ecco il log di combofix.
due precisazioni.
mio figlio quindicenne per sbaglio ha cliccato su di una finestra che installava live-player che ha subito disistallato poichè si è accorto dello sbaglio
ho notato una applicazione strana ikycmmi.exe
può essere utile usare navilog1.exe?
ComboFix 09-05-18.06 - Mauro 19/05/2009 18.13.54.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2046.1511 [GMT 2:00]
Eseguito da: c:\documents and settings\Mauro\Desktop\ComboFix.exe
AV: Sistema Antivirus NOD32 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
* Creato nuovo punto di ripristino
* Resident AV is active
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Flavio Massimo.OK\Impostazioni locali\Dati applicazioni\ikycmmi.dat
c:\documents and settings\Flavio Massimo.OK\Impostazioni locali\Dati applicazioni\ikycmmi.exe
c:\documents and settings\Flavio Massimo.OK\Impostazioni locali\Dati applicazioni\ikycmmi_nav.dat
c:\documents and settings\Flavio Massimo.OK\Impostazioni locali\Dati applicazioni\ikycmmi_navps.dat
c:\documents and settings\Flavio Massimo.OK\Impostazioni locali\Dati applicazioni\qouau.dat
c:\documents and settings\Flavio Massimo.OK\Impostazioni locali\Dati applicazioni\qouau_nav.dat
c:\documents and settings\Flavio Massimo.OK\Impostazioni locali\Dati applicazioni\qouau_navps.dat
.
((((((((((((((((((((((((( Files Creati Da 2009-04-19 al 2009-05-19 )))))))))))))))))))))))))))))))))))
.
2009-05-15 20:14 . 2009-05-15 20:14 -------- d-----w c:\documents and settings\Mauro\Dati applicazioni\dvdcss
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-19 16:13 . 2008-02-29 19:30 -------- d-----w c:\programmi\ESET
2009-05-19 15:46 . 2008-06-25 16:24 -------- d-----w c:\programmi\SpywareBlaster
2009-05-05 19:51 . 2008-11-05 14:24 -------- d-----w c:\programmi\SUPERAntiSpyware
2009-04-27 17:15 . 2007-02-26 23:10 -------- d-----w c:\programmi\eMule
2009-04-17 13:05 . 2008-01-17 19:41 -------- d-----w c:\programmi\Windows Live Safety Center
2009-04-16 19:38 . 2008-11-13 20:33 -------- d-----w c:\programmi\Spyware Terminator
2009-04-15 14:50 . 2001-08-31 11:00 72580 ----a-w c:\windows\system32\perfc010.dat
2009-04-15 14:50 . 2001-08-31 11:00 444988 ----a-w c:\windows\system32\perfh010.dat
2009-04-07 19:56 . 2008-11-04 18:23 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-04-06 13:32 . 2008-11-04 18:23 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2008-11-04 18:23 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-20 17:43 . 2009-02-13 18:14 -------- d-----w c:\programmi\PC Tools Firewall Plus
2009-03-13 18:14 . 2009-02-13 18:14 130424 ----a-w c:\windows\system32\drivers\PCTCore.sys
2009-03-07 09:37 . 2008-02-13 20:21 90248 ----a-w c:\documents and settings\ff\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-03-06 14:19 . 2002-09-09 12:51 286208 ----a-w c:\windows\system32\pdh.dll
2009-02-20 08:09 . 2002-09-09 12:51 668672 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:09 . 2007-02-26 23:34 81920 ----a-w c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="c:\programmi\Eset\nod32kui.exe" [2008-11-07 949376]
"SpywareTerminator"="c:\programmi\Spyware Terminator\SpywareTerminatorShield.exe" [2008-11-13 1783808]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-24 2652056]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2007-02-26 98304]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-13 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2007-2-27 127488]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"JavaQuickStarterService"=2 (0x2)
"gusvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"<NO NAME>"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [07/11/2008 22.47.14 15424]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [13/02/2009 20.14.16 159600]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\SASDIFSV.SYS [03/09/2008 15.07.14 9968]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [03/09/2008 15.07.12 55024]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [13/11/2008 22.33.12 141312]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [13/02/2009 20.14.16 73840]
R2 PMJ151NM;Panasonic DVC Web Camera;c:\windows\system32\drivers\PMJ151NM.sys [27/02/2007 1.55.44 14848]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [13/02/2009 20.14.05 95640]
R3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [03/09/2008 15.07.16 7408]
S3 MovRVDrv32;MovRVDrv32;c:\windows\system32\drivers\MovRVDrv32.sys [30/01/2008 20.18.25 3768]
S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [02/03/2008 10.48.54 44928]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
LSP: c:\windows\system32\imon.dll
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-19 18:14
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\PMJ151LA]
"ImagePath"="%SystemRoot%\PMJ151LA.BIN"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1056)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1112)
c:\windows\system32\imon.dll
c:\programmi\Eset\pr_imon.dll
c:\windows\system32\nvappfilter.dll
.
Ora fine scansione: 2009-05-19 18.15.56
ComboFix-quarantined-files.txt 2009-05-19 16:15
Pre-Run: 67.716.972.544 byte disponibili
Post-Run: 67.909.398.528 byte disponibili
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
120 --- E O F --- 2009-05-13 13:02
attendo tue notizie