Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 14-01-04.03 - Maurizio 04/01/2014 17.26.57.1.1 - x86
- Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1023.591 [GMT 1:00]
- Eseguito da: c:\documents and settings\Maurizio\Documenti\Downloads\ComboFix.exe
- * Creato nuovo punto di ripristino
- .
- .
- ((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\documents and settings\Maurizio\Dati applicazioni\facemoods.com
- c:\documents and settings\Maurizio\Dati applicazioni\facemoods.com\facemoods\rprt\4AC16.upld
- c:\documents and settings\Maurizio\Dati applicazioni\OfferBox
- c:\documents and settings\Maurizio\Dati applicazioni\OfferBox\config.xml
- c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\cqsaa.dat
- c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\cqsaa.exe
- c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\cqsaa_nav.dat
- c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\cqsaa_navps.dat
- c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\xiscte.dat
- c:\documents and settings\maurizio\impostazioni locali\dati applicazioni\xiscte.exe
- c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\xiscte_nav.dat
- c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\xiscte_navps.dat
- c:\documents and settings\Maurizio\WINDOWS
- c:\programmi\FunWebProducts
- c:\programmi\FunWebProducts\Shared\000CDD2C.dat
- c:\programmi\Mozilla Firefox\extensions\[email protected]
- c:\programmi\Mozilla Firefox\extensions\[email protected]\chrome.manifest
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\blgc.js
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\facemoods.png
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\facemoods.xul
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\Loader.js
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\pref.jpg
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\preferences.js
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\preferences.xul
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\prefman.js
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\script-compiler.js
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\Thumbs.db
- c:\programmi\Mozilla Firefox\extensions\[email protected]\content\xmlhttprequester.js
- c:\programmi\Mozilla Firefox\extensions\[email protected]\defaults\preferences\facemoods.js
- c:\programmi\Mozilla Firefox\extensions\[email protected]\install.rdf
- c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
- c:\windows\IsUn0410.exe
- c:\windows\system32\dbghelp.dll.tmp
- c:\windows\system32\SETB1.tmp
- c:\windows\system32\SETBD.tmp
- c:\windows\UA000022.DLL
- c:\windows\unin0410.exe
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- -------\Legacy_NPF
- .
- .
- ((((((((((((((((((((((((( Files Creati Da 2013-12-04 al 2014-01-04 )))))))))))))))))))))))))))))))))))
- .
- .
- 2014-01-04 16:00 . 2014-01-04 16:00 -------- dc----w- c:\documents and settings\Administrator
- 2014-01-01 17:49 . 2014-01-01 17:49 -------- dc----w- c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\SearchProtect
- 2014-01-01 17:48 . 2014-01-01 17:48 -------- dc----w- c:\documents and settings\All Users\Dati applicazioni\Auslogics
- 2014-01-01 17:47 . 2014-01-01 17:47 -------- d-----w- c:\programmi\Auslogics
- 2014-01-01 17:33 . 2014-01-01 17:33 21361 ----a-w- c:\windows\system32\drivers\AegisP.sys
- 2014-01-01 17:33 . 2014-01-01 17:33 -------- d-----w- c:\programmi\TP-LINK
- 2014-01-01 17:33 . 2014-01-01 17:33 -------- dc----w- c:\documents and settings\All Users\Dati applicazioni\TP-LINK Driver
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- .
- ((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Nota* i valori vuoti & legittimi/default non sono visualizzati.
- REGEDIT4
- .
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
- .
- c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
- TL-WN321G Wireless Utility.lnk - c:\programmi\TP-LINK\TL-WN321G\COMMON\TWCU.exe -s [2014-1-1 1298432]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
- 2004-03-03 11:00 335872 ----a-w- c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
- .
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\Programmi\\eMule\\emule.exe"=
- "c:\\Programmi\\Pinnacle\\Studio 11\\programs\\RM.exe"=
- "c:\\Programmi\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
- "c:\\Programmi\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
- "c:\\Programmi\\Pinnacle\\Studio 11\\programs\\umi.exe"=
- "c:\\Programmi\\Messenger\\msmsgs.exe"=
- "c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
- "c:\\Programmi\\BitTorrent\\bittorrent.exe"=
- "c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
- "c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
- "c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
- "c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
- "c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
- "c:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
- "c:\\Programmi\\IHMC CmapTools\\jre\\bin\\javaw.exe"=
- "c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
- "c:\\Programmi\\Skype\\Phone\\Skype.exe"=
- .
- S2 cgpystb;Boot Microsoft;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
- S2 derzfkdcg;Support Shell;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
- S2 kvsif;Update Helper;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
- S2 nqtmhds;Microsoft Manager;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
- S2 rcilqea;Monitor Security;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
- S2 wmklzow;Monitor Update;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
- S2 xhcrynga;uxaebynf;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
- S2 zcajq;Image Center;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
- S3 iComp;Python2 USB WDM Encoder;c:\windows\system32\drivers\p2usbwdm.sys [31/07/2005 19.21.22 1183616]
- S3 KMWDFILTERx86;MLK KM DRIVER;c:\windows\system32\drivers\KMWDFILTER.sys [22/05/2010 9.41.57 18432]
- S3 mdxgthkn;mdxgthkn;\??\c:\docume~1\Maurizio\IMPOST~1\Temp\mdxgthkn.sys --> c:\docume~1\Maurizio\IMPOST~1\Temp\mdxgthkn.sys [?]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
- HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
- hpdevmgmt REG_MULTI_SZ hpqcxs08
- .
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
- fangysb
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
- 2014-01-01 17:50 1210320 ----a-w- c:\programmi\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
- .
- Contenuto della cartella 'Scheduled Tasks'
- .
