Ciao e intanto grazie per esserti offerto di aiutarmi!
Ho provveduto alla scansione e questo è il report:
ComboFix 09-11-18.06 - mà 19/11/2009 2.03.49.1.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.2550.1711 [GMT 1:00]
Eseguito da: c:\documents and settings\mà\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\mà\Impostazioni locali\Dati applicazioni\bqxmshod.dat
c:\documents and settings\mà\Impostazioni locali\Dati applicazioni\bqxmshod.exe
c:\documents and settings\mà\Impostazioni locali\Dati applicazioni\bqxmshod_nav.dat
c:\documents and settings\mà\Impostazioni locali\Dati applicazioni\bqxmshod_navps.dat
c:\documents and settings\mà\Impostazioni locali\Dati applicazioni\kegwnb_nav.dat
c:\programmi\WinPCap
c:\programmi\WinPCap\daemon_mgm.exe
c:\programmi\WinPCap\npf_mgm.exe
c:\programmi\WinPCap\rpcapd.exe
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\service.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\nvs2.inf
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Files Creati Da 2009-10-19 al 2009-11-19 )))))))))))))))))))))))))))))))))))
.
2009-11-18 15:05 . 2008-03-05 14:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2009-11-16 23:21 . 2009-11-16 23:21 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-11-16 23:20 . 2009-11-16 23:20 -------- d-----w- c:\programmi\File comuni\Skype
2009-11-12 02:04 . 2009-11-12 02:04 -------- d-----w- c:\windows\system32\wbem\Repository
2009-11-10 01:33 . 2009-11-10 01:33 -------- d-s---w- c:\documents and settings\LocalService\Preferiti
2009-11-08 23:38 . 2009-11-08 23:38 -------- d-----w- c:\programmi\GammonEmpire
2009-11-08 20:35 . 2009-11-08 20:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TVU Networks
2009-11-08 20:35 . 2009-11-08 20:35 -------- d-----w- c:\windows\system32\TVUAx
2009-11-07 13:14 . 2009-11-07 13:15 1925024 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NOS\Adobe_Downloads\install_flash_player.exe
2009-11-03 18:14 . 2009-11-03 18:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WebcamMax
2009-11-03 17:51 . 2009-10-07 08:43 199192 ----a-w- c:\windows\system32\lvci12101110.dll
2009-11-03 17:49 . 2008-03-11 13:14 941784 ----a-w- c:\windows\system32\drivers\CAMTHWDM.sys
2009-11-03 17:49 . 2009-11-03 17:49 -------- d-----w- c:\programmi\WebcamMax
2009-11-03 16:46 . 2009-11-03 16:46 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\EmailNotifier
2009-11-03 16:46 . 2009-11-03 16:46 -------- d-----w- c:\programmi\oovootb
2009-11-03 16:46 . 2009-11-03 16:46 -------- d-----w- c:\programmi\ooVoo
2009-11-03 08:53 . 2009-11-03 08:53 -------- d-----w- c:\programmi\iPod
2009-11-03 08:53 . 2009-11-03 08:53 -------- d-----w- c:\programmi\iTunes
2009-11-03 08:53 . 2009-11-03 08:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-03 08:45 . 2009-11-03 08:45 79144 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-01 12:52 . 2009-11-01 12:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee
2009-10-30 18:05 . 2009-10-30 18:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee Security Scan
2009-10-30 18:05 . 2009-10-30 18:05 -------- d-----w- c:\programmi\McAfee Security Scan
2009-10-30 18:05 . 2009-10-30 18:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-10-27 20:28 . 2008-02-15 11:49 188416 ----a-w- c:\windows\system32\igfxres.dll
