Eccomi con il report di combofix. Attendo fiducioso e ringrazio per l'aiuto.
ComboFix 09-11-07.04 - Amministratore 08/11/2009 16.36.40.2.1 - FAT32x86
Eseguito da: c:\documents and settings\Amministratore\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Amministratore\rundll32.exe sispower .exe
c:\documents and settings\Amministratore\soundman .exe
c:\documents and settings\Amministratore\soundman.exe
c:\documents and settings\Giampaolo\rundll32.exe sispower .exe
c:\documents and settings\Giampaolo\soundman .exe
c:\documents and settings\Giampaolo\soundman.exe
c:\windows\system32\ctfmon .exe
.
((((((((((((((((((((((((( Files Creati Da 2009-10-08 al 2009-11-08 )))))))))))))))))))))))))))))))))))
.
2009-11-08 12:26 . 2009-11-08 12:26 -------- d--h--w- c:\windows\PIF
2009-11-05 11:24 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-05 11:24 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-05 10:16 . 2009-11-05 10:16 -------- d-----w- c:\documents and settings\Amministratore\.housecall6.6
2009-11-05 10:13 . 2009-11-05 10:13 -------- d-----w- c:\windows\Sun
2009-11-03 20:21 . 2009-11-03 20:21 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\Yahoo!
2009-11-03 20:21 . 2009-11-03 20:21 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\HPAppData
2009-11-03 20:21 . 2009-11-03 20:21 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\.clamwin
2009-11-03 06:25 . 2009-11-03 06:25 -------- d-sh--w- c:\documents and settings\Amministratore\IECompatCache
2009-11-03 05:07 . 2009-11-03 05:07 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-11-03 05:07 . 2009-11-03 05:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-11-01 19:47 . 2009-11-01 19:47 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\.clamwin
2009-10-31 06:57 . 2009-10-31 06:57 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\.clamwin
2009-10-31 06:57 . 2009-10-31 06:57 -------- d-----w- c:\programmi\ClamWin
2009-10-31 06:57 . 2009-10-31 06:57 -------- d-----w- c:\documents and settings\All Users\.clamwin
2009-10-29 10:20 . 2009-10-29 10:20 -------- d-sh--w- c:\documents and settings\Giampaolo\IECompatCache
2009-10-28 07:42 . 2009-10-28 07:43 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Softland
2009-10-27 10:37 . 2009-10-27 10:37 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\Temp
2009-10-24 08:26 . 2009-10-29 10:38 165232 ---ha-w- c:\documents and settings\Giampaolo\Dati applicazioni\Microsoft\Virtual PC\VPCKeyboard.dll
2009-10-24 08:25 . 2009-10-24 08:25 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\VMware
2009-10-23 09:27 . 2009-10-23 09:27 -------- d-----w- C:\Virtual_Machine
2009-10-23 08:28 . 2001-08-17 20:53 3328 ----a-w- c:\windows\system32\drivers\qv2kux.sys
2009-10-23 08:28 . 2001-08-17 20:53 3328 ----a-w- c:\windows\system32\dllcache\qv2kux.sys
2009-10-23 08:07 . 2008-09-18 15:49 31280 ----a-r- c:\windows\system32\drivers\vmusb.sys
2009-10-23 07:15 . 2008-09-18 15:49 55856 ----a-r- c:\windows\system32\vnetinst.dll
2009-10-23 07:15 . 2008-09-18 15:49 16560 ----a-r- c:\windows\system32\drivers\vmnetadapter.sys
2009-10-23 07:15 . 2008-09-18 22:11 326192 ----a-w- c:\windows\system32\vmnetdhcp.exe
2009-10-23 07:15 . 2008-09-18 22:12 26288 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2009-10-23 07:15 . 2008-09-18 22:11 399920 ----a-w- c:\windows\system32\vmnat.exe
2009-10-23 07:15 . 2008-09-18 15:49 50736 ----a-r- c:\windows\system32\vmnetbridge.dll
2009-10-23 07:15 . 2008-09-18 15:49 31280 ----a-r- c:\windows\system32\drivers\vmnetbridge.sys
2009-10-23 07:15 . 2008-09-18 15:49 18736 ----a-r- c:\windows\system32\drivers\vmnet.sys
2009-10-23 07:15 . 2008-09-18 22:11 723504 ----a-w- c:\windows\system32\vnetlib.dll
2009-10-23 07:14 . 2008-09-18 22:12 23216 ----a-w- c:\windows\system32\drivers\VMkbd.sys
2009-10-23 07:12 . 2009-10-23 07:12 -------- d-----w- c:\programmi\VMware
2009-10-22 13:50 . 2009-10-30 08:34 165232 ---ha-w- c:\documents and settings\Amministratore\Dati applicazioni\Microsoft\Virtual PC\VPCKeyboard.dll
