ComboFix 12-06-06.02 - Marco Licari 07/06/2012 17.01.26.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1015.496 [GMT 2:00]
Eseguito da: c:\documents and settings\Marco Licari\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Marco Licari\Desktop\CFScript.txt
AV: Avira Desktop *Enabled/Updated* {00000000-0000-0000-0000-000000000000}
AV: Avira Desktop *Enabled/Updated* {00000000-0715-0000-08F2-12003094807C}
* Creato nuovo punto di ripristino
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
FILE ::
"c:\documents and settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
"c:\documents and settings\Marco Licari\Impostazioni locali\Dati applicazioni\Facebook\Update\FacebookUpdate.exe"
"c:\programmi\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe"
"c:\programmi\Roxio\BackOnTrack\Instant Restore\BOTService.exe"
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Marco Licari\Impostazioni locali\Dati applicazioni\Facebook\Update\FacebookUpdate.exe
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_BOTSERVICE
-------\Legacy_SKYPE_C2C_SERVICE
-------\Service_BOTService
-------\Service_Skype C2C Service
-------\Legacy_9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269
-------\Service_9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269
.
.
((((((((((((((((((((((((( Files Creati Da 2012-05-07 al 2012-06-07 )))))))))))))))))))))))))))))))))))
.
.
2012-06-05 23:59 . 2012-06-05 23:59 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-06-05 23:57 . 2012-06-05 23:57 -------- d-----w- c:\documents and settings\Marco Licari\Dati applicazioni\Malwarebytes
2012-06-05 23:57 . 2012-06-05 23:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2012-06-05 23:57 . 2012-06-06 23:06 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2012-06-04 19:24 . 2012-06-04 19:24 -------- d-----w- c:\windows\LastGood
2012-06-03 01:37 . 2012-06-03 01:37 -------- d-----w- c:\documents and settings\Marco Licari\Impostazioni locali\Dati applicazioni\Identities
2012-06-02 10:55 . 2012-06-02 10:55 -------- d-----w- c:\documents and settings\Marco Licari\Dati applicazioni\Avira
2012-06-02 10:49 . 2012-06-02 10:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2012-05-24 17:44 . 2012-05-24 17:44 -------- d-----w- c:\documents and settings\Administrator
2012-05-22 13:05 . 2012-05-22 13:05 -------- d-----w- c:\documents and settings\Marco Licari\Impostazioni locali\Dati applicazioni\PCHealth
2012-05-11 18:00 . 2012-05-11 18:00 -------- d-----w- c:\documents and settings\Marco Licari\Dati applicazioni\Mozilla-Cache
2012-05-10 22:34 . 2012-05-10 22:34 -------- d-----w- c:\programmi\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-31 13:21 . 2011-09-28 07:06 603136 ----a-w- c:\windows\system32\crypt32.dll
2012-05-04 23:00 . 2012-04-03 23:28 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-04 23:00 . 2012-03-02 06:22 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-11 13:51 . 2012-04-11 13:51 2030080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 13:51 . 2012-04-11 13:51 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 13:51 . 2012-04-11 13:51 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-01 22:16 . 2012-04-01 22:05 21840 ----atw- c:\windows\system32\SIntfNT.dll
2012-04-01 22:16 . 2012-04-01 22:05 17212 ----atw- c:\windows\system32\SIntf32.dll
2012-04-01 22:16 . 2012-04-01 22:05 12067 ----atw- c:\windows\system32\SIntf16.dll
2012-04-01 22:03 . 2012-04-01 22:03 2829 ----a-w- c:\windows\DIIUnin.pif
2012-04-01 22:03 . 2012-04-01 22:03 102400 ----a-w- c:\windows\DIIUnin.exe
2012-04-01 21:42 . 2012-04-01 21:41 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-06_21.53.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-06-07 15:26 . 2012-06-07 15:26 16384 c:\windows\temp\Perflib_Perfdata_7dc.dat
- 2009-04-14 11:24 . 2012-05-12 13:50 99230 c:\windows\system32\perfc010.dat
+ 2009-04-14 11:24 . 2012-06-07 15:02 99230 c:\windows\system32\perfc010.dat
- 2009-04-14 11:24 . 2012-05-12 13:50 83932 c:\windows\system32\perfc009.dat
+ 2009-04-14 11:24 . 2012-06-07 15:02 83932 c:\windows\system32\perfc009.dat
+ 2009-04-14 11:24 . 2012-06-07 15:02 543016 c:\windows\system32\perfh010.dat
- 2009-04-14 11:24 . 2012-05-12 13:50 543016 c:\windows\system32\perfh010.dat
- 2009-04-14 11:24 . 2012-05-12 13:50 493388 c:\windows\system32\perfh009.dat
+ 2009-04-14 11:24 . 2012-06-07 15:02 493388 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 15:10 35696 -c--a-w- c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AESTFltr]
2009-07-06 21:06 737280 ----a-w- c:\windows\system32\AESTFltr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2012-02-03 13:26 258512 ----a-w- c:\programmi\Avira\AntiVir Desktop\avgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-15 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2012-02-02 15:16 3035968 ----a-w- c:\programmi\DAEMON Tools Pro\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-05-25 17:38 116648 ----atw- c:\documents and settings\Marco Licari\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-15 21:46 159744 ----a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP]
2009-07-14 01:54 589104 -c--a-w- c:\programmi\Hewlett-Packard\HP QuickSync\QuickSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-02-15 21:46 135168 ----a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mylbx]
2010-05-28 01:00 1699552 ----a-w- c:\programmi\My Lockbox\mylbx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-02-15 21:46 131072 ----a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-04-05 09:41 17356424 ----a-r- c:\programmi\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 13:02 254696 -c--a-w- c:\programmi\File comuni\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2009-01-16 02:40 1418536 -c--a-w- c:\programmi\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
2009-06-29 20:44 458844 ----a-w- c:\programmi\IDT\WDM\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant]
2009-07-23 09:04 498744 ----a-w- c:\programmi\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269"=2 (0x2)
"CiSvc"=3 (0x3)
"BOTService"=2 (0x2)
"BITS"=2 (0x2)
"AppMgmt"=3 (0x3)
"ALG"=3 (0x3)
"aspnet_state"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"winmgmt"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"VSS"=3 (0x3)
"UPS"=3 (0x3)
"upnphost"=3 (0x3)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SysmonLog"=3 (0x3)
"SwPrv"=3 (0x3)
"srservice"=2 (0x2)
"Spooler"=2 (0x2)
"LanmanServer"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"hpqwmiex"=3 (0x3)
"helpsvc"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"SCardSvr"=3 (0x3)
"RSVP"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"MSIServer"=3 (0x3)
"mnmsrvc"=3 (0x3)
"lanmanworkstation"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"NtmsSvc"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Hewlett-Packard\\HP QuickSync\\jre\\bin\\javaw.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\Marco Licari\\Impostazioni locali\\Dati applicazioni\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
.
R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [05/03/2012 1.14.33 43792]
R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [11/08/2009 13.17.08 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [11/08/2009 13.17.08 15856]
R0 SysCow;SysCow;c:\windows\system32\drivers\syscow32x.sys [01/07/2009 23.10.54 103792]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [01/04/2012 23.41.32 242240]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [11/08/2009 13.17.09 25584]
R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [05/03/2012 1.14.34 142648]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [11/08/2009 13.03.47 113664]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [31/03/2009 22.11.44 39424]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14.16.28 130384]
S2 MBAMService;MBAMService;"c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe"

