ho seguito le indicazioni dei messaggi precedenti, e questo è il report ottenuto da combofix.
potete darmi una mano? Grazie mille! Mario
- Codice: Seleziona tutto
ComboFix 10-09-06.03 - ASUS_14.1 06/09/2010 23.59.08.2.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1007.454 [GMT 2:00]
Eseguito da: c:\documents and settings\ASUS_14.1\Desktop\ab.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-08-06 al 2010-09-06 )))))))))))))))))))))))))))))))))))
.
2010-09-06 21:53 . 2010-09-06 21:53 -------- d-----w- C:\FOUND.060
2010-09-06 21:03 . 2010-09-06 21:03 -------- d-----w- c:\documents and settings\ASUS_14.1\Dati applicazioni\r2 Studios
2010-09-06 21:03 . 2010-09-06 21:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\r2 Studios
2010-09-06 21:03 . 2010-09-06 21:03 -------- d-----w- c:\programmi\r2 Studios
2010-09-06 20:55 . 2010-09-06 20:55 -------- d-----w- c:\programmi\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-06 21:53 . 2009-10-15 15:09 45056 ----a-w- c:\windows\system32\acovcnt.exe
2010-02-15 21:32 . 2010-02-15 21:32 155085 --sh--r- c:\windows\system32\pcjnp.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\ASUS_14.1\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-02-15 133104]
"CTSyncU.exe"="c:\programmi\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-08-23 110592]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-08-14 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-08-14 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-08-14 94208]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2009-08-28 1557800]
"Wireless Console 2"="c:\programmi\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"IntelZeroConfig"="c:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 802816]
"IntelWireless"="c:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 696320]
"ATKMEDIA"="c:\programmi\ASUS\ATK Media\DMEDIA.EXE" [2006-05-16 53248]
"Power_Gear"="c:\programmi\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-14 90112]
"ACMON"="c:\programmi\ASUS\Splendid\ACMON.exe" [2006-05-30 811008]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"RemoteControl"="c:\programmi\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"SMSERIAL"="c:\programmi\Motorola\SMSERIAL\sm56hlpr.exe" [2006-08-06 573440]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-11-03 28160]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-02-03 136600]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"StartupDelayer"="c:\programmi\r2 Studios\Startup Delayer\Startup Launcher.exe" [2009-03-08 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
MultiFrame.lnk - c:\programmi\ASUS\Asus MultiFrame\MultiFrame.exe [2007-4-10 491520]
Logitech SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2007-4-10 532480]
Status Monitor.lnk - c:\programmi\Brother\Brmfcmon\BrMfcWnd.exe [2009-7-14 1089536]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SvcOnlineArmor"=2 (0x2)
"SeaPort"=2 (0x2)
"OAcat"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\DNA\\btdna.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4082:TCP"= 4082:TCP:ghcydewk
S2 auimrlj;Monitor Universal;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 bibcxgn;Driver Image;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 djhldbw;Windows Update;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 kmboehg;System Center;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 odijy;Time Boot;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 otnajz;Image System;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 pazqshox;Shell Image;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 tgvgvs;System Helper;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 tulgg;qqbbd;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S2 uqtoyy;Support Network;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 16.03.53 14336]
S3 ipswuio;ipswuio;c:\windows\system32\drivers\ipswuio.sys [10/04/2007 18.55.51 34944]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - GETPADD
*Deregistered* - GETPADD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
tulgg
tgvgvs
pazqshox
djhldbw
kmboehg
bibcxgn
odijy
uqtoyy
otnajz
auimrlj
.
Contenuto della cartella 'Scheduled Tasks'
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-916021484-280282206-15943825-1004Core1cae1d3f793bd50.job
- c:\documents and settings\ASUS_14.1\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-01-14 14:06]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
IE: &Download by Orbit
IE: &Grab video by Orbit
IE: Do&wnload selected by Orbit
IE: Down&load all by Orbit
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {76E21A26-F6B3-45B6-8235-6A849BD1C126} = 212.216.112.112,212.216.172.62
TCP: {784B131B-4F9C-4DFE-A579-42D8B2C14B80} = 212.216.112.112,212.216.172.62
FF - ProfilePath - c:\documents and settings\ASUS_14.1\Dati applicazioni\Mozilla\Firefox\Profiles\w2ruk42h.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=13166&l=dis
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-07 00:01
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\auimrlj]
"ServiceDll"="c:\windows\system32\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bibcxgn]
"ServiceDll"="c:\programmi\Movie Maker\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\djhldbw]
"ServiceDll"="c:\programmi\Movie Maker\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kmboehg]
"ServiceDll"="c:\windows\system32\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\odijy]
"ServiceDll"="c:\programmi\Internet Explorer\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\otnajz]
"ServiceDll"="c:\programmi\Internet Explorer\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pazqshox]
"ServiceDll"="c:\windows\system32\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tgvgvs]
"ServiceDll"="c:\programmi\Movie Maker\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tulgg]
"ServiceDll"="c:\windows\system32\pcjnp.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uqtoyy]
"ServiceDll"="c:\windows\system32\pcjnp.dll"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(3348)
c:\programmi\ASUS\Asus MultiFrame\HookTitle.dll
c:\program files\SetPoint\lgscroll.dll
c:\windows\system32\MSVCP71.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-09-07 00:02:59
ComboFix-quarantined-files.txt 2010-09-06 22:02
ComboFix2.txt 2010-09-06 21:39
Pre-Run: 35.806.183.424 byte disponibili
Post-Run: 35.795.238.912 byte disponibili
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - B84C6E3A55E0066C3D5678F550ED6DEC