Allora...eseguito tutti gli ordini..mi pare di aver letto che ha eliminato qualche cartella. Ecco il report di COMBOFIX:
ComboFix 08-02-19.2 - User 2008-02-19 15.41.30.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.171 [GMT 1:00]
Eseguito da: C:\Documents and Settings\User\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\User\Dati applicazioni\MessengerSkinner
C:\Documents and Settings\User\Dati applicazioni\MessengerSkinner\Userdata\Install_MessengerSkinner.zip
C:\Documents and Settings\User\Dati applicazioni\MessengerSkinner\Userdata\languages_v2.xml
C:\Documents and Settings\User\Dati applicazioni\MessengerSkinner\Userdata\pack1.cab
C:\Documents and Settings\User\Impostazioni locali\Dati applicazioni\gfjptpsno.dat
c:\documents and settings\user\impostazioni locali\dati applicazioni\gfjptpsno.exe
C:\Documents and Settings\User\Impostazioni locali\Dati applicazioni\gfjptpsno_nav.dat
C:\Documents and Settings\User\Impostazioni locali\Dati applicazioni\gfjptpsno_navps.dat
C:\Documents and Settings\User\Menu Avvio\Programmi\MessengerSkinner
C:\Documents and Settings\User\Menu Avvio\Programmi\MessengerSkinner\MessengerSkinner.lnk
C:\Documents and Settings\User\Menu Avvio\Programmi\MessengerSkinner\Privacy Policy.lnk
C:\Documents and Settings\User\Menu Avvio\Programmi\MessengerSkinner\Terms and conditions.lnk
C:\Documents and Settings\User\Menu Avvio\Programmi\MessengerSkinner\Website.lnk
C:\Programmi\messengerskinner\download\defaultPack.cab
C:\Programmi\messengerskinner\MessengerSkinner.exe
C:\Programmi\messengerskinner\MessengerSkinnerDll.dll
C:\Programmi\messengerskinner\Privacy Policy.url
C:\Programmi\messengerskinner\resources\appconfig.xml
C:\Programmi\messengerskinner\resources\btn.rgn
C:\Programmi\messengerskinner\resources\btnBnr.rgn
C:\Programmi\messengerskinner\resources\btnIn.rgn
C:\Programmi\messengerskinner\resources\btnInNormal.bmp
C:\Programmi\messengerskinner\resources\btnInOver.bmp
C:\Programmi\messengerskinner\resources\btnNormal.bmp
C:\Programmi\messengerskinner\resources\btnNormal.gif
C:\Programmi\messengerskinner\resources\btnNormalBnr.bmp
C:\Programmi\messengerskinner\resources\btnNormalBnr.gif
C:\Programmi\messengerskinner\resources\btnOver.bmp
C:\Programmi\messengerskinner\resources\btnOver.gif
C:\Programmi\messengerskinner\resources\btnOverBnr.bmp
C:\Programmi\messengerskinner\resources\btnOverBnr.gif
C:\Programmi\messengerskinner\resources\languages_v2.xml
C:\Programmi\messengerskinner\Terms and conditions.url
C:\Programmi\messengerskinner\uninst.exe
C:\Programmi\messengerskinner\Website.url
C:\WINDOWS\system32\nvs2.inf
----- BITS: Possible infected sites -----
hxxp://au.download.windowsupdate.c.
((((((((((((((((((((((((( Files Creati Da 2008-01-19 al 2008-02-19 )))))))))))))))))))))))))))))))))))
.
2008-02-19 11:05 . 2008-02-19 11:05 <DIR> d-------- C:\Programmi\Lavasoft
2008-02-19 11:05 . 2008-02-19 11:06 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-02-19 11:03 . 2008-02-19 11:03 <DIR> d-------- C:\Programmi\File comuni\Wise Installation Wizard
2008-02-19 10:51 . 2008-02-19 10:51 <DIR> d-------- C:\Programmi\Trend Micro
2008-02-11 11:57 . 2008-02-11 11:57 332,800 --a------ C:\WINDOWS\system32\ffeglvz.exe
2008-02-06 16:26 . 2008-02-06 16:26 <DIR> d-------- C:\Programmi\File comuni\Oberon Media
2008-02-06 16:26 . 2008-02-06 21:27 <DIR> d-a------ C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-02-05 12:06 . 2008-02-05 12:06 268 --ah----- C:\sqmdata15.sqm
2008-02-05 12:06 . 2008-02-05 12:06 244 --ah----- C:\sqmnoopt15.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 16:15 --------- d-----w C:\Programmi\Windows Live Safety Center
2008-02-11 09:43 --------- d-----w C:\Documents and Settings\User\Dati applicazioni\Lavasoft
2008-02-08 08:45 --------- d-----w C:\Programmi\ESET
2008-02-06 19:55 --------- d-----w C:\Programmi\Oberon Media
2008-01-17 09:28 --------- d-----w C:\Programmi\C6 Messenger
2008-01-12 22:39 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-01-12 22:01 --------- d-----w C:\Programmi\Virgilio Toolbar
2008-01-12 22:01 --------- d-----w C:\Documents and Settings\User\Dati applicazioni\Virgilio Toolbar
2008-01-10 15:28 24,936 ----a-w C:\Documents and Settings\User\Dati applicazioni\GDIPFONTCACHEV1.DAT
2007-12-30 20:28 45,056 ----a-w C:\WINDOWS\NCUNINST.EXE
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 11:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-09-20 15:35 202024]
"WMPNSCFG"="C:\Programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 21:56 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Programmi\Apoint2K\Apoint.exe" [2003-10-30 15:46 192512]
"PadTouch"="C:\Programmi\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 09:56 1077327]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 13:37 88363 C:\WINDOWS\agrsmmsg.exe]
