ciao luke57 ecco i risultati:
ComboFix 09-02-08.01 - User 2009-02-09 11:06:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.256.86 [GMT 1:00]
Eseguito da: c:\documents and settings\User\desktop\abc.exe
Opzioni usate :: /killall
AV: avast! antivirus 4.8.1229 [VPS 080723-1] *On-access scanning enabled* (Outdated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\documents and settings\User\Dati applicazioni\inst.exe
C:\m0vnonh.bat
C:\pook.com
C:\uvsqfgwd.cmd
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
c:\windows\system32\olhrwef.exe
.
((((((((((((((((((((((((( Files Creati Da 2009-01-09 al 2009-02-09 )))))))))))))))))))))))))))))))))))
.
2009-02-08 23:11 . 2009-02-08 23:11 <DIR> d-------- C:\SOPHTEMP
2009-02-08 18:43 . 2009-02-08 18:43 <DIR> d-------- c:\programmi\Sophos
2009-02-05 11:01 . 2009-02-05 11:01 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\EPSON
2009-02-05 11:01 . 2006-05-08 03:00 75,264 --a------ c:\windows\system32\E_FLBBOE.DLL
2009-02-05 11:01 . 2006-04-19 03:00 62,976 --a------ c:\windows\system32\E_FD4BBOE.DLL
2009-02-05 11:01 . 2004-09-10 21:12 49,152 --a------ c:\windows\system32\E_DCINST.DLL
2009-02-04 21:15 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-02-04 21:15 . 2004-08-03 23:01 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2009-02-04 16:56 . 2009-02-04 16:56 32 --a------ c:\windows\album.ini
2009-02-04 16:43 . 2009-02-04 16:48 <DIR> d-------- c:\documents and settings\User\Contacts
2009-02-04 16:41 . 2009-02-04 16:41 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-02-04 16:41 . 2009-02-04 16:41 <DIR> d-------- c:\programmi\MSN Messenger
2009-02-03 19:24 . 2004-08-19 15:39 16,384 --a------ c:\windows\system32\ipsink.ax
2009-02-03 19:24 . 2004-08-03 23:10 15,360 --a------ c:\windows\system32\drivers\StreamIP.sys
2009-02-03 19:24 . 2004-08-03 23:10 11,136 --a------ c:\windows\system32\drivers\SLIP.sys
2009-02-03 19:23 . 2004-08-03 23:10 85,376 --a------ c:\windows\system32\drivers\NABTSFEC.sys
2009-02-03 19:23 . 2004-08-03 23:10 85,376 --a--c--- c:\windows\system32\dllcache\nabtsfec.sys
2009-02-03 19:23 . 2004-08-03 23:07 59,264 --a------ c:\windows\system32\drivers\USBAUDIO.sys
2009-02-03 19:23 . 2004-08-03 23:07 59,264 --a--c--- c:\windows\system32\dllcache\usbaudio.sys
2009-02-03 19:23 . 2004-08-03 23:10 19,328 --a------ c:\windows\system32\drivers\WSTCODEC.SYS
2009-02-03 19:23 . 2004-08-03 23:10 19,328 --a--c--- c:\windows\system32\dllcache\wstcodec.sys
2009-02-03 19:23 . 2004-08-03 23:10 17,024 --a------ c:\windows\system32\drivers\CCDECODE.sys
2009-02-03 19:23 . 2004-08-03 23:10 17,024 --a--c--- c:\windows\system32\dllcache\ccdecode.sys
2009-02-03 19:22 . 2009-02-03 19:22 <DIR> d-------- c:\programmi\File comuni\logishrd
2009-02-03 19:21 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys
2009-02-03 19:21 . 2004-08-03 23:08 31,616 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2009-02-03 19:17 . 2009-02-03 19:17 <DIR> d-------- c:\programmi\Camfrog
2009-02-03 19:17 . 2009-02-03 19:17 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\Camfrog
2009-02-03 17:50 . 2009-02-03 17:50 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\vlc
2009-02-03 17:16 . 2009-02-08 23:10 <DIR> d-------- c:\programmi\eMule
2009-02-03 16:54 . 2009-02-03 17:59 <DIR> d-------- c:\windows\system32\CatRoot_bak
