Buona domenica a tutti!
l log non c'era per cui ho riscaricato il combofix, ho disattivato il ripristino configurazione, ho rilanciato combofix disattivando tutti i programmi aperti e clickando su ok ad ogni comunicazione di norton che c'era un file sospetto. Alla fina di tutto questo, ho ottenuto il seguente log di combofix:
ComboFix 09-11-15.01 - Amministratore 15/11/2009 10.26.24.6.1 - FAT32x86
Eseguito da: c:\documents and settings\Amministratore\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\system32\ctfmon .exe
.
((((((((((((((((((((((((( Files Creati Da 2009-10-15 al 2009-11-15 )))))))))))))))))))))))))))))))))))
.
2009-11-14 18:02 . 2009-11-14 18:02 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
2009-11-14 18:02 . 2009-11-14 18:02 -------- d-----w- c:\documents and settings\NetworkService\Dati applicazioni\Yahoo!
2009-11-14 18:02 . 2009-11-14 18:02 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
2009-11-14 18:00 . 2009-11-14 18:00 -------- d-----w- c:\documents and settings\NetworkService\Dati applicazioni\HPAppData
2009-11-14 18:00 . 2009-11-14 18:00 -------- d-----r- c:\documents and settings\NetworkService\Preferiti
2009-11-14 16:11 . 2009-11-14 16:11 -------- d-----w- c:\programmi\File Scanner Library (Spybot - Search & Destroy)
2009-11-11 20:33 . 2009-11-11 20:33 1 ----a-w- c:\documents and settings\Giampaolo\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-11 20:32 . 2009-11-11 20:32 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\OpenOffice.org
2009-11-10 09:13 . 2009-11-10 09:13 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\CyberLink
2009-11-08 12:26 . 2009-11-08 12:26 -------- d--h--w- c:\windows\PIF
2009-11-05 10:16 . 2009-11-05 10:16 -------- d-----w- c:\documents and settings\Amministratore\.housecall6.6
2009-11-05 10:13 . 2009-11-05 10:13 -------- d-----w- c:\windows\Sun
2009-11-03 20:21 . 2009-11-03 20:21 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\Yahoo!
2009-11-03 20:21 . 2009-11-03 20:21 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\HPAppData
2009-11-03 20:21 . 2009-11-03 20:21 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\.clamwin
2009-11-03 06:25 . 2009-11-03 06:25 -------- d-sh--w- c:\documents and settings\Amministratore\IECompatCache
2009-11-03 05:07 . 2009-11-03 05:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-11-01 19:47 . 2009-11-01 19:47 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\.clamwin
2009-10-31 06:57 . 2009-10-31 06:57 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\.clamwin
2009-10-31 06:57 . 2009-10-31 06:57 -------- d-----w- c:\programmi\ClamWin
2009-10-31 06:57 . 2009-10-31 06:57 -------- d-----w- c:\documents and settings\All Users\.clamwin
2009-10-29 10:20 . 2009-10-29 10:20 -------- d-sh--w- c:\documents and settings\Giampaolo\IECompatCache
2009-10-28 07:42 . 2009-10-28 07:43 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Softland
2009-10-27 10:37 . 2009-10-27 10:37 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\Temp
2009-10-24 08:26 . 2009-10-29 10:38 165232 ---ha-w- c:\documents and settings\Giampaolo\Dati applicazioni\Microsoft\Virtual PC\VPCKeyboard.dll
2009-10-24 08:25 . 2009-10-24 08:25 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\VMware
2009-10-23 09:27 . 2009-10-23 09:27 -------- d-----w- C:\Virtual_Machine
2009-10-23 08:28 . 2001-08-17 20:53 3328 ----a-w- c:\windows\system32\drivers\qv2kux.sys
2009-10-23 08:28 . 2001-08-17 20:53 3328 ----a-w- c:\windows\system32\dllcache\qv2kux.sys
2009-10-23 08:07 . 2008-09-18 15:49 31280 ----a-r- c:\windows\system32\drivers\vmusb.sys
2009-10-23 07:15 . 2008-09-18 15:49 55856 ----a-r- c:\windows\system32\vnetinst.dll
2009-10-23 07:15 . 2008-09-18 15:49 16560 ----a-r- c:\windows\system32\drivers\vmnetadapter.sys
2009-10-23 07:15 . 2008-09-18 22:11 326192 ----a-w- c:\windows\system32\vmnetdhcp.exe
2009-10-23 07:15 . 2008-09-18 22:12 26288 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2009-10-23 07:15 . 2008-09-18 22:11 399920 ----a-w- c:\windows\system32\vmnat.exe
2009-10-23 07:15 . 2008-09-18 15:49 50736 ----a-r- c:\windows\system32\vmnetbridge.dll
