rieccomi
da modalità normale si è spento di nuovo così ho potuto farla solo da mod provv
ComboFix 11-06-30.02 - kikko 30/06/2011 18.12.18.2.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.502.234 [GMT 2:00]
Eseguito da: d:\documents and settings\kikko\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-14EF-9D7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-3C24-9E7C08000A00}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((( Files Creati Da 2011-05-28 al 2011-06-30 )))))))))))))))))))))))))))))))))))
.
.
2011-06-22 07:26 . 2011-06-22 07:26 -------- d-----w- d:\documents and settings\kikko\Dati applicazioni\Malwarebytes
2011-06-22 07:26 . 2011-05-29 07:11 39984 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2011-06-22 07:26 . 2011-06-22 07:26 -------- d-----w- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes
2011-06-22 07:26 . 2011-05-29 07:11 22712 ----a-w- d:\windows\system32\drivers\mbam.sys
2011-06-22 07:26 . 2011-06-22 11:01 -------- d-----w- d:\programmi\Malwarebytes' Anti-Malware
2011-06-17 10:34 . 2011-06-17 10:34 388096 ----a-r- d:\documents and settings\kikko\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-06-17 10:34 . 2011-06-17 10:34 -------- d-----w- d:\programmi\Trend Micro
2011-06-16 06:46 . 2011-04-21 13:37 105472 -c----w- d:\windows\system32\dllcache\mup.sys
2011-06-14 08:05 . 2011-06-14 08:05 -------- d-----w- d:\documents and settings\kikko\Impostazioni locali\Dati applicazioni\Help
2011-06-14 08:01 . 2011-06-14 08:01 -------- d-----w- d:\documents and settings\kikko\Impostazioni locali\Dati applicazioni\Ilivid Player
2011-06-14 07:58 . 2011-06-14 07:58 -------- d-----w- d:\documents and settings\kikko\Impostazioni locali\Dati applicazioni\PackageAware
2011-06-14 07:37 . 2011-06-19 10:11 -------- d-----w- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SecTaskMan
2011-06-14 07:37 . 2011-06-14 08:05 -------- d-----w- d:\programmi\Security Task Manager
2011-06-14 07:30 . 2011-06-14 12:03 -------- d-----w- d:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Adobe
2011-06-09 17:41 . 2011-06-09 17:41 -------- d-----w- d:\programmi\microsoft frontpage
2011-06-09 10:46 . 2011-06-09 14:32 -------- d-----w- d:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-02 15:31 . 2010-03-26 08:45 692736 ----a-w- d:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2004-08-19 12:00 151552 ----a-w- d:\windows\system32\schannel.dll
2011-04-29 16:19 . 2004-08-19 12:00 456320 ----a-w- d:\windows\system32\drivers\mrxsmb.sys
2011-04-25 15:45 . 2004-08-19 12:00 832512 ----a-w- d:\windows\system32\wininet.dll
2011-04-25 15:45 . 2004-08-19 12:00 1830912 ------w- d:\windows\system32\inetcpl.cpl
2011-04-25 15:45 . 2004-08-19 12:00 78336 ----a-w- d:\windows\system32\ieencode.dll
2011-04-25 15:45 . 2004-08-19 12:00 17408 ------w- d:\windows\system32\corpol.dll
2011-04-25 12:01 . 2004-08-19 12:00 389120 ----a-w- d:\windows\system32\html.iec
2011-04-21 13:37 . 2004-08-19 12:00 105472 ----a-w- d:\windows\system32\drivers\mup.sys
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"acerWireless"="d:\programmi\acer\Wireless\Utility\WlanUtil.exe" [2004-06-09 417792]
"avgnt"="d:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="d:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="d:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="d:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"HP Software Update"="d:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
d:\documents and settings\kikko\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.2.lnk - d:\programmi\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
.
d:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - d:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Programmi\\eMule\\eMule.exe"=
"d:\\Programmi\\Messenger\\msmsgs.exe"=
"d:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"d:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"d:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"d:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"d:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
.
S0 Lbd;Lbd;d:\windows\system32\DRIVERS\Lbd.sys --> d:\windows\system32\DRIVERS\Lbd.sys [?]
S2 Network WanMiniport First Position;Network WanMiniport First Position;d:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [12/04/2011 12.06.25 8192]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\d:\programmi\Lavasoft\Ad-Aware\KernExplorer.sys --> d:\programmi\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 RTL8187B;Wireless Network USB Adapter 54g WL-168v1.004;d:\windows\system32\drivers\RTL8187B.sys [26/03/2010 13.20.02 264576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: Google Sidewiki... - d:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKCU-Run-msnmsgr - d:\programmi\Windows Live\Messenger\msnmsgr.exe
HKLM-Run-hpqSRMon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-06-30 18:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(1864)
d:\windows\system32\WININET.dll
.
Ora fine scansione: 2011-06-30 18:19:49
ComboFix-quarantined-files.txt 2011-06-30 16:19
.
Pre-Run: 17.842.327.552 byte disponibili
Post-Run: 19.342.196.736 byte disponibili
.
- - End Of File - - 1E5BF0E2791D6CC6F4E25097D499A221