Eseguito combofix ed ecco il log:
ComboFix 10-03-12.04 - agostino 13/03/2010 12.59.48.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2558.1980 [GMT 1:00]
Eseguito da: c:\documents and settings\agostino\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Outpost Firewall *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\LOG.TXT
c:\windows\AUTOLNCH.REG
c:\windows\system32\drivers\isvfihwkueci.sys
c:\windows\system32\muzapp.exe
La copia infetta di c:\windows\system32\midimap.dll è stata trovata e disinfettata
ipristinata copia da - c:\windows\VistaMizer\old\midimap.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
-------\Legacy_isvfihwkueci
-------\Service_isvfihwkueci
((((((((((((((((((((((((( Files Creati Da 2010-02-13 al 2010-03-13 )))))))))))))))))))))))))))))))))))
.
2010-03-12 19:23 . 2010-03-12 19:23 -------- d-----w- c:\documents and settings\agostino\Dati applicazioni\Nero
2010-03-10 09:51 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-04 19:26 . 2010-02-23 12:03 253952 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Mozilla\Firefox\Profiles\3h6ti7k2.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
2010-02-17 08:39 . 2010-02-17 08:39 -------- d-----w- c:\programmi\TeraCopy
2010-02-16 15:12 . 2009-11-10 23:08 180224 ----a-w- c:\windows\system32\QTCF.dll
2010-02-15 08:11 . 2010-02-15 08:11 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-02-14 08:13 . 2010-02-14 08:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Panda Security
2010-02-14 08:13 . 2010-02-14 08:13 -------- d-----w- c:\programmi\Panda USB Vaccine
2010-02-13 12:50 . 2010-02-13 13:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\KidCoaster
2010-02-13 12:44 . 2010-02-13 12:48 -------- d-----w- c:\programmi\Software Informer
2010-02-12 15:23 . 2010-03-09 11:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-12 15:23 . 2010-03-09 11:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-12 15:23 . 2010-03-09 11:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-12 15:23 . 2010-03-09 11:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-12 15:23 . 2010-03-09 11:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-12 15:23 . 2010-03-09 11:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-12 15:23 . 2010-03-09 11:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-12 15:23 . 2010-03-09 11:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-12 15:23 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-12 15:23 . 2010-02-12 15:23 -------- d-----w- c:\programmi\Alwil Software
2010-02-12 15:23 . 2010-02-12 15:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Alwil Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-13 12:21 . 2009-03-07 18:11 1616017440 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-03-13 12:18 . 2007-09-26 16:34 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000000-00000000-0000000C-00001102-00000004-20021102}.dat
2010-03-13 12:18 . 2007-09-26 16:34 384 ----a-w- c:\windows\system32\DVCState-{00000000-00000000-0000000C-00001102-00000004-20021102}.dat
2010-03-13 12:18 . 2009-03-07 18:11 18940460 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-03-13 08:47 . 2008-08-22 11:25 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-03-12 19:23 . 2007-09-26 17:41 -------- d-----w- c:\programmi\Nero
2010-03-12 18:56 . 2009-08-12 11:43 -------- d-----w- c:\programmi\SpywareBlaster
2010-03-12 07:22 . 2010-01-09 14:52 -------- d-----w- c:\documents and settings\agostino\Dati applicazioni\Simple Adblock
2010-03-11 17:33 . 2008-12-08 18:44 -------- d-----w- c:\documents and settings\agostino\Dati applicazioni\TeraCopy
2010-03-11 08:29 . 2010-02-01 10:58 -------- d-----w- c:\documents and settings\agostino\Dati applicazioni\vlc
2010-03-10 10:21 . 2007-09-26 17:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-03-05 08:05 . 2010-03-05 08:05 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-27 07:19 . 2008-12-02 12:47 -------- d-----r- c:\programmi\Skype
