ciao r16, questo è il log di combofix:
ComboFix 08-11-23.02 - manu 2008-11-24 19.26.32.1 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1040.18.1184 [GMT 1:00]
Eseguito da: c:\users\manu\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\manu\AppData\Local\ycimmok.dat
c:\users\manu\AppData\Local\ycimmok.exe
c:\users\manu\AppData\Local\ycimmok_nav.dat
c:\users\manu\AppData\Local\ycimmok_navps.dat
c:\users\manu\FAVORI~1\Videos.url
c:\users\manu\Favorites\Videos.url
c:\windows\system32\x64
.
((((((((((((((((((((((((( Files Creati Da 2008-10-24 al 2008-11-24 )))))))))))))))))))))))))))))))))))
.
2008-11-22 16:33 . 2008-11-22 16:52 96,976 --a------ c:\windows\System32\drivers\klin.dat
2008-11-22 16:33 . 2008-11-22 16:52 87,855 --a------ c:\windows\System32\drivers\klick.dat
2008-11-22 16:32 . 2008-11-24 19:14 <DIR> d-------- c:\users\All Users\Kaspersky Lab
2008-11-22 16:32 . 2008-11-24 19:14 <DIR> d-------- c:\programdata\Kaspersky Lab
2008-11-22 16:32 . 2008-11-22 16:32 <DIR> d-------- c:\program files\Kaspersky Lab
2008-11-22 16:32 . 2008-11-24 19:03 4,039,200 --ahs---- c:\windows\System32\drivers\fidbox.dat
2008-11-22 16:32 . 2008-11-24 19:26 450,592 --ahs---- c:\windows\System32\drivers\fidbox2.dat
2008-11-22 16:32 . 2008-11-24 19:03 33,684 --ahs---- c:\windows\System32\drivers\fidbox.idx
2008-11-22 16:32 . 2008-11-24 19:26 3,668 --ahs---- c:\windows\System32\drivers\fidbox2.idx
2008-11-22 16:30 . 2008-11-22 16:30 <DIR> d-------- c:\users\All Users\Kaspersky Lab Setup Files
2008-11-22 16:30 . 2008-11-22 16:30 <DIR> d-------- c:\programdata\Kaspersky Lab Setup Files
2008-11-22 14:58 . 2008-11-22 14:58 <DIR> d-------- c:\program files\Trend Micro
2008-11-22 14:24 . 2008-11-22 14:24 <DIR> d-------- C:\PerfLogs
2008-11-12 09:55 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 09:55 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 09:55 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-03 18:42 . 2008-11-03 18:42 <DIR> d-------- c:\users\manu\AppData\Roaming\Malwarebytes
2008-11-03 18:42 . 2008-11-03 18:42 <DIR> d-------- c:\users\All Users\Malwarebytes
2008-11-03 18:42 . 2008-11-03 18:42 <DIR> d-------- c:\programdata\Malwarebytes
2008-11-03 18:42 . 2008-11-03 18:42 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-03 18:42 . 2008-10-22 16:10 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-03 18:42 . 2008-10-22 16:10 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-10-30 11:45 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-30 11:45 . 2008-01-19 08:36 37,888 --a------ c:\windows\System32\printcom.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-24 18:02 --------- d-----w c:\program files\Lx_cats
2008-11-24 17:54 --------- d-----w c:\programdata\GamesBar
2008-11-24 17:54 --------- d-----w c:\program files\Acer GameZone
2008-11-22 16:06 --------- d-----w c:\program files\eMule
2008-11-22 15:26 --------- d-----w c:\program files\ESET
2008-11-22 13:35 174 --sha-w c:\program files\desktop.ini
2008-11-22 13:27 --------- d-----w c:\program files\Windows Sidebar
2008-11-22 13:27 --------- d-----w c:\program files\Windows Photo Gallery
2008-11-22 13:27 --------- d-----w c:\program files\Windows Mail
2008-11-22 13:27 --------- d-----w c:\program files\Windows Journal
2008-11-22 13:27 --------- d-----w c:\program files\Windows Collaboration
2008-11-22 13:27 --------- d-----w c:\program files\Windows Calendar
2008-11-22 13:26 --------- d-----w c:\program files\Windows Defender
2008-11-22 13:05 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-11-22 13:05 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-11-13 16:51 --------- d-----w c:\programdata\Microsoft Help
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-08-13 14:41 334 ----a-w c:\users\manu\AppData\Roaming\wklnhst.dat
2008-04-18 16:05 92,064 ----a-w c:\users\manu\mqdmmdm.sys
2008-04-18 16:05 9,232 ----a-w c:\users\manu\mqdmmdfl.sys
