Ecco il file combofix
_____
ComboFix 10-07-01.02 - Francesco 02/07/2010 22.00.17.1.2 - x86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.39.1040.18.3061.1694 [GMT 2:00]
Eseguito da: c:\users\Francesco\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Creati Da 2010-06-02 al 2010-07-02 )))))))))))))))))))))))))))))))))))
.
2010-07-02 20:11 . 2010-07-02 20:11 -------- d-----w- c:\users\Vivi\AppData\Local\temp
2010-07-02 20:11 . 2010-07-02 20:11 -------- d-----w- c:\users\Sara\AppData\Local\temp
2010-07-02 20:11 . 2010-07-02 20:11 -------- d-----w- c:\users\manu\AppData\Local\temp
2010-07-02 20:11 . 2010-07-02 20:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-02 15:58 . 2010-07-02 15:58 43646 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_E8107429428345802769A1.exe
2010-07-02 15:58 . 2010-07-02 15:58 43646 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_D707CE1C009F1381803C2C.exe
2010-07-02 15:58 . 2010-07-02 15:58 43646 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_21F3885A18D238E15AAE81.exe
2010-07-02 15:58 . 2010-07-02 15:58 43646 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_01A0E73821A82CA3751F06.exe
2010-07-02 15:58 . 2010-07-02 15:58 29926 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_7D9DC4673740B3F1827A58.exe
2010-07-02 15:58 . 2010-07-02 15:58 109534 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_6FEFF9B68218417F98F549.exe
2010-07-02 15:58 . 2010-07-02 15:58 -------- d-----w- c:\program files\Macrium
2010-07-02 15:54 . 2010-07-02 15:55 -------- d-----w- c:\program files\IZArc
2010-07-02 15:02 . 2010-07-02 15:02 -------- d-----w- c:\users\Francesco\AppData\Roaming\Uniblue
2010-06-30 21:46 . 2010-06-30 21:46 -------- dc----w- C:\353a499f9f114ea0c67a9d3ce63e
2010-06-30 21:09 . 2010-06-30 21:09 -------- dc----w- C:\Temp
2010-06-30 21:06 . 2010-06-30 21:06 -------- d-----w- c:\users\Francesco\AppData\Local\IsolatedStorage
2010-06-30 20:06 . 2010-06-30 19:50 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-06-30 19:50 . 2010-06-30 19:49 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-30 19:50 . 2010-06-30 19:50 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-30 19:43 . 2010-06-30 19:43 -------- dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-06-30 19:43 . 2010-02-04 15:53 2954656 -c--a-w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-06-29 21:05 . 2010-06-29 21:05 -------- d-----w- c:\windows\CheckSur
2010-06-29 20:51 . 2010-06-29 20:51 -------- d-----w- c:\windows\system32\EventProviders
2010-06-29 20:29 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-29 20:29 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-21 09:58 . 2010-06-21 09:58 15328 ----a-w- c:\windows\system32\drivers\pssnap.sys
2010-06-21 09:57 . 2010-06-21 09:57 44512 ----a-w- c:\windows\system32\drivers\psmounter.sys
2010-06-19 21:34 . 2010-07-02 14:42 -------- d-----w- c:\program files\Panda Security
2010-06-19 21:24 . 2010-06-20 13:16 -------- d-----w- c:\program files\Fortinet
2010-06-19 21:22 . 2010-06-19 21:22 -------- d-----w- c:\programdata\Applications
2010-06-18 21:20 . 2010-05-06 04:01 44080 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2010-06-17 17:37 . 2010-06-17 17:37 -------- d-----w- c:\users\Francesco\AppData\Roaming\Malwarebytes
2010-06-17 17:36 . 2010-06-17 17:36 -------- d-----w- c:\programdata\Malwarebytes
2010-06-17 17:36 . 2010-06-29 20:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-15 17:31 . 2010-06-29 20:25 -------- d-----w- c:\program files\Windows Live Safety Center
2010-06-10 21:50 . 2010-06-10 21:51 -------- dc----w- C:\WUA
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-30 22:18 . 2008-08-19 21:56 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-06-30 20:13 . 2008-08-19 21:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-30 19:46 . 2009-03-20 18:31 -------- d-----w- c:\program files\Lavasoft
2010-06-30 19:43 . 2009-03-20 18:31 -------- d-----w- c:\programdata\Lavasoft
2010-06-30 17:26 . 2007-11-30 03:30 662846 ----a-w- c:\windows\system32\perfh010.dat
2010-06-30 17:26 . 2007-11-30 03:30 120326 ----a-w- c:\windows\system32\perfc010.dat
2010-06-19 15:54 . 2010-04-12 19:43 -------- d-----w- c:\program files\7-Zip
2010-06-10 21:08 . 2007-11-29 20:29 -------- d-----w- c:\programdata\Microsoft Help
2010-06-07 18:38 . 2008-08-07 21:23 -------- d-----w- c:\users\Francesco\AppData\Roaming\U3
