ho fatto tutto quello che mi hai detto ed ecco il log di ComboFix 08-09-13.05 - user 2008-09-14 19.11.45.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.608 [GMT 2:00]
Eseguito da: C:\Documents and Settings\user\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
* Resident AV is active
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((( Files Creati Da 2008-08-14 al 2008-09-14 )))))))))))))))))))))))))))))))))))
.
2008-09-11 17:05 . 2008-09-11 17:26 202 --a------ C:\WINDOWS\system\CmiCnfg.ini
2008-09-11 16:45 . 2003-07-02 04:42 27,904 --a------ C:\WINDOWS\system32\drivers\VIAAGP1.SYS
2008-09-11 16:40 . 2008-09-14 19:20 <DIR> d-------- C:\TEMP\_ISTMP1.DIR
2008-09-11 16:40 . 2008-09-11 16:40 <DIR> d-------- C:\Documents and Settings\user\WINDOWS
2008-09-11 16:34 . 2008-09-14 19:20 <DIR> d-------- C:\TEMP
2008-09-11 16:13 . 2001-08-31 13:00 113,222 --a--c--- C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-09-11 16:13 . 2001-08-31 13:00 41,029 --a--c--- C:\WINDOWS\system32\dllcache\zcorem.dll
2008-09-11 16:13 . 2001-08-31 13:00 36,937 --a--c--- C:\WINDOWS\system32\dllcache\zclientm.exe
2008-09-11 16:13 . 2001-08-31 13:00 29,760 --a--c--- C:\WINDOWS\system32\dllcache\znetm.dll
2008-09-11 16:13 . 2001-08-31 13:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-09-11 16:13 . 2001-08-31 13:00 13,894 --a--c--- C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-09-11 16:13 . 2001-08-31 13:00 4,677 --a--c--- C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-09-11 16:11 . 2004-08-03 22:32 571,392 --a--c--- C:\WINDOWS\system32\dllcache\tintlgnt.ime
2008-09-11 16:10 . 2001-08-31 13:00 2,178,131 --a--c--- C:\WINDOWS\system32\dllcache\shvlres.dll
2008-09-11 16:09 . 2001-08-31 13:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-09-11 16:08 . 2001-08-31 13:00 1,158,818 --a--c--- C:\WINDOWS\system32\dllcache\korwbrkr.lex
2008-09-11 16:07 . 2004-08-03 22:31 811,064 --a--c--- C:\WINDOWS\system32\dllcache\imjp81k.dll
2008-09-11 16:06 . 2001-08-31 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-09-11 16:06 . 2001-08-31 13:00 10,129,408 --a--c--- C:\WINDOWS\system32\dllcache\hwxkor.dll
2008-09-11 16:06 . 2001-08-31 13:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-09-11 16:06 . 2001-08-31 13:00 1,175,635 --a--c--- C:\WINDOWS\system32\dllcache\hrtzres.dll
2008-09-11 16:06 . 2004-08-19 15:39 268,288 --a--c--- C:\WINDOWS\system32\dllcache\httpext.dll
2008-09-11 16:06 . 2004-08-19 15:39 61,440 --a--c--- C:\WINDOWS\system32\dllcache\httpod51.dll
2008-09-11 16:06 . 2001-08-31 13:00 57,409 --a--c--- C:\WINDOWS\system32\dllcache\hrtz.dll
2008-09-11 16:06 . 2001-08-31 13:00 42,573 --a--c--- C:\WINDOWS\system32\dllcache\hrtzzm.exe
2008-09-11 16:06 . 2004-08-19 15:39 39,936 --a--c--- C:\WINDOWS\system32\dllcache\hostmib.dll
2008-09-11 16:06 . 2004-08-19 15:39 8,192 --a--c--- C:\WINDOWS\system32\dllcache\httpmb51.dll
2008-09-11 16:04 . 2001-08-31 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-09-11 16:03 . 2001-08-31 13:00 1,817,687 --a--c--- C:\WINDOWS\system32\dllcache\bckgres.dll
2008-09-11 16:02 . 2004-08-19 15:39 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-09-11 16:01 . 2004-08-19 15:39 290,816 --a--c--- C:\WINDOWS\system32\dllcache\adsiis51.dll
2008-09-11 15:57 . 2008-09-11 15:57 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-09-11 15:56 . 2001-08-31 13:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-09-11 15:37 . 2001-08-31 13:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-09-11 15:37 . 2001-08-31 13:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-09-11 15:37 . 2001-08-31 13:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-09-11 15:37 . 2001-08-31 13:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-09-11 15:36 . 2008-09-11 15:36 <DIR> d--h----- C:\Documents and Settings\Default User\Risorse di stampa
2008-09-11 15:36 . 2008-09-11 15:36 <DIR> d--h----- C:\Documents and Settings\Default User\Risorse di rete
2008-09-11 15:36 . 2008-09-11 15:36 <DIR> d-------- C:\Documents and Settings\Default User\Preferiti
