PERLUKE57:
ho fatto la scansione come esattamente scritto da te al riavvio mi ha inviato un documento bloc note "log -blocco note",io l'ho aperto e ti allego quello che c'era scritto dentro:
ComboFix 08-10-29.06 - Nicola 2008-10-29 13.59.20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.285 [GMT 1:00]
Eseguito da: C:\Documents and Settings\Nicola\Desktop\abc.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Nicola\Desktop\Videos.url
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\sc
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\sc\console.html
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\sc\script0.html
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\sc\script1.html
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\temp1.htm
C:\Documents and Settings\Nicola\Menu Avvio\Programmi\Videos.url
C:\Documents and Settings\Nicola\Preferiti\Videos.url
C:\InfoSat.txt
C:\WINDOWS\4.tmp
C:\WINDOWS\6.tmp
C:\WINDOWS\7.tmp
C:\WINDOWS\8.tmp
C:\WINDOWS\system32\kernel32.exe
C:\WINDOWS\winhelp.ini
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_POWERMANAGER
-------\Legacy_WINDOWS_MANAGEMENT_SERVICE
-------\Service_PowerManager
((((((((((((((((((((((((( Files Creati Da 2008-09-28 al 2008-10-29 )))))))))))))))))))))))))))))))))))
.
2008-10-28 18:07 . 2008-10-28 18:01 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-28 18:07 . 2008-10-28 18:01 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-28 18:00 . 2008-10-28 18:00 <DIR> d-------- C:\Programmi\Java
2008-10-28 12:48 . 2008-10-28 12:48 <DIR> d-------- C:\Documents and Settings\Nicola\Dati applicazioni\AVG7
2008-10-27 20:35 . 2008-10-29 14:07 16,928,800 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-27 20:35 . 2008-10-29 14:04 198,968 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-27 19:32 . 2008-07-08 13:54 148,496 --a------ C:\WINDOWS\system32\drivers\74884857.sys
2008-10-27 19:30 . 2008-07-08 13:54 148,496 --a------ C:\WINDOWS\system32\drivers\31452749.sys
2008-10-23 23:20 . 2008-10-23 23:20 <DIR> d-------- C:\Programmi\AVG
2008-10-23 23:20 . 2008-10-23 23:20 <DIR> d-------- C:\Documents and Settings\Nicola\Dati applicazioni\AVGTOOLBAR
2008-10-23 23:20 . 2008-10-27 13:33 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\avg8
2008-10-23 22:29 . 2008-10-23 22:29 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-10-23 22:29 . 2008-10-23 22:29 270,336 --a------ C:\WINDOWS\system32\imon.dll
2008-10-23 18:52 . 2008-10-23 22:30 <DIR> d-------- C:\Programmi\ESET
2008-10-23 13:12 . 2008-10-23 22:46 <DIR> d-------- C:\Programmi\Enigma Software Group
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 13:05 --------- d-----w C:\Documents and Settings\Nicola\Dati applicazioni\AdobeUM
2008-10-28 22:34 --------- d-----w C:\Documents and Settings\Nicola\Dati applicazioni\skypePM
2008-10-28 22:34 --------- d-----w C:\Documents and Settings\Nicola\Dati applicazioni\Skype
2008-10-28 19:45 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Avg7
2008-10-28 19:37 --------- d-----w C:\Programmi\PeerGuardian2
2008-10-28 17:12 --------- d-----w C:\Programmi\Google
2008-10-27 12:55 --------- d-----w C:\Documents and Settings\Nicola\Dati applicazioni\Azureus
2008-10-27 12:27 --------- d-----w C:\Programmi\Easy CD-DA Extractor 10
2008-10-27 12:16 --------- d-----w C:\Programmi\Spybot
2008-10-23 22:25 --------- d-----w C:\Programmi\Ad-Aware
2008-10-23 21:46 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-01-09 14:51 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"TaskTray"="C:\Programmi\Creative\SBAudigy\Taskbar\CTLTray.exe" [2001-06-29 163840]
"Taskbar"="C:\Programmi\Creative\SBAudigy\Taskbar\CTLTask.exe" [2001-07-26 118784]
