ComboFix 09-01-21.04 - Administrator 2009-01-29 14.12.26.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1040.18.3326.2798 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
 * Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
(((((((((((((((((((((((((((((((((((((   Altre eliminazioni   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Dati applicazioni\drivers\downld
c:\documents and settings\Administrator\Preferiti\Videos.url
C:\InfoSat.txt
.
(((((((((((((((((((((((((   Files Creati Da 2008-12-28 al 2009-01-29  )))))))))))))))))))))))))))))))))))
.
2009-01-28 22:13 . 2009-01-28 22:13	<DIR>	d--------	c:\programmi\Trend Micro
2009-01-28 22:07 . 2009-01-28 22:07	<DIR>	d--------	c:\programmi\Malwarebytes' Anti-Malware
2009-01-28 22:07 . 2009-01-28 22:07	<DIR>	d--------	c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-01-28 22:07 . 2009-01-28 22:07	<DIR>	d--------	c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2009-01-28 22:07 . 2009-01-14 16:11	38,496	--a------	c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-28 22:07 . 2009-01-14 16:11	15,504	--a------	c:\windows\system32\drivers\mbam.sys
2009-01-28 22:00 . 2009-01-29 14:12	<DIR>	d--h-----	c:\documents and settings\Administrator\Dati applicazioni\drivers
2009-01-28 21:38 . 2009-01-28 21:48	<DIR>	d--------	c:\programmi\FindyKill
2009-01-24 20:09 . 2009-01-24 20:09	<DIR>	d--------	c:\programmi\File comuni\AVSMedia
2009-01-24 20:09 . 2009-01-25 16:09	<DIR>	d--------	c:\programmi\AVS4YOU
2009-01-24 20:09 . 2009-01-24 20:09	<DIR>	d--------	c:\documents and settings\All Users\Dati applicazioni\AVS4YOU
2009-01-24 20:09 . 2009-01-24 20:09	<DIR>	d--------	c:\documents and settings\Administrator\Dati applicazioni\AVS4YOU
2009-01-24 20:09 . 2006-03-03 10:02	658,432	--a------	c:\windows\system32\cc3270mt.dll
2009-01-24 20:09 . 2002-01-05 15:40	487,424	--a------	c:\windows\system32\msvcp70.dll
2009-01-24 20:09 . 2003-05-21 13:50	24,576	--a------	c:\windows\system32\msxml3a.dll
2009-01-22 18:46 . 2001-09-24 11:58	230	---------	c:\windows\XIIIHooligans.ini
2009-01-19 21:20 . 1996-10-16 11:49	301,568	--a------	c:\windows\unin0410.exe
2009-01-15 23:01 . 2009-01-15 23:01	<DIR>	d--------	c:\windows\{C173E1F3-D2DF-4B8D-89BC-9A3AF75E2AC7}
2009-01-15 23:01 . 2009-01-15 23:01	<DIR>	d--------	c:\programmi\USRobotics
2009-01-15 21:51 . 2009-01-15 21:51	<DIR>	d--------	c:\documents and settings\Administrator\Dati applicazioni\InstallShield
2009-01-14 15:31 . 2009-01-14 15:31	<DIR>	d--------	c:\documents and settings\Administrator\Dati applicazioni\Yahoo!
2009-01-12 19:51 . 2008-04-13 11:45	60,032	--a------	c:\windows\system32\drivers\USBAUDIO.sys
2009-01-12 19:51 . 2008-04-13 11:45	60,032	--a--c---	c:\windows\system32\dllcache\usbaudio.sys
2009-01-12 19:50 . 2008-01-29 09:39	77,056	--a------	c:\windows\system32\drivers\HDJMidi.sys
2009-01-12 19:50 . 2009-01-12 19:50	0	--ah-----	c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-01-12 19:50 . 2009-01-12 19:50	0	--ah-----	c:\windows\system32\drivers\Msft_Kernel_HDJBulk_01005.Wdf
2009-01-12 19:50 . 2009-01-12 19:50	0	--ah-----	c:\windows\system32\drivers\Msft_Kernel_HDJAsioK_01005.Wdf
2009-01-12 19:49 . 2006-11-02 07:09	1,419,232	--a------	c:\windows\system32\WdfCoInstaller01005.dll
2009-01-12 19:47 . 2009-01-12 19:47	<DIR>	d--------	c:\programmi\Guillemot
2009-01-12 19:47 . 2008-02-11 11:54	159,744	--a------	c:\windows\system32\HDJAPI.dll
2009-01-12 19:47 . 2008-02-11 11:54	106,496	--a------	c:\windows\system32\HRFDongle.dll
2009-01-12 19:47 . 2008-01-18 14:03	27,136	--a------	c:\windows\system32\HDJSAPI.dll
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-29 12:54	196,608	-c--a-w	c:\windows\system32\drivers\nStandard.bin
2009-01-29 12:52	---------	d-----w	c:\documents and settings\LocalService\Dati applicazioni\VMware
2009-01-29 12:52	---------	d-----w	c:\documents and settings\All Users\Dati applicazioni\VMware
2009-01-25 19:12	---------	d-----w	c:\programmi\Windows Live
2009-01-25 19:05	---------	d-----w	c:\documents and settings\All Users\Dati applicazioni\WLInstaller
2009-01-22 17:45	---------	d--h--w	c:\programmi\InstallShield Installation Information
2009-01-15 20:58	---------	d-----w	c:\programmi\File comuni\Adobe
2009-01-15 20:52	---------	d-----w	c:\programmi\Yahoo!
2009-01-14 14:31	---------	d-----w	c:\programmi\CCleaner
2008-12-21 13:22	---------	d-----w	c:\programmi\Microsoft
2008-12-21 13:21	---------	d-----w	c:\programmi\Windows Live SkyDrive
2008-12-21 13:12	---------	d-----w	c:\programmi\File comuni\Windows Live
2008-12-13 19:29	---------	d-----w	c:\programmi\Illustrate