2008-04-18 16:05 79,328 ----a-w c:\users\manu\mqdmserd.sys
2008-04-18 16:05 66,656 ----a-w c:\users\manu\mqdmbus.sys
2008-04-18 16:05 6,208 ----a-w c:\users\manu\mqdmcmnt.sys
2008-04-18 16:05 5,936 ----a-w c:\users\manu\mqdmwhnt.sys
2008-04-18 16:05 4,048 ----a-w c:\users\manu\mqdmcr.sys
2008-04-18 16:05 25,600 ----a-w c:\users\manu\usbsermptxp.sys
2008-04-18 16:05 22,768 ----a-w c:\users\manu\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-09 845360]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"eAudio"="c:\acer\Empowering Technology\eAudio\eAudio.exe" [2007-05-09 1286144]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-12 457728]
"EzPrint"="c:\program files\Lexmark 2300 Series\ezprint.exe" [2007-04-29 103344]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-05-03 206952]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-04-04 678672]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"dscService"="c:\windows\system32\USBPlug.exe" [2005-03-01 278528]
"lxdpmon.exe"="c:\program files\Lexmark Z2300 Series\lxdpmon.exe" [2008-03-27 656040]
"LXCGCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2007-02-22 73728]
"lxcgmon.exe"="c:\program files\Lexmark 2300 Series\lxcgmon.exe" [2007-04-29 205744]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-10 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-05-07 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\users\manu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
VirtualExpander.lnk - c:\users\manu\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe [2008-03-16 474808]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2001-01-12 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll eNetHook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4B0751C5-784B-403C-956E-DC5CCB6177DF}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BB86AB3F-5A5B-4CF1-A043-70B99CF3C7DB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A2527E5E-2B9E-4247-91E8-DB394D49473E}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{F687A61F-981B-4F51-87E8-F6638F7E7418}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{47956FC8-36AC-4C18-B68B-2A14FBBE1282}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{84895A17-328E-4F95-81A5-7DB717CDD81C}"= c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{0A13BE49-2B62-470D-AAD0-3EE360B3A47A}"= c:\program files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{B488E90E-A860-4209-80F4-6A0D458FC76C}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{671CB9C9-2E09-4DFF-8CEF-D1AB1F3D075F}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{73CB679F-E3BE-4411-B698-82BA2D079972}"= c:\program files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{A721887E-D5B3-44CE-9740-4453470F753E}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{2F011741-A436-4B3B-AF1A-8F3CAE1AFC52}"= c:\program files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{7FE56284-BF1E-4485-9F54-50CB31129A2F}"= c:\program files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{20A9B4B3-52C2-4AA6-8223-66978D69ECB6}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{505BCF9E-56EF-498A-AF4B-EFD5F08628D7}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{146605B1-88E3-472B-A0A7-560CCECFC66A}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{D4639763-73BA-4A4E-A694-4D7D05D0E9F6}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{1BFB9EA4-5E99-40BA-8D7B-CE3751436635}"= UDP:c:\windows\System32\lxdpcoms.exe:Lexmark Communications System
"{2724A735-F55E-4111-9CA4-614E65C2573C}"= TCP:c:\windows\System32\lxdpcoms.exe:Lexmark Communications System
"{8D3BA477-0CC5-4E3E-AF25-3576274EC8C5}"= UDP:c:\windows\System32\lxcgcoms.exe:Lexmark Communications System
"{60E53207-0ED7-4A9F-9721-385661776349}"= TCP:c:\windows\System32\lxcgcoms.exe:Lexmark Communications System
"{1C09487F-0553-4276-BCD6-654C9059F455}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxcgpswx.exe:Printer Status Window
