ComboFix 10-05-12.03 - Utente 13/05/2010 23.26.53.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.895.574 [GMT 2:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
((((((((((((((((((((((((( Files Creati Da 2010-04-13 al 2010-05-13 )))))))))))))))))))))))))))))))))))
.
2010-05-13 18:51 . 2010-05-13 18:51 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2010-05-13 18:51 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-13 18:51 . 2010-05-13 18:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-05-13 18:51 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-13 18:51 . 2010-05-13 18:51 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-05-13 15:22 . 2010-05-13 15:22 -------- d-----w- c:\programmi\Trend Micro
2010-05-13 15:21 . 2010-05-13 15:21 -------- d-----w- C:\hijactthis
2010-05-13 12:27 . 2010-05-13 15:07 -------- d-----w- c:\programmi\a-squared Free
2010-05-12 21:29 . 2010-05-12 21:29 -------- d-----w- C:\VritualRoot
2010-05-12 21:28 . 2010-05-12 21:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\COMODO
2010-05-12 21:28 . 2010-05-12 21:37 72465 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-05-12 21:20 . 2010-05-12 21:44 -------- d-----w- c:\programmi\COMODO
2010-05-12 21:13 . 2010-05-12 21:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Comodo Downloader
2010-05-12 20:32 . 2010-05-12 20:36 -------- d-----w- c:\windows\SxsCaPendDel
2010-04-22 23:15 . 2010-04-22 23:15 -------- d-----w- c:\programmi\CCleaner
2010-04-22 00:23 . 2010-04-22 00:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Norton
2010-04-22 00:23 . 2010-04-22 00:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Symantec
2010-04-22 00:23 . 2010-04-22 00:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NortonInstaller
2010-04-21 21:59 . 2010-04-21 21:59 152576 ----a-w- c:\windows\Jpefua.exe
2010-04-21 21:25 . 2010-04-21 21:25 57344 ----a-w- c:\documents and settings\All Users\Dati applicazioni\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-04-21 21:25 . 2010-04-21 21:22 1180952 ----a-w- c:\documents and settings\All Users\Dati applicazioni\DivX\Setup\DivXSetup.exe
2010-04-21 21:22 . 2010-05-12 20:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DivX
2010-04-19 00:50 . 2010-05-01 15:52 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\WMTools Downloaded Files
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-13 21:31 . 2008-11-24 20:53 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\tor
2010-05-13 20:22 . 2008-11-13 17:22 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-13 18:00 . 2009-02-12 16:36 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Vidalia
2010-05-13 17:17 . 2009-03-03 14:02 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Skype
2010-05-13 15:19 . 2009-03-03 14:04 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\skypePM
2010-05-12 20:46 . 2008-07-14 10:28 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-05-12 20:45 . 2008-10-14 00:06 -------- d-----w- c:\programmi\Veoh Networks
2010-05-12 20:38 . 2009-08-19 19:10 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Wuala
2010-05-12 20:32 . 2008-11-05 21:57 -------- d-----w- c:\programmi\DivX
2010-05-10 18:24 . 2010-03-11 15:30 78336 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Wuala\Program0\WDokan.dll
2010-05-10 18:24 . 2009-08-19 19:10 253952 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Wuala\Roaming\Wuala.exe
2010-05-08 13:49 . 2001-09-01 05:00 70766 ----a-w- c:\windows\system32\perfc010.dat
2010-05-08 13:49 . 2001-09-01 05:00 440500 ----a-w- c:\windows\system32\perfh010.dat
2010-04-29 21:55 . 2009-08-20 02:47 64 ----a-w- c:\windows\popcinfot.dat
2010-04-08 23:26 . 2010-04-08 23:26 277240 ----a-w- c:\windows\system32\guard32.dll
2010-04-08 23:25 . 2010-04-08 23:25 86800 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-04-08 23:25 . 2010-04-08 23:25 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-04-08 23:25 . 2010-04-08 23:25 225344 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-04-08 23:25 . 2010-04-08 23:25 15464 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-04-03 17:50 . 2008-07-19 01:30 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Datalayer
2010-04-01 23:22 . 2010-04-01 23:22 50354 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Facebook\uninstall.exe
2010-04-01 23:22 . 2010-04-01 23:22 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Facebook