2010-02-26 10:18 . 2008-10-18 12:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2010-02-26 10:08 . 2008-10-18 12:39 -------- d-----w- c:\documents and settings\agostino\Dati applicazioni\skypePM
2010-02-26 09:46 . 2001-08-31 11:00 80268 ----a-w- c:\windows\system32\perfc010.dat
2010-02-26 09:46 . 2001-08-31 11:00 481664 ----a-w- c:\windows\system32\perfh010.dat
2010-02-25 17:04 . 2010-01-18 16:09 -------- d-----w- c:\programmi\CCleaner
2010-02-24 09:24 . 2008-11-14 12:36 -------- d-----w- c:\programmi\Innovative Solutions
2010-02-16 15:12 . 2009-10-11 14:57 -------- d-----w- c:\programmi\QuickTime Alternative
2010-02-15 17:14 . 2009-09-21 18:28 -------- d-----w- c:\programmi\Defraggler
2010-02-03 11:58 . 2009-01-26 09:24 -------- d-----w- c:\programmi\Photocopier
2010-02-03 06:54 . 2010-02-03 06:54 -------- d-----w- c:\programmi\FileHippo.com
2010-01-25 19:39 . 2010-01-25 19:39 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
2010-01-24 20:12 . 2010-01-24 20:12 503808 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a20f565-n\msvcp71.dll
2010-01-24 20:12 . 2010-01-24 20:12 499712 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a20f565-n\jmc.dll
2010-01-24 20:12 . 2010-01-24 20:12 348160 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a20f565-n\msvcr71.dll
2010-01-24 20:08 . 2010-01-24 20:08 61440 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3b3ffbb8-n\decora-sse.dll
2010-01-24 20:08 . 2010-01-24 20:08 12800 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3b3ffbb8-n\decora-d3d.dll
2010-01-23 07:39 . 2010-01-23 07:39 -------- d-----w- c:\programmi\MRU-Blaster
2010-01-23 07:38 . 2010-01-23 07:37 -------- d-----w- c:\programmi\Disk Cleaner
2010-01-23 07:31 . 2010-01-23 07:31 -------- d-----w- c:\documents and settings\agostino\Dati applicazioni\Systenance
2010-01-23 07:30 . 2010-01-23 07:30 -------- d-----w- c:\programmi\Index.dat Analyzer
2010-01-22 08:27 . 2009-10-10 09:16 -------- d-----w- c:\programmi\ThreatFire
2010-01-21 10:03 . 2008-11-06 07:08 -------- d-----w- c:\documents and settings\agostino\Dati applicazioni\dvdcss
2010-01-21 07:03 . 2007-09-26 16:29 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-01-21 07:03 . 2009-05-24 10:57 -------- d-----w- c:\programmi\Samsung
2010-01-20 08:34 . 2009-06-30 13:11 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-01-20 08:10 . 2010-01-20 08:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\F-Secure
2010-01-19 06:51 . 2009-08-25 08:17 -------- d-----w- c:\programmi\AviSynth 2.5
2010-01-16 13:50 . 2010-01-16 13:48 -------- d-----w- c:\documents and settings\agostino\Dati applicazioni\PhotoFiltre
2010-01-15 08:22 . 2010-01-15 08:22 348160 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-7deaf636-n\msvcr71.dll
2010-01-15 08:22 . 2010-01-15 08:22 503808 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-7deaf636-n\msvcp71.dll
2010-01-15 08:22 . 2010-01-15 08:22 499712 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-7deaf636-n\jmc.dll
2010-01-15 08:22 . 2010-01-15 08:22 61440 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-7deaf636-n\decora-sse.dll
2010-01-15 08:22 . 2010-01-15 08:22 12800 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-7deaf636-n\decora-d3d.dll
2010-01-15 08:22 . 2010-01-15 08:22 114688 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-33290bd3-n\jogl_cg.dll
2010-01-15 08:22 . 2010-01-15 08:22 315392 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-33290bd3-n\jogl.dll
2010-01-15 08:22 . 2010-01-15 08:22 20480 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-33290bd3-n\jogl_awt.dll
2010-01-15 08:22 . 2010-01-15 08:22 20480 ----a-w- c:\documents and settings\agostino\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\45\4f710eed-36764fa0-n\gluegen-rt.dll
2010-01-15 08:22 . 2008-08-09 18:24 -------- d-----w- c:\programmi\File comuni\Java
2010-01-15 08:21 . 2008-12-08 14:56 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-15 08:21 . 2010-01-15 08:21 -------- d-----w- c:\programmi\Java