2010-06-05 08:41 . 2008-08-21 20:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-03 21:39 . 2010-05-30 13:07 -------- d-----w- c:\program files\Common Files\Nero
2010-06-03 21:38 . 2010-05-30 13:07 -------- d-----w- c:\programdata\Nero
2010-05-30 13:22 . 2010-05-30 13:22 -------- d-----w- c:\users\Francesco\AppData\Roaming\Nero
2010-05-30 10:16 . 2009-01-26 22:20 -------- d-----w- c:\program files\Microsoft
2010-05-26 15:24 . 2010-01-28 21:15 -------- d-----w- c:\program files\CCleaner
2010-05-22 18:33 . 2007-11-29 21:00 -------- d-----w- c:\program files\Common Files\Java
2010-05-22 18:14 . 2007-11-29 21:00 -------- d-----w- c:\program files\Java
2010-05-14 20:07 . 2009-12-13 09:54 -------- d-----w- c:\users\Francesco\AppData\Roaming\SATURN_Gadgets
2010-05-10 19:37 . 2010-05-10 19:37 -------- d-----w- c:\users\Francesco\AppData\Roaming\KoshyJohn.com
2010-05-10 19:37 . 2010-05-10 19:37 913446 ----a-w- c:\users\Francesco\AppData\Roaming\KoshyJohn.com\DiskMax\DiskMax.exe
2010-05-07 15:29 . 2010-05-04 16:49 -------- d-----w- c:\program files\Google
2010-05-03 12:47 . 2008-09-08 21:40 568 ----a-w- c:\users\Francesco\AppData\Roaming\wklnhst.dat
2010-04-12 15:29 . 2010-05-22 18:14 411368 ----a-w- c:\windows\system32\deployJava1.dll
2008-08-18 20:49 . 2008-08-18 20:49 22 --sha-w- c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-10-25 212992]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-27 202032]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-03-23 17:00 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-17 16:40 767312 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2007-10-01 15:10 1783136 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 gupdate;Servizio di Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 136176]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-30 1352832]
R3 cpuz131;cpuz131;c:\users\FRANCE~1\AppData\Local\Temp\cpuz131\cpuz_x32.sys [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-30 64288]
S0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\DRIVERS\pssnap.sys [2010-06-21 15328]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1107000.00C\SYMDS.SYS [2009-10-15 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1107000.00C\SYMEFA.SYS [2010-04-22 173104]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100619.001\BHDrvx86.sys [2010-05-22 691248]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1107000.00C\ccHPx86.sys [2010-02-26 501888]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100701.001\IDSvix86.sys [2010-05-28 344112]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1107000.00C\Ironx86.SYS [2010-04-29 116784]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NIS\1107000.00C\SYMTDIV.SYS [2010-05-06 339504]
S2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe [2010-02-26 126392]
S2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2010-06-21 220128]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-05-27 102448]
.
Contenuto della cartella 'Scheduled Tasks'
2010-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 16:49]
2010-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 16:49]
2010-05-26 c:\windows\Tasks\Norton Internet Security - Francesco - Scansione completa.job
- c:\program files\Norton Internet Security\Engine\17.7.0.12\navw32.exe [2010-05-26 05:34]
2010-06-13 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-12-16 14:48]
2010-07-02 c:\windows\Tasks\User_Feed_Synchronization-{AA888B5A-860D-408D-8F93-87CBFFC56934}.job
- c:\windows\system32\msfeedssync.exe [2008-08-24 07:33]
2010-07-02 c:\windows\Tasks\User_Feed_Synchronization-{B5A88B38-907E-4947-856F-6499D7DB775F}.job
- c:\windows\system32\msfeedssync.exe [2008-08-24 07:33]
2010-07-02 c:\windows\Tasks\User_Feed_Synchronization-{CBBAAE3C-B911-4739-A239-97EC70E4B7EC}.job
- c:\windows\system32\msfeedssync.exe [2008-08-24 07:33]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Presario&pf=laptop
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-02 22:11
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.7.0.12\diMaster.dll\" /prefetch:1"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2010-07-02 22:18:16
ComboFix-quarantined-files.txt 2010-07-02 20:18
Pre-Run: 103.459.774.464 byte disponibili
Post-Run: 103.415.496.704 byte disponibili
- - End Of File - - B7E75F516F8A0F35300248FE016CBC12