@R16
ti chiedo scusa, ieri ero cosi felice di esserci riuscita, non ho controllato di mandarne un solo pezzetto.
Questa è la schermata finale ...spero vada bene.
Grazie per la tua attenzione e pazienza.
ComboFix 10-11-07.04 - xxxxxxxx 08/11/2010 9.39.52.2.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1918.1435 [GMT 1:00]
Eseguito da: c:\documents and settings\xxxxxxxx\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_npf
((((((((((((((((((((((((( Files Creati Da 2010-10-08 al 2010-11-08 )))))))))))))))))))))))))))))))))))
.
2010-11-08 08:35 . 2010-11-08 08:35 -------- d-----w- C:\FOUND.000
2010-11-07 17:46 . 2010-11-07 17:46 -------- d-----w- C:\AVGTemp
2010-11-04 20:09 . 2010-11-04 20:09 -------- d-sh--w- c:\documents and settings\xxxxxxxx\IECompatCache
2010-11-04 13:39 . 2010-11-04 13:39 -------- d-sh--w- c:\documents and settings\xxxxxxxx\PrivacIE
2010-11-04 13:37 . 2010-11-04 13:37 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-11-04 13:36 . 2010-11-04 13:37 -------- d-sh--w- c:\documents and settings\xxxxxxxx\IETldCache
2010-11-04 13:29 . 2010-11-04 13:29 -------- d--h--w- c:\windows\ie8
2010-11-04 13:23 . 2010-08-26 11:08 13312 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-11-04 13:22 . 2010-09-10 05:49 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-11-04 13:22 . 2010-09-10 05:49 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-11-04 13:22 . 2010-09-10 05:49 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2010-11-02 18:19 . 2010-11-02 18:19 -------- d-----w- c:\documents and settings\xxxxxxxx\Impostazioni locali\Dati applicazioni\Conduit
2010-11-02 18:19 . 2010-11-02 18:19 -------- d-----w- c:\programmi\Conduit
2010-11-02 18:19 . 2010-11-02 18:19 -------- d-----w- c:\documents and settings\xxxxxxxx\Impostazioni locali\Dati applicazioni\PHPNukeIT
2010-11-02 18:19 . 2010-11-02 18:19 -------- d-----w- c:\programmi\File comuni\eSellerate
2010-11-02 18:18 . 2010-11-02 18:18 -------- d-----w- c:\programmi\PHPNukeIT
2010-11-02 18:18 . 2010-11-02 18:18 -------- d-----w- C:\E-Zsoft
2010-10-17 16:57 . 2004-08-19 04:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-17 16:25 . 2010-10-17 16:25 -------- d-----w- c:\programmi\File comuni\Adobe
2010-10-17 15:26 . 2010-09-18 07:53 974848 ------w- c:\windows\system32\dllcache\mfc42.dll
2010-10-17 15:26 . 2010-09-18 07:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-17 15:26 . 2010-08-23 17:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 11:23 . 2004-08-19 04:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 07:53 . 2004-08-19 04:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 07:53 . 2004-08-19 04:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 07:53 . 2004-08-19 04:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:49 . 2006-01-09 19:01 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:49 . 2004-08-19 04:00 43520 ------w- c:\windows\system32\licmgr10.dll
2010-09-10 05:49 . 2004-08-19 04:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-01 12:51 . 2004-08-19 04:00 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 08:54 . 2004-08-19 04:00 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 09:02 . 2004-08-19 04:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 06:58 . 2004-08-19 04:00 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 02:43 . 2008-05-05 06:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 14:39 . 2004-08-19 04:00 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 17:12 . 2004-08-19 04:00 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 14:17 . 2004-08-19 04:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 09:44 . 2004-08-19 04:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}"= "c:\programmi\PHPNukeIT\tbPHP1.dll" [2010-11-02 3908192]
[HKEY_CLASSES_ROOT\clsid\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
2010-11-02 19:55 3908192 ----a-w- c:\programmi\PHPNukeIT\tbPHP1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-02 19:55 3908192 ----a-w- c:\programmi\ConduitEngine\ConduitEngin0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}"= "c:\programmi\PHPNukeIT\tbPHP1.dll" [2010-11-02 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\programmi\ConduitEngine\ConduitEngin0.dll" [2010-11-02 3908192]
[HKEY_CLASSES_ROOT\clsid\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{2C965F3F-8EFD-4BFC-A2C5-1672845FDBBF}"= "c:\programmi\PHPNukeIT\tbPHP1.dll" [2010-11-02 3908192]
[HKEY_CLASSES_ROOT\clsid\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-08 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\programmi\Realtek\InstallShield\AzMixerSel.exe" [2006-04-14 53248]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-27 16248320]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 413696]
"SMSTray"="c:\programmi\Samsung\EmoDio\SMSTray.exe" [2009-03-21 484888]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-10-17 2067808]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-20 13:01 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-02-08 06:50 68856 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\MSMSGS.EXE"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Java\\JRE6\\BIN\\java.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08/01/2010 13.16.25 216400]
R1 VD_FileDisk;VD_FileDisk;c:\windows\system32\drivers\vd_filedisk.sys [13/01/2006 14.00.52 15872]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys --> c:\windows\system32\eLock2BurnerLockDriver.sys [?]
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys --> c:\windows\system32\eLock2FSCTLDriver.sys [?]
S2 gupdate1c9ea07e20480b7;Servizio di Google Update (gupdate1c9ea07e20480b7);c:\programmi\Google\Update\GoogleUpdate.exe [10/06/2009 22.13.10 133104]
.
Contenuto della cartella 'Scheduled Tasks'
2010-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-10 21:12]
2010-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-10 21:12]
.
.
------- Scansione supplementare -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.libero.it/
uSearchURL,(Default) = hxxp://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-LaunchApp - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-11-08 09:45
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(648)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2836)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-11-08 09:47:44
ComboFix-quarantined-files.txt 2010-11-08 08:47
Pre-Run: 33.310.932.992 byte disponibili
Post-Run: 33.265.680.384 byte disponibili
- - End Of File - - C63B558D1D42B9ABB8143C18AD041E9F