Ecco il log di ComboFix, spero di aver fatto bene......non ho molto esperienza con questi programmi......sai sono una nonna ma molto appassionata di computer...
ComboFix 08-07-19.1 - GASPERINI 2008-07-20 10.25.48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.80 [GMT 2:00]
Eseguito da: C:\Documents and Settings\GASPERINI\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\setup.inf
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Creati Da 2008-06-20 al 2008-07-20 )))))))))))))))))))))))))))))))))))
.
2008-07-20 07:32 . 2008-07-20 09:32 <DIR> d-------- C:\VEXPLITE
2008-07-20 07:32 . 2008-03-17 19:23 39,808 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-07-19 23:25 . 2008-07-19 23:25 <DIR> d-------- C:\Programmi\CCleaner
2008-07-19 12:12 . 2008-07-19 12:12 <DIR> d-------- C:\Programmi\File comuni\Wise Installation Wizard
2008-07-19 10:12 . 2008-07-19 11:21 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-07-13 18:12 . 2008-06-20 19:36 247,296 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-07-13 18:12 . 2008-06-20 11:32 225,920 --------- C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-07-13 18:12 . 2008-06-20 12:44 138,368 --------- C:\WINDOWS\system32\dllcache\afd.sys
2008-07-13 18:12 . 2006-08-16 14:13 100,352 --------- C:\WINDOWS\system32\dllcache\6to4svc.dll
2008-07-07 22:16 . 2008-07-07 22:16 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\eBay
2008-07-01 16:33 . 2008-07-06 09:02 539 --a------ C:\WINDOWS\asprofil.ini
2008-07-01 16:33 . 2008-07-18 18:17 410 --a------ C:\WINDOWS\Studio.ini
2008-07-01 16:32 . 2008-07-02 22:37 <DIR> d-------- C:\Studio4
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-16 15:00 --------- d-----w C:\Programmi\eMule
2008-07-08 14:12 --------- d-----w C:\Programmi\Google
2008-07-01 13:10 --------- d-----w C:\Programmi\Microsoft Works
2008-06-20 17:36 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:36 147,968 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:44 360,960 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 360,960 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:32 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-07 15:16 --------- d-----w C:\Programmi\Western Digital Technologies
2008-06-03 08:31 --------- d-----w C:\Programmi\Fast Midi To Mp3 KARAOKE
2008-06-01 15:09 --------- d-----w C:\Programmi\MIDIP3
2008-06-01 15:04 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-01 15:04 253,952 ------w C:\WINDOWS\Setup1.exe
2008-06-01 14:43 --------- d-----w C:\Programmi\NCH Swift Sound
2008-06-01 14:43 --------- d-----w C:\Documents and Settings\GASPERINI\Dati applicazioni\NCH Swift Sound
2008-06-01 14:43 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\NCH Swift Sound
2008-05-31 13:42 --------- d-----w C:\Programmi\KARINO VIDEO CONVERTER 1.2
2008-05-29 18:54 --------- d-----w C:\Programmi\DivX
2008-05-25 15:44 --------- d-----w C:\Programmi\VideoLAN
2008-05-20 14:10 --------- d-----w C:\Programmi\ffdshow
2008-05-08 12:14 203,008 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:14 1,292,800 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:14 1,292,800 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-27 18:11 364,544 ----a-w C:\WINDOWS\system32\WDBtnMgr.exe
2008-04-23 20:16 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:42 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:42 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-03-17 09:28 16,384 --sha-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
2008-03-17 09:28 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
2008-03-17 09:28 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008031720080318\index.dat
2008-03-17 09:28 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:39 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-09-20 15:35 202024]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-07-08 16:12 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
"NeroFilterCheck"="C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 09:51 1836328]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-07-20 08:42 245760]
"WD Button Manager"="WDBtnMgr.exe" [2008-04-27 20:11 364544 C:\WINDOWS\system32\WDBtnMgr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15:39 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Reader Synchronizer.lnk - C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 01:01:50 734872]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 02:48:20 40048]
hp psc 1000 series.lnk - C:\Programmi\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 02:17:18 147456]
hpoddt01.exe.lnk - C:\Programmi\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 02:06:58 28672]
LUMIX Simple Viewer.lnk - C:\Programmi\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-03-24 18:42:49 57344]
WinZip Quick Pick.lnk - C:\Programmi\WinZip\WZQKPICK.EXE [2008-03-30 20:40:00 118784]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0
"1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1
"1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2
"1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3
"1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4
"1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5
"1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6
"1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7
"1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8
"1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration
"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 19:23]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-07-20 08:42]
R3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
S2 Network WanMiniport First Position;Network WanMiniport First Position;C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe []
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\wd_windows_tools\WDEULA.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
"2008-07-19 20:31:01 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1206048671.job"
- C:\Programmi\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
.
- - - - ORFÃOS REMOVIDOS - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-20 10:27:35
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-07-20 10:29:14
ComboFix-quarantined-files.txt 2008-07-20 08:29:11
Pre-Run: 61,549,453,312 byte disponibili
Post-Run: 61,565,165,568 byte disponibili
143 --- E O F --- 2008-07-15 08:27:35