ciao luke57,oggi accendendo il computer,sono andato nel programma di avenger e stranamente non mi si chiudeva più dopo circa2-3secondi;gli ho incollato lo script ma mi si bloccava ugualmente.Ecco di seguito l'ultimo report di combofix:
ComboFix 09-06-21.01 - User 2010-06-23 13:19.18 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.256.80 [GMT 2:00]
Eseguito da: c:\documents and settings\User\Desktop\123.exe
Opzioni usate :: c:\documents and settings\User\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
- MODALITÀ CON FUNZIONALITÀ RIDOTTE -
FILE ::
"c:\documents and settings\User\Dati applicazioni\drivers\srosa2.sys"
"c:\documents and settings\User\Dati applicazioni\drivers\wfsintwq.sys"
"c:\documents and settings\User\Dati applicazioni\drivers\winupgro.exe"
"c:\windows\system32\drivers\byxnp.sys"
"c:\windows\system32\drivers\bzarjmlc.sys"
"c:\windows\system32\drivers\gaawqe.sys"
"c:\windows\system32\drivers\qnsjr.sys"
"c:\windows\system32\drivers\vrzzzdn.sys"
"c:\windows\system32\mdelk.exe"
"c:\windows\system32\wintems.exe"
"C:\zip.exe"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\User\Dati applicazioni\drivers\srosa2.sys
c:\documents and settings\User\Dati applicazioni\drivers\wfsintwq.sys
c:\documents and settings\User\Dati applicazioni\drivers\winupgro.exe
c:\documents and settings\User\Dati applicazioni\m
c:\documents and settings\User\Dati applicazioni\m\data.oct
c:\documents and settings\User\Dati applicazioni\m\list.oct
c:\documents and settings\User\Dati applicazioni\m\srvlist.oct
c:\documents and settings\User\Impostazioni locali\temp
c:\documents and settings\User\Impostazioni locali\temp\Av-test.txt
c:\documents and settings\User\Impostazioni locali\temp\java_install_reg.log
c:\documents and settings\User\Impostazioni locali\temp\jusched.log
c:\windows\system32\drivers\byxnp.sys
c:\windows\system32\drivers\bzarjmlc.sys
c:\windows\system32\drivers\gaawqe.sys
c:\windows\system32\drivers\qnsjr.sys
c:\windows\system32\drivers\vrzzzdn.sys
c:\windows\temp\Perflib_Perfdata_5b4.dat
c:\windows\temp . . . . Eliminazione Fallita
.
((((((((((((((((((((((((( Files Creati Da 2010-05-23 al 2010-06-23 )))))))))))))))))))))))))))))))))))
.
2010-06-22 16:16 . 2010-06-22 16:16 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1357015.exe
2010-06-22 16:16 . 2010-06-22 16:16 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1356875.exe
2010-06-22 16:16 . 2010-06-22 16:16 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1355359.exe
2010-06-22 16:16 . 2010-06-22 16:16 3601 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1354484.exe
2010-06-22 16:16 . 2010-06-22 16:16 3601 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1354234.exe
2010-06-22 16:16 . 2010-06-22 16:16 3601 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1353218.exe
2010-06-22 16:16 . 2010-06-22 16:16 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1342312.exe
2010-06-22 16:14 . 2010-06-22 16:14 10322 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1257765.exe
2010-06-22 16:14 . 2010-06-22 16:14 10322 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1257484.exe
2010-06-22 16:14 . 2010-06-22 16:14 10322 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1257015.exe
2010-06-22 16:12 . 2010-06-22 16:12 306 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1112093.exe
2010-06-22 16:12 . 2010-06-22 16:12 306 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1112046.exe
2010-06-22 16:12 . 2010-06-22 16:12 306 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1111812.exe
2010-06-22 16:12 . 2010-06-22 16:12 10313 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1105218.exe
2010-06-22 16:12 . 2010-06-22 16:12 10313 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1104984.exe
2010-06-22 16:12 . 2010-06-22 16:12 10313 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1104437.exe
2010-06-22 16:11 . 2010-06-22 16:11 1065988 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1064234.exe
2010-06-22 16:11 . 2010-06-22 16:11 10286 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1049218.exe
2010-06-22 16:11 . 2010-06-22 16:11 10286 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1045625.exe
2010-06-22 16:11 . 2010-06-22 16:11 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1043734.exe
2010-06-22 16:11 . 2010-06-22 16:11 766 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1040312.exe
2010-06-22 16:11 . 2010-06-22 16:11 766 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1039625.exe