2010-01-14 23:08 . 2010-01-14 22:46 59664 ----a-w- c:\windows\system32\drivers\TfSysMon.sys
2010-01-14 23:08 . 2010-01-14 22:46 33552 ----a-w- c:\windows\system32\drivers\TfNetMon.sys
2010-01-14 23:08 . 2010-01-14 22:45 51984 ----a-w- c:\windows\system32\drivers\TfFsMon.sys
2010-01-13 17:15 . 2010-01-13 16:58 -------- d-----w- c:\programmi\Real
2010-01-13 17:06 . 2009-07-09 09:42 -------- d-----w- c:\programmi\File comuni\Real
2010-01-13 13:58 . 2007-09-26 17:14 -------- d-----w- c:\programmi\File comuni\Adobe
2010-01-08 08:01 . 2009-12-31 07:06 5115824 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-07 15:07 . 2009-12-15 16:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-12-15 16:21 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 16:38 . 2007-09-26 17:30 76960 ----a-w- c:\documents and settings\agostino\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-12-31 16:50 . 2007-01-03 10:51 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:06 . 2007-01-03 10:56 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 07:40 . 2007-09-26 16:20 346112 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-19 13:39 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteCenter"="c:\programmi\Creative\MediaSource\RemoteControl\RCMan.EXE" [2003-10-08 139264]
"FileHippo.com"="c:\programmi\FileHippo.com\UpdateChecker.exe" [2010-03-03 155648]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 25088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\programmi\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"CTDVDDET"="c:\programmi\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-17 45056]
"CTHelper"="CTHELPER.EXE" [2003-10-06 24576]
"SBDrvDet"="c:\programmi\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 339968]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"ISUSPM Startup"="c:\progra~1\FILECO~1\INSTAL~1\updateservice\isuspm.exe" [2004-06-14 221184]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"ThreatFire"="c:\programmi\ThreatFire\TFTray.exe" [2010-01-14 378128]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-01-11 246504]
"SMSTray"="c:\programmi\Samsung\EmoDio\SMSTray.exe" [2009-10-08 479232]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 25088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-08 128512]
c:\documents and settings\agostino\Menu Avvio\Programmi\Esecuzione automatica\
MRU-Blaster Scheduler.lnk - c:\programmi\MRU-Blaster\scheduler.exe [2003-7-19 118784]
MRU-Blaster Silent Clean.lnk - c:\programmi\MRU-Blaster\mrublaster.exe [2004-3-28 1216512]
Secunia PSI.lnk - c:\programmi\Secunia\PSI\psi.exe [2009-8-21 900816]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Pinnacle Scheduler.lnk - c:\programmi\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe [2007-9-27 245760]
PrintAndFax.lnk - c:\programmi\Fastweb\PrintAndFax\FaxMonitor.exe [2005-11-3 970856]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [20/05/2008 8.32.40 15328]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [14/01/2010 23.45.54 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [14/01/2010 23.46.02 59664]
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [11/08/2004 17.22.54 77312]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [12/02/2010 16.23.35 162640]
R1 is-QVPF3drv;is-QVPF3drv;c:\windows\system32\drivers\38729904.sys [07/03/2009 19.10.59 148496]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [04/10/2009 9.44.03 704384]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [04/10/2009 9.42.37 1195008]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/02/2010 16.23.35 19024]
R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\PfModNT.sys [26/09/2007 17.28.18 15840]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\programmi\Macrium\Reflect\ReflectService.exe [25/08/2009 11.16.36 220128]
R2 ThreatFire;ThreatFire;c:\programmi\ThreatFire\TFService.exe service --> c:\programmi\ThreatFire\TFService.exe service [?]
