ComboFix 09-03-15.01 - gvggt 2009-03-18 15.24.10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1022.435 [GMT 1:00]
Eseguito da: d:\documents and settings\gvggt\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\File comuni\{B4530~1
c:\windows\Downloaded Program Files\
0e17f
c:\windows\Downloaded Program Files\BwiGE
c:\windows\Downloaded Program Files\gqzvpj3
c:\windows\Downloaded Program Files\l5nqw
c:\windows\Downloaded Program Files\LbmBW
c:\windows\Downloaded Program Files\ob54o
c:\windows\Downloaded Program Files\PCSXw
c:\windows\Downloaded Program Files\PmKTu
c:\windows\Downloaded Program Files\PmKTu\hitrV.dat
c:\windows\Downloaded Program Files\RLpcNo
c:\windows\Downloaded Program Files\rtim1
c:\windows\system32\mdm.exe
d:\documents and settings\gvggt\Dati applicazioni\setup_it[1].exe
.
((((((((((((((((((((((((( Files Creati Da 2009-02-18 al 2009-03-18 )))))))))))))))))))))))))))))))))))
.
Nessun nuovo file creato in questo arco di tempo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-18 02:13 --------- d-----w d:\documents and settings\gvggt\Dati applicazioni\Skype
2009-03-17 17:22 --------- d-----w d:\documents and settings\All Users\Dati applicazioni\AntiVir PersonalEdition Classic
2009-03-16 21:38 --------- d-----w c:\programmi\eMule
2009-03-14 21:19 --------- d-----w d:\documents and settings\gvggt\Dati applicazioni\Azureus
2009-03-12 13:16 --------- d-----w c:\programmi\DkZ Studio
2009-03-10 23:40 --------- d-----w c:\programmi\Azureus
2009-02-17 01:45 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-17 01:38 --------- d-----w c:\programmi\DAEMON Tools
2009-02-16 01:45 --------- d-----w d:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2009-02-16 01:44 --------- d-----w d:\documents and settings\gvggt\Dati applicazioni\SUPERAntiSpyware.com
2009-02-16 01:44 --------- d-----w c:\programmi\SUPERAntiSpyware
2009-02-16 01:44 --------- d-----w c:\programmi\File comuni\Wise Installation Wizard
2009-02-16 01:07 --------- d-----w c:\programmi\PHPNukeIT
2009-02-16 01:07 --------- d-----w c:\programmi\elenco_radio
2009-02-15 23:50 --------- d-----w d:\documents and settings\gvggt\Dati applicazioni\Malwarebytes
2009-02-15 23:50 --------- d-----w d:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-02-15 23:50 --------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-09 14:04 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 14:04 1,846,784 ------w c:\windows\system32\dllcache\win32k.sys
2009-01-30 22:51 --------- d-----w c:\programmi\PhotoScape
2009-01-16 20:15 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-20 22:31 826,368 ------w c:\windows\system32\dllcache\wininet.dll
2008-12-20 22:31 671,232 ------w c:\windows\system32\dllcache\mstime.dll
2008-12-20 22:31 477,696 ------w c:\windows\system32\dllcache\mshtmled.dll
2008-12-20 22:31 44,544 ------w c:\windows\system32\dllcache\pngfilt.dll
2008-12-20 22:31 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
2008-12-20 22:31 193,024 ------w c:\windows\system32\dllcache\msrating.dll
2008-12-20 22:31 105,984 ------w c:\windows\system32\dllcache\url.dll
2008-12-20 22:31 102,912 ------w c:\windows\system32\dllcache\occache.dll
2008-12-20 22:31 1,160,192 ------w c:\windows\system32\dllcache\urlmon.dll
2008-12-19 09:12 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-09-15 17:44 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008091520080916\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 24,576 2003-05-02 09:31:50 c:\apps\ABOARD\bak\ABoard.exe
----a-w 19,417,640 2006-01-18 11:05:18 c:\apps\skype\phone\bak\SKYPE.EXE
----a-w 975,360 2005-12-08 14:39:08 c:\apps\SMP\bak\SmpSys.exe
----a-r 313,472 2006-03-30 14:45:08 c:\programmi\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
