ho eseguito tutto alla lettera. ecco il log di combofix. grazie.ComboFix 10-05-31.03 - user 01/06/2010 15.39.27.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.511.191 [GMT 2:00]
Eseguito da: c:\documents and settings\user\Documenti\Downloads\ComboFix.exe
Opzioni usate :: c:\documents and settings\user\Desktop\CFScript.txt.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
FILE ::
"c:\programmi\Lavasoft\Ad-Aware\AAWService.exe"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\Lavasoft\Ad-Aware\AAWService.exe
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_LAVASOFT_AD-AWARE_SERVICE
-------\Legacy_LBD
-------\Service_Lavasoft Ad-Aware Service
-------\Service_Lbd
((((((((((((((((((((((((( Files Creati Da 2010-05-01 al 2010-06-01 )))))))))))))))))))))))))))))))))))
.
2010-06-01 11:01 . 2010-06-01 11:01 -------- d-----w- c:\programmi\VS Revo Group
2010-05-30 13:42 . 2010-05-30 13:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-05-30 13:42 . 2010-05-30 13:42 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-30 13:42 . 2010-05-30 13:42 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-30 13:41 . 2010-06-01 07:54 -------- d-----w- c:\windows\system32\drivers\Avg
2010-05-30 13:41 . 2010-05-30 13:41 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-30 13:41 . 2010-05-30 13:41 -------- d-----w- c:\programmi\AVG
2010-05-30 13:41 . 2010-05-30 13:41 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-05-30 13:21 . 2010-05-30 13:21 -------- d-----w- c:\programmi\Foxit Software
2010-05-30 13:21 . 2010-05-30 13:21 -------- d-----w- c:\documents and settings\user\Dati applicazioni\Foxit
2010-05-30 13:15 . 2010-05-30 13:15 -------- d-----w- c:\documents and settings\user\Dati applicazioni\TeamViewer
2010-05-30 13:15 . 2010-05-30 13:15 -------- d-----w- c:\programmi\TeamViewer
2010-05-30 13:12 . 2010-05-30 13:12 -------- d-----w- c:\programmi\IZArc
2010-05-30 11:43 . 2010-05-30 11:43 388096 ----a-r- c:\documents and settings\user\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-05-30 11:43 . 2010-05-30 11:43 -------- d-----w- c:\programmi\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-01 12:23 . 2010-03-21 23:40 -------- d-----w- c:\programmi\FlashCAD
2010-06-01 10:51 . 2009-06-20 12:06 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-05-31 19:55 . 2004-08-19 12:00 93636 ----a-w- c:\windows\system32\perfc010.dat
2010-05-31 19:55 . 2004-08-19 12:00 515520 ----a-w- c:\windows\system32\perfh010.dat
2010-05-30 14:15 . 2008-09-19 23:29 -------- d-----w- c:\programmi\Google
2010-05-30 13:24 . 2008-09-11 08:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WinZip
2010-05-30 12:52 . 2008-09-11 08:24 -------- d-----w- c:\programmi\File comuni\Adobe
2010-05-30 12:43 . 2008-12-07 00:43 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-05-30 12:43 . 2008-12-07 00:43 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-04-29 13:39 . 2009-06-20 12:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2009-06-20 12:06 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-09 19:01 . 2010-04-09 19:01 -------- d-----w- c:\programmi\Fatbits
2010-03-10 06:15 . 2004-08-19 12:00 420352 ----a-w- c:\windows\system32\vbscript.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRISMSVR.EXE"="c:\programmi\U.S. Robotics\Wireless USB Manager\PRISMSVR.EXE" [2004-07-02 295001]
"EPSON Stylus CX3600 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE" [2004-03-04 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
U.S. Robotics Wireless USB Adapter.lnk - c:\programmi\U.S. Robotics\Wireless USB Manager\USR11G.exe [2005-7-8 323584]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-30 13:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Windows Search.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-05-30 13:41 2064736 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\FlashCAD\\FlashCAD.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\TeamViewer\\Version5\\TeamViewer.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [30/05/2010 15.42.10 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [30/05/2010 15.41.23 242896]
R2 avg9wd;AVG Free WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [30/05/2010 15.41.10 308064]
S3 RSC4_A02;U.S. Robotics Wireless USB Adapter Driver;c:\windows\system32\drivers\RSC4USB.sys [16/11/2005 11.33.02 357568]
.
Contenuto della cartella 'Scheduled Tasks'
2010-05-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-1202660629-1801674531-1004Core.job
- c:\documents and settings\user\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-05 10:07]
2010-06-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-1202660629-1801674531-1004UA.job
- c:\documents and settings\user\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-05 10:07]
2010-06-01 c:\windows\Tasks\User_Feed_Synchronization-{A189DD0C-3F74-4E65-AF9D-2E0249B69CD4}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = <local>
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: {D81BF914-3DA4-4963-ACBB-0EE2E22F00D5} = 151.99.125.2,151.1.1.1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-01 15:46
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(684)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\AVG\AVG9\avgchsvx.exe
c:\programmi\AVG\AVG9\avgrsx.exe
c:\programmi\AVG\AVG9\avgcsrvx.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\File comuni\Protexis\License Service\PsiService_2.exe
c:\windows\system32\SearchIndexer.exe
c:\programmi\AVG\AVG9\avgnsx.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2010-06-01 15:51:30 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-06-01 13:51
ComboFix2.txt 2010-06-01 13:26
ComboFix3.txt 2010-06-01 13:00
Pre-Run: 47.618.318.336 byte disponibili
Post-Run: 47.497.367.552 byte disponibili
- - End Of File - - 8951149782471DFB15FFAAAA874B49E8