ciao r16 ecco il mio ultimo report di combofix...cmq il pc sembra vadi bene
grazie ancora per l'aiuto.
ComboFix 09-04-23.A3 - Utente 25/04/2009 12.10.23.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1423 [GMT 2:00]
Eseguito da: c:\documents and settings\Utente\Documenti\ComboFix.exe
Opzioni usate :: c:\documents and settings\Utente\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-05-25 al 2009-4-25 )))))))))))))))))))))))))))))))))))
.
2009-04-24 18:26 . 2008-04-13 17:13 21504 ----a-w c:\windows\system32\hidserv.dll
2009-04-24 18:26 . 2008-04-13 17:13 21504 ----a-w c:\windows\system32\dllcache\hidserv.dll
2009-04-24 10:37 . 2009-04-24 10:37 -------- d-----w c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\WMTools Downloaded Files
2009-04-23 21:54 . 2009-04-23 21:54 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2009-04-23 21:53 . 2009-04-23 21:53 -------- d-----w c:\windows\system32\xircom
2009-04-23 21:53 . 2009-04-23 21:53 -------- d-----w c:\programmi\microsoft frontpage
2009-04-23 16:19 . 2009-04-23 16:19 -------- d-----w c:\programmi\Trend Micro
2009-04-23 11:28 . 2009-04-23 11:28 -------- d-----w c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2009-04-23 11:28 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-23 11:28 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-23 11:28 . 2009-04-23 11:28 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-04-23 11:28 . 2009-04-23 11:28 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-04-21 17:07 . 2005-08-16 10:23 38422 ----a-w c:\windows\system32\drivers\StMp3Rec.sys
2009-04-21 17:07 . 2009-04-21 17:07 -------- d-----w c:\programmi\Creative
2009-04-16 11:37 . 2009-01-09 19:19 1090181 ------w c:\windows\system32\dllcache\ntprint.cat
2009-04-16 11:37 . 2009-03-06 14:19 286208 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-16 11:37 . 2009-02-09 11:22 111104 ------w c:\windows\system32\dllcache\services.exe
2009-04-16 11:37 . 2009-02-09 10:51 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 11:37 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 11:37 . 2009-02-09 10:51 734720 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 11:37 . 2009-02-09 10:51 683520 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 11:37 . 2009-02-09 10:51 736256 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 11:37 . 2009-02-09 10:51 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 11:37 . 2009-02-09 10:51 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 11:37 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-16 11:32 . 2009-03-27 06:48 1203922 ------w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 11:32 . 2008-04-21 21:14 219136 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-16 11:28 . 2009-04-16 11:28 -------- d-----w c:\programmi\eMule AdunanzA
2009-04-10 10:58 . 2009-04-14 09:43 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-10 10:58 . 2009-04-14 09:43 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-10 10:57 . 2009-04-25 09:52 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-04-10 10:57 . 2009-04-24 22:26 3164 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-10 10:57 . 2009-04-24 22:26 311264 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-10 10:57 . 2009-04-24 22:26 1824288 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-10 10:57 . 2009-04-24 22:26 17428 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-10 10:57 . 2009-04-10 10:57 -------- d-----w c:\programmi\Kaspersky Lab
2009-04-08 15:53 . 2009-04-08 16:10 -------- d-----w c:\windows\SxsCaPendDel
2009-04-08 13:43 . 2009-04-08 13:43 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2009-04-08 13:43 . 2009-04-10 10:54 -------- d-----w c:\programmi\SUPERAntiSpyware
2009-04-08 13:43 . 2009-04-08 13:43 -------- d-----w c:\documents and settings\Utente\Dati applicazioni\SUPERAntiSpyware.com
2009-04-08 13:38 . 2009-04-08 13:38 -------- d-----w c:\documents and settings\Utente\DoctorWeb
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-25 09:52 . 2008-09-28 17:22 -------- d-----w c:\documents and settings\Utente\Dati applicazioni\skypePM
2009-04-25 09:52 . 2008-09-28 17:09 -------- d-----w c:\documents and settings\Utente\Dati applicazioni\Skype
2009-04-23 16:58 . 2009-02-22 13:40 -------- d-----w c:\programmi\uusee
2009-04-23 16:55 . 2001-08-31 12:00 85330 ----a-w c:\windows\system32\perfc010.dat
2009-04-23 16:55 . 2001-08-31 12:00 492504 ----a-w c:\windows\system32\perfh010.dat
2009-04-16 15:53 . 2008-09-23 17:24 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-04-14 09:43 . 2008-01-29 16:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-08 16:12 . 2008-09-23 16:36 66904 ----a-w c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-08 13:36 . 2008-09-25 15:11 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-03-25 10:56 . 2008-09-25 15:11 -------- d-----w c:\programmi\Spybot - Search & Destroy
2009-03-25 10:53 . 2008-09-25 14:08 -------- d-----w c:\programmi\CCleaner
2009-03-21 14:06 . 2009-03-21 14:06 1033728 ------w c:\windows\system32\dllcache\kernel32.dll
2009-03-06 14:19 . 2008-04-13 17:13 286208 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:03 . 2008-09-23 16:21 826368 ------w c:\windows\system32\dllcache\wininet.dll
2009-03-03 00:03 . 2008-03-01 12:58 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-28 04:54 . 2008-09-23 16:21 636072 ------w c:\windows\system32\dllcache\iexplore.exe
2009-02-27 09:27 . 2009-02-27 09:27 487979 ----a-w c:\windows\system32\imagens1234.exe
2009-02-26 22:15 . 2008-09-23 16:20 -------- d-----w c:\programmi\Microsoft Silverlight