2009-02-03 16:41 . 2009-02-03 16:41 <DIR> d-------- c:\programmi\Alwil Software
2009-02-03 16:13 . 2009-02-03 16:13 <DIR> d-------- c:\documents and settings\NetworkService\Menu Avvio
2009-02-03 16:02 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-02-03 15:29 . 2009-02-03 16:52 <DIR> d--h----- c:\windows\$hf_mig$
2009-02-02 22:48 . 2009-02-02 22:48 <DIR> d-------- c:\programmi\ArcSoft
2009-02-02 22:48 . 1998-10-06 18:57 327,168 --a------ c:\windows\IsUn0410.exe
2009-02-02 22:48 . 2001-06-20 09:59 21 --a------ c:\windows\PS_setup.ini
2009-02-02 22:46 . 2009-02-04 16:56 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\ArcSoft
2009-02-02 22:45 . 1999-05-26 09:46 212,480 --a------ c:\windows\pcdlib32.dll
2009-02-02 22:38 . 2009-02-02 22:38 <DIR> d-------- c:\programmi\VideoLAN
2009-02-02 21:40 . 2009-02-02 21:40 <DIR> d-------- c:\windows\Motive
2009-02-02 21:40 . 2009-02-02 21:40 <DIR> d-------- c:\programmi\Pirelli
2009-02-02 21:40 . 2009-02-02 21:40 <DIR> d-------- c:\programmi\Common Files
2009-02-02 21:40 . 2009-02-02 21:40 <DIR> d-------- c:\documents and settings\LocalService\Menu Avvio
2009-02-02 21:40 . 2004-10-05 17:41 52,864 --a------ c:\windows\system32\drivers\CnxTrUsb.sys
2009-02-02 21:40 . 2004-10-05 17:41 25,984 --a------ c:\windows\system32\drivers\CnxTrLan.sys
2009-02-02 21:39 . 2009-02-02 21:40 <DIR> d-------- c:\programmi\Motive
2009-02-02 21:39 . 2009-02-02 21:40 <DIR> d-------- c:\programmi\Alice ti aiuta
2009-02-02 21:38 . 2009-02-02 21:38 <DIR> d-------- c:\programmi\Telecom Italia
2009-02-02 21:38 . 2009-02-02 21:38 <DIR> d-------- c:\programmi\File comuni\InstallShield
2009-02-02 17:12 . 2009-02-02 17:12 <DIR> d-------- c:\programmi\DivX
2009-02-02 17:03 . 2009-02-02 17:03 <DIR> d-------- c:\programmi\Windows Media Connect 2
2009-02-02 17:01 . 2009-02-02 17:01 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-02 17:01 . 2009-02-02 17:02 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-02-02 17:01 . 2006-09-25 17:58 23,856 --a------ c:\windows\system32\spupdsvc.exe
2009-02-02 16:59 . 2009-02-02 16:59 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2009-02-02 16:16 . 2009-02-02 16:16 25 --a------ c:\windows\mixerdef.ini
2009-01-31 13:22 . 2009-02-03 19:14 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-01-31 12:43 . 2009-01-31 12:44 <DIR> d-------- c:\programmi\File comuni\Adobe
2009-01-31 12:40 . 2009-01-31 12:40 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\CyberLink
2009-01-31 12:39 . 2009-02-02 22:45 <DIR> d--h----- c:\programmi\InstallShield Installation Information
2009-01-31 12:31 . 2009-02-06 17:45 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\Ahead
2009-01-31 12:29 . 2009-01-31 12:29 <DIR> d-------- c:\programmi\Nero
2009-01-31 12:29 . 2009-01-31 12:32 <DIR> d-------- c:\programmi\File comuni\Ahead
2009-01-31 11:51 . 2009-01-31 11:52 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\Vso
2009-01-31 11:51 . 2009-01-31 11:51 47,360 --a------ c:\windows\system32\drivers\pcouffin.sys
2009-01-31 11:51 . 2009-01-31 11:52 47,360 --a------ c:\documents and settings\User\Dati applicazioni\pcouffin.sys
2009-01-31 11:23 . 2006-10-26 19:58 30,512 --a------ c:\windows\system32\mdimon.dll
2009-01-31 11:22 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2009-01-31 11:18 . 2009-01-31 11:18 <DIR> d-------- c:\programmi\Microsoft Works
