ComboFix 12-02-10.03 - Administrator 10/02/2012 22.44.04.1.1 - FAT32x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.502.250 [GMT 1:00]
Eseguito da: c:\documents and settings\utente\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {0012F2B4-5CC9-7C92-0300-000100000000}
AV: Avira Desktop *Enabled/Updated* {00000000-0715-0000-08F2-12001494807C}
AV: Avira Desktop *Enabled/Updated* {00000000-0715-0000-08F2-12003094807C}
AV: Avira Desktop *Enabled/Updated* {00000001-000D-0000-0400-000050555348}
AV: Avira Desktop *Enabled/Updated* {00000004-5550-4853-0000-000000000000}
AV: Avira Desktop *Enabled/Updated* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: FireWall *Enabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\alcrmv.exe
c:\windows\system32\abefeeecea1_r.dll
c:\windows\system32\autorun.ini
c:\windows\system32\bedbfaffbf_s.dll
.
.
((((((((((((((((((((((((( Files Creati Da 2012-01-10 al 2012-02-10 )))))))))))))))))))))))))))))))))))
.
.
2012-02-10 20:58 . 2012-02-10 20:58 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2012-02-10 20:58 . 2012-02-10 20:58 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2012-02-10 20:58 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-10 20:09 . 2012-02-10 20:09 -------- d-----w- c:\documents and settings\Administrator
2012-02-09 21:17 . 2012-02-09 21:17 -------- d-----w- c:\documents and settings\utente\Impostazioni locali\Dati applicazioni\ApplicationHistory
2012-02-09 20:46 . 2012-02-09 20:46 -------- d-----w- c:\documents and settings\utente\Tracing
2012-02-09 20:45 . 2012-02-09 20:45 -------- d-----w- c:\programmi\Microsoft Silverlight
2012-02-09 20:45 . 2010-04-28 06:44 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2012-02-09 20:43 . 2012-02-09 20:43 -------- d-----w- c:\programmi\Microsoft
2012-02-09 20:42 . 2012-02-09 20:43 -------- d-----w- c:\programmi\Windows Live SkyDrive
2012-02-09 20:42 . 2012-02-09 20:42 -------- d-----w- c:\programmi\Windows Live
2012-02-09 20:37 . 2012-02-09 20:37 -------- d-----w- c:\programmi\File comuni\Windows Live
2012-02-09 20:36 . 2012-02-09 20:36 -------- d-----w- c:\windows\system32\winrm
2012-02-09 20:36 . 2012-02-09 20:36 -------- d--h--w- c:\windows\$968930Uinstall_KB968930$
2012-02-09 20:35 . 2006-06-29 12:07 14048 ------w- c:\windows\system32\spmsg2.dll
2012-02-09 20:33 . 2012-02-09 20:33 -------- d-----w- c:\windows\system32\URTTEMP
2012-02-08 21:19 . 2012-02-08 21:19 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-02-08 21:10 . 2012-02-08 21:10 -------- d-sh--w- c:\documents and settings\utente\IETldCache
2012-02-08 21:03 . 2011-08-16 10:45 6144 ------w- c:\windows\system32\dllcache\iecompat.dll
2012-02-08 21:03 . 2011-11-04 19:13 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2012-02-08 21:03 . 2011-11-04 19:13 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2012-02-08 21:03 . 2011-11-04 19:13 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2012-02-08 21:00 . 2012-02-08 21:00 -------- d--h--w- c:\windows\ie8
2012-02-08 20:40 . 2012-02-08 20:40 -------- d-----w- c:\documents and settings\utente\Dati applicazioni\Avira
2012-02-08 20:27 . 2012-02-08 20:27 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Avira
2012-02-08 20:25 . 2011-12-16 08:44 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-02-08 20:25 . 2011-12-16 08:44 134856 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-02-08 20:25 . 2011-12-16 08:44 111160 ----a-w- c:\windows\system32\drivers\avfwot.sys
2012-02-08 20:25 . 2011-12-16 08:44 91096 ----a-w- c:\windows\system32\drivers\avfwim.sys
2012-02-08 20:25 . 2012-02-08 20:25 -------- d-----w- c:\programmi\Avira
2012-02-08 20:25 . 2012-02-08 20:25 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2012-02-07 22:35 . 2012-02-07 22:35 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
2012-02-07 22:31 . 2012-02-07 22:31 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Google
2012-02-07 22:15 . 2012-02-07 22:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CPA_VA
2012-02-07 22:11 . 2012-02-07 22:11 272 ----a-w- c:\windows\system32\drivers\sfi.dat
2012-02-07 22:04 . 2012-02-07 22:04 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2012-02-07 21:07 . 2004-08-19 19:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2012-02-07 20:59 . 2012-02-07 20:59 -------- d-----w- c:\programmi\MSXML 4.0
