ComboFix 12-03-04.02 - Alessio 05/03/2012 23.01.00.3.2 - x86Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.39.1040.18.2047.1020 [GMT 1:00]
Eseguito da: c:\users\Alessio\Desktop\abc.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\users\Alessio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Videos.url
c:\users\Alessio\Favorites\Videos.url
c:\users\Alessio\java.exe
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((((( Files Creati Da 2012-02-05 al 2012-03-05 )))))))))))))))))))))))))))))))))))
.
.
2012-03-05 22:18 . 2012-03-05 22:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-05 22:18 . 2012-03-05 22:18 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-03-02 21:33 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-02 21:33 . 2012-03-02 21:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-02 20:56 . 2012-03-05 22:18 -------- d-----w- c:\users\Alessio\AppData\Local\temp
2012-03-02 09:26 . 2012-02-08 06:03 6552120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DF780576-F82E-4AE3-88F3-8F706F211C75}\mpengine.dll
2012-02-29 21:38 . 2012-02-29 22:14 -------- d-----w- C:\abc
2012-02-29 13:16 . 2012-02-29 13:16 -------- d-----w- c:\program files\LogMeIn Hamachi
2012-02-28 21:55 . 2012-02-28 21:55 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin7.dll
2012-02-28 21:55 . 2012-02-28 21:55 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin6.dll
2012-02-28 21:55 . 2012-02-28 21:55 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin5.dll
2012-02-28 21:55 . 2012-02-28 21:55 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin4.dll
2012-02-28 21:55 . 2012-02-28 21:55 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin3.dll
2012-02-28 21:55 . 2012-02-28 21:55 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin2.dll
2012-02-28 21:55 . 2012-02-28 21:55 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin.dll
2012-02-27 11:16 . 2012-02-27 11:16 -------- d-----w- c:\users\Alessio\AppData\Local\ADDP
2012-02-27 11:16 . 2012-02-27 11:17 -------- d-----w- c:\users\Alessio\AppData\Local\Acer
2012-02-27 11:14 . 2012-02-28 16:14 -------- d-----w- c:\programdata\Acer
2012-02-27 11:11 . 2012-02-27 11:11 -------- d-----w- c:\program files\Acer
2012-02-27 11:02 . 2009-08-14 16:08 105984 ----a-w- c:\windows\system32\drivers\qcusbser.sys
2012-02-27 11:02 . 2009-08-21 16:41 25728 ----a-w- c:\windows\system32\drivers\androidusb.sys
2012-02-24 23:08 . 2012-02-26 20:30 -------- d-----w- c:\users\Alessio\AppData\Roaming\gtk-2.0
2012-02-24 23:08 . 2012-02-24 23:08 -------- d-----w- c:\users\Alessio\.thumbnails
2012-02-07 23:15 . 2012-02-08 21:40 -------- d-----w- c:\programdata\AVAST Software
2012-02-07 23:15 . 2012-02-07 23:15 -------- d-----w- c:\program files\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-22 13:26 . 2011-05-15 10:29 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-29 04:10 . 2010-02-05 16:19 237072 ------w- c:\windows\system32\MpSigStub.exe
2011-12-07 17:22 . 2011-12-22 20:18 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-12-07 17:22 . 2011-12-22 20:18 52096 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-12-07 17:22 . 2011-12-22 20:18 30592 ----a-w- c:\windows\system32\LMIport.dll
2011-12-07 17:21 . 2011-12-22 20:18 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-03 68856]
"Akamai NetSession Interface"="c:\users\Alessio\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 3329824]
"Acer AnySync"="c:\program files\Acer\AcerSync\AcerSync.exe" [2011-06-16 3044456]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-01-24 319488]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-04-12 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-12 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-12 81920]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-11-30 198160]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2006-1-12 528384]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:5704dae8b
.
[HKLM\~\startupfolder\C:^Users^Alessio^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Ritaglio schermata e avvio di OneNote 2007.lnk]
path=c:\users\Alessio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ritaglio schermata e avvio di OneNote 2007.lnk
backup=c:\windows\pss\Ritaglio schermata e avvio di OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Heck Aim]
c:\programdata\five byte byte.r11hu [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LESS CITY AMEN SETUP]
c:\programdata\Mags Bags Owns.j5mov [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
2007-02-15 17:39 151552 ----a-w- c:\acer\AcerTour\Reminder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-04-13 00:29 47392 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-11-01 22:25 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-08-02 07:33 4910912 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GM4IE]
2006-07-23 08:32 61440 ----a-w- c:\program files\SocialPlus\gm4ie.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-01-16 16:22 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2011-09-16 13:10 63048 ----a-w- c:\program files\LogMeIn\x86\LogMeInSystray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2012-02-28 16:38 1987976 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-16 21:11 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
2008-06-17 14:00 1249280 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2008-06-18 12:31 1122816 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-01-12 20:24 151552 ------w- c:\acer\Empowering Technology\eMode\PCM\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSPAP]
2007-02-02 10:30 2990080 ----a-w- c:\program files\Thrustmaster\FunAccess\PSPAP.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-11-30 10:01 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
2006-11-05 19:48 57344 ----a-w- c:\acer\WR_PopUp\WarReg_PopUp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WPCUMI]
2006-11-02 12:34 176128 ----a-w- c:\windows\System32\wpcumi.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
S2 AcerSyncSystemService;AcerSyncSystemService;c:\program files\Acer\AcerSync\AcerSyncSystemService.exe [2011-06-16 60312]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-11 20:39]
.
2012-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-11 20:39]
.
2012-03-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786955474-3549510060-3803283922-1000Core.job
- c:\users\Alessio\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-25 21:28]
.
2012-03-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786955474-3549510060-3803283922-1000UA.job
- c:\users\Alessio\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-25 21:28]
.
2010-12-15 c:\windows\Tasks\User_Feed_Synchronization-{35774BE7-2DE0-4C32-A470-2606B1CBB571}.job
- c:\windows\system32\msfeedssync.exe [2012-02-19 04:44]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://home.sweetim.com
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: &SHOUTcast Search - c:\programdata\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: Aggiungi ad Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\wpclsp.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
BHO-{08d495ab-a86c-47b0-82ef-da87bf92f730} - (no file)
BHO-{9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
Toolbar-{9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
Toolbar-{08d495ab-a86c-47b0-82ef-da87bf92f730} - (no file)
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
WebBrowser-{9565115D-C7D6-46D3-BD63-B67B481A4368} - (no file)
WebBrowser-{08D495AB-A86C-47B0-82EF-DA87BF92F730} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2012-03-05 23:18
Windows 6.0.6002 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_7de0ed9.dll"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-2786955474-3549510060-3803283922-1000\Software\SecuROM\License information*]
"datasecu"=hex:2a,88,49,ff,dc,bf,c3,16,3f,1f,30,a5,f3,38,51,51,53,cc,57,ca,b4,
b0,c7,e9,a8,dd,bf,a2,8f,45,b8,43,34,22,7b,07,98,5e,01,47,54,0e,56,23,48,20,\
"rkeysecu"=hex:17,98,39,da,9d,d0,6e,e0,da,6e,d8,17,0e,7f,dc,a5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'Explorer.exe'(5040)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
Ora fine scansione: 2012-03-05 23:24:14
ComboFix-quarantined-files.txt 2012-03-05 22:24
ComboFix2.txt 2012-02-29 22:14
.
Pre-Run: 15.244.136.448 byte disponibili
Post-Run: 15.175.327.744 byte disponibili
.
- - End Of File - - CA195E84057C9035D01E774749C69E5B