c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S2 SkypeUpdate;Skype Updater;c:\programmi\Skype\Updater\Updater.exe [05/04/2012 11.37.38 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [04/04/2012 1.28.12 257696]
S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys

c:\windows\system32\drivers\mbam.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [06/06/2012 1.59.32 40776]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTS5121.sys

c:\windows\system32\Drivers\RTS5121.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys

c:\windows\system32\DRIVERS\Rts516xIR.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14.16.28 753504]
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-06-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 23:00]
.
2012-06-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-289857532-3307141164-1466306369-1005Core.job
- c:\documents and settings\Marco Licari\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2012-05-25 17:38]
.
2012-06-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-289857532-3307141164-1466306369-1005UA.job
- c:\documents and settings\Marco Licari\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2012-05-25 17:38]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnbuInternet Connection Wizard,ShellNext = "c:\programmi\Outlook Express\msimn.exe" //mailurl:mailto:armenigiardini@tiscali.it
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.39.0.1 10.39.0.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-06-07 17:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(2612)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\idt\wdm\STacSV.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2012-06-07 17:30:52 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-06-07 15:30
ComboFix2.txt 2012-06-06 21:59
.
Pre-Run: 20.167.286.784 byte disponibili
Post-Run: 20.079.640.576 byte disponibili
.
- - End Of File - - B4A50CCEE3A41D56E5B817623AC2EFC1