r16 ha scritto:Vediamo cosa dice Combofix:
Scarica Combofix (usa
Internet Explorer)
http://download.bleepingcomputer.com/sUBs/ComboFix.exeSalvalo sul
desktop. (
è obligatorio)
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.
Doppio click su combofix.exe .
E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix)
tu ignorali.
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca
NO.
Durante l'operazione di scansione
è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt.
Postalo qui.
Ho tardato perchè ho avuto dei problemi: nonostante avessi disabilitato Outpost firewall e AVG, combofix continuava a dare avvisi per la presenza di AVG. Alla fine ho rimosso AVG (per scaricarlo nuovamente dopo l'uso di combofix). Poi riscontrava Antivir Desktop (non so neppure cosa sia), comunque dopo alcune disavventure ecco il file log:
ComboFix 11-02-15.04 - gabri 16/02/2011 14.13.29.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.503.226 [GMT 1:00]
Eseguito da: c:\documents and settings\gabri\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
FW: Outpost Firewall *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Creati Da 2011-01-16 al 2011-02-16 )))))))))))))))))))))))))))))))))))
.
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\documents and settings\gabri\Dati applicazioni\Auslogics
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\programmi\Auslogics
2011-02-07 13:59 . 2011-02-07 13:59 4646264 ----a-w- c:\programmi\disk-defrag-setup.exe
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-sh--w- c:\documents and settings\gabri\IECompatCache
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\TRADUTTORI
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\AIUTAMICI.COM
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\DIZIONARI INFORM
2011-02-06 11:23 . 2011-02-06 11:23 -------- d-sh--w- c:\documents and settings\gabri\PrivacIE
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\gabri\IETldCache
2011-02-06 11:12 . 2011-02-06 11:14 -------- dc-h--w- c:\windows\ie8
2011-02-06 11:09 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-06 11:09 . 2010-12-20 23:53 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-02-06 11:09 . 2010-12-20 23:53 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-02-06 11:08 . 2010-12-20 23:53 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-06 11:08 . 2010-12-20 23:53 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-02-06 11:08 . 2010-12-20 23:53 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-06 11:08 . 2010-12-20 23:53 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-06 11:08 . 2010-12-21 04:23 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-02-06 11:06 . 2011-02-06 11:05 16968544 ----a-w- c:\programmi\IE8-WindowsXP-x86-ITA.exe
2011-02-04 11:15 . 2011-02-04 11:15 388608 ----a-w- c:\programmi\HijackThis.exe
2011-01-21 14:44 . 2011-01-21 14:44 440832 -c----w- c:\windows\system32\dllcache\shimgvw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2009-11-25 10:20 440832 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2009-11-25 10:20 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2009-11-25 10:20 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-30 10:53 . 2009-11-25 10:05 17408 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-22 12:34 . 2009-11-25 10:20 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:53 . 2009-11-25 10:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:53 . 2009-11-25 10:20 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:53 . 2009-11-25 10:20 43520 ------w- c:\windows\system32\licmgr10.dll
2010-12-20 17:26 . 2009-11-25 10:20 735744 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2009-11-28 15:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-11-28 15:59 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2009-11-25 11:00 385024 ------w- c:\windows\system32\html.iec
2010-12-19 11:51 . 2010-12-19 11:50 2493933 ----a-w- c:\programmi\vsoDivxToDVD_setup.exe
2010-12-14 10:25 . 2010-12-14 10:25 10414088 ----a-w- c:\programmi\K-Lite_Codec_Pack_666_Standard.exe
2010-12-13 13:30 . 2010-12-13 13:17 153061304 ----a-w- c:\programmi\OOo_3.2.1_Win_x86_install-wJRE_it.exe
2010-12-13 11:10 . 2010-12-13 11:09 8399024 ----a-w- c:\programmi\Firefox Setup 3.6.13.exe
2010-12-09 15:15 . 2009-11-25 10:20 739840 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2009-11-25 10:20 2196480 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2009-11-25 10:20 2073088 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2009-11-25 10:20 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-11-19 12:43 . 2010-11-19 12:43 955272 ----a-w- c:\programmi\SkypeSetup.exe
2010-11-18 18:12 . 2009-11-25 10:20 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-18 13:31 . 2010-11-18 13:31 2811584 ----a-w- c:\programmi\ccsetup300.exe
2010-11-15 10:40 . 2010-11-18 13:20 19985265 ----a-w- c:\programmi\vlc-1.1.5-win32.exe
2009-11-29 15:07 . 2009-11-29 15:07 3738880 ----a-w- c:\programmi\FoxitReader30_enu_Setup.exe
2009-11-25 19:04 . 2009-11-25 19:04 4409491 ----a-w- c:\programmi\cdbxp_setup_4.2.7.1801.exe
2009-11-25 18:14 . 2009-11-25 18:14 25823304 ----a-w- c:\programmi\wmp11-windowsxp-x86-it-it.exe
2008-04-25 22:33 . 2009-11-25 11:13 323000872 ----a-w- c:\programmi\WINDOWSXP-KB936929-SP3-X86-ITA_2162c1d419d1e462a7dc34294528b2daf593302c.exe
2005-09-23 16:55 . 2009-11-25 11:10 23510720 ----a-w- c:\programmi\dotnetfx.exe
2005-05-04 23:24 . 2009-11-25 10:40 2585872 ----a-w- c:\programmi\WindowsInstaller-KB893803-v2-x86.exe
2004-08-20 02:26 . 2009-11-25 10:17 273229544 ------w- c:\programmi\WindowsXP-KB835935-SP2-ITA.exe
2003-02-21 21:37 . 2009-11-25 10:16 24265736 ------w- c:\programmi\dotnetfx_001.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-07-01 118784]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"CnxDslTaskBar"="c:\programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2009-11-25 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^gabri^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\gabri\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 14:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:14 1695232 ----a-w- c:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 15:49 14940040 ----a-r- c:\programmi\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [25/11/2009 12.49.50 704384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [25/11/2009 12.48.20 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [25/11/2009 12.49.32 257432]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [25/11/2009 13.34.53 60288]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [25/11/2009 13.34.53 646400]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [25/11/2009 13.34.53 108771]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [25/11/2009 12.48.19 1195008]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/11/2009 11.05.39 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Scansione supplementare -------
.
