Ho fatto quanto richiesto.
Grazie
ComboFix 10-06-16.03 - Ortopedia 17/06/2010 11.22.11.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.895.404 [GMT 2:00]
Eseguito da: c:\documents and settings\Ortopedia\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\RelevantKnowledge
c:\programmi\RelevantKnowledge\components\rlxg.dll
c:\programmi\RelevantKnowledge\install.rdf
c:\programmi\RelevantKnowledge\MSVCP71.DLL
c:\programmi\RelevantKnowledge\MSVCR71.DLL
c:\programmi\RelevantKnowledge\rlls.dll
c:\programmi\RelevantKnowledge\rlls64.dll
c:\programmi\RelevantKnowledge\rloci.bin
c:\programmi\RelevantKnowledge\rlph.dll
c:\programmi\RelevantKnowledge\rlservice.exe
c:\programmi\RelevantKnowledge\rlvknlg.exe
c:\programmi\RelevantKnowledge\rlvknlg64.exe
c:\programmi\RelevantKnowledge\rlxf.dll
c:\windows\system32\win.com
.
((((((((((((((((((((((((( Files Creati Da 2010-05-17 al 2010-06-17 )))))))))))))))))))))))))))))))))))
.
2010-06-04 10:41 . 2010-06-04 10:41 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-06-03 16:01 . 2010-06-17 09:22 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-03 15:23 . 2010-06-03 15:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DVD Shrink
2010-06-03 15:22 . 2010-06-03 15:23 -------- d-----w- c:\programmi\DVD Shrink
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-17 09:28 . 2008-10-20 12:58 65207328 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-06-17 09:28 . 2009-06-11 09:03 -------- d-----w- c:\documents and settings\Ortopedia\Dati applicazioni\uTorrent
2010-06-17 09:26 . 2008-10-20 12:58 688928 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-06-17 09:25 . 2008-10-20 12:58 882572 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-06-17 09:25 . 2008-10-20 12:58 72896 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-06-15 13:05 . 2010-03-13 19:52 -------- d-----w- c:\programmi\File comuni\Symantec Shared
2010-06-12 08:01 . 2008-10-20 12:58 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2010-06-10 01:05 . 2008-04-14 12:00 79292 ----a-w- c:\windows\system32\perfc010.dat
2010-06-10 01:05 . 2008-04-14 12:00 478808 ----a-w- c:\windows\system32\perfh010.dat
2010-06-03 15:59 . 2008-09-11 08:16 -------- d-----w- c:\programmi\S3
2010-06-02 14:15 . 2008-10-21 07:59 -------- d-----w- c:\programmi\UltraVNC
2010-06-02 14:15 . 2010-03-11 12:01 -------- d-----w- c:\programmi\Nokia
2010-06-02 14:12 . 2010-03-03 10:08 -------- d-----w- c:\programmi\File comuni\AVSMedia
2010-06-02 14:12 . 2010-03-03 10:08 -------- d-----w- c:\programmi\AVS4YOU
2010-05-23 10:15 . 2010-02-13 11:17 -------- d-----w- c:\programmi\ScarabeoDigital
2010-05-17 10:57 . 2010-05-17 10:57 -------- d-----w- c:\documents and settings\Ortopedia\Dati applicazioni\Lite
2010-05-14 11:33 . 2010-05-14 11:30 -------- d-----w- c:\programmi\MKV Player
2010-05-08 06:16 . 2008-10-20 12:58 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-05-08 06:16 . 2008-10-20 12:58 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-05-07 16:03 . 2010-05-07 16:03 -------- d-----w- c:\programmi\Norton Security Scan
2010-05-07 16:03 . 2010-03-13 19:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Norton
2010-05-07 16:03 . 2010-03-13 19:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NortonInstaller
2010-05-04 17:16 . 2008-04-14 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 17:15 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:15 . 2008-04-14 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-05-02 08:06 . 2008-04-14 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2008-04-14 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2009-01-22 07:06 . 2009-01-22 07:05 120 --sh--w- c:\windows\system32\ikudurey.tmp
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-02-15 39408]
"uTorrent"="c:\programmi\uTorrent\uTorrent.exe" [2009-06-11 272176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer" [X]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-31 16116224]
"SkyTel"="SkyTel.EXE" [2006-05-17 2879488]
"EPSON Stylus C62 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-04-10 74240]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-10-30 136600]
"TrueImageMonitor.exe"="c:\programmi\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-11-21 4371440]
"AcronisTimounterMonitor"="c:\programmi\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-11-21 961208]
"Acronis Scheduler2 Service"="c:\programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2008-11-21 165144]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-04-02 40368]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiapsrv.exe"=
"c:\\Programmi\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0 for Windows Workstations\\avp.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Programmi\\File comuni\\EPSON\\EBAPI\\SAgent2.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Programmi\\File comuni\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Programmi\\SICILIA SISTEMI TECNOLOGIE\\GESTIONE REPARTO\\Aggiorna.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:@xpsp2res.dll,-22002
R0 tdrpman147;Acronis Try&Decide and Restore Points filter (build 147);c:\windows\system32\drivers\tdrpm147.sys [15/02/2009 12.30.13 971584]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/05/2007 17.49.06 24344]
S0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys --> c:\windows\system32\drivers\pxscan.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [26/02/2010 19.09.02 38224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contenuto della cartella 'Scheduled Tasks'
2010-06-16 c:\windows\Tasks\Norton Security Scan for Ortopedia.job
- c:\programmi\Norton Security Scan\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-05-07 16:03]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
TCP: {C6EED09A-3F29-4747-9A80-2502EC4ED114} = 151.99.125.2,151.99.250.2
DPF: {15CAC53B-5F45-4D70-BE98-386E6F3B3328} - hxxp://192.168.0.200:8085/resources/medweb/MedstWWW.cab
DPF: {3BB4FE3B-7A37-11D3-A41E-0060080C03B3} - hxxp://193.205.23.35/vblu/NWWClientFull.cab
DPF: {4FEE6316-7B6F-4A6C-BD4E-4157C59A9E9D} - hxxp://static.s2g.gate5.de/ovi_maps/OviMapsPlugin_4.0.12.11.cab
DPF: {601B418B-E6A6-47FC-A094-07248741CEB3} - file:///D:/vwr_data/WebVwr.cab
DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} - file:///D:/CDVIEWER/CdViewer.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-VTTimer - VTTimer.exe
HKLM-Run-S3Trayp - S3trayp.exe
AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\programmi\RelevantKnowledge\rlvknlg.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-17 11:26
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1156)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(3812)
c:\windows\system32\WININET.dll
c:\progra~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\progra~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\MSCTF.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\Acronis\Schedule2\schedul2.exe
c:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
c:\programmi\File comuni\EPSON\EBAPI\SAgent2.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\RTHDCPL.EXE
c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
.
**************************************************************************
.
Ora fine scansione: 2010-06-17 11:29:56 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-06-17 09:29
ComboFix2.txt 2010-02-27 09:41
Pre-Run: 34.845.507.584 byte disponibili
Post-Run: 34.906.898.432 byte disponibili
- - End Of File - - 227DC19CDE4759CE2E451DC04A0145C0