R3 3xHybrid;Pinnacle PCTV Stereo service;c:\windows\system32\drivers\3xHybrid.sys [26/09/2007 17.56.01 698368]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [04/10/2009 9.42.42 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [04/10/2009 9.43.57 257432]
R3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [26/09/2007 18.07.59 44544]
R3 pctvvbi;PCTVVBI;c:\windows\system32\drivers\pctvvbi.sys [26/09/2007 18.11.17 6400]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [17/06/2009 13.20.34 12648]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [14/01/2010 23.46.08 33552]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys --> c:\windows\system32\Drivers\avgldx86.sys [?]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys --> c:\windows\system32\Drivers\avgtdix.sys [?]
S2 avg9wd;AVG Free WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe --> c:\programmi\AVG\AVG9\avgwdsvc.exe [?]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\agostino\IMPOST~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys --> c:\docume~1\agostino\IMPOST~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [?]
S3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\drivers\SIVX32.sys [02/03/2009 13.17.03 49632]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
2010-03-13 c:\windows\Tasks\PandaUSBVaccine.job
- c:\programmi\Panda USB Vaccine\RunInteractiveWin.exe [2010-02-14 15:45]
2010-03-13 c:\windows\Tasks\User_Feed_Synchronization-{A6A01747-FD5F-45F8-86D4-862341F42BC4}.job
- c:\windows\system32\msfeedssync.exe [2007-01-03 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.speedapps.com/search.htm
IE: &Clean Traces
IE: &Download with &DAP
IE: Download &all with DAP
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Scarica con Download &Express - c:\programmi\Download Express\Add_Url.htm
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
FF - ProfilePath - c:\documents and settings\agostino\Dati applicazioni\Mozilla\Firefox\Profiles\3h6ti7k2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - plugin: c:\documents and settings\agostino\Dati applicazioni\Mozilla\Firefox\Profiles\3h6ti7k2.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-13 13:20
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThreatFire]
"AlternateImagePath"=""
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(2036)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\cscui.dll
c:\programmi\ThreatFire\TFNI.dll
c:\programmi\ThreatFire\TFMon.dll
c:\programmi\ThreatFire\TFRK.dll
c:\programmi\ThreatFire\TFWAH.dll
- - - - - - - > 'lsass.exe'(288)
c:\windows\system32\scecli.dll
c:\windows\system32\SETUPAPI.dll
c:\programmi\ThreatFire\TFWAH.dll
- - - - - - - > 'explorer.exe'(3760)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\programmi\ThreatFire\TfWah.dll
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\LINKINFO.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\programmi\ThreatFire\TFNI.dll
c:\programmi\ThreatFire\TFMon.dll
c:\programmi\ThreatFire\TFRK.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\eappcfg.dll
c:\windows\system32\MSVCP60.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Alwil Software\Avast5\AvastSvc.exe
c:\programmi\Panda USB Vaccine\USBVaccine.exe
c:\windows\system32\CTsvcCDA.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\rnamfler\naofsvc.exe
c:\programmi\ThreatFire\TFService.exe
c:\windows\system32\MsPMSPSv.exe
.
**************************************************************************
.
Ora fine scansione: 2010-03-13 13:33:59 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-03-13 12:33
Pre-Run: 26.087.788.544 byte disponibili
Post-Run: 26.072.461.312 byte disponibili
- - End Of File - - 5C617720172B6E4DFD69A90F4AC85757
Attendo ordine di disinstallazione combofix ed altre istruzioni.
Salutoni..