ecco il risultato di combofix
grazie
ComboFix 09-10-24.01 - Paolo 25/10/09 8.20.23.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1022.536 [GMT 1:00]
Eseguito da: c:\documents and settings\Paolo\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 091024-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD0EC-FFA4-00EB-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD0EC-FFA4-00F3-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD2B8-FFA4-00EB-0D24-347CA8A3377C}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
ADS - explorer.exe: deleted 88 bytes in 2 streams. ((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Menu Avvio\HP Image Zone .lnk
c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\soiegoi.dat
c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\soiegoi_nav.dat
c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\soiegoi_navps.dat
.
((((((((((((((((((((((((( Files Creati Da 2009-09-25 al 2009-10-25 )))))))))))))))))))))))))))))))))))
.
2009-10-24 16:16 . 2009-10-24 16:16 -------- d-----w- c:\documents and settings\Paolo\Dati applicazioni\Malwarebytes
2009-10-24 16:16 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-24 16:16 . 2009-10-24 16:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-10-24 16:16 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-24 11:24 . 2009-10-24 11:24 -------- d-----w- c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\Innovative Solutions
2009-10-24 11:24 . 2009-10-24 11:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Innovative Solutions
2009-10-24 07:14 . 2009-10-24 07:14 -------- d-----w- c:\programmi\Trend Micro
2009-10-16 21:24 . 2009-10-16 21:24 -------- d-----w- c:\programmi\TIAB
2009-09-25 17:59 . 2004-08-17 00:40 16384 ----a-w- c:\windows\system32\FileOps.exe
2009-09-25 17:59 . 2009-09-25 17:59 -------- d-----w- c:\windows\system32\Adobe
2009-09-25 16:19 . 2009-09-25 16:19 -------- d-----w- c:\documents and settings\Paolo\Impostazioni locali\Dati applicazioni\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-25 07:34 . 2008-07-26 06:32 67119136 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-25 07:18 . 2004-08-19 12:00 89790 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 07:18 . 2004-08-19 12:00 502766 ----a-w- c:\windows\system32\perfh010.dat
2009-10-24 20:42 . 2008-07-26 06:32 789872 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-23 16:24 . 2007-12-01 09:18 -------- d-----w- c:\documents and settings\Paolo\Dati applicazioni\Skype
2009-10-23 15:25 . 2007-12-01 09:19 -------- d-----w- c:\documents and settings\Paolo\Dati applicazioni\skypePM
2009-10-20 16:20 . 2009-08-29 21:51 -------- d-----w- c:\programmi\Alice MOBILE
2009-10-19 18:40 . 2006-06-09 17:36 -------- d-----w- c:\programmi\File comuni\Adobe
2009-10-19 18:38 . 2007-12-28 20:31 -------- d-----w- c:\documents and settings\Linda\Dati applicazioni\Skype
2009-10-19 18:25 . 2007-12-28 20:53 -------- d-----w- c:\documents and settings\Linda\Dati applicazioni\skypePM
2009-10-11 21:25 . 2009-07-11 22:07 272784 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2009-10-11 09:24 . 2009-01-21 20:42 -------- d-----w- c:\programmi\Microsoft
2009-10-07 21:53 . 2009-07-04 13:07 -------- d-----w- c:\programmi\File comuni\Nokia
2009-10-07 21:52 . 2006-07-11 17:40 -------- d-----w- c:\programmi\Nokia
2009-10-06 18:39 . 2008-03-02 09:23 -------- d-----w- c:\documents and settings\Linda\Dati applicazioni\U3
2009-09-25 17:11 . 2009-08-29 07:26 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Drivers HeadQuarters
2009-09-22 17:00 . 2009-09-22 17:00 -------- d-----w- c:\documents and settings\Paolo\Dati applicazioni\HpUpdate
2009-09-22 16:52 . 2009-09-22 16:51 -------- d-----w- c:\documents and settings\Linda\Dati applicazioni\HpUpdate
2009-09-18 19:23 . 2006-05-16 07:50 -------- d-----w- c:\programmi\File comuni\Macrovision Shared
2009-09-17 21:30 . 2009-09-17 21:30 -------- d-----w- c:\programmi\File comuni\DVDVideoSoft
2009-09-17 21:30 . 2009-09-17 21:30 -------- d-----w- c:\programmi\DVDVideoSoft
2009-09-17 21:19 . 2009-09-17 21:19 -------- d-----w- c:\documents and settings\Linda\Dati applicazioni\InterVideo
2009-09-17 11:33 . 2009-09-17 11:33 -------- d-----w- c:\programmi\imaxel
2009-09-11 14:17 . 2004-08-19 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-19 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 21:51 . 2006-05-15 14:17 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-08-29 07:56 . 2004-08-19 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:38 . 2009-08-29 07:17 -------- d-----w- c:\programmi\Flash Memory Toolkit
2009-08-26 20:41 . 2007-04-10 10:33 49920 ----a-w- c:\windows\system32\drivers\HPZid412.sys
2009-08-26 20:41 . 2007-04-10 10:33 16496 ----a-w- c:\windows\system32\drivers\HPZipr12.sys
2009-08-26 20:40 . 2007-04-10 10:33 21568 ----a-w- c:\windows\system32\drivers\HPZius12.sys
