Che stress!!!
Mentre Combo lavorava lo schermo del pc si è spento, ho atteso, poi è andato in sospensione tutto il pc e si è riavviato, così si è riattivato outpost e Avira.... allora ho ricominciato tutto da capo dopo aver tolto il risparmio energetico, speriamo di aver fatto tutto a dovere, io che poi con l'inglese sono una schiappa.... mi sa che ho eliminato anche outpost non lo trovo più... ora lo vado nuovamente ad installare!
ComboFix 11-01-06.06 - Simonetta 07/01/2011 23.25.31.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1012.494 [GMT 1:00]
Eseguito da: c:\documents and settings\Simonetta\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {0013F2B4-5CE9-7C92-0300-000100000000}
AV: AntiVir Desktop *Disabled/Updated* {0012F2B4-5CE9-7C92-0300-000100000000}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
FW: Outpost Firewall *Enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\documents and settings\Simonetta\Dati applicazioni\inst.exe
c:\windows\system32\system
.
((((((((((((((((((((((((( Files Creati Da 2010-12-07 al 2011-01-07 )))))))))))))))))))))))))))))))))))
.
2011-01-07 14:50 . 2011-01-07 14:50 -------- d-----w- c:\documents and settings\Simonetta\Dati applicazioni\Avira
2011-01-07 14:47 . 2011-01-07 14:56 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-01-07 14:47 . 2011-01-07 14:56 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-01-07 14:47 . 2010-06-17 14:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2011-01-07 14:47 . 2010-06-17 14:28 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2011-01-07 14:47 . 2011-01-07 14:47 -------- d-----w- c:\programmi\Avira
2011-01-07 14:47 . 2011-01-07 14:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2011-01-07 13:40 . 2011-01-07 13:40 -------- d-----w- c:\programmi\SpywareBlaster
2011-01-05 23:16 . 2011-01-05 23:16 -------- d-----r- c:\documents and settings\LocalService\Preferiti
2011-01-05 23:15 . 2011-01-05 23:15 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-01-05 22:22 . 2011-01-07 10:36 -------- d-----w- c:\windows\system32\NtmsData
2010-12-12 20:38 . 2010-12-12 20:38 -------- d-----w- c:\documents and settings\Simonetta\Dati applicazioni\AVG10
2010-12-12 20:32 . 2010-12-12 20:32 -------- d--h--w- c:\documents and settings\All Users\Dati applicazioni\Common Files
2010-12-12 20:29 . 2011-01-05 21:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AVG10
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 16:42 . 2010-03-09 08:27 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 16:42 . 2010-03-09 08:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-18 18:12 . 2009-02-27 19:34 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-06 00:21 . 2009-02-28 04:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:21 . 2009-02-28 04:19 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2009-02-28 04:19 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2009-02-28 04:19 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2009-02-28 04:19 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-29 18:51 . 2010-10-29 18:51 45200 ------w- c:\windows\system32\drivers\PxHelp20.sys
2010-10-29 18:51 . 2010-10-29 18:51 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-10-29 18:51 . 2010-10-29 18:51 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-10-29 18:50 . 2010-10-29 18:51 59888 ------w- c:\windows\system32\pxwma.dll
2010-10-28 13:13 . 2009-02-28 04:19 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 14:05 . 2009-02-28 04:20 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-05-31 07:47 . 2010-05-28 12:54 10933953 ----a-w- c:\programmi\K-Lite_Codec_Pack_600_Standard.exe
2009-12-26 15:32 . 2009-12-26 15:31 4105936 ----a-w- c:\programmi\FileZilla_3.3.0.1_win32-setup.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mobile Partner"="c:\programmi\3 Internet\3 Internet.exe" [2009-07-27 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"RTHDCPL"="RTHDCPL.EXE" [2009-01-13 18084864]
"AzMixerSel"="c:\programmi\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-17 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"LManager"="c:\programmi\Launch Manager\LManager.exe" [2009-02-20 817672]
"PLFSetL"="c:\windows\PLFSetL.exe" [2008-07-03 94208]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2010-03-21 202256]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2010-09-01 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Simonetta\Menu Avvio\Programmi\Esecuzione automatica\
PandaUSBVaccine.lnk - f:\panda usb vaccine\USBVaccine.exe [N/A]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Acer\\Acer VCM\\VC.exe"=
"c:\\Programmi\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [06/12/2009 13.23.33 704384]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [06/12/2009 13.21.35 1195008]
R2 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool;c:\programmi\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [30/09/2010 14.39.10 196912]
R2 RS_Service;Raw Socket Service;c:\programmi\Acer\Acer VCM\RS_Service.exe [27/02/2009 22.01.25 237568]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [06/12/2009 13.21.46 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [06/12/2009 13.23.22 257432]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [27/02/2009 21.29.35 162816]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
2011-01-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-01 09:59]
2011-01-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-01 09:59]
2011-01-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-212580986-801667920-1073472683-1005.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2011-01-07 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-212580986-801667920-1073472683-1005.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: Add to Local Website Archive - c:\documents and settings\Simonetta\Dati applicazioni\aignes\Local Website Archive\config\iearc.htm
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Invia a Bluetooth - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Save Flash - c:\programmi\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
IE: Save YouTube Video - c:\programmi\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/217
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-HijackThis - f:\nuova cartella\HijackThis.exe
AddRemove-{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1 - f:\panda usb vaccine\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-07 23:32
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(1276)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2011-01-07 23:35:58
ComboFix-quarantined-files.txt 2011-01-07 22:35
Pre-Run: 59.202.682.880 byte disponibili
Post-Run: 59.159.498.752 byte disponibili
- - End Of File - - 88D25E3A9EBC9D89CE56511DF347B738