Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1613 [GMT 2:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090509-0] *On-access scanning disabled* (Updated)
FW: ActiveArmor Firewall *disabled*
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\windows\system32\bgotrtu0.dll
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Creati Da 2009-04-10 al 2009-05-10 )))))))))))))))))))))))))))))))))))
.
2009-05-02 07:30 . 2009-05-02 07:31 115855 ----a-w c:\windows\hpqins07.dat
2009-05-02 07:12 . 2009-05-02 07:12 -------- d--h--w c:\documents and settings\All Users\Dati applicazioni\CanonIJSolutionMenu
2009-05-02 07:11 . 2009-05-02 07:11 -------- d-----w c:\documents and settings\Administrator\Dati applicazioni\CD-LabelPrint
2009-05-02 07:10 . 2009-05-02 07:10 -------- d--h--w c:\documents and settings\All Users\Dati applicazioni\CanonIJMyPrinter
2009-05-02 07:09 . 2009-05-02 07:09 -------- d-----w c:\programmi\File comuni\CANON
2009-05-01 13:05 . 2009-05-01 13:05 -------- d-----w c:\windows\Sun
2009-05-01 12:43 . 2009-05-01 12:43 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-01 12:43 . 2009-05-01 12:43 -------- d-----w c:\programmi\Java
2009-04-22 20:05 . 2009-04-22 20:05 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Hewlett-Packard
2009-04-22 20:05 . 2007-09-07 10:30 118272 ----a-w c:\windows\system32\hpz3l4xa.dll
2009-04-22 20:05 . 2007-01-13 08:31 258048 ----a-r c:\windows\system32\hpzids01.dll
2009-04-22 20:04 . 2009-04-26 16:50 -------- d-----w c:\programmi\HP
2009-04-22 20:02 . 2009-04-22 20:06 128467 ----a-w c:\windows\hpwins13.dat
2009-04-22 20:02 . 2007-09-26 04:48 350 ------w c:\windows\hpwmdl13.dat
2009-04-22 19:39 . 2009-05-02 11:01 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\CanonIJPLM
2009-04-22 19:33 . 2009-04-22 19:33 -------- d--h--w c:\documents and settings\All Users\Dati applicazioni\CanonBJ
2009-04-22 19:33 . 2008-04-22 05:00 230912 ----a-w c:\windows\system32\CNMLM9A.DLL
2009-04-22 19:33 . 2009-04-22 19:33 -------- d--h--w c:\windows\system32\CanonIJ Uninstaller Information
2009-04-22 19:33 . 2009-04-22 19:33 -------- d--h--w c:\programmi\CanonBJ
2009-04-22 19:32 . 2009-05-02 07:08 -------- d-----w c:\programmi\Canon
2009-04-22 18:55 . 2008-04-13 09:45 15104 -c--a-w c:\windows\system32\dllcache\usbscan.sys
2009-04-22 18:55 . 2008-04-13 09:45 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 22:19 . 2009-03-24 21:03 -------- d-----w c:\programmi\DaneaProManager5
2009-05-05 18:59 . 2009-03-21 10:16 -------- d-----w c:\programmi\PhoneDeck
2009-05-02 09:20 . 2009-03-20 21:14 336672 ----a-w c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-16 20:36 . 2001-08-31 18:00 69790 ----a-w c:\windows\system32\perfc010.dat
2009-04-16 20:36 . 2001-08-31 18:00 437644 ----a-w c:\windows\system32\perfh010.dat
2009-04-05 17:01 . 2009-04-05 17:01 -------- d-----w c:\programmi\hp deskjet 3420 series
2009-04-05 17:00 . 2009-04-05 17:00 -------- d-----w c:\programmi\Hewlett-Packard
2009-04-04 10:37 . 2009-03-20 20:47 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-03 16:15 . 2009-03-21 10:07 -------- d-----w c:\programmi\FileZilla FTP Client
2009-04-03 08:53 . 2009-04-03 08:53 -------- d-----w c:\programmi\Lavalys
2009-03-29 08:27 . 2009-03-29 08:27 -------- d-----w c:\programmi\Microsoft.NET
2009-03-29 08:16 . 2009-03-29 08:16 -------- d-----w c:\programmi\Next Limit
2009-03-28 22:34 . 2009-03-23 20:05 -------- d-----w c:\programmi\File comuni\Adobe
2009-03-28 22:03 . 2009-03-28 22:03 -------- d-----w c:\programmi\File comuni\Adobe Systems Shared
2009-03-28 21:57 . 2009-03-28 21:52 -------- d-----w c:\programmi\Alias
2009-03-28 21:52 . 2009-03-28 21:52 -------- d-----w c:\programmi\File comuni\Alias Shared
2009-03-28 21:50 . 2009-03-28 21:50 -------- d-----w c:\programmi\ArcSoft
2009-03-28 21:50 . 2009-03-20 20:58 -------- d--h--w c:\programmi\InstallShield Installation Information
2009-03-28 21:43 . 2009-03-28 21:42 -------- d-----w c:\programmi\MAXON
2009-03-28 21:28 . 2009-03-28 21:26 -------- d-----w c:\programmi\Macromedia
2009-03-28 21:28 . 2009-03-28 21:26 -------- d-----w c:\programmi\File comuni\Macromedia
2009-03-24 20:21 . 2009-03-24 20:19 -------- d-----w c:\programmi\Winamp
2009-03-23 20:18 . 2009-03-23 20:16 -------- d-----w c:\programmi\File comuni\Autodesk Shared
2009-03-23 20:18 . 2009-03-23 20:17 -------- d-----w c:\programmi\AutoCAD 2008
2009-03-23 20:16 . 2009-03-23 20:16 -------- d-----w c:\programmi\Autodesk
2009-03-23 20:10 . 2009-03-23 20:10 -------- d-----w c:\programmi\Bonjour
