FrancescoFDAC ha scritto:Scarica
ComboFix:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe● posiziona il file scaricato sul
Desktop ●
disattiva l'Antivirus in uso, dall'icona presente sulla Traybar (accanto all'orologio di Windows)
●
disattiva il Firewall eventualmente installato, dall'icona presente sulla Traybar (accanto all'orologio di Windows)
Eseguiti i passaggi indicati sopra:
● lancia
ComboFix con un doppio click
● una volta avviato clicca il pulsante
Accetto: conferma cliccando
Ok due volte
● segui le istruzioni che verranno rilasciate per eseguire la scansione:
"Tipicamente non impiega più di 10 minuti
Su pc molto infetti il tempo di scansione può raddoppiare facilmente"
● nel caso tu abbia
Windows XP, verrà richiesta l'installazione della
Console di ripristino di emergenza:
non la installare (clicca il pulsante
No)
●
senza eseguire nessuna altra operazione, lascia che il tool completi il suo lavoro
Note - durante la scansione:
● potrebbero comparire alcuni file sul
Desktop, e poi eliminati
● spariranno, per un attimo, tutte le icone presenti sul
Desktop: nulla di cui preoccuparsi
● potrebbe venire rilasciato
un messaggio in relazione all'
Antivirus in uso:
prosegui ignorando il messaggio● il firewall potrebbe rilasciare un avviso circa la
rimozione di alcuni driver:
consenti● potrebbe apparire sul
Desktop l'icona di
Internet ExplorerQuando
ComboFix avrà concluso l'operazione di scansione:
● il sistema verrà
riavviato automaticamente: in caso contrario,
riavvialo te● vai in
Disco Locale C:, cerca il file di testo dal nome
ComboFix.txt ed
allegaloNota - riguardo al programma:
● per eseguire correttamente
ComboFix su
Windows Vista e
Windows Seven, clicca con il
tasto destro del mouse sull'icona del programma e, dal menù contestuale, scegli la voce
Esegui come Amministratore●
sUBs, la software house che distribuisce ComboFix,
non è responsabile di qualsiasi danno causato dopo l'utilizzo del programma stesso.
Esso non dovrebbe essere utilizzato a meno che non venga espressamente richiesto da un esperto●
ComboFix disabilita l'esecuzione automatica delle unità USB (Chiavette, Hard Disk Esterni, Lettori MP3...) per prevenire future minacce: quando inserisci una Pendrive, dovrai avviarla manualmente dalle
Risorse del computer.
ecco il log di combofix:
ComboFix 12-04-20.03 - Utente 20/04/2012 22.06.00.1.2 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.3583.3266 [GMT 2:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {7698207D-28F8-003E-AC1D-9876381E9876}
AV: AntiVir Desktop *Enabled/Outdated* {0012F2B4-5C49-7C92-0300-000000000000}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {0012F2B4-5CE9-7C92-0300-000000000000}
AV: Avira Desktop *Disabled/Updated* {00000000-0715-0000-08F2-13003094807C}
AV: Avira Desktop *Disabled/Updated* {7C926E90-FFFF-FFFF-00F0-FD7FB0F21200}
AV: Avira Desktop *Enabled/Updated* {7C926E90-FFFF-FFFF-00D0-FD7FB0F21200}
AV: Avira Desktop *Enabled/Updated* {7C926E90-FFFF-FFFF-00E0-FD7FB0F21200}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\Utente\Dati applicazioni\cacaoweb
c:\documents and settings\Utente\Dati applicazioni\cacaoweb\adstorage.db
c:\documents and settings\Utente\Dati applicazioni\cacaoweb\replicating98C232C5CE5913BEA351418B8AE6B41F.cacao
c:\documents and settings\Utente\Dati applicazioni\cacaoweb\storage.db
c:\documents and settings\Utente\Dati applicazioni\Microsoft\~DFK73abf0.tmp
c:\documents and settings\Utente\Dati applicazioni\Microsoft\1eaadjc.dll
c:\documents and settings\Utente\Dati applicazioni\Microsoft\bass.dll
c:\documents and settings\Utente\Dati applicazioni\Microsoft\kfgresk.dll
c:\documents and settings\Utente\Dati applicazioni\Microsoft\mjcriu.dll
c:\documents and settings\Utente\Dati applicazioni\Microsoft\peaadje.dll
c:\documents and settings\Utente\Dati applicazioni\Microsoft\qwadjb.dll
c:\documents and settings\Utente\Dati applicazioni\Microsoft\rsaadjd.dll
c:\documents and settings\Utente\Dati applicazioni\OfferBox
c:\documents and settings\Utente\Dati applicazioni\OfferBox\config.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong
c:\documents and settings\Utente\WINDOWS
c:\programmi\Windows Searchqu Toolbar
c:\windows\IsUn0410.exe
c:\windows\iun6002.exe
c:\windows\jestertb.dll
c:\windows\system32\roboot.exe
c:\windows\unin0410.exe
c:\windows\XSxS
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
.