----a-w 249,896 2007-09-10 21:04:33 c:\programmi\AntiVir PersonalEdition Classic\bak\avgnt.exe
----a-w 266,497 2008-07-17 21:43:47 c:\programmi\AntiVir PersonalEdition Classic\avgnt.exe
----a-w 94,208 2005-09-03 13:18:30 c:\programmi\File comuni\Ahead\Lib\bak\NMBgMonitor.exe
----a-w 180,269 2006-10-28 23:38:22 c:\programmi\File comuni\Real\Update_OB\bak\realsched.exe
----a-w 185,872 2008-10-29 22:44:50 c:\programmi\File comuni\Real\Update_OB\realsched.exe
----a-w 90,112 2004-11-26 09:43:34 c:\programmi\File comuni\Ulead Systems\AutoDetector\bak\monitor.exe
----a-w 310,272 2004-10-04 11:03:18 c:\programmi\Goto Software\Vade Retro\bak\Vaderetro_oe.exe
----a-w 132,496 2007-07-12 02:00:36 c:\programmi\Java\jre1.6.0_02\bin\bak\jusched.exe
----a-r 73,840 2006-12-27 15:53:42 c:\programmi\Macrogaming\SweetIM\bak\SweetIM.exe
----a-w 282,624 2007-04-27 07:41:54 c:\programmi\QuickTime\bak\qttask.exe
----a-w 15,872 2006-09-07 17:19:27 c:\programmi\Unlocker\bak\UnlockerAssistant.exe
----a-w 67,584 2005-09-29 12:01:14 c:\windows\ehome\bak\ehtray.exe
----a-w 64,512 2005-08-17 20:40:06 c:\windows\ehome\ehtray.exe
----a-w 208,952 2004-09-07 12:00:00 c:\windows\ime\IMJP8_1\bak\IMJPMIG.EXE
----a-w 208,952 2004-09-07 12:00:00 c:\windows\ime\IMJP8_1\imjpmig.exe
----a-w 15,360 2004-09-07 12:00:00 c:\windows\system32\bak\ctfmon.exe
----a-w 15,360 2008-04-14 02:14:03 c:\windows\system32\ctfmon.exe
----a-w 155,648 2001-07-09 09:50:42 c:\windows\system32\bak\NeroCheck.exe
----a-w 455,168 2004-09-07 12:00:00 c:\windows\system32\IME\TINTLGNT\bak\TINTSETP.EXE
----a-w 455,168 2004-09-07 12:00:00 c:\windows\system32\IME\TINTLGNT\tintsetp.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-26 10:32 279944 --a------ c:\programmi\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
2009-02-05 15:24 1881112 --a------ c:\programmi\PHPNukeIT\tbPHP1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{337d7945-7b40-405d-95d9-b4f5c93148f2}]
2009-01-20 15:11 1881112 --a------ c:\programmi\elenco_radio\tbele0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{337d7945-7b40-405d-95d9-b4f5c93148f2}"= "c:\programmi\elenco_radio\tbele0.dll" [2009-01-20 1881112]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\programmi\AskBarDis\bar\bin\askBar.dll" [2008-08-26 279944]
"{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}"= "c:\programmi\PHPNukeIT\tbPHP1.dll" [2009-02-05 1881112]
[HKEY_CLASSES_ROOT\clsid\{337d7945-7b40-405d-95d9-b4f5c93148f2}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CLASSES_ROOT\clsid\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{337D7945-7B40-405D-95D9-B4F5C93148F2}"= "c:\programmi\elenco_radio\tbele0.dll" [2009-01-20 1881112]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\programmi\AskBarDis\bar\bin\askBar.dll" [2008-08-26 279944]
"{2C965F3F-8EFD-4BFC-A2C5-1672845FDBBF}"= "c:\programmi\PHPNukeIT\tbPHP1.dll" [2009-02-05 1881112]
[HKEY_CLASSES_ROOT\clsid\{337d7945-7b40-405d-95d9-b4f5c93148f2}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CLASSES_ROOT\clsid\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus C20 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2001-01-19 68608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\apps\skype\phone\bak\Skype.exe" [2006-01-18 19417640]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-09-07 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-09-07 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-09-07 455168]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-17 64512]
"avgnt"="c:\programmi\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 266497]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2008-10-29 185872]
