ComboFix 09-11-11.02 - ilaria 11/11/2009 21.31.27.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1015.533 [GMT 1:00]
Eseguito da: c:\documents and settings\ilaria\Desktop\gino.exe
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\ilaria\Impostazioni locali\Dati applicazioni\sufbwv.dat
c:\documents and settings\ilaria\Impostazioni locali\Dati applicazioni\sufbwv_nav.dat
c:\documents and settings\ilaria\Impostazioni locali\Dati applicazioni\sufbwv_navps.dat
c:\recycler\S-1-5-21-3849886930-3926732281-1373199100-500
c:\windows\Fonts\mushu.ttf
c:\windows\kb913800.exe
c:\windows\system32\hrmhjy.dat
c:\windows\system32\hrmhjy_navps.dat
c:\windows\system32\nvs2.inf
.
((((((((((((((((((((((((( Files Creati Da 2009-10-11 al 2009-11-11 )))))))))))))))))))))))))))))))))))
.
2009-11-11 20:17 . 2009-11-11 20:17 -------- d-----w- c:\programmi\Trend Micro
2009-11-11 20:07 . 2009-11-11 20:07 -------- d-----w- c:\windows\LastGood
2009-11-11 20:07 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-11 20:07 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-11-11 20:07 . 2009-02-13 11:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-11-11 20:07 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-11-11 20:07 . 2009-11-11 20:07 -------- d-----w- c:\programmi\Avira
2009-11-11 20:07 . 2009-11-11 20:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-11-11 19:41 . 2009-11-11 19:41 -------- d-----w- c:\programmi\VS Revo Group
2009-11-11 19:05 . 2009-11-11 19:05 -------- d-----w- c:\programmi\CCleaner
2009-11-07 20:44 . 2009-11-07 20:44 294912 ----a-w- c:\documents and settings\ilaria\Dati applicazioni\THE GREAT\upload rect bin.exe
2009-11-07 20:44 . 2009-11-07 20:44 278528 ----a-w- c:\documents and settings\ilaria\Dati applicazioni\THE GREAT\WarnSettingsUpMpeg.exe
2009-11-07 20:44 . 2009-11-11 19:58 753664 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Roam Program Comp About\grey this.exe
2009-11-07 20:44 . 2009-11-07 20:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Roam Program Comp About
2009-11-07 20:44 . 2009-11-07 20:44 749568 ----a-w- c:\documents and settings\ilaria\Dati applicazioni\THE GREAT\ofubzhkq.exe
2009-11-07 20:44 . 2009-11-07 20:44 -------- d-----w- c:\documents and settings\ilaria\Dati applicazioni\THE GREAT
2009-11-07 20:44 . 2009-11-07 20:44 -------- d-----w- c:\programmi\THE GREAT
2009-11-07 20:44 . 2009-11-07 20:43 532480 ----a-w- c:\documents and settings\ilaria\Dati applicazioni\THE GREAT\DEFYBENDEACH.exe
2009-11-07 20:43 . 2009-11-07 20:43 -------- d-----w- c:\programmi\Cicle Developement
2009-10-26 20:01 . 2009-10-26 20:01 -------- d-----w- c:\documents and settings\ilaria\Dati applicazioni\HiYo
2009-10-26 20:01 . 2009-10-26 20:01 -------- d-----w- c:\programmi\HiYo
2009-10-26 20:01 . 2009-10-26 20:01 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HiYo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-11 19:55 . 2007-07-20 09:09 -------- d-----w- c:\programmi\Alice ti aiuta
2009-11-07 20:43 . 2009-03-21 18:31 -------- d-----w- c:\programmi\Messenger Plus! Live
2009-11-04 19:26 . 2008-12-25 13:38 -------- d-----w- c:\programmi\Windows Live Safety Center
2009-10-25 10:46 . 2004-10-25 18:40 84702 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 10:46 . 2004-10-25 18:40 489980 ----a-w- c:\windows\system32\perfh010.dat
2009-10-09 17:29 . 2009-10-09 17:29 -------- d-----w- c:\documents and settings\ilaria\Dati applicazioni\ArcSoft
2009-10-09 17:28 . 2009-10-09 17:28 -------- d-----w- c:\documents and settings\ilaria\Dati applicazioni\EPSON
2009-10-09 17:27 . 2009-10-09 17:27 -------- d-----w- c:\documents and settings\ilaria\Dati applicazioni\InterTrust
2009-10-09 17:27 . 2008-05-19 20:41 -------- d-----w- c:\programmi\File comuni\Adobe
2009-10-09 17:26 . 2009-10-09 17:26 -------- d-----w- c:\programmi\ArcSoft
2009-10-09 17:26 . 2006-10-24 23:20 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-10-09 17:25 . 2009-10-09 17:25 -------- d-----w- c:\programmi\File comuni\Python
2009-10-09 17:24 . 2009-10-09 17:21 -------- d-----w- c:\programmi\EPSON
2009-09-16 18:54 . 2008-12-25 13:45 -------- d-----w- c:\programmi\Windows Live
2009-09-11 14:17 . 2004-10-25 18:38 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-10-25 18:38 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-10-25 18:39 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-28 17:46 . 2006-10-24 23:35 61264 ----a-w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-08-26 08:00 . 2004-10-25 18:40 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-14 15:12 . 2004-10-25 18:39 1850624 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="c:\apps\SMP\SmpSys.exe" [2005-12-08 975360]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-09-07 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-09-07 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-09-07 455168]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2006-05-12 774233]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-08-14 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-08-14 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-08-14 94208]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 36975]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Collegamento alla pagina delle proprietà di High Definition Audio"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Alice ti aiuta.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Alice ti aiuta.lnk
backup=c:\windows\pss\Alice ti aiuta.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Avvio veloce di Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Avvio veloce di Adobe Reader.lnk
backup=c:\windows\pss\Avvio veloce di Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\APPS\\skype\\phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R0 d346bus;d346bus;c:\windows\system32\drivers\d346bus.sys [05/06/2007 17.38.24 156800]
R0 d346prt;d346prt;c:\windows\system32\drivers\d346prt.sys [05/06/2007 17.38.24 5248]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmi\Avira\AntiVir Desktop\sched.exe [11/11/2009 21.07.42 108289]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [20/03/2009 19.12.10 54752]
R3 SynMini;USB2.0 VGA WebCam;c:\windows\system32\drivers\SynMini.sys [25/10/2006 0.20.01 1056512]
R3 SynScan;USB2.0 VGA WebCam Still Image;c:\windows\system32\drivers\SynScan.sys [25/10/2006 0.20.02 8064]
S3 fsssvc;Servizio Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21.48.42 704864]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - ANTIVIRSCHEDULERSERVICE
*NewlyCreated* - ANTIVIRSERVICE
*NewlyCreated* - AVGIO
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-11 c:\windows\Tasks\B92C1551914B8D3D.job
- c:\docume~1\ilaria\datiap~1\thegre~1\upload rect bin.exe [2009-11-07 20:44]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Settings,ProxyServer = 192.168.1.1:80
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxTCP: {A59242F4-7B8C-4504-8DD2-499747D3931F} = 85.37.17.5 85.38.28.77
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-11 21:40
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86A472F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86a472f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
**************************************************************************
.
Ora fine scansione: 2009-11-11 21.42.09
ComboFix-quarantined-files.txt 2009-11-11 20:42
Pre-Run: 67.406.979.072 byte disponibili
Post-Run: 71.296.786.432 byte disponibili
- - End Of File - - 4C101A1C79E4DAB5CA2809545F7F3E54