ComboFix 09-01-21.04 - Administrator 2009-01-29 14.12.26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.3326.2798 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Dati applicazioni\drivers\downld
c:\documents and settings\Administrator\Preferiti\Videos.url
C:\InfoSat.txt
.
((((((((((((((((((((((((( Files Creati Da 2008-12-28 al 2009-01-29 )))))))))))))))))))))))))))))))))))
.
2009-01-28 22:13 . 2009-01-28 22:13 <DIR> d-------- c:\programmi\Trend Micro
2009-01-28 22:07 . 2009-01-28 22:07 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-01-28 22:07 . 2009-01-28 22:07 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-01-28 22:07 . 2009-01-28 22:07 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2009-01-28 22:07 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-28 22:07 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-28 22:00 . 2009-01-29 14:12 <DIR> d--h----- c:\documents and settings\Administrator\Dati applicazioni\drivers
2009-01-28 21:38 . 2009-01-28 21:48 <DIR> d-------- c:\programmi\FindyKill
2009-01-24 20:09 . 2009-01-24 20:09 <DIR> d-------- c:\programmi\File comuni\AVSMedia
2009-01-24 20:09 . 2009-01-25 16:09 <DIR> d-------- c:\programmi\AVS4YOU
2009-01-24 20:09 . 2009-01-24 20:09 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\AVS4YOU
2009-01-24 20:09 . 2009-01-24 20:09 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\AVS4YOU
2009-01-24 20:09 . 2006-03-03 10:02 658,432 --a------ c:\windows\system32\cc3270mt.dll
2009-01-24 20:09 . 2002-01-05 15:40 487,424 --a------ c:\windows\system32\msvcp70.dll
2009-01-24 20:09 . 2003-05-21 13:50 24,576 --a------ c:\windows\system32\msxml3a.dll
2009-01-22 18:46 . 2001-09-24 11:58 230 --------- c:\windows\XIIIHooligans.ini
2009-01-19 21:20 . 1996-10-16 11:49 301,568 --a------ c:\windows\unin0410.exe
2009-01-15 23:01 . 2009-01-15 23:01 <DIR> d-------- c:\windows\{C173E1F3-D2DF-4B8D-89BC-9A3AF75E2AC7}
2009-01-15 23:01 . 2009-01-15 23:01 <DIR> d-------- c:\programmi\USRobotics
2009-01-15 21:51 . 2009-01-15 21:51 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\InstallShield
2009-01-14 15:31 . 2009-01-14 15:31 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Yahoo!
2009-01-12 19:51 . 2008-04-13 11:45 60,032 --a------ c:\windows\system32\drivers\USBAUDIO.sys
2009-01-12 19:51 . 2008-04-13 11:45 60,032 --a--c--- c:\windows\system32\dllcache\usbaudio.sys
2009-01-12 19:50 . 2008-01-29 09:39 77,056 --a------ c:\windows\system32\drivers\HDJMidi.sys
2009-01-12 19:50 . 2009-01-12 19:50 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-01-12 19:50 . 2009-01-12 19:50 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_HDJBulk_01005.Wdf
2009-01-12 19:50 . 2009-01-12 19:50 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_HDJAsioK_01005.Wdf
2009-01-12 19:49 . 2006-11-02 07:09 1,419,232 --a------ c:\windows\system32\WdfCoInstaller01005.dll
2009-01-12 19:47 . 2009-01-12 19:47 <DIR> d-------- c:\programmi\Guillemot
2009-01-12 19:47 . 2008-02-11 11:54 159,744 --a------ c:\windows\system32\HDJAPI.dll
2009-01-12 19:47 . 2008-02-11 11:54 106,496 --a------ c:\windows\system32\HRFDongle.dll
2009-01-12 19:47 . 2008-01-18 14:03 27,136 --a------ c:\windows\system32\HDJSAPI.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-29 12:54 196,608 -c--a-w c:\windows\system32\drivers\nStandard.bin
2009-01-29 12:52 --------- d-----w c:\documents and settings\LocalService\Dati applicazioni\VMware
2009-01-29 12:52 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\VMware
2009-01-25 19:12 --------- d-----w c:\programmi\Windows Live
2009-01-25 19:05 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\WLInstaller
2009-01-22 17:45 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-01-15 20:58 --------- d-----w c:\programmi\File comuni\Adobe
2009-01-15 20:52 --------- d-----w c:\programmi\Yahoo!
2009-01-14 14:31 --------- d-----w c:\programmi\CCleaner
2008-12-21 13:22 --------- d-----w c:\programmi\Microsoft
2008-12-21 13:21 --------- d-----w c:\programmi\Windows Live SkyDrive
2008-12-21 13:12 --------- d-----w c:\programmi\File comuni\Windows Live
2008-12-13 19:29 --------- d-----w c:\programmi\Illustrate
2008-12-13 19:29 --------- d-----w c:\documents and settings\Administrator\Dati applicazioni\AccurateRip
2008-12-13 19:27 5,068,152 ----a-w c:\windows\system32\SpoonUninstall.exe
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-10 15:41 --------- d-----w c:\documents and settings\Administrator\Dati applicazioni\DivX
2008-12-10 15:39 --------- d-----w c:\programmi\DivX
2008-12-01 20:25 --------- d-----w c:\programmi\Horizons 2
2008-12-01 20:23 --------- d-----w c:\documents and settings\Administrator\Dati applicazioni\Any DVD Converter Professional
2008-11-21 21:47 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-11-21 21:47 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-11-21 21:47 129,784 ------w c:\windows\system32\pxafs.dll
2008-11-21 21:47 120,056 ------w c:\windows\system32\pxcpyi64.exe
2008-11-21 21:47 118,520 ------w c:\windows\system32\pxinsi64.exe
2008-11-21 21:46 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-11-21 21:46 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-11-21 21:44 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-11-21 21:44 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
2008-11-15 01:20 960 --sha-w C:\wvzjawja.sys
2008-07-07 12:31 24,992 -c--a-w c:\documents and settings\Administrator\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-09-26 21:41 67,696 ----a-w c:\programmi\mozilla firefox\components\jar50.dll
2008-09-26 21:41 54,376 -c--a-w c:\programmi\mozilla firefox\components\jsd3250.dll
2008-09-26 21:41 34,952 ----a-w c:\programmi\mozilla firefox\components\myspell.dll
2008-09-26 21:41 46,720 ----a-w c:\programmi\mozilla firefox\components\spellchk.dll
2008-09-26 21:41 172,144 -c--a-w c:\programmi\mozilla firefox\components\xpinstal.dll
2008-09-26 22:41 16,384 -csha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-09-26 22:41 32,768 -csha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
2008-05-11 20:29 32,768 -csha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008051120080512\index.dat
2008-09-26 22:41 32,768 -csha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS SmartDoctor"="c:\program files\ASUS\SmartDoctor\SmartDoctor.exe" [2007-10-30 1126400]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-11-24 94208]
"PcSync"="j:\pcsuite\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2006-09-21 137216]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"AsusStartupHelp"="c:\programmi\ASUS\AASP\1.00.24\AsRunHelp.exe" [2006-12-29 363008]
"Launch Ai Booster"="c:\programmi\ASUS\AI Booster\OverClk.exe" [2006-12-08 3714048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"RemoteControl"="c:\programmi\ASUS\ASUS Remote\RemoteControlAppl.exe" [2007-02-12 65536]
"PCMService"="c:\programmi\CyberLink\PowerCinema\PCMService.exe" [2007-02-09 159744]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"PCSuiteTrayApplication"="j:\pcsuite\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
"Gtwatch"="c:\windows\gtwatch.exe" [2000-11-13 28672]
"VMware hqtray"="c:\programmi\VMware\VMware Player\hqtray.exe" [2008-05-15 55856]
"CanonSolutionMenu"="c:\programmi\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\programmi\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"SMSTray"="j:\samsung mp3\SMSTray.exe" [2007-12-14 132624]
"nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
USRobotics Wireless USB Adapter.lnk - c:\programmi\USRobotics\Wireless USB Manager\USR54G.exe [2006-04-14 663552]
Watch.lnk - c:\windows\twain_32\Trust\Direct Webscan\WATCH.exe [2008-01-24 356352]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\ASUS\ASUS Splendid
ASUS Splendid.lnk - c:\programmi\ASUS\ASUS Splendid\ASUSplendid.exe [2008-01-01 651264]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "c:\progra~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\VMware\\VMware Player\\bin\\vmware-vmx.exe"=
"j:\\MotoGP 2007\\motogp.exe"=
"f:\\Matteo\\eMule\\emule.exe"=
"f:\\Matteo\\eMule10\\emule.exe"=
"k:\\Matteo\\eMule10\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"j:\\eMuleprimo\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4672:UDP"= 4672:UDP:eMule_UDP
"4662:TCP"= 4662:TCP:eMule_TCP
R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [2008-01-01 2831232]
S1 aswSP;avast! Self Protection; [x]
S1 sdpiosys;sdpiosys;c:\windows\system32\drivers\sdpiosys.sys

