Ecco il log di combofix, e adesso aspetto tue istruzioni perchè per me è arabo grazieeeeeeeeeeee
ComboFix 08-12-26.03 - Federico 2008-12-27 18.05.53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1023.555 [GMT 1:00]
Eseguito da: c:\documents and settings\Federico\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\dumphive.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-11-27 al 2008-12-27 )))))))))))))))))))))))))))))))))))
.
2008-12-27 16:04 . 2008-12-27 16:04 <DIR> d-------- c:\documents and settings\Federico\Dati applicazioni\Malwarebytes
2008-12-27 16:04 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-27 16:03 . 2008-12-27 16:14 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-12-27 16:03 . 2008-12-27 16:03 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-12-27 16:03 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-22 15:31 . 2008-12-22 15:31 <DIR> d-------- c:\programmi\Humax Digital
2008-12-22 15:26 . 2000-10-12 21:55 299,520 --a------ c:\windows\uninst.exe
2008-12-20 20:09 . 2008-12-26 21:38 <DIR> d-------- c:\programmi\PeerGuardian2
2008-12-19 15:31 . 2008-12-23 20:53 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-19 15:14 . 2008-12-27 09:34 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-12-19 15:14 . 2008-12-19 15:14 <DIR> d-------- c:\programmi\AVG
2008-12-19 15:14 . 2008-12-19 20:22 <DIR> d-------- c:\documents and settings\Federico\Dati applicazioni\AVGTOOLBAR
2008-12-19 15:14 . 2008-12-19 15:14 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\avg8
2008-12-19 15:14 . 2008-12-19 15:14 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-12-19 15:14 . 2008-12-19 15:14 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
2008-12-19 15:14 . 2008-12-19 15:14 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-12-19 13:14 . 2008-12-19 13:14 <DIR> d-------- c:\programmi\CCleaner
2008-12-16 10:04 . 2008-12-16 10:04 53,958 --a------ c:\windows\system32\cont_milehighads-remove.exe
2008-12-16 10:04 . 2008-12-25 17:35 47,576 --a------ c:\windows\system32\ztcqcpgpolor.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 16:59 --------- d-----w c:\programmi\Spybot - Search & Destroy
2008-12-27 16:59 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-12-27 12:09 --------- d-----w c:\programmi\a-squared Free
2008-12-26 19:53 --------- d-----w c:\documents and settings\Federico\Dati applicazioni\uTorrent
2008-12-26 18:08 --------- d-----w c:\documents and settings\Federico\Dati applicazioni\LimeWire
2008-12-16 09:07 --------- d-----w c:\programmi\LimeWire
2008-12-16 09:07 --------- d-----w c:\programmi\Incomplete
2008-11-21 13:53 --------- d-----w c:\programmi\Apple Software Update
2008-11-21 13:19 --------- d-----w c:\documents and settings\Federico\Dati applicazioni\PlayFirst
2008-11-13 07:58 --------- d-----w c:\programmi\P2P_Max
2008-11-13 07:58 --------- d-----w c:\programmi\Conduit
2008-11-12 13:48 --------- d-----w c:\programmi\uTorrent
2008-11-09 17:22 --------- d-----w c:\documents and settings\Federico\Dati applicazioni\Vso
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 01:00 668,672 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-08-17 09:22 87,608 ----a-w c:\documents and settings\Federico\Dati applicazioni\ezpinst.exe
2008-08-17 09:22 47,360 ----a-w c:\documents and settings\Federico\Dati applicazioni\pcouffin.sys
2008-04-02 11:40 49,851 ----a-w c:\documents and settings\dog\uninst.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{72ae8426-3b8d-4ead-b191-8d0ad1c62158}"= "c:\programmi\P2P_Max\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}]
2008-09-15 06:47 1784856 --a------ c:\programmi\P2P_Max\tbP2P_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{72ae8426-3b8d-4ead-b191-8d0ad1c62158}"= "c:\programmi\P2P_Max\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{72AE8426-3B8D-4EAD-B191-8D0AD1C62158}"= "c:\programmi\P2P_Max\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\progra~1\MESSEN~1\Msmsgs.exe" [2005-08-31 1658592]
"Yahoo! Pager"="c:\programmi\Yahoo!\Messenger\ypager.exe" [2004-08-06 2502656]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-02 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-17 64512]
"SoundMAXPnP"="c:\programmi\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"EPSON Stylus C86 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE" [2003-11-25 99840]
"SMSTray"="c:\programmi\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 132624]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-05 7323648]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-19 1261336]
"SMSERIAL"="sm56hlpr.exe" [2005-09-13 c:\windows\sm56hlpr.exe]
"nwiz"="nwiz.exe" [2006-01-05 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "c:\progra~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\Msmsgs.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Documents and Settings\\Federico\\Documenti\\eMule\\emule.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Documents and Settings\\Federico\\Documenti\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Documents and Settings\\Federico\\Documenti\\uTorrent.exe"=
"c:\\Documents and Settings\\Federico\\Documenti\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-19 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-19 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-19 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-19 76040]
R3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2006-05-22 835200]
R3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys [2006-05-22 7040]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acd384da-540c-11dc-b7f4-0015f28ace34}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
2008-12-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORFÃOS REMOVIDOS - - - -
BHO-{f0aeeba0-65ac-9511-55ab-8b3b5dec320c} - (no file)
.
------- Supplementare di scansione -------
.
uStart Page = hxxp://it.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {CEA6B116-F051-4E9A-A95C-E3374564A6E5} = 81.88.224.129,81.88.224.130
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-27 18:06:54
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\avgrsstx.dll
- - - - - - - > 'lsass.exe'(840)
c:\windows\system32\avgrsstx.dll
.
Ora fine scansione: 2008-12-27 18.07.48
ComboFix-quarantined-files.txt 2008-12-27 17:07:46
Pre-Run: 178.402.156.544 byte disponibili
Post-Run: 178,417,102,848 byte disponibili
173 --- E O F --- 2008-12-18 07:15:14