ComboFix 11-12-09.02 - max 09/12/2011 19.01.22.1.2 - x86
Ciao a tutti,
per la prima volta ho fatto una scansione Combofix
Non ci capisco nulla qualcuno mi può spiegare cosa ha fatto e cosa devo fare ?
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.767.90 [GMT 1:00]
Eseguito da: d:\documents and settings\max\Documenti\Download\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {00000002-0002-0000-6C25-9E7C08000A00}
AV: AntiVir Desktop *Disabled/Updated* {0012F2B4-5C49-7C92-0300-000100000000}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {0012F2B4-5CE9-7C92-0300-000100000000}
AV: Avira AntiVir PersonalEdition Classic *Disabled/Outdated* {804FD408-FFA4-00FC-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition Classic *Disabled/Updated* {804FD408-FFA4-00EB-0D24-347CA8A3377C}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programmi\Setup.exe
C:\VDM96.tmp
C:\VDM97.tmp
C:\VDM98.tmp
C:\VDM99.tmp
C:\VDM9A.tmp
C:\VDM9B.tmp
C:\VDM9C.tmp
C:\VDM9D.tmp
C:\VDM9E.tmp
C:\VDM9F.tmp
C:\VDMA0.tmp
C:\VDMA1.tmp
C:\VDMA2.tmp
C:\VDMA3.tmp
C:\VDMA4.tmp
C:\VDMA5.tmp
C:\VDMA6.tmp
C:\VDMA7.tmp
C:\VDMA8.tmp
C:\VDMA9.tmp
C:\VDMAA.tmp
C:\VDMAC.tmp
C:\VDMAD.tmp
C:\VDMAE.tmp
C:\VDMAF.tmp
C:\VDMB0.tmp
C:\VDMB1.tmp
c:\windows\{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe
c:\windows\alcrmv.exe
c:\windows\IsUn0410.exe
c:\windows\ST6UNST.000
c:\windows\struct~.ini
c:\windows\system32\ctfmon .exe
c:\windows\system32\Thumbs.db
c:\windows\system32\vvvwa.bak2
c:\windows\system32\vvvwa.ini
c:\windows\TEMP\tll2bxbt.vbt
d:\documents and settings\All Users\Dati applicazioni\TEMP
d:\documents and settings\All Users\Menu Avvio\HP Image Zone .lnk
d:\documents and settings\max\WINDOWS
.
.
((((((((((((((((((((((((( Files Creati Da 2011-11-09 al 2011-12-09 )))))))))))))))))))))))))))))))))))
.
.
2011-12-09 16:10 . 2011-12-09 16:10 -------- d-----w- d:\documents and settings\max\Dati applicazioni\Malwarebytes
2011-12-09 16:10 . 2011-12-09 16:10 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-12-09 14:40 . 2011-12-09 14:40 -------- d-----w- C:\Preventon
2011-12-09 14:19 . 2011-12-09 14:19 -------- d-----w- d:\documents and settings\LocalService.NT AUTHORITY.007\Dati applicazioni\Fighters
2011-12-09 12:47 . 2011-12-09 13:17 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\clp
2011-12-09 12:47 . 2011-12-09 12:47 -------- d-----w- d:\documents and settings\NetworkService.NT AUTHORITY.007\Dati applicazioni\Fighters
2011-12-09 12:47 . 2011-12-09 12:47 -------- d-----w- d:\documents and settings\max\Dati applicazioni\Fighters
2011-12-09 12:46 . 2011-12-09 12:46 -------- d-----w- c:\programmi\File comuni\Common Toolkit Suite
2011-12-09 12:46 . 2011-12-09 12:46 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Common Toolkit Suite
2011-12-09 12:45 . 2011-12-09 12:46 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Fighters
2011-12-08 22:52 . 2011-12-08 22:52 -------- d-----w- c:\programmi\File comuni\Java
2011-12-08 21:19 . 2011-12-08 21:19 82168 ----a-w- c:\windows\system32\drivers\viragtlt.sys
2011-12-08 18:17 . 2011-12-08 18:20 4608 ----a-w- c:\windows\listcmd.bin
