ti posto il log di comboFix
ComboFix 10-02-07.01 - carrefour 07/02/2010 19.14.25.5.2 - FAT32x86
Eseguito da: c:\documents and settings\carrefour\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-01-07 al 2010-02-07 )))))))))))))))))))))))))))))))))))
.
Nessun nuovo file creato in questo arco di tempo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-24 15:33 . 2009-09-12 16:19 5115824 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-14 10:12 . 2009-10-02 16:48 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-07 15:07 . 2009-09-05 17:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-09-05 17:45 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 16:16 . 2010-01-06 16:16 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-12-21 19:06 . 2004-08-23 19:35 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-16 17:54 . 2009-12-16 17:54 -------- d-----w- c:\documents and settings\carrefour\Dati applicazioni\GARMIN
2009-11-21 15:54 . 2002-09-10 11:00 471552 ----a-w- c:\windows\AppPatch\AcLayers.dll
2009-10-27 11:44 . 2009-10-27 11:44 16520840 ----a-w- c:\programmi\PDFXVwerSE.exe
2009-08-04 11:04 . 2009-08-04 11:04 3942048 ----a-w- c:\programmi\malwarebytesAnti_malwar_-setup.exe
2009-03-25 09:27 . 2009-03-25 09:27 5649472 ----a-w- c:\programmi\gusetup.exe
2008-07-18 17:16 . 2008-07-18 17:16 5244440 ----a-w- c:\programmi\TVUPlayer2.3.7.1.exe
2008-03-28 14:51 . 2008-03-28 14:51 3199108 ----a-w- c:\programmi\Setup-SopCast-3.0.1-2008-3-28.exe
2008-01-21 21:22 . 2008-01-21 21:22 9739116 ----a-w- c:\programmi\InstSocr.exe
2008-01-15 19:57 . 2008-01-15 19:57 20907376 ----a-w- c:\programmi\aaw2007.exe
2007-08-09 07:17 . 2007-08-09 07:17 1563724 ----a-w- c:\programmi\icarbonsetup.exe
2007-03-11 11:14 . 2007-03-11 11:14 112 ----a-w- c:\programmi\Config.ini
2007-02-14 15:02 . 2007-02-14 15:02 4732416 ----a-w- c:\programmi\OnLineLiveSetup.msi
2006-10-31 16:48 . 2006-10-31 16:48 34698 ----a-w- c:\programmi\rojadirecta
2006-09-21 16:46 . 2006-09-21 16:46 1156042 ----a-w- c:\programmi\IEPrivacyKeeperSetup.exe
2006-08-04 17:19 . 2006-08-04 17:19 6227687 ----a-w- c:\programmi\Setup TvuPlayer.exe
2006-04-09 17:43 . 2006-04-09 17:43 516608 ----a-w- c:\programmi\Starter.exe
2006-01-30 17:11 . 2006-01-30 17:11 1082742 ----a-w- c:\programmi\WRar351it.exe
2005-04-28 16:21 . 2005-04-28 16:44 606666 ----a-w- c:\programmi\WinPlayer.exe
2005-04-13 16:27 . 2005-04-13 16:27 11760072 ----a-w- c:\programmi\Alice_ti_aiuta.exe
2003-04-27 14:24 . 2003-04-27 14:24 383254 ----a-w- c:\programmi\CDEX.HLP
2003-04-27 14:24 . 2003-04-27 14:24 96768 ----a-w- c:\programmi\libsndfile.dll
2003-04-27 14:23 . 2003-04-27 14:23 83456 ----a-w- c:\programmi\CDRip.dll
2003-04-27 14:23 . 2003-04-27 14:23 7051 ----a-w- c:\programmi\CDex.cnt
2003-03-24 20:25 . 2003-03-24 20:25 21652 ----a-w- c:\programmi\Changes.txt
2003-02-04 20:35 . 2003-02-04 20:35 4320 ----a-w- c:\programmi\ReadMe.txt
2002-08-07 21:07 . 2002-08-07 21:07 71680 ----a-w- c:\programmi\MACDll.dll
2002-07-06 12:25 . 2002-07-06 12:25 1007 ----a-w- c:\programmi\CDex.ini
2002-05-09 15:22 . 2002-05-09 15:22 537 ----a-w- c:\programmi\CDex.exe.manifest
2002-04-20 12:07 . 2002-04-20 12:07 69632 ----a-w- c:\programmi\WMA8Connect.dll
2001-03-10 12:18 . 2001-03-10 12:18 1044168 ----a-w- c:\programmi\vbrun60sp5.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\programmi\File comuni\Symantec Shared\ccApp.exe" [2006-04-04 71304]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2007-02-15 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\MSMSGS.EXE"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\carrefour\\Dati applicazioni\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\TVAnts\\Tvants.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\SopCast\\sopvod.exe"=
"c:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [2003-04-18 8192]
S2 MSSQL$VLSOLE24EXPRESS;SQL Server (VLSOLE24EXPRESS);c:\programmi\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
S2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;c:\programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-08-03 100032]
S2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [2006-11-03 13592]
.
Contenuto della cartella 'Scheduled Tasks'
2010-02-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2009-11-06 c:\windows\Tasks\Norton AntiVirus - Scansione del computer.job
- c:\progra~1\NORTON~1\Navw32.exe [2003-08-22 20:14]
2010-02-07 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2009-02-17 22:01]
2010-02-07 c:\windows\Tasks\User_Feed_Synchronization-{EB99D812-E6C0-40EE-9A81-3FF831D3F6A9}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.ansa.it/index.shtml
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ricerca AltaVista - file://c:\documents and settings\carrefour\Dati applicazioni\ALTAVISTA\SelectedContextSearch_Ricerca AltaVista.htm
IE: Traduci - file://c:\documents and settings\carrefour\Dati applicazioni\ALTAVISTA\SelectedContextTranslation.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-07 19:19
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Realtek\AC97 Audio]
@DACL=(02 0000)
@SACL=
"SpoutPage"=hex:01
[HKEY_LOCAL_MACHINE\software\Sensaura\Environment]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Sensaura\Speaker]
@DACL=(02 0000)
@SACL=
"ChannelConfig"=dword:00000003
"SpeakerGeometry"=dword:0000000a
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2844)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-02-07 19:38:30
ComboFix-quarantined-files.txt 2010-02-07 18:38
ComboFix2.txt 2010-01-09 11:54
ComboFix3.txt 2010-01-07 18:51
ComboFix4.txt 2010-01-07 18:40
Pre-Run: 65.365.835.776 byte disponibili
Post-Run: 65.493.532.672 byte disponibili
- - End Of File - - 88C7A3D38503C63D6C1834C25AE1ABE3