Grazie r16 x l'aiuto.
Ecco qui il LOG
ComboFix 08-04-26.5 - Utente 2008-04-27 18.13.18.1 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6000.0.1252.1.1040.18.1208 [GMT 2:00]
Eseguito da: C:\Users\Utente\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\Users\Utente\AppData\Local\lptaeaw.dat
c:\users\utente\appdata\local\lptaeaw.exe
c:\Users\Utente\AppData\Local\lptaeaw_nav.dat
C:\Users\Utente\AppData\Local\lptaeaw_navps.dat
C:\Windows\system32\nvs2.inf
C:\Windows\system32\x64
.
((((((((((((((((((((((((( Files Creati Da 2008-03-27 al 2008-04-27 )))))))))))))))))))))))))))))))))))
.
Nessun nuovo file creato in questo arco di tempo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 15:52 --------- d-----w C:\Users\Utente\AppData\Roaming\AVG7
2008-04-27 15:46 --------- d-----w C:\Program Files\Trend Micro
2008-04-27 14:59 45,056 ----a-w C:\Windows\System32\acovcnt.exe
2008-04-26 18:13 98,304 ----a-w C:\Windows\System32\VB5IT.dll
2008-04-26 18:13 89,360 ----a-w C:\Windows\System32\VB5DB.dll
2008-04-26 18:13 77,824 ----a-w C:\Windows\System32\ODBCTL32.dll
2008-04-26 18:13 73,216 ----a-w C:\Windows\ST5UNST.EXE
2008-04-26 18:13 29,696 ----a-w C:\Windows\System32\VB5StKit.dll
2008-04-26 18:13 1,355,776 ----a-w C:\Windows\System32\msvbvm50.dll
2008-04-26 18:12 430,080 ----a-w C:\Windows\System32\MsRepl35.dll
2008-04-26 18:12 36,864 ----a-w C:\Windows\System32\MSJtEr35.dll
2008-04-26 18:12 33,280 ----a-w C:\Windows\System32\CmDlgIT.dll
2008-04-26 18:12 32,256 ----a-w C:\Windows\System32\DBLstIT.dll
2008-04-26 18:12 252,176 ----a-w C:\Windows\System32\MSRD2x35.dll
2008-04-26 18:12 180,224 ----a-w C:\Windows\System32\ijl11.dll
2008-04-26 18:12 139,264 ----a-w C:\Windows\System32\MSJInt35.dll
2008-04-26 18:12 107,008 ----a-w C:\Windows\System32\CmCtlIT.dll
2008-04-26 18:12 1,064,960 ----a-w C:\Windows\System32\MSJet35.dll
2008-04-26 18:06 --------- d-----w C:\Program Files\ManyBooks
2008-04-24 18:05 --------- d-----w C:\Users\Utente\AppData\Roaming\XnView
2008-04-24 17:58 --------- d-----w C:\Program Files\XnView
2008-04-22 18:02 --------- d-----w C:\ProgramData\SweetIM
2008-04-09 11:06 --------- d-----w C:\Program Files\Windows Mail
2008-03-08 22:07 --------- d-----w C:\ProgramData\eMule
2008-03-08 22:07 --------- d-----w C:\Program Files\eMule
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-27 12:03 --------- d-----w C:\Program Files\ATnotes
2008-02-27 11:09 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-02-27 11:04 --------- d-----w C:\Program Files\Windows Live
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-18 14:27 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-02-16 13:22 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-16 13:17 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-16 13:17 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-16 13:16 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-16 13:16 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-16 13:16 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-16 13:15 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-16 13:15 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-16 13:15 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-16 13:15 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-16 13:15 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-16 13:15 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-16 13:15 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2008-02-01 10:17 586,752 ----a-w C:\Windows\WLXPGSS.SCR
2007-12-11 11:50 174 --sha-w C:\Program Files\desktop.ini
2008-01-03 20:51 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-01-03 20:51 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-03 20:51 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 12:50 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"CTZDetec.exe"="C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe" [2007-12-18 15:20 401408]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 17:21 1449984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-11 13:38 1006264]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 13:43 729088]
"ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 17:27 61440]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 07:27 815104]
"PowerForPhone"="C:\Program Files\PowerForPhone\PowerForPhone.exe" [2007-01-16 00:17 778240]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-20 21:05 579584]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 13:36 229376]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-01-02 18:07 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-01-02 18:06 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-01-02 18:07 133656]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-11 12:40 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-07-28 12:45 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F1A3CDA9-9F35-4ED6-A6DF-1FF788C51D73}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{9643FDD0-FA76-4EDB-BE51-58CB7817964D}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{BC340F37-1BCB-472C-8FCD-2CD7C4296EF6}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{3C510CB8-ED82-48C4-A02F-A901F093D131}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{CD3089B6-F214-44EE-B86D-E46F985EAA95}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{F35E9E5C-43B6-4266-9B8E-6AEB308F69A5}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{5C4C4AFF-17C2-422D-A2F8-280971096287}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{D3A3FD89-79D9-4B5B-950C-3C182B83E6ED}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{79CEFFA7-D647-4ED9-B1AE-1840000E1932}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{CC95F1E6-DBC1-4FDA-8A37-DD793120D81F}C:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:C:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{CE59D205-F901-4243-A2F8-78C7097E9B12}C:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:C:\program files\common files\ahead\nero web\setupx.exe:MSI starter
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2008-02-20 07:47]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 17:48]
R3 WCPU;WCPU;C:\Program Files\P4G\WCPU.sys [2007-01-03 00:37]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
*Newly Created Service* - CATCHME
.
Contenuto della cartella 'Scheduled Tasks'
"2008-04-26 16:48:35 C:\Windows\Tasks\User_Feed_Synchronization-{A16B09BE-A6B4-4FA0-98A6-D6B0FEE512A5}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-27 18:16:04
Windows 6.0.6000 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 156
**************************************************************************
.
Ora fine scansione: 2008-04-27 18.17.09
ComboFix-quarantined-files.txt 2008-04-27 16:17:04
Impossibile trovare il testo del messaggio per il numero di messaggio 0x2379 nel file di messaggio per Application.
Impossibile trovare il testo del messaggio per il numero di messaggio 0x2379 nel file di messaggio per Application.
159 --- E O F --- 2008-04-25 14:42:58