2009-10-23 07:15 . 2008-09-18 15:49 31280 ----a-r- c:\windows\system32\drivers\vmnetbridge.sys
2009-10-23 07:15 . 2008-09-18 15:49 18736 ----a-r- c:\windows\system32\drivers\vmnet.sys
2009-10-23 07:15 . 2008-09-18 22:11 723504 ----a-w- c:\windows\system32\vnetlib.dll
2009-10-23 07:14 . 2008-09-18 22:12 23216 ----a-w- c:\windows\system32\drivers\VMkbd.sys
2009-10-23 07:12 . 2009-10-23 07:12 -------- d-----w- c:\programmi\VMware
2009-10-22 13:50 . 2009-10-30 08:34 165232 ---ha-w- c:\documents and settings\Amministratore\Dati applicazioni\Microsoft\Virtual PC\VPCKeyboard.dll
2009-10-22 13:49 . 2009-10-22 13:49 -------- d-----w- c:\programmi\Microsoft Virtual PC
2009-10-21 17:13 . 2009-10-21 17:13 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\WinZip
2009-10-21 17:07 . 2009-10-21 17:07 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Uniblue
2009-10-21 17:07 . 2009-10-21 17:07 -------- d-----w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\WinZip
2009-10-21 17:06 . 2009-10-21 17:06 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WinZip
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\NorthWind
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\MdiFavorites
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\MdiBrowser
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\IsapiFilter
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\IntelliSense
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\FormatCodes
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\EditAndContinue
2009-10-20 11:17 . 2009-10-20 11:17 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Media Player Classic
2009-10-20 11:14 . 2009-10-20 11:14 -------- d-----w- c:\programmi\XP Codec Pack
2009-10-20 11:06 . 2009-10-20 11:06 -------- d-----w- c:\programmi\pdfsam
2009-10-20 11:05 . 2008-10-08 12:43 20120 ----a-w- c:\windows\system32\dopdfmn6.dll
2009-10-20 11:05 . 2008-10-08 12:43 18072 ----a-w- c:\windows\system32\dopdfmi6.dll
2009-10-20 11:05 . 2009-10-20 11:05 -------- d-----w- c:\programmi\Softland
2009-10-20 10:05 . 2009-10-20 10:05 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\CyberLink
2009-10-20 10:05 . 2009-10-20 10:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CyberLink
2009-10-20 09:28 . 2009-10-20 09:28 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\VMware
2009-10-20 09:26 . 2009-10-20 09:26 -------- d-----w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\Temp
2009-10-20 09:26 . 2009-10-20 09:26 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\VMware
2009-10-20 09:23 . 2009-10-20 09:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\VMware
2009-10-19 13:08 . 2009-10-19 13:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Macrovision
2009-10-19 12:50 . 2009-10-19 12:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\National Instruments
2009-10-19 12:47 . 2009-10-19 12:47 -------- d-----w- c:\windows\system32\cvirte
2009-10-19 12:46 . 2009-10-19 12:46 -------- d-----w- c:\programmi\National Instruments
2009-10-19 07:18 . 2009-10-19 07:18 -------- d-----w- c:\programmi\TopOCR
2009-10-19 07:06 . 2009-10-19 07:06 -------- d-----w- c:\programmi\Softi Software
2009-10-19 07:06 . 2009-10-19 07:06 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Softi Software
2009-10-16 10:23 . 2009-10-16 10:23 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\HpUpdate
2009-10-16 10:21 . 2009-10-16 10:21 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\HpUpdate
2009-10-16 10:21 . 2009-10-16 10:21 -------- d-----w- c:\windows\Hewlett-Packard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-23 07:14 . 2005-11-03 12:03 550550 ----a-w- c:\windows\system32\perfh010.dat
2009-10-23 07:14 . 2005-11-03 12:03 108458 ----a-w- c:\windows\system32\perfc010.dat
2009-10-16 07:55 . 2009-10-16 07:55 -------- d-----w- c:\programmi\MSXML 4.0
2009-10-14 07:06 . 2005-11-03 11:43 76875 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-13 19:43 . 2009-10-13 08:15 120712 ----a-w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-13 19:43 . 2009-10-13 19:43 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\HP
2009-10-13 19:22 . 2009-10-13 19:22 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\Yahoo!