2010-06-22 16:11 . 2010-06-22 16:11 766 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1037671.exe
2010-06-22 16:11 . 2010-06-22 16:11 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1030296.exe
2010-06-22 16:11 . 2010-06-22 16:11 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1030234.exe
2010-06-22 16:11 . 2010-06-22 16:11 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1029343.exe
2010-06-22 16:10 . 2010-06-22 16:10 10322 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1022125.exe
2010-06-22 16:10 . 2010-06-22 16:10 10322 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1014562.exe
2010-06-22 16:10 . 2010-06-22 16:10 3252 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\997703.exe
2010-06-22 16:10 . 2010-06-22 16:10 3252 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1006718.exe
2010-06-22 16:10 . 2010-06-22 16:10 3252 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\1006656.exe
2010-06-22 16:10 . 2010-06-22 16:10 10340 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\968125.exe
2010-06-22 16:10 . 2010-06-22 16:10 10340 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\963765.exe
2010-06-22 16:05 . 2010-06-22 16:05 61440 ----a-w- c:\windows\system32\drivers\ktvh.sys
2010-06-22 16:04 . 2010-06-22 16:04 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\654500.exe
2010-06-22 16:03 . 2010-06-22 16:03 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\600078.exe
2010-06-22 16:03 . 2010-06-22 16:03 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\595953.exe
2010-06-22 16:03 . 2010-06-22 16:03 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\589921.exe
2010-06-22 16:02 . 2010-06-22 16:02 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\519984.exe
2010-06-22 16:02 . 2010-06-22 16:02 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\515390.exe
2010-06-22 16:01 . 2010-06-22 16:01 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\464156.exe
2010-06-22 16:01 . 2010-06-22 16:01 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\463093.exe
2010-06-22 16:01 . 2010-06-22 16:01 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\458468.exe
2010-06-22 16:01 . 2010-06-22 16:01 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\456000.exe
2010-06-22 16:01 . 2010-06-22 16:01 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\454953.exe
2010-06-22 16:01 . 2010-06-22 16:01 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\452609.exe
2010-06-22 16:00 . 2010-06-22 16:00 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\355984.exe
2010-06-22 15:58 . 2010-06-22 15:58 67667 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\262781.exe
2010-06-22 15:57 . 2010-06-22 15:57 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\201359.exe
2010-06-22 15:57 . 2010-06-22 15:57 610820 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\191406.exe
2010-06-22 15:51 . 2010-06-22 15:51 610820 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\928953.exe
2010-06-22 15:49 . 2010-06-22 15:49 10340 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\834328.exe
2010-06-22 15:49 . 2010-06-22 15:49 10340 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\833062.exe
2010-06-22 15:49 . 2010-06-22 15:49 10340 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\830375.exe
2010-06-22 15:45 . 2010-06-22 15:45 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\569812.exe
2010-06-22 15:44 . 2010-06-22 15:44 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\551250.exe
2010-06-22 15:44 . 2010-06-22 15:44 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\551062.exe
2010-06-22 15:44 . 2010-06-22 15:44 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\550328.exe
2010-06-22 15:43 . 2010-06-22 15:43 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\477671.exe
2010-06-22 15:43 . 2010-06-22 15:43 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\474421.exe
2010-06-22 15:42 . 2010-06-22 15:42 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\420812.exe
2010-06-22 15:42 . 2010-06-22 15:42 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\420671.exe
2010-06-22 15:42 . 2010-06-22 15:42 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\420156.exe
2010-06-22 15:42 . 2010-06-22 15:42 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\417437.exe
2010-06-22 15:42 . 2010-06-22 15:42 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\416515.exe
2010-06-22 15:42 . 2010-06-22 15:42 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\414328.exe
