ComboFix 09-04-15.08 - Claudio 15/04/2009 23.21.53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2038.1130 [GMT 2:00]
Eseguito da: c:\documents and settings\Claudio\Desktop\dsadasdsa.exe
AV: avast! antivirus 4.8.1335 [VPS 090414-0] *On-access scanning enabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_000010_.tmp.dll
.
((((((((((((((((((((((((( Files Creati Da 2009-03-15 al 2009-04-15 )))))))))))))))))))))))))))))))))))
.
2009-04-14 12:49 . 2009-04-14 12:49 0 --sha-r C:\kht
2009-04-14 12:49 . 2009-04-14 12:49 925 --sha-r c:\windows\system32\autorun.in
2009-04-14 12:49 . 2009-04-14 12:49 1007 --sha-r c:\windows\system32\autorun.i
2009-04-14 12:17 . 2005-10-16 06:00 12928 ----a-w c:\windows\system32\drivers\filedisk.sys
2009-04-11 23:54 . 2009-04-11 23:54 -------- d-----w c:\documents and settings\Claudio\dwhelper
2009-04-09 12:29 . 2009-04-09 12:29 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\105myPlayer
2009-04-05 20:24 . 2009-04-07 14:57 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\uTorrent
2009-04-01 17:48 . 2009-04-01 17:49 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-04-01 17:44 . 2009-03-05 21:59 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-03-31 09:10 . 2009-03-31 09:10 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-03-31 09:10 . 2009-03-31 09:10 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-03-31 09:10 . 2008-03-21 11:57 14640 ------w c:\windows\system32\spmsgXP_2k3.dll
2009-03-30 23:40 . 2009-03-30 23:40 -------- d-----w c:\documents and settings\Claudio\Impostazioni locali\Dati applicazioni\HoldemLuck
2009-03-23 02:30 . 2009-03-23 02:30 -------- d-----w C:\Sandbox
2009-03-23 02:22 . 2009-03-23 02:22 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\VoipCheapCom
2009-03-23 02:21 . 2009-03-23 02:21 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\VoipBuster
2009-03-21 20:59 . 2009-03-22 23:50 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\InternetCalls
2009-03-21 01:26 . 2009-03-21 01:26 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\VoipStunt
2009-03-21 01:16 . 2009-03-21 02:48 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\ADPHONE
2009-03-21 00:29 . 2009-03-23 01:37 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\Voipwise
2009-03-18 02:15 . 2008-08-26 08:26 18816 ----a-w c:\windows\system32\drivers\pccsmcfd.sys
2009-03-18 02:14 . 2008-09-15 06:29 1112288 ----a-w c:\windows\system32\wdfcoinstaller01007.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 21:38 . 2009-01-18 01:10 748691488 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-15 21:38 . 2009-01-18 01:10 748691488 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-15 21:33 . 2008-06-23 21:57 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\mirc
2009-04-15 14:13 . 2008-06-23 21:57 -------- d-----w c:\programmi\mIRC
2009-04-15 02:47 . 2009-01-18 01:10 8731088 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-15 00:22 . 2009-03-26 00:28 -------- d-----w c:\programmi\PokerStars.IT
2009-04-14 17:00 . 2008-06-23 21:22 -------- d--h--w c:\programmi\InstallShield Installation Information
2009-04-13 19:36 . 2008-07-02 20:38 -------- d-----w c:\programmi\PokerStars
2009-04-09 12:29 . 2009-04-09 12:28 -------- d-----w c:\programmi\105 myPlayer
2009-04-08 12:08 . 2004-08-30 20:00 70964 ----a-w c:\windows\system32\perfc010.dat
2009-04-08 12:08 . 2004-08-30 20:00 440738 ----a-w c:\windows\system32\perfh010.dat
2009-04-05 22:31 . 2008-06-23 22:40 -------- d-----w c:\programmi\Full Tilt Poker
2009-04-05 20:24 . 2009-04-05 20:24 -------- d-----w c:\programmi\uTorrent
2009-04-05 16:29 . 2009-04-05 16:29 -------- d-----w c:\programmi\File comuni\Adobe AIR
2009-04-04 21:07 . 2008-11-04 13:45 -------- d-----w c:\programmi\Italian VIP Club
2009-04-04 20:55 . 2008-07-11 00:08 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\Apple Computer
2009-04-01 17:49 . 2009-04-01 17:48 -------- d-----w c:\programmi\iTunes
2009-04-01 17:48 . 2009-04-01 17:48 -------- d-----w c:\programmi\iPod
2009-04-01 17:48 . 2008-09-19 21:33 -------- d-----w c:\programmi\File comuni\Apple