2009-08-26 08:00 . 2004-08-19 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 16:10 . 2007-09-13 08:58 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2007-09-13 08:58 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2007-09-13 08:58 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-04-25 09:18 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-25 09:18 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2007-09-13 08:58 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2007-09-13 08:58 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2007-09-13 08:58 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2007-09-13 08:58 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-06 17:24 . 2006-05-15 13:57 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2006-05-15 13:57 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2006-05-15 13:57 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2005-05-26 02:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2006-05-15 13:57 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2004-08-19 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2006-05-15 13:57 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2008-11-14 08:32 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 17:23 . 2008-11-14 08:32 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 17:23 . 2006-05-15 13:57 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 08:59 . 2004-08-19 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 20:56 . 2004-08-19 12:00 2192896 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 17:26 . 2004-08-19 15:34 2069760 ----a-w- c:\windows\system32\ntkrnlpa.exe
2006-07-26 20:19 . 2006-07-26 20:19 2518 ----a-w- c:\programmi\Install.inf
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer" [X]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"SoundMAXPnP"="c:\programmi\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"Apoint"="c:\programmi\Apoint2K\Apoint.exe" [2005-02-08 159744]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-20 344064]
"Cpqset"="c:\programmi\HPQ\Default Settings\cpqset.exe" [2005-03-29 233534]
"QlbCtrl.exe"="c:\programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-09-25 202032]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-11-12 208952]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"HP Software Update"="c:\programmi\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"NokiaMusic FastStart"="c:\programmi\Nokia\Nokia Music\NokiaMusic.exe" [2009-07-22 2331936]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2006-09-01 282624]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-10-03 39792]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-04-13 88209]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Software Bluetooth\BTTray.exe [2005-5-31 577597]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\G:\0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnsvc"=3 (0x3)
"iPodService"=3 (0x3)
"AntiVirService"=2 (0x2)
"AntiVirScheduler"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Programmi\\File comuni\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Programmi\\Graphisoft\\ArchiCAD 11\\ArchiCAD.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [25/04/08 10.18.52 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [25/04/08 10.18.52 20560]
R2 BdHttpServer;Bd Http Server;c:\programmi\Maggioli Editore\Banchedati\prg\bdsrvc.exe [14/06/04 1.56.14 1421824]
R3 Com4QLBEx;Com4QLBEx;c:\programmi\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [23/11/08 10.45.33 193840]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\SupportAppXL\cdrom_mon.exe [29/08/09 10.50.17 81920]
S2 gupdate1c9faff92e9969a;Servizio di Google Update (gupdate1c9faff92e9969a);c:\programmi\Google\Update\GoogleUpdate.exe [02/07/09 11.26.32 133104]
S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSVC.EXE [30/03/09 3.28.36 1533808]
S3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\drivers\ONDAusbmdm6k.sys [29/08/09 10.51.51 104960]
S3 ONDAusbnet;ONDA USB-NDIS miniport;c:\windows\system32\drivers\ONDAusbnet.sys [29/08/09 10.51.51 110080]
S3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\drivers\ONDAusbnmea.sys [29/08/09 10.51.51 104960]
S3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\drivers\ONDAusbser6k.sys [29/08/09 10.51.51 104960]
S4 Rdentsitrcw;Rdentsitrcw; [x]
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-25 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2008-07-26 16:10]
2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-07-02 10:26]
2009-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-07-02 10:26]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = *.local
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
Toolbar-Locked - (no file)
AddRemove-DMX5_is1 - e:\drivermax\unins000.exe
AddRemove-eMule - f:\programmi\eMule\Uninstall.exe
AddRemove-Malwarebytes' Anti-Malware_is1 - e:\malwarebytes' anti-malware\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-25 08:34
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\HPQ\Default Settings\cpqset.exe????????????2?3?7?6??????? ???B?????????????hLC????????
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1960408961-1844237615-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"0140AC1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-10-25 8.37.16
ComboFix-quarantined-files.txt 2009-10-25 07:37
Pre-Run: 33.088.475.136 byte disponibili
Post-Run: 34.316.320.768 byte disponibili
- - End Of File - - 6B515C731DFEA8D4F271B39D76474D8A