2009-10-22 13:49 . 2009-10-22 13:49 -------- d-----w- c:\programmi\Microsoft Virtual PC
2009-10-21 17:13 . 2009-10-21 17:13 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\WinZip
2009-10-21 17:07 . 2009-10-21 17:07 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Uniblue
2009-10-21 17:07 . 2009-10-21 17:07 -------- d-----w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\WinZip
2009-10-21 17:06 . 2009-10-21 17:06 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WinZip
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\NorthWind
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\MdiFavorites
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\MdiBrowser
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\IsapiFilter
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\IntelliSense
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\FormatCodes
2009-10-21 12:09 . 2009-10-21 12:09 -------- d-----w- c:\documents and settings\Amministratore\EditAndContinue
2009-10-20 11:17 . 2009-10-20 11:17 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Media Player Classic
2009-10-20 11:14 . 2009-10-20 11:14 -------- d-----w- c:\programmi\XP Codec Pack
2009-10-20 11:06 . 2009-10-20 11:06 -------- d-----w- c:\programmi\pdfsam
2009-10-20 11:05 . 2008-10-08 12:43 20120 ----a-w- c:\windows\system32\dopdfmn6.dll
2009-10-20 11:05 . 2008-10-08 12:43 18072 ----a-w- c:\windows\system32\dopdfmi6.dll
2009-10-20 11:05 . 2009-10-20 11:05 -------- d-----w- c:\programmi\Softland
2009-10-20 10:05 . 2009-10-20 10:05 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\CyberLink
2009-10-20 10:05 . 2009-10-20 10:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CyberLink
2009-10-20 09:28 . 2009-10-20 09:28 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\VMware
2009-10-20 09:26 . 2009-10-20 09:26 -------- d-----w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\Temp
2009-10-20 09:26 . 2009-10-20 09:26 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\VMware
2009-10-20 09:23 . 2009-10-20 09:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\VMware
2009-10-19 13:08 . 2009-10-19 13:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Macrovision
2009-10-19 12:50 . 2009-10-19 12:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\National Instruments
2009-10-19 12:47 . 2009-10-19 12:47 -------- d-----w- c:\windows\system32\cvirte
2009-10-19 12:46 . 2009-10-19 12:46 -------- d-----w- c:\programmi\National Instruments
2009-10-19 07:18 . 2009-10-19 07:18 -------- d-----w- c:\programmi\TopOCR
2009-10-19 07:06 . 2009-10-19 07:06 -------- d-----w- c:\programmi\Softi Software
2009-10-19 07:06 . 2009-10-19 07:06 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Softi Software
2009-10-16 10:23 . 2009-10-16 10:23 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\HpUpdate
2009-10-16 10:21 . 2009-10-16 10:21 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\HpUpdate
2009-10-16 10:21 . 2009-10-16 10:21 -------- d-----w- c:\windows\Hewlett-Packard
2009-10-16 07:55 . 2009-10-16 07:55 -------- d-----w- c:\programmi\MSXML 4.0
2009-10-14 07:03 . 2009-10-14 07:03 -------- d-----w- c:\windows\l2schemas
2009-10-14 07:03 . 2009-10-14 07:03 -------- d-----w- c:\windows\system32\it
2009-10-14 07:03 . 2009-10-14 07:03 -------- d-----w- c:\windows\system32\bits
2009-10-14 06:54 . 2009-10-14 06:55 -------- d-----w- c:\windows\EHome
2009-10-13 21:09 . 2009-10-13 21:09 -------- d-----w- c:\documents and settings\Augusta\Impostazioni locali\Dati applicazioni\Identities
2009-10-13 19:52 . 2009-10-13 19:52 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\Identities
2009-10-13 19:49 . 2009-10-13 19:49 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\Adobe
2009-10-13 19:44 . 2009-10-13 19:44 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\HP
2009-10-13 19:43 . 2009-10-13 19:43 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\HP
2009-10-13 19:22 . 2009-10-13 19:22 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\Yahoo!