FF - ProfilePath - c:\documents and settings\gabri\Dati applicazioni\Mozilla\Firefox\Profiles\7fgwmzip.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-16 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2011-02-16 14:19:41
ComboFix-quarantined-files.txt 2011-02-16 13:19
Pre-Run: 68.519.919.616 byte disponibili
Post-Run: 68.509.491.200 byte disponibili
- - End Of File - - B21BA4516B4FCEDEBEDA259592ED1A34ComboFix 11-02-15.04 - gabri 16/02/2011 14.13.29.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.503.226 [GMT 1:00]
Eseguito da: c:\documents and settings\gabri\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
FW: Outpost Firewall *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Creati Da 2011-01-16 al 2011-02-16 )))))))))))))))))))))))))))))))))))
.
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\documents and settings\gabri\Dati applicazioni\Auslogics
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\programmi\Auslogics
2011-02-07 13:59 . 2011-02-07 13:59 4646264 ----a-w- c:\programmi\disk-defrag-setup.exe
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-sh--w- c:\documents and settings\gabri\IECompatCache
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\TRADUTTORI
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\AIUTAMICI.COM
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\DIZIONARI INFORM
2011-02-06 11:23 . 2011-02-06 11:23 -------- d-sh--w- c:\documents and settings\gabri\PrivacIE
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\gabri\IETldCache
2011-02-06 11:12 . 2011-02-06 11:14 -------- dc-h--w- c:\windows\ie8
2011-02-06 11:09 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-06 11:09 . 2010-12-20 23:53 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-02-06 11:09 . 2010-12-20 23:53 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-02-06 11:08 . 2010-12-20 23:53 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-06 11:08 . 2010-12-20 23:53 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-02-06 11:08 . 2010-12-20 23:53 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-06 11:08 . 2010-12-20 23:53 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-06 11:08 . 2010-12-21 04:23 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-02-06 11:06 . 2011-02-06 11:05 16968544 ----a-w- c:\programmi\IE8-WindowsXP-x86-ITA.exe
2011-02-04 11:15 . 2011-02-04 11:15 388608 ----a-w- c:\programmi\HijackThis.exe
2011-01-21 14:44 . 2011-01-21 14:44 440832 -c----w- c:\windows\system32\dllcache\shimgvw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2009-11-25 10:20 440832 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2009-11-25 10:20 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2009-11-25 10:20 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-30 10:53 . 2009-11-25 10:05 17408 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-22 12:34 . 2009-11-25 10:20 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:53 . 2009-11-25 10:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:53 . 2009-11-25 10:20 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:53 . 2009-11-25 10:20 43520 ------w- c:\windows\system32\licmgr10.dll
2010-12-20 17:26 . 2009-11-25 10:20 735744 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2009-11-28 15:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-11-28 15:59 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2009-11-25 11:00 385024 ------w- c:\windows\system32\html.iec
2010-12-19 11:51 . 2010-12-19 11:50 2493933 ----a-w- c:\programmi\vsoDivxToDVD_setup.exe
2010-12-14 10:25 . 2010-12-14 10:25 10414088 ----a-w- c:\programmi\K-Lite_Codec_Pack_666_Standard.exe
2010-12-13 13:30 . 2010-12-13 13:17 153061304 ----a-w- c:\programmi\OOo_3.2.1_Win_x86_install-wJRE_it.exe
2010-12-13 11:10 . 2010-12-13 11:09 8399024 ----a-w- c:\programmi\Firefox Setup 3.6.13.exe
2010-12-09 15:15 . 2009-11-25 10:20 739840 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2009-11-25 10:20 2196480 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2009-11-25 10:20 2073088 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2009-11-25 10:20 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-11-19 12:43 . 2010-11-19 12:43 955272 ----a-w- c:\programmi\SkypeSetup.exe
2010-11-18 18:12 . 2009-11-25 10:20 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-18 13:31 . 2010-11-18 13:31 2811584 ----a-w- c:\programmi\ccsetup300.exe
2010-11-15 10:40 . 2010-11-18 13:20 19985265 ----a-w- c:\programmi\vlc-1.1.5-win32.exe
2009-11-29 15:07 . 2009-11-29 15:07 3738880 ----a-w- c:\programmi\FoxitReader30_enu_Setup.exe
2009-11-25 19:04 . 2009-11-25 19:04 4409491 ----a-w- c:\programmi\cdbxp_setup_4.2.7.1801.exe
2009-11-25 18:14 . 2009-11-25 18:14 25823304 ----a-w- c:\programmi\wmp11-windowsxp-x86-it-it.exe
2008-04-25 22:33 . 2009-11-25 11:13 323000872 ----a-w- c:\programmi\WINDOWSXP-KB936929-SP3-X86-ITA_2162c1d419d1e462a7dc34294528b2daf593302c.exe
2005-09-23 16:55 . 2009-11-25 11:10 23510720 ----a-w- c:\programmi\dotnetfx.exe
2005-05-04 23:24 . 2009-11-25 10:40 2585872 ----a-w- c:\programmi\WindowsInstaller-KB893803-v2-x86.exe
2004-08-20 02:26 . 2009-11-25 10:17 273229544 ------w- c:\programmi\WindowsXP-KB835935-SP2-ITA.exe
2003-02-21 21:37 . 2009-11-25 10:16 24265736 ------w- c:\programmi\dotnetfx_001.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-07-01 118784]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"CnxDslTaskBar"="c:\programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2009-11-25 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^gabri^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\gabri\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 14:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:14 1695232 ----a-w- c:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 15:49 14940040 ----a-r- c:\programmi\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [25/11/2009 12.49.50 704384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [25/11/2009 12.48.20 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [25/11/2009 12.49.32 257432]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [25/11/2009 13.34.53 60288]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [25/11/2009 13.34.53 646400]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [25/11/2009 13.34.53 108771]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [25/11/2009 12.48.19 1195008]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/11/2009 11.05.39 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Scansione supplementare -------
.
