eccolo se ho fatto giusto ho anche disabilitato non so che provo adesso ad attivare l'antivirus e fare la scansine della pen drive
ComboFix 09-04-01.01 - Asus 2009-04-02 22.56.47.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1919.1313 [GMT 2:00]
Eseguito da: c:\documents and settings\Asus\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Asus\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-03-02 al 2009-04-02 )))))))))))))))))))))))))))))))))))
.
2009-04-02 22:51 . 2003-06-25 16:05 266,360 --a------ c:\windows\system32\TweakUI.exe
2009-04-02 22:51 . 2002-06-21 15:09 160,217 --a------ c:\windows\system32\PowerToysLicense.rtf
2009-04-02 22:26 . 2009-04-02 22:26 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2009-04-02 22:26 . 2009-04-02 22:26 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2009-04-02 19:03 . 2009-04-02 19:03 <DIR> d-------- c:\programmi\Trend Micro
2009-04-02 18:03 . 2009-04-02 18:03 <DIR> d-------- c:\programmi\Secunia
2009-04-01 17:33 . 2009-04-01 17:33 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\NortonInstaller
2009-04-01 17:08 . 2009-04-01 17:08 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-04-01 17:08 . 2009-04-01 17:08 <DIR> d-------- c:\documents and settings\Asus\Dati applicazioni\Malwarebytes
2009-04-01 17:08 . 2009-04-01 17:08 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-04-01 17:08 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-01 17:08 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-28 18:43 . 2009-03-29 15:36 <DIR> d-------- c:\programmi\File comuni\Adobe AIR
2009-03-26 21:18 . 2009-03-26 21:18 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-24 13:03 . 2009-03-24 13:03 7,808 --a------ c:\windows\system32\drivers\psi_mf.sys
2009-03-22 19:22 . 2009-03-22 19:22 48 --ah----- c:\windows\system32\ezsidmv.dat
2009-03-22 19:19 . 2009-03-22 19:19 <DIR> dr------- c:\programmi\Skype
2009-03-22 19:19 . 2009-03-22 19:19 <DIR> d-------- c:\programmi\File comuni\Skype
2009-03-17 19:20 . 2006-06-29 14:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-03-17 00:03 . 2009-03-17 00:03 <DIR> d-------- c:\documents and settings\Asus\Dati applicazioni\Windows Search
2009-03-17 00:02 . 2009-03-17 00:02 <DIR> d-------- c:\windows\system32\GroupPolicy
2009-03-17 00:02 . 2009-03-18 10:45 <DIR> d-------- c:\programmi\Windows Desktop Search
2009-03-16 23:24 . 2009-01-09 21:19 1,090,181 -----c--- c:\windows\system32\dllcache\ntprint.cat
2009-03-16 22:23 . 2009-03-17 00:05 <DIR> d-------- c:\windows\system32\XPSViewer
2009-03-16 22:23 . 2009-03-16 22:23 <DIR> d-------- c:\programmi\Reference Assemblies
2009-03-16 22:22 . 2008-07-06 14:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-03-16 22:22 . 2008-07-06 14:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-03-16 22:22 . 2008-07-06 12:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-03-16 22:22 . 2008-07-06 14:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-03-16 22:22 . 2008-07-06 14:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-03-16 22:22 . 2008-07-06 14:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-03-16 22:22 . 2008-07-06 14:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-03-14 01:14 . 2009-03-14 01:16 <DIR> d-------- c:\documents and settings\Asus\Dati applicazioni\vlc
2009-03-12 22:11 . 2008-04-14 05:13 159,232 --a------ c:\windows\system32\ptpusd.dll
2009-03-12 22:11 . 2008-04-13 21:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-03-12 22:11 . 2008-04-13 21:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-03-12 22:11 . 2001-08-31 00:07 5,632 --a------ c:\windows\system32\ptpusb.dll
2009-03-12 21:15 . 2009-03-12 21:15 <DIR> d-------- c:\programmi\Microsoft Visual Studio 8
2009-03-12 00:29 . 2004-08-19 15:39 221,184 --a------ c:\windows\system32\wmpns.dll
2009-03-10 00:58 . 2009-04-02 21:42 <DIR> d-------- c:\documents and settings\Asus\Tracing
2009-03-10 00:57 . 2009-03-11 14:11 <DIR> d-------- c:\programmi\Microsoft Silverlight
2009-03-10 00:57 . 2009-03-10 00:57 <DIR> d-------- c:\programmi\Microsoft Office Outlook Connector
2009-03-10 00:50 . 2009-03-10 00:50 <DIR> d-------- c:\programmi\Windows Live SkyDrive
2009-03-10 00:50 . 2009-03-10 00:57 <DIR> d-------- c:\programmi\Microsoft
2009-03-10 00:44 . 2009-03-10 00:44 <DIR> d-------- c:\programmi\File comuni\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 20:26 --------- d-----w c:\documents and settings\Asus\Dati applicazioni\SUPERAntiSpyware.com
2009-04-02 19:42 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-04-02 19:40 622,624 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-02 19:40 4,256 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-02 19:40 23,448 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-02 19:40 2,594,848 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-02 19:01 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-04-01 15:36 --------- d-----w c:\documents and settings\Asus\Dati applicazioni\Symantec
