r16 ha scritto:Ciao.
Che mi venga un accidente se ho capito qualcosa.......
Ciao r16 e scusa se sono stato un po troppo frettoloso nell'esporre la cosa.
Ti torna utile riscritto più chiaro?
Considera che Combofix collideva con Spybot, ma tutto dovrebbe essere
andato bene perché Spybot chiedeva conferma di ciò che aveva fatto
Combofix e io ho sempre detto di sì.
Ho aggiornati tutti e due prima di iniziare, Combofix mi ha chiesto se
volevo installare la Console di emergenza e io ho risposto sì.
Sempre Combofix è partito in automatico anzichè su mio comando.
Per abitudine lo ho messo dove metto sempre i programmi scaricati
anzichè sul desktop e poi lo ho installato, la cosa può avere conseguenze?
Ti spedisco i risultati di ambedue (Malwarebytes è pulito).
Malwarebytes' Anti-Malware 1.33
Versione del database: 1665
Windows 5.1.2600 Service Pack 2
18/01/2009 16.43.45
mbam-log-2009-01-18 (16-43-45).txt
Tipo di scansione: Scansione completa (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
Elementi scansionati: 115900
Tempo trascorso: 23 minute(s), 16 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
(Nessun elemento malevolo rilevato)
ComboFix 09-01-17.04 - b 2009-01-18 16.52.24.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.1023.669 [GMT 1:00]
Eseguito da: d:\aggiornamenti e programmi utili\Programmi\Prelevati da Internet\Windowsiani\Antitutto\Combo fix\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090117-0] *On-access scanning disabled* (Outdated)
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
h:\windows\expiorer.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-12-18 al 2009-01-18 )))))))))))))))))))))))))))))))))))
.
2009-01-18 16:17 . 2009-01-18 16:17 <DIR> d-------- h:\programmi\Malwarebytes' Anti-Malware
2009-01-18 16:17 . 2009-01-18 16:17 <DIR> d-------- h:\documents and settings\b\Dati applicazioni\Malwarebytes
2009-01-18 16:17 . 2009-01-18 16:17 <DIR> d-------- h:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-01-18 16:17 . 2009-01-14 16:11 38,496 --a------ h:\windows\system32\drivers\mbamswissarmy.sys
2009-01-18 16:17 . 2009-01-14 16:11 15,504 --a------ h:\windows\system32\drivers\mbam.sys
2009-01-18 16:16 . 2009-01-18 16:16 <DIR> d-------- h:\windows\LastGood
2009-01-17 09:50 . 2009-01-17 09:50 13,718 --a------ h:\windows\system32\wpa.bak
2009-01-16 22:14 . 2009-01-16 22:14 <DIR> d-------- h:\programmi\Spybot - Search & Destroy
2009-01-16 22:14 . 2009-01-16 22:14 <DIR> d-------- h:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-01-10 19:37 . 2009-01-10 19:37 <DIR> d-------- h:\windows\BDOSCAN8
2009-01-10 12:49 . 2009-01-10 12:49 <DIR> d--h----- h:\windows\system32\GroupPolicy
2009-01-06 19:19 . 2009-01-06 19:19 <DIR> d-------- h:\programmi\Alwil Software
2009-01-06 19:19 . 2003-03-18 21:20 1,060,864 --a------ h:\windows\system32\MFC71.dll
2009-01-06 19:19 . 2003-03-18 20:14 499,712 --a------ h:\windows\system32\MSVCP71.dll
2009-01-06 19:19 . 2003-02-21 04:42 348,160 --a------ h:\windows\system32\MSVCR71.dll
2009-01-06 13:36 . 2009-01-06 13:36 <DIR> d-------- h:\windows\Sun
2009-01-06 13:35 . 2009-01-06 13:35 <DIR> d-------- h:\programmi\Java
2009-01-06 13:35 . 2009-01-06 13:35 410,984 --a------ h:\windows\system32\deploytk.dll
2009-01-06 13:35 . 2009-01-06 13:35 73,728 --a------ h:\windows\system32\javacpl.cpl
2009-01-06 12:57 . 2009-01-06 12:57 118,784 --a------ h:\windows\SeaMonkeyUninstall.exe
2009-01-06 12:57 . 2009-01-06 12:57 118,784 --a------ h:\windows\GREUninstall.exe
2009-01-06 12:57 . 2009-01-06 12:57 7,122 --a------ h:\windows\mozver.dat
2009-01-06 12:57 . 2009-01-06 12:57 335 --a------ h:\windows\nsreg.dat
2009-01-06 12:56 . 2009-01-06 12:56 <DIR> d-------- h:\programmi\mozilla.org
2009-01-06 12:20 . 2009-01-06 12:20 <DIR> d-------- h:\programmi\Total Commander
2009-01-06 12:20 . 2008-08-08 07:04 545 --a------ h:\windows\UC.PIF
2009-01-06 12:20 . 2008-08-08 07:04 545 --a------ h:\windows\RAR.PIF
2009-01-06 12:20 . 2008-08-08 07:04 545 --a------ h:\windows\PKZIP.PIF
2009-01-06 12:20 . 2008-08-08 07:04 545 --a------ h:\windows\PKUNZIP.PIF