2011-12-08 17:42 . 2011-12-08 17:42 32562 ----a-w- c:\windows\SCHEDLGU.TXT.TMP
2011-12-08 17:42 . 2011-12-08 17:42 242768 ----a-w- c:\windows\WINDOWSUPDATE.LOG.TMP
2011-12-08 16:21 . 2011-12-08 16:21 -------- d-----w- d:\documents and settings\max\Impostazioni locali\Dati applicazioni\PackageAware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-13 21:26 . 2011-05-14 08:17 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-19 10:06 . 2011-10-19 10:06 10264 ----a-w- c:\windows\system32\drivers\avfsfilter.sys
2011-10-10 14:22 . 2004-09-03 10:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 04:06 . 2010-04-18 16:04 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-03 01:37 . 2010-04-18 16:04 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2004-09-03 10:36 603136 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 613888 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2004-09-03 10:36 23040 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2004-09-03 10:36 220160 ----a-w- c:\windows\system32\oleacc.dll
2010-05-22 20:04 . 2010-05-22 20:04 3099136 -c--a-w- c:\programmi\openofficeorg32.msi
2009-07-15 23:58 . 2008-01-31 11:43 90112 ----a-w- c:\programmi\RegCleaner.exe
2009-07-15 23:58 . 2008-01-31 10:28 262144 ----a-w- c:\programmi\RegCleaner.dll
2009-07-15 23:58 . 2007-06-13 13:23 499712 ----a-w- c:\programmi\msvcp71.dll
2009-07-15 23:58 . 2003-03-19 04:19 1060864 ----a-w- c:\programmi\MFC71.dll
2009-07-15 23:58 . 2003-02-21 11:42 348160 ----a-w- c:\programmi\msvcr71.dll
2011-11-10 22:45 . 2011-05-01 19:39 134104 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2006-01-16 23:03 . 2003-05-02 09:31 24576 c:\apps\ABOARD\bak\ABoard.exe
.
2006-01-16 23:10 . 2005-05-11 12:48 127118 c:\apps\Powercinema\bak\PCMService.exe
.
2005-12-08 15:39 . 2005-12-08 15:39 975360 c:\apps\SMP\bak\SmpSys.exe
.
2006-01-16 22:53 . 2005-08-05 20:05 344064 c:\ati technologies\ATI Control Panel\bak\atiptaxx.exe
.
2007-03-22 13:09 . 2007-03-22 13:09 63712 c:\programmi\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak\apdproxy.exe
.
2007-11-03 23:13 . 2007-10-10 18:51 39792 c:\programmi\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
2011-08-31 01:57 . 2011-08-31 01:57 40368 c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
.
2006-01-16 23:07 . 2006-01-16 23:07 180269 c:\programmi\File comuni\Real\Update_OB\bak\realsched.exe
.
2006-01-16 23:02 . 2004-11-26 10:43 90112 c:\programmi\File comuni\Ulead Systems\AutoDetector\bak\monitor.exe
.
2005-05-11 21:12 . 2005-05-11 21:12 49152 c:\programmi\HP\HP Software Update\bak\HPWuSchd2.exe
2011-05-10 00:41 . 2011-05-10 00:41 49208 c:\programmi\HP\HP Software Update\hpwuschd2.exe
.
2007-10-04 21:22 . 2007-09-24 23:11 132496 c:\programmi\Java\jre1.6.0_03\bin\bak\jusched.exe
.
2006-01-16 23:07 . 2006-01-16 23:07 98304 c:\programmi\QuickTime\bak\qttask.exe
2009-11-10 22:08 . 2009-11-10 22:08 417792 c:\programmi\QuickTime\QTTask.exe
.
2004-09-03 10:46 . 2004-08-19 13:00 208952 c:\windows\ime\IMJP8_1\bak\IMJPMIG.EXE
2004-09-03 10:46 . 2004-08-19 13:00 208952 c:\windows\ime\IMJP8_1\imjpmig.exe
.
