Bonjour,
Pourriez vous me dire ce que rapport me dit.
Merci
ComboFix 10-08-12.03 - Gonzo 13/08/2010 13:01:06.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1014.434 [GMT 3:00]
Eseguito da: c:\documents and settings\Gonzo\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
((((((((((((((((((((((((( Files Creati Da 2010-07-13 al 2010-08-13 )))))))))))))))))))))))))))))))))))
.
2010-08-13 09:58 . 2001-08-17 17:15 455680 -c--a-w- c:\windows\system32\dllcache\fus2base.sys
2010-08-13 09:58 . 2001-08-17 17:15 442240 -c--a-w- c:\windows\system32\dllcache\fpnpbase.sys
2010-08-13 09:58 . 2001-08-17 17:14 441728 -c--a-w- c:\windows\system32\dllcache\fpcmbase.sys
2010-08-13 09:58 . 2001-08-17 17:14 444416 -c--a-w- c:\windows\system32\dllcache\fpcibase.sys
2010-08-13 09:58 . 2008-04-13 06:35 34173 -c--a-w- c:\windows\system32\dllcache\forehe.sys
2010-08-13 09:58 . 2001-08-30 20:07 71680 -c--a-w- c:\windows\system32\dllcache\fnfilter.dll
2010-08-13 09:58 . 2001-08-17 17:13 27165 -c--a-w- c:\windows\system32\dllcache\fetnd5.sys
2010-08-13 09:56 . 2001-08-30 18:54 596159 -c--a-w- c:\windows\system32\dllcache\es56cvmp.sys
2010-08-13 09:55 . 2001-08-30 18:33 176128 -c--a-w- c:\windows\system32\dllcache\el99xn51.sys
2010-08-13 09:54 . 2001-08-30 18:20 23936 -c--a-w- c:\windows\system32\dllcache\dot4usb.sys
2010-08-13 09:53 . 2001-08-30 18:15 103460 -c--a-w- c:\windows\system32\dllcache\digidxb.sys
2010-08-13 09:52 . 2008-04-13 06:36 48640 -c--a-w- c:\windows\system32\dllcache\cwrwdm.sys
2010-08-13 09:51 . 2001-08-30 17:33 980034 -c--a-w- c:\windows\system32\dllcache\cicap.sys
2010-08-13 09:50 . 2001-08-30 17:19 13952 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys
2010-08-13 09:49 . 2001-08-17 17:49 23552 -c--a-w- c:\windows\system32\dllcache\atixbar.sys
2010-08-13 09:48 . 2001-08-17 18:49 26624 -c--a-w- c:\windows\system32\dllcache\alifir.sys
2010-08-13 09:47 . 2001-08-30 20:07 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-08-13 09:47 . 2010-08-13 09:58 -------- d-----w- c:\windows\LastGood
2010-08-13 08:26 . 2010-08-13 08:26 -------- d-----w- c:\documents and settings\Gonzo\Dati applicazioni\AVG9
2010-08-12 06:51 . 2010-08-12 06:51 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Apple
2010-08-10 17:17 . 2010-08-10 17:19 715152 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Simply Super Software\Trojan Remover\Data\trunins.exe
2010-08-10 17:02 . 2006-06-19 10:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-08-10 17:02 . 2006-05-25 12:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-08-10 17:02 . 2005-08-25 22:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-08-10 17:02 . 2002-03-05 22:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2010-08-10 17:02 . 2003-02-02 17:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2010-08-10 17:02 . 2010-08-10 18:29 -------- d-----w- c:\programmi\Trojan Remover
2010-08-10 05:58 . 2010-08-10 05:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WinZip
2010-08-10 04:58 . 2010-08-10 04:58 -------- d-----w- c:\programmi\Babylon
2010-08-05 10:19 . 2010-08-05 10:19 -------- d-----w- c:\programmi\iPod
2010-08-05 10:19 . 2010-08-05 10:20 -------- d-----w- c:\programmi\iTunes
2010-08-05 10:19 . 2010-08-05 10:20 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-05 10:14 . 2010-08-05 10:15 -------- d-----w- c:\programmi\QuickTime
2010-08-05 10:12 . 2010-08-05 10:12 -------- d-----w- c:\programmi\Apple Software Update
2010-08-05 10:06 . 2010-08-05 10:06 -------- d-----w- c:\programmi\Bonjour
2010-08-05 09:15 . 2010-08-05 09:16 -------- d-----w- c:\programmi\Safari
2010-08-05 09:09 . 2010-08-05 09:09 72488 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-07-28 10:32 . 2010-07-28 10:32 -------- d-----w- c:\programmi\File comuni\Skype
2010-07-23 06:49 . 2010-07-23 06:49 1615200 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgssie.dll
2010-07-23 06:49 . 2010-07-23 06:49 1107296 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgxpl.dll
2010-07-23 06:49 . 2010-07-23 06:49 921440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgemc.exe
2010-07-23 06:49 . 2010-07-23 06:49 4368224 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgcorex.dll
2010-07-21 13:30 . 2010-07-21 13:30 73000 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-17 05:24 . 2010-07-17 05:24 242896 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgtdix.sys
2010-07-17 05:24 . 2010-07-17 05:24 216200 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgldx86.sys
2010-07-17 05:23 . 2010-07-17 05:23 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-17 05:19 . 2010-07-17 05:19 1038688 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.exe
2010-07-17 05:19 . 2010-07-17 05:19 813336 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avginet.dll
2010-07-17 05:19 . 2010-07-17 05:19 624920 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgiproxy.exe
2010-07-17 05:19 . 2010-07-17 05:19 1690464 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-13 09:39 . 2009-11-24 21:00 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-08-13 07:59 . 2009-09-26 16:53 -------- d-----w- c:\documents and settings\Gonzo\Dati applicazioni\Skype