2008-09-11 15:36 . 2008-09-11 15:36 <DIR> d-------- C:\Documents and Settings\Default User\Documenti
2008-09-11 15:35 . 2004-08-19 17:22 1,014,202 -ra------ C:\WINDOWS\SETB2.tmp
2008-09-08 09:26 . 2008-09-08 13:49 982,016 --ahs---- C:\WINDOWS\system32\atjscript
2008-09-08 09:25 . 2008-09-08 09:25 <DIR> d-------- C:\Programmi\AlphaTESTER
2008-09-08 09:25 . 2003-04-21 16:43 385,536 --a------ C:\WINDOWS\system32\js32.dll
2008-09-02 11:24 . 2008-09-05 16:11 <DIR> d-------- C:\Programmi\nLite
2008-08-31 17:26 . 2008-08-31 17:26 <DIR> d-------- C:\Documents and Settings\user\Dati applicazioni\KC Softwares
2008-08-20 10:04 . 2008-09-14 13:38 1,220,354,080 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-20 10:04 . 2008-09-14 11:23 14,003,516 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-20 10:04 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\24219396.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 16:54 524,288 ----a-w C:\WINDOWS\system32\drivers\CnxE2FS.bin
2008-09-13 19:33 --------- d-----w C:\Programmi\eMule
2008-09-11 15:53 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-09-11 15:05 --------- d-----w C:\Programmi\C-Media 3D Audio
2008-09-09 15:15 25,992 -c--a-w C:\WINDOWS\system32\pgdfgsvc.exe
2008-09-05 10:33 --------- d-----w C:\Programmi\Malwarebytes' Anti-Malware
2008-09-04 08:08 --------- d---a-w C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-09-04 08:07 --------- d-----w C:\Programmi\SpywareBlaster
2008-09-02 06:44 --------- d-----w C:\Documents and Settings\user\Dati applicazioni\U3
2008-09-01 22:16 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-01 22:16 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-09-01 07:30 --------- d-----w C:\Programmi\Spybot - Search & Destroy
2008-08-31 15:26 --------- d-----w C:\Programmi\KC Softwares
2008-08-31 13:34 --------- d-----w C:\Programmi\Notepad++
2008-08-31 13:34 --------- d-----w C:\Documents and Settings\user\Dati applicazioni\Notepad++
2008-07-29 15:18 --------- d-----w C:\Programmi\EvilLyrics
2008-07-29 15:06 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-07-17 12:45 --------- d-----w C:\Documents and Settings\user\Dati applicazioni\PCF-VLC
2008-07-17 12:43 --------- d-----w C:\Documents and Settings\user\Dati applicazioni\Participatory Culture Foundation
2008-07-16 10:27 --------- d-----w C:\Programmi\a-squared Free
2008-06-24 16:12 295,936 -c--a-w C:\WINDOWS\system32\wmpeffects.dll
2008-05-18 15:34 78,440 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\firstlsp.reg.dat
2008-02-19 11:23 47,360 ----a-w C:\Documents and Settings\user\Dati applicazioni\pcouffin.sys
2007-12-26 17:28 502,055 -c--a-w C:\Programmi\gmer.zip
2007-12-25 10:44 122,168 -c--a-w C:\Programmi\modalità provv BootSafe.exe
2006-05-24 14:38 233,472 -c--a-w C:\Programmi\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-18 15:00 204,895 -c--a-w C:\Programmi\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 12:41 77,824 -c--a-w C:\Programmi\mozilla firefox\plugins\ctframeplayerobject.dll
2006-05-18 14:59 426,081 -c--a-w C:\Programmi\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 10:19 458,752 -c--a-w C:\Programmi\mozilla firefox\plugins\imagickrt.dll
2006-04-10 16:35 139,264 -c--a-w C:\Programmi\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 09:10 204,800 -c--a-w C:\Programmi\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 09:42 106,496 -c--a-w C:\Programmi\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 09:22 212,992 -c--a-w C:\Programmi\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 09:21 167,936 -c--a-w C:\Programmi\mozilla firefox\plugins\RLVoiceUnpacker.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CnxTrApp"="C:\Programmi\StarModem\StarModem USB Network\CnxTrApp.dll" [2003-07-07 247296]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
"COMODO Firewall Pro"="C:\Programmi\COMODO\Firewall\cfp.exe" [2008-06-02 1655552]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2008-06-02 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 44544]
C:\Documents and Settings\user\Menu Avvio\Programmi\Esecuzione automatica\
