Buon pomeriggio, ho effettuato esattamente tutto ciò che mi avevi indicato e qui di seguito ti copio il report di combofix come mi avevi chiesto.
Ti ringrazio anticipatamente e attendo altre indicazioni se necessario.
Roberto
ComboFix 10-07-08.02 - VR 10/07/2010 10.28.47.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.247.7 [GMT 2:00]
Eseguito da: c:\documents and settings\VR\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\VR\Dati applicazioni\Install.dat
C:\Logo.sys
c:\windows\command
c:\windows\desktop
c:\windows\system\Color
.
((((((((((((((((((((((((( Files Creati Da 2010-06-10 al 2010-07-10 )))))))))))))))))))))))))))))))))))
.
2010-07-09 15:56 . 2010-07-09 15:56 -------- d-----w- c:\programmi\Trend Micro
2010-07-09 15:40 . 2010-07-09 15:40 -------- d-----w- c:\documents and settings\VR\Dati applicazioni\Malwarebytes
2010-07-09 15:39 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-09 15:39 . 2010-07-09 15:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-07-09 15:39 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-09 15:38 . 2010-07-09 15:39 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-07-05 15:33 . 2010-07-05 15:33 -------- d-----w- c:\windows\Samsung
2010-07-05 13:15 . 2010-07-05 13:15 -------- d-----w- c:\documents and settings\VR\Dati applicazioni\SmarThru4
2010-07-05 13:14 . 2007-10-22 06:55 41984 ------w- c:\windows\system32\drivers\DgivEcpXP.sys
2010-07-05 13:13 . 2007-12-27 14:15 458752 ----a-w- c:\windows\prinst.exe
2010-07-05 13:12 . 2007-12-27 14:38 94208 ----a-w- c:\windows\system32\SamFaxPort.dll
2010-07-05 13:12 . 2010-07-05 13:12 -------- d-----w- c:\programmi\File comuni\SRC Shared
2010-07-05 13:11 . 1997-05-26 12:55 23040 ----a-w- c:\windows\system32\irisco32.dll
2010-07-05 13:08 . 2010-07-05 13:11 -------- d-----w- c:\programmi\Readiris10
2010-07-05 13:06 . 2010-07-05 13:24 -------- d-----w- c:\programmi\SmarThru 4
2010-07-05 12:54 . 2010-07-05 12:54 -------- d-----w- c:\programmi\Samsung
2010-07-05 08:22 . 2010-07-05 08:22 -------- d-----w- C:\spoolerlogs
2010-07-05 08:04 . 2010-07-05 08:04 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-29 20:20 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-29 20:20 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-29 20:20 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-29 20:20 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-29 20:20 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-29 20:20 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-29 20:20 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-29 20:18 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-06-29 20:18 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-22 14:35 . 2003-03-29 14:45 89184 ----a-w- c:\windows\system32\drivers\imagedrv.sys
2010-06-22 14:34 . 2001-06-26 06:15 38912 ----a-w- c:\windows\system32\picn20.dll
2010-06-22 14:34 . 2001-07-06 12:41 569344 ----a-w- c:\windows\system32\imagr5.dll
2010-06-22 14:34 . 2001-07-06 10:44 544768 ----a-w- c:\windows\system32\imagx5.dll
2010-06-22 14:34 . 2001-07-06 16:24 283920 ----a-w- c:\windows\system32\ImagXpr5.dll
2010-06-22 14:34 . 2010-06-22 14:34 -------- d-----w- c:\programmi\File comuni\Ahead
2010-06-22 14:34 . 2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
2010-06-16 06:37 . 2010-06-16 06:37 -------- d-----w- c:\programmi\MSXML 6.0