2008-12-13 19:29	---------	d-----w	c:\documents and settings\Administrator\Dati applicazioni\AccurateRip
2008-12-13 19:27	5,068,152	----a-w	c:\windows\system32\SpoonUninstall.exe
2008-12-11 10:57	333,952	----a-w	c:\windows\system32\drivers\srv.sys
2008-12-10 15:41	---------	d-----w	c:\documents and settings\Administrator\Dati applicazioni\DivX
2008-12-10 15:39	---------	d-----w	c:\programmi\DivX
2008-12-01 20:25	---------	d-----w	c:\programmi\Horizons 2
2008-12-01 20:23	---------	d-----w	c:\documents and settings\Administrator\Dati applicazioni\Any DVD Converter Professional
2008-11-21 21:47	524,288	----a-w	c:\windows\system32\DivXsm.exe
2008-11-21 21:47	3,596,288	----a-w	c:\windows\system32\qt-dx331.dll
2008-11-21 21:47	129,784	------w	c:\windows\system32\pxafs.dll
2008-11-21 21:47	120,056	------w	c:\windows\system32\pxcpyi64.exe
2008-11-21 21:47	118,520	------w	c:\windows\system32\pxinsi64.exe
2008-11-21 21:46	200,704	----a-w	c:\windows\system32\ssldivx.dll
2008-11-21 21:46	1,044,480	----a-w	c:\windows\system32\libdivx.dll
2008-11-21 21:44	161,096	----a-w	c:\windows\system32\DivXCodecVersionChecker.exe
2008-11-21 21:44	12,288	----a-w	c:\windows\system32\DivXWMPExtType.dll
2008-11-15 01:20	960	--sha-w	C:\wvzjawja.sys
2008-07-07 12:31	24,992	-c--a-w	c:\documents and settings\Administrator\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-09-26 21:41	67,696	----a-w	c:\programmi\mozilla firefox\components\jar50.dll
2008-09-26 21:41	54,376	-c--a-w	c:\programmi\mozilla firefox\components\jsd3250.dll
2008-09-26 21:41	34,952	----a-w	c:\programmi\mozilla firefox\components\myspell.dll
2008-09-26 21:41	46,720	----a-w	c:\programmi\mozilla firefox\components\spellchk.dll
2008-09-26 21:41	172,144	-c--a-w	c:\programmi\mozilla firefox\components\xpinstal.dll
2008-09-26 22:41	16,384	-csha-w	c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-09-26 22:41	32,768	-csha-w	c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
2008-05-11 20:29	32,768	-csha-w	c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008051120080512\index.dat
2008-09-26 22:41	32,768	-csha-w	c:\windows\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((((((   Punti Reg Caricati   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati. 
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS SmartDoctor"="c:\program files\ASUS\SmartDoctor\SmartDoctor.exe" [2007-10-30 1126400]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-11-24 94208]
"PcSync"="j:\pcsuite\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2006-09-21 137216]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"AsusStartupHelp"="c:\programmi\ASUS\AASP\1.00.24\AsRunHelp.exe" [2006-12-29 363008]
"Launch Ai Booster"="c:\programmi\ASUS\AI Booster\OverClk.exe" [2006-12-08 3714048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"RemoteControl"="c:\programmi\ASUS\ASUS Remote\RemoteControlAppl.exe" [2007-02-12 65536]
"PCMService"="c:\programmi\CyberLink\PowerCinema\PCMService.exe" [2007-02-09 159744]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"PCSuiteTrayApplication"="j:\pcsuite\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
"Gtwatch"="c:\windows\gtwatch.exe" [2000-11-13 28672]
"VMware hqtray"="c:\programmi\VMware\VMware Player\hqtray.exe" [2008-05-15 55856]
"CanonSolutionMenu"="c:\programmi\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\programmi\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"SMSTray"="j:\samsung mp3\SMSTray.exe" [2007-12-14 132624]
"nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
 USRobotics Wireless USB Adapter.lnk - c:\programmi\USRobotics\Wireless USB Manager\USR54G.exe [2006-04-14 663552]
Watch.lnk - c:\windows\twain_32\Trust\Direct Webscan\WATCH.exe [2008-01-24 356352]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\ASUS\ASUS Splendid
ASUS Splendid.lnk - c:\programmi\ASUS\ASUS Splendid\ASUSplendid.exe [2008-01-01 651264]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "c:\progra~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\VMware\\VMware Player\\bin\\vmware-vmx.exe"=
"j:\\MotoGP 2007\\motogp.exe"=
"f:\\Matteo\\eMule\\emule.exe"=
"f:\\Matteo\\eMule10\\emule.exe"=
"k:\\Matteo\\eMule10\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"j:\\eMuleprimo\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4672:UDP"= 4672:UDP:eMule_UDP
"4662:TCP"= 4662:TCP:eMule_TCP
R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [2008-01-01 2831232]
S1 aswSP;avast! Self Protection; [x]
S1 sdpiosys;sdpiosys;c:\windows\system32\drivers\sdpiosys.sys 

