per sicurezza ho fatto girare combofix. guarda se va tutto bene ciao e grazie
ComboFix 08-10-04.07 - SaWa 2008-10-05 10.06.42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.607 [GMT 2:00]
Eseguito da: C:\Documents and Settings\SaWa\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MCHINJDRV
((((((((((((((((((((((((( Files Creati Da 2008-09-05 al 2008-10-05 )))))))))))))))))))))))))))))))))))
.
2008-10-05 09:38 . 2008-10-05 09:38 <DIR> d-------- C:\Programmi\Defraggler
2008-10-05 09:24 . 2008-10-05 09:24 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-10-04 13:22 . 2008-10-04 13:22 <DIR> d-------- C:\Programmi\Eusing Free Registry Cleaner
2008-10-04 12:53 . 2008-10-04 12:53 <DIR> d-------- C:\Documents and Settings\SaWa\WINDOWS
2008-09-09 11:56 . 2008-09-09 11:56 <DIR> d-------- C:\Programmi\NKProds
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-04 11:28 --------- d-----w C:\Programmi\Spybot - Search & Destroy
2008-10-04 10:54 --------- dcsh--w C:\Programmi\File comuni\WindowsLiveInstaller
2008-10-04 10:54 --------- d-----w C:\Programmi\QuickTime
2008-10-04 10:54 --------- d-----w C:\Programmi\Picasa2
2008-10-04 10:54 --------- d-----w C:\Programmi\eMule
2008-10-04 10:54 --------- d-----w C:\Programmi\CDBurnerXP
2008-10-04 10:54 --------- d-----w C:\Programmi\AMP Font Viewer
2008-10-04 10:54 --------- d-----w C:\Documents and Settings\SaWa\Dati applicazioni\Nokia
2008-10-04 10:54 --------- d-----w C:\Documents and Settings\SaWa\Dati applicazioni\LimeWire
2008-10-04 10:49 --------- d-----w C:\Documents and Settings\SaWa\Dati applicazioni\EPSON
2008-10-04 10:49 --------- d-----w C:\Documents and Settings\SaWa\Dati applicazioni\Acronis
2008-10-04 10:49 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Trymedia
2008-10-04 10:49 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-10-04 10:49 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Avg8
2008-10-04 10:43 --------- d-----w C:\Programmi\a-squared Free
2008-10-04 10:38 --------- d-----w C:\Programmi\SpywareBlaster
2008-09-04 16:12 --------- d-----w C:\Documents and Settings\SaWa\Dati applicazioni\U3
2008-08-31 13:31 51,716 ----a-w C:\WINDOWS\system32\pdf995mon.dll
2008-08-31 13:31 249,856 ----a-w C:\WINDOWS\system32\pdfmona.dll
2008-08-31 13:31 --------- d-----w C:\Programmi\pdf995
2008-08-31 13:31 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\pdf995
2008-08-30 17:10 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-08-28 08:40 --------- d-----w C:\Programmi\ABBYY FineReader Professional
2008-08-27 08:36 --------- d-----w C:\Documents and Settings\SaWa\Dati applicazioni\GlarySoft
2008-08-27 08:35 --------- d-----w C:\Programmi\Glary Utilities
2008-08-25 09:16 --------- d-----w C:\Programmi\Auslogics
2008-08-22 14:50 --------- d-----w C:\Programmi\LimeWire
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-14 12:53 122,724 ----a-w C:\Documents and Settings\SaWa\cmd.bat
2008-07-07 20:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 14:04 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus CX3200"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-07-01 74752]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2005-12-21 73728]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-25 1235736]
"TrueImageMonitor.exe"="C:\Programmi\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-03-10 2617808]
"AcronisTimounterMonitor"="C:\Programmi\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-03-10 909592]
"Acronis Scheduler2 Service"="C:\Programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2008-03-10 140568]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 8523776]
"EPSON Stylus CX3200"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-07-01 74752]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2008-03-28 413696]
"SoundMan"="SOUNDMAN.EXE" [2005-06-20 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2007-12-05 C:\WINDOWS\system32\nwiz.exe]
C:\Documents and Settings\SaWa\Menu Avvio\Programmi\Esecuzione automatica\
ScreenHunter 5.0 Free.lnk.disabled [2008-04-25 1784]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Picture Package Menu.lnk.disabled [2008-05-02 743]
Picture Package VCD Maker.lnk.disabled [2008-05-02 793]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Programmi\QuickTime\QTTask.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
"PcSync"=C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" -atboottime
"NeroFilterCheck"=C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
"EPSON Stylus CX3200"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
"TrueImageMonitor.exe"=C:\Programmi\Acronis\TrueImageHome\TrueImageMonitor.exe
"UnlockerAssistant"="C:\Programmi\Unlocker\UnlockerAssistant.exe" -H
"PCSuiteTrayApplication"=C:\PROGRA~1\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\Programmi\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"C:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"C:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\Download Express\\dep.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-20 12936]
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2005-02-10 16640]
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-05-22 368480]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-25 97928]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-15 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-25 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-20 76040]
R2 NMSAccessU;NMSAccessU;C:\Programmi\CDBurnerXP\NMSAccessU.exe [2008-06-15 71096]
R2 TryAndDecideService;Acronis Try And Decide Service;C:\Programmi\File comuni\Acronis\Fomatik\TrueImageTryStartService.exe [2008-03-10 522448]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80a2a0dc-7141-11dd-96b0-00508d7f1720}]
\Shell\AutoRun\command - G:\.\run\autorun.exe
\Shell\open\Command - G:\.\run\autorun.exe
.
Contenuto della cartella 'Scheduled Tasks'
2008-10-05 C:\WINDOWS\Tasks\GlaryInitialize.job
- C:\Programmi\Glary Utilities\initialize.exe [2008-07-18 11:08]
2008-08-28 C:\WINDOWS\Tasks\Schedule Task Weekly.job
- C:\Programmi\Registry Easy\RE.exe []
.
.
------- Supplementare di scansione -------
.
FireFox -: Profile - C:\Documents and Settings\SaWa\Dati applicazioni\Mozilla\Firefox\Profiles\6w9eikde.default\
FF -: plugin - C:\Programmi\Picasa2\npPicasa2.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-05 10:09:26
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
C:\Programmi\File comuni\EPSON\eEBAPI\eEBSvc.exe
C:\Programmi\a-squared Free\a2service.exe
C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
C:\Programmi\File comuni\EPSON\eEBAPI\SAgent2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Ora fine scansione: 2008-10-05 10:10:48 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-10-05 08:10:44
Pre-Run: 83.750.363.136 byte disponibili
Post-Run: 83,654,299,648 byte disponibili
179 --- E O F --- 2008-10-05 07:27:25