ComboFix 14-09-16.01 - stefano 16/09/2014 17.19.19.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.39.1040.18.1023.152 [GMT 2:00]
Eseguito da: c:\users\stefano\Desktop\ComboFix.exe
Opzioni usate :: c:\users\stefano\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((( Files Creati Da 2014-08-16 al 2014-09-16 )))))))))))))))))))))))))))))))))))
.
.
2014-09-12 12:33 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-09-12 12:32 . 2014-09-12 12:36 -------- dc----w- C:\AdwCleaner
2014-09-08 14:31 . 2014-09-08 14:31 30976 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys
2014-09-08 14:16 . 2014-09-08 14:16 12872 ----a-w- c:\windows\system32\bootdelete.exe
2014-09-08 14:00 . 2014-09-08 14:16 -------- d-----w- c:\programdata\HitmanPro
2014-08-30 02:09 . 2014-08-30 17:29 -------- d-----w- c:\users\stefano\AppData\Local\AVG Web TuneUp
2014-08-30 02:09 . 2014-08-30 02:08 42784 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2014-08-30 02:08 . 2014-09-03 14:11 -------- d-----w- c:\program files\AVG Web TuneUp
2014-08-30 02:08 . 2014-08-30 02:09 -------- d-----w- c:\programdata\AVG Web TuneUp
2014-08-22 18:51 . 2014-09-16 14:52 -------- d-----w- c:\users\stefano\AppData\Roaming\vlc
2014-08-22 18:49 . 2014-08-22 18:49 -------- d-----w- c:\program files\VideoLAN
2014-08-21 15:41 . 2014-08-21 15:41 254168 ----a-w- c:\users\stefano\AppData\Roaming\Microsoft\IdentityCRL\ppcrlui.dll
2014-08-21 15:41 . 2014-08-21 15:41 15576 ----a-w- c:\users\stefano\AppData\Roaming\Microsoft\IdentityCRL\ppcrlconfig.dll
2014-08-20 09:07 . 2014-09-13 10:45 -------- d-----w- c:\program files\Mozilla Maintenance Service
2014-08-19 18:11 . 2014-08-19 18:11 -------- d-----w- c:\users\stefano\AppData\Local\MFAData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-11 03:34 . 2014-06-15 01:23 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-09-11 03:34 . 2014-06-15 01:23 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\users\stefano\AppData\Roaming\uTorrent\uTorrent.exe" [2014-07-02 1322832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2014-06-09 149280]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-08-25 5188112]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0bootdelete
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - AVGTP
.
Contenuto della cartella 'Scheduled Tasks'
.
2014-09-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-15 03:34]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.comIE: Add to AMV/AVI Video Converter... - c:\program files\Media Player Utilities 4.29\AMVConverter\grab.html
TCP: DhcpNameServer = 192.168.254.251
FF - ProfilePath - c:\users\stefano\AppData\Roaming\Mozilla\Firefox\Profiles\3cx9xzj1.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2014-09-16 17:26
Windows 6.0.6000 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
Ora fine scansione: 2014-09-16 17:27:58
ComboFix-quarantined-files.txt 2014-09-16 15:27
.
Pre-Run: 22.517.125.120 byte disponibili
Post-Run: 22.511.005.696 byte disponibili
.
- - End Of File - - 3CD244AE3806663D54738EB72BF447E7
5C616939100B85E558DA92B899A0FC36