2010-06-22 15:41 . 2010-06-22 15:41 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\371828.exe
2010-06-22 15:40 . 2010-06-22 15:40 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\288125.exe
2010-06-22 15:38 . 2010-06-22 15:38 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\194218.exe
2010-06-22 15:38 . 2010-06-22 15:38 610820 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\185203.exe
2010-06-22 13:00 . 2010-06-22 13:01 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\301625.exe
2010-06-22 13:00 . 2010-06-22 13:00 610820 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\289500.exe
2010-06-22 12:58 . 2005-07-18 06:05 1047552 ----a-w- c:\windows\system32\mfc71u.dll
2010-06-22 12:58 . 2006-01-31 09:54 31744 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-06-22 12:58 . 2005-07-04 09:58 14848 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-06-22 12:58 . 2010-06-22 12:58 -------- d-----w- c:\programmi\AntiVir PersonalEdition Premium
2010-06-22 12:58 . 2010-06-22 12:58 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AntiVir PersonalEdition Premium
2010-06-22 12:51 . 2010-06-22 12:51 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\356406.exe
2010-06-22 12:51 . 2010-06-22 12:51 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\355937.exe
2010-06-22 12:51 . 2010-06-22 12:51 10349 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\354796.exe
2010-06-22 12:51 . 2010-06-22 12:51 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\351593.exe
2010-06-22 12:51 . 2010-06-22 12:51 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\350703.exe
2010-06-22 12:51 . 2010-06-22 12:51 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\347906.exe
2010-06-22 12:50 . 2010-06-22 12:50 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\265218.exe
2010-06-22 12:49 . 2010-06-22 12:49 67667 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\191234.exe
2010-06-22 12:47 . 2010-06-22 12:47 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\94671.exe
2010-06-22 12:47 . 2010-06-22 12:47 610820 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\83046.exe
2010-06-22 11:48 . 2010-06-22 11:48 145 ----a-w- C:\fix.reg
2010-06-22 10:24 . 2010-06-22 10:24 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\4091859.exe
2010-06-22 10:24 . 2010-06-22 10:24 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\4091781.exe
2010-06-22 10:24 . 2010-06-22 10:24 488 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\4090968.exe
2010-06-22 10:24 . 2010-06-22 10:24 3601 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\4084390.exe
2010-06-22 10:23 . 2010-06-22 10:23 3601 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\4027921.exe
2010-06-22 10:23 . 2010-06-22 10:23 3601 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\4018453.exe
2010-06-22 10:22 . 2010-06-22 10:22 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\4012468.exe
2010-06-22 10:21 . 2010-06-22 10:21 10322 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3925421.exe
2010-06-22 10:21 . 2010-06-22 10:21 10322 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3925265.exe
2010-06-22 10:21 . 2010-06-22 10:21 10322 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3922218.exe
2010-06-22 10:17 . 2010-06-22 10:17 3252 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3724671.exe
2010-06-22 10:17 . 2010-06-22 10:17 3252 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3724484.exe
2010-06-22 10:17 . 2010-06-22 10:17 3252 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3723687.exe
2010-06-22 10:17 . 2010-06-22 10:17 10340 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3716156.exe
2010-06-22 10:17 . 2010-06-22 10:17 10340 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3715781.exe
2010-06-22 10:17 . 2010-06-22 10:17 10340 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3715312.exe
2010-06-22 10:14 . 2010-06-22 10:14 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3539640.exe
2010-06-22 10:14 . 2010-06-22 10:14 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3520531.exe
2010-06-22 10:14 . 2010-06-22 10:14 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3520375.exe
2010-06-22 10:14 . 2010-06-22 10:14 10301 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3517453.exe
2010-06-22 10:14 . 2010-06-22 10:14 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3487281.exe
2010-06-22 10:14 . 2010-06-22 10:14 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\3485781.exe