2009-10-13 19:22 . 2009-10-13 19:22 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\HPAppData
2009-10-13 18:26 . 2009-10-13 18:26 -------- d-----w- c:\programmi\Microsoft
2009-10-13 18:26 . 2009-10-13 18:26 -------- d-----w- c:\programmi\Windows Live SkyDrive
2009-10-13 18:26 . 2009-10-13 18:26 -------- d-----w- c:\programmi\Windows Live
2009-10-13 18:25 . 2006-11-29 12:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-10-13 18:25 . 2009-10-13 18:25 -------- d-----w- c:\programmi\Microsoft SQL Server Compact Edition
2009-10-13 18:24 . 2009-10-13 18:24 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\HPAppData
2009-10-13 18:21 . 2009-10-13 18:21 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-10-13 18:21 . 2009-10-13 18:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WEBREG
2009-10-13 18:21 . 2009-10-13 18:21 -------- d-----w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\HP
2009-10-13 18:08 . 2009-10-13 18:08 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\HP
2009-10-13 17:58 . 2008-10-28 11:31 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2009-10-13 17:58 . 2008-10-28 11:31 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2009-10-13 17:58 . 2008-10-29 19:56 271704 ----a-r- c:\windows\system32\hpzids01.dll
2009-10-13 17:58 . 2008-10-06 14:38 121344 ----a-w- c:\windows\system32\hpf3l083.dll
2009-10-13 17:58 . 2008-10-28 11:31 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2009-10-13 17:57 . 2008-10-29 19:57 307200 ----a-r- c:\windows\system32\hposc_p02a.dll
2009-10-13 17:57 . 2008-10-28 11:31 372736 ----a-r- c:\windows\system32\hppldcoi.dll
2009-10-13 17:57 . 2008-10-28 11:31 309760 ----a-r- c:\windows\system32\difxapi.dll
2009-10-13 17:57 . 2008-10-29 19:57 974848 ----a-r- c:\windows\system32\hpost_p02b.dll
2009-10-13 17:57 . 2008-10-29 19:57 737280 ----a-r- c:\windows\system32\hposwia_p02b.dll
2009-10-13 17:56 . 2009-10-13 17:56 -------- d-----w- c:\documents and settings\Amministratore\Dati applicazioni\Yahoo!
2009-10-13 17:56 . 2009-10-13 17:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2009-10-13 17:56 . 2009-10-13 17:56 -------- d-----w- c:\programmi\Yahoo!
2009-10-13 17:54 . 2009-10-13 17:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP Product Assistant
2009-10-13 17:52 . 2009-10-13 17:52 -------- d-----w- c:\programmi\File comuni\HP
2009-10-13 17:51 . 2009-10-13 17:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP
2009-10-13 17:50 . 2009-10-13 17:50 -------- d-----w- c:\programmi\File comuni\Hewlett-Packard
2009-10-13 17:49 . 2009-10-13 17:49 -------- d-----w- c:\windows\system32\DRVSTORE
2009-10-13 17:48 . 2009-10-13 17:48 -------- d-----w- c:\programmi\HP
2009-10-13 17:48 . 2008-04-13 19:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-10-13 17:48 . 2008-04-13 19:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-10-13 17:46 . 2009-10-13 18:21 169199 ----a-w- c:\windows\hpoins36.dat
2009-10-13 17:46 . 2009-06-24 10:40 652 ------w- c:\windows\hpomdl36.dat
2009-10-13 10:58 . 2009-10-13 10:59 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\IsolatedStorage
2009-10-13 10:39 . 2009-10-13 10:39 -------- d-sh--w- c:\documents and settings\Giampaolo\PrivacIE
2009-10-13 10:16 . 2009-10-13 10:16 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\Microsoft Help
2009-10-13 08:15 . 2009-10-13 19:43 120712 ----a-w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-13 08:15 . 2009-10-13 08:15 -------- d-----w- c:\documents and settings\Giampaolo\Impostazioni locali\Dati applicazioni\Autodesk
2009-10-13 08:15 . 2009-10-13 08:15 -------- d-----w- c:\documents and settings\Giampaolo\Dati applicazioni\Autodesk
2009-10-13 08:14 . 2009-10-13 08:14 -------- d-sh--w- c:\documents and settings\Giampaolo\IETldCache
2009-10-13 07:36 . 2009-10-13 07:36 -------- d-----w- c:\programmi\AnswerWorks 4.0
2009-10-13 07:34 . 2009-10-13 07:34 -------- d-----w- c:\programmi\AutoCAD 2007
2009-10-13 07:34 . 2009-10-13 07:34 -------- d-----w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\Autodesk
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-23 07:14 . 2005-11-03 12:03 550550 ----a-w- c:\windows\system32\perfh010.dat
2009-10-23 07:14 . 2005-11-03 12:03 108458 ----a-w- c:\windows\system32\perfc010.dat
2009-10-14 07:06 . 2005-11-03 11:43 76875 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-13 18:30 . 2009-10-09 10:29 120712 ----a-w- c:\documents and settings\Amministratore\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-12 08:58 . 2009-10-12 08:58 -------- d-----w- c:\documents and settings\Telemaco\Dati applicazioni\Malwarebytes