2010-08-13 06:06 . 2009-03-11 17:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-08-13 06:02 . 2009-09-28 07:14 -------- d-----w- c:\programmi\Mozilla Thunderbird
2010-08-13 05:52 . 2009-09-28 18:37 -------- d-----w- c:\documents and settings\Gonzo\Dati applicazioni\skypePM
2010-08-10 18:30 . 2009-11-30 18:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-08-10 18:22 . 2010-03-01 17:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-08-05 10:19 . 2010-01-13 15:55 -------- d-----w- c:\programmi\File comuni\Apple
2010-08-05 10:02 . 2010-01-13 16:00 -------- d-----w- c:\documents and settings\Gonzo\Dati applicazioni\Apple Computer
2010-07-26 12:47 . 2010-03-22 11:39 60 ----a-w- c:\windows\wpd99.drv
2010-07-26 12:47 . 2010-03-22 11:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\pdf995
2010-07-17 05:23 . 2009-11-30 18:03 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-17 05:22 . 2009-11-30 18:03 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-25 05:21 . 2009-03-11 09:19 81404 ----a-w- c:\windows\system32\perfc010.dat
2010-06-25 05:21 . 2009-03-11 09:19 483524 ----a-w- c:\windows\system32\perfh010.dat
2010-06-23 05:23 . 2009-12-10 08:22 -------- d-----w- c:\programmi\Google
2010-06-17 11:47 . 2010-06-17 11:47 -------- d-----w- c:\documents and settings\Gonzo\Dati applicazioni\dvdcss
2010-06-14 14:31 . 2009-03-11 16:33 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-09 00:31 . 2009-11-24 21:04 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-06-09 00:31 . 2009-11-24 21:04 264144 ----a-w- c:\windows\PCTBDRes.dll
2010-06-09 00:31 . 2009-11-24 21:04 192 ----a-w- c:\windows\UDB.zip
2010-06-09 00:31 . 2009-11-24 21:04 1435600 ----a-w- c:\windows\PCTBDCore.dll
2010-06-09 00:31 . 2009-11-24 21:04 767952 ----a-w- c:\windows\BDTSupport.dll
2010-06-03 05:34 . 2009-11-30 18:03 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-18 13:35 . 2010-05-18 13:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 13:35 . 2010-05-18 13:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 13:35 . 2010-05-18 13:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-10-16 09:12 1119488 ----a-w- c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ProductReg"="c:\programmi\Acer\WR_PopUp\ProductReg.exe" [2008-11-17 135168]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-24 17529856]
"AzMixerSel"="c:\programmi\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-01-25 53248]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2009-02-05 1430824]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-12-30 875016]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PLFSetL"="c:\windows\PLFSetL.exe" [2008-07-03 94208]
"snp2uvc"="c:\windows\system32\csnp2uvc.dll" [2009-02-16 196608]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-17 2065760]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"TrojanScanner"="c:\programmi\Trojan Remover\Trjscan.exe" [2010-08-10 1167808]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Gonzo\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Acer VCM.lnk - c:\programmi\Acer\Acer VCM\AcerVCM.exe [2009-3-11 565248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-17 05:23 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Acer\\Acer VCM\\VC.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [25/11/2009 00:01 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [30/11/2009 21:03 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [30/11/2009 21:03 243024]
R2 avg9emc;AVG Free E-mail Scanner;c:\programmi\AVG\AVG9\avgemc.exe [17/07/2010 08:22 921952]
R2 avg9wd;AVG Free WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [17/07/2010 08:23 308136]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\programmi\Spyware Doctor\BDT\BDTUpdateService.exe [25/11/2009 00:04 198608]
R2 RS_Service;Raw Socket Service;c:\programmi\Acer\Acer VCM\RS_Service.exe [11/03/2009 21:04 237568]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [04/03/2009 06:03 38912]
S2 gupdate;Service Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [23/06/2010 08:24 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [11/03/2009 20:26 1684736]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [11/03/2009 20:24 162816]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\programmi\Spyware Doctor\pctsAuxs.exe [25/11/2009 00:00 359624]
.
Contenuto della cartella 'Scheduled Tasks'
2010-08-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2009-10-22 08:50]
2010-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-06-23 05:23]
2010-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-06-23 05:23]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://liberation.fr/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0410&s=0&o=xph&d=0909&m=aspire_one
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Translate this web page with Babylon
IE: Translate with Babylon
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-13 13:10
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(1412)
c:\windows\system32\WININET.dll
.
Ora fine scansione: 2010-08-13 13:16:38
ComboFix-quarantined-files.txt 2010-08-13 10:16
Pre-Run: 111 917 780 992 byte disponibili
Post-Run: 111 901 847 552 byte disponibili
- - End Of File - - 1655FFD35C94D35F7E0AB811D72625CA
Afficher la suite
13 août 2010 à 14:50