.
((((((((((((((((((((((((( Files Creati Da 2012-03-20 al 2012-04-20 )))))))))))))))))))))))))))))))))))
.
.
2012-04-20 19:18 . 2012-04-20 19:35 -------- d-----w- C:\sh4ldr
2012-04-20 19:18 . 2012-04-20 19:18 -------- d-----w- c:\programmi\Enigma Software Group
2012-04-20 19:18 . 2012-04-20 19:34 -------- d-----w- c:\windows\4E0C6314A8B84026AC15084E8B63AFB5.TMP
2012-04-20 19:18 . 2012-04-20 19:18 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2012-04-20 19:01 . 2012-04-20 19:01 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Registry Mechanic
2012-04-20 18:56 . 2012-04-20 18:57 -------- d-----w- c:\programmi\SUPERAntiSpyware
2012-04-20 18:51 . 2012-04-20 18:51 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\TestApp
2012-04-20 18:49 . 2012-04-20 18:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Tools
2012-04-20 14:40 . 2012-04-20 14:40 295424 ----a-w- c:\windows\system32\bwmedia1.dll
2012-04-20 14:40 . 2012-04-20 14:40 150016 ----a-w- c:\windows\system32\bwmedia.dll
2012-04-17 20:05 . 2012-04-18 11:03 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-11 13:13 . 2008-05-13 15:23 417792 ----a-w- c:\programmi\Windows Media Player\Plugins\wmp_scrobbler.dll
2012-04-11 13:12 . 2012-04-11 13:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Last.fm
2012-04-11 13:04 . 2012-04-11 13:04 -------- d-----w- c:\programmi\Last.fm
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\programmi\Mozilla Firefox\plugins\nppdf32.dll
2012-03-23 12:22 . 2012-03-23 12:22 8192 ----a-w- c:\windows\system32\srvany.exe
2012-03-23 12:06 . 2012-03-23 12:06 -------- d-----w- c:\programmi\Microsoft Synchronization Services
2012-03-23 12:05 . 2012-03-23 12:05 -------- d-----w- c:\programmi\Microsoft Sync Framework
2012-03-23 12:05 . 2012-03-23 12:05 -------- d-----w- c:\programmi\Microsoft SQL Server Compact Edition
2012-03-23 12:05 . 2012-03-23 12:05 -------- d-----w- c:\documents and settings\All Users\Microsoft
2012-03-23 11:56 . 2012-03-23 11:56 -------- d-----w- c:\programmi\Microsoft Visual Studio 8
2012-03-23 11:54 . 2012-03-23 11:54 -------- d-----w- c:\programmi\Microsoft Analysis Services
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-18 11:03 . 2011-05-14 12:14 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 13:56 . 2010-08-16 15:55 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-11 21:13 . 2011-06-30 07:38 97760 ----a-w- c:\windows\system32\drivers\inspect.sys
2012-03-11 21:13 . 2011-06-30 07:38 31704 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2012-03-11 21:13 . 2011-06-30 07:38 494968 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2012-03-11 21:13 . 2011-06-30 07:38 18056 ----a-w- c:\windows\system32\drivers\cmderd.sys
2012-03-11 21:13 . 2011-10-19 19:22 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2012-03-11 21:13 . 2011-06-30 07:37 301224 ----a-w- c:\windows\system32\guard32.dll
