aiuto!! dopo la scansione di combofix il pc ha deciso che explorer doveva essere il mio browser. Provo ad aprire mozilla, ma al suo posto apre explorer
ComboFix 10-06-03.01 - Administrator 05/06/2010 22.10.51.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1022.686 [GMT 2:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix1.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\SHELLLNK.TLB
.
((((((((((((((((((((((((( Files Creati Da 2010-05-05 al 2010-06-05 )))))))))))))))))))))))))))))))))))
.
2010-06-05 20:00 . 2010-06-05 20:00 -------- d-----w- c:\programmi\File comuni\Java
2010-06-05 20:00 . 2010-06-05 20:00 503808 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1c59315c-n\msvcp71.dll
2010-06-05 20:00 . 2010-06-05 20:00 499712 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1c59315c-n\jmc.dll
2010-06-05 20:00 . 2010-06-05 20:00 348160 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1c59315c-n\msvcr71.dll
2010-06-05 20:00 . 2010-06-05 20:00 61440 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-35b845ed-n\decora-sse.dll
2010-06-05 20:00 . 2010-06-05 20:00 12800 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-35b845ed-n\decora-d3d.dll
2010-06-05 20:00 . 2010-04-12 15:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-05 19:52 . 2010-06-05 19:52 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2010-06-05 19:52 . 2010-06-05 19:52 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-06-05 19:35 . 2010-06-05 19:35 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2010-06-05 19:35 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-05 19:35 . 2010-06-05 19:36 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-06-05 19:35 . 2010-06-05 19:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-06-05 19:35 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-05 18:42 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-06-05 18:31 . 2010-06-05 18:31 503808 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Sun\Java\Deployment\cache\6.0\46\f84c6ae-6a28f2af-n\msvcp71.dll
2010-06-05 18:31 . 2010-06-05 18:31 499712 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Sun\Java\Deployment\cache\6.0\46\f84c6ae-6a28f2af-n\jmc.dll
2010-06-05 18:31 . 2010-06-05 18:31 348160 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Sun\Java\Deployment\cache\6.0\46\f84c6ae-6a28f2af-n\msvcr71.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-05 20:11 . 2001-08-31 15:00 64576 ----a-w- c:\windows\system32\perfc010.dat
2010-06-05 20:11 . 2001-08-31 15:00 428898 ----a-w- c:\windows\system32\perfh010.dat
2010-06-05 20:00 . 2007-09-30 23:01 19776 -c--a-w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-06-05 20:00 . 2008-01-14 16:33 -------- d-----w- c:\programmi\Java
2010-06-05 19:36 . 2007-10-01 00:09 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\uTorrent
2010-06-05 17:55 . 2007-10-01 02:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Messenger Plus!
2010-06-05 17:54 . 2007-10-01 02:37 -------- d-----w- c:\programmi\Messenger Plus! Live
2010-03-10 06:15 . 2004-08-19 16:39 420352 ----a-w- c:\windows\system32\vbscript.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"Iconoid"="c:\programmi\Iconoid\iconoid.exe" [2005-12-03 180736]
"RocketDock"="c:\programmi\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\programmi\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"IntelZeroConfig"="c:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2005-11-28 667718]
"IntelWireless"="c:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"EOUApp"="c:\programmi\Intel\Wireless\Bin\EOUWiz.exe" [2005-11-28 569413]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2005-01-08 102491]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-01-08 692315]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2006-03-30 471040]
