Eccolo:
ComboFix 10-12-08.04 - Giuseppe 09/12/2010 19.48.12.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.2047.1510 [GMT 1:00]
Eseguito da: c:\documents and settings\Giuseppe\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {0012F2B4-5CE9-7C92-0300-000000000000}
FW: Outpost Firewall *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\install.exe
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Legacy_WCSCD
-------\Service_cdfss
((((((((((((((((((((((((( Files Creati Da 2010-11-09 al 2010-12-09 )))))))))))))))))))))))))))))))))))
.
2010-12-09 18:13 . 2009-04-06 10:37 704384 ----a-w- c:\windows\system32\drivers\SandBox.sys
2010-12-09 18:13 . 2009-02-10 15:15 257432 ----a-w- c:\windows\system32\drivers\afwcore.sys
2010-12-09 18:11 . 2009-02-18 16:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys
2010-12-09 18:11 . 2010-12-09 18:11 -------- d-----w- c:\programmi\Agnitum
2010-12-09 18:11 . 2010-12-09 18:11 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Agnitum
2010-12-09 17:42 . 2010-12-09 17:45 -------- d-----w- c:\programmi\SpywareBlaster
2010-12-07 11:42 . 2010-12-07 11:42 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\Avira
2010-12-07 11:38 . 2010-09-01 13:22 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-07 11:38 . 2010-09-01 13:22 126856 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-12-07 11:38 . 2010-06-17 14:28 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-12-07 11:38 . 2010-06-17 14:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-12-07 11:38 . 2010-12-07 11:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-12-07 11:38 . 2010-12-07 11:38 -------- d-----w- c:\programmi\Avira
2010-12-07 01:44 . 2010-12-07 01:44 -------- d-----r- c:\documents and settings\LocalService\Preferiti
2010-12-07 01:21 . 2010-12-09 16:47 -------- d-----w- c:\windows\system32\NtmsData
2010-12-02 16:36 . 2008-04-13 19:40 62976 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2010-12-02 16:36 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-12-01 18:46 . 2010-12-01 18:46 -------- d-sh--w- c:\documents and settings\Giuseppe\IECompatCache
2010-12-01 18:44 . 2010-12-01 18:44 -------- d-sh--w- c:\documents and settings\Giuseppe\PrivacIE
2010-12-01 18:43 . 2010-12-01 18:43 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-12-01 18:42 . 2010-12-01 18:42 -------- d-sh--w- c:\documents and settings\Giuseppe\IETldCache
2010-12-01 18:38 . 2010-12-01 18:39 -------- dc-h--w- c:\windows\ie8
2010-12-01 18:36 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-12-01 18:35 . 2010-09-10 05:49 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-12-01 18:35 . 2010-09-10 05:49 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-12-01 18:35 . 2010-09-10 05:49 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-01 18:35 . 2010-09-10 05:49 1986560 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-12-01 18:35 . 2010-09-10 05:49 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-01 18:35 . 2010-09-10 05:49 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-01 18:35 . 2010-09-10 05:49 11080192 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-11-26 17:45 . 2010-11-26 17:45 388096 ----a-r- c:\documents and settings\Giuseppe\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-26 17:45 . 2010-11-26 17:45 -------- d-----w- c:\programmi\Trend Micro
2010-11-26 16:38 . 2010-11-26 16:38 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\Danea
2010-11-26 16:06 . 2010-11-26 16:07 -------- d-----w- c:\programmi\Panda Security
2010-11-26 13:21 . 2010-11-26 13:21 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\Malwarebytes
2010-11-26 13:21 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-26 13:21 . 2010-12-01 00:58 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-11-26 13:21 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-26 13:21 . 2010-11-26 13:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-11-25 16:55 . 2010-12-02 15:30 -------- d-----w- c:\programmi\ClamWin
2010-11-25 14:54 . 2010-12-07 01:04 -------- d-----w- c:\documents and settings\Administrator
2010-11-25 11:24 . 2010-11-25 11:24 -------- d-----w- c:\programmi\Sophos
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-09 19:08 . 2010-02-06 19:43 60416 ----a-w- c:\windows\ALCFDRTM.VER
2010-09-18 10:23 . 2004-08-19 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-19 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-08-19 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-08-19 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 73728]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"D-Link AirPlus XtremeG Utility"="c:\programmi\Wireless USB adapter Alice G-132\AirPlusCFG.exe" [2006-11-20 1728512]
"ANIWZCS2Service"="c:\programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2006-06-29 49152]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-03-17 421888]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2010-09-01 281768]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-27 561213]
[HKLM\~\startupfolder\C:^Documents and Settings^Giuseppe^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.1.lnk]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Creative Detector"=c:\programmi\Creative\MediaSource\Detector\CTDetect.exe /R
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe"
"Lexmark 2200 Series"="c:\programmi\Lexmark 2200 Series\lxbvbmgr.exe"
"DNS7reminder"="c:\programmi\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "c:\documents and settings\All Users\Dati applicazioni\Nuance\NaturallySpeaking10\Ereg.ini
"FaxCenterServer"="c:\programmi\Lexmark Fax Solutions\fm3032.exe" /s
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"ISUSPM Startup"=c:\progra~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
"AlcWzrd"=ALCWZRD.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\Giuseppe\\temp\\TeamViewer3\\TeamViewer.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [07/11/2009 9.59.04 24971]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23/10/2009 10.02.12 716272]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [09/12/2010 19.13.28 704384]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [09/12/2010 19.11.49 1195008]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [09/12/2010 19.11.52 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [09/12/2010 19.13.17 257432]
S2 gupdate1ca94a3a6b02fe8;Servizio di Google Update (gupdate1ca94a3a6b02fe8); [x]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [21/09/2006 10.19.04 347648]
S3 maconfservice;Ma-Config Service;c:\programmi\ma-config.com\maconfservice.exe [17/12/2009 19.00.28 243056]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\7.tmp --> c:\windows\system32\7.tmp [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contenuto della cartella 'Scheduled Tasks'
2010-12-09 c:\windows\Tasks\User_Feed_Synchronization-{2F4D0430-51A6-4DD0-9729-EE368A304078}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-12-09 19:53
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet015\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7.tmp"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1343024091-838170752-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A8FFB7C4-1DAD-3080-15A4-3B05588F2068}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oalimdonnkhfjokbiiddbngleoaagl"=hex:6b,61,61,6f,6f,6f,62,6c,67,6c,67,62,68,6a,
6c,69,65,70,6b,62,66,6b,00,00
"nafhciadmapbklmldmfllkpiicln"=hex:6b,61,61,6f,6f,6f,62,6c,67,6c,67,62,68,6a,
6c,69,65,70,6b,62,66,6b,00,00
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2440)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\CTsvcCDA.EXE
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\Avira\AntiVir Desktop\avshadow.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2010-12-09 19:56:33 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-12-09 18:56
Pre-Run: 194.730.422.272 byte disponibili
Post-Run: 194.657.722.368 byte disponibili
Current=15 Default=15 Failed=14 LastKnownGood=16 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16
- - End Of File - - 8F46BCBEAEA33E15E7F3E915A4328637
Ciao.