ComboFix 10-10-19.04 - Valerio 20/10/2010 21.22.24.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1023.829 [GMT 2:00]
Eseguito da: c:\documents and settings\Valerio\Documenti\Download\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 101020-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-09-20 al 2010-10-20 )))))))))))))))))))))))))))))))))))
.
2010-10-20 18:56 . 2010-10-20 18:56 -------- d-----w- c:\documents and settings\Valerio\Dati applicazioni\Malwarebytes
2010-10-20 17:58 . 2010-10-20 17:58 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-10-20 17:58 . 2010-10-20 17:58 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-10-20 17:53 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-20 17:53 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-20 15:21 . 2010-10-20 15:21 -------- d-----w- c:\programmi\CCleaner
2010-10-20 12:12 . 2010-10-20 12:12 -------- d-----w- c:\windows\system32\wbem\Repository
2010-10-15 23:36 . 2010-10-15 23:36 -------- d-----w- c:\documents and settings\Valerio\Dati applicazioni\Airytec
2010-10-15 23:36 . 2010-10-15 23:36 -------- d-----w- c:\programmi\Airytec
2010-10-14 01:07 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-08 19:06 . 2010-10-08 19:06 -------- d-----w- c:\programmi\File comuni\Adobe
2010-10-05 22:15 . 2010-10-05 22:15 -------- d-----w- c:\programmi\iPod
2010-10-05 22:14 . 2010-10-05 22:15 -------- d-----w- c:\programmi\iTunes
2010-10-05 22:10 . 2010-10-05 22:10 -------- d-----w- c:\programmi\Bonjour
2010-09-30 09:43 . 2010-10-18 14:03 -------- d-----w- C:\FarmVilleBot_2.1
2010-09-22 16:10 . 2010-09-22 16:10 103864 ----a-w- c:\programmi\Mozilla Firefox\plugins\nppdf32.dll
2010-09-21 10:09 . 2010-09-21 10:09 -------- d-----w- c:\documents and settings\Valerio\Impostazioni locali\Dati applicazioni\Identities
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-14 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Charles\\Charles.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20/09/2010 14.04.27 691696]
S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [14/07/2010 0.39.55 111184]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [14/07/2010 0.39.55 20560]
S2 SwOffScheduler;Airytec Switch Off - Task Scheduler;c:\programmi\Airytec\Switch Off\swoff.exe -service
c:\programmi\Airytec\Switch Off\swoff.exe -service
S2 SwOffWeb;Airytec Switch Off - Web Interface;c:\programmi\Airytec\Switch Off\swoff.exe -service
c:\programmi\Airytec\Switch Off\swoff.exe -service
.
Contenuto della cartella 'Scheduled Tasks'
2010-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1659004503-1801674531-1003Core.job
- c:\documents and settings\Valerio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-08-31 14:05]
2010-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1659004503-1801674531-1003UA.job
- c:\documents and settings\Valerio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-08-31 14:05]
.
.
------- Scansione supplementare -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Valerio\Dati applicazioni\Mozilla\Firefox\Profiles\24ww12yh.default\
FF - prefs.js: browser.startup.homepage -
www.google.itFF - component: c:\programmi\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\Valerio\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
SafeBoot-klmdb.sys
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(784)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1684)
c:\windows\system32\WININET.dll
.
Ora fine scansione: 2010-10-20 21:25:47
ComboFix-quarantined-files.txt 2010-10-20 19:25
Pre-Run: 20.100.669.440 byte disponibili
Post-Run: 20.103.077.888 byte disponibili