Sempre un grazie per la pazienza e il supporto fornitomi!ecco il log:ComboFix 09-06-24.05 - Paul 26/06/2009 10.32.02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1033.18.1535.1090 [GMT 2:00]
Eseguito da: c:\documents and settings\Paul\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9D7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\SI3112r.sys
c:\windows\system32\lsp.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_Si3112r
((((((((((((((((((((((((( Files Creati Da 2009-05-26 al 2009-06-26 )))))))))))))))))))))))))))))))))))
.
2009-06-26 08:18 . 2009-06-26 08:19 -------- dc----w- c:\program files\WLM Lite 8.5
2009-06-24 07:18 . 2009-03-30 08:33 96104 -c--a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-24 07:18 . 2009-03-24 14:08 55640 -c--a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-24 07:18 . 2009-02-13 10:29 22360 -c--a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-24 07:18 . 2009-02-13 10:17 45416 -c--a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-24 07:18 . 2009-06-24 07:18 -------- dc----w- c:\program files\Avira
2009-06-24 07:18 . 2009-06-24 07:18 -------- dc----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-24 07:06 . 2009-06-24 07:06 -------- dc----w- c:\program files\ATI Technologies
2009-06-24 06:44 . 2008-10-16 12:06 208744 -c--a-w- c:\windows\system32\muweb.dll
2009-06-23 10:47 . 2009-06-17 09:27 38160 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-23 10:47 . 2009-06-23 10:47 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-23 10:47 . 2009-06-17 09:27 19096 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-06-23 10:47 . 2009-06-23 10:47 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-22 12:33 . 2009-06-22 12:33 -------- dc----w- c:\program files\Trend Micro
2009-06-22 12:01 . 2009-06-22 12:16 -------- dc----w- c:\windows\BDOSCAN8
2009-06-21 16:18 . 2009-06-21 16:18 -------- dcsh--w- c:\documents and settings\Administrator\IETldCache
2009-06-21 16:02 . 2009-06-22 10:47 -------- dc----w- c:\documents and settings\Paul\.housecall6.6
2009-06-21 14:45 . 2008-06-19 15:24 28544 -c--a-w- c:\windows\system32\drivers\pavboot.sys
2009-06-21 14:43 . 2009-06-21 14:43 -------- dc----w- c:\program files\Panda Security
2009-06-21 11:12 . 2009-06-21 11:14 -------- dc----w- c:\program files\PageFix 2.0
2009-06-21 11:08 . 2009-06-21 11:08 -------- dc----w- c:\program files\ClamWin
2009-06-21 11:08 . 2009-06-21 11:08 -------- dc----w- c:\documents and settings\All Users\.clamwin
2009-06-19 08:18 . 2009-06-19 08:18 -------- dcsh--w- c:\documents and settings\Paul\IECompatCache
2009-06-19 07:57 . 2009-06-19 07:57 -------- dcsh--w- c:\documents and settings\Paul\PrivacIE
2009-06-19 07:55 . 2009-06-19 07:55 -------- dcsh--w- c:\documents and settings\Paul\IETldCache
2009-06-19 07:51 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-19 07:51 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-19 07:51 . 2009-06-22 22:03 -------- dc----w- c:\windows\ie8updates
2009-06-19 07:50 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-19 07:48 . 2009-02-20 18:09 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-19 07:48 . 2009-02-20 18:09 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-06-18 13:04 . 2009-06-18 13:50 -------- dc----w- c:\program files\Opera
2009-05-31 08:12 . 2009-05-31 08:12 -------- dc----w- c:\program files\ProcessExplorer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-26 07:58 . 2007-09-07 16:23 -------- dc----w- c:\program files\Thunderbird 2.0.0.6
2009-06-25 17:41 . 2009-02-06 07:35 -------- dc----w- c:\program files\Steam
2009-06-25 16:22 . 2007-08-29 10:08 -------- dc----w- c:\program files\emule0.48a-Xtreme6.1
2009-06-23 21:43 . 2009-05-25 19:16 -------- dc----w- c:\program files\Yahoo!
