ciao r16, ho fatto combofix, senza toccare il mouse e con i tuoi consigli, quando è uscito il blocco note mi è scomparso tutto il desktop e la barra delle applicazioni, per far tornare tutto ho dovuto usare i tasti ctrl alt canc e cliccare su nuova operazione. è normale? ComboFix 09-06-19.01 - Admin 20/06/2009 13.53.18.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.512.233 [GMT 2:00]
Eseguito da: c:\documents and settings\Admin\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090619-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\hfkxiqkwirleeavt.dll-uninst.exe
.
((((((((((((((((((((((((( Files Creati Da 2009-05-20 al 2009-06-20 )))))))))))))))))))))))))))))))))))
.
2009-06-18 10:16 . 2009-06-18 10:17 -------- d-----w- c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\Yahoo
2009-06-18 10:12 . 2009-05-26 19:35 607472 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Yahoo!\YUpdater\yupdater.exe
2009-06-12 12:16 . 2009-06-12 12:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MailFrontier
2009-06-12 12:16 . 2009-06-12 12:18 4212 ---h--w- c:\windows\system32\zllictbl.dat
2009-06-12 12:16 . 2004-04-27 02:40 11264 ----a-w- c:\windows\system32\SpOrder.dll
2009-06-12 12:14 . 2009-06-12 12:14 -------- d-----w- c:\windows\Internet Logs
2009-06-09 12:58 . 2009-06-09 12:58 -------- d-----w- c:\windows\system32\Librerie XP e Vista
2009-06-09 12:17 . 2009-06-09 12:17 -------- d-----w- c:\programmi\Jasc Software Inc
2009-05-30 13:18 . 2009-05-30 13:18 -------- d-----w- c:\docume~1\Admin\DATIAP~1\GlarySoft
2009-05-30 12:58 . 2009-05-30 12:58 -------- d-----w- c:\docume~1\Admin\DATIAP~1\it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1
2009-05-30 12:56 . 2009-05-30 12:56 -------- d-----w- c:\programmi\File comuni\Adobe AIR
2009-05-27 12:35 . 2009-05-27 12:35 -------- d-----w- c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\Clock_22
2009-05-25 12:47 . 2009-05-25 12:47 2967799 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-25 12:40 . 2009-05-25 12:40 -------- d-----w- c:\windows\system32\PolarClock3 dir
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 09:37 . 2002-10-04 17:03 70964 ----a-w- c:\windows\system32\perfc010.dat
2009-06-10 09:37 . 2002-10-04 17:03 440738 ----a-w- c:\windows\system32\perfh010.dat
2009-05-20 12:45 . 2009-05-20 12:45 -------- d-----w- c:\docume~1\Admin\DATIAP~1\Auslogics
2009-05-07 15:32 . 2002-10-04 17:02 347648 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 09:26 . 2005-12-06 12:54 76875 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-04-29 04:45 . 2005-06-17 22:26 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:44 . 2009-03-26 09:13 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-20 12:19 . 2009-04-20 12:19 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-04-20 12:19 . 2009-04-20 12:19 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-04-20 12:19 . 2009-04-20 12:19 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-04-20 12:19 . 2009-04-20 12:20 34447128 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_ita.exe
2009-04-19 19:47 . 2002-10-04 17:03 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:52 . 2004-03-06 01:18 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-06 13:32 . 2009-02-25 12:04 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2009-02-25 12:04 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-28 13:59 . 2009-03-28 13:59 27136 ----a-w- c:\windows\system32\drivers\nchssvad.sys
2008-09-22 14:21 . 2008-08-27 09:47 7518 --sha-w- c:\windows\system32\KGyGaAvL.sys
2008-09-22 14:19 . 2008-08-27 09:47 88 --sh--r- c:\windows\system32\BCD1FABB0B.sys
2008-09-01 09:59 . 2008-08-30 15:42 56 --sh--r- c:\windows\system32\
0BBBFAD1BC.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Messenger (Yahoo!)"="c:\programmi\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-26 4351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="c:\windows\ATK0100\Hcontrol.exe" [2003-09-21 61440]
"ASUS Live Update"="c:\programmi\ASUS\ASUS Live Update\ALU.exe" [2003-09-19 172032]
"Power_Gear"="c:\progra~1\ASUS\Power4 Gear\BatteryLife.exe" [2002-11-29 73728]
"ATIPTA"="c:\progra~1\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-13 335872]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2003-12-03 110592]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2003-12-03 618496]
"Control Center"="c:\program files\ASUS\WLAN Card Utilities\Center.exe" [2003-09-19 1241088]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-10 136600]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2006-08-23 98304]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-12-01 57344]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2003-12-15 28672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Hotkey.lnk - c:\programmi\Asus\ASUS Hotkey\Hotkey.exe [2005-12-6 798208]
hp psc 2000 Series.lnk - c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-9 323646]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Asus\\ASUS Live Update\\LiveUpdt.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15867:TCP"= 15867:TCP:BitComet 15867 TCP
"15867:UDP"= 15867:UDP:BitComet 15867 UDP
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [07/03/2009 15.39.01 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07/03/2009 15.39.01 20560]
R3 ASNDIS5;ASNDIS5 Protocol Driver;c:\windows\ATK0100\ASNDIS5.sys [06/12/2005 12.10.01 16269]
R3 HSFHWSIS;HSFHWSIS;c:\windows\system32\drivers\HSFHWSIS.sys [06/12/2005 12.10.17 190080]
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;c:\windows\system32\drivers\wbms.sys [06/12/2005 12.10.18 35328]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [06/12/2005 12.10.19 26240]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\programmi\NOS\bin\getPlus_HelperSvc.exe [21/02/2009 16.12.00 33752]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [20/04/2009 14.21.52 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [20/04/2009 14.21.53 8320]
S3 o1394bul;o1394bul; [x]
.
Contenuto della cartella 'Scheduled Tasks'
2008-01-12 c:\windows\Tasks\FRU Task 2003-04-10 00:56ewlett-Packard2003-04-10 00:56p psc 2200 series272A572217594EBCF1CEE215E352B92AD073FDE4159871007.job
- c:\programmi\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 15:56]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://it.yahoo.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://it.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://www.asus.com.tw/
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://it.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://it.search.yahoo.com
IE: E&sporta in Microsoft Excel
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-20 13:56
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
Ora fine scansione: 2009-06-20 13.57.37
ComboFix-quarantined-files.txt 2009-06-20 11:57
Pre-Run: 21.919.531.008 byte disponibili
Post-Run: 22.081.601.536 byte disponibili
144 --- E O F --- 2009-06-15 10:04