2009-10-13 19:22 . 2009-10-13 19:22 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\HPAppData
2009-10-13 18:30 . 2009-10-09 10:29 120712 ----a-w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-13 18:26 . 2009-10-13 18:26 -------- d-----w- c:\programmi\Microsoft
2009-10-13 18:26 . 2009-10-13 18:26 -------- d-----w- c:\programmi\Windows Live SkyDrive
2009-10-13 18:26 . 2009-10-13 18:26 -------- d-----w- c:\programmi\Windows Live
2009-10-13 18:25 . 2009-10-13 18:25 -------- d-----w- c:\programmi\Microsoft SQL Server Compact Edition
2009-10-13 18:24 . 2009-10-13 18:24 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\HPAppData
2009-10-13 18:21 . 2009-10-13 18:21 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-10-13 18:21 . 2009-10-13 18:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WEBREG
2009-10-13 18:21 . 2009-10-13 17:46 169199 ----a-w- c:\windows\hpoins36.dat
2009-10-13 18:08 . 2009-10-13 18:08 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\HP
2009-10-13 17:56 . 2009-10-13 17:56 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Yahoo!
2009-10-13 17:56 . 2009-10-13 17:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2009-10-13 17:56 . 2009-10-13 17:56 -------- d-----w- c:\programmi\Yahoo!
2009-10-13 17:54 . 2009-10-13 17:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP Product Assistant
2009-10-13 17:52 . 2009-10-13 17:52 -------- d-----w- c:\programmi\File comuni\HP
2009-10-13 17:51 . 2009-10-13 17:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP
2009-10-13 17:50 . 2009-10-13 17:50 -------- d-----w- c:\programmi\File comuni\Hewlett-Packard
2009-10-13 17:48 . 2009-10-13 17:48 -------- d-----w- c:\programmi\HP
2009-10-13 08:15 . 2009-10-13 08:15 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\Autodesk
2009-10-13 07:36 . 2009-10-13 07:36 -------- d-----w- c:\programmi\AnswerWorks 4.0
2009-10-13 07:34 . 2009-10-13 07:34 -------- d-----w- c:\programmi\AutoCAD 2007
2009-10-13 07:34 . 2009-10-13 07:34 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Autodesk
2009-10-13 07:34 . 2009-10-13 07:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Autodesk
2009-10-13 07:30 . 2009-10-13 07:30 -------- d-----w- c:\programmi\File comuni\Autodesk Shared
2009-10-13 07:30 . 2009-10-13 07:30 -------- d-----w- c:\programmi\Autodesk
2009-10-12 13:24 . 2009-10-12 13:24 -------- d-----w- c:\programmi\MSBuild
2009-10-12 13:24 . 2009-10-12 13:24 -------- d-----w- c:\programmi\Reference Assemblies
2009-10-12 12:21 . 2009-10-12 12:21 -------- d-----w- c:\programmi\File comuni\Crystal Decisions
2009-10-12 11:38 . 2009-10-12 11:38 9062 ----a-r- c:\documents and settings\Amministratore\Dati applicazioni\Microsoft\Installer\{0320FBC7-E1D8-4815-9FC1-112DC0358C3D}\_6FEFF9B68218417F98F549.exe
2009-10-12 11:38 . 2009-10-12 11:38 -------- d-----w- c:\programmi\Microsoft SQL Server Report Packs
2009-10-12 10:53 . 2009-10-12 10:53 -------- d-----w- c:\programmi\IIS
2009-10-12 09:23 . 2009-10-12 09:23 -------- d-----w- c:\programmi\File comuni\Merge Modules
2009-10-12 08:58 . 2009-10-12 08:58 -------- d-----w- c:\documents and settings\Telemaco\Dati applicazioni\Malwarebytes
2009-10-12 08:01 . 2009-10-12 08:01 -------- d-----w- c:\programmi\MSXML 6.0
2009-10-11 17:23 . 2009-10-11 17:23 -------- d-----w- c:\programmi\freepops
2009-10-11 11:13 . 2009-10-11 11:13 -------- d-----w- c:\programmi\File comuni\Adobe
2009-10-11 11:10 . 2009-10-11 11:10 -------- d-----w- c:\programmi\Google
2009-10-11 11:09 . 2009-10-11 11:09 -------- d-----w- c:\programmi\NOS
2009-10-11 11:09 . 2009-10-11 11:09 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-10-11 09:25 . 2009-10-11 09:25 -------- d-----w- c:\programmi\Microsoft SQL Server
2009-10-11 09:18 . 2009-10-11 09:18 -------- d-----w- c:\programmi\Microsoft.NET
2009-10-11 09:18 . 2009-10-11 09:18 -------- d-----w- c:\programmi\Microsoft Visual Studio 8
2009-10-11 09:18 . 2009-10-11 09:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-10-10 11:31 . 2009-10-10 11:31 1 ----a-w- c:\documents and settings\Augusta\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-10-10 11:30 . 2009-10-10 11:30 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\OpenOffice.org
