riporto il log di Combofix
un grazie e un saluto a tutti!
- Codice: Seleziona tutto
ComboFix 11-07-13.04 - utente 14/07/2011 14.50.39.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1023.538 [GMT 2:00]
Eseguito da: c:\documents and settings\utente\Documenti\Download\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {0012F2B4-5C49-7C92-0300-000000000000}
AV: AntiVir Desktop *Enabled/Outdated* {0012F2B4-55E1-7C92-0300-000000000000}
AV: AntiVir Desktop *Enabled/Updated* {0012F2B4-5CE9-7C92-0300-000000000000}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((( Files Creati Da 2011-06-14 al 2011-07-14 )))))))))))))))))))))))))))))))))))
.
.
2011-07-12 22:38 . 2011-07-12 22:38 -------- d-----w- c:\programmi\File comuni\BitDefender
2011-07-12 22:37 . 2011-07-12 22:57 50584 ----a-w- c:\documents and settings\All Users\Dati applicazioni\bdinstall.bin
2011-07-12 22:24 . 2011-07-12 22:24 -------- d-----w- c:\documents and settings\utente\Dati applicazioni\QuickScan
2011-07-11 12:35 . 2011-07-11 12:35 -------- d-----w- c:\programmi\Trend Micro
2011-07-09 19:42 . 2011-07-09 19:42 -------- d-----w- C:\Softland
2011-07-09 11:46 . 2011-07-09 11:46 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Softland
2011-07-09 11:46 . 2011-07-09 11:46 -------- d-----w- c:\documents and settings\utente\Dati applicazioni\Softland
2011-07-09 11:44 . 2011-06-09 09:33 23376 ----a-w- c:\windows\system32\dopdfmn7.dll
2011-07-09 11:44 . 2011-06-09 09:33 20816 ----a-w- c:\windows\system32\dopdfmi7.dll
2011-07-09 11:44 . 2010-02-05 13:00 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2011-07-09 11:43 . 2011-07-09 11:43 -------- d-----w- c:\programmi\Softland
2011-07-08 12:58 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-08 12:58 . 2011-07-13 20:43 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-07-08 12:58 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-01 12:35 . 2011-07-01 12:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\LightScribe
2011-06-30 13:41 . 2011-06-30 13:41 2106216 ----a-w- c:\programmi\Mozilla Firefox\D3DCompiler_43.dll
2011-06-30 13:41 . 2011-06-30 13:41 1998168 ----a-w- c:\programmi\Mozilla Firefox\d3dx9_43.dll
2011-06-26 14:36 . 2011-06-26 14:36 -------- d-----w- c:\programmi\File comuni\LightScribe
2011-06-26 14:30 . 2011-06-26 14:32 -------- d-----w- c:\programmi\File comuni\Ahead
2011-06-26 14:30 . 2011-06-26 14:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2011-06-26 14:30 . 2011-06-26 14:30 -------- d-----w- c:\programmi\Nero
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-30 13:41 . 2011-04-02 08:08 142296 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe" [2007-12-05 2295072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"DSLSTATEXE"="c:\program files\D-Link\DSL-200\dslstat.exe" [2005-12-12 344064]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2011-01-21 281768]
"EEventManager"="c:\programmi\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
.
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [08/03/2011 21.26.53 136176]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [08/03/2011 21.26.53 136176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-12-05 10:27 451872 ----a-w- c:\programmi\File comuni\LightScribe\LSRunOnce.exe
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-03-08 19:26]
.
2011-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-03-08 19:26]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{BEEE07BA-649D-45D9-B593-1ADCA3E792F3}: NameServer = 193.70.152.15 193.70.152.25
FF - ProfilePath - c:\documents and settings\utente\Dati applicazioni\Mozilla\Firefox\Profiles\7cj3ldh9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-14 14:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(956)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
Ora fine scansione: 2011-07-14 15:04:21
ComboFix-quarantined-files.txt 2011-07-14 13:04
.
Pre-Run: 60.642.271.232 byte disponibili
Post-Run: 61.486.465.024 byte disponibili
.
- - End Of File - - FCB2BEAC0A680B496ED3BF94823ED62A