2010-06-16 06:27 . 2010-05-06 10:32 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-06-16 06:27 . 2010-05-06 10:32 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-06-16 06:27 . 2010-05-06 10:32 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-06-16 06:27 . 2010-05-06 10:32 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-06-16 06:27 . 2010-05-06 10:32 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-06-16 06:27 . 2010-05-06 10:32 11076096 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-06-16 06:27 . 2010-05-06 10:32 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-16 06:25 . 2010-04-16 11:43 41984 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-06-16 01:06 . 2004-08-19 11:00 22060 -c----w- c:\windows\system32\dllcache\npds.zip
2010-06-16 01:06 . 2004-08-19 11:00 403 -c----w- c:\windows\system32\dllcache\npdrmv2.zip
2010-06-16 01:06 . 2008-04-14 01:53 92672 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2010-06-16 01:06 . 2009-07-31 08:02 1372672 -c----w- c:\windows\system32\dllcache\msxml6.dll
2010-06-16 01:04 . 2008-04-14 02:12 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll
2010-06-16 01:04 . 2008-04-14 02:12 24064 -c----w- c:\windows\system32\dllcache\pidgen.dll
2010-06-16 01:03 . 2008-04-14 02:13 81920 ------w- c:\windows\system32\ieencode.dll
2010-06-16 01:02 . 2008-04-14 02:14 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2010-06-15 21:01 . 2008-06-14 17:32 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-06-15 21:00 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-06-15 20:59 . 2009-11-21 15:54 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-06-15 20:58 . 2010-02-12 04:33 100864 -c----w- c:\windows\system32\dllcache\6to4svc.dll
2010-06-15 20:57 . 2009-10-15 16:29 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-06-15 20:57 . 2009-10-15 16:29 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-06-15 20:56 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-06-15 20:56 . 2010-02-17 12:05 2193664 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-06-15 20:56 . 2009-03-06 14:19 286208 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-06-15 20:56 . 2009-02-09 11:22 111104 -c----w- c:\windows\system32\dllcache\services.exe
2010-06-15 20:56 . 2009-02-09 10:51 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-06-15 20:56 . 2009-02-09 10:51 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-06-15 20:56 . 2009-02-09 10:51 683520 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-06-15 20:56 . 2009-06-25 08:25 735744 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-06-15 20:56 . 2009-02-09 10:51 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-06-15 20:56 . 2009-02-09 10:51 736256 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-06-15 20:56 . 2010-02-16 19:05 2149888 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-06-15 20:56 . 2010-02-16 19:05 2028032 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-06-15 20:53 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-06-15 20:53 . 2010-05-02 08:06 1851264 -c----w- c:\windows\system32\dllcache\win32k.sys
2010-06-15 20:50 . 2010-03-05 14:38 65536 -c----w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-15 20:46 . 2010-02-05 18:25 1296896 -c----w- c:\windows\system32\dllcache\quartz.dll
2010-06-15 20:45 . 2008-10-15 16:36 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-06-15 20:44 . 2009-12-24 06:59 177664 -c----w- c:\windows\system32\dllcache\wintrust.dll
2010-06-15 20:44 . 2010-01-13 14:00 86528 -c----w- c:\windows\system32\dllcache\cabview.dll
2010-06-15 20:42 . 2008-04-21 21:14 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-06-15 20:37 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-06-15 18:57 . 2010-06-29 20:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Alwil Software
2010-06-15 16:16 . 2001-08-31 12:00 31360 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2010-06-15 16:16 . 2001-08-31 12:00 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll
