ho usato combofix tutto in modalità provvisoria che se no me lo cancella =(
ecco il log
ComboFix 11-01-16.04 - Administrator 17/01/2011 13.44.13.2.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.511.395 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator.COMPUTER.000\Documenti\Download\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\documents and settings\user\Dati applicazioni\completescan
c:\documents and settings\user\Dati applicazioni\install
c:\documents and settings\user\Dati applicazioni\OfferBox\config.dat
c:\documents and settings\user\Dati applicazioni\OfferBox\config.xml
c:\windows\system32\wbem\svchost.jxe
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SVCHOST32
((((((((((((((((((((((((( Files Creati Da 2010-12-17 al 2011-01-17 )))))))))))))))))))))))))))))))))))
.
2011-01-16 10:44 . 2011-01-16 10:44 -------- d-----w- c:\documents and settings\user\Dati applicazioni\SUPERAntiSpyware.com
2011-01-16 10:44 . 2011-01-16 10:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2011-01-16 10:44 . 2011-01-16 10:44 -------- d-----w- c:\programmi\SUPERAntiSpyware
2011-01-15 19:02 . 2011-01-15 19:02 -------- d-----w- c:\documents and settings\user\Dati applicazioni\Malwarebytes
2011-01-15 19:01 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-15 19:01 . 2011-01-15 19:01 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-01-15 19:01 . 2011-01-15 19:01 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-01-15 19:01 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-15 17:52 . 2011-01-15 20:25 -------- d-----w- c:\windows\SxsCaPendDel
2011-01-15 17:34 . 2011-01-15 20:51 -------- d-----w- c:\documents and settings\Administrator.COMPUTER.000
2011-01-11 13:33 . 2008-04-13 10:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2011-01-11 13:33 . 2008-04-13 10:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-01-11 13:33 . 2008-04-13 10:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2011-01-11 13:33 . 2008-04-13 10:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-12-21 15:06 . 2010-12-21 15:07 -------- d-----w- c:\programmi\Zuma Deluxe
2010-12-21 14:56 . 2011-01-15 08:49 -------- d-----w- c:\programmi\PopCap Games
2010-12-21 14:35 . 2010-12-21 14:35 -------- d-----w- c:\documents and settings\user\Dati applicazioni\Zylom
2010-12-21 14:35 . 2009-10-26 15:45 102400 ----a-w- c:\programmi\Mozilla Firefox\plugins\npzylomgamesplayer.dll
2010-12-21 14:35 . 2010-12-21 14:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Zylom
2010-12-21 14:34 . 2010-12-21 14:34 -------- d-----w- c:\programmi\Zylom Games
2010-12-20 11:48 . 2010-12-20 11:48 -------- d-----w- c:\programmi\Panda Security
2010-12-20 11:45 . 2010-12-20 11:45 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee
2010-12-20 11:42 . 2010-12-20 11:42 -------- d-----w- c:\documents and settings\user\Dati applicazioni\QuickScan
2010-12-20 10:39 . 2011-01-12 14:55 -------- d-----w- c:\documents and settings\user\Dati applicazioni\vlc
2010-12-20 10:38 . 2010-12-20 10:38 -------- d-----w- c:\programmi\VideoLAN
2010-12-19 11:35 . 2010-12-19 11:35 -------- d-----w- c:\programmi\ChaosLongju Client
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-22 13:17 . 2010-11-21 14:27 65536 ----a-w- c:\windows\IFinst27.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2010-04-15 08:17 427328 ----a-w- c:\programmi\DAEMON Tools Pro\DTAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\programmi\File comuni\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 09:17 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 15:49 14940040 ----a-r- c:\programmi\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2010-07-06 14:01 2634048 ----a-w- c:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"PCToolsSSDMonitorSvc"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Programmi\\DeluxeMt2_v3.2\\deluxe.bin"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15/10/2010 14.43.45 697328]
S1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19.25.48 12872]
S1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19.41.30 67656]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [15/01/2011 20.01.57 38224]
S3 NDISKIO;NDISKIO;\??\c:\docume~1\user\IMPOST~1\Temp\000003d1.nmc\nse\bin\ndiskio.sys --> c:\docume~1\user\IMPOST~1\Temp\000003d1.nmc\nse\bin\ndiskio.sys [?]
S4 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\programmi\File comuni\PC Tools\sMonitor\StartManSvc.exe [16/10/2010 17.17.31 632792]
.
Contenuto della cartella 'Scheduled Tasks'
2011-01-15 c:\windows\Tasks\RMSchedule.job
- c:\programmi\Registry Mechanic\RegMech.exe [2010-10-16 09:26]
2011-01-16 c:\windows\Tasks\RMSmartUpdate.job
- c:\programmi\Registry Mechanic\Update.exe [2010-10-16 09:26]
.
.
------- Scansione supplementare -------
.
FF - ProfilePath - c:\documents and settings\Administrator.COMPUTER.000\Dati applicazioni\Mozilla\Firefox\Profiles\e9o2jqrg.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\programmi\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-17 13:47
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(588)
c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2011-01-17 13:49:18
ComboFix-quarantined-files.txt 2011-01-17 12:49
Pre-Run: 57.740.488.704 byte disponibili
Post-Run: 57.729.761.280 byte disponibili
- - End Of File - - E5CC4227D10791D6A10054B241AE9E41