scusami...
- Codice: Seleziona tutto
ComboFix 10-06-06.03 - marti 07/06/2010 9.57.35.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1015.704 [GMT 2:00]
Eseguito da: c:\documents and settings\marti\Documenti\Download\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\File comuni\Real\Update_OB\lang\faust_it.dll
c:\programmi\File comuni\Real\Update_OB\lang\rpsearch_it.dll
c:\programmi\Real\RealPlayer\converter\rnuninst_it.dll
c:\programmi\Real\RealPlayer\lang\cdplay_it.dll
c:\programmi\Real\RealPlayer\lang\dbcomp_it.dll
c:\programmi\Real\RealPlayer\lang\embed_it.dll
c:\programmi\Real\RealPlayer\lang\gemctl_it.dll
c:\programmi\Real\RealPlayer\lang\mydevices_it.dll
c:\programmi\Real\RealPlayer\lang\pngui_it.dll
c:\programmi\Real\RealPlayer\lang\rjctl_it.dll
c:\programmi\Real\RealPlayer\lang\rjdlg_it.dll
c:\programmi\Real\RealPlayer\lang\rjeq_it.dll
c:\programmi\Real\RealPlayer\lang\rjfade_it.dll
c:\programmi\Real\RealPlayer\lang\rjmisc_it.dll
c:\programmi\Real\RealPlayer\lang\rjprog_it.dll
c:\programmi\Real\RealPlayer\lang\rjres_it.dll
c:\programmi\Real\RealPlayer\lang\rjskin_it.dll
c:\programmi\Real\RealPlayer\lang\rjviz_it.dll
c:\programmi\Real\RealPlayer\lang\rjwma_it.dll
c:\programmi\Real\RealPlayer\lang\rnuninst_it.dll
c:\programmi\Real\RealPlayer\lang\rpapp_it.dll
c:\programmi\Real\RealPlayer\lang\rpbgr_it.dll
c:\programmi\Real\RealPlayer\lang\rpbrp_it.dll
c:\programmi\Real\RealPlayer\lang\rpclsvc_it.dll
c:\programmi\Real\RealPlayer\lang\rpclutil_it.dll
c:\programmi\Real\RealPlayer\lang\rpdemand_it.dll
c:\programmi\Real\RealPlayer\lang\rpdsplyr_it.dll
c:\programmi\Real\RealPlayer\lang\rpext_it.dll
c:\programmi\Real\RealPlayer\lang\rpgutil_it.dll
c:\programmi\Real\RealPlayer\lang\rpmnpane_it.dll
c:\programmi\Real\RealPlayer\lang\rpplylst_it.dll
c:\programmi\Real\RealPlayer\lang\rpsearch_it.dll
c:\programmi\Real\RealPlayer\lang\rpwebctl_it.dll
c:\programmi\Real\RealPlayer\lang\systray_it.dll
c:\programmi\Real\RealPlayer\lang\tcdinfo_it.dll
c:\programmi\Real\RealPlayer\lang\tclsvc_it.dll
c:\programmi\Real\RealPlayer\lang\tdwnmgr_it.dll
c:\programmi\Real\RealPlayer\lang\tearm_it.dll
c:\programmi\Real\RealPlayer\lang\teasdk_it.dll
c:\programmi\Real\RealPlayer\lang\tmdedit_it.dll
c:\programmi\Real\RealPlayer\lang\tmp3_it.dll
c:\programmi\Real\RealPlayer\lang\twave_it.dll
c:\programmi\Real\RealPlayer\lang\upgrdhlp_it.dll
c:\programmi\Real\RealPlayer\lang\upgrdlib_it.dll
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Creati Da 2010-05-07 al 2010-06-07 )))))))))))))))))))))))))))))))))))
.