2010-06-15 16:16 . 2001-08-31 12:00 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll
2010-06-15 16:16 . 2001-08-31 12:00 5632 -c--a-w- c:\windows\system32\dllcache\w3svapi.dll
2010-06-15 16:16 . 2001-08-31 12:00 74240 -c--a-w- c:\windows\system32\dllcache\w3ext.dll
2010-06-15 16:16 . 2001-08-31 12:00 4608 -c--a-w- c:\windows\system32\dllcache\w3ctrs51.dll
2010-06-15 16:16 . 2001-08-31 12:00 48256 -c--a-w- c:\windows\system32\dllcache\w32.dll
2010-06-15 16:16 . 2008-04-14 02:13 86073 -c--a-w- c:\windows\system32\dllcache\voicesub.dll
2010-06-15 16:16 . 2008-04-14 02:13 426041 -c--a-w- c:\windows\system32\dllcache\voicepad.dll
2010-06-15 16:14 . 2001-08-30 21:08 57856 -c--a-w- c:\windows\system32\dllcache\EXCH_scripto.dll
2010-06-15 16:13 . 2001-08-31 12:00 98304 -c--a-w- c:\windows\system32\dllcache\msir3jp.dll
2010-06-15 16:12 . 2001-08-31 12:00 6144 -c--a-w- c:\windows\system32\dllcache\kbd101a.dll
2010-06-15 16:11 . 2001-08-31 12:00 36864 -c--a-w- c:\windows\system32\dllcache\hanjadic.dll
2010-06-15 16:10 . 2004-08-03 20:31 480256 -c--a-w- c:\windows\system32\dllcache\cintsetp.exe
2010-06-15 16:09 . 2001-08-31 12:00 29184 -c--a-w- c:\windows\system32\dllcache\asptxn.dll
2010-06-15 16:09 . 2001-08-31 12:00 10240 -c--a-w- c:\windows\system32\dllcache\aspperf.dll
2010-06-15 16:09 . 2001-08-31 12:00 6144 -c--a-w- c:\windows\system32\dllcache\admxprox.dll
2010-06-15 16:09 . 2001-08-31 12:00 50176 -c--a-w- c:\windows\system32\dllcache\adrot.dll
2010-06-15 16:08 . 2003-04-14 19:04 16384 -c--a-w- c:\windows\system32\dllcache\tcptsat.dll
2010-06-15 16:08 . 2001-08-31 12:00 7680 -c--a-w- c:\windows\system32\dllcache\inetmgr.exe
2010-06-15 16:08 . 2001-08-31 12:00 5632 -c--a-w- c:\windows\system32\dllcache\iisrstap.dll
2010-06-15 16:08 . 2001-08-31 12:00 6144 -c--a-w- c:\windows\system32\dllcache\ftpsapi2.dll
2010-06-15 16:08 . 2001-08-31 12:00 15360 -c--a-w- c:\windows\system32\dllcache\iisreset.exe
2010-06-15 16:08 . 2003-04-14 19:04 217088 -c--a-w- c:\windows\system32\dllcache\fpmmcsat.dll
2010-06-15 16:04 . 2001-08-31 12:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2010-06-15 15:59 . 2001-08-31 12:00 7168 -c--a-w- c:\windows\system32\dllcache\wamregps.dll
2010-06-15 15:59 . 2001-08-31 12:00 7168 ----a-w- c:\windows\system32\wamregps.dll
2010-06-15 15:59 . 2001-08-31 12:00 60928 -c--a-w- c:\windows\system32\dllcache\iisclex4.dll
2010-06-15 15:59 . 2001-08-31 12:00 3584 -c--a-w- c:\windows\system32\dllcache\iismui.dll
2010-06-15 15:59 . 2001-08-31 12:00 3584 ----a-w- c:\windows\system32\iismui.dll
2010-06-15 15:59 . 2001-08-31 12:00 19968 -c--a-w- c:\windows\system32\dllcache\inetsloc.dll
2010-06-15 15:59 . 2001-08-31 12:00 19968 ----a-w- c:\windows\system32\inetsloc.dll
2010-06-15 15:59 . 2001-08-31 12:00 171520 -c--a-w- c:\windows\system32\dllcache\iisui.dll
2010-06-15 15:59 . 2008-04-14 02:13 8192 ----a-w- c:\windows\system32\staxmem.dll
2010-06-15 15:58 . 2008-04-14 02:13 68608 ----a-w- c:\windows\system32\iisext.dll
2010-06-15 15:58 . 2008-04-14 02:13 65024 ----a-w- c:\windows\system32\iismap.dll
2010-06-15 15:58 . 2008-04-14 02:13 13312 ----a-w- c:\windows\system32\infoadmn.dll
2010-06-15 15:58 . 2008-04-14 02:13 290816 ----a-w- c:\windows\system32\adsiis.dll
2010-06-15 15:58 . 2008-04-14 02:13 133632 ----a-w- c:\windows\system32\iisrtl.dll
2010-06-15 15:58 . 2008-04-14 02:13 14336 ----a-w- c:\windows\system32\exstrace.dll
2010-06-15 15:58 . 2008-04-14 02:13 43520 ----a-w- c:\windows\system32\admwprox.dll
2010-06-15 15:57 . 2008-04-14 02:13 29696 ----a-w- c:\windows\system32\irmon.dll
2010-06-15 15:57 . 2008-04-14 02:14 152576 ----a-w- c:\windows\system32\irftp.exe
