Francesco, ecco il report prodotto da Combofix (che non so allegare...pardon)
ComboFix 12-04-04.01 - Matteo 04/04/2012 14.45.17.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2550.1899 [GMT 2:00]
Eseguito da: c:\documents and settings\Matteo\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\Matteo\Impostazioni locali\Dati applicazioni\ecpboypw.dat
c:\documents and settings\Matteo\Impostazioni locali\Dati applicazioni\ecpboypw_nav.dat
c:\documents and settings\Matteo\Impostazioni locali\Dati applicazioni\ecpboypw_navps.dat
c:\documents and settings\Matteo\Impostazioni locali\Dati applicazioni\vwmpby.exe
c:\documents and settings\Matteo\System
c:\documents and settings\Matteo\System\win_qs8.jqx
c:\windows\3F32A78A.exe
c:\windows\system32\14400b58.dat
c:\windows\system32\4b566489.dll
c:\windows\system32\b805ba68.dll
c:\windows\system32\ctfmon .exe
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\e74d7bb7.dll
c:\windows\system32\SET44.tmp
c:\windows\system32\SET46.tmp
c:\windows\system32\SET4B.tmp
c:\windows\system32\SET52.tmp
c:\windows\system32\SET9A.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ASC3550P
.
.
((((((((((((((((((((((((( Files Creati Da 2012-03-04 al 2012-04-04 )))))))))))))))))))))))))))))))))))
.
.
2012-03-15 23:42 . 2012-03-22 19:05 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\Neem
2012-03-15 23:42 . 2012-03-15 23:58 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\Ebluhau
2012-03-15 21:44 . 2012-03-15 21:44 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
- Codice: Seleziona tutto
<pre>
c:\programmi\CyberLink\PowerDVD\pdvdserv .exe
c:\programmi\CyberLink\PowerDVD\Language\language .exe
c:\programmi\File comuni\Ahead\Lib\nerocheck .exe
c:\programmi\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\programmi\Windows Media Player\wmpnscfg .exe
c:\windows\system32\hkcmd .exe
c:\windows\system32\igfxpers .exe
c:\windows\system32\igfxtray .exe
</pre>
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-15 39408]
"ISUSPM"="c:\programmi\File comuni\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"WMPNSCFG"="c:\programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 204288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\programmi\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Google Quick Search Box"="c:\programmi\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-15 122368]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2010-11-04 281768]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"IMBooster"="c:\programmi\Iminent\IMBooster\imbooster.exe" [2011-03-30 1324008]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Matteo^Menu Avvio^Programmi^Esecuzione automatica^Ritaglio schermata e avvio di OneNote 2007.lnk]
path=c:\documents and settings\Matteo\Menu Avvio\Programmi\Esecuzione automatica\Ritaglio schermata e avvio di OneNote 2007.lnk
backup=c:\windows\pss\Ritaglio schermata e avvio di OneNote 2007.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-14 23:04 39792 ----a-w- c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 02:14 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E07IXLRD_10036640]
c:\programmi\Microsoft Encarta\Microsoft Encarta 2007 - Premium DVD\EDICT.EXE [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E07IXLRD_8148468]
c:\programmi\Microsoft Encarta\Microsoft Encarta 2007 - Premium DVD\EDICT.EXE [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
2009-08-15 15:29 122368 ----a-w- c:\programmi\Google\Quick Search Box\GoogleQuickSearchBox.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
c:\programmi\HP\hpcoretech\hpcmpmgr.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-06-25 10:24 49152 ----a-w- c:\programmi\Hewlett-Packard\HP Software Update\hpwuSchd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 08:14 206112 ----a-w- c:\programmi\File comuni\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2008-10-24 08:14 206112 ----a-w- c:\progra~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 13:33 421160 ----a-w- c:\programmi\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
c:\programmi\CyberLink\PowerDVD\Language\Language.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]
2006-11-03 10:01 319488 ----a-w- c:\windows\PixArt\PAC207\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 15:38 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
c:\programmi\CyberLink\PowerDVD\PDVDServ.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 16:04 2879488 ----a-w- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-08-15 15:29 39408 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ygggoei]
c:\documents and settings\matteo\impostazioni locali\dati applicazioni\ygggoei.exe [N/A]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Iminent\\IMBooster\\IMBooster.exe"=