FF - ProfilePath - c:\documents and settings\gabri\Dati applicazioni\Mozilla\Firefox\Profiles\7fgwmzip.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-16 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2011-02-16 14:19:41
ComboFix-quarantined-files.txt 2011-02-16 13:19
Pre-Run: 68.519.919.616 byte disponibili
Post-Run: 68.509.491.200 byte disponibili
- - End Of File - - B21BA4516B4FCEDEBEDA259592ED1A34ComboFix 11-02-15.04 - gabri 16/02/2011 14.13.29.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.503.226 [GMT 1:00]
Eseguito da: c:\documents and settings\gabri\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
FW: Outpost Firewall *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Creati Da 2011-01-16 al 2011-02-16 )))))))))))))))))))))))))))))))))))
.
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\documents and settings\gabri\Dati applicazioni\Auslogics
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\programmi\Auslogics
2011-02-07 13:59 . 2011-02-07 13:59 4646264 ----a-w- c:\programmi\disk-defrag-setup.exe
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-sh--w- c:\documents and settings\gabri\IECompatCache
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\TRADUTTORI
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\AIUTAMICI.COM
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\DIZIONARI INFORM
2011-02-06 11:23 . 2011-02-06 11:23 -------- d-sh--w- c:\documents and settings\gabri\PrivacIE
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\gabri\IETldCache
2011-02-06 11:12 . 2011-02-06 11:14 -------- dc-h--w- c:\windows\ie8
2011-02-06 11:09 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-06 11:09 . 2010-12-20 23:53 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-02-06 11:09 . 2010-12-20 23:53 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-02-06 11:08 . 2010-12-20 23:53 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-06 11:08 . 2010-12-20 23:53 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-02-06 11:08 . 2010-12-20 23:53 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-06 11:08 . 2010-12-20 23:53 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-06 11:08 . 2010-12-21 04:23 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-02-06 11:06 . 2011-02-06 11:05 16968544 ----a-w- c:\programmi\IE8-WindowsXP-x86-ITA.exe
2011-02-04 11:15 . 2011-02-04 11:15 388608 ----a-w- c:\programmi\HijackThis.exe
2011-01-21 14:44 . 2011-01-21 14:44 440832 -c----w- c:\windows\system32\dllcache\shimgvw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2009-11-25 10:20 440832 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2009-11-25 10:20 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2009-11-25 10:20 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-30 10:53 . 2009-11-25 10:05 17408 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-22 12:34 . 2009-11-25 10:20 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:53 . 2009-11-25 10:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:53 . 2009-11-25 10:20 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:53 . 2009-11-25 10:20 43520 ------w- c:\windows\system32\licmgr10.dll
2010-12-20 17:26 . 2009-11-25 10:20 735744 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2009-11-28 15:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-11-28 15:59 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2009-11-25 11:00 385024 ------w- c:\windows\system32\html.iec
2010-12-19 11:51 . 2010-12-19 11:50 2493933 ----a-w- c:\programmi\vsoDivxToDVD_setup.exe
2010-12-14 10:25 . 2010-12-14 10:25 10414088 ----a-w- c:\programmi\K-Lite_Codec_Pack_666_Standard.exe
2010-12-13 13:30 . 2010-12-13 13:17 153061304 ----a-w- c:\programmi\OOo_3.2.1_Win_x86_install-wJRE_it.exe
2010-12-13 11:10 . 2010-12-13 11:09 8399024 ----a-w- c:\programmi\Firefox Setup 3.6.13.exe
2010-12-09 15:15 . 2009-11-25 10:20 739840 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2009-11-25 10:20 2196480 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2009-11-25 10:20 2073088 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2009-11-25 10:20 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-11-19 12:43 . 2010-11-19 12:43 955272 ----a-w- c:\programmi\SkypeSetup.exe
2010-11-18 18:12 . 2009-11-25 10:20 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-18 13:31 . 2010-11-18 13:31 2811584 ----a-w- c:\programmi\ccsetup300.exe
2010-11-15 10:40 . 2010-11-18 13:20 19985265 ----a-w- c:\programmi\vlc-1.1.5-win32.exe
2009-11-29 15:07 . 2009-11-29 15:07 3738880 ----a-w- c:\programmi\FoxitReader30_enu_Setup.exe
2009-11-25 19:04 . 2009-11-25 19:04 4409491 ----a-w- c:\programmi\cdbxp_setup_4.2.7.1801.exe
2009-11-25 18:14 . 2009-11-25 18:14 25823304 ----a-w- c:\programmi\wmp11-windowsxp-x86-it-it.exe
2008-04-25 22:33 . 2009-11-25 11:13 323000872 ----a-w- c:\programmi\WINDOWSXP-KB936929-SP3-X86-ITA_2162c1d419d1e462a7dc34294528b2daf593302c.exe
2005-09-23 16:55 . 2009-11-25 11:10 23510720 ----a-w- c:\programmi\dotnetfx.exe
2005-05-04 23:24 . 2009-11-25 10:40 2585872 ----a-w- c:\programmi\WindowsInstaller-KB893803-v2-x86.exe