2009-02-20 10:20 . 2008-09-23 16:21 13824 ------w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2008-09-23 16:21 70656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2008-09-23 16:21 161792 ------w c:\windows\system32\dllcache\ieakui.dll
2009-02-10 17:02 . 2009-01-25 00:06 2069760 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-09 14:04 . 2009-01-25 00:06 1846784 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 14:04 . 2008-04-13 16:50 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:23 . 2009-01-25 00:06 2192768 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-09 11:23 . 2009-01-25 00:06 2027520 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-09 11:23 . 2008-04-13 18:55 2027520 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:22 . 2009-01-25 00:06 2148864 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-09 11:22 . 2008-04-13 16:54 2148864 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:22 . 2008-04-13 17:14 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 2008-04-13 17:13 734720 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2008-04-13 17:13 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 2008-04-13 17:13 683520 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 2008-04-13 17:13 736256 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 2001-08-31 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-04 09:50 . 2009-02-04 09:50 24576 ----a-w c:\windows\system32\nsis_loader.dll
2009-02-03 19:57 . 2009-02-03 19:57 56832 ------w c:\windows\system32\dllcache\secur32.dll
2009-02-03 19:57 . 2008-04-13 17:13 56832 ----a-w c:\windows\system32\secur32.dll
.
------- Sigcheck -------
[-] 2008-04-30 11:56 1571840 3316C8A8EC07A9D4C0BE10310809A9E5 c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-04-23_21.54.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-25 09:52 . 2009-04-25 09:52 16384 c:\windows\Temp\Perflib_Perfdata_4d4.dat
+ 2008-09-05 22:30 . 2009-02-06 10:35 1486208 c:\windows\system32\LegitCheckControl.DLL
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
2009-01-11 09:03 34816 ----a-w c:\programmi\Java\jre6\bin\jp2ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
2009-01-11 09:03 73728 ----a-w c:\programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2008-08-12 21741864]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl8"="c:\programmi\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\programmi\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"ATKMEDIA"="c:\programmi\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"ATKOSD2"="c:\programmi\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-21 544768]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2007-11-16 1024000]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"ACU"="c:\programmi\Atheros\ACU.exe" [2007-10-23 376921]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-11 136600]
"WinampAgent"="c:\programmi\Winamp\winampa.exe" [2008-08-03 36352]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-04-10 201992]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-06-20 16872448]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-02-20 124928]
c:\documents and settings\Utente\Menu Avvio\Programmi\Esecuzione automatica\
CCC.lnk - c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-7-17 49152]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"= "c:\programmi\Microsoft Office\Office12\GrooveShellExtensions.dll" [2007-08-24 2212224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"= {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - c:\windows\system32\webcheck.dll [2009-02-20 233472]
"WPDShServiceObj"= {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll [2007-01-19 133632]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:*:Disabled:emule_tcp
"4672:UDP"= 4672:UDP:emule_udp
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-04-14 33808]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S3 WSIMD;wsimd Service;c:\windows\system32\DRIVERS\wsimd.sys [2007-07-03 57344]
.
Contenuto della cartella 'Scheduled Tasks'
2009-04-24 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
2009-04-25 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
SSODL-CDBurn-{fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {{FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmi\Messenger\msmsgs.exe
Handler: http\
0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FILECO~1\System\OLEDB~1\MSDAIPP.DLL
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FILECO~1\System\OLEDB~1\MSDAIPP.DLL
Handler: https\
0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FILECO~1\System\OLEDB~1\MSDAIPP.DLL
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FILECO~1\System\OLEDB~1\MSDAIPP.DLL
Handler: ipp\
0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FILECO~1\System\OLEDB~1\MSDAIPP.DLL
Handler: msdaipp\
0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FILECO~1\System\OLEDB~1\MSDAIPP.DLL
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FILECO~1\System\OLEDB~1\MSDAIPP.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\FILECO~1\Skype\SKYPE4~1.DLL
Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - c:\windows\system32\msvidctl.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-25 12:12
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(328)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(13708)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Ora fine scansione: 2009-04-25 12.14.01
ComboFix-quarantined-files.txt 2009-04-25 10:13
ComboFix2.txt 2009-04-24 18:41
ComboFix3.txt 2009-04-24 11:10
ComboFix4.txt 2009-04-23 21:57
Pre-Run: 65.706.024.960 byte disponibili
Post-Run: 65.731.895.296 byte disponibili
222 --- E O F --- 2009-04-23 17:11