"msnmsgr"="C:\Programmi\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"updateMgr"="C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-10-28 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 6803456]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-06-15 86016]
"ISUSPM Startup"="C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 221184]
"ISUSScheduler"="C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"UpdReg"="C:\WINDOWS\Updreg.exe" [2000-05-11 90112]
"CTStartup"="C:\Programmi\Creative\SBAudigy\Program\CTEaxSpl.EXE" [2001-06-04 28672]
"Jet Detection"="C:\Programmi\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2001-04-20 28672]
"HWCU"="C:\Programmi\Hamlet\HWCU.exe" [2007-09-18 348160]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2005-10-23 155648]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2008-10-28 921600]
"SunJavaUpdateSched"="C:\Programmi\Java\jre6\bin\jusched.exe" [2008-10-28 136600]
"nwiz"="nwiz.exe" [2005-06-15 C:\WINDOWS\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2007-04-09 C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 C:\WINDOWS\system32\Ctxfihlp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytoosl"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= C:\WINDOWS\system32\ctmp3.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 11:54 5674352 C:\Programmi\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-10-23 17:07 155648 C:\Programmi\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteCenter]
--------- 2001-07-03 01:30 122880 C:\Programmi\Creative\SBAudigy\RemoteCenter\Rc\RcMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 19:24 32768 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Taskbar]
--------- 2001-07-26 01:00 118784 C:\Programmi\Creative\SBAudigy\Taskbar\CTLTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskTray]
--------- 2001-06-29 01:00 163840 C:\Programmi\Creative\SBAudigy\Taskbar\CTLTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 15:45 313472 C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\EMULE\\emule.exe"=
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmi\\MSN Messenger\\livecall.exe"=
"C:\\Programmi\\Azureus\\Azureus.exe"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 is-DE5PTdrv;is-DE5PTdrv;C:\WINDOWS\system32\DRIVERS\31452749.sys [2008-07-08 148496]
R1 is-MQN6Ddrv;is-MQN6Ddrv;C:\WINDOWS\system32\DRIVERS\74884857.sys [2008-07-08 148496]
R2 JavaQuickStarterService;Java Quick Starter;C:\Programmi\Java\jre6\bin\jqs.exe [2008-10-28 152984]
R3 AR5523;Hamlet Wireless Adapter;C:\WINDOWS\system32\DRIVERS\ar5523.sys [2007-08-02 360288]
R3 DLKRTS;D-Link DFE-538TX 10/100 Adapter;C:\WINDOWS\system32\DRIVERS\DLKRTS.SYS [2002-06-24 45568]
S3 vsc32;Virtual Sound Canvas 3.2;C:\WINDOWS\system32\DRIVERS\vsc.sys [ ]
.
- - - - ORFÃOS REMOVIDOS - - - -
BHO-{9311A251-3766-3DF7-F4C3-E6C08854D8DF} - C:\WINDOWS\aacsr1.dll
HKCU-Run-clamav - NopeZ.exe
HKLM-Run-csdcb.exe - C:\WINDOWS\system32\csdcb.exe
HKLM-Run-dmxnx.exe - C:\WINDOWS\system32\dmxnx.exe
HKLM-Run-dialer423 - InpriseMon.exe
Notify- -wdtuzgie - C:\WINDOWS\system32\awwdtu.dll
SafeBoot-sglfb.sys
SafeBoot-tga.sys
SafeBoot-wd.sys
SafeBoot-sacsvr
MSConfigStartUp-KillAndClean - C:\Programmi\KillAndClean\KillAndClean.exe
MSConfigStartUp-onwu1 - C:\WINDOWS\TEMP\onwu1.exe
MSConfigStartUp-Quicktime - C:\WINDOWS\qttasks.exe
MSConfigStartUp-resagnt - C:\WINDOWS\restun.exe
MSConfigStartUp-SpybotSD TeaTimer - C:\Programmi\Spybot\Spybot - Search & Destroy\TeaTimer.exe
MSConfigStartUp-WindowsServicesStartup - C:\DOCUME~1\Nicola\IMPOST~1\Temp\svchost.exe
MSConfigStartUp-AliceSD - NopeZ.exe
MSConfigStartUp-C-Media Mixer - Mixer.exe
MSConfigStartUp-init32 - scanSYS.exe
MSConfigStartUp-powerdll - zantu.exe
.
