la scansione l ho fatta dall account admin di mio fratello,va bene lo stesso?
comunque mentre facevo la scansione ho dovuto disattivare avira,e nel mentre sul cellulare mi è apparsa questa strana scritta
spiacente...
si è verificato un problema con gwes.exe
questo è il log:
ComboFix 11-12-13.03 - polizia di Stato 14/12/2011 2.27.45.1.2 - x86
Eseguito da: c:\users\polizia di Stato\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Creati Da 2011-11-14 al 2011-12-14 )))))))))))))))))))))))))))))))))))
.
.
2011-12-13 23:22 . 2011-12-13 23:22 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2AF1B1F0-FD95-47ED-A1C5-ED975189AAAF}\offreg.dll
2011-12-13 22:44 . 2011-12-13 22:44 -------- d-----w- c:\program files\VS Revo Group
2011-12-12 21:49 . 2011-12-12 21:49 -------- d-----w- c:\program files\Unknown Device Identifier
2011-12-12 08:23 . 2011-12-12 08:23 106904 ----a-w- c:\windows\system32\drivers\avfwot.sys
2011-12-12 08:23 . 2011-12-12 08:23 82952 ----a-w- c:\windows\system32\drivers\avfwim.sys
2011-12-12 08:03 . 2011-12-12 11:40 -------- d-----w- c:\program files\ClamWin
2011-12-11 22:54 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2AF1B1F0-FD95-47ED-A1C5-ED975189AAAF}\mpengine.dll
2011-12-09 11:14 . 2008-11-13 08:26 616024 ----a-w- c:\windows\system32\COMCTL32.OCX
2011-12-07 18:58 . 2011-12-07 20:04 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-12-07 18:58 . 2011-12-07 20:04 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-12-07 18:58 . 2011-12-07 18:58 -------- d-----w- c:\program files\Avira
2011-12-07 11:47 . 2011-12-09 08:54 -------- d-----w- c:\programdata\Avira
2011-12-06 02:32 . 2011-12-06 02:34 -------- d-----w- c:\program files\DIFX
2011-12-06 02:28 . 2011-05-18 09:13 75264 ----a-w- c:\windows\system32\nmwcdcls.dll
2011-12-06 02:24 . 2011-12-06 14:36 -------- d-----w- c:\programdata\Installations
2011-12-03 06:09 . 2011-12-11 23:51 181064 ----a-w- c:\windows\PSEXESVC.EXE
2011-12-03 05:58 . 2011-12-03 06:09 -------- d-----w- c:\program files\PsExec
2011-12-03 00:28 . 2011-12-03 02:00 -------- d-----w- C:\$RECYCLE(0).BIN
2011-12-02 05:07 . 2011-12-11 22:15 -------- d-----w- c:\program files\Unlocker
2011-12-02 02:26 . 2010-01-06 17:23 142648 ----a-w- c:\windows\system32\fsproflt.exe
2011-12-02 02:26 . 2008-06-05 18:37 43792 ----a-w- c:\windows\system32\drivers\FSPFltd.sys
2011-12-01 05:31 . 2011-12-07 12:43 -------- d--h--w- c:\programdata\Common Files
2011-12-01 05:31 . 2011-12-04 15:42 -------- d-----w- c:\programdata\MFAData
2011-12-01 04:50 . 2011-12-03 13:00 -------- d-----w- c:\program files\RegCleaner
2011-11-30 10:22 . 2011-11-30 10:22 -------- d-----w- c:\program files\Debugging Tools for Windows (x86)
2011-11-30 10:06 . 2011-12-08 01:26 -------- d-----w- c:\program files\Application Verifier
2011-11-30 09:27 . 2011-11-30 09:27 -------- d-----w- c:\program files\Microsoft SDKs
2011-11-30 09:08 . 2011-12-01 12:04 -------- d-----w- C:\2af6857427497f0280bb9b
2011-11-29 06:23 . 2011-11-29 06:23 -------- d-----w- C:\rsit
2011-11-29 01:45 . 2011-12-03 13:00 -------- d-----w- c:\program files\CamStudio 2.6b
2011-11-28 23:01 . 2011-12-01 11:46 -------- d-----w- c:\windows\Lhsp
2011-11-28 01:11 . 2011-11-28 02:01 -------- d-----w- c:\program files\Freemake
2011-11-27 23:58 . 2011-11-28 02:11 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2011-11-27 23:58 . 2011-11-27 23:58 -------- d-----w- c:\program files\DVDVideoSoft
2011-11-27 02:29 . 2011-12-03 13:00 -------- d-----w- c:\program files\Drive Rescue
2011-11-27 01:17 . 2011-11-28 02:02 -------- d-----w- c:\programdata\Freemake
2011-11-27 00:38 . 2007-04-12 13:19 129024 ----a-w- c:\windows\system32\AVERM.dll
2011-11-23 16:57 . 2011-11-29 18:50 -------- d-----w- c:\programdata\WindowsSearch
2011-11-23 15:27 . 2011-11-23 15:27 -------- d--h--w- c:\windows\PIF
2011-11-22 11:05 . 2011-11-22 11:05 -------- d-----w- c:\program files\Motorola
2011-11-22 03:34 . 2011-11-22 03:33 69632 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-22 03:33 . 2011-11-22 03:33 -------- d-----w- c:\program files\Java
2011-11-22 03:33 . 2011-11-22 03:33 -------- d-----w- c:\program files\Common Files\Java
2011-11-21 17:54 . 2011-11-21 17:54 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-20 17:49 . 2011-10-28 09:41 105792 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2011-11-20 17:49 . 2011-10-28 09:40 252840 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-11-20 17:49 . 2011-10-28 10:01 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys
