ecco la prima:
ComboFix 09-06-26.02 - Proprietario 28/06/2009 18.23.27.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1022.693 [GMT 2:00]
Eseguito da: c:\documents and settings\Proprietario\Documenti\FILE RICEVUTI\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-05-28 al 2009-06-28 )))))))))))))))))))))))))))))))))))
.
2009-06-26 17:17 . 2009-06-26 17:17 -------- d-----w- c:\programmi\File comuni\HP
2009-06-26 17:15 . 2009-06-26 17:15 -------- d-----w- c:\programmi\Hewlett-Packard
2009-06-26 17:10 . 2009-06-26 17:24 123143 ----a-w- c:\windows\hpoins11.dat
2009-06-26 17:10 . 2006-05-06 00:21 11634 ------w- c:\windows\hpomdl11.dat
2009-06-26 14:15 . 2009-06-26 14:19 -------- d-----w- c:\programmi\Microsoft Student
2009-06-26 14:15 . 2005-05-26 13:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-06-12 15:16 . 2009-06-12 15:21 -------- d-----w- c:\programmi\PC Error Eliminator
2009-06-12 13:57 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-06-09 21:16 . 2009-04-30 21:13 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-09 21:16 . 2009-04-30 21:13 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-28 15:44 . 2009-02-15 18:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-06-28 15:01 . 2009-03-16 16:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-06-28 14:56 . 2009-03-16 16:03 499744 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-28 14:56 . 2009-03-16 16:03 2788 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-28 14:56 . 2009-03-16 16:03 2519584 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-28 14:56 . 2009-03-16 16:03 21812 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-27 18:22 . 2009-03-03 19:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-06-27 15:03 . 2009-01-06 18:39 -------- d-----w- c:\programmi\Unlocker
2009-06-26 17:25 . 2009-01-30 20:22 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\TeraCopy
2009-06-26 17:15 . 2009-01-16 07:58 -------- d-----w- c:\programmi\HP
2009-06-26 17:10 . 2006-01-01 02:08 25760 ----a-w- c:\documents and settings\Proprietario\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-06-26 16:43 . 2009-01-06 21:23 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\uTorrent
2009-06-26 15:14 . 2006-01-01 02:40 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Ahead
2009-06-21 18:40 . 2009-04-22 15:00 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Spamihilator
2009-06-19 21:30 . 2009-01-05 23:36 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-06-19 21:29 . 2009-03-02 19:12 3561743 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 09:27 . 2009-01-05 23:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2009-01-05 23:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-09 22:14 . 2009-05-18 16:49 -------- d-----w- c:\programmi\TuneUp Utilities 2008
2009-06-06 16:18 . 2004-08-19 11:00 556916 ----a-w- c:\windows\system32\perfh010.dat
2009-06-06 16:18 . 2004-08-19 11:00 115338 ----a-w- c:\windows\system32\perfc010.dat
2009-06-05 17:13 . 2009-03-28 17:25 -------- d-----w- c:\programmi\blueMSX
2009-05-26 14:20 . 2009-01-05 19:30 -------- d-----w- c:\programmi\Google
2009-05-23 17:42 . 2009-05-23 17:42 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Babylon
2009-05-23 17:42 . 2009-05-23 17:42 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Babylon
2009-05-23 17:20 . 2009-05-23 17:20 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Prevx
2009-05-20 20:53 . 2009-03-16 16:04 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 20:53 . 2009-03-16 16:04 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-18 16:50 . 2009-05-18 16:50 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-05-18 16:49 . 2009-01-29 18:15 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-05-17 17:10 . 2009-05-17 17:10 -------- d-----w- c:\programmi\File comuni\PCSuite
2009-05-17 17:10 . 2009-05-17 17:10 -------- d-----w- c:\programmi\File comuni\Nokia
2009-05-17 17:10 . 2009-01-16 19:32 -------- d-----w- c:\programmi\Nokia
2009-05-17 17:09 . 2009-05-17 17:09 -------- d-----w- c:\programmi\PC Connectivity Solution
2009-05-17 17:08 . 2009-01-16 19:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Installations
2009-05-17 17:08 . 2009-05-17 17:08 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-05-17 17:08 . 2009-05-17 17:08 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-05-17 17:08 . 2009-05-17 17:08 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-05-17 17:07 . 2009-05-17 17:08 34447128 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_ita.exe