2010-06-02 21:08 . 2008-04-13 09:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-06-02 21:08 . 2008-04-13 09:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-26 12:35 . 2010-05-26 12:35 49152 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-05-26 12:35 . 2010-05-26 12:35 45056 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-05-26 12:35 . 2010-05-26 12:35 45056 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-05-26 12:35 . 2010-05-26 12:35 45056 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-05-26 12:35 . 2010-05-26 12:35 45056 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-07 07:58 . 2009-08-25 11:24 70336 ----a-w- c:\windows\system32\perfc010.dat
2010-06-07 07:58 . 2009-08-25 11:24 438214 ----a-w- c:\windows\system32\perfh010.dat
2010-06-07 07:53 . 2009-08-25 11:52 -------- d-----w- c:\programmi\Norton Internet Security
2010-06-07 07:52 . 2010-04-11 23:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Norton
2010-05-28 20:20 . 2010-04-11 01:14 148 ----a-w- c:\documents and settings\marti\Dati applicazioni\wklnhst.dat
2010-05-26 12:35 . 2010-05-26 12:35 40960 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-05-26 12:35 . 2010-05-26 12:35 308808 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-05-26 12:35 . 2010-05-26 12:35 14848 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-05-26 12:35 . 2010-05-26 12:35 341600 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-05-26 12:35 . 2010-05-26 12:33 -------- d-----w- c:\programmi\File comuni\Real
2010-05-26 12:34 . 2010-05-26 12:33 -------- d-----w- c:\programmi\Real
2010-05-26 12:34 . 2010-05-26 12:34 -------- d-----w- c:\programmi\File comuni\xing shared
2010-05-26 12:34 . 2010-05-26 12:34 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-05-26 12:34 . 2010-05-26 12:34 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-04-26 18:31 . 2010-04-26 18:31 -------- d-----w- c:\documents and settings\marti\Dati applicazioni\Template
2010-04-11 23:54 . 2010-04-11 23:54 0 ----a-w- c:\windows\nsreg.dat
2010-04-11 23:44 . 2010-04-11 23:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NortonInstaller
2009-03-21 14:06 . 2009-08-25 11:24 169822 --sha-r- c:\windows\system32\uhklxges.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\programmi\ASUS\Eee Docking\Eee Docking.exe" [2009-07-27 397312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-27 17881088]
"AsusACPIServer"="c:\programmi\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\programmi\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\programmi\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2009-04-09 1512744]
"SynAsusAcpi"="c:\programmi\Synaptics\SynTP\SynAsusAcpi.exe" [2009-04-09 79144]
"LiveUpdate"="c:\programmi\Asus\LiveUpdate\LiveUpdate.exe" [2009-06-25 712704]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2010-05-26 202256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\marti\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
SuperHybridEngine.lnk - c:\programmi\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-8-25 376832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7739:TCP"= 7739:TCP:pfszeits
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [18/08/2009 23.44.33 38912]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [25/08/2009 13.08.18 1015424]
S2 yyceyk;Boot Microsoft;c:\windows\system32\svchost.exe -k netsvcs [25/08/2009 13.24.54 14336]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [25/08/2009 13.05.30 1684736]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [12/08/2009 8.57.17 39040]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
yyceyk
.
Contenuto della cartella 'Scheduled Tasks'
2010-06-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3769156265-213131487-877873343-1005.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
2010-06-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3769156265-213131487-877873343-1005.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.talti.com
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Invia a Bluetooth - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\marti\Dati applicazioni\Mozilla\Firefox\Profiles\rggf6rv0.default\
FF - component: c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-snp2uvc - c:\windows\vsnp2uvc.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-07 10:02
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\yyceyk]
"ServiceDll"="c:\windows\system32\uhklxges.dll"
.
Ora fine scansione: 2010-06-07 10:03:59
ComboFix-quarantined-files.txt 2010-06-07 08:03
Pre-Run: 63.425.265.664 byte disponibili
Post-Run: 63.483.047.936 byte disponibili
WindowsXP-KB310994-SP2-Home-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 51ACEA2DF9022A69EA382AADB57275F4