fatto. Ecco il report:
((((((((((((((((((((((((( Files Creati Da 2009-09-10 al 2009-10-10 )))))))))))))))))))))))))))))))))))
.
2009-10-09 18:39 . 2009-10-09 18:39 -------- d-----w- c:\documents and settings\Frasnelli Alessandra\Dati applicazioni\Malwarebytes
2009-10-09 18:39 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-09 18:39 . 2009-10-09 18:39 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-10-09 18:39 . 2009-10-09 18:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-10-09 18:39 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-09 18:34 . 2009-10-09 18:34 -------- d-----w- c:\programmi\CCleaner
2009-10-07 19:18 . 2009-10-07 19:18 -------- d-----w- c:\programmi\Avery
2009-10-07 19:15 . 2009-10-07 19:16 9886192 ----a-w- C:\averywizard_3_1_it.exe
2009-10-05 16:28 . 2009-10-05 16:28 -------- d-----w- c:\programmi\Paper Label Maker
2009-10-05 16:27 . 2009-10-05 16:28 4288178 ----a-w- C:\paperlabelmaker.zip
2009-09-15 18:38 . 2009-09-15 18:38 -------- d-----w- c:\windows\system32\it
2009-09-15 18:38 . 2009-09-15 18:38 -------- d-----w- c:\windows\l2schemas
2009-09-14 16:12 . 2009-09-14 16:12 -------- d-----w- c:\documents and settings\Frasnelli Alessandra\Dati applicazioni\Canon
2009-09-14 15:02 . 2009-09-14 15:02 -------- d-----w- c:\documents and settings\Frasnelli Alessandra\Dati applicazioni\VoipStunt
2009-09-14 14:57 . 2009-09-14 14:57 -------- d-----w- c:\documents and settings\Frasnelli Alessandra\Impostazioni locali\Dati applicazioni\Opera
2009-09-14 14:56 . 2009-09-14 14:56 -------- d-----w- c:\programmi\Opera
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-15 18:53 . 1979-12-31 22:00 381428 ----a-w- c:\windows\system32\perfh010.dat
2009-09-15 18:53 . 1979-12-31 22:00 64812 ----a-w- c:\windows\system32\perfc010.dat
2009-09-11 18:01 . 2003-10-09 20:09 85376 ----a-w- c:\documents and settings\Frasnelli Alessandra\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-09 13:19 . 2009-09-09 13:19 -------- d-----w- c:\programmi\Valpas
2009-09-07 16:08 . 2009-09-07 14:54 10752 ----a-w- c:\windows\DCEBoot.exe
2009-09-07 14:20 . 2009-09-07 14:10 20058 ----a-w- c:\documents and settings\Frasnelli Alessandra\Impostazioni locali\Dati applicazioni\JunkAtx.bin
2009-09-02 17:35 . 2009-09-02 17:35 -------- d-----w- c:\documents and settings\Frasnelli Alessandra\Dati applicazioni\OpenOffice.org
2009-09-02 17:32 . 2009-09-02 17:32 -------- d-----w- c:\programmi\JRE
2009-09-02 17:32 . 2009-09-02 17:32 -------- d-----w- c:\programmi\OpenOffice.org 3
2009-08-05 08:59 . 2004-03-24 11:55 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:34 . 1979-12-31 22:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:34 . 1979-12-31 22:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-25 03:23 . 2009-03-26 16:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 1979-12-31 22:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-10-01 09:50 286208 ------w- c:\windows\system32\wmpdxm.dll
2008-04-14 02:13 . 1979-12-31 22:00 1384479 --sh--r- c:\windows\system32\msvbvm60.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"delmsbb"="c:\windows\delmsbb.exe" [2003-01-06 327680]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-26 68856]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2005-06-11 98304]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2008-10-17 185872]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"DSLAGENTEXE"="dslagent.exe" - c:\windows\system32\dslagent.exe [2001-08-21 16384]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-05-14 55296]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Frasnelli Alessandra\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.1.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0PFDNNT c:\programmi\MyWay\myBar\1.bin\0PFDNNT c:\programmi\MyWay\myBar\1.bin\0PFDNNT c:\programmi\MyWay\myBar\0PFDNNT c:\programmi\MYWAY\MYBAR\1.BIN\MYBAR.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Frasnelli Alessandra^Menu Avvio^Programmi^Esecuzione automatica^UltimateZip Quick Start.lnk]
backup=c:\windows\pss\UltimateZip Quick Start.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\PROGRA~1\\A-TIME~1\\TIMESYNC.EXE"=
"c:\\WINDOWS\\System32\\FXSCLNT.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19126:TCP"= 19126:TCP:GoogleReference schemasPages
"61906:UDP"= 61906:UDP:GoogleReference MediaDownloaded
"56121:TCP"= 56121:TCP:GoogleReference MailVideo
"10517:UDP"= 10517:UDP:GoogleReference en64
R3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\RTL8180.sys [28/08/2003 12.07.32 173184]
S2 gafwload;IPM Datacom USB ADSL Loader;c:\windows\system32\drivers\gafwload.sys [25/09/2004 8.01.24 26985]
S3 CMIUSB;Motic New MC Camera;c:\windows\system32\drivers\MC1001200130012001B\cmiusb.sys [14/01/2008 8.48.35 10373]
S3 DisplayLinkGA;DisplayLinkGA;c:\windows\system32\DRIVERS\DisplayLinkGAport.sys --> c:\windows\system32\DRIVERS\DisplayLinkGAport.sys [?]
S3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\DRIVERS\DisplayLinkmirrorport.sys --> c:\windows\system32\DRIVERS\DisplayLinkmirrorport.sys [?]
S3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\DRIVERS\DisplayLinkUsbPort.sys --> c:\windows\system32\DRIVERS\DisplayLinkUsbPort.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
wuauSystem
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/ieuInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: {BFFC50D2-75B1-4CCF-B175-A17C3E5FA7FF} = 151.99.0.100,151.99.125.1
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {04365000-DFC6-11D3-B2BB-00105AE309D0} -
hxxps://ib.rolbank.com/ib2000/TlqJ2kQrc.cabDPF: {13083D70-37BD-11D4-B315-00508B6D3B87} -
hxxps://ib.rolbank.com/ib2000/TlqJ2kQF.cabDPF: {2A5C1DD0-DFC5-11D3-B2BB-00105AE309D0} -
hxxps://ib.rolbank.com/ib2000/TlqJ2kOth.cabDPF: {5140EE10-DFC4-11D3-B2BB-00105AE309D0} -
hxxps://ib.rolbank.com/ib2000/de/TlqJ2kImg.cabDPF: {B1738950-DFC5-11D3-B2BB-00105AE309D0} -
hxxps://ib.rolbank.com/ib2000/TlqJ2kQCb.cabDPF: {CB572CC0-E5F9-11D3-B2C1-00105AE309D0} -
hxxps://ib.rolbank.com/ib2000/TlqJ2kQDt.cabDPF: {D7417188-1FBD-40B1-A6C0-0DDC8B98E666} -
hxxps://ib.rolbank.com/ib2000/TlqJ2kR.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-10 14:43
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2600)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2009-10-10 14.44.37
ComboFix-quarantined-files.txt 2009-10-10 12:44
ComboFix2.txt 2009-10-09 04:33
ComboFix3.txt 2009-09-07 18:32
ComboFix4.txt 2009-06-22 13:12
Pre-Run: 7.105.069.056 byte disponibili
Post-Run: 7.079.002.112 byte disponibili
WindowsXP-KB310994-SP2-Home-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
144 --- E O F --- 2009-09-15 18:47