Salve,
desidero avere risposta da un esperto se possibile, ho effettuato la scansione con Combofix ieri, ho il log adesso lo incollo.
Le pagine web in apertura sono lentissime ma anche la posta elettronica, di tanto in tanto Norton mi rilevo queste minacce: clipsrv.exe sessmgr.exe esentutl.exe.
Cosa devo fare?? Aiutatemi grazie
ComboFix 10-02-10.05 - Agata Sapuppo 11/02/2010 19.30.37.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1014.371 [GMT 1:00]
Eseguito da: c:\documents and settings\Agata Sapuppo\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Agata Sapuppo\Dati applicazioni\comrepl.exe
c:\documents and settings\Agata Sapuppo\Dati applicazioni\dllhst3g.exe
c:\documents and settings\Agata Sapuppo\Dati applicazioni\esentutl.exe
c:\documents and settings\Agata Sapuppo\Dati applicazioni\ieudinit.exe
c:\documents and settings\Agata Sapuppo\Dati applicazioni\Microsoft\ieudinit.exe
c:\documents and settings\Agata Sapuppo\Dati applicazioni\mstsc.exe
c:\recycler\S-1-5-21-2326369520-891307005-2424629274-1006
c:\windows\dllhst3g.exe
c:\windows\system\comrepl.exe
c:\windows\system\ieudinit.exe
c:\windows\system\logman.exe
c:\windows\system\sessmgr.exe
c:\windows\system32\drivers\esentutl.exe
c:\windows\system32\drivers\logman.exe
c:\windows\system32\drivers\mqtgsvc.exe
c:\windows\system32\drivers\mstsc.exe
c:\windows\system32\drivers\rsvp.exe
.
((((((((((((((((((((((((( Files Creati Da 2010-01-11 al 2010-02-11 )))))))))))))))))))))))))))))))))))
.
2010-02-11 11:51 . 2010-02-03 09:00 84912 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100210.048\NAVENG.SYS
2010-02-11 11:51 . 2010-02-03 09:00 1324720 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100210.048\NAVEX15.SYS
2010-02-11 11:51 . 2009-12-28 09:00 177520 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100210.048\NAVENG32.DLL
2010-02-11 11:51 . 2009-12-28 09:00 1647984 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100210.048\NAVEX32A.DLL
2010-02-11 11:51 . 2009-12-28 09:00 371248 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100210.048\EECTRL.SYS
2010-02-11 11:51 . 2009-12-28 09:00 2747440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100210.048\CCERASER.DLL
2010-02-11 11:51 . 2009-12-28 09:00 259440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100210.048\ECMSVR32.DLL
2010-02-11 11:51 . 2009-12-28 09:00 102448 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100210.048\ERASER.SYS
2010-02-10 11:27 . 2010-02-11 16:47 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-02-10 11:27 . 2010-02-11 11:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-02-06 07:09 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\Scxpx86.dll
2010-02-06 07:09 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSvix86.sys
2010-02-06 07:09 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys
2010-02-06 07:09 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSxpx86.dll
2010-02-06 07:09 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSviA64.sys
2010-01-31 07:59 . 2010-01-31 07:59 -------- d-----w- c:\windows\system32\LogFiles
2010-01-30 08:20 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSXpx86.sys
2010-01-30 08:20 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\Scxpx86.dll
2010-01-30 08:20 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSxpx86.dll
2010-01-30 08:20 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSvix86.sys
2010-01-30 08:20 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSviA64.sys
2010-01-27 21:20 . 2010-01-27 21:20 -------- d--h--w- c:\windows\PIF
2010-01-27 21:20 . 1996-02-08 16:07 284160 ----a-w- c:\windows\unin0410.exe
2010-01-27 21:20 . 2010-01-27 21:20 -------- d-----w- c:\documents and settings\Agata Sapuppo\WINDOWS
2010-01-27 19:16 . 2010-01-27 19:17 -------- d-----w- c:\programmi\Imikimi
2010-01-14 19:49 . 2010-01-14 19:49 -------- d-----w- c:\documents and settings\Agata Sapuppo\Dati applicazioni\vlc
2010-01-14 19:37 . 2010-01-14 19:37 -------- d-----w- c:\programmi\VideoLAN
2010-01-14 18:16 . 2010-01-14 20:00 -------- d-----w- c:\programmi\File comuni\DVDVideoSoft
