ComboFix 10-01-03.05 - OEM 04/01/2010 14.12.38.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.3066.1989 [GMT 1:00]
Eseguito da: c:\downloads\Software\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-882718197-68631507-246064436-500
c:\program files\pdfforge Toolbar\SearchSettings.dll
c:\users\canonicos\AppData\Local\lrpvcage.dat
c:\users\canonicos\AppData\Local\lrpvcage.exe
c:\users\canonicos\AppData\Local\lrpvcage_nav.dat
c:\users\canonicos\AppData\Local\lrpvcage_navps.dat
c:\users\canonicos\AppData\Roaming\.#
c:\windows\Suyin.reg
c:\windows\Temp\log.txt
.
((((((((((((((((((((((((( Files Creati Da 2009-12-04 al 2010-01-04 )))))))))))))))))))))))))))))))))))
.
2010-01-04 13:16 . 2010-01-04 13:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-25 17:11 . 2009-12-25 17:11 -------- d-----w- c:\users\canonicos\AppData\Roaming\PeerNetworking
2009-12-25 16:21 . 2009-12-25 16:21 -------- d-----w- c:\users\Default\AppData\Roaming\Intel
2009-12-25 16:21 . 2009-12-25 16:21 -------- d-----w- c:\programdata\Roaming
2009-12-25 16:20 . 2009-12-25 16:20 -------- d-----w- c:\program files\Cisco
2009-12-25 16:20 . 2009-12-25 16:20 -------- d-----w- c:\programdata\Intel
2009-12-25 08:32 . 2009-12-25 08:32 -------- d-----w- C:\found.000
2009-12-16 22:07 . 2009-12-16 22:08 -------- d-----w- c:\windows\system32\ca-ES
2009-12-16 22:07 . 2009-12-16 22:08 -------- d-----w- c:\windows\system32\eu-ES
2009-12-16 22:07 . 2009-12-16 22:08 -------- d-----w- c:\windows\system32\vi-VN
2009-12-16 19:12 . 2009-12-16 19:12 -------- d-----w- c:\windows\system32\EventProviders
2009-12-16 19:11 . 2009-11-02 19:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-12-10 16:02 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-10 16:01 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-10 16:01 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-09 15:17 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-04 13:17 . 2009-10-03 16:27 -------- d-----w- c:\users\canonicos\AppData\Roaming\Free Download Manager
2010-01-04 13:16 . 2009-09-29 18:22 -------- d-----w- c:\program files\pdfforge Toolbar
2010-01-04 12:55 . 2009-02-25 08:42 662846 ----a-w- c:\windows\system32\perfh010.dat
2010-01-04 12:55 . 2009-02-25 08:42 120326 ----a-w- c:\windows\system32\perfc010.dat
2010-01-04 12:49 . 2009-10-03 16:27 95 ----a-w- c:\users\canonicos\AppData\Local\hyzse.bat
2010-01-04 12:48 . 2009-09-26 11:35 48747 ----a-w- c:\programdata\nvModes.dat
2010-01-04 08:26 . 2009-09-26 11:35 7592 ----a-w- c:\users\canonicos\AppData\Local\d3d9caps.dat
2009-12-25 16:20 . 2009-02-11 20:12 -------- d-----w- c:\program files\Intel
2009-12-17 14:48 . 2009-09-26 16:54 -------- d-----w- c:\program files\Google
2009-12-17 13:49 . 2009-07-15 12:56 -------- d-----w- c:\programdata\NVIDIA
2009-12-16 22:09 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-12-16 22:09 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-16 22:09 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-12-16 22:09 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-12-16 22:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-12-16 22:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-12-16 22:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-12-16 22:07 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-16 19:06 . 2009-02-25 00:40 -------- d-----w- c:\programdata\McAfee
2009-12-10 16:01 . 2009-02-25 01:05 -------- d-----w- c:\programdata\Microsoft Help
2009-12-10 15:52 . 2009-09-26 18:52 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-02 17:11 . 2009-07-15 13:04 -------- d-----w- c:\programdata\eSobi
2009-11-21 06:40 . 2009-12-09 15:22 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 15:22 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-09 15:22 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-09 15:22 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-19 17:47 . 2009-11-19 17:43 -------- d-----w- c:\program files\Docfa4
2009-11-19 17:39 . 2009-11-19 17:38 -------- d-----w- c:\program files\Java
2009-11-19 17:38 . 2009-11-19 17:38 -------- d-----w- c:\program files\Common Files\Java
2009-11-19 17:11 . 2009-11-19 17:11 -------- d-----w- c:\programdata\NtiDvdCopy
2009-11-18 20:15 . 2009-09-26 14:09 -------- d-----w- c:\users\canonicos\AppData\Roaming\Autodesk
2009-11-18 19:31 . 2009-11-18 19:24 -------- d-----w- c:\programdata\Autodesk
2009-11-18 19:31 . 2009-09-26 16:55 102192 ----a-w- c:\users\canonicos\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-18 19:29 . 2009-11-18 19:24 -------- d-----w- c:\program files\AutoCAD 2009
2009-11-18 19:29 . 2009-09-26 14:06 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2009-11-08 09:41 . 2009-09-26 19:51 -------- d-----w- c:\program files\Messenger Plus! Live
2009-10-29 09:17 . 2009-11-27 16:42 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-21 13:20 . 2009-11-21 13:21 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
2009-07-31 00:00 698880 ----a-w- c:\program files\pdfforge Toolbar\pdfforgeToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B922D405-6D13-4A2B-AE89-08A030DA4402}"= "c:\program files\pdfforge Toolbar\pdfforgeToolbarIE.dll" [2009-07-31 698880]