c:\windows\system32\drivers\sdpiosys.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-10-20 16512]
S3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys

c:\windows\system32\Drivers\HDJBulk.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 HDJAsioK;HDJAsioK;c:\windows\system32\Drivers\HDJAsioK.sys

c:\windows\system32\Drivers\HDJAsioK.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 HDJMidi;Hercules DJ Console Rmx MIDI;c:\windows\system32\drivers\HDJMidi.sys [2009-01-12 77056]
S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2008-01-14 31872]
S3 USRWGU(USR);USRobotics Wireless USB Adapter(USR);c:\windows\system32\drivers\USRWGU.sys [2005-12-29 408064]
S4 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys

c:\windows\system32\DRIVERS\aswFsBlk.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S4 d3dramp32;Microsoft Direct3D;rundll32.exe c:\windows\system32\d3dramp32.dll,esov

rundll32.exe c:\windows\system32\d3dramp32.dll,esov
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S4 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [2006-11-03 13592]
.
Contenuto della cartella 'Scheduled Tasks'
2009-01-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-01-17 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-04-08 11:16]
2009-01-29 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-04-08 11:16]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-NVIDIA nTune - c:\programmi\NVIDIA Corporation\nTune\nTuneCmd.exe
HKCU-Run-WebCamRT.exe - (no file)
Notify-d3dramp32 - d3dramp32.dll
.
------- Scansione supplementare -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - i:\office\PROGRA~1\Office10\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-29 14:13:23
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(952)
c:\windows\system32\nvappfilter.dll
.
Ora fine scansione: 2009-01-29 14.14.15
ComboFix-quarantined-files.txt 2009-01-29 13:14:13
Pre-Run: 6.536.605.696 byte disponibili
Post-Run: 6,520,102,912 byte disponibili
204 --- E O F --- 2009-01-27 13:51:00