2010-03-20 12:31 . 2010-03-20 12:31 -------- d-----w- c:\programmi\Pirelli
2010-03-11 15:30 . 2010-03-11 15:30 353792 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Wuala\Program0\orangevolt-4n-1.1.1.dll
2010-03-06 05:30 . 2010-03-06 05:30 847040 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Facebook\axfbootloader.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Facebook\npfbplugin_1_0_3.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"AdobeUpdater"="c:\programmi\File comuni\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
"VeohPlugin"="c:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-04-03 3558648]
"Vidalia"="c:\programmi\Vidalia Bundle\Vidalia\vidalia.exe" [2008-11-11 4033618]
"Google Update"="c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-06-06 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16844800]
"SkyTel"="SkyTel.EXE" [2007-08-03 1826816]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"avgnt"="c:\programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-01-05 413696]
"COMODO Internet Security"="c:\programmi\COMODO\COMODO Internet Security\cfp.exe" [2010-04-08 2029456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-20 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2008-7-14 217088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Utente^Menu Avvio^Programmi^Esecuzione automatica^Wuala.lnk]
path=c:\documents and settings\Utente\Menu Avvio\Programmi\Esecuzione automatica\Wuala.lnk
backup=c:\windows\pss\Wuala.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\aMSN\\bin\\wish.exe"=
"c:\\eMule\\emule.exe"=
"e:\\Programmi\\Soulseek\\slsk.exe"=
"c:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Programmi\\Soulseek\\slsk.exe"=
"c:\\Programmi\\Java\\jre6\\launch4j-tmp\\Wuala.exe"=
"c:\\Documents and Settings\\Utente\\Dati applicazioni\\Wuala\\Roaming\\Wuala.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [04/11/2008 21.50.47 716272]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [09/04/2010 1.25.46 225344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [09/04/2010 1.25.46 25240]
R2 a2free;a-squared Free Service;c:\programmi\a-squared Free\a2service.exe [13/05/2010 14.27.24 1872320]
R2 CLPSLS;COMODO livePCsupport Service;c:\programmi\COMODO\COMODO livePCsupport\CLPSLS.exe [19/02/2010 17.00.24 148744]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [17/11/2008 14.42.23 8192]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [14/07/2008 12.54.56 36864]
.
Contenuto della cartella 'Scheduled Tasks'
2010-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-2000478354-725345543-1003Core.job
- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-06 11:42]
2010-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-2000478354-725345543-1003UA.job
- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-06 11:42]
.
.
------- Scansione supplementare -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\sbc4vg61.default\
FF - plugin: c:\documents and settings\Utente\Dati applicazioni\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\programmi\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
Notify-AtiExtEvent - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-13 23:31
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x84BDA1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf74e0fc3
\Driver\ACPI -> ACPI.sys @ 0xf725ecb8
\Driver\atapi -> 0x84bda1f8
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x8058236c
ParseProcedure -> ntkrnlpa.exe @ 0x8058146a
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x8058236c
ParseProcedure -> ntkrnlpa.exe @ 0x8058146a
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(3756)
c:\progra~1\ALICET~1\SMARTB~1\SBHook.dll
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\COMODO\COMODO Internet Security\cmdagent.exe
c:\programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
c:\programmi\File comuni\PCSuite\Services\ServiceLayer.exe
c:\progra~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
c:\programmi\Vidalia Bundle\Tor\tor.exe
.
**************************************************************************
.
Ora fine scansione: 2010-05-13 23:33:43 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-05-13 21:33
Pre-Run: 8.326.471.680 byte disponibili
Post-Run: 9.721.393.152 byte disponibili
- - End Of File - - A72D1E3F7A18579481EEC84745F56372