi\TOSHIBA\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="c:\programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-05-12 118784]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
"IntelZeroConfig"="c:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-12-04 406016]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2007-12-11 286720]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2007-12-11 267048]
"DataLayer"="c:\programmi\File comuni\PCSuite\DataLayer\DataLayer.exe" [2005-09-06 820736]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 176128]
"Monitor"="c:\windows\Philips\SPC220NC\Monitor.exe" [2006-11-03 319488]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-28 1261336]
"TomTomHOME.exe"="c:\programmi\TomTom HOME\TomTomHOME.exe" [2008-04-01 3976528]
"PWRISOVM.EXE"="c:\programmi\PowerISO\PWRISOVM.EXE" [2008-07-07 167936]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-09 c:\windows\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 c:\windows\agrsmmsg.exe]
"TPSMain"="TPSMain.exe" [2005-08-04 c:\windows\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [2005-09-16 c:\windows\system32\TDispVol.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\xp\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2007-02-19 212992]
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-12-07 1744896]
Controllo del Calendario di Ulead Photo Express.lnk - c:\programmi\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe [2007-07-20 69632]
Tasto di scelta rapida per l'avvio di AutoCAD.lnk - c:\programmi\File comuni\Autodesk Shared\acstart17.exe [2006-03-05 11000]
TrayMin220.lnk - c:\programmi\Philips\Philips SPC220NC Webcam\TrayMin220.exe [2008-03-07 278528]
Ulead Photo Express SE Calendar Checker.lnk - c:\programmi\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe [2007-07-14 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll njghxu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.MJPX"= PICVideo MJPEG Codec
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\BearShare Applications\\BearShare\\BearShare.exe"=
"c:\\Programmi\\Toshiba\\ConfigFree\\CFXFER.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\umi.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-05-29 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-03 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-03 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-05-29 76040]
S3 SPC220NC;Philips SPC220NC Webcam;c:\windows\system32\DRIVERS\SPC220NC.SYS [2008-03-07 507136]
.
Contenuto della cartella 'Scheduled Tasks'
2008-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-12-14 c:\windows\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- c:\programmi\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORFÃOS REMOVIDOS - - - -
URLSearchHooks-{849cd0d1-3831-4476-86b4-469f00cc3f2f} - (no file)
BHO-{82343A87-5B23-4C8B-9341-1C80A9304DEE} - c:\windows\system32\awtrOiIx.dll
BHO-{8840b29a-ac6b-4f34-a78d-9f532ba7d8e3} - c:\windows\system32\njghxu.dll
Toolbar-{849cd0d1-3831-4476-86b4-469f00cc3f2f} - (no file)
WebBrowser-{849CD0D1-3831-4476-86B4-469F00CC3F2F} - (no file)
HKLM-Run-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
Notify-rqRHabxv - rqRHabxv.dll
.
------- Supplementare di scansione -------
.
uStart Page =
hxxp://search.bearshare.com/it/uSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/iemDefault_Search_URL =
hxxp://www.google.com/ieuInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
mSearchAssistant =
hxxp://www.google.com/ieIE: &Windows Live Search - c:\programmi\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: Apri in nuova scheda in primo piano - c:\programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?1287d277d0644f5abb9c9c6152e2a365
IE: Apri in nuova scheda in secondo piano - c:\programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?1287d277d0644f5abb9c9c6152e2a365
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - {BCEB373D-A35A-4200-BD43-8586CD9DFAE7} - c:\programmi\SmartShopper\Bin\2.5.0\SmrtShpr.dll
O16 -: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-14 17:35:05
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(1196)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Toshiba\ConfigFree\CFSvcs.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\programmi\Toshiba\TOSHIBA Applet\TAPPSRV.exe
c:\windows\system32\wdfmgr.exe
c:\programmi\Toshiba\ConfigFree\NDSTray.exe
c:\programmi\Toshiba\TOSHIBA Controls\TFncKy.exe
c:\programmi\Synaptics\SynTP\Toshiba.exe
c:\progra~1\FILECO~1\PCSuite\Services\SERVIC~1.EXE
c:\windows\system32\TPSBattM.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\progra~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
c:\programmi\AVG\AVG8\avgrsx.exe
c:\programmi\AVG\AVG8\avgrsx.exe
c:\programmi\AVG\AVG8\avgrsx.exe
c:\programmi\AVG\AVG8\avgrsx.exe
c:\windows\SoftwareDistribution\Download\55ee6e30b9085b53586efa1179870a1d\update\update.exe
.
**************************************************************************
.
Ora fine scansione: 2008-12-14 17:47:41 - macchina è stato riavviato [xp]
ComboFix-quarantined-files.txt 2008-12-14 16:47:19
Pre-Run: 45,291,376,640 byte disponibili
Post-Run: 46,076,248,064 byte disponibili
235 --- E O F --- 2008-11-12 22:37:49