"c:\\Programmi\\Iminent\\MMServer\\Iminent.MMServer.exe"=
"%windir%\explorer.exe"= %windir%\explorer.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:e mule TPC
"4672:UDP"= 4672:UDP:e mule UDP
"7818:TCP"= 7818:TCP:messenger
"7181:TCP"= 7181:TCP:messenger
"5558:TCP"= 5558:TCP:messenger
"1158:TCP"= 1158:TCP:messenger
"3863:TCP"= 3863:TCP:messenger
"6725:TCP"= 6725:TCP:messenger
"7724:TCP"= 7724:TCP:messenger
"6115:TCP"= 6115:TCP:messenger
"4116:TCP"= 4116:TCP:messenger
"7624:TCP"= 7624:TCP:messenger
"8777:TCP"= 8777:TCP:messenger
"3438:TCP"= 3438:TCP:messenger
"8161:TCP"= 8161:TCP:messenger
"6177:TCP"= 6177:TCP:messenger
"3323:TCP"= 3323:TCP:messenger
"3436:TCP"= 3436:TCP:messenger
"5176:TCP"= 5176:TCP:messenger
"8812:TCP"= 8812:TCP:messenger
"5627:TCP"= 5627:TCP:messenger
"6278:TCP"= 6278:TCP:messenger
"3261:TCP"= 3261:TCP:messenger
"6616:TCP"= 6616:TCP:messenger
"3237:TCP"= 3237:TCP:messenger
"7633:TCP"= 7633:TCP:messenger
"1675:TCP"= 1675:TCP:messenger
"6852:TCP"= 6852:TCP:messenger
"1235:TCP"= 1235:TCP:messenger
"4881:TCP"= 4881:TCP:messenger
"7333:TCP"= 7333:TCP:messenger
"7356:TCP"= 7356:TCP:messenger
"8722:TCP"= 8722:TCP:messenger
"7635:TCP"= 7635:TCP:messenger
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [29/07/2009 12.35.21 721904]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmi\Avira\AntiVir Desktop\sched.exe [30/06/2010 17.27.56 136360]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [25/05/2009 20.36.46 33792]
S2 esunid32;EPSON WIA USD;rundll32.exe c:\windows\system32\esunid32.dll,akek --> rundll32.exe c:\windows\system32\esunid32.dll,akek [?]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [06/02/2010 16.14.39 135664]
S2 pkuuxjci;pkuuxjci; [x]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;c:\windows\system32\drivers\bsusbser.sys [28/06/2008 11.55.33 94848]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [06/02/2010 16.14.39 135664]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [30/08/2011 13.42.45 22216]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 NDISKIO;NDISKIO;\??\c:\docume~1\Matteo\IMPOST~1\Temp\00000bcd.nmc\nse\bin\ndiskio.sys --> c:\docume~1\Matteo\IMPOST~1\Temp\00000bcd.nmc\nse\bin\ndiskio.sys [?]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14/05/2007 11.26.10 508288]
S4 MBAMService;MBAMService;c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe [30/08/2011 13.42.49 366152]
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-06 14:14]
.
2012-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-06 14:14]
.
2012-04-04 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
2012-04-04 c:\windows\Tasks\User_Feed_Synchronization-{271805D7-8EBA-415D-8CC2-30C764D35978}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Scarica con Mipony -
file://c:\programmi\MiPony\Browser\IEContext.htm
TCP: DhcpNameServer = 62.101.93.101 83.103.25.250
TCP: Interfaces\{D908FF38-01B1-4E4A-A60C-4B877EFDBAA0}: NameServer = 192.168.2.1
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} -
hxxp://game08.zylom.com/activex/zylomgamesplayer.cabFF - ProfilePath - c:\documents and settings\Matteo\Dati applicazioni\Mozilla\Firefox\Profiles\jjhmyd41.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.theprizeday.com/today.php|ht ... t:official\n
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Iminent WebBooster:
webbooster@iminent.com - c:\programmi\Mozilla Firefox\extensions\webbooster@iminent.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Babylon:
ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Notify-esunid32 - esunid32.dll
SafeBoot-ddnxfisc
SafeBoot-pkuuxjci
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-04-04 14:55
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet006\Services\vsdatant]
"ImagePath"=""
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(304)
c:\windows\system32\WININET.dll
c:\programmi\Iminent\IMBooster\Iminent.WinCore.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Avira\AntiVir Desktop\avshadow.exe
c:\programmi\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exe
c:\programmi\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
c:\programmi\CyberLink\Shared Files\RichVideo.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programmi\Windows Media Player\WMPNetwk.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\File comuni\Ahead\Lib\NMIndexingService.exe
.
**************************************************************************
.
Ora fine scansione: 2012-04-04 14:57:19 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-04-04 12:57
.
Pre-Run: 15.758.200.832 byte disponibili
Post-Run: 15.806.533.632 byte disponibili
.
- - End Of File - - 3A456ABD6C73303CBF248C43AA4489D4