2009-10-27 20:24 . 2008-02-15 12:12 1670144 ----a-w- c:\windows\system32\igxpdv32.dll
2009-10-27 20:24 . 2008-02-15 12:12 5854752 ----a-w- c:\windows\system32\drivers\igxpmp32.sys
2009-10-27 20:24 . 2008-02-15 12:12 57344 ----a-w- c:\windows\system32\igxprd32.dll
2009-10-27 20:24 . 2008-02-15 12:12 151040 ----a-w- c:\windows\system32\igxpgd32.dll
2009-10-27 20:24 . 2008-02-15 12:21 147456 ----a-w- c:\windows\system32\igfxCoIn_v4926.dll
2009-10-27 20:24 . 2008-02-15 12:12 2643968 ----a-w- c:\windows\system32\igxpdx32.dll
2009-10-27 20:24 . 2008-03-07 11:56 920088 ----a-w- c:\windows\system32\igxpun.exe
2009-10-27 20:24 . 2009-10-27 20:24 -------- d-----w- C:\Intel
2009-10-26 20:02 . 2009-10-26 20:02 -------- d-----w- c:\programmi\Microsoft CAPICOM 2.1.0.2
2009-10-25 19:36 . 2009-10-07 08:49 23832 ----a-w- c:\windows\system32\drivers\lvuvcflt.sys
2009-10-25 19:36 . 2009-10-25 19:36 -------- d-----w- c:\programmi\Logitech
2009-10-25 19:29 . 2009-10-25 19:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\LogiShrd
2009-10-25 19:26 . 2008-04-13 19:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-10-25 19:26 . 2008-04-13 19:45 60032 ----a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-10-25 19:26 . 2009-10-25 19:26 -------- d-----w- c:\programmi\File comuni\logishrd
2009-10-25 19:26 . 2008-04-14 03:13 54784 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-10-25 19:26 . 2008-04-14 03:13 54784 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2009-10-25 10:41 . 2009-10-25 10:41 -------- d-----w- c:\programmi\Microsoft Student
2009-10-25 10:41 . 2009-10-25 10:41 -------- d-----w- c:\programmi\Learning Essentials
2009-10-23 19:22 . 2009-09-25 17:42 129784 ------w- c:\windows\system32\pxafs.dll
2009-10-23 19:22 . 2009-09-25 17:42 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-10-23 19:22 . 2009-09-25 17:42 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-10-23 19:10 . 2009-10-23 19:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DAEMON Tools Lite
2009-10-23 19:10 . 2009-10-23 19:10 -------- d-----w- c:\programmi\DAEMON Tools Toolbar
2009-10-23 19:10 . 2009-10-23 19:10 -------- d-----w- c:\programmi\DAEMON Tools Lite
2009-10-22 21:37 . 2009-10-22 21:37 -------- d--h--w- c:\windows\PIF
2009-10-21 15:55 . 2009-10-21 15:55 -------- d-----w- c:\programmi\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-19 01:11 . 2009-10-25 19:26 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2009-11-19 01:11 . 2009-10-30 18:07 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2009-11-17 21:08 . 2005-02-05 04:26 86394 ----a-w- c:\windows\system32\perfc010.dat
2009-11-17 21:08 . 2005-02-05 04:26 494086 ----a-w- c:\windows\system32\perfh010.dat
2009-11-01 13:40 . 2009-09-29 15:20 189784 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-23 19:07 . 2008-06-23 11:07 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-10-14 12:40 . 2009-10-14 12:40 296280 ----a-w- c:\documents and settings\All Users\Dati applicazioni\LogiShrd\LQCVFX\Filters\VMSEF.dll
2009-10-14 12:37 . 2009-10-14 12:37 6781272 ----a-w- c:\documents and settings\All Users\Dati applicazioni\LogiShrd\LQCVFX\Filters\MMSEF.dll