------- Supplementare di scansione -------
.
FireFox -: Profile - C:\Documents and Settings\Nicola\Dati applicazioni\Mozilla\Firefox\Profiles\kmswy3rb.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://italian.eazel.com/index.php?rvs=hompag.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-29 14:05:48
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = C:\Programmi\Creative\SBAudigy\Program\CTEaxSpl.EXE /run?&2?????????????x??????s$????\?w? ?w???????w???w4???????.??w4???????4???TA?s4????????&2???9~??9~????????\???\???<???$???U?9~??9~\???\???<???(?`???????:~\???\??????s????\??????s\????&2?A??s?&2???:~???
Scansione files nascosti ...
C:\Documents and Settings\Nicola\Dati applicazioni\Adobe\Acrobat\7.0\Updater\AdbeRdr710_en_US.exe 19900192 bytes executable
Scansione completata con successo
Files nascosti: 1
**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\Ctsvccda.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
.
**************************************************************************
.
Ora fine scansione: 2008-10-29 14:11:12 - macchina è stato riavviato [Nicola]
ComboFix-quarantined-files.txt 2008-10-29 13:11:05
Pre-Run: 502.218.752 byte disponibili
Post-Run: 591,269,888 byte disponibili
192 --- E O F --- 2008-02-01 19:35:08
POI COME MI HAI DETTO TU SONO ANDATO CU "C" è ho trovato il Combofix ,l'ho aperto e ti allego il contenuto:
ComboFix 08-10-29.06 - Nicola 2008-10-29 13.59.20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.285 [GMT 1:00]
Eseguito da: C:\Documents and Settings\Nicola\Desktop\abc.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Nicola\Desktop\Videos.url
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\sc
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\sc\console.html
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\sc\script0.html
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\sc\script1.html
C:\Documents and Settings\Nicola\Impostazioni locali\Temporary Internet Files\temp1.htm
C:\Documents and Settings\Nicola\Menu Avvio\Programmi\Videos.url
C:\Documents and Settings\Nicola\Preferiti\Videos.url
C:\InfoSat.txt
C:\WINDOWS\4.tmp
C:\WINDOWS\6.tmp
C:\WINDOWS\7.tmp
C:\WINDOWS\8.tmp
C:\WINDOWS\system32\kernel32.exe
C:\WINDOWS\winhelp.ini
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_POWERMANAGER
-------\Legacy_WINDOWS_MANAGEMENT_SERVICE
-------\Service_PowerManager
((((((((((((((((((((((((( Files Creati Da 2008-09-28 al 2008-10-29 )))))))))))))))))))))))))))))))))))
.