2004-08-20 02:26 . 2009-11-25 10:17 273229544 ------w- c:\programmi\WindowsXP-KB835935-SP2-ITA.exe
2003-02-21 21:37 . 2009-11-25 10:16 24265736 ------w- c:\programmi\dotnetfx_001.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-07-01 118784]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"CnxDslTaskBar"="c:\programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2009-11-25 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^gabri^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\gabri\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 14:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:14 1695232 ----a-w- c:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 15:49 14940040 ----a-r- c:\programmi\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [25/11/2009 12.49.50 704384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [25/11/2009 12.48.20 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [25/11/2009 12.49.32 257432]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [25/11/2009 13.34.53 60288]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [25/11/2009 13.34.53 646400]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [25/11/2009 13.34.53 108771]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [25/11/2009 12.48.19 1195008]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/11/2009 11.05.39 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Scansione supplementare -------
.
FF - ProfilePath - c:\documents and settings\gabri\Dati applicazioni\Mozilla\Firefox\Profiles\7fgwmzip.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-16 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2011-02-16 14:19:41
ComboFix-quarantined-files.txt 2011-02-16 13:19
Pre-Run: 68.519.919.616 byte disponibili
Post-Run: 68.509.491.200 byte disponibili
- - End Of File - - B21BA4516B4FCEDEBEDA259592ED1A34ComboFix 11-02-15.04 - gabri 16/02/2011 14.13.29.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.503.226 [GMT 1:00]
Eseguito da: c:\documents and settings\gabri\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
FW: Outpost Firewall *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Creati Da 2011-01-16 al 2011-02-16 )))))))))))))))))))))))))))))))))))
.
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\documents and settings\gabri\Dati applicazioni\Auslogics
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\programmi\Auslogics
2011-02-07 13:59 . 2011-02-07 13:59 4646264 ----a-w- c:\programmi\disk-defrag-setup.exe
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-sh--w- c:\documents and settings\gabri\IECompatCache
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\TRADUTTORI
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\AIUTAMICI.COM
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\DIZIONARI INFORM
2011-02-06 11:23 . 2011-02-06 11:23 -------- d-sh--w- c:\documents and settings\gabri\PrivacIE
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\gabri\IETldCache
2011-02-06 11:12 . 2011-02-06 11:14 -------- dc-h--w- c:\windows\ie8
2011-02-06 11:09 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-06 11:09 . 2010-12-20 23:53 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-02-06 11:09 . 2010-12-20 23:53 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-02-06 11:08 . 2010-12-20 23:53 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-06 11:08 . 2010-12-20 23:53 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-02-06 11:08 . 2010-12-20 23:53 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-06 11:08 . 2010-12-20 23:53 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-06 11:08 . 2010-12-21 04:23 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-02-06 11:06 . 2011-02-06 11:05 16968544 ----a-w- c:\programmi\IE8-WindowsXP-x86-ITA.exe
2011-02-04 11:15 . 2011-02-04 11:15 388608 ----a-w- c:\programmi\HijackThis.exe
2011-01-21 14:44 . 2011-01-21 14:44 440832 -c----w- c:\windows\system32\dllcache\shimgvw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2009-11-25 10:20 440832 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2009-11-25 10:20 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2009-11-25 10:20 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-30 10:53 . 2009-11-25 10:05 17408 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-22 12:34 . 2009-11-25 10:20 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:53 . 2009-11-25 10:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:53 . 2009-11-25 10:20 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:53 . 2009-11-25 10:20 43520 ------w- c:\windows\system32\licmgr10.dll
2010-12-20 17:26 . 2009-11-25 10:20 735744 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2009-11-28 15:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-11-28 15:59 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2009-11-25 11:00 385024 ------w- c:\windows\system32\html.iec
2010-12-19 11:51 . 2010-12-19 11:50 2493933 ----a-w- c:\programmi\vsoDivxToDVD_setup.exe
2010-12-14 10:25 . 2010-12-14 10:25 10414088 ----a-w- c:\programmi\K-Lite_Codec_Pack_666_Standard.exe
