ComboFix 10-12-14.01 - x 14/12/2010 20.15.32.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.512.293 [GMT 1:00]
Eseguito da: c:\documents and settings\x\Documenti\Download\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {0012F2B4-5CC9-7C92-0300-000000000000}
AV: AntiVir Desktop *Enabled/Updated* {0012F2B4-5AF1-7C92-0300-000000000000}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\msssc.dll
.
((((((((((((((((((((((((( Files Creati Da 2010-11-14 al 2010-12-14 )))))))))))))))))))))))))))))))))))
.
2010-12-12 18:16 . 2010-12-12 18:16 -------- d-----w- c:\documents and settings\x\Dati applicazioni\Greenshot
2010-12-12 18:15 . 2010-12-12 18:15 -------- d-----w- c:\programmi\Greenshot
2010-12-10 16:11 . 2009-12-08 19:19 114432 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2010-12-10 16:11 . 2009-12-07 18:53 102912 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2010-12-10 16:11 . 2009-10-12 14:21 100736 ----a-w- c:\windows\system32\drivers\ewusbdev.sys
2010-12-10 16:11 . 2007-08-09 03:13 24448 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2010-12-09 13:37 . 2010-12-09 13:37 12872 ----a-w- c:\windows\system32\bootdelete.exe
2010-12-09 10:33 . 2010-12-09 10:34 -------- d-----w- c:\programmi\File comuni\Adobe
2010-12-08 19:59 . 2010-12-08 19:59 -------- d-----w- c:\programmi\uTorrent
2010-12-08 19:58 . 2010-12-14 18:55 -------- d-----w- c:\documents and settings\x\Dati applicazioni\uTorrent
2010-12-08 19:31 . 2010-12-11 10:46 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-12-08 19:30 . 2010-12-08 19:30 -------- d-----w- c:\programmi\Hitman Pro 3.5
2010-12-08 19:20 . 2010-12-09 13:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Hitman Pro
2010-12-06 11:49 . 2010-12-06 11:49 -------- d-----w- c:\documents and settings\x\Dati applicazioni\Malwarebytes
2010-12-06 11:48 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-06 11:48 . 2010-12-06 11:48 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-12-06 11:48 . 2010-12-14 16:28 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-12-06 11:48 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-05 23:05 . 2010-12-05 23:05 -------- d-----w- c:\documents and settings\x\Impostazioni locali\Dati applicazioni\uTorrentBar
2010-12-05 20:45 . 2010-12-05 20:45 -------- d-----w- c:\windows\Sun
2010-12-05 19:24 . 2010-12-05 19:24 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-05 19:12 . 2010-12-05 19:24 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-12-05 19:11 . 2010-12-05 19:24 -------- d-----w- c:\programmi\Java
2010-12-05 19:11 . 2010-12-05 19:25 -------- d-----w- c:\programmi\File comuni\Java
2010-12-04 23:54 . 2010-12-04 23:54 -------- d-----w- c:\programmi\MSN Messenger
2010-12-04 20:35 . 2003-01-09 09:14 13101168 ----a-r- c:\programmi\Windows Media Player\Installer\mpsetup9x_ita.exe
2010-12-01 13:34 . 2010-12-01 13:34 -------- d-----w- c:\programmi\Windows Live SkyDrive
2010-12-01 12:53 . 2010-12-01 12:53 -------- d-----w- c:\programmi\File comuni\Windows Live
2010-12-01 11:26 . 2008-04-13 18:12 6144 ------w- c:\windows\system32\kbdiultn.dll
2010-12-01 11:16 . 2010-12-01 11:27 -------- d-----w- c:\windows\ServicePackFiles
2010-12-01 11:15 . 2008-04-13 18:14 294912 ------w- c:\programmi\Windows Media Player\dlimport.exe
2010-12-01 11:15 . 2008-04-13 18:14 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2010-11-30 23:30 . 2010-11-30 23:30 -------- d-----w- c:\documents and settings\x\Dati applicazioni\Avira
2010-11-30 23:29 . 2010-11-30 23:29 -------- d-----w- c:\documents and settings\x\Impostazioni locali\Dati applicazioni\Mozilla
2010-11-30 23:02 . 2010-09-01 13:22 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-30 23:02 . 2010-09-01 13:22 126856 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-30 23:02 . 2010-06-17 14:28 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-11-30 23:02 . 2010-06-17 14:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-11-30 23:02 . 2010-11-30 23:02 -------- d-----w- c:\programmi\Avira
2010-11-30 23:02 . 2010-11-30 23:02 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-11-30 22:55 . 2010-12-10 16:11 -------- d-----w- c:\programmi\Mobile Partner