2008-10-28 18:07 . 2008-10-28 18:01 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-28 18:07 . 2008-10-28 18:01 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-28 18:00 . 2008-10-28 18:00 <DIR> d-------- C:\Programmi\Java
2008-10-28 12:48 . 2008-10-28 12:48 <DIR> d-------- C:\Documents and Settings\Nicola\Dati applicazioni\AVG7
2008-10-27 20:35 . 2008-10-29 14:07 16,928,800 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-27 20:35 . 2008-10-29 14:04 198,968 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-27 19:32 . 2008-07-08 13:54 148,496 --a------ C:\WINDOWS\system32\drivers\74884857.sys
2008-10-27 19:30 . 2008-07-08 13:54 148,496 --a------ C:\WINDOWS\system32\drivers\31452749.sys
2008-10-23 23:20 . 2008-10-23 23:20 <DIR> d-------- C:\Programmi\AVG
2008-10-23 23:20 . 2008-10-23 23:20 <DIR> d-------- C:\Documents and Settings\Nicola\Dati applicazioni\AVGTOOLBAR
2008-10-23 23:20 . 2008-10-27 13:33 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\avg8
2008-10-23 22:29 . 2008-10-23 22:29 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-10-23 22:29 . 2008-10-23 22:29 270,336 --a------ C:\WINDOWS\system32\imon.dll
2008-10-23 18:52 . 2008-10-23 22:30 <DIR> d-------- C:\Programmi\ESET
2008-10-23 13:12 . 2008-10-23 22:46 <DIR> d-------- C:\Programmi\Enigma Software Group
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 13:05 --------- d-----w C:\Documents and Settings\Nicola\Dati applicazioni\AdobeUM
2008-10-28 22:34 --------- d-----w C:\Documents and Settings\Nicola\Dati applicazioni\skypePM
2008-10-28 22:34 --------- d-----w C:\Documents and Settings\Nicola\Dati applicazioni\Skype
2008-10-28 19:45 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Avg7
2008-10-28 19:37 --------- d-----w C:\Programmi\PeerGuardian2
2008-10-28 17:12 --------- d-----w C:\Programmi\Google
2008-10-27 12:55 --------- d-----w C:\Documents and Settings\Nicola\Dati applicazioni\Azureus
2008-10-27 12:27 --------- d-----w C:\Programmi\Easy CD-DA Extractor 10
2008-10-27 12:16 --------- d-----w C:\Programmi\Spybot
2008-10-23 22:25 --------- d-----w C:\Programmi\Ad-Aware
2008-10-23 21:46 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-01-09 14:51 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"TaskTray"="C:\Programmi\Creative\SBAudigy\Taskbar\CTLTray.exe" [2001-06-29 163840]
"Taskbar"="C:\Programmi\Creative\SBAudigy\Taskbar\CTLTask.exe" [2001-07-26 118784]
"msnmsgr"="C:\Programmi\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"updateMgr"="C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-10-28 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 6803456]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-06-15 86016]
"ISUSPM Startup"="C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 221184]
"ISUSScheduler"="C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"UpdReg"="C:\WINDOWS\Updreg.exe" [2000-05-11 90112]
"CTStartup"="C:\Programmi\Creative\SBAudigy\Program\CTEaxSpl.EXE" [2001-06-04 28672]
"Jet Detection"="C:\Programmi\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2001-04-20 28672]
"HWCU"="C:\Programmi\Hamlet\HWCU.exe" [2007-09-18 348160]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2005-10-23 155648]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2008-10-28 921600]
"SunJavaUpdateSched"="C:\Programmi\Java\jre6\bin\jusched.exe" [2008-10-28 136600]
"nwiz"="nwiz.exe" [2005-06-15 C:\WINDOWS\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2007-04-09 C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 C:\WINDOWS\system32\Ctxfihlp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytoosl"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= C:\WINDOWS\system32\ctmp3.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 11:54 5674352 C:\Programmi\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-10-23 17:07 155648 C:\Programmi\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteCenter]
--------- 2001-07-03 01:30 122880 C:\Programmi\Creative\SBAudigy\RemoteCenter\Rc\RcMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 19:24 32768 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Taskbar]
--------- 2001-07-26 01:00 118784 C:\Programmi\Creative\SBAudigy\Taskbar\CTLTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskTray]
--------- 2001-06-29 01:00 163840 C:\Programmi\Creative\SBAudigy\Taskbar\CTLTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 15:45 313472 C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\EMULE\\emule.exe"=
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmi\\MSN Messenger\\livecall.exe"=
"C:\\Programmi\\Azureus\\Azureus.exe"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 is-DE5PTdrv;is-DE5PTdrv;C:\WINDOWS\system32\DRIVERS\31452749.sys [2008-07-08 148496]
R1 is-MQN6Ddrv;is-MQN6Ddrv;C:\WINDOWS\system32\DRIVERS\74884857.sys [2008-07-08 148496]
R2 JavaQuickStarterService;Java Quick Starter;C:\Programmi\Java\jre6\bin\jqs.exe [2008-10-28 152984]
R3 AR5523;Hamlet Wireless Adapter;C:\WINDOWS\system32\DRIVERS\ar5523.sys [2007-08-02 360288]
R3 DLKRTS;D-Link DFE-538TX 10/100 Adapter;C:\WINDOWS\system32\DRIVERS\DLKRTS.SYS [2002-06-24 45568]
S3 vsc32;Virtual Sound Canvas 3.2;C:\WINDOWS\system32\DRIVERS\vsc.sys [ ]
.