ERUNT AutoBackup.lnk - C:\Programmi\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"WRP"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 14:41 294912 C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Tutorial_SW.lnk]
backup=C:\WINDOWS\pss\Tutorial_SW.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Watch.lnk]
backup=C:\WINDOWS\pss\Watch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Menu Avvio^Programmi^Esecuzione automatica^HDDlife.lnk]
backup=C:\WINDOWS\pss\HDDlife.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Menu Avvio^Programmi^Esecuzione automatica^MRU-Blaster Scheduler.lnk]
backup=C:\WINDOWS\pss\MRU-Blaster Scheduler.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Menu Avvio^Programmi^Esecuzione automatica^MRU-Blaster Silent Clean.lnk]
backup=C:\WINDOWS\pss\MRU-Blaster Silent Clean.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Menu Avvio^Programmi^Esecuzione automatica^Secunia PSI (RC1).lnk]
backup=C:\WINDOWS\pss\Secunia PSI (RC1).lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\
0wl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\is-EP8G0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC-Checkup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedItUpEX
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a--c--- 2005-06-28 22:05 344064 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a--c--- 2005-09-08 12:06 94208 C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
--a------ 2008-06-02 10:04 1655552 C:\Programmi\COMODO\Firewall\cfp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-19 15:39 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-03 11:24 133104 C:\Documents and Settings\user\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a--c--- 2004-10-13 18:21 1694208 c:\WINDOWS\$hf_mig$\KB887472\SP2QFE\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:54 5674352 C:\Programmi\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a--c--- 2007-05-11 03:08 2512392 C:\WINDOWS\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra--c--- 2006-01-30 18:00 98304 C:\Programmi\Hewlett-Packard\OrderReminder\OrderReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
-ra------ 2005-06-20 12:53 1056768 C:\Programmi\VIA\RAID\raid_tool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-05-28 10:33 1506544 C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2006-09-07 19:19 15872 C:\Programmi\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VIRIT LITE MONITOR]
--a------ 2008-08-31 17:38 245760 C:\VEXPLITE\MONLITE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"usnjsvc"=3 (0x3)
"a2free"=2 (0x2)
"ose"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"HDDlife HDD Access service"=2 (0x2)
"viritsvclite"=2 (0x2)
"SbieSvc"=3 (0x3)
"is-EP8G0"=2 (0x2)
"wuauserv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programmi\\eMule\\emule.exe"=
"%windir%\\system32\\sessmgr.exe"=
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 39808]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-06-01 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-06-01 24208]
R1 is-EP8G0drv;is-EP8G0drv;C:\WINDOWS\system32\drivers\24219396.sys [2008-03-05 148496]
S4 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-08-31 57344]
.
Contenuto della cartella 'Scheduled Tasks'
.
- - - - ORFÃOS REMOVIDOS - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\user\Dati applicazioni\Mozilla\Firefox\Profiles\x5bvbo1h.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.yahoo.itFF -: plugin - C:\Documents and Settings\user\Impostazioni locali\Dati applicazioni\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF -: plugin - C:\Programmi\Mozilla Firefox\plugins\npRLCT4Player.dll
FF -: plugin - C:\Programmi\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-14 19:20:44
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-09-14 19:25:52
ComboFix-quarantined-files.txt 2008-09-14 17:25:27
Pre-Run: 94,173,220,864 byte disponibili
Post-Run: 94,163,460,096 byte disponibili
237 --- E O F --- 2008-05-14 17:17:34