ok r16 ho fatto come mi hai detto, ora ti faccio vedere il log
ComboFix 08-09-26.01 - ANOMIS 2008-09-27 15.41.55.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.573 [GMT 2:00]
Eseguito da: C:\Documents and Settings\ANOMIS\Documenti\Programmi scaricati antivirus\ComboFix.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((( Files Creati Da 2008-08-27 al 2008-09-27 )))))))))))))))))))))))))))))))))))
.
2008-09-27 15:21 . 2008-09-27 15:21 <DIR> d-------- C:\Programmi\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-27 13:41 --------- d-----w C:\Documents and Settings\ANOMIS\Dati applicazioni\StarOffice8
2008-09-27 13:03 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Zylom
2008-09-27 07:13 --------- d-----w C:\Programmi\GamesBar
2008-09-27 07:10 --------- d---a-w C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-09-26 21:14 --------- d-----w C:\Programmi\BearShare
2008-09-26 19:21 --------- d-----w C:\Programmi\Google
2008-09-26 19:18 --------- d-----w C:\Programmi\Messenger Plus! Live
2008-09-26 19:17 --------- d-----w C:\Programmi\Spyware Doctor
2008-09-26 19:16 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Google Updater
2008-08-10 03:26 --------- d-----w C:\Programmi\File comuni\Symantec Shared
2008-07-27 20:30 --------- d-----w C:\Programmi\Windows Live
2008-07-27 20:29 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Microsoft Help
2008-07-27 20:07 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Messenger Plus!
2008-07-27 16:49 --------- d-----w C:\Programmi\Microsoft SQL Server Compact Edition
2008-07-27 16:40 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\WLInstaller
2008-07-27 16:00 --------- d-----w C:\Programmi\Norton Security Scan
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-10-09 17:14 410 ----a-w C:\Documents and Settings\ANOMIS\Dati applicazioni\wklnhst.dat
2007-05-12 15:37 17,938,288 ----a-w C:\Programmi\Install_Messenger.exe
2007-03-23 22:04 8,178,872 ----a-w C:\Programmi\BearShareV6it.exe
2006-07-26 17:37 560 ----a-w C:\Documents and Settings\ANOMIS\Dati applicazioni\ViewerApp.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{323d5e65-9ec7-481e-a888-5bbe30b80dfb}"= "C:\Programmi\ITALIA_version\tbITAL.dll" [2008-07-10 1600024]
[HKEY_CLASSES_ROOT\clsid\{323d5e65-9ec7-481e-a888-5bbe30b80dfb}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{323d5e65-9ec7-481e-a888-5bbe30b80dfb}]
2008-07-10 14:04 1600024 --a------ C:\Programmi\ITALIA_version\tbITAL.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{323d5e65-9ec7-481e-a888-5bbe30b80dfb}"= "C:\Programmi\ITALIA_version\tbITAL.dll" [2008-07-10 1600024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{323D5E65-9EC7-481E-A888-5BBE30B80DFB}"= "C:\Programmi\ITALIA_version\tbITAL.dll" [2008-07-10 1600024]
[HKEY_CLASSES_ROOT\clsid\{323d5e65-9ec7-481e-a888-5bbe30b80dfb}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-16 68856]
"msnmsgr"="C:\Programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-28 344064]
"SynTPEnh"="C:\Programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-08-01 708697]
"Smart Start UP"="C:\Programmi\NewSoft\Smart Start UP\PnPDetect.exe" [2003-01-21 98304]
"CnxTrApp"="C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll" [2004-04-20 247296]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 406016]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="C:\Programmi\Ahead\InCD\InCD.exe" [2004-09-07 1450094]
"GrooveMonitor"="C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Google Desktop Search"="C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-02 1836544]
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2008-03-02 185632]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-28 1177368]
"Collegamento alla pagina delle proprietà di High Definition Audio"="HDAShCut.exe" [2005-01-07 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-08-01 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-08-01 C:\WINDOWS\ALCWZRD.EXE]
"SMSERIAL"="sm56hlpr.exe" [2005-09-16 C:\WINDOWS\sm56hlpr.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15360]
C:\Documents and Settings\ANOMIS\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - C:\Programmi\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
StarOffice 8.lnk - C:\Programmi\Sun\StarOffice 8\program\quickstart.exe [2007-08-17 122880]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.lnk - C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2006-05-19 110592]
Google Updater.lnk - C:\Programmi\Google\Google Updater\GoogleUpdater.exe [2008-03-02 125624]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.I420"= vdrcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\BearShare Applications\\BearShare\\BearShare.exe"=
"C:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
R0 Achernar;Achernar - SCSI Command Filters;C:\WINDOWS\system32\Drivers\Achernar.sys [2004-02-11 16855]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-28 96520]
R1 SSHDRV82;SSHDRV82;C:\WINDOWS\system32\drivers\SSHDRV82.sys [2006-06-29 76288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-28 282904]
R3 Aldebaran;Aldebaran - SCSI Command Filters;C:\WINDOWS\system32\Drivers\Aldebaran.sys [2004-02-11 21808]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41a4153a-a329-11dc-b346-0013ce5d41e3}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contenuto della cartella 'Scheduled Tasks'
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\ANOMIS\Dati applicazioni\Mozilla\Firefox\Profiles\2d27rmqn.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://it.msn.com/
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://it.msn.com/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-27 15:43:02
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-09-27 15:45:13
ComboFix-quarantined-files.txt 2008-09-27 13:44:56
ComboFix2.txt 2008-09-27 13:39:37
ComboFix3.txt 2008-09-27 07:39:17
Pre-Run: 31.978.827.776 byte disponibili
Post-Run: 31,966,150,656 byte disponibili
146 --- E O F --- 2008-07-27 20:31:00