Ciao,
avevo dimenticato di togliere un gioco dal lettore.
Ora riesco di nuovo a riavviare in modallità provissoria, di consegunza ho cancellato le voci dette in precedenza da a.roselli.
Ho notato che mi sono state create delle cartelle vuote in quasi tutte le partizioni (6 su 8), denominate "$RECYCLE.BIN"; è normale?
Ora posto il log di combofix:
ComboFix 10-03-29.04 - test 01/04/2010 1.24.16.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.39.1040.18.3070.1889 [GMT 2:00]
Eseguito da: p:\generale\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 081119-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1229 [VPS 081119-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Creati Da 2010-02-28 al 2010-03-31 )))))))))))))))))))))))))))))))))))
.
2010-03-31 23:34 . 2010-03-31 23:34 -------- d-----w- c:\users\test\AppData\Local\temp
2010-03-31 23:34 . 2010-03-31 23:34 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-03-31 23:34 . 2010-03-31 23:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-31 23:10 . 2010-03-31 23:10 -------- d-----w- c:\program files\Trend Micro
2010-03-29 22:51 . 2010-03-30 01:41 -------- d-----w- C:\FyK
2010-03-28 22:39 . 2010-03-28 22:48 -------- d-----w- c:\users\test\AppData\Roaming\.clamwin
2010-03-28 22:39 . 2010-03-28 22:39 -------- d-----w- c:\programdata\.clamwin
2010-03-28 16:14 . 2010-03-28 18:11 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-03-28 15:39 . 2010-03-28 15:39 -------- d-----w- c:\programdata\Microsoft Games
2010-03-26 00:40 . 2010-03-26 00:40 -------- d-----w- c:\program files\Creative
2010-03-10 23:23 . 2008-10-27 09:04 514384 ----a-w- c:\windows\system32\XAudio2_3.dll
2010-03-10 23:23 . 2008-10-27 09:04 70992 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2010-03-10 23:23 . 2008-10-27 09:04 235856 ----a-w- c:\windows\system32\xactengine3_3.dll
2010-03-10 23:23 . 2008-10-27 09:04 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2010-03-10 00:27 . 2010-03-10 00:27 -------- d-sh--w- c:\programdata\SecuROM
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-31 23:30 . 2006-11-06 01:52 672382 ----a-w- c:\windows\system32\perfh010.dat
2010-03-31 23:30 . 2006-11-06 01:52 124848 ----a-w- c:\windows\system32\perfc010.dat
2010-03-31 23:14 . 2008-09-02 21:45 -------- d-----w- c:\users\test\AppData\Roaming\tor
2010-03-31 23:14 . 2008-09-02 21:44 -------- d-----w- c:\users\test\AppData\Roaming\Vidalia
2010-03-28 21:46 . 2008-03-26 13:54 -------- d-----w- c:\program files\AVAST
2010-03-10 23:23 . 2008-10-24 23:00 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-03-10 00:09 . 2008-10-24 23:01 -------- d-----w- c:\program files\AGEIA Technologies
2010-02-27 02:31 . 2008-07-19 06:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-24 09:16 . 2009-10-02 23:34 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-19 15:42 . 2010-02-19 15:42 -------- d-----w- c:\users\test\AppData\Roaming\FastStone
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DAEMON Tools Lite"="c:\program files\MASTERIZZAZIONE\Daemon Tools Lite 4.12\daemon.exe" [2008-01-17 486856]
"Vidalia"="c:\program files\INTERNET\Vidalia Bundle\Vidalia\vidalia.exe" [2007-11-22 12889088]
"Packard Bell Software Suite"="c:\program files\Packard Bell\Packard Bell Software Suite\Launcher.exe" [2008-01-09 1914168]
"RGSC"="l:\giochi\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2009-03-29 306088]
"Lingoes"="d:\programmi\MULTIMEDIA\Translator2\Lingoes.exe" [2008-08-10 2064384]
"Active Desktop Calendar"="d:\programmi\ACCESORI\Active Desktop Calendar\ADC.exe" [2007-07-16 3670016]
"eMuleAutoStart"="c:\program files\P2P\eMule\emule.exe" [2008-05-11 5423104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-01-24 319488]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avast!"="c:\progra~1\AVAST\ashDisp.exe" [2009-11-24 81000]
"QuickTime Task"="d:\programmi\AUDIO&VIDEO\QuickTime Alternative\QTTask.exe" [2008-01-31 385024]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]
"UnlockerAssistant"="d:\programmi\SICUREZZA\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"CloneCDElbyCDFL"="d:\programmi\MASTERIZZAZIONE\CloneCD\ElbyCheck.exe" [2001-12-06 45056]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"ClamWin"="d:\programmi\SICUREZZA\ClamWin\bin\ClamTray.exe" [2009-11-03 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Avvio veloce di Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-4-24 528384]
PCM Media Sharing.lnk - c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2007-4-24 200812]
Privoxy.lnk - c:\program files\INTERNET\Vidalia Bundle\Privoxy\privoxy.exe [2006-11-20 250368]
w98Eject.lnk - c:\windows\System\w98eject.exe [2008-12-25 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-214327634-1795953299-1007255817-1000]
"EnableNotificationsRef"=dword:00000002
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-02-02 716272]
S1 aswSP;avast! Self Protection; [x]
S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-04-04 266343]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-11-24 53328]
S2 SBSDWSCService;SBSD Security Center Service;d:\programmi\SICUREZZA\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
.
