dovrei aver fatto tutto come richiesto:
ComboFix 10-01-13.06 - Proprietario 13/01/2010 22.07.41.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.1023.727 [GMT 1:00]
Eseguito da: c:\documents and settings\Proprietario\Desktop\pippo.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {0012EF58-EE90-0012-58EF-1200F054927C}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\PROPRI~1\IMPOST~1\Temp\wscsvc32.exe
C:\Thumbs.db
c:\windows\system32\drivers\H8SRTjxboeyfwxw.sys
c:\windows\system32\H8SRTbakdqtjcwl.dll
c:\windows\system32\H8SRTbrsnjdjoow.dll
c:\windows\system32\H8SRTdulhrhnrvu.dll
c:\windows\system32\H8SRThfldymttkk.dll
c:\windows\system32\h8srtkrl32mainweq.dll
c:\windows\system32\h8srtshsyst.dll
c:\windows\system32\H8SRTtkomlippnt.dat
c:\windows\system32\SIntf16.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
((((((((((((((((((((((((( Files Creati Da 2009-12-13 al 2010-01-13 )))))))))))))))))))))))))))))))))))
.
2010-01-13 19:44 . 2009-11-25 10:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-13 19:44 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-13 19:44 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-13 19:44 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-13 19:44 . 2010-01-13 19:44 -------- d-----w- c:\programmi\Avira
2010-01-13 19:44 . 2010-01-13 19:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-01-12 17:21 . 2010-01-12 17:21 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Ascaron Entertainment
2009-12-26 11:26 . 2009-12-26 11:26 -------- d-----w- c:\windows\Logs
2009-12-26 11:22 . 2010-01-12 19:42 -------- d-----w- c:\programmi\Impero dei Mari Anthology
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-13 12:39 . 2006-12-15 14:11 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\OpenOffice.org2
2009-12-26 11:26 . 2007-12-04 17:45 -------- d--h--w- c:\programmi\FX Uninstall Information
2009-11-29 14:21 . 2007-02-07 14:06 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Apple Computer
2009-11-29 14:18 . 2009-11-29 14:17 -------- d-----w- c:\programmi\iTunes
2009-11-29 14:18 . 2009-11-29 14:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-29 14:17 . 2009-11-29 14:17 -------- d-----w- c:\programmi\iPod
2009-11-29 14:17 . 2008-11-02 13:03 -------- d-----w- c:\programmi\File comuni\Apple
2009-11-29 14:16 . 2009-11-29 14:16 -------- d-----w- c:\programmi\Bonjour
2009-11-29 14:15 . 2009-11-29 14:15 -------- d-----w- c:\programmi\QuickTime
2009-11-21 16:38 . 2004-08-19 12:00 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-13 18:21 . 2006-12-15 04:17 47552 -c--a-w- c:\documents and settings\Proprietario\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-11-12 16:07 . 2009-11-12 16:07 79144 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-29 07:42 . 2004-08-19 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2009-10-29 07:42 . 2004-08-19 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:42 . 2004-08-19 12:00 17408 ------w- c:\windows\system32\corpol.dll
2009-10-25 08:33 . 2004-08-19 12:00 63180 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 08:33 . 2004-08-19 12:00 425432 ----a-w- c:\windows\system32\perfh010.dat
2009-10-21 06:00 . 2004-08-19 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2004-08-19 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-19 12:00 263552 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-15 21:50 . 2004-08-19 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-10 406016]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 81920]
"ATICCC"="c:\programmi\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
"RemoteControl"=c:\programmi\CyberLink\PowerDVD\PDVDServ.exe
"SsAAD.exe"=c:\progra~1\Sony\SONICS~1\SsAAD.exe
"MessengerPlus3"="c:\programmi\MessengerPlus! 3\MsgPlus.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"e:\\emule\\eMule\\eMule.exe"=
"e:\\VIDEOCAMERA PROGRAMMA\\programs\\RM.exe"=
"e:\\VIDEOCAMERA PROGRAMMA\\programs\\Studio.exe"=
"e:\\VIDEOCAMERA PROGRAMMA\\programs\\PMSRegisterFile.exe"=
"e:\\VIDEOCAMERA PROGRAMMA\\programs\\umi.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"e:\\Programmi\\age of empires\\age3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\programmi\Microsoft ActiveSync\rapimgr.exe"= c:\programmi\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programmi\Microsoft ActiveSync\wcescomm.exe"= c:\programmi\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programmi\Microsoft ActiveSync\WCESMgr.exe"= c:\programmi\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"e:\\Programmi\\age of empires\\age3x.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 a2free;a-squared Free Service;c:\programmi\a-squared Free\a2service.exe [07/08/2007 10.11.46 226936]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [18/09/2008 13.22.29 8192]
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-01-08 c:\windows\Tasks\Norton Security Scan.job
- c:\programmi\Norton Security Scan\Nss.exe [2008-01-09 15:04]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.yahoo.it/
uInternet Settings,ProxyOverride = *.local
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Proprietario\Dati applicazioni\Mozilla\Firefox\Profiles\9psivcgj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101699&gct=&gc=1&q=
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
HKCU-Run-Malware Defense - c:\programmi\Malware Defense\mdefense.exe
HKU-Default-Run-msnmsgr - c:\programmi\MSN Messenger\msnmsgr.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-13 22:13
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-725345543-1682526488-2147196821-1003\S*o**‹F,…Àuè(pÿÿ‹M*øëŠr*o*ùÿÿW*‹F,]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(908)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3280)
c:\windows\system32\WININET.dll
c:\windows\system32\browselc.dll
c:\programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
c:\progra~1\SPYBOT~1\SDHelper.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
c:\windows\system32\wdfmgr.exe
c:\programmi\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-13 22:17:15 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-13 21:17
Pre-Run: 3.078.995.968 byte disponibili
Post-Run: 3.067.039.744 byte disponibili
- - End Of File - - 7654DF2E32789F8C11153A5E8C997818