2010-06-15 15:57 . 2008-04-13 18:54 88192 ----a-w- c:\windows\system32\drivers\irda.sys
2010-06-15 15:57 . 2008-04-14 02:13 8192 ----a-w- c:\windows\system32\wshirda.dll
2010-06-15 15:51 . 2001-08-17 19:51 19584 ----a-w- c:\windows\system32\drivers\rasirda.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-10 07:26 . 2009-11-17 08:48 -------- d-----w- c:\programmi\CCleaner
2010-07-09 17:46 . 2007-11-07 21:20 1744 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-09 15:56 . 2010-07-09 15:56 388096 ----a-r- c:\documents and settings\VR\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-09 10:19 . 2009-09-08 12:26 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spyware Terminator
2010-07-07 07:06 . 2009-09-08 12:26 -------- d-----w- c:\documents and settings\VR\Dati applicazioni\Spyware Terminator
2010-07-07 07:06 . 2009-09-08 12:26 -------- d-----w- c:\programmi\Spyware Terminator
2010-07-05 14:34 . 2007-10-04 18:48 -------- d-----w- c:\programmi\Google
2010-07-05 13:09 . 2007-06-28 13:42 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-07-05 10:48 . 2008-11-16 00:21 -------- d-----w- c:\programmi\DivX
2010-07-03 09:02 . 2001-08-31 10:00 46072 ----a-w- c:\windows\system32\perfc010.dat
2010-07-03 09:02 . 2001-08-31 10:00 341524 ----a-w- c:\windows\system32\perfh010.dat
2010-06-22 14:34 . 2009-04-05 23:31 -------- d-----w- c:\programmi\Ahead
2010-06-22 06:58 . 2008-04-26 12:01 -------- d-----w- c:\programmi\Crawler
2010-06-18 17:03 . 2009-05-30 17:47 -------- d-----w- c:\documents and settings\VR\Dati applicazioni\U3
2010-06-16 20:17 . 2007-06-28 04:25 68712 ----a-w- c:\documents and settings\VR\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-06-15 19:15 . 2007-06-28 04:05 -------- d-----w- c:\programmi\Alwil Software
2010-06-15 16:00 . 2007-06-26 14:57 22980 ----a-w- c:\windows\system32\emptyregdb.dat
2010-06-10 12:18 . 2010-06-10 12:18 503808 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-693f8cb5-n\msvcp71.dll
2010-06-10 12:18 . 2010-06-10 12:18 499712 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-693f8cb5-n\jmc.dll
2010-06-10 12:18 . 2010-06-10 12:18 348160 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-693f8cb5-n\msvcr71.dll
2010-06-10 12:18 . 2010-06-10 12:18 12800 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2b6656f3-n\decora-d3d.dll
2010-06-10 12:18 . 2010-06-10 12:18 61440 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2b6656f3-n\decora-sse.dll
2010-05-06 10:32 . 2004-08-19 11:39 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:06 . 2004-08-19 11:31 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 17:11 . 2009-08-19 15:10 30878 ----a-w- c:\windows\nsreg.dat
2010-04-28 13:45 . 2010-04-28 13:45 73000 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-04-20 05:46 . 2004-08-19 11:37 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-13 09:40 . 2010-04-13 09:40 503808 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3654fe93-n\msvcp71.dll
2010-04-13 09:40 . 2010-04-13 09:40 499712 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3654fe93-n\jmc.dll
2010-04-13 09:40 . 2010-04-13 09:40 12800 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-2dee28aa-n\decora-d3d.dll
2010-04-13 09:40 . 2010-04-13 09:40 61440 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-2dee28aa-n\decora-sse.dll
2010-04-13 09:40 . 2010-04-13 09:40 348160 ----a-w- c:\documents and settings\VR\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3654fe93-n\msvcr71.dll
2010-04-12 15:29 . 2010-04-25 19:28 411368 ----a-w- c:\windows\system32\deployJava1.dll
2001-06-05 06:32 . 2001-06-05 06:32 23476 ---ha-w- c:\programmi\folder.htt