2009-10-10 11:18 . 2009-10-10 11:18 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\Malwarebytes
2009-10-10 09:26 . 2009-10-10 09:26 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\AdobeUM
2009-10-10 08:01 . 2009-10-10 08:01 1 ----a-w- c:\documents and settings\Amministratore\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-10-10 08:00 . 2009-10-10 08:00 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\OpenOffice.org
2009-10-10 07:48 . 2009-10-10 07:48 143 ----a-w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\fusioncache.dat
2009-10-10 07:19 . 2009-10-10 07:19 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\Malwarebytes
2009-10-09 15:53 . 2009-10-09 15:53 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Malwarebytes
2009-10-09 15:53 . 2009-10-09 15:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-10-09 15:53 . 2009-10-09 15:53 -------- d-----w- c:\programmi\Manutenzione
2009-10-09 13:33 . 2009-10-09 13:33 -------- d-----w- c:\programmi\Pubblicazione guidata
2009-10-09 12:35 . 2009-10-09 12:35 -------- d-----w- c:\programmi\Ufficio
2009-10-09 12:30 . 2009-10-09 12:30 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Symantec
2009-10-09 10:31 . 2009-10-09 10:31 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-09 10:31 . 2009-10-09 10:31 152576 ----a-w- c:\documents and settings\Amministratore\Dati applicazioni\Sun\Java\jre1.6.0_15\lzma.dll
2009-10-09 10:25 . 2009-10-09 10:25 -------- d-----w- c:\programmi\SymNetDrv
2009-10-09 09:44 . 2009-10-09 09:44 -------- d-----w- c:\programmi\Java
2009-10-09 09:44 . 2009-10-09 09:44 -------- d-----w- c:\programmi\File comuni\Java
2009-10-09 09:34 . 2009-10-09 09:34 -------- d-----w- c:\programmi\SiSLan
2009-09-11 15:17 . 2004-08-19 04:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 22:03 . 2004-08-19 04:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:56 . 2005-07-03 02:15 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 09:00 . 2004-08-19 04:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2005-10-12 14:04 . 2005-10-12 14:04 131072 ----a-w- c:\programmi\internet explorer\plugins\LV80ActiveXControl.dll
2006-06-07 13:40 . 2006-06-07 13:40 132848 ----a-w- c:\programmi\internet explorer\plugins\LV82ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Programmi\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Programmi\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Programmi\\VMware\\VMware Workstation\\vmware-authd.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe [2008-04-14 14336]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\programmi\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-12-09 2799808]
S1 GhPciScan;GhostPciScanner;c:\programmi\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 5632]
S2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;c:\programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-08-03 100032]
S2 vmci;VMware vmci;c:\windows\system32\Drivers\vmci.sys [2008-09-18 54960]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - PROCEXP113
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-09 c:\windows\Tasks\Norton AntiVirus - Scansione del computer - Amministratore.job
- c:\progra~1\NORTON~1\Navw32.exe [2004-08-24 12:26]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\Ufficio\MICROS~1\Office10\EXCEL.EXE/3000
LSP: c:\programmi\VMware\VMware Workstation\vsocklib.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-Adobe_Reader - c:\programmi\Adobe\acrotray.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-15 10:39
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-3237291647-1294369284-1593085102-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(3064)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
.
Ora fine scansione: 2009-11-15 10:43
ComboFix-quarantined-files.txt 2009-11-15 09:43
Pre-Run: 53.099.593.728 byte disponibili
Post-Run: 53.065.777.152 byte disponibili
- - End Of File - - 71AB6A1C7CE6C4BA133D005827A921C2
r16, che faccio ora???