2009-04-01 17:46 . 2009-04-01 17:46 -------- d-----w c:\programmi\QuickTime
2009-03-26 18:41 . 2008-10-05 21:09 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\Skype
2009-03-26 15:06 . 2008-10-05 21:10 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\skypePM
2009-03-26 14:07 . 2008-07-07 14:25 -------- d-----w c:\programmi\PokerStrategy
2009-03-23 20:03 . 2008-06-25 19:56 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\Microgaming
2009-03-23 17:04 . 2008-12-17 16:19 -------- d-----w c:\programmi\FTPShell
2009-03-23 02:35 . 2009-03-23 02:35 -------- d-----w c:\programmi\FreeCall.com
2009-03-18 02:16 . 2009-03-18 02:16 -------- d-----w c:\programmi\File comuni\PCSuite
2009-03-18 02:16 . 2009-03-18 02:16 -------- d-----w c:\programmi\File comuni\Nokia
2009-03-18 02:16 . 2009-03-18 02:14 -------- d-----w c:\programmi\Nokia
2009-03-18 02:15 . 2009-03-18 02:15 -------- d-----w c:\programmi\PC Connectivity Solution
2009-03-18 02:13 . 2008-08-11 11:13 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Installations
2009-03-14 15:00 . 2009-03-14 15:00 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\FLEXnet
2009-03-11 15:22 . 2008-07-15 01:12 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-03-10 21:19 . 2008-10-05 21:08 -------- d-----w c:\programmi\Skype
2009-03-08 10:12 . 2008-08-10 12:20 -------- d-----w c:\programmi\Microsoft Silverlight
2009-03-05 21:59 . 2008-12-01 16:56 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-04 15:32 . 2008-09-26 21:40 -------- d-----w c:\documents and settings\Claudio\Dati applicazioni\TeamViewer
2009-03-04 15:31 . 2009-03-04 15:31 -------- d-----w c:\programmi\TeamViewer
2009-02-22 01:29 . 2009-02-10 20:29 -------- d-----w c:\programmi\PokerTracker 3
2009-02-09 14:04 . 2004-08-30 20:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2008-12-24 14:27 . 2008-12-21 17:17 2269 ----a-w c:\documents and settings\All Users\Dati applicazioni\sortedcards.tmp
2008-12-21 17:25 . 2008-08-07 15:19 0 ----a-w c:\documents and settings\All Users\Dati applicazioni\playercachelines.tmp
2008-11-08 10:47 . 2008-06-24 00:48 2322008 ----a-w c:\documents and settings\Claudio\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-09-11 21:38 . 2008-09-11 21:38 0 ----a-w c:\documents and settings\Claudio\java_ee_sdk-5_01-windows.exe
2008-08-07 15:14 . 2008-08-07 15:14 337 ----a-w c:\documents and settings\Claudio\Impostazioni locali\Dati applicazioni\postgresinstall.bat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" [2008-07-08 486856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-08-03 202024]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="c:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2008-03-04 999424]
"IntelWireless"="c:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2008-03-04 1101824]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1028096]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2007-05-04 502544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 1828136]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-08-30 286720]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-11 143360]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-11 172032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-09-11 143360]
"ROBOTFTPSCHED"="c:\programmi\FTPShell\botsched.exe" [2004-07-26 60928]
"AppleSyncNotifier"="c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-05 177472]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-06-27 16875008]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Claudio\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
is-VOIOK.lnk - c:\documents and settings\Claudio\Desktop\Virus Removal Tool\is-VOIOK\startup.exe [2009-1-31 65536]
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-6-24 535336]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
Trusted 1e6f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-06 17:52 3885408 ----a-w c:\programmi\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-09-29 15:57 21755688 ----a-r c:\programmi\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\mIRC\\mirc.exe"=