"CeEKEY"="C:\Programmi\TOSHIBA\E-KEY\CeEKey.exe" [2005-01-21 20:48 675840]
"TPNF"="C:\Programmi\TOSHIBA\TouchPad\TPTray.exe" [2004-11-29 20:06 53248]
"TOSHIBA Accessibility"="C:\Programmi\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-12-07 20:24 24576]
"HWSetup"="C:\Programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-12-23 17:07 28672]
"SVPWUTIL"="C:\Programmi\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-25 14:59 65536]
"Zooming"="ZoomingHook.exe" [2004-07-14 15:07 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-02-16 13:43 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TPSMain"="TPSMain.exe" [2005-02-17 10:11 266240 C:\WINDOWS\system32\TPSMain.exe]
"SmoothView"="C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-11-15 10:44 118784]
"Tvs"="C:\Programmi\TOSHIBA\Tvs\TvsTray.exe" [2004-11-12 16:57 73728]
"NDSTray.exe"="NDSTray.exe" []
"TFncKy"="TFncKy.exe" []
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2007-07-26 10:17 180269]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"NeroFilterCheck"="C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 09:51 1836328]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2007-12-05 22:11 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 11:00 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.lnk - C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2005-12-17 21:49:34 110592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Avvio veloce di Adobe Reader.lnk]
backup=C:\WINDOWS\pss\Avvio veloce di Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Bluetooth Manager.lnk]
path=C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Bluetooth Manager.lnk
backup=C:\WINDOWS\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^User^Menu Avvio^Programmi^Esecuzione automatica^C6 Messenger.lnk]
backup=C:\WINDOWS\pss\C6 Messenger.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^User^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office OneNote 2003 Quick Launch.lnk]
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-03-14 18:05 257088 C:\Programmi\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 11:54 5674352 C:\Programmi\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-02-16 09:54 282624 C:\Programmi\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra------ 2006-12-27 16:53 73840 C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
R1 SerTVOutCtlr;TOSHIBA Controls Driver -EPIOMngr;C:\WINDOWS\system32\drivers\EPIOMngr.sys [2004-07-30 14:05]
R1 TPwSav;Common Driver;C:\WINDOWS\system32\Drivers\TPwSav.sys [2005-02-25 18:08]
R3 DLKRCB;D-Link DFE-690TXD CardBus PC Card;C:\WINDOWS\system32\DRIVERS\DLKRCB.SYS [2001-10-15 13:38]
S1 StickyMesger;StickyMesger;C:\Programmi\TOSHIBA\Accessibility\StickyMesger.sys []
S3 brfilt;Driver filtro Brother MFC;C:\WINDOWS\system32\Drivers\Brfilt.sys [2001-08-17 21:12]
S3 BrSerWDM;Driver seriale Brother WDM;C:\WINDOWS\system32\Drivers\BrSerWdm.sys [2001-08-17 21:12]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\WINDOWS\system32\Drivers\BrUsbMdm.sys [2001-08-17 21:12]
S3 BrUsbScn;Driver scanner Brother MFC USB;C:\WINDOWS\system32\Drivers\BrUsbScn.sys [2001-08-17 21:12]
S3 PentaxUsb;Pentax Digital Camera on USB;C:\WINDOWS\system32\DRIVERS\CoachUsb.sys [2004-03-17 21:59]
S3 PentaxVc;Pentax Video Capture;C:\WINDOWS\system32\DRIVERS\CoachVc.sys [2004-03-17 22:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e31cf16-c190-11db-a823-00134638dcbd}]
\Shell\Auto\command - Song.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Song.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8375840b-1a62-11dc-a8dc-00134638dcbd}]
\Shell\Auto\command - Cn911.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8404edfa-2964-11dc-a8f4-00134638dcbd}]
\Shell\Auto\command - Cn911.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
.
Contenuto della cartella 'Scheduled Tasks'
"2005-09-09 18:20:11 C:\WINDOWS\Tasks\Promemoria registrazione 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2005-09-16 13:35:11 C:\WINDOWS\Tasks\Promemoria registrazione 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-19 15:48:03
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\Programmi\Eset\pr_imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\brss01a.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmi\Eset\nod32krn.exe
C:\Programmi\Windows Media Player\WMPNetwk.exe
C:\Programmi\TOSHIBA\ConfigFree\NDSTray.exe
C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Programmi\Apoint2K\Apntex.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\RAMASST.exe
.
**************************************************************************
.
Ora fine scansione: 2008-02-19 15:51:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-19 14:50:59
.
2008-02-15 02:04:58 --- E O F ---
Come si intepreta tutto ciò? Che roba è? Ci sono virus?
