eccomi r16...si uso anche google chrome. ricordami alla fine cone disinstallare combofix. di seguito il report
ComboFix 09-03-18.01 - Salvatore 2009-03-18 23:39:12.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.2047.1488 [GMT 1:00]
Eseguito da: c:\documents and settings\Salvatore\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated)
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-02-18 al 2009-03-18 )))))))))))))))))))))))))))))))))))
.
2009-03-08 17:27 . 2009-03-08 17:28 6,703,104 --a------ C:\dump_dvd.vob
2009-03-08 07:18 . 2004-05-14 16:53 462,848 --a------ c:\windows\system32\ltkrn13n.dll
2009-03-08 07:18 . 2004-05-14 16:53 450,560 --a------ c:\windows\system32\ltimg13n.dll
2009-03-08 07:18 . 2004-05-14 16:53 401,408 --a------ c:\windows\system32\lfcmp13n.dll
2009-03-08 07:18 . 2004-05-14 16:53 299,008 --a------ c:\windows\system32\ltdis13n.dll
2009-03-08 07:18 . 2004-01-12 02:09 206,336 --a------ c:\windows\system32\ltefx13n.dll
2009-03-08 07:18 . 2004-05-14 16:53 163,840 --a------ c:\windows\system32\ltfil13n.dll
2009-03-08 07:18 . 2003-11-04 15:11 159,744 --a------ c:\windows\system32\lfpng13n.dll
2009-03-08 07:18 . 2003-11-04 15:10 69,632 --a------ c:\windows\system32\lfgif13n.dll
2009-03-08 07:18 . 2004-05-14 16:53 57,344 --a------ c:\windows\system32\lfbmp13n.dll
2009-03-08 00:25 . 2009-03-08 00:25 <DIR> d-------- c:\documents and settings\Salvatore\Dati applicazioni\dvdcss
2009-03-07 18:14 . 2009-03-07 18:14 <DIR> d-------- c:\documents and settings\Salvatore\Dati applicazioni\vlc
2009-03-07 18:13 . 2009-03-07 18:13 <DIR> d-------- c:\programmi\VideoLAN
2009-02-25 19:07 . 2009-02-25 19:07 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2009-02-24 19:07 . 2009-01-09 20:19 1,090,181 -----c--- c:\windows\system32\dllcache\ntprint.cat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-18 21:28 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-03-18 18:50 --------- d-----w c:\documents and settings\Salvatore\Dati applicazioni\uTorrent
2009-03-16 19:55 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-03-16 18:45 --------- d-----w c:\programmi\Spybot - Search & Destroy
2009-03-16 18:44 --------- d---a-w c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-03-16 18:44 --------- d-----w c:\programmi\SpywareBlaster
2009-03-16 18:09 --------- d-----w c:\programmi\EPSON Print CD
2009-03-08 10:02 --------- d-----w c:\programmi\eMule
2009-03-07 23:19 --------- d-----w c:\documents and settings\Salvatore\Dati applicazioni\Ahead
2009-03-07 23:19 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Ahead
2009-02-27 07:08 --------- d-----w c:\programmi\Microsoft Silverlight
2009-02-25 18:08 --------- d-----w c:\programmi\SUPERAntiSpyware
2009-02-25 18:08 --------- d-----w c:\documents and settings\Salvatore\Dati applicazioni\SUPERAntiSpyware.com
2009-02-15 17:51 --------- d-----w c:\programmi\Windows Live SkyDrive
2009-02-15 17:51 --------- d-----w c:\programmi\Microsoft
2009-02-15 17:50 --------- d-----w c:\programmi\Windows Live
2009-02-14 23:03 --------- d-----w c:\programmi\HDD Regenerator
2009-02-14 20:16 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\TVU Networks
2009-02-14 18:59 --------- d-----w c:\documents and settings\LocalService\Dati applicazioni\Ahead
2009-02-12 22:07 --------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-09 14:04 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 17:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-02 20:18 --------- d-----w c:\programmi\Reference Assemblies
2009-02-02 20:18 --------- d-----w c:\programmi\MSBuild
2009-01-25 10:42 --------- d-----w c:\programmi\Photo Story 3 for Windows
2009-01-23 09:26 --------- d-----w c:\programmi\IObit
2009-01-23 09:26 --------- d-----w c:\documents and settings\Salvatore\Dati applicazioni\IObit
2009-01-19 19:20 --------- d-----w c:\documents and settings\Salvatore\Dati applicazioni\Skype
2009-01-19 19:06 --------- d-----w c:\documents and settings\Salvatore\Dati applicazioni\skypePM
2009-01-07 17:37 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-11 08:09 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008101120081012\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Salvatore\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-17 64512]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"RemoteControl"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"LogitechCommunicationsManager"="c:\programmi\File comuni\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LVCOMSX"="c:\programmi\File comuni\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-07 1601304]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-12-14 136600]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:\windows\system32\HdAShCut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-07 18:37 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iPMS.exe]
"Debugger"=dummy.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iPMS20.exe]
"Debugger"=dummy.dat
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-10-01 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-01 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-10-01 107272]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-07 903960]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-07 298264]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
.
Contenuto della cartella 'Scheduled Tasks'
2009-03-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-484763869-884357618-682003330-1003.job
- c:\documents and settings\Salvatore\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2008-09-04 19:39]
2009-03-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-03-01 c:\windows\Tasks\SmartDefrag.job
- c:\programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-13 18:15]
2009-03-01 c:\windows\Tasks\SmartDefrag.job
- c:\programmi\IObit\IObit SmartDefrag\ [2009-03-01 07:57]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-18 23:40:29
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-03-18 23:42:01
ComboFix-quarantined-files.txt 2009-03-18 22:41:59
Pre-Run: 245,251,825,664 byte disponibili
Post-Run: 245,291,499,520 byte disponibili
161 --- E O F --- 2009-03-16 07:15:01