2011-11-20 17:48 . 2011-10-28 10:03 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-11-20 14:45 . 2011-10-07 16:52 660992 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2011-11-20 14:45 . 2011-10-07 16:52 341656 ----a-w- c:\windows\system32\drivers\pctDS.sys
2011-11-20 14:45 . 2011-10-22 14:11 331880 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-11-20 14:45 . 2011-10-22 14:11 162584 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-11-20 14:45 . 2011-10-28 10:02 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-11-20 04:46 . 2011-12-11 22:16 -------- d-----w- c:\users\Administrator
2011-11-20 04:28 . 2011-11-20 04:28 -------- d-----w- c:\windows\system32\Macromed
2011-11-20 00:36 . 2011-11-20 00:48 -------- d-----w- c:\program files\DebugMode
2011-11-19 00:32 . 2011-11-19 00:32 -------- d--h--w- c:\windows\msdownld.tmp
2011-11-18 01:58 . 2011-11-18 01:58 -------- d-----w- c:\program files\Common Files\InstallShield
2011-11-17 15:19 . 2011-03-02 10:43 175616 ----a-w- c:\windows\system32\unrar.dll
2011-11-17 11:37 . 2011-11-17 11:38 -------- d-----w- c:\program files\Common Files\Adobe
2011-11-17 03:21 . 2009-06-25 15:25 38400 ----a-w- c:\windows\system32\drivers\rixdptsk.sys
2011-11-17 03:21 . 2007-07-25 11:48 172032 ----a-w- c:\windows\system32\rixdicon.dll
2011-11-17 03:21 . 2011-12-06 14:47 -------- dc----w- c:\windows\system32\DRVSTORE
2011-11-17 02:45 . 2011-12-03 13:00 -------- d-----w- c:\program files\TCPEye
2011-11-17 01:11 . 2009-06-25 15:58 48128 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2011-11-17 01:11 . 2009-06-25 15:10 44544 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2011-11-17 01:11 . 2004-09-04 02:00 90112 ----a-w- c:\windows\system32\snymsico.dll
2011-11-17 01:06 . 2009-07-24 09:49 114688 ----a-w- c:\windows\system32\RicohMediadriverVer.dll
2011-11-16 21:50 . 2011-11-16 21:50 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-11-16 21:50 . 2011-11-16 21:50 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-11-16 21:50 . 2011-11-16 21:50 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2011-11-16 19:33 . 2011-11-16 19:33 -------- d-----w- c:\program files\Common Files\CANON
2011-11-16 19:30 . 2011-11-23 15:57 -------- d--h--w- c:\programdata\CanonBJ
2011-11-16 19:30 . 2010-04-24 04:00 70656 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP9W.DLL
2011-11-16 19:30 . 2010-04-24 04:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD9W.DLL
2011-11-16 19:30 . 2011-11-23 15:57 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2011-11-16 19:28 . 2009-03-11 10:34 303104 ----a-w- c:\windows\system32\CNC250L.dll
2011-11-16 19:28 . 2009-04-03 15:00 1310720 ----a-w- c:\windows\system32\CNC250C.dll
2011-11-16 19:28 . 2009-04-03 14:59 110592 ----a-w- c:\windows\system32\CNC250I.dll
2011-11-16 19:28 . 2009-04-03 14:57 106496 ----a-w- c:\windows\system32\CNC250U.dll
2011-11-16 19:28 . 2008-08-25 17:02 15872 ----a-w- c:\windows\system32\CNHMCA.dll
2011-11-16 19:27 . 2010-04-24 04:00 272384 ----a-w- c:\windows\system32\CNMLM9W.DLL
2011-11-16 19:27 . 2009-02-04 12:17 90112 ----a-w- c:\windows\system32\CNC250O.dll
2011-11-16 19:27 . 2009-03-18 08:09 178176 ----a-w- c:\windows\system32\CNMIU9W.DLL
2011-11-16 19:27 . 2011-11-23 15:57 -------- d--h--w- c:\program files\CanonBJ
2011-11-16 14:16 . 2011-12-03 13:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-16 14:16 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-16 12:53 . 2011-09-01 02:22 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-16 12:53 . 2011-09-01 02:35 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-16 12:53 . 2011-09-01 02:28 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-11-16 11:23 . 2011-12-13 20:36 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-11-16 11:23 . 2011-12-03 13:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-11-16 02:02 . 2011-11-16 02:02 -------- d-----w- c:\program files\Microsoft.NET
2011-11-16 01:02 . 2011-11-16 01:04 -------- d-----w- c:\programdata\NVIDIA
2011-11-16 00:43 . 2009-10-03 05:02 584296 ----a-w- c:\windows\system32\nvuninst.exe
2011-11-16 00:25 . 2009-04-29 06:46 15872 ----a-w- c:\windows\system32\drivers\HpqKbFiltr.sys
2011-11-16 00:25 . 2006-11-02 05:09 1419232 ----a-w- c:\windows\system32\drivers\wdfcoinstaller01005.dll
2011-11-16 00:25 . 2011-11-16 00:26 -------- d-----w- c:\program files\Hewlett-Packard
2011-11-16 00:25 . 2008-09-08 12:31 1885488 ----a-w- c:\windows\system32\BttnCmns.dll