 c:\windows\system32\drivers\sdpiosys.sys 
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-10-20 16512]
S3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys 

 c:\windows\system32\Drivers\HDJBulk.sys 
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 HDJAsioK;HDJAsioK;c:\windows\system32\Drivers\HDJAsioK.sys 

 c:\windows\system32\Drivers\HDJAsioK.sys 
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 HDJMidi;Hercules DJ Console Rmx MIDI;c:\windows\system32\drivers\HDJMidi.sys [2009-01-12 77056]
S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2008-01-14 31872]
S3 USRWGU(USR);USRobotics Wireless USB Adapter(USR);c:\windows\system32\drivers\USRWGU.sys [2005-12-29 408064]
S4 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys 

 c:\windows\system32\DRIVERS\aswFsBlk.sys 
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S4 d3dramp32;Microsoft Direct3D;rundll32.exe c:\windows\system32\d3dramp32.dll,esov 

 rundll32.exe c:\windows\system32\d3dramp32.dll,esov 
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S4 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [2006-11-03 13592]
.
Contenuto della cartella 'Scheduled Tasks'
2009-01-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-01-17 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-04-08 11:16]
2009-01-29 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-04-08 11:16]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-NVIDIA nTune - c:\programmi\NVIDIA Corporation\nTune\nTuneCmd.exe
HKCU-Run-WebCamRT.exe - (no file)
Notify-d3dramp32 - d3dramp32.dll
.
------- Scansione supplementare -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - i:\office\PROGRA~1\Office10\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
FF - ProfilePath - 
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, 
http://www.gmer.netRootkit scan 2009-01-29 14:13:23
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ... 
scansione entrate autostart nascoste ... 
Scansione files nascosti ... 
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(952)
c:\windows\system32\nvappfilter.dll
.
Ora fine scansione: 2009-01-29 14.14.15
ComboFix-quarantined-files.txt  2009-01-29 13:14:13
Pre-Run: 6.536.605.696 byte disponibili
Post-Run: 6,520,102,912 byte disponibili
204	--- E O F ---	2009-01-27 13:51:00