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CnxDslTaskBar"="c:\programmi\I-Storm USB ADSL Modem\CnxDslTb.exe" [2003-10-29 462848]
"SpywareTerminator"="c:\programmi\Spyware Terminator\SpywareTerminatorShield.exe" [2010-04-08 2176512]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\System32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Programmi\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\TWAIN_32\\Samsung\\ScanMgr.exe"=
"c:\\WINDOWS\\TWAIN_32\\Samsung\\CLX3170\\Scan2Pc.exe"=
"c:\\WINDOWS\\TWAIN_32\\Samsung\\CLX3170\\Sscan2io.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1542:TCP"= 1542:TCP:Realtek WPS TCP Prot
"1542:UDP"= 1542:UDP:Realtek WPS UDP Prot
"53:UDP"= 53:UDP:Realtek AP UDP Prot
R1 aswSP;aswSP;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [29/06/2010 22.20.39 165456]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\SYSTEM32\DRIVERS\sp_rsdrv2.sys [08/09/2009 14.26.53 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [29/06/2010 22.20.39 17744]
R3 trid3d;trid3d;c:\windows\SYSTEM32\DRIVERS\trid3dm.sys [28/06/2007 16.24.48 222336]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 av100s2k;av100s2k;c:\windows\SYSTEM32\DRIVERS\av100s2k.sys [23/01/2009 17.08.13 10496]
S3 av100u2k;av100u2k;c:\windows\SYSTEM32\DRIVERS\av100u2k.sys [23/01/2009 17.08.13 11392]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\SYSTEM32\DRIVERS\camdrv21.sys [15/11/2007 23.01.05 223232]
S3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;c:\windows\SYSTEM32\DRIVERS\CnxEtP.sys [13/08/2009 23.36.18 60288]
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\SYSTEM32\DRIVERS\CnxEtU.sys [13/08/2009 23.31.31 646784]
S3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;c:\windows\SYSTEM32\DRIVERS\CnxTgN.sys [13/08/2009 23.36.18 108675]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys --> c:\windows\system32\DRIVERS\RTL8192su.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
2010-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-06-21 12:49]
2010-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-06-21 12:49]
2010-07-10 c:\windows\Tasks\User_Feed_Synchronization-{CD8C8E0D-2B32-4BB4-9AF3-506F183C97AC}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://google.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.avast.com/go.php?verb=register-home&lang=ita
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Crawler Search - tbr:iemenu
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: SmarThru4 Acquisisci selezione - c:\programmi\SmarThru 4\WebCapture.dll2.htm
IE: SmarThru4 Capture Selection - c:\programmi\SmarThru 4\WebCapture.dll2.htm
IE: SmarThru4 Salva come HTML - c:\programmi\SmarThru 4\WebCapture.dll1.htm
IE: SmarThru4 Salva testo selezionato - c:\programmi\SmarThru 4\WebCapture.dll.htm
IE: SmarThru4 Save as HTML - c:\programmi\SmarThru 4\WebCapture.dll1.htm
IE: SmarThru4 Save Selected Text - c:\programmi\SmarThru 4\WebCapture.dll.htm
IE: SmarThru4 Web Capture - c:\programmi\SmarThru 4\WebCapture.dll
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\programmi\Crawler\ctbr.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-10 10:48
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2916)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Alwil Software\Avast5\AvastSvc.exe
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Spyware Terminator\sp_rsser.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2010-07-10 11:04:27 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-07-10 09:04
Pre-Run: 28.134.157.824 byte disponibili
Post-Run: 27.994.878.976 byte disponibili
- - End Of File - - 21D0EFA824834D8E9397ED90E48A75DF