2009-06-23 10:22 . 2009-03-21 09:05 -------- dc----w- c:\program files\CCleaner
2009-06-23 08:01 . 2007-09-09 17:41 -------- dc----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-21 11:12 . 2008-05-13 11:05 249856 -c----w- c:\windows\Setup1.exe
2009-06-21 11:12 . 2008-05-13 11:05 73216 -c--a-w- c:\windows\ST6UNST.EXE
2009-05-30 12:42 . 2007-11-24 14:58 -------- dc----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-30 08:48 . 2008-06-30 21:11 -------- dc----w- c:\documents and settings\All Users\Application Data\QuickTime
2009-05-30 08:09 . 2009-02-28 08:56 -------- dc----w- c:\program files\Free Video Converter
2009-05-26 18:05 . 2009-04-15 17:48 -------- dc----w- c:\program files\Winamp
2009-05-25 19:19 . 2009-05-25 19:16 -------- dc----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-20 12:24 . 2009-05-20 12:24 -------- dc----w- c:\program files\MSN BackUp
2009-05-14 13:17 . 2008-05-14 10:58 -------- dc----w- c:\program files\Google
2009-05-14 13:14 . 2009-05-14 13:14 -------- dc----w- c:\program files\Tacmi
2009-05-14 13:14 . 2007-09-06 16:02 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-05-12 09:40 . 2009-05-12 09:40 -------- dc----w- c:\program files\Defraggler
2009-05-07 15:32 . 2003-03-31 12:00 345600 -c--a-w- c:\windows\system32\localspl.dll
2009-05-04 07:52 . 2009-05-04 07:52 -------- dc----w- c:\program files\Ahead
2009-04-29 13:12 . 2008-02-20 17:39 -------- dc----w- c:\program files\Spybot - Search & Destroy
2009-04-28 14:41 . 2009-04-28 14:41 -------- dc----w- c:\program files\Belkin
2009-04-17 12:26 . 2003-03-31 12:00 1847168 -c--a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-03-06 02:16 585216 -c--a-w- c:\windows\system32\rpcrt4.dll
2009-04-03 17:02 . 2009-04-03 17:02 4096 -c--a-w- c:\windows\d3dx.dat
2008-12-14 16:31 . 2008-12-14 16:31 23 -csha-w- c:\windows\system32\bceccddad8_g.dll
2008-12-14 16:26 . 2008-12-14 16:26 23 -csha-w- c:\windows\system32\cfbcfded2_z.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2009-06-11 86016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"idsvc"=3 (0x3)
"TomTomHOMEService"=3 (0x3)
"FirebirdServerMAGIXInstance"=3 (0x3)
"Fabs"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\emule0.48a-Xtreme6.1\\emule.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_03\\bin\\java.exe"=
"c:\\Program Files\\Steam\\steamapps\\lordalcool\\team fortress 2\\hl2.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"e:\\Gomes\\Worms2\\Frontend.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Programmi & Zip\\hfs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\MSN BackUp\\MSNBackup.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\red orchestra\\System\\RedOrchestra.exe"=
"c:\\Program Files\\Avira\\AntiVir Desktop\\avcenter.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [21/06/2009 16.45.02 28544]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19.19.58 13592]
S3 ATICDSDr;ATICDSDr;\??\c:\docume~1\Paul\LOCALS~1\Temp\ATICDSDr.sys --> c:\docume~1\Paul\LOCALS~1\Temp\ATICDSDr.sys [?]
S3 camfilt2;camfilt2;c:\windows\system32\drivers\camfilt2.sys [29/08/2008 19.16.22 94720]
S4 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [08/04/2009 12.38.14 92008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1604221776-682003330-1003.job
- c:\documents and settings\Paul\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-17 16:39]
2007-09-07 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2007-02-05 13:52]
2009-06-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
.
.
------- Scansione supplementare -------
.
IE: Add to AMV Convert Tool... - c:\program files\MP3 Player Utilities 4.00\AMVConverter\grab.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.00\MediaManager\grab.html
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-26 10:43
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-448539723-1604221776-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:26,b7,2d,55,ff,60,6e,2f,f4,7e,e4,bb,1f,3b,1a,39,a7,f7,7e,2c,79,f8,a0,
12,28,76,83,a0,d9,fa,44,fe,79,f6,9c,3b,d5,41,eb,12,17,51,2e,8c,da,82,f1,3b,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3832)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2009-06-26 10.47.09 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-06-26 08:47
Pre-Run: 8.113.655.808 bytes free
Post-Run: 8.111.050.752 bytes free
194 --- E O F --- 2009-06-25 19:42