2012-03-01 11:00 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:00 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-03-01 11:00 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2008-04-14 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-14 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-02-29 11:34 . 2010-07-24 07:44 473656 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-02-15 14:23 . 2011-12-26 16:54 137416 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-02-15 10:01 . 2010-06-18 18:20 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-15 10:01 . 2010-06-18 18:20 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2012-02-14 10:09 . 2012-02-14 10:09 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-03 09:57 . 2008-04-14 12:00 1860096 ----a-w- c:\windows\system32\win32k.sys
2012-03-18 18:21 . 2011-03-31 11:48 97208 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-03-07 3905920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mylbx"="c:\programmi\My Lockbox\mylbx.exe" [2011-05-07 1899328]
"SwitchBoard"="c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"COMODO Internet Security"="c:\programmi\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2000-01-01 13892200]
"nwiz"="c:\programmi\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360]
"RTHDCPL"="RTHDCPL.EXE" [2000-01-01 20064872]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2011-12-16 258512]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-01-17 252296]
"BCSSync"="c:\programmi\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 45056]
SkyServer.lnk - c:\programmi\Modem SAT\bin\SkyServer.exe [2010-6-17 430080]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-07-14 12:46 137536 ----atw- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-03-27 03:09 421736 ----a-w- c:\programmi\iTunes\iTunesHelper.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"Google Update"="c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe"
"EEventManager"="c:\programmi\Epson Software\Event Manager\EEventManager.exe"
"AdobeAAMUpdater-1.0"="c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"AdobeCS5ServiceManager"="c:\programmi\File comuni\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"DivXUpdate"="c:\programmi\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe"
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" -atboottime
"APSDaemon"="c:\programmi\File comuni\Apple\Apple Application Support\APSDaemon.exe"
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"RemoteControl"=c:\programmi\CyberLink\PowerDVD\PDVDServ.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Modem SAT\\bin\\SkyServer.exe"=
"c:\\Programmi\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Programmi\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Smart PC Solutions\\Arrange Startup\\StartupSoftware.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Winamp\\winamp.exe"=
"c:\\Programmi\\SHOUTcast\\sc_serv.exe"=
"c:\\Programmi\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\File comuni\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Programmi\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Utente\\Impostazioni locali\\Dati applicazioni\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Gestione remota Windows
.