2010-12-13 13:30 . 2010-12-13 13:17 153061304 ----a-w- c:\programmi\OOo_3.2.1_Win_x86_install-wJRE_it.exe
2010-12-13 11:10 . 2010-12-13 11:09 8399024 ----a-w- c:\programmi\Firefox Setup 3.6.13.exe
2010-12-09 15:15 . 2009-11-25 10:20 739840 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2009-11-25 10:20 2196480 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2009-11-25 10:20 2073088 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2009-11-25 10:20 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-11-19 12:43 . 2010-11-19 12:43 955272 ----a-w- c:\programmi\SkypeSetup.exe
2010-11-18 18:12 . 2009-11-25 10:20 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-18 13:31 . 2010-11-18 13:31 2811584 ----a-w- c:\programmi\ccsetup300.exe
2010-11-15 10:40 . 2010-11-18 13:20 19985265 ----a-w- c:\programmi\vlc-1.1.5-win32.exe
2009-11-29 15:07 . 2009-11-29 15:07 3738880 ----a-w- c:\programmi\FoxitReader30_enu_Setup.exe
2009-11-25 19:04 . 2009-11-25 19:04 4409491 ----a-w- c:\programmi\cdbxp_setup_4.2.7.1801.exe
2009-11-25 18:14 . 2009-11-25 18:14 25823304 ----a-w- c:\programmi\wmp11-windowsxp-x86-it-it.exe
2008-04-25 22:33 . 2009-11-25 11:13 323000872 ----a-w- c:\programmi\WINDOWSXP-KB936929-SP3-X86-ITA_2162c1d419d1e462a7dc34294528b2daf593302c.exe
2005-09-23 16:55 . 2009-11-25 11:10 23510720 ----a-w- c:\programmi\dotnetfx.exe
2005-05-04 23:24 . 2009-11-25 10:40 2585872 ----a-w- c:\programmi\WindowsInstaller-KB893803-v2-x86.exe
2004-08-20 02:26 . 2009-11-25 10:17 273229544 ------w- c:\programmi\WindowsXP-KB835935-SP2-ITA.exe
2003-02-21 21:37 . 2009-11-25 10:16 24265736 ------w- c:\programmi\dotnetfx_001.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-07-01 118784]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"CnxDslTaskBar"="c:\programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2009-11-25 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^gabri^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\gabri\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 14:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:14 1695232 ----a-w- c:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 15:49 14940040 ----a-r- c:\programmi\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [25/11/2009 12.49.50 704384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [25/11/2009 12.48.20 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [25/11/2009 12.49.32 257432]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [25/11/2009 13.34.53 60288]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [25/11/2009 13.34.53 646400]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [25/11/2009 13.34.53 108771]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [25/11/2009 12.48.19 1195008]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/11/2009 11.05.39 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Scansione supplementare -------
.
FF - ProfilePath - c:\documents and settings\gabri\Dati applicazioni\Mozilla\Firefox\Profiles\7fgwmzip.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-16 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2011-02-16 14:19:41
ComboFix-quarantined-files.txt 2011-02-16 13:19
Pre-Run: 68.519.919.616 byte disponibili
Post-Run: 68.509.491.200 byte disponibili
- - End Of File - - B21BA4516B4FCEDEBEDA259592ED1A34ComboFix 11-02-15.04 - gabri 16/02/2011 14.13.29.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.503.226 [GMT 1:00]
Eseguito da: c:\documents and settings\gabri\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
FW: Outpost Firewall *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Creati Da 2011-01-16 al 2011-02-16 )))))))))))))))))))))))))))))))))))
.
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\documents and settings\gabri\Dati applicazioni\Auslogics
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\programmi\Auslogics
2011-02-07 13:59 . 2011-02-07 13:59 4646264 ----a-w- c:\programmi\disk-defrag-setup.exe
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-sh--w- c:\documents and settings\gabri\IECompatCache
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\TRADUTTORI
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\AIUTAMICI.COM
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\DIZIONARI INFORM
2011-02-06 11:23 . 2011-02-06 11:23 -------- d-sh--w- c:\documents and settings\gabri\PrivacIE
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\gabri\IETldCache
2011-02-06 11:12 . 2011-02-06 11:14 -------- dc-h--w- c:\windows\ie8
2011-02-06 11:09 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-06 11:09 . 2010-12-20 23:53 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-02-06 11:09 . 2010-12-20 23:53 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-02-06 11:08 . 2010-12-20 23:53 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-06 11:08 . 2010-12-20 23:53 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-02-06 11:08 . 2010-12-20 23:53 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-06 11:08 . 2010-12-20 23:53 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-06 11:08 . 2010-12-21 04:23 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-02-06 11:06 . 2011-02-06 11:05 16968544 ----a-w- c:\programmi\IE8-WindowsXP-x86-ITA.exe