2011-11-16 00:25 . 2008-09-08 12:31 1885488 ----a-r- c:\windows\system32\BttnCmn.dll
2011-11-16 00:25 . 2011-11-17 01:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2011-11-16 00:25 . 2011-11-28 08:02 -------- d-----w- c:\windows\QLB
2011-11-15 18:46 . 2011-12-03 13:00 -------- d-----w- c:\program files\VirtualDJ
2011-11-15 17:57 . 2011-03-03 15:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-11-15 17:57 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-11-15 17:54 . 2009-07-14 17:45 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2011-11-15 17:54 . 2009-07-14 17:45 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2011-11-15 17:47 . 2011-11-15 17:47 -------- d-----w- c:\program files\Synaptics
2011-11-15 17:37 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-11-15 17:34 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2011-11-15 17:34 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2011-11-15 17:00 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2011-11-15 16:02 . 2011-11-15 16:02 -------- d-----w- c:\program files\VITSOFT
2011-11-15 15:34 . 2011-11-15 13:29 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-11-15 14:05 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2011-11-15 14:05 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2011-11-15 14:05 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2011-11-15 14:05 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2011-11-15 14:05 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2011-11-15 14:05 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2011-11-15 14:05 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2011-11-15 14:05 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2011-11-15 14:02 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2011-11-15 14:02 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll
2011-11-15 14:02 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-24 23:06 . 2011-09-24 23:06 5617810 -c--a-w- C:\$RUXORFC.zip
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 1721640]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-10-26 1458176]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-02-04 281768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HijackThis startup scan]
2010-03-25 17:42 388096 ----a-w- c:\program files\Trend Micro\HiJackThis\HiJackThis.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2009-11-24 10:07 323640 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-11-22 03:34 77824 ----a-w- c:\program files\Java\jre1.6.0\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
.
R3 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 99329906;99329906;c:\windows\system32\DRIVERS\99329906.sys [x]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
R4 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-10-07 341656]
R4 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD.sys [2011-10-28 185560]
R4 viritsvclite;VirIT eXplorer Lite;c:\vexplite\viritsvc.exe [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-10-22 331880]
S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-10-07 660992]
S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [2011-12-07 340136]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-12-07 136360]
S2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2011-12-07 428200]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
.
.
--- Altri Servizi/Drivers In Memoria ---
.
*Deregistered* - PROCEXP141
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-12-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2341135496-3086221404-111232173-1000Core.job
- c:\users\polizia di Stato\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-15 08:59]
.
2011-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2341135496-3086221404-111232173-1000UA.job
- c:\users\polizia di Stato\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-15 08:59]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-12-14 02:34
Windows 6.0.6002 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Everyone)
@Denied: (A) (Users)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Ora fine scansione: 2011-12-14 02:36:46
ComboFix-quarantined-files.txt 2011-12-14 01:36
ComboFix2.txt 2011-12-05 10:43
ComboFix3.txt 2011-12-04 02:32
ComboFix4.txt 2011-12-03 04:20
ComboFix5.txt 2011-12-07 17:53
.
Pre-Run: 115.916.976.128 byte disponibili
Post-Run: 115.889.299.456 byte disponibili
.
- - End Of File - - 6803C151319AAC53474232515E4FA350