2010-06-22 09:21 . 2010-06-22 09:21 61699 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\317234.exe
2010-06-22 09:21 . 2010-06-22 09:21 61667 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\315937.exe
2010-06-22 09:21 . 2010-06-22 09:21 61618 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\307546.exe
2010-06-22 09:21 . 2010-06-22 09:21 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\306218.exe
2010-06-22 09:21 . 2010-06-22 09:21 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\305187.exe
2010-06-22 09:20 . 2010-06-22 09:20 24741 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\302062.exe
2010-06-22 09:20 . 2010-06-22 09:20 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\247406.exe
2010-06-22 09:19 . 2010-06-22 09:19 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\243859.exe
2010-06-22 09:19 . 2010-06-22 09:19 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\167796.exe
2010-06-22 09:18 . 2010-06-22 09:18 610820 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\155328.exe
2010-06-22 08:24 . 2010-06-22 08:24 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\203453.exe
2010-06-22 08:23 . 2010-06-22 08:23 71684 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\163640.exe
2010-06-22 08:23 . 2010-06-22 08:23 10247 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\162156.exe
2010-06-22 08:22 . 2010-06-22 08:22 99332 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\97046.exe
2010-06-22 08:22 . 2010-06-22 08:22 610820 ----a-w- c:\documents and settings\User\Dati applicazioni\drivers\downld\83703.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-23 11:21 . 2009-03-29 16:47 -------- d--h--w- c:\documents and settings\User\Dati applicazioni\drivers
2010-06-22 16:07 . 2010-06-22 16:07 1354 ----a-w- c:\programmi\bgcs.txt
2010-06-22 12:58 . 2010-06-22 12:58 126264 ----a-w- c:\documents and settings\All Users\Dati applicazioni\firstlsp.reg.dat
2010-06-22 12:54 . 2009-02-03 15:41 -------- d-----w- c:\programmi\Alwil Software
2010-06-22 12:02 . 2009-02-03 16:16 -------- d-----w- c:\programmi\eMule
2010-06-16 12:00 . 2010-04-23 11:49 3416 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2010-06-16 11:59 . 2010-04-04 12:10 -------- d-----w- c:\programmi\FindyKill
2010-06-01 15:54 . 2009-02-14 11:15 -------- d-----w- c:\documents and settings\User\Dati applicazioni\Canon
2010-05-15 16:33 . 2010-05-15 16:30 -------- d-----w- c:\programmi\cdcover
2010-05-07 10:24 . 2010-05-07 10:24 -------- d-----w- c:\documents and settings\User\Dati applicazioni\dvdcss
2010-05-06 14:16 . 2009-01-31 11:43 -------- d-----w- c:\programmi\File comuni\Adobe
2010-04-23 13:18 . 2010-04-23 13:18 408522 ----a-r- c:\documents and settings\User\Dati applicazioni\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_4ae13d6c.exe
2010-04-23 13:18 . 2010-04-23 13:18 408522 ----a-r- c:\documents and settings\User\Dati applicazioni\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_294823.exe
2010-04-23 13:18 . 2010-04-23 13:18 408522 ----a-r- c:\documents and settings\User\Dati applicazioni\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_18be6784.exe
2010-04-23 12:00 . 2010-04-23 12:00 133 ----a-w- c:\documents and settings\User\Impostazioni locali\Dati applicazioni\fusioncache.dat
2010-04-23 11:59 . 2010-04-23 11:59 5694 ----a-r- c:\documents and settings\User\Dati applicazioni\Microsoft\Installer\{A29B3A9E-250D-44D5-BC04-00B57CBE877A}\_70347633.exe
2010-04-23 11:59 . 2010-04-23 11:59 5694 ----a-r- c:\documents and settings\User\Dati applicazioni\Microsoft\Installer\{A29B3A9E-250D-44D5-BC04-00B57CBE877A}\_611d2f5f.exe
2010-04-23 11:59 . 2010-04-23 11:59 5694 ----a-r- c:\documents and settings\User\Dati applicazioni\Microsoft\Installer\{A29B3A9E-250D-44D5-BC04-00B57CBE877A}\_468a2e62.exe
2010-04-15 12:51 . 2009-02-02 20:29 75688 ----a-w- c:\documents and settings\User\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-04-09 14:03 . 2010-04-09 14:03 2678 ----a-w- c:\windows\java\Packages\Data\D3DBF3RV.DAT
2010-04-09 14:03 . 2010-04-09 14:03 2678 ----a-w- c:\windows\java\Packages\Data\8WU5ZBRV.DAT
2010-04-09 14:03 . 2010-04-09 14:03 2678 ----a-w- c:\windows\java\Packages\Data\OHZ131FV.DAT
2010-04-09 14:03 . 2010-04-09 14:03 2678 ----a-w- c:\windows\java\Packages\Data\O2GDV9N7.DAT
2010-04-09 14:03 . 2010-04-09 14:03 2678 ----a-w- c:\windows\java\Packages\Data\6QIBLBT3.DAT
2010-04-04 12:12 . 2009-03-29 16:22 106 ----a-w- c:\windows\system32\jpg.dat
.