- 2013-04-14 c:\windows\Tasks\Driver Robot.job
- - c:\programmi\Driver Robot\1.1.0.14\DriverRobot.exe [2009-11-30 12:53]
- .
- 2014-01-04 c:\windows\Tasks\Google Software Updater.job
- - c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-21 13:52]
- .
- 2014-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\programmi\Google\Update\GoogleUpdate.exe [2010-04-05 13:55]
- .
- 2014-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\programmi\Google\Update\GoogleUpdate.exe [2010-04-05 13:55]
- .
- 2013-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1078145449-839522115-1004Core.job
- - c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-05-14 17:07]
- .
- 2014-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1078145449-839522115-1004UA.job
- - c:\documents and settings\Maurizio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-05-14 17:07]
- .
- .
- ------- Scansione supplementare -------
- .
- uStart Page = hxxp://it.msn.com
- uDefault_Search_URL = hxxp://www.google.com/ie
- uInternet Settings,ProxyOverride = ;127.0.0.1;<local>
- uSearchAssistant = hxxp://www.google.com/ie
- uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
- IE: E&sporta in Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
- IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
- IE: MediaManager tool grab multimedia file - c:\programmi\MP3 Player Utilities 3.74\MediaManager\grab.html
- TCP: DhcpNameServer = 192.168.1.1
- DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
- .
- - - - - CHIAVI ORFANE RIMOSSE - - - -
- .
- WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
- MSConfigStartUp-xiscte - c:\documents and settings\maurizio\impostazioni locali\dati applicazioni\xiscte.exe
- AddRemove-xiscte - c:\documents and settings\maurizio\impostazioni locali\dati applicazioni\xiscte.exe
- AddRemove-Techno Design IP Notify - c:\programmi\Techno Design IP\LiveSearch Notification.exe
- .
- .
- .
- **************************************************************************
- .
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2014-01-04 17:36
- Windows 5.1.2600 Service Pack 3 NTFS
- .
- scansione processi nascosti ...
- .
- scansione entrate autostart nascoste ...
- .
- Scansione files nascosti ...
- .
- Scansione completata con successo
- Files nascosti: 0
- .
- **************************************************************************
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cgpystb]
- "ServiceDll"="c:\documents and settings\Maurizio\Dati applicazioni\qtyzf.dll"
- --
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\derzfkdcg]
- "ServiceDll"="c:\programmi\Internet Explorer\qtyzf.dll"
- --
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kvsif]
- "ServiceDll"="c:\windows\system32\qtyzf.dll"
- --
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nqtmhds]
- "ServiceDll"="c:\programmi\Movie Maker\qtyzf.dll"
- --
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rcilqea]
- "ServiceDll"="c:\programmi\Internet Explorer\qtyzf.dll"
- --
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wmklzow]
- "ServiceDll"="c:\windows\system32\qtyzf.dll"
- --
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xhcrynga]
- "ServiceDll"="c:\windows\system32\qtyzf.dll"
- --
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zcajq]
- "ServiceDll"="c:\programmi\Movie Maker\qtyzf.dll"
- .
- --------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
- .
- [HKEY_USERS\S-1-5-21-842925246-1078145449-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3554563A-AF50-385D-FF36-F6A3A22263B8}*]
- @Allowed: (Read) (RestrictedCode)
- @Allowed: (Read) (RestrictedCode)
- "oaodlcnokahgepfdbjbkfboggmahkg"=hex:61,69,6d,62,6d,65,70,70,69,6d,68,6a,6a,64,
- 63,6f,6c,67,6b,6f,6f,67,62,6b,6e,6f,67,6e,67,69,66,69,6d,61,63,64,6d,64,68,\
- "iahenplfcbpbphjngc"=hex:6b,61,64,61,6f,6a,61,65,62,65,70,6c,70,68,65,62,62,67,
- 66,6b,6c,6e,00,00
- "hafehbkmdndmmhac"=hex:6b,61,64,61,6f,6a,61,65,62,65,70,6c,70,68,65,62,62,67,
- 66,6b,6c,6e,00,00
- .
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
- "0140311900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
- .
- --------------------- Dlls caricate dai processi in esecuzione ---------------------
- .
- - - - - - - - > 'winlogon.exe'(540)
- c:\windows\system32\Ati2evxx.dll
- .
- - - - - - - - > 'explorer.exe'(3164)
- c:\windows\system32\WININET.dll
- c:\windows\system32\WPDShServiceObj.dll
- c:\windows\system32\PortableDeviceTypes.dll
- c:\windows\system32\PortableDeviceApi.dll
- .
- ------------------------ Altri processi in esecuzione ------------------------
- .
- c:\windows\system32\Ati2evxx.exe
- c:\windows\system32\Ati2evxx.exe
- c:\programmi\TP-LINK\TL-WN321G\COMMON\RegistryWriter.exe
- c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
- c:\windows\system32\wscntfy.exe
- .
- **************************************************************************
- .
- Ora fine scansione: 2014-01-04 17:42:12 - Il pc è stato riavviato
- ComboFix-quarantined-files.txt 2014-01-04 16:42
- .
- Pre-Run: 44.379.492.352 byte disponibili
- Post-Run: 44.597.637.120 byte disponibili
- .
- WindowsXP-KB310994-SP2-Home-BootDisk-ITA.exe
- [boot loader]
- timeout=2
- default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
- [operating systems]
- c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
- UnsupportedDebug="do not select this" /debug
- multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- .
- - - End Of File - - 2E4C21A75833CD7CD73D7F4A626D0872
- 828E02D5C4A4FBE53441EE9DBEE51F43
Advertisement
Add Comment
Please, Sign In to add comment