"c:\\Programmi\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"=
"d:\\eMule\\emule.exe"=
"d:\\Programmi\\guitarhero\\GH3.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\Programmi\\ClubDelGioco\\jre\\jre\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"d:\\mIRC\\mirc.exe"=
"d:\\Programmi\\PokerStrategy\\PokerStrategy Elephant\\PokerStrategy Elephant.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\PokerStrategy\\PokerStrategy Equilator\\Equilator.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\programmi\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [2007-10-16 22640]
S1 aswSP;avast! Self Protection; [x]
S1 is-VOIOKdrv;is-VOIOKdrv;c:\windows\system32\DRIVERS\82608522.sys [2008-07-08 148496]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
S2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2004-07-19 4096]
S2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2005-04-07 78208]
S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\programmi\PostgreSQL\8.3\bin\pg_ctl.exe [2008-10-31 65536]
S3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\DRIVERS\hidshim.sys [2008-06-03 5632]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
S3 winbondhidcir;Winbond HID CIR Receiver;c:\windows\system32\DRIVERS\winbondhidcir.sys [2008-06-03 23040]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cae701e-8647-11dd-9487-001cbfc01585}]
\Shell\AutoRun\command - System\Security\DriveGuard.exe -run
\Shell\Explore\Command - System\Security\DriveGuard.exe -run
\Shell\Open\Command - System\Security\DriveGuard.exe -run
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fecb252a-5734-11dd-93e0-001cbfc01585}]
\Shell\AutoRun\command - G:\qwultj1.bat
\Shell\explore\Command - G:\qwultj1.bat
\Shell\open\Command - G:\qwultj1.bat
.
Contenuto della cartella 'Scheduled Tasks'
2009-04-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-RunOnce-Shockwave Updater - c:\windows\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -Mozilla/5.0 (Windows; U; Windows NT 5.1; it; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
MSConfigStartUp-ADPHONE - c:\programmi\ADPHONE3\ADPHONE.EXE
MSConfigStartUp-InternetCalls - c:\programmi\InternetCalls.com\InternetCalls\InternetCalls.exe
MSConfigStartUp-PoivY - c:\programmi\PoivY.com\PoivY\PoivY.exe
MSConfigStartUp-SandboxieControl - c:\programmi\Sandboxie\SbieCtrl.exe
MSConfigStartUp-VoipBuster - c:\programmi\VoipBuster.com\VoipBuster\VoipBuster.exe
MSConfigStartUp-VoipCheapCom - c:\programmi\VoipCheapCom\VoipCheapCom.exe
MSConfigStartUp-VoipStunt - c:\programmi\VoipStunt.com\VoipStunt\VoipStunt.exe
MSConfigStartUp-Voipwise - c:\programmi\Voipwise.com\Voipwise\Voipwise.exe
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: {{3063c161-2f7e-4225-ba73-08bc8f64c67e} - c:\programmi\Betway\Casino\casinogame.exe
IE: {{4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - c:\programmi\Betway\Poker\MPPoker.exe
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\programmi\PokerStars.IT\PokerStarsUpdate.exe
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
TCP: {0AC1A45B-8A21-465F-9091-2A199D4E7A02} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\Claudio\Dati applicazioni\Mozilla\Firefox\Profiles\hw3ltp2b.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.itFF - component: c:\programmi\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\programmi\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\Claudio\Dati applicazioni\Mozilla\Firefox\Profiles\hw3ltp2b.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-15 23:38
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\EverestDriver]
"ImagePath"="\??\c:\programmi\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\netprovcredman.dll
- - - - - - - > 'lsass.exe'(932)
c:\windows\system32\netprovcredman.dll
.
Ora fine scansione: 2009-04-15 23.41.20
ComboFix-quarantined-files.txt 2009-04-15 21:40
Pre-Run: 1.686.007.808 byte disponibili
Post-Run: 2.561.662.976 byte disponibili
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
231 --- E O F --- 2009-03-22 03:24