"SMSERIAL"="sm56hlpr.exe" [2005-10-18 c:\windows\sm56hlpr.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-09 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
d:\documents and settings\gvggt\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
d:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
BlueSoleil.lnk - c:\programmi\IVT Corporation\BlueSoleil\gprs.exe [2007-12-27 43608]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\FILECO~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= c:\progra~1\FILECO~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= c:\progra~1\FILECO~1\ULEADS~1\MPEG\mpegacm.acm
"vidc.XVID"= xvid.dll
"msacm.l3codec"= l3codecp.acm
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Azureus\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Programmi\\BearShare.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"<NO NAME>"= "c:\\Programmi\\PPStream\\PPStream.exe" "c:\\Programmi\\PPStream\\PPStream.exe
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\EA Games\\Ultima Online 2D Client\\client6.exe"=
"c:\\Programmi\\EA Games\\Ultima Online 2D Client\\client5.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"d:\\f1challanges\\F1Challenge2007.exe"=
"c:\\Programmi\\Lphant\\eLePhantClient.exe"=
"c:\\APPS\\skype\\phone\\bak\\SKYPE.EXE"=
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 Start BT in service;Start BT in service;c:\programmi\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-12-27 51816]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [2006-05-17 799744]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2007-03-22 20992]
R3 X10Hid;X10 Hid Device;c:\windows\system32\drivers\x10hid.sys [2006-05-17 7040]
S2 ctrlacclc;Controllo account locale;c:\windows\Downlo~1\rtim1\5jwry.exe

c:\windows\Downlo~1\rtim1\5jwry.exe
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 ovt530;Webcam Deluxe;c:\windows\system32\drivers\ov530vid.sys [2006-09-25 161792]
S3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
.
Contenuto della cartella 'Scheduled Tasks'
2009-02-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
2009-03-18 c:\windows\Tasks\Configura il mio PC.job
- c:\apps\SMP\PCSETUP.EXE [2005-11-17 09:03]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
Notify-ssqpq - c:\windows\system32\ssqpq.dll
Notify-urqpppp - urqpppp.dll
.
------- Scansione supplementare -------
.
uInternet Connection Wizard,ShellNext = iexplore
TCP: {81BCCC61-15D0-4248-8914-0D9F97BD6B82} = 85.37.17.17 85.38.28.72
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - d:\documents and settings\gvggt\Dati applicazioni\Mozilla\Firefox\Profiles\hxl45x2t.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-18 15:26:18
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON Stylus C20 Series = c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "c:\windows\system32\E_S4A.tmp"??t?9~??9~????????Z?9~????*?9~??????????????????????9~??Y???????????????????????????????????????????;~????????????????h?????????????????????????9~(?????>~????????????????
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-534961410-3740681359-3380630062-1008\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8A46D85F-23F8-DF16-E938-206BEA6B8586}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaofajcpejandmcbjh"=hex:6b,61,6e,6b,63,6e,62,67,64,61,65,66,66,69,66,6d,69,63,
67,62,6a,6b,00,00
"haefghbkdbdlglja"=hex:6b,61,6e,6b,63,6e,62,67,64,61,65,66,66,69,66,6d,69,63,
67,62,6a,6b,00,00
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1052)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\CLBCATQ.DLL
.
Ora fine scansione: 2009-03-18 15.30.51
ComboFix-quarantined-files.txt 2009-03-18 14:30:48
Pre-Run: 15.897.833.472 byte disponibili
Post-Run: 15,877,390,336 byte disponibili
249 --- E O F --- 2009-03-13 03:24:30