2009-10-11 03:17 . 2009-05-12 17:51 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-07 08:49 . 2009-04-30 22:03 6756632 ----a-w- c:\windows\system32\drivers\lvuvc.sys
2009-10-07 08:48 . 2009-04-30 22:02 539160 ------w- c:\windows\system32\LVUI2RC.dll
2009-10-07 08:48 . 2009-04-30 22:02 539160 ------w- c:\windows\system32\LVUI2.dll
2009-10-07 08:47 . 2009-04-30 22:01 266008 ----a-w- c:\windows\system32\drivers\lvrs.sys
2009-10-07 08:43 . 2009-04-30 21:57 416280 ----a-w- c:\windows\system32\LVCodec2.dll
2009-10-07 08:25 . 2009-04-30 21:40 266828 ----a-w- c:\windows\system32\drivers\LVAFT.cfg
2009-10-07 08:24 . 2009-04-30 21:39 34068 ----a-w- c:\windows\system32\Repository.reg
2009-10-07 00:46 . 2009-10-07 00:46 25752 ----a-w- c:\windows\system32\drivers\LVPr2Mon.sys
2009-10-07 00:25 . 2009-10-07 00:25 85302 ----a-w- c:\windows\system32\drivers\LVFeL102.cfg
2009-10-07 00:25 . 2009-10-07 00:25 69592 ----a-w- c:\windows\system32\drivers\LVFaL100.cfg
2009-10-07 00:25 . 2009-10-07 00:25 227172 ----a-w- c:\windows\system32\drivers\LVFeL100.cfg
2009-10-07 00:25 . 2009-10-07 00:25 146680 ----a-w- c:\windows\system32\drivers\LVFeL101.cfg
2009-10-07 00:23 . 2009-10-07 00:23 13584 ----a-w- c:\windows\system32\drivers\iKeyLFT2.dll
2009-10-06 00:52 . 2009-09-29 15:20 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-06 00:52 . 2009-09-29 15:20 2373712 ----a-w- c:\windows\system32\pbsvc.exe
2009-10-01 16:21 . 2009-10-01 16:21 -------- d-----w- c:\programmi\PDF Suite
2009-09-29 15:20 . 2009-09-29 15:20 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\id Software
2009-09-26 23:24 . 2009-09-26 23:24 -------- d-----w- c:\programmi\Avira
2009-09-26 23:24 . 2009-09-26 23:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-09-25 17:41 . 2009-09-25 17:41 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-09-25 17:41 . 2009-09-25 17:41 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-09-25 17:41 . 2009-09-25 17:41 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-09-25 17:41 . 2009-09-25 17:41 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-09-25 17:41 . 2009-09-25 17:41 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-09-25 17:41 . 2009-09-25 17:41 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-09-25 17:41 . 2009-09-25 17:41 696320 ----a-w- c:\windows\system32\DivX.dll
2009-09-11 15:17 . 2004-08-19 04:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 22:03 . 2004-08-19 04:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 21:38 . 2009-08-29 18:44 192673 ----a-w- c:\windows\hpwins20.dat
2009-09-01 21:32 . 2009-09-01 21:29 101580 ----a-w- c:\windows\hpqins01.dat
2009-09-01 21:22 . 2009-09-01 21:17 99379 ----a-w- c:\windows\hpqins11.dat
2009-08-30 17:07 . 2009-08-30 17:03 134899 ----a-w- c:\windows\hpqins00.dat
2009-08-29 08:56 . 2004-08-19 04:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 22:34 . 2009-08-26 22:32 40960 ----a-w- c:\windows\DelPiv.exe
2009-08-26 09:00 . 2004-08-19 04:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2008-01-16 17:40 . 2008-01-16 17:40 1256519 ----a-w- c:\programmi\wrar371it.exe
2006-11-02 21:56 . 2008-02-10 21:08 64000 --sha-w- c:\windows\BricoPacks\SysFiles\71_wmplayer.exe
.
