ciao!qesto è il log di combofix:
ComboFix 09-01-21.04 - Administrator 2009-01-31 16.13.39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.510.154 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
* Resident AV is active
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
- MODALITÀ CON FUNZIONALITÀ RIDOTTE -
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\Uninstall Fun Web Products.dll
c:\windows\system32\Cache
.
((((((((((((((((((((((((( Files Creati Da 2008-12-28 al 2009-01-31 )))))))))))))))))))))))))))))))))))
.
2009-01-30 18:36 . 2009-01-30 19:07 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-01-30 18:36 . 2009-01-30 18:36 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-01-30 18:36 . 2009-01-30 18:36 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2009-01-30 18:36 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-30 18:36 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-30 17:39 . 2009-01-30 17:39 <DIR> d-------- c:\programmi\Trend Micro
2009-01-26 02:12 . 2009-01-31 12:28 <DIR> d-------- c:\programmi\SpeedBit Video Accelerator
2009-01-26 02:12 . 2009-01-26 02:12 172,032 --a------ c:\windows\system32\AniGIF.ocx
2009-01-14 17:08 . 2009-01-14 17:08 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\OpenOffice.org
2009-01-14 17:04 . 2009-01-14 17:04 <DIR> d-------- c:\programmi\OpenOffice.org 3
2009-01-14 17:04 . 2009-01-14 17:04 <DIR> d-------- c:\programmi\JRE
2009-01-14 17:03 . 2009-01-14 17:03 <DIR> d-------- c:\programmi\File comuni\Java
2008-12-15 13:40 . 2008-12-15 13:40 <DIR> d-------- c:\programmi\HiYo
2008-12-15 13:40 . 2008-12-15 13:40 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\HiYo
2008-12-15 13:40 . 2008-12-15 13:40 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\HiYo
2008-12-06 16:53 . 2008-12-06 16:53 <DIR> d-------- c:\windows\Sun
2008-12-06 16:48 . 2009-01-14 17:04 <DIR> d-------- c:\programmi\Java
2008-12-06 16:48 . 2008-12-06 16:48 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-06 16:48 . 2008-12-06 16:48 73,728 --a------ c:\windows\system32\javacpl.cpl
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-22 23:55 --------- d-----w c:\documents and settings\Administrator\Dati applicazioni\Skype
2009-01-22 20:34 --------- d-----w c:\programmi\Launch Manager
2009-01-12 10:20 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2008-12-17 13:19 --------- d-----w c:\programmi\AdunanzA
2008-12-01 21:22 --------- d-----w c:\programmi\MSN Messenger
.
------- Sigcheck -------
2004-09-29 19:45 659456 5e44c65a8fdf34e023467b13c0305196 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
2005-03-10 08:48 660480 c3bcd4313f62f6f22f06899fec77d725 c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
2005-03-10 10:04 1219072 03d7ee01102c11e2dbf18a7e9d40d84e c:\windows\system32\wininet.dll
2004-08-19 14:39 1883136 bdd34cf918b9133e03eea7633ba002b5 c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\programmi\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2007-09-24 57344]
[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"msnmsgr"="c:\programmi\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 339968]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-05-20 98304]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-05-20 532480]
"acerWireless"="c:\programmi\acer\Wireless\Utility\WlanUtil.exe" [2004-06-09 417792]
"PRONoMgr.exe"="c:\programmi\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2004-02-05 86016]
"LManager"="c:\programmi\Launch Manager\QtZgAcer.EXE" [2004-07-05 315392]
"PCMService"="c:\programmi\Aspire Arcade\PCMService.exe" [2004-03-25 81920]
"nod32kui"="c:\programmi\Eset\nod32kui.exe" [2007-09-24 921600]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2005-06-06 2614496]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2007-09-14 267064]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2007-06-29 286720]
"BigDog303"="c:\windows\VM303_STI.EXE" [2005-06-23 61440]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-12-05 176128]
"HPHUPD05"="c:\programmi\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe" [2003-11-12 49152]
"HP Component Manager"="c:\programmi\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HP Software Update"="c:\programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2003-12-05 49152]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2004-02-02 495616]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-12-06 136600]
"Hiyo"="c:\programmi\HiYo\bin\HiYo.exe" [2008-12-10 300336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"="c:\windows\system32\sti_ci.dll" [2004-08-19 137728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\Administrator\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
Stardock ObjectDock.lnk - c:\windows\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-02-21 1826885]
Y'z ToolBar.lnk - c:\windows\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-09-29 90112]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-03-03 15:48 110592 c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.imc"= imc32.acm
"msacm.l3codecp"= l3codecp.acm
"VIDC.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 SMBHC;Driver del controller host del bus di gestione sistema Microsoft;c:\windows\system32\drivers\smbhc.sys [2007-09-24 6784]
R3 SMBBATT;Driver di Microsoft Smart Battery;c:\windows\system32\drivers\smbbatt.sys [2007-09-24 16128]
R4 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2004-06-01 10386]
R4 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2004-05-31 4054]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43299520-cb80-11dd-867b-000e3548f99f}]
\Shell\AutoRun\command - .\run\autorun.exe
\Shell\open\Command - .\run\autorun.exe
.
Contenuto della cartella 'Scheduled Tasks'
2008-11-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2009-01-31 c:\windows\Tasks\HP Usg Daily.job
- c:\programmi\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\pexpress\hphped05.exe [2004-01-07 06:05]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-FAST Defrag - (no file)
.
------- Scansione supplementare -------
.
uStart Page = hxxp://search.speedbit.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\Microsoft Office\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\svo5kkn9.default\
FF - prefs.js: browser.search.selectedEngine - Google
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-31 16:14:11
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????????0?????????@??????????????
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(872)
c:\windows\system32\LgNotify.dll
.
Ora fine scansione: 2009-01-31 16.15.39
ComboFix-quarantined-files.txt 2009-01-31 15:15:37
Pre-Run: 33.722.482.688 byte disponibili
Post-Run: 33,727,279,104 byte disponibili
177
se ho sbagliato qualcosa avvisami(molto probabile)