2010-11-30 22:54 . 2008-04-13 10:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-11-30 22:04 . 2010-11-30 22:04 -------- d-----w- c:\programmi\File comuni\EPSON
2010-11-30 22:04 . 2000-06-07 00:01 169472 ----a-w- c:\windows\system32\EBAPI2.dll
2010-11-30 22:03 . 2001-03-04 17:15 61598 ----a-w- c:\windows\system32\E_SL2346.DLL
2010-11-30 22:03 . 2010-11-30 22:04 -------- d-----w- c:\programmi\EPSON
2010-11-30 22:03 . 2000-06-25 17:20 32768 ----a-w- c:\windows\system32\ECBTEG.DLL
2010-11-30 22:03 . 2000-06-06 16:01 34304 ----a-w- c:\windows\system32\EBPCHP.DLL
2010-11-30 21:44 . 2003-12-02 20:10 212992 ----a-w- c:\programmi\File comuni\InstallShield\Engine\6\Intel 32\ILog.dll
2010-11-30 21:44 . 2010-11-30 21:44 -------- d-----w- C:\ATI
2010-11-30 21:43 . 2010-11-30 21:43 -------- d-----w- c:\programmi\Creative
2010-11-30 21:43 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-11-30 21:30 . 2010-11-30 21:32 -------- d-----w- c:\windows\nview
2010-11-30 21:30 . 2005-11-11 05:47 180224 ----a-w- c:\windows\system32\nvudisp.exe
2010-11-30 21:30 . 2005-11-11 13:49 180224 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-11-30 21:30 . 2003-11-10 17:13 69715 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2010-11-30 21:30 . 2003-11-10 17:12 266240 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2010-11-30 21:30 . 2003-11-10 17:12 192512 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2010-11-30 21:30 . 2003-11-10 17:11 5632 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2010-11-30 21:30 . 2003-11-10 17:14 729088 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2010-11-30 21:30 . 2010-11-30 21:30 311428 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2010-11-30 21:30 . 2010-11-30 21:30 188548 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2010-11-30 21:24 . 2010-11-30 21:24 -------- d-----w- c:\documents and settings\Administrator
2010-11-30 21:21 . 2001-08-30 19:41 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-11-30 21:21 . 2001-08-30 19:41 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-11-30 21:21 . 2008-04-13 10:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-11-30 21:15 . 2001-08-17 19:13 27165 -c--a-w- c:\windows\system32\dllcache\fetnd5.sys
2010-11-30 21:15 . 2001-08-17 19:13 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
2010-11-30 21:15 . 2008-04-13 10:45 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Greenshot"="c:\programmi\Greenshot\Greenshot.exe" [2010-07-12 548864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 16143872]
"nwiz"="nwiz.exe" [2005-11-11 1519616]
"Smapp"="c:\programmi\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2010-09-01 281768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-11 7311360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2010-11-30 127488]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
R0 mv614x;mv614x;c:\windows\system32\drivers\mv614x.sys [22/09/2008 10.09.51 61184]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [20/10/2009 11.52.16 133104]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;c:\windows\system32\drivers\atl01_xp.sys [22/09/2008 10.05.42 31104]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [10/12/2010 17.11.08 114432]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [10/12/2010 17.11.08 100736]
.
Contenuto della cartella 'Scheduled Tasks'
2010-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-10-20 10:52]
2010-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-10-20 10:52]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {B358EDEE-A3E2-4B58-AB20-A63F1E7B67C0} = 151.99.125.3,151.99.125.2
FF - ProfilePath - c:\documents and settings\x\Dati applicazioni\Mozilla\Firefox\Profiles\tc2utasy.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-NWEReboot - (no file)
MSConfigStartUp-Samsung Common SM - c:\windows\Samsung\ComSMMgr\ssmmgr.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-12-14 20:19
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-20\AppEvents\EventLabels\Clos*]
@="Chiusura applicazione"
"DispFileName"="@mmsys.cpl,-5826"
.
Ora fine scansione: 2010-12-14 20:21:40
ComboFix-quarantined-files.txt 2010-12-14 19:21
Pre-Run: 11.322.949.632 byte disponibili
Post-Run: 11.285.221.376 byte disponibili
- - End Of File - - 1531D9047E936D9429C67B42A5924D84