Grazie Luke57,
l'ho fatto in modalità provvisoria, ovviamente, immagino che non faccia differenza.
ComboFix 12-04-31.03 - Chicco 01/05/2012 17.42.23.5.4 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3573.3281 [GMT 2:00]
Eseguito da: c:\documents and settings\Chicco\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Chicco\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Outdated* {0013F2B4-5C49-7C92-0300-000000000000}
AV: AntiVir Desktop *Disabled/Outdated* {7698207D-3DB8-003E-AC1D-9876381E9876}
AV: AntiVir Desktop *Enabled/Outdated* {0012F2B4-5C49-7C92-0300-000000000000}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
FILE ::
"c:\docume~1\ALLUSE~1\LOCALS~1\Temp\mssoucweh.exe"
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\ALLUSE~1\LOCALS~1\Temp\mssoucweh.exe
c:\documents and settings\Chicco\Dati applicazioni\drppedjjtvgfl
c:\documents and settings\Chicco\Dati applicazioni\drppedjjtvgfl\hzgzstr.bmp
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((((( Files Creati Da 2012-04-01 al 2012-05-01 )))))))))))))))))))))))))))))))))))
.
.
2012-04-27 18:47 . 2012-04-27 18:47 -------- d-----w- c:\programmi\File comuni\Java
2012-04-27 18:04 . 2012-04-27 18:04 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-04-27 18:04 . 2012-04-27 18:04 476960 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-04-27 18:03 . 2012-04-27 18:03 -------- d-----w- c:\programmi\Java
2012-04-26 09:37 . 2012-04-26 09:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Samsung
2012-04-16 12:09 . 2012-04-16 12:30 -------- d-----w- C:\Ex disco C
2012-04-08 19:27 . 2012-04-08 19:27 -------- d-----w- c:\programmi\A-FF Find and Mount
2012-04-08 19:22 . 2012-04-14 13:11 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-27 18:04 . 2011-12-09 17:23 472864 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-14 13:11 . 2011-12-20 20:21 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-01 11:00 . 2006-03-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:00 . 2006-03-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:00 . 2006-03-02 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2006-03-02 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2006-03-02 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2006-03-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-02-03 09:57 . 2006-03-02 12:00 1860096 ----a-w- c:\windows\system32\win32k.sys
2011-12-26 11:05 . 2011-12-01 20:43 121816 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-05-01_03.34.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-03-02 12:00 . 2012-05-01 03:11 80696 c:\windows\system32\perfc010.dat
+ 2006-03-02 12:00 . 2012-05-01 15:38 80696 c:\windows\system32\perfc010.dat
- 2006-03-02 12:00 . 2012-05-01 03:11 68584 c:\windows\system32\perfc009.dat
+ 2006-03-02 12:00 . 2012-05-01 15:38 68584 c:\windows\system32\perfc009.dat
+ 2006-03-02 12:00 . 2012-05-01 15:38 482092 c:\windows\system32\perfh010.dat
- 2006-03-02 12:00 . 2012-05-01 03:11 482092 c:\windows\system32\perfh010.dat
+ 2006-03-02 12:00 . 2012-05-01 15:38 435688 c:\windows\system32\perfh009.dat
- 2006-03-02 12:00 . 2012-05-01 03:11 435688 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-05-20 36864]
"IAStorIcon"="c:\programmi\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2009-08-14 614400]
"4623 Scan2PC"="c:\windows\Twain_32\Samsung\SCX4623\Scan2pc.exe" [2009-09-10 1968640]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"nwiz"="c:\programmi\NVIDIA Corporation\nView\nwiz.exe" [2010-07-07 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-07-09 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
"RTHDCPL"="RTHDCPL.EXE" [2010-09-07 19573352]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 08:27 153136 ----a-w- c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\ScanMgr.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\SCX4623\\Scan2Pc.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\SCX4623\\Sscan2io.exe"=
"c:\\Programmi\\ASUS\\AI Suite II\\AI Suite II.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\UltraVNC\\vncviewer.exe"=
"c:\\Programmi\\FIFA 12\\Game\\fifa.exe"=
.
R0 ndasfs;ndasfs;c:\windows\system32\drivers\ndasfs.sys [13/01/2010 10.12.36 562152]
R1 ndasfat;NDAS FAT File System Service;c:\windows\system32\drivers\ndasfat.sys [13/01/2010 10.12.36 461288]
R1 ndasrofs;NDAS ROFS File System Service;c:\windows\system32\drivers\ndasrofs.sys [13/01/2010 10.12.28 791528]
R3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys [20/04/2011 22.55.10 95720]
R3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys [20/04/2011 22.55.11 292840]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28/12/2011 14.41.34 691696]
S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [06/05/2011 18.49.52 11832]
S2 asComSvc;ASUS Com Service;c:\programmi\ASUS\AXSP\1.00.13\atkexComSvc.exe [06/05/2011 18.47.15 918144]
S2 asHmComSvc;ASUS HM Com Service;c:\programmi\ASUS\AAHM\1.00.13\aaHMSvc.exe [06/05/2011 18.47.18 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\programmi\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [06/05/2011 18.49.30 586880]
S2 gupdate;Servizio Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [23/12/2011 16.17.09 136176]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\programmi\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [20/04/2011 22.48.07 13336]
S2 Samsung Network Fax Server;Samsung Network Fax Server;c:\windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe [11/05/2011 19.16.07 162304]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [08/04/2012 21.22.59 253088]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [26/01/2012 0.29.55 1691480]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [23/12/2011 16.17.09 136176]
S3 PROCEXP151;PROCEXP151;\??\c:\windows\system32\Drivers\PROCEXP151.SYS --> c:\windows\system32\Drivers\PROCEXP151.SYS [?]
S3 SliceDisk5;SliceDisk5;c:\programmi\A-FF Find and Mount\slicedisk.sys [08/04/2012 21.27.57 26192]
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-05-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 13:11]
.
2012-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-12-23 14:17]
.
2012-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-12-23 14:17]
.
.
------- Scansione supplementare -------
.
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{843BFDA4-C344-4C55-B685-A37DC954B3B4}: NameServer = 88.149.128.12,88.149.128.22
FF - ProfilePath - c:\documents and settings\Chicco\Dati applicazioni\Mozilla\Firefox\Profiles\5j5g6jes.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKLM-Explorer_Run-39691 - c:\docume~1\ALLUSE~1\LOCALS~1\Temp\mssoucweh.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-05-01 17:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2012-05-01 17:47:55
ComboFix-quarantined-files.txt 2012-05-01 15:47
ComboFix2.txt 2012-05-01 03:55
ComboFix3.txt 2012-05-01 03:35
ComboFix4.txt 2011-12-23 00:34
.
Pre-Run: 247.541.153.792 byte disponibili
Post-Run: 247.527.649.280 byte disponibili
.
- - End Of File - - 264B5B2615D48003982D597651AC2459