- - - - ORFÃOS REMOVIDOS - - - -
BHO-{9311A251-3766-3DF7-F4C3-E6C08854D8DF} - C:\WINDOWS\aacsr1.dll
HKCU-Run-clamav - NopeZ.exe
HKLM-Run-csdcb.exe - C:\WINDOWS\system32\csdcb.exe
HKLM-Run-dmxnx.exe - C:\WINDOWS\system32\dmxnx.exe
HKLM-Run-dialer423 - InpriseMon.exe
Notify- -wdtuzgie - C:\WINDOWS\system32\awwdtu.dll
SafeBoot-sglfb.sys
SafeBoot-tga.sys
SafeBoot-wd.sys
SafeBoot-sacsvr
MSConfigStartUp-KillAndClean - C:\Programmi\KillAndClean\KillAndClean.exe
MSConfigStartUp-onwu1 - C:\WINDOWS\TEMP\onwu1.exe
MSConfigStartUp-Quicktime - C:\WINDOWS\qttasks.exe
MSConfigStartUp-resagnt - C:\WINDOWS\restun.exe
MSConfigStartUp-SpybotSD TeaTimer - C:\Programmi\Spybot\Spybot - Search & Destroy\TeaTimer.exe
MSConfigStartUp-WindowsServicesStartup - C:\DOCUME~1\Nicola\IMPOST~1\Temp\svchost.exe
MSConfigStartUp-AliceSD - NopeZ.exe
MSConfigStartUp-C-Media Mixer - Mixer.exe
MSConfigStartUp-init32 - scanSYS.exe
MSConfigStartUp-powerdll - zantu.exe
.
------- Supplementare di scansione -------
.
FireFox -: Profile - C:\Documents and Settings\Nicola\Dati applicazioni\Mozilla\Firefox\Profiles\kmswy3rb.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://italian.eazel.com/index.php?rvs=hompag.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-29 14:05:48
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = C:\Programmi\Creative\SBAudigy\Program\CTEaxSpl.EXE /run?&2?????????????x??????s$????\?w? ?w???????w???w4???????.??w4???????4???TA?s4????????&2???9~??9~????????\???\???<???$???U?9~??9~\???\???<???(?`???????:~\???\??????s????\??????s\????&2?A??s?&2???:~???
Scansione files nascosti ...
C:\Documents and Settings\Nicola\Dati applicazioni\Adobe\Acrobat\7.0\Updater\AdbeRdr710_en_US.exe 19900192 bytes executable
Scansione completata con successo
Files nascosti: 1
**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\Ctsvccda.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
.
**************************************************************************
.
Ora fine scansione: 2008-10-29 14:11:12 - macchina è stato riavviato [Nicola]
ComboFix-quarantined-files.txt 2008-10-29 13:11:05
Pre-Run: 502.218.752 byte disponibili
Post-Run: 591,269,888 byte disponibili
192 --- E O F --- 2008-02-01 19:35:08
APPENSA SAI COME DEVO ANDARE AVANTI FAMMI SAPERE ANCHE SE PURTROPPO PER LA SCANSIONE ONLINE E' UN PROBLEMA VISTO CHE INTERNET A VOLTE MI SALTA VIA,INTANTO GRAZIE E CIAO!