2010-01-14 17:52 . 2010-01-14 17:52 -------- d-----w- c:\documents and settings\Agata Sapuppo\Impostazioni locali\Dati applicazioni\Ahead
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-13 23:24 . 2009-12-30 10:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WinZip
2010-01-09 20:17 . 2009-08-14 12:42 -------- d-----w- c:\programmi\File comuni\Adobe
2010-01-07 16:41 . 2010-01-07 16:41 -------- d-----w- c:\documents and settings\Agata Sapuppo\Dati applicazioni\Nero
2010-01-07 16:39 . 2010-01-07 16:34 -------- d-----w- c:\programmi\File comuni\Nero
2010-01-07 16:34 . 2010-01-07 16:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2010-01-07 16:34 . 2010-01-07 16:34 -------- d-----w- c:\programmi\Nero
2010-01-06 11:45 . 2010-01-06 11:45 -------- d-----w- c:\documents and settings\Agata Sapuppo\Dati applicazioni\Packard Bell
2010-01-06 11:18 . 2010-01-05 11:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Recisio
2010-01-05 11:23 . 2010-01-05 11:23 253952 ------w- c:\windows\Setup1.exe
2010-01-05 11:23 . 2010-01-05 11:23 74752 ----a-w- c:\windows\ST6UNST.EXE
2010-01-04 21:28 . 2010-01-04 21:28 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Messenger Plus!
2010-01-04 21:28 . 2010-01-04 21:28 -------- d-----w- c:\programmi\Messenger Plus! Live
2009-12-31 11:22 . 2009-08-14 18:32 75346 ----a-w- c:\windows\system32\perfc010.dat
2009-12-31 11:22 . 2009-08-14 18:32 449362 ----a-w- c:\windows\system32\perfh010.dat
2009-12-30 20:01 . 2009-08-14 09:58 76875 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-30 10:29 . 2009-08-14 12:38 -------- d-----w- c:\programmi\Packard Bell
2009-12-29 18:51 . 2009-12-28 16:57 -------- d-----w- c:\programmi\File comuni\Symantec Shared
2009-12-29 15:34 . 2009-12-28 16:57 -------- d-----w- c:\programmi\Symantec
2009-12-29 15:34 . 2009-12-28 16:57 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-12-29 15:34 . 2009-12-28 16:57 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-12-29 15:34 . 2009-12-28 16:57 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-12-29 15:34 . 2009-12-28 16:57 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-12-29 10:58 . 2009-08-14 13:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Symantec
2009-12-29 08:57 . 2009-12-29 08:57 -------- d-----w- c:\programmi\vanBasco's Karaoke Player
2009-12-28 19:16 . 2009-08-14 13:03 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-12-28 18:36 . 2009-12-28 18:36 -------- d--h--w- c:\documents and settings\All Users\Dati applicazioni\CanonBJ
2009-12-28 18:11 . 2009-12-28 18:11 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\FLEXnet
2009-12-28 18:04 . 2009-08-14 13:06 -------- d-----w- c:\programmi\Windows Live
2009-12-28 18:00 . 2009-12-28 18:00 -------- d-----w- c:\programmi\Microsoft
2009-12-28 17:13 . 2009-12-28 17:12 -------- d-----w- c:\programmi\eMule
2009-12-28 17:12 . 2009-08-14 12:39 -------- d-----w- c:\programmi\Google
2009-12-28 17:10 . 2009-12-28 16:51 142 ----a-w- c:\documents and settings\Agata Sapuppo\Impostazioni locali\Dati applicazioni\fusioncache.dat
2009-12-28 17:04 . 2009-08-14 12:25 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-12-28 17:02 . 2009-12-28 17:02 -------- d-----w- c:\programmi\File comuni\CyberLink
2009-12-28 17:02 . 2009-12-28 17:02 -------- d-----w- c:\programmi\CyberLink
2009-12-28 16:59 . 2009-12-28 16:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Temp
2009-12-28 16:59 . 2009-12-28 17:00 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-12-28 16:59 . 2009-12-28 17:00 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-28 16:59 . 2009-12-28 17:00 505128 ----a-w- c:\windows\system32\msvcp71.dll
2009-12-28 16:59 . 2009-12-28 16:59 53319 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Temp\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
2009-12-28 16:58 . 2009-08-14 13:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Norton
2009-12-28 16:56 . 2009-12-28 16:56 -------- d-----w- c:\programmi\Launch Manager
2009-12-28 16:56 . 2009-12-28 16:56 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01007.Wdf
2009-12-28 16:56 . 2009-12-28 16:56 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-28 16:56 . 2009-12-28 16:56 -------- d-----w- c:\programmi\Synaptics
