LOGO COMBOFIX
1)
questo intanto è il risultato dello scan con combofix . bah..io non ci capisco niente..
2)
questa consolle di ripristino di emergenza..la devo poi installare??
3)
qui comincia con "altre eliminazioni"..ma quelle "altre" dove sono??
****
ComboFix 10-07-11.02 - Frankie 11/07/2010 21.20.08.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.255.127 [GMT 2:00]
Eseguito da: c:\programmi\Accessori\ComboFix.exe
FW: Sygate Personal Firewall *enabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\KAV
c:\programmi\KAV\KasperskyAV6.0.2.614\english\kav6.en.msi
c:\programmi\KAV\KasperskyAV6.0.2.614\english\release_notes_en.html
c:\programmi\KAV\KasperskyAV6.0.2.614\english\setup.exe
c:\programmi\KAV\kav6.0\english\doc\kav6.0en.pdf
c:\programmi\KAV\kav6.0\english\kav6.0.0.300en.msi
c:\programmi\KAV\kav6.0\english\release_notes.txt
c:\programmi\KAV\kis6.0\english\doc\kis6.0en.pdf
c:\programmi\KAV\kis6.0\english\kis6.en.msi
c:\programmi\KAV\kis6.0\english\release_notes_en.html
c:\programmi\KAV\kis6.0\english\setup.exe
c:\programmi\KAV\kis6.0\english\setup.reg
.
((((((((((((((((((((((((( Files Creati Da 2010-06-11 al 2010-07-11 )))))))))))))))))))))))))))))))))))
.
2010-07-11 15:36 . 2010-07-11 15:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Prevx
2010-07-11 14:38 . 2010-07-11 14:38 388096 ----a-r- c:\documents and settings\Frankie\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-11 14:38 . 2010-07-11 14:38 -------- d-----w- c:\programmi\Trend Micro
2010-07-11 10:15 . 2010-07-11 10:15 77312 ----a-w- C:\mbr.exe
2010-06-25 05:22 . 2010-06-25 05:22 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Apple
2010-06-18 17:15 . 2010-06-18 17:15 -------- d-----w- c:\windows\system32\shxfont
2010-06-18 17:15 . 2008-05-30 10:46 1712128 ----a-w- c:\windows\system32\gdiplus.dll
2010-06-18 17:15 . 2002-11-21 20:13 3907640 ----a-w- c:\windows\system32\gsdll32.dll
2010-06-18 17:15 . 2010-06-18 17:15 -------- d-----w- c:\windows\system32\PS
2010-06-17 20:34 . 2010-06-17 21:13 -------- d-----w- c:\documents and settings\Frankie\Dati applicazioni\Apple Computer
2010-06-17 20:34 . 2009-05-18 11:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-17 20:25 . 2001-08-30 21:07 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-06-17 20:25 . 2004-08-19 13:39 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-06-15 18:01 . 2010-06-15 18:01 72504 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-11 19:15 . 2008-05-08 11:00 -------- d-----r- c:\programmi\Accessori
2010-07-11 09:50 . 2008-05-08 14:26 45312 ----a-w- c:\windows\system32\drivers\VIRAGTLT.SYS
2010-06-24 07:22 . 2008-05-08 08:03 -------- d-----w- c:\documents and settings\Frankie\Dati applicazioni\Skype
2010-06-24 07:22 . 2008-05-08 08:03 -------- d-----w- c:\documents and settings\Frankie\Dati applicazioni\skypePM
2010-06-18 17:14 . 2008-05-08 07:30 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-06-17 20:43 . 2010-06-17 20:32 -------- d-----w- c:\programmi\iTunes
2010-06-17 20:33 . 2010-06-17 20:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-17 20:33 . 2010-06-17 20:33 -------- d-----w- c:\programmi\iPod
2010-06-17 20:32 . 2010-06-17 20:29 -------- d-----w- c:\programmi\File comuni\Apple
2010-06-17 20:32 . 2010-06-17 20:31 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2010-06-17 20:32 . 2008-05-08 08:32 -------- d-----w- c:\programmi\QuickTime
2010-06-17 20:30 . 2010-06-17 20:30 -------- d-----w- c:\programmi\Apple Software Update
2010-06-17 20:30 . 2010-06-17 20:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple
2010-05-26 10:47 . 2008-05-08 14:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-04-19 18:47 . 2010-06-17 20:30 3062048 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-04-19 18:47 . 2010-06-17 20:30 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2008-05-11 07:11 . 2008-05-08 08:24 17 ----a-w- c:\programmi\stinger.opt
2008-05-11 07:04 . 2008-05-11 07:04 499 ----a-w- c:\programmi\Collegamento a WinRAR.lnk
2008-05-08 10:34 . 2008-05-08 10:34 5831808 ----a-w- c:\programmi\Firefox Setup 2.0.0.14.exe
2008-05-04 09:44 . 2008-05-07 10:16 522 ----a-w- c:\programmi\hpfr3420.xml
