Ecco il log di combofix dopo avere accuratamente chiuso tutto quel che c'era aperto di AVG.
Puoi controllare per favore r16? adesso preparo il log di Hijac. Grazie
ComboFix 08-10-02.04 - io 2008-10-03 18.17.49.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.654 [GMT 2:00]
Eseguito da: C:\Documents and Settings\io\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-09-03 al 2008-10-03 )))))))))))))))))))))))))))))))))))
.
2008-10-02 23:04 . 2008-10-02 23:05 <DIR> d-------- C:\Programmi\Malwarebytes' Anti-Malware
2008-10-02 23:04 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-02 23:04 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-30 11:07 . 2008-10-03 16:04 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-30 11:07 . 2008-10-01 20:13 <DIR> d-------- C:\Documents and Settings\io\Dati applicazioni\AVGTOOLBAR
2008-09-30 11:07 . 2008-09-30 11:07 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-30 11:07 . 2008-09-30 11:07 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-30 11:06 . 2008-09-30 11:06 <DIR> d-------- C:\Programmi\AVG
2008-09-26 15:33 . 2008-09-30 18:40 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\avg8
2008-09-26 09:10 . 2008-09-26 09:10 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Grisoft
2008-09-26 09:00 . 2008-09-26 09:00 <DIR> d-------- C:\Documents and Settings\io\Dati applicazioni\Malwarebytes
2008-09-26 09:00 . 2008-09-26 09:00 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2008-09-26 08:58 . 2008-09-26 15:30 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Avira
2008-09-25 02:05 . 2008-09-25 02:05 400,196 --a------ C:\WINDOWS\system32\%LocalXml%
2008-09-24 18:46 . 2008-09-24 18:46 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2008-09-21 19:55 . 2008-09-26 15:29 <DIR> d-------- C:\Programmi\Spybot - Search & Destroy
2008-09-19 23:14 . 2008-09-20 21:14 49 --a------ C:\WINDOWS\transp.gif
2008-09-19 22:28 . 2008-09-20 22:09 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-09-19 22:22 . 2008-09-20 22:09 <DIR> d-------- C:\Programmi\File comuni\Agnitum Shared
2008-09-19 22:22 . 2008-09-19 22:22 <DIR> d-------- C:\Programmi\Agnitum
2008-09-18 19:41 . 2008-09-19 22:07 <DIR> d-------- C:\Programmi\COMODO
2008-09-18 19:41 . 2008-09-19 22:07 <DIR> d-------- C:\Documents and Settings\io\Dati applicazioni\Comodo
2008-09-14 19:50 . 2008-09-14 19:50 <DIR> d-------- C:\Documents and Settings\io\Dati applicazioni\skypePM
2008-09-14 19:50 . 2008-09-14 19:50 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-09-08 18:54 . 2008-09-08 18:54 <DIR> d-------- C:\Documents and Settings\io\Dati applicazioni\PCToolsFirewallPlus
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 16:19 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Google Updater
2008-09-30 16:35 --------- d---a-w C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-09-26 13:29 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-09-14 17:49 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Skype
2008-09-03 20:39 20 ---h--w C:\Documents and Settings\All Users\Dati applicazioni\PKP_DLdu.DAT
2008-08-22 16:00 --------- d-----w C:\Programmi\Google
2008-08-20 22:33 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-08-19 08:17 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-08-17 18:51 --------- d-----w C:\Programmi\Windows Media Connect 2
2008-08-03 14:51 --------- d-----w C:\Programmi\Eset
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-07 20:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:27 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [X]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"SynTPLpr"="C:\Programmi\Synaptics\SynTP\SynTPLpr.exe" [2005-03-10 98394]
"SynTPEnh"="C:\Programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-03-10 688218]
"STDSB"="C:\WINDOWS\system32\drivers\STDSB.exe" [2003-12-17 28672]
"AzMixerSel"="C:\Programmi\Realtek\InstallShield\AzMixerSel.exe" [2005-04-26 45056]
"SunJavaUpdateSched"="C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe" [2004-06-03 32881]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 114688]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 127118]
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2006-02-15 180269]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2007-04-27 282624]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Collegamento alla pagina delle proprietà di High Definition Audio"="HDAShCut.exe" [2005-01-07 C:\WINDOWS\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-05-04 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\io\Menu Avvio\Programmi\Esecuzione automatica\
Nikon Monitor.lnk - C:\Programmi\File comuni\Nikon\Monitor\NkMonitor.exe [2007-05-15 479232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
--a------ 2008-09-30 11:06 1234712 C:\PROGRA~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Powercinema\\PowerCinema.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\italian\\setup.exe"=
"C:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-30 97928]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-30 231704]
R2 MTC0007_STDSB;Scroll Bar Driver;C:\WINDOWS\system32\drivers\STDSB.sys [2005-08-25 11279]
R2 NwSapAgent;Agente SAP;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 Slazldrv;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\SLDRV\slazldrv.sys [2005-01-05 226768]
S2 STDSB;STDSB;C:\WINDOWS\system32\DRIVERS\STDSB.sys [2005-08-25 11279]
S2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe [ ]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
.
Contenuto della cartella 'Scheduled Tasks'
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://it.yahoo.com/
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.grisoft.com/
O8 -: E&sporta in Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-03 18:19:28
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-10-03 18:21:12
ComboFix-quarantined-files.txt 2008-10-03 16:21:09
ComboFix2.txt 2008-10-03 15:56:31
ComboFix3.txt 2008-10-03 15:42:03
Pre-Run: 34.495.426.560 byte disponibili
Post-Run: 34,480,029,696 byte disponibili
147 --- E O F --- 2008-09-23 20:38:07