Contenuto della cartella 'Scheduled Tasks'
2010-03-31 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\SISTEMA\Glary Utilities\initialize.exe [2008-07-11 11:22]
2007-11-17 c:\windows\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.tiscali.it/
mStart Page = hxxp://it.yahoo.com
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\test\AppData\Roaming\Mozilla\Firefox\Profiles\is89hbls.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://it.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:it:official
FF - plugin: d:\programmi\AUDIO&VIDEO\QuickTime Alternative\Plugins\npqtplugin.dll
FF - plugin: d:\programmi\AUDIO&VIDEO\QuickTime Alternative\Plugins\npqtplugin2.dll
FF - plugin: d:\programmi\AUDIO&VIDEO\QuickTime Alternative\Plugins\npqtplugin3.dll
FF - plugin: d:\programmi\AUDIO&VIDEO\QuickTime Alternative\Plugins\npqtplugin4.dll
FF - plugin: d:\programmi\AUDIO&VIDEO\QuickTime Alternative\Plugins\npqtplugin5.dll
FF - plugin: d:\programmi\AUDIO&VIDEO\Real Alternative\browser\plugins\nppl3260.dll
FF - plugin: d:\programmi\AUDIO&VIDEO\Real Alternative\browser\plugins\nprpjplug.dll
FF - plugin: d:\programmi\AUDIO&VIDEO\VLC\npvlc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("ui.use_native_colors", true);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("svg.smil.enabled", false);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("browser.formfill.debug", false);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
d:\programmi\INTERNET\FireFox\greprefs\all.js - pref("html5.enable", false);
d:\programmi\INTERNET\FireFox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
d:\programmi\INTERNET\FireFox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
d:\programmi\INTERNET\FireFox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
d:\programmi\INTERNET\FireFox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
d:\programmi\INTERNET\FireFox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
d:\programmi\INTERNET\FireFox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-01 01:34
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\.Default\Software\JavaSoft\Java2D]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-214327634-1795953299-1007255817-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:82,dd,f4,e7,8f,50,9d,0e,07,32,5d,60,33,7b,ed,be,2f,10,ce,08,2a,d3,ec,
80,b6,3b,72,f8,68,e6,de,67,d9,10,d7,f5,7a,32,87,a3,09,c8,f7,60,a6,5b,37,31,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-214327634-1795953299-1007255817-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:90,e8,c0,d1,64,ef,f8,38,f3,32,1e,fb,40,0c,30,3c,a3,70,71,f2,83,
bb,d7,a6,26,04,0d,08,55,cc,74,41,15,a1,ab,21,6d,a5,4a,4f,2b,99,6e,90,2e,1c,\
"rkeysecu"=hex:92,ef,c5,af,20,f0,05,6b,bc,eb,e7,8d,40,e3,b2,50
.
Ora fine scansione: 2010-04-01 01:38:30
ComboFix-quarantined-files.txt 2010-03-31 23:38
Pre-Run: 4.144.824.320 byte disponibili
Post-Run: 3.968.221.184 byte disponibili
- - End Of File - - F43716A61AE7B9ACB030F7F64780FBF1