ok r16 ti invio il risultato
ComboFix 09-10-23.01 - ser 24/10/2009 21.50.06.2.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.500.136 [GMT 2:00]
Eseguito da: c:\documents and settings\ser\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-09-24 al 2009-10-24 )))))))))))))))))))))))))))))))))))
.
2009-10-23 15:40 . 2009-10-23 15:40 -------- d-----w- c:\programmi\SUPERAntiSpyware
2009-10-23 15:36 . 2009-10-23 15:36 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-10-22 16:38 . 2009-10-22 16:38 -------- d-----w- c:\documents and settings\ser\Dati applicazioni\AVG9
2009-10-22 13:44 . 2009-10-22 13:44 -------- d-----w- c:\programmi\Trend Micro
2009-10-21 21:05 . 2009-10-21 21:05 -------- d-----w- c:\documents and settings\ser\DoctorWeb
2009-10-17 11:00 . 2009-10-17 11:00 -------- d-----w- C:\$AVG
2009-10-17 10:02 . 2009-10-17 10:02 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-17 10:02 . 2009-10-22 08:43 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-17 10:02 . 2009-10-17 10:02 -------- d-----w- c:\windows\system32\drivers\Avg
2009-10-17 10:00 . 2009-10-22 08:40 25608 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2009-10-17 10:00 . 2009-10-22 08:32 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-10-17 10:00 . 2009-10-22 08:46 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-17 10:00 . 2009-10-17 10:00 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-17 09:57 . 2009-10-22 08:37 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-10-17 09:57 . 2009-10-22 08:37 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2009-10-17 09:56 . 2009-10-17 09:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2009-10-09 08:22 . 2009-10-09 08:22 -------- d-----w- c:\windows\Sun
2009-10-07 13:29 . 2009-10-07 13:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2009-10-07 13:28 . 2009-10-07 13:28 -------- d-----w- c:\documents and settings\ser\Dati applicazioni\SUPERAntiSpyware.com
2009-10-01 16:39 . 2009-10-01 16:39 -------- d-----w- C:\FOUND.002
2009-10-01 16:04 . 2009-10-01 16:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-09-28 19:50 . 2009-09-28 19:50 -------- d-----w- c:\documents and settings\ser\Dati applicazioni\OpenOffice.org
2009-09-28 16:37 . 2009-09-28 16:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Agnitum
2009-09-27 20:50 . 2009-09-27 20:50 -------- d-----w- c:\programmi\JRE
2009-09-27 20:50 . 2009-09-27 20:50 -------- d-----w- c:\programmi\OpenOffice.org 3
2009-09-27 20:48 . 2009-09-27 20:47 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-27 20:46 . 2009-09-27 20:46 -------- d-----w- c:\programmi\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-24 17:43 . 2009-08-18 23:34 12 ----a-w- c:\windows\bthservsdp.dat
2009-09-28 07:41 . 2009-06-12 01:11 63936 ----a-w- c:\documents and settings\ser\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-13 17:16 . 2009-09-13 17:16 -------- d-----w- c:\programmi\DIFX
2009-09-11 14:17 . 2008-09-30 06:48 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 12:54 . 2009-06-21 19:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-06-21 19:14 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2008-09-30 06:48 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 12:30 . 2009-09-04 12:30 -------- d-----w- c:\programmi\Windows Live
2009-08-29 07:26 . 2008-09-30 06:48 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:26 . 2008-09-30 06:48 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:26 . 2008-09-30 06:48 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2008-09-30 06:48 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 15:57 . 2008-09-30 06:48 64316 ----a-w- c:\windows\system32\perfc010.dat
2009-08-18 15:57 . 2008-09-30 06:48 427292 ----a-w- c:\windows\system32\perfh010.dat
2009-08-05 08:59 . 2008-09-30 06:48 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 17:26 . 2008-04-13 08:54 2148864 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:26 . 2008-04-13 08:55 2027520 ------w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-10-12 2000112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\programmi\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2008-04-24 1044480]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-10-22 2010904]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-15 16862720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-17 10:02 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgam.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [17/10/2009 12.00.21 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [17/10/2009 12.00.19 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [17/10/2009 12.00.15 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [17/10/2009 12.00.18 360584]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [12/10/2009 21.24.54 9968]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [12/10/2009 21.24.52 74480]
R2 avg9emc;AVG E-mail Scanner;c:\programmi\AVG\AVG9\avgemc.exe [17/10/2009 12.00.23 906520]
R2 avg9wd;AVG WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [17/10/2009 11.59.28 285392]
R2 avgfws9;AVG Firewall;c:\programmi\AVG\AVG9\avgfws9.exe [22/10/2009 10.36.03 2321208]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [17/10/2009 11.57.52 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [17/10/2009 11.59.26 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [17/10/2009 11.59.24 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [17/10/2009 11.59.19 25736]
R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [12/06/2009 3.05.38 254976]
R3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [12/10/2009 21.24.56 7408]
S2 AVGIDSAgent;AVG9IDSAgent;c:\programmi\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [22/10/2009 10.38.26 5832712]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [17/10/2009 11.57.52 30104]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [30/09/2008 8.20.19 96856]
S3 u9usbser;MYWAVEU9 USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\u9usbser.sys --> c:\windows\system32\DRIVERS\u9usbser.sys [?]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.virgilio.it/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0410&s=0&o=xph&d=0609&m=aoa110
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {5183C2D4-A348-4039-B785-A4648224A2A5} = 151.99.125.1,151.99.0.100
TCP: {E523514D-2360-4836-A23E-B37D85F8B8F5} = 151.99.125.1,151.99.0.100
FF - ProfilePath - c:\documents and settings\ser\Dati applicazioni\Mozilla\Firefox\Profiles\xm44r21d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.virgilio.it/
FF - component: c:\programmi\AVG\AVG9\Firefox\components\avgssff.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-24 21:57
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1092)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3696)
c:\windows\system32\WININET.dll
.
Ora fine scansione: 2009-10-24 22.00.55
ComboFix-quarantined-files.txt 2009-10-24 20:00
Pre-Run: 1.575.477.248 byte disponibili
Post-Run: 1.542.807.552 byte disponibili
- - End Of File - - 6CB40B491F191A5E0D2A215D06981BC0