2012-02-07 20:33 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2012-02-07 20:30 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2012-02-07 20:30 . 2011-03-11 14:10 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2012-02-07 20:28 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2012-02-07 20:21 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2012-02-07 20:21 . 2009-10-15 16:29 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2012-02-07 20:21 . 2010-08-27 08:02 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2012-02-07 20:20 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2012-02-07 20:19 . 2009-03-06 14:19 286208 ------w- c:\windows\system32\dllcache\pdh.dll
2012-02-07 20:19 . 2009-02-09 11:22 111104 ------w- c:\windows\system32\dllcache\services.exe
2012-02-07 20:19 . 2009-02-09 10:51 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2012-02-07 20:19 . 2009-02-09 10:51 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2012-02-07 20:19 . 2009-02-09 10:51 683520 ------w- c:\windows\system32\dllcache\advapi32.dll
2012-02-07 20:19 . 2009-02-09 10:51 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2012-02-07 20:19 . 2009-06-21 21:47 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2012-02-07 20:17 . 2011-06-24 14:10 139656 ------w- c:\windows\system32\dllcache\rdpwd.sys
2012-02-07 20:16 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2012-02-07 20:16 . 2012-02-07 20:16 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-07 20:14 . 2012-02-07 20:14 -------- d-----w- c:\windows\Sun
2012-02-07 20:14 . 2012-02-07 20:14 -------- d-----w- c:\programmi\File comuni\Java
2012-02-07 20:13 . 2012-02-07 20:13 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-07 20:13 . 2012-02-07 20:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-07 20:12 . 2012-02-07 20:12 -------- d-----w- c:\programmi\Java
2012-02-07 20:08 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2012-02-07 19:52 . 2012-02-07 19:52 -------- d-----w- c:\documents and settings\utente\Dati applicazioni\CheckPoint
2012-02-07 19:52 . 2012-02-07 19:52 -------- d-----w- c:\documents and settings\utente\Impostazioni locali\Dati applicazioni\Temp
2012-02-07 19:51 . 2012-02-07 19:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CheckPoint
2012-02-07 19:49 . 2010-06-18 13:36 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2012-02-07 19:42 . 2010-12-09 15:15 739840 ------w- c:\windows\system32\dllcache\ntdll.dll
2012-02-07 19:39 . 2010-07-16 12:02 221696 ------w- c:\windows\system32\dllcache\wordpad.exe
2012-02-07 19:38 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys
2012-02-07 19:38 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2012-02-07 19:38 . 2010-08-16 08:44 590848 ------w- c:\windows\system32\dllcache\rpcrt4.dll
2012-02-07 19:28 . 2012-02-07 19:28 -------- d-----w- c:\programmi\CheckPoint
2012-02-06 23:38 . 2011-12-16 08:44 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-25 21:57 . 2008-04-14 03:13 293888 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 14:40 . 2008-09-15 16:24 1859584 ------w- c:\windows\system32\win32k.sys
2011-11-20 06:12 . 2008-04-14 03:14 60928 ------w- c:\windows\system32\packager.exe
2011-11-16 14:22 . 2008-04-14 03:13 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:22 . 2008-04-14 03:13 152064 ----a-w- c:\windows\system32\schannel.dll
2012-01-29 16:26 . 2012-02-07 19:45 134104 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"preload"="c:\windows\RUNXMLPL.exe" [2005-05-19 32768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 77824]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2005-02-04 102490]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 708698]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-10-26 212992]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-10-26 2889728]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"LaunchAp"="c:\programmi\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"PowerKey"="c:\programmi\Launch Manager\PowerKey.exe" [2002-08-30 94208]
"LManager"="c:\programmi\Launch Manager\HotkeyApp.exe" [2005-06-06 69632]
"CtrlVol"="c:\programmi\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"LMgrOSD"="c:\programmi\Launch Manager\OSDCtrl.exe" [2005-07-25 241664]