2009-03-23 20:05 . 2009-03-23 20:05 -------- d-----w c:\programmi\File comuni\Macrovision Shared
2009-03-23 19:58 . 2009-03-23 19:58 -------- d-----w c:\programmi\eMule AdunanzA
2009-03-21 10:16 . 2009-03-21 10:16 -------- d-----w c:\programmi\DustBuster XP
2009-03-21 10:10 . 2009-03-21 10:10 -------- d-----w c:\programmi\File comuni\McNeel Shared
2009-03-21 10:09 . 2009-03-21 10:09 -------- d-----w c:\programmi\Rhinoceros 4.0
2009-03-21 10:00 . 2009-03-21 10:00 0 ----a-w c:\windows\nsreg.dat
2009-03-21 09:56 . 2009-03-21 09:56 -------- d-----w c:\programmi\Alwil Software
2009-03-21 09:31 . 2009-03-21 09:30 -------- d-----w c:\programmi\ANI
2009-03-21 09:30 . 2009-03-21 09:30 -------- d-----w c:\programmi\D-Link
2009-03-21 09:24 . 2008-04-13 19:14 510464 ----a-w c:\windows\system32\winlogon.exe
2009-03-20 21:13 . 2009-03-20 21:13 0 ----a-w c:\windows\ativpsrm.bin
2009-03-20 21:11 . 2009-03-20 21:06 -------- d-----w c:\programmi\ATI Technologies
2009-03-20 21:10 . 2009-03-20 21:10 -------- d-----w c:\programmi\File comuni\ATI Technologies
2009-03-20 21:06 . 2009-03-20 20:57 -------- d-----w c:\programmi\File comuni\InstallShield
2009-03-20 21:03 . 2009-03-20 21:03 -------- d-----w c:\programmi\NVIDIA Corporation
2009-03-20 21:00 . 2009-03-20 21:00 -------- d-----w c:\programmi\DIFX
2009-03-20 20:58 . 2009-03-20 20:58 -------- d-----w c:\programmi\Realtek
2009-03-20 20:48 . 2009-03-20 20:48 -------- d-----w c:\programmi\microsoft frontpage
2009-03-20 20:48 . 2001-08-31 18:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-03-20 20:47 . 2009-03-20 20:47 -------- d-----w c:\programmi\Servizi in linea
2009-03-20 20:45 . 2009-03-20 20:45 21840 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-06 14:19 . 2008-04-13 19:13 286208 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:03 . 2008-04-13 19:13 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 17:08 . 2008-04-13 19:13 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-10 17:02 . 2008-04-13 18:55 2069760 ----a-w c:\windows\system32\ntkrnlpa.exe
.
------- Sigcheck -------
[-] 2009-03-21 09:24 510464 90F406811EE1EEE294792D00E21CA16C c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ANIWZCS2Service"="c:\programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"D-Link D-Link Wireless N DWA-140"="c:\programmi\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe" [2007-03-14 1388544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Acrobat Assistant 7.0"="c:\programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-16 188416]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-05-01 148888]
"CanonSolutionMenu"="c:\programmi\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\programmi\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-04-17 16143872]
"C-Media Mixer"="Mixer.exe" - c:\windows\mixer.exe [2002-10-15 1818624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Acrobat.lnk - c:\windows\Installer\{AC76BA86-1034-4700-7760-000000000002}\SC_Acrobat.exe [2009-3-29 25214]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21/03/2009 11.56.25 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21/03/2009 11.56.25 20560]
R2 renderqueue;Alias ImageStudio Render Queue;c:\programmi\Alias\ImageStudio3.0\bin\renderqueue.exe [07/11/2005 23.34.02 204800]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [21/03/2009 11.30.53 476416]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{563203b8-1c60-11de-98c6-001cf014d62e}]
\Shell\AutoRun\command - L:\LaunchU3.exe -a
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-kvasoft - c:\windows\system32\kva8wr.exe
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Settings,ProxyOverride = *.local
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti nel file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {EDB79041-108D-4CA6-A5F9-5B07698B9F9A} = 192.168.0.99
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\u3qqwbx5.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - plugin: c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\u3qqwbx5.default\extensions\StreamingPlugin@conviva.com\platform\WINNT_x86-msvc\plugins\npconviva.4.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-10 16:48
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-05-10 16.49.47
ComboFix-quarantined-files.txt 2009-05-10 14:49
Pre-Run: 110.378.541.056 byte disponibili
Post-Run: 110.642.479.104 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
182 --- E O F --- 2009-04-15 19:44