2009-05-16 14:59 . 2009-05-16 14:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DriverScanner
2009-05-16 14:59 . 2009-05-16 14:56 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Uniblue
2009-05-13 18:35 . 2009-03-21 17:39 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\dvdcss
2009-05-13 05:02 . 2004-08-19 11:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-19 11:00 347648 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 15:53 . 2009-05-05 18:53 -------- d-----w- c:\programmi\File comuni\Symantec Shared
2009-05-05 19:21 . 2009-05-05 18:53 -------- d-----w- c:\programmi\Norton Security Scan
2009-05-05 18:02 . 2009-05-05 17:32 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-05-05 17:26 . 2009-05-05 17:24 -------- d-----w- c:\programmi\Taskbar Hide
2009-05-05 17:26 . 2009-05-05 17:26 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-05-04 16:38 . 2009-05-04 16:38 -------- d-----w- c:\programmi\Glary Utilities
2009-04-20 19:16 . 2009-04-20 19:16 37888 ----a-w- c:\windows\system32\setupnt.dll
2009-04-20 19:16 . 2009-04-20 19:16 82464 ----a-w- c:\windows\system32\drivers\snapman.sys
2009-04-20 19:16 . 2009-04-20 19:16 28928 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-04-20 19:16 . 2009-04-20 19:16 213888 ----a-w- c:\windows\system32\drivers\timntr.sys
2009-04-19 19:47 . 2004-08-19 11:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-16 22:29 . 2009-01-28 21:28 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-16 22:28 . 2009-04-16 22:28 152576 ----a-w- c:\documents and settings\Proprietario\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-15 14:52 . 2004-08-19 11:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-14 17:17 . 2009-04-14 17:17 18112 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-10 39408]
"L09IXLRD_3606125"="c:\programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" [2009-03-02 351000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-03-16 201992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-01-11 15961088]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"=
"c:\\Programmi\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\italian\\setup.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\italian\\setup.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 19.29.38 33808]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [20/02/2009 19.47.14 55152]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [27/01/2009 21.44.17 46080]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [27/01/2009 21.44.03 56960]
S2 gupdate1c98f9ee3c86c5c;Servizio di Google Update (gupdate1c98f9ee3c86c5c);c:\programmi\Google\Update\GoogleUpdate.exe [15/02/2009 20.54.53 133104]
S3 fsssvc;Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19.08.58 533360]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-28 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2009-05-04 19:44]
2009-06-28 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-05 18:53]
2009-06-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-15 18:54]
2009-06-28 c:\windows\Tasks\Verifica e correzione automatica.job
- c:\programmi\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 07:27]
.
.
------- Scansione supplementare -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Proprietario\Dati applicazioni\Mozilla\Firefox\Profiles\hghox8ke.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Cerca
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://mystart.hiyo.com/?loc=ff_address&search=
FF - component: c:\programmi\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-28 18:26
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1935655697-1220945662-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1F14D1D7-B391-AC45-918D-4B980785CB51}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abemkbiibhifolnloeeggflcmhnoipebce"=hex:61,61,00,00
"bbemkbiibhifolnloehgnbgicldckcklelkn"=hex:61,61,00,00
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(568)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(1912)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2009-06-28 18.27.41
ComboFix-quarantined-files.txt 2009-06-28 16:27
Pre-Run: 249.451.196.416 byte disponibili
Post-Run: 249.440.432.128 byte disponibili
214
tra poco ti mando l'altra.ciao