((((((((((((((((((((((((((((( SnapShot@2010-06-15_09.49.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-23 11:21 . 2010-06-23 11:21 16384 c:\windows\temp\Perflib_Perfdata_5b0.dat
+ 2009-01-31 08:40 . 2010-06-17 15:38 89102 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2009-01-31 08:40 . 2009-01-31 08:40 89102 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-01-30 18:53 . 2006-08-21 09:14 23040 c:\windows\system32\fltmc.exe
- 2009-01-30 18:53 . 2004-08-19 13:39 16896 c:\windows\system32\fltlib.dll
+ 2009-01-30 18:53 . 2006-08-21 12:26 16896 c:\windows\system32\fltlib.dll
+ 2009-01-30 18:53 . 2006-08-21 09:14 23040 c:\windows\system32\dllcache\fltmc.exe
+ 2009-01-30 18:53 . 2006-08-21 12:26 16896 c:\windows\system32\dllcache\fltlib.dll
- 2009-01-30 18:53 . 2004-08-19 13:39 16896 c:\windows\system32\dllcache\fltlib.dll
+ 2010-06-22 12:58 . 2006-01-18 11:06 57344 c:\windows\system32\avsda.dll
+ 2009-02-03 02:07 . 2009-02-03 02:07 240544 c:\windows\system32\Macromed\Flash\FlashUtil10b.exe
+ 2010-06-16 11:11 . 2010-06-16 11:09 148888 c:\windows\system32\javaws.exe
+ 2010-06-16 11:11 . 2010-06-16 11:09 144792 c:\windows\system32\javaw.exe
+ 2010-06-16 11:11 . 2010-06-16 11:09 144792 c:\windows\system32\java.exe
+ 2009-01-30 18:53 . 2006-08-21 09:14 128896 c:\windows\system32\drivers\fltmgr.sys
+ 2009-01-30 18:53 . 2006-08-21 09:14 128896 c:\windows\system32\dllcache\fltmgr.sys
+ 2010-06-16 11:11 . 2010-06-16 11:09 410984 c:\windows\system32\deploytk.dll
+ 2010-06-22 12:54 . 2010-06-22 12:54 262144 c:\windows\system32\config\systemprofile\NtUser.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"EPSON Stylus Photo R360 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIBOE.EXE" [2006-05-29 139264]
"AdobeUpdater"="c:\programmi\File comuni\Adobe\Updater5\AdobeUpdater.exe" [2006-01-05 856064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2006-01-05 856064]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2010-06-16 148888]
"avgnt"="c:\programmi\AntiVir PersonalEdition Premium\avgnt.exe" [2010-06-23 229416]
"C-Media Mixer"="Mixer.exe" - c:\windows\mixer.exe [2002-06-12 1495040]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-19 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\User\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Reader Synchronizer.lnk - c:\programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2009-2-2 212992]
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [2010-06-22 14848]
R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [2010-06-22 31744]
S2 AntiVirMailService;AntiVir Mail Security Service;c:\programmi\AntiVir PersonalEdition Premium\avmailc.exe [2010-06-22 167936]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\5.tmp --> c:\windows\system32\5.tmp [?]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2009-01-31 182784]
S4 AVEService;AntiVir Engine Service;c:\programmi\AntiVir PersonalEdition Premium\avesvc.exe [2010-06-22 45056]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: avsda.dll
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-23 13:22
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\5.tmp"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(704)
c:\windows\system32\avsda.dll
- - - - - - - > 'explorer.exe'(2392)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\rundll32.exe
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
.
**************************************************************************
.
Ora fine scansione: 2010-06-23 13:28 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-06-23 11:28
ComboFix2.txt 2010-06-22 16:43
ComboFix3.txt 2010-06-21 17:02
ComboFix4.txt 2010-06-17 14:18
ComboFix5.txt 2010-06-23 11:17
Pre-Run: 49,353,515,008 byte disponibili
Post-Run: 49,469,272,064 byte disponibili
306 --- E O F --- 2010-06-16 12:01