------- Sigcheck -------
[-] 2008-04-14 . 6DC43081C760EEC1130D2C8C145DF375 . 549888 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[7] 2008-04-14 . 9259170D29B5A256735FCB8B80280857 . 510464 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe
[-] 2008-04-14 . 6DC43081C760EEC1130D2C8C145DF375 . 549888 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2004-08-19 . E6F62282EBAA63BA07FA2DC7198B8D0D . 544256 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-04-14 . 663E53939024F3DFBAF00CF44E122898 . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
[7] 2008-04-14 . 10AA0E13B4D20EE798E3382C9B89B3E3 . 617472 . . [5.82] . . c:\windows\VistaMizer\old\comctl32.dll
[-] 2008-04-14 . 663E53939024F3DFBAF00CF44E122898 . 724992 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2006-08-25 . DC57C1C5D7C651079754D2A6EF247F97 . 724992 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll
[7] 2004-08-19 . 0FE5F5912C30795C455A9645970E6C7C . 611328 . . [5.82] . . c:\windows\$NtUninstallKB923191$\comctl32.dll
[-] 2008-04-14 . 70B14F74A77121FB970692BBAFF64748 . 1554944 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[7] 2008-04-14 . 70D7F99D95615C3C278367756287DB71 . 1036288 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe
[-] 2008-04-14 . 70B14F74A77121FB970692BBAFF64748 . 1554944 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 21B69AA06FCE941009A3C58DC8E94A5E . 1554432 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2007-06-13 . B4E85805BE6D23DE697F7B3BA7492D0B . 1035776 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[7] 2004-08-19 . 178D42BD8FC34A9837417A6CE1D6BB7B . 1034752 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
[-] 2008-04-14 . 91B6AAC828F8BBE1796275424E44DFB0 . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[7] 2008-04-14 . F53CDDEF33A4C41336A782BE3D170158 . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe
[-] 2008-04-14 . 91B6AAC828F8BBE1796275424E44DFB0 . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2004-08-19 . 40DE117B6CCFC031D2DC8B73D82020CF . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1FB2F9A-D35E-11DD-8935-E46A56D89593}]
2009-05-08 19:00 86016 ----a-w- c:\programmi\oovootb\oovoodx.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A1FB2F9A-D35E-11DD-8935-E46A56D89593}"= "c:\programmi\oovootb\oovoodx.dll" [2009-05-08 86016]
[HKEY_CLASSES_ROOT\clsid\{a1fb2f9a-d35e-11dd-8935-e46a56d89593}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoftAuto.exe"="c:\programmi\Creative\Software Update 3\SoftAuto.exe" [2008-08-13 405504]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-29 68856]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Logitech Vid"="c:\programmi\Logitech\Logitech Vid\Vid.exe" [2009-07-16 5458704]
"L09IXLRD_36520531"="c:\programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" [2009-03-02 351000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 25088]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-01-09 589824]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 397312]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-01-17 344064]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-10-28 141600]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"SmartDefrag"="c:\programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2009-07-02 2453264]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 25088]
c:\documents and settings\m…\Menu Avvio\Programmi\Esecuzione automatica\
Logitech . Registrazione prodotti.lnk - c:\programmi\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]
c:\documents and settings\m…\Menu Avvio\Programmi\Esecuzione automatica\
Logitech . Registrazione prodotti.lnk - c:\programmi\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]
c:\documents and settings\m…\Menu Avvio\Programmi\Esecuzione automatica\
Logitech . Registrazione prodotti.lnk - c:\programmi\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
McAfee Security Scan.lnk - c:\programmi\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
c:\documents and settings\m…\Menu Avvio\Programmi\Esecuzione automatica\
Logitech . Registrazione prodotti.lnk - c:\programmi\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\AIUTAMICI\\emule\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\System32\\mmc.exe"=
"c:\\Programmi\\TavoliVerdi\\TVControllo.exe"=
"c:\\Programmi\\TavoliVerdi\\TavoliVerdi.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\WINDOWS\\System32\\PnkBstrA.exe"=
"c:\\WINDOWS\\System32\\PnkBstrB.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\ooVoo\\ooVoo.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Logitech\\Logitech Vid\\Vid.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:Porta TCP ooVoo 443
