Ecco:
ComboFix 11-12-12.02 - Mio 12/12/2011 22.34.00.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1738 [GMT 1:00]
Eseguito da: c:\documents and settings\Mio\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Mio\Dati applicazioni\PriceGong
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\1.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\a.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\b.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\c.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\d.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\e.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\f.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\g.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\h.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\i.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\J.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\k.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\l.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\m.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\mru.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\n.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\o.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\p.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\q.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\r.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\s.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\t.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\u.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\v.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\w.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\x.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\y.xml
c:\documents and settings\Mio\Dati applicazioni\PriceGong\Data\z.xml
c:\documents and settings\Mio\WINDOWS
c:\windows\$NtUninstallKB35630$
c:\windows\$NtUninstallKB35630$\2527337866\@
c:\windows\$NtUninstallKB35630$\2527337866\bckfg.tmp
c:\windows\$NtUninstallKB35630$\2527337866\cfg.ini
c:\windows\$NtUninstallKB35630$\2527337866\Desktop.ini
c:\windows\$NtUninstallKB35630$\2527337866\kwrd.dll
c:\windows\$NtUninstallKB35630$\2527337866\L\scdxfiex
c:\windows\$NtUninstallKB35630$\2527337866\U\00000001.@
c:\windows\$NtUninstallKB35630$\2527337866\U\00000002.@
c:\windows\$NtUninstallKB35630$\2527337866\U\00000004.@
c:\windows\$NtUninstallKB35630$\2527337866\U\80000000.@
c:\windows\$NtUninstallKB35630$\2527337866\U\80000004.@
c:\windows\$NtUninstallKB35630$\2527337866\U\80000032.@
c:\windows\$NtUninstallKB35630$\3504255461
C:\WinLogon
c:\winlogon\7817BAD801BC398
.
.
((((((((((((((((((((((((( Files Creati Da 2011-11-12 al 2011-12-12 )))))))))))))))))))))))))))))))))))
.
.
2011-12-08 14:03 . 2011-12-08 14:03 -------- d-----w- C:\found.000
2011-12-05 21:53 . 2011-12-05 21:53 388096 ----a-r- c:\documents and settings\Mio\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-05 21:53 . 2011-12-05 21:53 -------- d-----w- c:\programmi\Trend Micro
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-08 12:57 . 2011-12-08 12:57 162816 ----a-w- c:\windows\system32\drivers\netbt.sys.org
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 14:50 1197448 ----a-w- c:\programmi\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\programmi\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\programmi\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2011-01-26 15026056]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-03-12 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="c:\programmi\Thomson\SpeedTouch USB\Dragdiag.exe" [2003-09-05 878080]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-03-17 421888]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
LUMIX Simple Viewer.lnk - c:\programmi\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2010-5-1 57344]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
.
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [12/03/2011 17.30.57 136176]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [12/03/2011 17.30.57 136176]
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-11-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2011-12-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-03-12 16:30]
.
2011-12-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-03-12 16:30]
.
2011-12-12 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\programmi\Ask.com\UpdateTask.exe [2010-02-04 14:50]
.
2011-12-12 c:\windows\Tasks\User_Feed_Synchronization-{473C26CF-B79E-45BC-9062-6242FF8C858B}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 85.37.17.56 85.38.28.98
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKLM-Run-Cmaudio - cmicnfg.cpl
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-12-12 22:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(2168)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\RunDll32.exe
c:\programmi\HP\Digital Imaging\bin\hpqSTE08.exe
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\windows\system32\dwwin.exe
.
**************************************************************************
.
Ora fine scansione: 2011-12-12 22:48:32 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-12-12 21:48
.
Pre-Run: 23.527.518.208 byte disponibili
Post-Run: 23.831.977.984 byte disponibili
.
- - End Of File - - 8E540C0484ABB63A9946AA70B8106294