2009-10-10 11:18 . 2009-10-10 11:18 -------- d-----w- c:\documents and settings\Augusta\Dati applicazioni\Malwarebytes
2009-10-09 13:33 . 2009-10-09 13:33 -------- d-----w- c:\programmi\Pubblicazione guidata
2009-10-09 12:35 . 2009-10-09 12:35 -------- d-----w- c:\programmi\Ufficio
2009-10-09 12:30 . 2009-10-09 12:30 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Symantec
2009-10-09 10:31 . 2009-10-09 10:31 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-09 10:31 . 2009-10-09 10:31 152576 ----a-w- c:\documents and settings\Amministratore\Dati applicazioni\Sun\Java\jre1.6.0_15\lzma.dll
2009-10-09 10:25 . 2009-10-09 10:25 -------- d-----w- c:\programmi\SymNetDrv
2009-10-09 09:44 . 2009-10-09 09:44 -------- d-----w- c:\programmi\Java
2009-10-09 09:44 . 2009-10-09 09:44 -------- d-----w- c:\programmi\File comuni\Java
2009-10-09 09:34 . 2009-10-09 09:34 -------- d-----w- c:\programmi\SiSLan
2009-09-11 15:17 . 2004-08-19 04:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 22:03 . 2004-08-19 04:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:56 . 2005-07-03 02:15 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 09:00 . 2004-08-19 04:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2005-10-12 14:04 . 2005-10-12 14:04 131072 ----a-w- c:\programmi\internet explorer\plugins\LV80ActiveXControl.dll
2006-06-07 13:40 . 2006-06-07 13:40 132848 ----a-w- c:\programmi\internet explorer\plugins\LV82ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-11 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"ntiMUI"="c:\programmi\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2009-11-08 36878]
"RemoteControl"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2009-11-08 36878]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"ccApp"="c:\programmi\File comuni\Symantec Shared\ccApp.exe" [2008-01-31 58728]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2009-11-08 36878]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-09 149280]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2009-10-09 100056]
"GhostStartTrayApp"="c:\programmi\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe" [2009-11-08 36878]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2009-11-08 36878]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"vmware-tray"="c:\programmi\VMware\VMware Workstation\vmware-tray.exe" [2008-09-18 84528]
"ClamWin"="c:\programmi\ClamWin\bin\ClamTray.exe" [2009-06-11 86016]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Manutenzione\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-07-13 49152]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-08-17 90112]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Programmi\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Programmi\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Programmi\\VMware\\VMware Workstation\\vmware-authd.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe [2008-04-14 14336]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\programmi\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-12-09 2799808]
S1 GhPciScan;GhostPciScanner;c:\programmi\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 5632]
S2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;c:\programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-08-03 100032]
S2 vmci;VMware vmci;c:\windows\system32\Drivers\vmci.sys [2008-09-18 54960]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - INT15.SYS
*Deregistered* - PROCEXP113
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-09 c:\windows\Tasks\Norton AntiVirus - Scansione del computer - Amministratore.job
- c:\progra~1\NORTON~1\Navw32.exe [2004-08-24 12:26]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\Ufficio\MICROS~1\Office10\EXCEL.EXE/3000
LSP: c:\programmi\VMware\VMware Workstation\vsocklib.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-08 16:50
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-3237291647-1294369284-1593085102-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(444)
c:\windows\system32\sxs.dll
.
Ora fine scansione: 2009-11-08 17.21.58
ComboFix-quarantined-files.txt 2009-11-08 16:21
ComboFix2.txt 2009-11-05 12:08
Pre-Run: 52.811.202.560 byte disponibili
Post-Run: 52.795.801.600 byte disponibili
- - End Of File - - 420E873F678E40236D52BEEF60472482
P.S. Dopo dovrò controllare anche il portatile!!! (una cosa alla volta)