"443:UDP"= 443:UDP:Porta UDP ooVoo 443
"37674:TCP"= 37674:TCP:Porta TCP ooVoo 37674
"37674:UDP"= 37674:UDP:Porta UDP ooVoo 37674
"37675:UDP"= 37675:UDP:Porta UDP ooVoo 37675
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [26/05/2009 10.51.09 54752]
S3 CTUPnPSv;Creative Centrale Media Server;c:\programmi\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 13.42.56 64000]
S3 fsssvc;Servizio Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22.48.42 704864]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - CLASSPNP_2
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-11-19 c:\windows\Tasks\User_Feed_Synchronization-{4AE8DE49-15B5-4E86-ACBE-7E62B19C30DB}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
2009-11-08 c:\windows\Tasks\SmartDefrag.job
- c:\programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-11-03 08:22]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Sample Toolband Serach - c:\windows\system32\ToolBand.dll/MENUSEARCH.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {4DC71BCD-FC34-4C57-A152-809E252F9966} = 192.168.1.1
FF - ProfilePath - c:\documents and settings\mà\Dati applicazioni\Mozilla\Firefox\Profiles\33rv1nkz.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it
FF - prefs.js: keyword.URL - hxxp://urlseek40.vmn.net/search.php?lg=en&type=dns&tbn=oovoo2_0dn&q=
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSeymour.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-bqxmshod - c:\documents and settings\mà\impostazioni locali\dati applicazioni\bqxmshod.exe
AddRemove-bqxmshod - c:\documents and settings\mà\impostazioni locali\dati applicazioni\bqxmshod.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-19 02:13
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spvs.sys >>UNKNOWN [0x8AAB5938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba16cf28
\Driver\ACPI -> ACPI.sys @ 0xb9e66cb8
\Driver\atapi -> atapi.sys @ 0xb9e03b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
SecurityProcedure -> ntkrnlpa.exe @ 0x80583d4a
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
SecurityProcedure -> ntkrnlpa.exe @ 0x80583d4a
NDIS: Intel(R) PRO/Wireless 3945ABG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xb9d1dbb0
PacketIndicateHandler -> NDIS.sys @ 0xb9d2aa21
SendHandler -> NDIS.sys @ 0xb9d0887b
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netatapi.sys @ 0x0 0x0 bytes
\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xB9E03B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xB9E03B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xB9E03B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xB9E03B40 atapi.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xB9E03B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xB9E03B40 atapi.sys
\Driver\atapi IRP hooks detected !
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-3401816449-2844666022-282875758-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E9E33D1A-13DE-B4ED-0179-8AA2A4860AB5}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140710900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"01400E0900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140A10900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140810900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140910900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140AC0900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140210900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140B10900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140610900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(936)
c:\windows\system32\SETUPAPI.dll
- - - - - - - > 'explorer.exe'(160)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\LINKINFO.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\acer\Empowering Technology\admServ.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Creative\Shared Files\CTDevSrv.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wbem\unsecapp.exe
c:\programmi\File comuni\Logishrd\LQCVFX\COCIManager.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\HP\Digital Imaging\bin\hpqSTE08.exe
c:\programmi\HP\Digital Imaging\bin\hpqbam08.exe
.
**************************************************************************
.
Ora fine scansione: 2009-11-19 02:16 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-11-19 01:16
Pre-Run: 10.184.523.776 byte disponibili
Post-Run: 10.782.769.152 byte disponibili
- - End Of File - - 985FEA0B585CA14DA8334610F915FD26
Una precisazione: dopo il riavvio il mouse nn è entrato in funzione...come mai?
Se hai tempo e voglia mi piacerebbe capire cosa ho fatto e perchè, nel senso di comprendere il senso del report
per quello che posso...Grazie per la pazienza e per il tempo dedicato.