2004-09-03 10:37 . 2004-08-19 13:00 15360 c:\windows\system32\bak\ctfmon.exe
2004-09-03 10:37 . 2008-04-14 02:14 15360 c:\windows\system32\ctfmon.exe
.
2004-09-03 10:46 . 2004-08-19 13:00 455168 c:\windows\system32\IME\TINTLGNT\bak\TINTSETP.EXE
2004-09-03 10:46 . 2004-08-19 13:00 455168 c:\windows\system32\IME\TINTLGNT\tintsetp.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-10 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"SiSPower"="SiSPower.dll" [2010-06-19 53248]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2010-09-01 281768]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-11-10 417792]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-29 937920]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
d:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-7-10 262144]
.
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Avvio rapido di HP Image Zone.lnk]
path=d:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Avvio rapido di HP Image Zone.lnk
backup=c:\windows\pss\Avvio rapido di HP Image Zone.lnkCommon Startup
.
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=d:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\APPS\\skype\\phone\\Skype.exe"=
"d:\\Documents and Settings\\All Users\\Dati applicazioni\\PPLiveVA\\Application\\pplap.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
.
R2 AV Engine Scanning Service;AV Engine Scanning Service;c:\programmi\File comuni\Common Toolkit Suite\AVEngine\AVScanningService.exe [19/10/2011 11.06.58 839240]
R2 AV Watch Service;AV Watch Service;c:\programmi\File comuni\Common Toolkit Suite\AVEngine\AVWatchService.exe [19/10/2011 11.06.58 142960]
R3 AVFSFilter;AVFSFilter;c:\windows\system32\drivers\avfsfilter.sys [19/10/2011 11.06.58 10264]
R3 xcpip;Driver protocollo TCP/IP;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]
R3 xpsec;Driver IPSEC;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]
S3 6n8uk6fsa.sys;6n8uk6fsa.sys;\??\c:\windows\system32\drivers\6n8uk6fsa.sys --> c:\windows\system32\drivers\6n8uk6fsa.sys [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [10/07/2009 17.17.12 1684736]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-12-09 c:\windows\Tasks\Garanzia estesa.job
- c:\apps\SMP\PBCARNOT.EXE [2005-11-09 12:55]
.
2011-12-09 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-16 18:22]
.
2006-04-26 c:\windows\Tasks\Promemoria registrazione 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-09-03 02:14]
.
2006-04-26 c:\windows\Tasks\Promemoria registrazione 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-09-03 02:14]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://it.ask.com/?l=dis&o=16621&gct=hp
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
Trusted Zone: bam.it\hb
TCP: DhcpNameServer = 192.168.1.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - d:\documents and settings\max\Dati applicazioni\Mozilla\Firefox\Profiles\8tzb98l0.default\
FF - prefs.js: browser.startup.homepage - http://www.google.com
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Microsoft Interactive Training - c:\windows\IsUn0410.exe
AddRemove-Voltura 1.0 - c:\windows\IsUn0410.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-09 19:15
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AV Engine Scanning Service]
"ImagePath"="C:/Programmi/File comuni/Common Toolkit Suite/AVEngine/AVScanningService.exe"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AV Watch Service]
"ImagePath"="C:/Programmi/File comuni/Common Toolkit Suite/AVEngine/AVWatchService.exe"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AV Engine Scanning Service]
"ImagePath"="C:/Programmi/File comuni/Common Toolkit Suite/AVEngine/AVScanningService.exe"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AV Watch Service]
"ImagePath"="C:/Programmi/File comuni/Common Toolkit Suite/AVEngine/AVWatchService.exe"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140C10900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140AC1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(468)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2892)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe
c:\programmi\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\programmi\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\apps\HIDSERVICE\HIDSERVICE.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
c:\programmi\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\HPZipm12.exe
c:\programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
c:\apps\Powercinema\Kernel\TV\CLSched.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Ora fine scansione: 2011-12-09 19:26:10 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-12-09 18:26
.
Pre-Run: 15.405.776.896 byte disponibili
Post-Run: 15.403.065.344 byte disponibili
.
- - End Of File - - 7FAE798A4DCB4B1338C77152BFCC1458