2009-03-28 16:36 --------- d-----w c:\programmi\File comuni\Adobe
2009-03-26 19:18 410,984 -c--a-w c:\windows\system32\deploytk.dll
2009-03-22 17:24 --------- d-----w c:\documents and settings\Asus\Dati applicazioni\Skype
2009-03-22 17:22 --------- d-----w c:\documents and settings\Asus\Dati applicazioni\skypePM
2009-03-22 17:19 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Skype
2009-03-16 20:23 --------- d-----w c:\programmi\MSBuild
2009-03-12 19:18 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-03-09 22:49 --------- d-----w c:\programmi\Windows Live
2009-02-28 18:22 --------- d-----w c:\programmi\Messenger Plus! Live
2009-02-21 21:20 --------- d-----w c:\documents and settings\Asus\Dati applicazioni\live-player
2009-02-21 07:25 691,592 ----a-w c:\windows\system32\OGACheckControl.DLL
2009-02-19 20:19 --------- d-----w c:\programmi\CCleaner
2009-02-18 17:40 --------- d-----w c:\programmi\MegaLink
2009-02-17 17:11 24,232 -c--a-w c:\windows\system32\drivers\ElbyCDIO.sys
2009-02-17 13:33 89,256 -c--a-w c:\windows\system32\ElbyCDIO.dll
2009-02-09 14:04 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-07 14:39 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\EPSON
2009-02-07 14:34 --------- d-----w c:\programmi\EPSON
2009-02-06 17:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-04 14:05 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-03 17:45 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 17:45 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-01-02 19:54 499,712 -c--a-w c:\windows\system32\msvcp71.dll
2009-01-02 19:54 348,160 -c--a-w c:\windows\system32\msvcr71.dll
2008-05-17 17:23 32 -c--a-w c:\documents and settings\All Users\Dati applicazioni\ezsid.dat
2008-10-03 18:28 32,768 -csha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008100320081004\index.dat
.
(((((((((((((((((((((((((((((
SnapShot@2009-04-02_21.44.30.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-02 20:26:35 18,944 ----a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2009-04-02 20:26:35 65,024 ----a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-09 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"VeohPlugin"="c:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-12-16 3528440]
"ccleaner"="c:\programmi\CCleaner\CCleaner.exe" [2009-03-24 1488112]
"EPSON Stylus Photo R285 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICKE.EXE" [2007-04-13 182272]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="c:\programmi\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-16 8478720]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-08-16 81920]
"RemoteControl"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-04 206088]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2009-01-02 185872]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-26 148888]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SkyTel"="SkyTel.EXE" [2007-04-13 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Asus\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 12:05 356352 c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Programmi\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\Italian\\setup.exe"=
"c:\\Programmi\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\Programmi\\Nero\\Nero8\\Nero ShowTime\\ShowTime.exe"=
"c:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [2009-03-23 9968]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [2009-03-23 72944]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:\windows\system32\StkCSrv.exe [2007-04-19 24576]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\system32\drivers\StkCMini.sys [2007-06-06 1260672]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-03-24 7808]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - SASDIFSV
*NewlyCreated* - SASENUM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{55f70c60-0f39-11de-a028-001d60dddb41}]
\Shell\AutoRun\command - G:\Autorun.exe /run
\Shell\Shell00\Command - G:\Autorun.exe /run
\Shell\Shell01\Command - G:\Autorun.exe /action
\Shell\Shell02\Command - G:\Autorun.exe /uninstall
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{91724ec6-cbe7-11dc-9dba-f1c7c3a4ee5c}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4a05e60-5be0-11dd-9ee5-001d60dddb41}]
\Shell\AutoRun\command - G:\setupSNK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'
2009-04-02 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 23:29]
2009-04-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-04-02 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
mStart Page = about:blank
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-02 22:58:22
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2009-04-02 23.00.11
ComboFix-quarantined-files.txt 2009-04-02 21:00:08
ComboFix2.txt 2009-04-02 19:50:38
ComboFix3.txt 2009-04-02 19:45:49
Pre-Run: 33.832.742.912 byte disponibili
Post-Run: 33,832,083,456 byte disponibili
212 --- E O F --- 2009-03-25 15:07:23