[HKEY_CLASSES_ROOT\clsid\{b922d405-6d13-4a2b-ae89-08a030da4402}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-05-14 21:02 120104 ----a-w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-11-17 135168]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Free Download Manager"="c:\progra~1\FREEDO~1\FDM.exe" [2009-09-30 3399727]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-26 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2009-01-20 156968]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2009-01-20 202024]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-16 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-16 92704]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-02-19 6793760]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-02-19 1833504]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-05 1410344]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-25 1069576]
"BackupManagerTray"="c:\program files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2009-04-11 249600]
"Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2009-06-23 440864]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-05-13 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-05-14 345384]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-12-26 173288]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-21 30192]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 94208]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2009-07-29 1024512]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):98,52,5e,a7,1f,7f,ca,01
R1 mwlPSDFilter;mwlPSDFilter;c:\windows\System32\drivers\mwlPSDFilter.sys [04/12/2008 17.34.34 19504]
R1 mwlPSDNServ;mwlPSDNServ;c:\windows\System32\drivers\mwlPSDNserv.sys [04/12/2008 17.34.34 16432]
R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\System32\drivers\mwlPSDVDisk.sys [04/12/2008 17.34.34 59952]
R2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [25/02/2009 2.19.31 75048]
R2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [15/07/2009 14.02.21 707104]
R2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\MWLService.exe [14/05/2009 22.03.30 305448]
R2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [11/04/2009 18.32.00 61184]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [23/09/2008 14.11.34 144632]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\k57nd60x.sys [04/09/2008 5.12.56 223232]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [15/07/2009 22.33.35 3666432]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [15/07/2009 22.32.42 45600]
S2 gupdate;Servizio di Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/10/2009 15.36.41 133104]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [21/01/2008 3.23.20 179712]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [26/09/2009 20.19.00 54632]
S3 fsssvc;Servizio Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21.48.42 704864]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [26/09/2009 17.54.23 30192]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [23/09/2008 14.11.32 50424]
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 14:36]
2010-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 14:36]
2010-01-04 c:\windows\Tasks\User_Feed_Synchronization-{BDF665B5-EEE9-43FA-A1B1-13A143D3FD14}.job
- c:\windows\system32\msfeedssync.exe [2009-12-09 04:59]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/mStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACA ... spire_5738uSearchURL,(Default) =
hxxp://www.google.com/search/?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Scarica con Free Download Manager -
file://c:\program files\Free Download Manager\dllink.htm
IE: Scarica i video con Free Download Manager -
file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Scarica selezionati con Free Download Manager -
file://c:\program files\Free Download Manager\dlselected.htm
IE: Scarica tutto con Free Download Manager -
file://c:\program files\Free Download Manager\dlall.htm
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
FF - ProfilePath - c:\users\canonicos\AppData\Roaming\Mozilla\Firefox\Profiles\m8ha6tvy.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - prefs.js: keyword.URL -
hxxp://it.search.yahoo.com/search?fr=gr ... =971163&p=FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}\components\pdfforgeToolbarFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\search@searchsettings.com\components\SearchSettingsFF.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJPI142_06.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-lrpvcage - c:\users\canonicos\appdata\local\lrpvcage.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-Access Gateway USB - c:\program files\Pirelli\Access Gateway USB Network\SETUP.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-04 14:17
Windows 6.0.6002 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-882718197-68631507-246064436-1000\Software\SecuROM\License information*]
"datasecu"=hex:e0,86,53,2f,16,fc,6e,86,ae,1f,8b,22,f5,d3,ba,45,32,9a,e0,93,23,
be,89,0e,71,73,4a,3c,4b,9b,ac,ef,73,29,7f,09,c0,02,1a,bf,c2,c9,d5,e6,23,c3,\
"rkeysecu"=hex:cb,10,f7,8f,90,21,e1,b7,a2,8c,f9,9f,9a,d8,bf,98
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Ora fine scansione: 2010-01-04 14:19:12
ComboFix-quarantined-files.txt 2010-01-04 13:19
Pre-Run: 256.082.739.200 byte disponibili
Post-Run: 256.264.445.952 byte disponibili
- - End Of File - - F028476AF93FEA96251C72CA3C338556