R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [19/06/2010 9.55.24 41912]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R2 !SASCORE;SAS Core Service;c:\programmi\SUPERAntiSpyware\SASCore.exe [12/08/2011 1.38.07 116608]
S1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [26/12/2011 18.54.27 36000]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [30/06/2011 9.38.14 494968]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [30/06/2011 9.38.14 31704]
S1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [22/07/2011 18.27.02 12880]
S1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [12/07/2011 23.55.22 67664]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\programmi\File comuni\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [14/05/2009 18.07.14 759048]
S2 AntiVirSchedulerService;Avira Pianificatore;c:\programmi\Avira\AntiVir Desktop\sched.exe [26/12/2011 18.54.29 86224]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13.16.28 130384]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [21/06/2010 12.54.01 20968]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [22/07/2011 19.38.46 21992]
S2 FastPara;FastPara;c:\windows\system32\drivers\fastpara.sys [19/07/2010 13.50.53 4832]
S2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [19/06/2010 9.55.25 142648]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [03/07/2010 11.08.05 136176]
S2 KMService;KMService;c:\windows\system32\srvany.exe [23/03/2012 14.22.57 8192]
S2 Micro Focus License Manager;Micro Focus License Manager;c:\rte-ne51\mflmwin.exe [10/06/2011 17.41.15 389120]
S2 NAUpdate;@c:\programmi\Nero\Update\NASvc.exe,-200;c:\programmi\Nero\Update\NASvc.exe [29/03/2011 15.33.08 598312]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\programmi\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [21/09/2011 11.07.10 2255464]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [17/04/2012 22.05.40 253088]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [17/06/2010 8.53.15 1691480]
S3 cpuz134;cpuz134;c:\programmi\CPUID\PC Wizard 2010\pcwiz_x32.sys [18/03/2012 21.08.10 20328]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [03/07/2010 11.08.05 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\programmi\Microsoft Office\Office14\GROOVE.EXE [12/06/2011 12.15.00 31125880]
S3 osppsvc;Office Software Protection Platform;c:\programmi\File comuni\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 22.37.50 4640000]
S3 SKYNET;B2C2 Broadband Receiver PCI Adapter;c:\windows\system32\drivers\SkyNET.sys [11/08/2011 10.30.18 451816]
S3 SwitchBoard;SwitchBoard;c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13.37.14 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14/04/2008 14.00.00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13.16.28 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-04-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 11:03]
.
2011-08-14 c:\windows\Tasks\AdobeAAMUpdater-1.0-UTENTE-DEE3957F-Utente.job
- c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-07-08 01:44]
.
2012-04-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2012-04-20 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-73586283-1801674531-1004Core.job
- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Facebook\Update\FacebookUpdate.exe [2011-07-07 12:46]
.
2012-04-20 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-73586283-1801674531-1004UA.job
- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Facebook\Update\FacebookUpdate.exe [2011-07-07 12:46]
.
2012-04-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-07-03 09:08]
.
2012-04-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-07-03 09:08]
.
2012-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-73586283-1801674531-1004Core.job
- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2012-03-15 18:59]
.
2012-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-73586283-1801674531-1004UA.job
- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2012-03-15 18:59]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 87.250.78.10 87.250.77.204
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\y3soqe5r.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.searchqu.com/410FF - prefs.js: keyword.URL -
hxxp://www.searchqu.com/web?src=ffb&app ... 10&sr=0&q=FF - prefs.js: network.proxy.type - 2
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Toolbar-10 - (no file)
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Alice Modem SAT - c:\windows\IsUn0410.exe
AddRemove-60a - c:\windows\IsUn0410.exe
AddRemove-Searchqu 410 MediaBar - c:\programmi\Windows Searchqu Toolbar\Datamngr\ToolBar\uninstallTB.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-04-20 22:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-1085031214-73586283-1801674531-1004\Software\SecuROM\License information*]
"datasecu"=hex:92,a0,9f,0a,ee,90,0a,58,fe,b0,34,33,0c,db,78,5b,ba,a1,93,5e,db,
8c,2f,67,b6,f5,e0,ad,99,ca,fa,bc,92,92,9e,dd,ce,4d,f4,5c,fd,76,ac,33,b6,b9,\
"rkeysecu"=hex:67,b3,24,46,33,63,1b,8a,29,76,48,15,92,5e,60,99
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(228)
c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1868)
c:\windows\system32\WININET.dll
c:\progra~1\FILECO~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1040\GrooveIntlResource.dll
c:\programmi\iTunes\iTunesMiniPlayer.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\it.lproj\iTunesMiniPlayerLocalized.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
.
Ora fine scansione: 2012-04-20 22:31:08 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-04-20 20:31
.
Pre-Run: 112.320.491.520 byte disponibili
Post-Run: 114.098.978.816 byte disponibili
.
- - End Of File - - 1AA4E345C158862E05F89C30F5FD706E
La homepage di searchnu è rimasta però boh..apparentemente sto virus non sta facendo nulla..non so nemmeno se l'o rimosso..