2009-01-06 12:20 . 2008-08-08 07:04 545 --a------ h:\windows\NOCLOSE.PIF
2009-01-06 12:20 . 2008-08-08 07:04 545 --a------ h:\windows\LHA.PIF
2009-01-06 12:20 . 2008-08-08 07:04 545 --a------ h:\windows\ARJ.PIF
2009-01-06 11:45 . 2009-01-06 11:45 8,025 --a------ H:\kill_amvo_virus_usb_en.vbs
2009-01-05 19:01 . 2009-01-05 19:01 <DIR> d--h----- h:\windows\$hf_mig$
2009-01-05 18:58 . 2008-10-16 14:09 43,544 --a------ h:\windows\system32\wups2.dll
2009-01-05 18:58 . 2008-10-16 14:12 35,864 --a------ h:\windows\system32\wucltui.dll.mui
2009-01-05 18:58 . 2008-10-16 14:08 27,672 --a------ h:\windows\system32\wuaucpl.cpl.mui
2009-01-05 18:58 . 2008-10-16 14:08 27,672 --a------ h:\windows\system32\wuapi.dll.mui
2009-01-05 18:58 . 2008-10-16 14:07 19,480 --a------ h:\windows\system32\wuaueng.dll.mui
2009-01-05 18:16 . 2009-01-05 18:16 <DIR> d-------- h:\documents and settings\b\Dati applicazioni\MSN6
2009-01-05 18:16 . 2009-01-05 18:16 <DIR> d-------- h:\documents and settings\All Users\Dati applicazioni\MSN6
2009-01-05 18:07 . 2009-01-05 18:07 <DIR> d-------- h:\documents and settings\b\Dati applicazioni\DeepBurner
2009-01-05 18:00 . 2009-01-18 16:48 3,564 --a------ h:\windows\WINCMD.INI
2009-01-05 17:30 . 2009-01-05 17:30 23,600 --a------ h:\windows\system32\drivers\TVICHW32.SYS
2009-01-05 16:43 . 2009-01-05 16:43 <DIR> d-------- h:\windows\system32\FxsTmp
2009-01-05 16:43 . 2001-08-31 13:00 138,240 --a------ h:\windows\system32\fxsclntR.dll
2009-01-05 16:43 . 2001-08-31 13:00 138,240 --a------ h:\windows\system32\dllcache\fxsclntr.dll
2009-01-05 16:43 . 2001-08-31 13:00 112,128 --a------ h:\windows\system32\fxscfgwz.dll
2009-01-05 16:43 . 2001-08-31 13:00 112,128 --a------ h:\windows\system32\dllcache\fxscfgwz.dll
2009-01-05 16:43 . 2001-08-31 13:00 31,744 --a------ h:\windows\system32\fxsroute.dll
2009-01-05 16:43 . 2001-08-31 13:00 31,744 --a------ h:\windows\system32\dllcache\fxsroute.dll
2009-01-05 16:43 . 2001-08-31 13:00 11,264 --a------ h:\windows\system32\fxssend.exe
2009-01-05 16:43 . 2001-08-31 13:00 11,264 --a------ h:\windows\system32\dllcache\fxssend.exe
2009-01-05 16:43 . 2001-08-31 13:00 3,476 --a------ h:\windows\system32\fxsperf.ini
2009-01-05 16:43 . 2001-08-31 13:00 1,361 --a------ h:\windows\system32\fxscount.h
2009-01-05 16:43 . 2009-01-05 16:43 550 --a------ h:\windows\system32\mapisvc.inf
2009-01-05 16:29 . 2004-08-03 23:08 26,496 --a------ h:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 19:05 2,864 ----a-w h:\windows\system32\winsock.dll
2009-01-06 19:05 2,864 ----a-w h:\windows\system32\dllcache\winsock.dll
2009-01-05 14:09 --------- d-----w h:\programmi\microsoft frontpage
2009-01-05 14:06 --------- d-----w h:\programmi\Servizi in linea
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="h:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MSMSGS"="h:\programmi\Messenger\msmsgs.exe" [2004-08-19 1667584]
"SpybotSD TeaTimer"="h:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="h:\programmi\Java\jre6\bin\jusched.exe" [2009-01-06 136600]
"avast!"="h:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="h:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;h:\windows\system32\drivers\aswSP.sys [2009-01-06 111184]
R4 aswFsBlk;aswFsBlk;h:\windows\system32\drivers\aswFsBlk.sys [2009-01-06 20560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70dcc016-db49-11dd-a1d3-000b6a058df5}]
\Shell\AutoRun\command - P:\fppg1.exe
\Shell\explore\Command - P:\fppg1.exe
\Shell\open\Command - P:\fppg1.exe
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-vamsoft - h:\windows\system32\vamsoft.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-18 16:54:24
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2009-01-18 16.55.57
ComboFix-quarantined-files.txt 2009-01-18 15:55:56
Pre-Run: 5.328.822.272 byte disponibili
Post-Run: 5,341,855,744 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=C:\
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
C:\="Microsoft Windows"
multi(0)disk(0)rdisk(0)partition(6)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
127
Ciao.