2008-05-04 09:44 . 2008-05-07 10:16 177174 ----a-w- c:\programmi\hpfr3425.log
2008-03-05 19:31 . 2008-05-07 10:16 230432 ----a-w- c:\programmi\StiImg.dat
2007-04-04 09:52 . 2008-05-07 10:16 227 ----a-w- c:\programmi\gromozon_removal.log
2007-02-05 07:13 . 2008-05-08 08:24 1144839 ----a-w- c:\programmi\stinger.exe
2006-07-26 17:48 . 2008-05-08 08:24 10786 ----a-w- c:\programmi\release_notes.txt
2005-03-31 08:53 . 2008-05-08 08:24 30473 ----a-w- c:\programmi\Whitney_Houston_-_When_you_believeOK.kar
2005-03-29 09:53 . 2008-05-08 08:24 241 ----a-w- c:\programmi\stinger.txt
2005-02-23 13:27 . 2008-05-07 10:16 56320 ----a-w- c:\programmi\allegato.jhtml.doc
2005-02-12 09:18 . 2008-05-08 08:24 7683569 ----a-w- c:\programmi\nentitst.exe
2005-01-29 20:56 . 2008-05-08 08:24 8263 ----a-w- c:\programmi\Uninst.isu
2005-01-29 20:18 . 2008-05-08 08:24 293354 ----a-w- c:\programmi\PrvDiskLight.exe
2005-01-29 17:07 . 2008-05-07 10:16 36 ----a-w- c:\programmi\AUTOEXEC.SYD
2005-01-29 13:43 . 2008-05-08 08:24 1834514 ----a-w- c:\programmi\wp6setup.exe
2005-01-29 12:31 . 2008-05-08 08:24 9228440 ----a-w- c:\programmi\spf.exe
2004-05-02 21:28 . 2008-05-07 10:16 15 ----a-w- c:\programmi\win2.log
2004-05-01 10:48 . 2008-05-07 10:16 12 ----a-w- c:\programmi\win.log
2002-07-29 20:46 . 2008-05-07 10:16 4514 ----a-w- c:\programmi\SETUPXLG.TXT
2002-05-15 13:32 . 2008-05-08 08:24 747520 ----a-w- c:\programmi\WinRAR.exe
2001-01-31 11:15 . 2008-05-07 10:16 5071 ----a-w- c:\programmi\Documento recuperato.txt
2000-11-21 16:02 . 2008-05-07 10:16 70008 ----a-w- c:\programmi\BOOTLOG.TXT
2000-06-16 14:26 . 2008-05-08 08:24 208896 ----a-w- c:\programmi\mwatch.exe
2000-06-16 14:10 . 2008-05-08 08:24 32768 ----a-w- c:\programmi\mwhook.dll
2000-04-24 11:40 . 2008-05-07 10:16 225 ----a-w- c:\programmi\RESETLOG.TXT
2000-04-20 13:10 . 2008-05-07 10:16 15563 ----a-w- c:\programmi\NETLOG.TXT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"nwiz"="nwiz.exe" [2003-11-20 323584]
"AdslTaskBar"="stmctrl.dll" [2003-03-27 151552]
"VIRIT LITE MONITOR"="c:\vexplite\MONLITE.EXE" [2010-07-11 278528]
"SmcService"="c:\progra~1\ACCESS~1\smc.exe" [2004-10-15 2577632]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2010-06-15 141624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Acrobat Assistant.lnk - c:\programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2008-5-8 49254]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"Logitech Hardware Abstraction Layer"=KHALMNPR.EXE
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"dla"=c:\windows\system32\dla\tfswctrl.exe
"StorageGuard"="c:\programmi\File comuni\Sonic\Update Manager\sgtray.exe" /r
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Accessori\\eMule\\emule.exe"=
"c:\\Programmi\\Accessori\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Accessori\\Phone\\Skype.exe"=
R0 VIRAGTLT;VIRAGTLT;c:\windows\system32\drivers\VIRAGTLT.SYS [08/05/2008 16.26.02 45312]
R2 viritsvclite;Virit eXplorer Lite;c:\vexplite\VIRITSVC.EXE [10/10/2007 12.12.34 73728]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [08/05/2008 11.52.31 59466]
S3 PAC207;Trust WB-1200p Mini Webcam;c:\windows\system32\drivers\PFC027.sys [24/02/2005 12.29.14 162176]
S3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [08/05/2008 11.52.31 538925]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
TCP: {C65B8DF5-6887-4481-A261-4188E7404B32} = 151.99.125.2,151.99.125.3
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Frankie\Dati applicazioni\Mozilla\Firefox\Profiles\xklwm207.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: network.proxy.type - 0
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-Sonic RecordNow! - (no file)
AddRemove-HijackThis - c:\docume~1\Frankie\IMPOST~1\Temp\Rar$EX00.297\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-11 21:30
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Ora fine scansione: 2010-07-11 21:34:53
ComboFix-quarantined-files.txt 2010-07-11 19:34
ComboFix2.txt 2008-05-22 18:23
ComboFix3.txt 2008-05-18 21:01
ComboFix4.txt 2008-05-14 05:38
Pre-Run: 56.815.476.736 byte disponibili
Post-Run: 56.905.166.848 byte disponibili
- - End Of File - - 89BE85477B32CCB6BBA1EF0B89F2F0FE