2011-02-04 11:15 . 2011-02-04 11:15 388608 ----a-w- c:\programmi\HijackThis.exe
2011-01-21 14:44 . 2011-01-21 14:44 440832 -c----w- c:\windows\system32\dllcache\shimgvw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2009-11-25 10:20 440832 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2009-11-25 10:20 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2009-11-25 10:20 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-30 10:53 . 2009-11-25 10:05 17408 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-22 12:34 . 2009-11-25 10:20 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:53 . 2009-11-25 10:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:53 . 2009-11-25 10:20 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:53 . 2009-11-25 10:20 43520 ------w- c:\windows\system32\licmgr10.dll
2010-12-20 17:26 . 2009-11-25 10:20 735744 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2009-11-28 15:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-11-28 15:59 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2009-11-25 11:00 385024 ------w- c:\windows\system32\html.iec
2010-12-19 11:51 . 2010-12-19 11:50 2493933 ----a-w- c:\programmi\vsoDivxToDVD_setup.exe
2010-12-14 10:25 . 2010-12-14 10:25 10414088 ----a-w- c:\programmi\K-Lite_Codec_Pack_666_Standard.exe
2010-12-13 13:30 . 2010-12-13 13:17 153061304 ----a-w- c:\programmi\OOo_3.2.1_Win_x86_install-wJRE_it.exe
2010-12-13 11:10 . 2010-12-13 11:09 8399024 ----a-w- c:\programmi\Firefox Setup 3.6.13.exe
2010-12-09 15:15 . 2009-11-25 10:20 739840 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2009-11-25 10:20 2196480 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2009-11-25 10:20 2073088 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2009-11-25 10:20 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-11-19 12:43 . 2010-11-19 12:43 955272 ----a-w- c:\programmi\SkypeSetup.exe
2010-11-18 18:12 . 2009-11-25 10:20 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-18 13:31 . 2010-11-18 13:31 2811584 ----a-w- c:\programmi\ccsetup300.exe
2010-11-15 10:40 . 2010-11-18 13:20 19985265 ----a-w- c:\programmi\vlc-1.1.5-win32.exe
2009-11-29 15:07 . 2009-11-29 15:07 3738880 ----a-w- c:\programmi\FoxitReader30_enu_Setup.exe
2009-11-25 19:04 . 2009-11-25 19:04 4409491 ----a-w- c:\programmi\cdbxp_setup_4.2.7.1801.exe
2009-11-25 18:14 . 2009-11-25 18:14 25823304 ----a-w- c:\programmi\wmp11-windowsxp-x86-it-it.exe
2008-04-25 22:33 . 2009-11-25 11:13 323000872 ----a-w- c:\programmi\WINDOWSXP-KB936929-SP3-X86-ITA_2162c1d419d1e462a7dc34294528b2daf593302c.exe
2005-09-23 16:55 . 2009-11-25 11:10 23510720 ----a-w- c:\programmi\dotnetfx.exe
2005-05-04 23:24 . 2009-11-25 10:40 2585872 ----a-w- c:\programmi\WindowsInstaller-KB893803-v2-x86.exe
2004-08-20 02:26 . 2009-11-25 10:17 273229544 ------w- c:\programmi\WindowsXP-KB835935-SP2-ITA.exe
2003-02-21 21:37 . 2009-11-25 10:16 24265736 ------w- c:\programmi\dotnetfx_001.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-07-01 118784]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"CnxDslTaskBar"="c:\programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2009-11-25 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^gabri^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\gabri\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 14:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:14 1695232 ----a-w- c:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 15:49 14940040 ----a-r- c:\programmi\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [25/11/2009 12.49.50 704384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [25/11/2009 12.48.20 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [25/11/2009 12.49.32 257432]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [25/11/2009 13.34.53 60288]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [25/11/2009 13.34.53 646400]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [25/11/2009 13.34.53 108771]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [25/11/2009 12.48.19 1195008]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/11/2009 11.05.39 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Scansione supplementare -------
.
FF - ProfilePath - c:\documents and settings\gabri\Dati applicazioni\Mozilla\Firefox\Profiles\7fgwmzip.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-16 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2011-02-16 14:19:41
ComboFix-quarantined-files.txt 2011-02-16 13:19
Pre-Run: 68.519.919.616 byte disponibili
Post-Run: 68.509.491.200 byte disponibili
- - End Of File - - B21BA4516B4FCEDEBEDA259592ED1A34ComboFix 11-02-15.04 - gabri 16/02/2011 14.13.29.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.503.226 [GMT 1:00]
Eseguito da: c:\documents and settings\gabri\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
FW: Outpost Firewall *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Creati Da 2011-01-16 al 2011-02-16 )))))))))))))))))))))))))))))))))))
.