"SpywareGuard"="c:\\Programmi\\SpywareGuard\\sgmain.exe" [2003-08-29 360448]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\utorrent.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [01/10/2007 3.34.19 5504]
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [01/10/2007 1.10.31 1088896]
S0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [01/10/2007 3.34.19 140800]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {EDA04982-A1E8-48DC-BD82-B59040DA612C} = 212.216.112.222,212.216.172.162
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\ogbt9zrl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programmi\QuickTime Alternative\Plugins\npqtplugin.dll
FF - plugin: c:\programmi\QuickTime Alternative\Plugins\npqtplugin2.dll
FF - plugin: c:\programmi\QuickTime Alternative\Plugins\npqtplugin3.dll
FF - plugin: c:\programmi\QuickTime Alternative\Plugins\npqtplugin4.dll
FF - plugin: c:\programmi\QuickTime Alternative\Plugins\npqtplugin5.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-05 22:13
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,bd,96,e9,51,d9,f0,86,44,af,4c,fa,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,bd,96,e9,51,d9,f0,86,44,af,4c,fa,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="E5EE5FB8082A633FB28F9EE551B589E70302E74BF85D4DB0103035C7842BB7923AA27D4F0A8B713898C35E7708C56F7222F94CD5CD34347DD992612BFBD89C9614752F5E073F3EDB48B2244FDAA8D68874D6836A7C114BF00F976D9BCA7A345D0947F4864613FDACDFA0C1996AA21647C2624FE11D4CAA64C1ADAB3EA39B782092CAD1D830E8AA5EE1A88DF3F98BC500B63877876BD2ABE5E419742D5B5DA3480E88CEDAD23800D935B461F16F4CC538E1CCC59CC8A3EDB9526F227469F5B7773DDCF986FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452C038D530D6EB3452FEBC9E127BECC74C0A8AF4BFA4C260ABF506E16E69DDC6969EA10B6AD79508A73BEB06210CE4E21BAB9B4500FC398AE8EA1D6780C32F75BE9B751290EB98CDD1A470E34759D35F7457A5F06B35F8A08AAFC052C1744DCDBF9AAA46B66C9009155176D9D26D0E9441449F2C7AFC901757159EB989168C734A2445BFB279373031A474A23313D3EB6BCC1772DCE9E1E30810F6FAE424148E05E45A5C0C9B193B592575BB907A344E5573AC857473A4054AB921B59281DF4D0A31943C7F3B18A9B47E9968C2B6962C51DA93E4D8F5E3F83E4E84CD05F23F5E677D32C5FD2967FA5E7F93ADD7BEB47629CA14D9D1B27E4278AF9F6BE52156F720640622AB9691B6E31AAB5612EE1C24972F8BEFE04EA5EA82E2027A0F1B1D51282374BDE09971664B673CEFE5072DB14C98E8F5384FE27C5A8F532B10D05FA8EA9B79C92A2D3896089FB34D7E289F1BEB3A31FDBCA48E87EF03CA73AC983D3D46D323BBC8AE6C5987A29705365C7C640FEBFC5F0A9BD79FA82F38095DABA9558B7614CCB0E165452874FC70A10D2294C02BF7B66FEBC25CDDA7F9E8CCA66CB8025102790B6CCFF13C3A90AD058BC1368115E2E1EC2BA5D9DBA606D35B0CA13362D43783B3582C008C40909E5A896157C56F91843B58A937E30767CD9B4039175C97916FBA15D08D5275D1EACE9ED90A74A2EC8545D14F97AB4C391ED40EF6378FD48308E47464433DEAB97AC347D9666BB8701027DBE9A45B992FD103A1F1ED146894592CADE549EFD9C57DCF626386F7632C93B5219D0710B80C38D50C9796F356DDB3BB59244D031C03653BB2CB09E074C5C2F52CE7F1DA95AAE631C4A5132B430D2E73F745810030156804E0BC90DBE6F41524ED1716C142F634ABA231C7AD78669FE9E9C11CE6B93580DAF6B443975405C62D3A4C2C3C7274BD91E4A01CE0653EA7667766D4A97F2CEA276584CCB1FB57D4B3CA7FEF3900B56362AC327E9F1B0025E4C8D36BAFEBDBAB01FED25A3F44DF048E3A7B2118E666C8D0FDF3DD364FA9BE97EE7E20D30EB48737FA98A04833275A498B5F03AE494255C4"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(792)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2010-06-05 22:14:09
ComboFix-quarantined-files.txt 2010-06-05 20:14
Pre-Run: 3.632.754.688 byte disponibili
Post-Run: 3.698.827.264 byte disponibili
- - End Of File - - AE5C9D20368660CB071DF83D44E576E7