"Wbutton"="c:\programmi\Launch Manager\Wbutton.exe" [2005-07-25 81920]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-10-31 385024]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2011-06-09 254696]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2011-12-16 258512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\programmi\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"Malwarebytes Anti-Malware (cleanup)"="c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll" [2012-01-13 1081416]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Windows Search.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
2005-05-17 16:42 933888 ------w- c:\programmi\Brother\ControlCenter2\brctrcen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2005-03-11 00:28 40960 ----a-w- c:\programmi\ScanSoft\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2005-03-11 00:01 57393 ----a-w- c:\programmi\ScanSoft\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2005-03-09 17:59 49152 ------w- c:\program files\Arcade\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-05-27 09:50 413696 ----a-w- c:\programmi\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
2005-01-26 17:02 49152 ------w- c:\programmi\Brother\Brmfl05a\BrStDvPt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-10-14 09:22 155648 ----a-r- c:\programmi\File comuni\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2007-12-26 16:19 185896 ----a-w- c:\programmi\File comuni\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2008-05-02 04:15 15872 ----a-w- c:\programmi\Unlocker\UnlockerAssistant.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\System32\\mmc.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Gestione remota Windows
.
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [08/02/2012 21.25.28 111160]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [08/02/2012 21.25.28 91096]
S1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [07/02/2012 0.38.32 36000]
S1 mailKmd;mailKmd; [x]
S2 AntiVirFirewallService;Avira FireWall;c:\programmi\Avira\AntiVir Desktop\avfwsvc.exe [08/02/2012 21.25.28 616400]
S2 AntiVirMailService;Avira Mail Protection;c:\programmi\Avira\AntiVir Desktop\avmailc.exe [08/02/2012 21.25.28 342480]
S2 AntiVirSchedulerService;Avira Pianificatore;c:\programmi\Avira\AntiVir Desktop\sched.exe [08/02/2012 21.25.31 86224]
S2 AntiVirWebService;Avira Web Protection;c:\programmi\Avira\AntiVir Desktop\avwebgrd.exe [08/02/2012 21.25.28 463824]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [07/02/2012 23.30.39 136176]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [18/04/2003 18.06.26 8192]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [07/02/2012 23.30.39 136176]
S3 PAC7311;Trust Webcam 14839;c:\windows\system32\drivers\PA707UCM.SYS [18/10/2005 11.48.38 154752]
S3 POWERKEY;POWERKEY;c:\programmi\Launch Manager\POWERKEY.SYS [19/12/2000 18.29.52 2343]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14/04/2008 4.14.22 14336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
.
2012-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2012-02-07 22:30]
.
2012-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2012-02-07 22:30]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://global.acer.com/LSP: c:\programmi\Avira\AntiVir Desktop\avsda.dll
TCP: Interfaces\{E7DE8C1A-6A68-48F2-910D-DB10CC9375BC}: NameServer = 8.26.56.26,156.154.70.22
TCP: Interfaces\{F6D4F57A-F25A-4C9F-84AB-6656A40F5505}: NameServer = 8.26.56.26,156.154.70.22
DPF: Microsoft XML Parser for Java
DPF: {E460C525-1FB6-40C8-A309-669BF787DDB3} -
hxxp://aiuto.alice.it/ata/static/instal ... _4-1-5.cabFF - ProfilePath -
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
MSConfigStartUp-Adobe Reader Speed Launcher - c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-AliceRE_McciTrayApp - c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
MSConfigStartUp-Motive SmartBridge - c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-02-10 22:49
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140AC1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2012-02-10 22:51:36
ComboFix-quarantined-files.txt 2012-02-10 21:51
.
Pre-Run: 42.197.876.736 byte disponibili
Post-Run: 42.177.757.184 byte disponibili
.
- - End Of File - - 4650106FCC38750D9B14E930D6DCB905