Eccolo qui , comunque il pc risponde più prontamente ;)
ComboFix 09-02-21.01 - ALFIO 2009-02-23 13:45:54.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.447.181 [GMT 1:00]
Eseguito da: d:\documents and settings\ALFIO.PACKARDBELL\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
.
((((((((((((((((((((((((( Files Creati Da 2009-01-23 al 2009-02-23 )))))))))))))))))))))))))))))))))))
.
2009-02-22 10:23 . 2009-02-22 10:23 94 --a------ c:\windows\wininit.ini
2009-02-22 08:58 . 2009-02-22 08:58 <DIR> d-------- d:\documents and settings\ALFIO.PACKARDBELL\Dati applicazioni\Malwarebytes
2009-02-22 08:57 . 2009-02-22 08:57 <DIR> d-------- d:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-02-22 08:57 . 2009-02-22 08:58 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-02-22 08:57 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-22 08:57 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-03 19:03 . 2009-02-03 19:03 <DIR> d-------- d:\documents and settings\LocalService.NT AUTHORITY.000\Dati applicazioni\Symantec
2009-02-01 12:43 . 2009-02-01 12:43 <DIR> d-------- C:\EPSON
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-22 20:53 --------- d-----w c:\programmi\File comuni\Symantec Shared
2009-02-22 10:01 --------- d-----w d:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-02-21 15:37 --------- d-----w c:\programmi\EPSON
2009-02-16 22:36 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-13 17:08 --------- d-----w c:\programmi\Norton Internet Security
2009-02-01 23:50 --------- d-----w d:\documents and settings\ALFIO.PACKARDBELL\Dati applicazioni\gtk-2.0
2009-01-31 23:09 --------- d-----w c:\programmi\Room Arranger
2009-01-16 20:15 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-01-11 21:57 --------- d-----w c:\programmi\Microsoft Silverlight
2009-01-09 20:55 --------- d-----w d:\documents and settings\ALFIO.PACKARDBELL\Dati applicazioni\Inkscape
2009-01-09 20:55 --------- d-----w c:\programmi\Inkscape
2009-01-05 19:27 1,012 ----a-w d:\documents and settings\ALFIO.PACKARDBELL\Dati applicazioni\wklnhst.dat
2008-12-29 10:04 --------- d-----w c:\programmi\CCleaner
2008-12-27 01:47 --------- d-----w d:\documents and settings\ALFIO.PACKARDBELL\Dati applicazioni\Skype
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
2008-12-20 22:31 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
2008-12-20 22:31 477,696 ----a-w c:\windows\system32\dllcache\mshtmled.dll
2008-12-20 22:31 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
2008-12-20 22:31 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
2008-12-20 22:31 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
2008-12-20 22:31 105,984 ------w c:\windows\system32\dllcache\url.dll
2008-12-20 22:31 102,912 ------w c:\windows\system32\dllcache\occache.dll
2008-12-20 22:31 1,160,192 ----a-w c:\windows\system32\dllcache\urlmon.dll
2008-12-19 09:12 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2008-08-05 19:05 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008080520080806\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LogitechSoftwareUpdate"="c:\programmi\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"ccApp"="c:\programmi\File comuni\Symantec Shared\ccApp.exe" [2008-01-31 58728]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2007-04-05 100056]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2006-12-14 98304]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2006-12-14 180269]
"PCMService"="c:\apps\Powercinema\PCMService.exe" [2005-05-11 127118]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="c:\programmi\Logitech\Video\ISStart.exe" [2004-10-08 458752]
"LogitechVideoTray"="c:\programmi\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
"VTTimer"="VTTimer.exe" [2005-12-05 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-12-05 c:\windows\system32\VTTrayp.exe]
"GSICONEXE"="GSICON.EXE" [2001-07-20 c:\windows\system32\gsicon.exe]
"SoundMan"="soundman.exe" [2001-05-29 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\FILECO~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= c:\progra~1\FILECO~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= c:\progra~1\FILECO~1\ULEADS~1\MPEG\mpegacm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;c:\programmi\Symantec\LiveUpdate\AluSchedulerSvc.exe [2006-12-15 100032]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S2 gafwload;Modem ADSL B-QUICK Loader;c:\windows\system32\drivers\gafwload.sys [2006-12-15 26859]
S3 SPC610NC;Philips SPC500NC Webcam;c:\windows\system32\DRIVERS\SPC610NC.SYS --> c:\windows\system32\DRIVERS\SPC610NC.SYS [?]
.
Contenuto della cartella 'Scheduled Tasks'
2009-02-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-02-23 c:\windows\Tasks\User_Feed_Synchronization-{2F4B2195-B3FC-4C81-90E8-D57D19D81D00}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.vivezheureux.com/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: carrefour.it\www
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - d:\documents and settings\ALFIO.PACKARDBELL\Dati applicazioni\Mozilla\Firefox\Profiles\enqxq7zl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.photos-animaux.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=it-IT&FORM=MICI05&q=
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\programmi\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\programmi\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\programmi\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\programmi\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\programmi\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\programmi\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\programmi\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\NPBILLARD8.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\NPBREAKOUT.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-23 13:47:29
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-282838324-3807862201-1112299103-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{896E86C7-1FDD-A097-9891-BE1014E288D9}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oaocmfollkdikdnainidiebcekmjfh"=hex:61,69,61,6f,62,68,6a,6c,6e,61,64,64,67,68,
6b,62,6b,68,63,62,65,6b,66,67,70,62,68,67,6c,64,66,6e,6a,70,67,69,66,66,68,\
"ialdocflnhamiknack"=hex:6b,61,6d,6f,69,61,69,64,65,6f,6d,68,6d,65,64,65,67,63,
66,68,6d,66,00,7e
"hafdmfollgnpfcdi"=hex:6a,61,67,6f,64,6b,66,62,64,65,61,6b,6a,66,6a,70,61,6b,
6f,69,00,00
.
Ora fine scansione: 2009-02-23 13:49:18
ComboFix-quarantined-files.txt 2009-02-23 12:49:15
Pre-Run: 20,057,759,744 byte disponibili
Post-Run: 20,045,697,024 byte disponibili
155 --- E O F --- 2009-02-19 17:42:57