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\documents and settings\gabri\Dati applicazioni\Auslogics
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\programmi\Auslogics
2011-02-07 13:59 . 2011-02-07 13:59 4646264 ----a-w- c:\programmi\disk-defrag-setup.exe
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-sh--w- c:\documents and settings\gabri\IECompatCache
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\TRADUTTORI
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\AIUTAMICI.COM
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\DIZIONARI INFORM
2011-02-06 11:23 . 2011-02-06 11:23 -------- d-sh--w- c:\documents and settings\gabri\PrivacIE
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\gabri\IETldCache
2011-02-06 11:12 . 2011-02-06 11:14 -------- dc-h--w- c:\windows\ie8
2011-02-06 11:09 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-06 11:09 . 2010-12-20 23:53 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-02-06 11:09 . 2010-12-20 23:53 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-02-06 11:08 . 2010-12-20 23:53 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-06 11:08 . 2010-12-20 23:53 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-02-06 11:08 . 2010-12-20 23:53 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-06 11:08 . 2010-12-20 23:53 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-06 11:08 . 2010-12-21 04:23 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-02-06 11:06 . 2011-02-06 11:05 16968544 ----a-w- c:\programmi\IE8-WindowsXP-x86-ITA.exe
2011-02-04 11:15 . 2011-02-04 11:15 388608 ----a-w- c:\programmi\HijackThis.exe
2011-01-21 14:44 . 2011-01-21 14:44 440832 -c----w- c:\windows\system32\dllcache\shimgvw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2009-11-25 10:20 440832 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2009-11-25 10:20 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2009-11-25 10:20 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-30 10:53 . 2009-11-25 10:05 17408 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-22 12:34 . 2009-11-25 10:20 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:53 . 2009-11-25 10:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:53 . 2009-11-25 10:20 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:53 . 2009-11-25 10:20 43520 ------w- c:\windows\system32\licmgr10.dll
2010-12-20 17:26 . 2009-11-25 10:20 735744 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2009-11-28 15:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-11-28 15:59 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2009-11-25 11:00 385024 ------w- c:\windows\system32\html.iec
2010-12-19 11:51 . 2010-12-19 11:50 2493933 ----a-w- c:\programmi\vsoDivxToDVD_setup.exe
2010-12-14 10:25 . 2010-12-14 10:25 10414088 ----a-w- c:\programmi\K-Lite_Codec_Pack_666_Standard.exe
2010-12-13 13:30 . 2010-12-13 13:17 153061304 ----a-w- c:\programmi\OOo_3.2.1_Win_x86_install-wJRE_it.exe
2010-12-13 11:10 . 2010-12-13 11:09 8399024 ----a-w- c:\programmi\Firefox Setup 3.6.13.exe
2010-12-09 15:15 . 2009-11-25 10:20 739840 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2009-11-25 10:20 2196480 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2009-11-25 10:20 2073088 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2009-11-25 10:20 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-11-19 12:43 . 2010-11-19 12:43 955272 ----a-w- c:\programmi\SkypeSetup.exe
2010-11-18 18:12 . 2009-11-25 10:20 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-18 13:31 . 2010-11-18 13:31 2811584 ----a-w- c:\programmi\ccsetup300.exe
2010-11-15 10:40 . 2010-11-18 13:20 19985265 ----a-w- c:\programmi\vlc-1.1.5-win32.exe
2009-11-29 15:07 . 2009-11-29 15:07 3738880 ----a-w- c:\programmi\FoxitReader30_enu_Setup.exe
2009-11-25 19:04 . 2009-11-25 19:04 4409491 ----a-w- c:\programmi\cdbxp_setup_4.2.7.1801.exe
2009-11-25 18:14 . 2009-11-25 18:14 25823304 ----a-w- c:\programmi\wmp11-windowsxp-x86-it-it.exe
2008-04-25 22:33 . 2009-11-25 11:13 323000872 ----a-w- c:\programmi\WINDOWSXP-KB936929-SP3-X86-ITA_2162c1d419d1e462a7dc34294528b2daf593302c.exe
2005-09-23 16:55 . 2009-11-25 11:10 23510720 ----a-w- c:\programmi\dotnetfx.exe
2005-05-04 23:24 . 2009-11-25 10:40 2585872 ----a-w- c:\programmi\WindowsInstaller-KB893803-v2-x86.exe
2004-08-20 02:26 . 2009-11-25 10:17 273229544 ------w- c:\programmi\WindowsXP-KB835935-SP2-ITA.exe
2003-02-21 21:37 . 2009-11-25 10:16 24265736 ------w- c:\programmi\dotnetfx_001.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-07-01 118784]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"CnxDslTaskBar"="c:\programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2009-11-25 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^gabri^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\gabri\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 14:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:14 1695232 ----a-w- c:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 15:49 14940040 ----a-r- c:\programmi\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [25/11/2009 12.49.50 704384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [25/11/2009 12.48.20 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [25/11/2009 12.49.32 257432]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [25/11/2009 13.34.53 60288]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [25/11/2009 13.34.53 646400]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [25/11/2009 13.34.53 108771]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [25/11/2009 12.48.19 1195008]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/11/2009 11.05.39 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Scansione supplementare -------
.
FF - ProfilePath - c:\documents and settings\gabri\Dati applicazioni\Mozilla\Firefox\Profiles\7fgwmzip.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-16 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2011-02-16 14:19:41
ComboFix-quarantined-files.txt 2011-02-16 13:19
Pre-Run: 68.519.919.616 byte disponibili
Post-Run: 68.509.491.200 byte disponibili
- - End Of File - - B21BA4516B4FCEDEBEDA259592ED1A34ComboFix 11-02-15.04 - gabri 16/02/2011 14.13.29.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.503.226 [GMT 1:00]
Eseguito da: c:\documents and settings\gabri\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
FW: Outpost Firewall *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Creati Da 2011-01-16 al 2011-02-16 )))))))))))))))))))))))))))))))))))
.