2009-01-31 11:17 . 2009-01-31 11:17 <DIR> d-------- c:\programmi\MSBuild
2009-01-31 11:16 . 2009-01-31 11:16 <DIR> d-------- c:\programmi\Microsoft.NET
2009-01-31 11:06 . 2009-01-31 11:06 <DIR> d-------- c:\programmi\Microsoft Visual Studio 8
2009-01-31 11:06 . 2009-01-31 11:06 <DIR> d-------- C:\IDE
2009-01-31 11:05 . 2009-01-31 11:17 <DIR> d-------- c:\windows\SHELLNEW
2009-01-31 11:04 . 2009-01-31 11:04 <DIR> dr-h----- C:\MSOCache
2009-01-31 10:51 . 2009-01-31 11:23 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-01-31 09:39 . 2009-01-31 09:39 <DIR> d---s---- c:\documents and settings\User\UserData
2009-01-31 09:36 . 2007-10-15 15:57 182,784 --a------ c:\windows\system32\drivers\wg111v2.sys
2009-01-31 09:34 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-02 20:39 155,995 ----a-w c:\windows\java\Packages\7ZFHRFTJ.ZIP
2009-01-30 18:57 --------- d-----w c:\programmi\microsoft frontpage
2009-01-30 18:54 --------- d-----w c:\programmi\Servizi in linea
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 139264]
"EPSON Stylus Photo R360 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIBOE.EXE" [2006-05-29 139264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"C-Media Mixer"="Mixer.exe" [2002-06-12 c:\windows\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\User\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Reader Synchronizer.lnk - c:\programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2009-02-02 212992]
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-03 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-03 20560]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\5.tmp --> c:\windows\system32\5.tmp [?]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2009-01-31 182784]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{37409c04-f171-11dd-a288-000827dd3010}]
\Shell\AutoRun\command - G:\1utbfd.bat
\Shell\open\Command - G:\1utbfd.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ab02d12-f2f8-11dd-a296-000827dd3010}]
\Shell\AutoRun\command - G:\pook.com
\Shell\open\Command - G:\pook.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f453f50e-ef71-11dd-a283-9f856fefd662}]
\Shell\AutoRun\command - F:\uvsqfgwd.cmd
\Shell\open\Command - F:\uvsqfgwd.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f453f50f-ef71-11dd-a283-9f856fefd662}]
\Shell\AutoRun\command - G:\uvsqfgwd.cmd
\Shell\open\Command - G:\uvsqfgwd.cmd
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Connection Wizard,ShellNext =
hxxp://www.google.it/uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-09 11:11:26
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\5.tmp"
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Alwil Software\Avast4\aswUpdSv.exe
c:\programmi\Alwil Software\Avast4\ashServ.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exe
c:\programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
c:\programmi\Alwil Software\Avast4\ashMaiSv.exe
c:\programmi\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
.
**************************************************************************
.
Ora fine scansione: 2009-02-09 11:14:49 - Il pc è stato riavviato [User]
ComboFix-quarantined-files.txt 2009-02-09 10:14:44
Pre-Run: 48,136,577,024 byte disponibili
Post-Run: 49,005,490,176 byte disponibili
197 --- E O F --- 2009-02-03 17:16:25