2009-12-28 16:54 . 2009-12-28 16:54 -------- d-----w- c:\programmi\Video Web Camera
2009-12-28 16:52 . 2009-12-28 16:52 -------- d-----w- c:\programmi\File comuni\SNP2UVC
2009-12-28 16:52 . 2009-12-28 16:52 -------- d-----w- c:\documents and settings\Agata Sapuppo\Dati applicazioni\InstallShield
2009-12-28 16:51 . 2009-12-28 16:51 61736 ----a-w- c:\documents and settings\Agata Sapuppo\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="c:\programmi\Packard Bell\SetupmyPC\SmpSys.exe" [2009-03-18 1160736]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-28 39408]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-05-01 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-05-01 354840]
"PersistenceThread"="c:\windows\system32\PersistenceThread.exe" [2009-05-01 92696]
"AzMixerSel"="c:\programmi\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-17 53248]
"Google Desktop Search"="c:\programmi\Google\Google Desktop Search\GoogleDesktop.exe" [2009-08-14 24064]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PLFSetL"="c:\windows\PLFSetL.exe" [2008-07-03 94208]
"snp2uvc"="c:\windows\system32\csnp2uvc.dll" [2009-02-16 196608]
"Camera Assistant Software"="c:\programmi\Video Web Camera\traybar.exe" [2009-07-27 630784]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2009-02-27 1434920]
"LManager"="c:\programmi\Launch Manager\LManager.exe" [2009-03-05 805384]
"RemoteControl8"="c:\programmi\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-10-17 91432]
"PDVD8LanguageShortcut"="c:\programmi\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-10 2221352]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SymEFA.sys [03/02/2010 22.04.45 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1008000.029\BHDrvx86.sys [03/02/2010 22.04.45 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1008000.029\cchpx86.sys [03/02/2010 22.04.18 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys [06/02/2010 8.09.07 329592]
R2 Norton Internet Security;Norton Internet Security;c:\programmi\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [03/02/2010 22.04.27 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [28/12/2009 10.00.00 102448]
R3 igd;igd;c:\windows\system32\drivers\igxpmp32.sys [14/08/2009 13.28.42 5096544]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\programmi\Google\Google Desktop Search\GoogleDesktop.exe [14/08/2009 13.39.46 24064]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0410&m=dotm&r=0xph12099706l0383wum5f4731r458
mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0410&m=dotm&r=0xph12099706l0383wum5f4731r458
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
TCP: {2BE54331-F623-4DD7-AE9D-CC1F9470BA18} = 193.70.152.15,193.70.152.25
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Explorer_Run-ComRepl - c:\docume~1\AGATAS~1\DATIAP~1\comrepl.exe
HKCU-Explorer_Run-Esent Utl - c:\windows\System32\drivers\esentutl.exe
HKCU-Explorer_Run-Logman - c:\windows\System\logman.exe
HKCU-Explorer_Run-rsvp - c:\windows\System32\drivers\rsvp.exe
HKCU-Explorer_Run-MstInit - c:\documents and settings\Agata Sapuppo\LOCALS~1\APPLIC~1\MICROS~1\mstinit.exe
HKCU-Explorer_Run-IEudinit - c:\docume~1\AGATAS~1\DATIAP~1\ieudinit.exe
HKCU-Explorer_Run-DllHst - c:\docume~1\AGATAS~1\DATIAP~1\dllhst3g.exe
HKU-Default-Explorer_Run-IEudinit - c:\docume~1\AGATAS~1\DATIAP~1\MICROS~1\ieudinit.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-11 19:44
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\programmi\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\programmi\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2004)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\programmi\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
.
**************************************************************************
.
Ora fine scansione: 2010-02-11 19:45:23 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-02-11 18:45
Pre-Run: 130.613.088.256 byte disponibili
Post-Run: 130.616.365.056 byte disponibili
WindowsXP-KB310994-SP2-Home-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - FA2FD8E32F8411BCAEF8DF88E9DE6F25