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\documents and settings\gabri\Dati applicazioni\Auslogics
2011-02-07 14:01 . 2011-02-07 14:01 -------- d-----w- c:\programmi\Auslogics
2011-02-07 13:59 . 2011-02-07 13:59 4646264 ----a-w- c:\programmi\disk-defrag-setup.exe
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-sh--w- c:\documents and settings\gabri\IECompatCache
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\TRADUTTORI
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\AIUTAMICI.COM
2011-02-06 11:25 . 2011-02-06 11:25 -------- d-----w- C:\DIZIONARI INFORM
2011-02-06 11:23 . 2011-02-06 11:23 -------- d-sh--w- c:\documents and settings\gabri\PrivacIE
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-02-06 11:20 . 2011-02-06 11:20 -------- d-sh--w- c:\documents and settings\gabri\IETldCache
2011-02-06 11:12 . 2011-02-06 11:14 -------- dc-h--w- c:\windows\ie8
2011-02-06 11:09 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-06 11:09 . 2010-12-20 23:53 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-02-06 11:09 . 2010-12-20 23:53 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-02-06 11:08 . 2010-12-20 23:53 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-06 11:08 . 2010-12-20 23:53 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-02-06 11:08 . 2010-12-20 23:53 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-06 11:08 . 2010-12-20 23:53 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-06 11:08 . 2010-12-21 04:23 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-02-06 11:06 . 2011-02-06 11:05 16968544 ----a-w- c:\programmi\IE8-WindowsXP-x86-ITA.exe
2011-02-04 11:15 . 2011-02-04 11:15 388608 ----a-w- c:\programmi\HijackThis.exe
2011-01-21 14:44 . 2011-01-21 14:44 440832 -c----w- c:\windows\system32\dllcache\shimgvw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2009-11-25 10:20 440832 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2009-11-25 10:20 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2009-11-25 10:20 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-30 10:53 . 2009-11-25 10:05 17408 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-12-22 12:34 . 2009-11-25 10:20 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:53 . 2009-11-25 10:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:53 . 2009-11-25 10:20 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:53 . 2009-11-25 10:20 43520 ------w- c:\windows\system32\licmgr10.dll
2010-12-20 17:26 . 2009-11-25 10:20 735744 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2009-11-28 15:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-11-28 15:59 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2009-11-25 11:00 385024 ------w- c:\windows\system32\html.iec
2010-12-19 11:51 . 2010-12-19 11:50 2493933 ----a-w- c:\programmi\vsoDivxToDVD_setup.exe
2010-12-14 10:25 . 2010-12-14 10:25 10414088 ----a-w- c:\programmi\K-Lite_Codec_Pack_666_Standard.exe
2010-12-13 13:30 . 2010-12-13 13:17 153061304 ----a-w- c:\programmi\OOo_3.2.1_Win_x86_install-wJRE_it.exe
2010-12-13 11:10 . 2010-12-13 11:09 8399024 ----a-w- c:\programmi\Firefox Setup 3.6.13.exe
2010-12-09 15:15 . 2009-11-25 10:20 739840 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2009-11-25 10:20 2196480 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2009-11-25 10:20 2073088 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2009-11-25 10:20 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-11-19 12:43 . 2010-11-19 12:43 955272 ----a-w- c:\programmi\SkypeSetup.exe
2010-11-18 18:12 . 2009-11-25 10:20 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-18 13:31 . 2010-11-18 13:31 2811584 ----a-w- c:\programmi\ccsetup300.exe
2010-11-15 10:40 . 2010-11-18 13:20 19985265 ----a-w- c:\programmi\vlc-1.1.5-win32.exe
2009-11-29 15:07 . 2009-11-29 15:07 3738880 ----a-w- c:\programmi\FoxitReader30_enu_Setup.exe
2009-11-25 19:04 . 2009-11-25 19:04 4409491 ----a-w- c:\programmi\cdbxp_setup_4.2.7.1801.exe
2009-11-25 18:14 . 2009-11-25 18:14 25823304 ----a-w- c:\programmi\wmp11-windowsxp-x86-it-it.exe
2008-04-25 22:33 . 2009-11-25 11:13 323000872 ----a-w- c:\programmi\WINDOWSXP-KB936929-SP3-X86-ITA_2162c1d419d1e462a7dc34294528b2daf593302c.exe
2005-09-23 16:55 . 2009-11-25 11:10 23510720 ----a-w- c:\programmi\dotnetfx.exe
2005-05-04 23:24 . 2009-11-25 10:40 2585872 ----a-w- c:\programmi\WindowsInstaller-KB893803-v2-x86.exe
2004-08-20 02:26 . 2009-11-25 10:17 273229544 ------w- c:\programmi\WindowsXP-KB835935-SP2-ITA.exe
2003-02-21 21:37 . 2009-11-25 10:16 24265736 ------w- c:\programmi\dotnetfx_001.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-07-01 118784]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"CnxDslTaskBar"="c:\programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2009-11-25 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^gabri^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\gabri\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 14:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:14 1695232 ----a-w- c:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 15:49 14940040 ----a-r- c:\programmi\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [25/11/2009 12.49.50 704384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [25/11/2009 12.48.20 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [25/11/2009 12.49.32 257432]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [25/11/2009 13.34.53 60288]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [25/11/2009 13.34.53 646400]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [25/11/2009 13.34.53 108771]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [25/11/2009 12.48.19 1195008]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [25/11/2009 11.05.39 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Scansione supplementare -------
.
FF - ProfilePath - c:\documents and settings\gabri\Dati applicazioni\Mozilla\Firefox\Profiles\7fgwmzip.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-16 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2011-02-16 14:19:41
ComboFix-quarantined-files.txt 2011-02-16 13:19
Pre-Run: 68.519.919.616 byte disponibili
Post-Run: 68.509.491.200 byte disponibili
- - End Of File - - B21BA4516B4FCEDEBEDA259592ED1A34
Ciao, a presto