"{322EC77C-EF95-4A82-974B-305BD1EDC1E7}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxcgpswx.exe:Printer Status Window
"{0938EB96-9C9E-4B22-B765-0FE3A7A5E768}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{FFCC859F-940C-4BE7-95CA-D8B3192F0524}c:\\program files\\lexmark z2300 series\\lxdpmon.exe"= UDP:c:\program files\lexmark z2300 series\lxdpmon.exe:Printer Device Monitor
"UDP Query User{103D42C4-3A87-4BDC-8493-A4DA4C6E30D0}c:\\program files\\lexmark z2300 series\\lxdpmon.exe"= TCP:c:\program files\lexmark z2300 series\lxdpmon.exe:Printer Device Monitor
"TCP Query User{757C5907-BC9C-4F77-86A2-A5B6A13D4BE0}c:\\program files\\lexmark z2300 series\\lxdpmon.exe"= UDP:c:\program files\lexmark z2300 series\lxdpmon.exe:Printer Device Monitor
"UDP Query User{7D3AD50D-4F41-4329-BCE1-63D5CA753192}c:\\program files\\lexmark z2300 series\\lxdpmon.exe"= TCP:c:\program files\lexmark z2300 series\lxdpmon.exe:Printer Device Monitor
"TCP Query User{F8AA5FC8-A32F-4131-8210-D2760531823C}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{ED8269F6-CE02-45CF-B8F9-38C21CBD3C2E}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{583670C8-463F-4B5E-B593-AF648613A7E9}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{10C9D537-CACF-4655-AD39-FA7535EF1AA6}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{22E6695E-002D-4808-B25D-EF64BDFA5F27}c:\\ludopoli\\ludopoli.exe"= UDP:c:\ludopoli\ludopoli.exe:ludopoli
"UDP Query User{CC34EFE6-E995-4E27-AAE1-E2B765DCA808}c:\\ludopoli\\ludopoli.exe"= TCP:c:\ludopoli\ludopoli.exe:ludopoli
"TCP Query User{B82ACC13-5748-4B31-B40A-3A882414D2A8}c:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\italian\\setup.exe"= UDP:c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\italian\setup.exe:Kaspersky Internet Security 2009 Setup
"UDP Query User{90AED05B-7722-4C9F-B121-563CA028A785}c:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\italian\\setup.exe"= TCP:c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\italian\setup.exe:Kaspersky Internet Security 2009 Setup
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2008-03-26 20496]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};\??\c:\program files\Acer Arcade Deluxe\Play Movie\
000.fcl [2007-07-03 22:20:08 13560]
R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2001-01-12 50688]
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service []
R2 TeamViewer;TeamViewer 3;"c:\program files\TeamViewer3\TeamViewer_Host.exe" -service [2008-01-28 94208]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2008-04-06 2591232]
R3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-04-06 32256]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-04-06 179712]
S3 qcusbser;Qualcomm USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\qcusbser.sys [2008-04-09 64640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
2008-11-24 c:\windows\Tasks\User_Feed_Synchronization-{FF2624F4-0DEC-4341-BF07-FB9D05D38EA2}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
- - - - ORFÃOS REMOVIDOS - - - -
HKCU-Run-ycimmok - c:\users\manu\appdata\local\ycimmok.exe
HKCU-Run-Acer Tour Reminder - (no file)
.
------- Supplementare di scansione -------
.
FireFox -: Profile - c:\users\manu\AppData\Roaming\Mozilla\Firefox\Profiles\3iuckwn2.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.yahoo.comFF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\Yahoo!\common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-24 19:29:23
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(744)
c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
- - - - - - - > 'lsass.exe'(692)
c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
.
Ora fine scansione: 2008-11-24 19.30.51
ComboFix-quarantined-files.txt 2008-11-24 18:30:48
Pre-Run: 33.254.408.192 byte disponibili
Post-Run: 33,119,879,168 byte disponibili
212 --- E O F --- 2008-11-24 17:21:52