Ciao!! Tutto sembra essere risolto!! Grazie mille!:DDD posto qui sotto i log.
p.s: ma che era successo? o_O
ComboFix 10-02-01.03 - Alessia 02/02/2010 13.39.36.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.1023.684 [GMT 1:00]
Eseguito da: c:\documents and settings\Alessia\desktop\abc.exe
Opzioni usate :: /killall
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\9fo3ar0j.exe
D:\y.exe
.
((((((((((((((((((((((((( Files Creati Da 2010-01-02 al 2010-02-02 )))))))))))))))))))))))))))))))))))
.
2047-12-31 23:00 . 2010-01-31 21:27 -------- d-----w- C:\! Lost & Found !
2010-02-01 22:58 . 2010-02-01 22:57 90624 --sh--r- C:\9d6tpg.exe
2010-02-01 11:17 . 2010-02-01 11:18 -------- d-----w- c:\programmi\FLAC
2010-01-30 10:25 . 2010-01-30 10:25 97280 --sh--r- C:\mvmdh.exe
2010-01-27 19:50 . 2010-02-02 10:42 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-01-27 19:50 . 2010-01-27 19:50 -------- d-----w- c:\programmi\Active Data Recovery Software
2010-01-27 19:10 . 2010-01-27 19:10 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\Apple Computer
2010-01-26 20:16 . 2010-01-26 20:15 100864 --sh--r- C:\df.exe
2010-01-26 11:14 . 2010-01-26 11:16 -------- d-----w- c:\windows\ShellNew
2010-01-24 17:45 . 2010-01-24 18:06 126464 ----a-w- c:\documents and settings\Alessia\Impostazioni locali\Dati applicazioni\ss.exe
2010-01-24 17:22 . 2004-08-19 13:00 93184 ----a-w- c:\documents and settings\Alessia\Impostazioni locali\Dati applicazioni\server.exe
2010-01-21 13:07 . 2010-01-21 13:08 -------- d-----w- c:\programmi\VirtualDJ
2010-01-21 12:53 . 2010-01-21 12:53 57344 ----a-r- c:\documents and settings\Alessia\Dati applicazioni\Microsoft\Installer\{8FE3E922-C58B-4E18-A923-FC85530C23C5}\NewShortcut7_B56E5B51EA954C948003CC703E2AFAD5.exe
2010-01-21 12:53 . 2010-01-21 12:53 57344 ----a-r- c:\documents and settings\Alessia\Dati applicazioni\Microsoft\Installer\{8FE3E922-C58B-4E18-A923-FC85530C23C5}\NewShortcut1_B56E5B51EA954C948003CC703E2AFAD5.exe
2010-01-21 12:52 . 2010-01-21 12:52 -------- d-----w- c:\programmi\Serato
2010-01-18 23:21 . 2010-01-18 23:21 454838 ----a-r- c:\documents and settings\Alessia\Dati applicazioni\Microsoft\Installer\{51E4FE53-D6B0-43A0-B98C-7DE233D53EAB}\_7DA8B262C7C0B2B5E2561D.exe
2010-01-18 23:21 . 2010-01-18 23:21 454838 ----a-r- c:\documents and settings\Alessia\Dati applicazioni\Microsoft\Installer\{51E4FE53-D6B0-43A0-B98C-7DE233D53EAB}\_7D2C132C50CCB86BED182C.exe
2010-01-18 23:21 . 2010-01-18 23:21 -------- d-----w- c:\programmi\AutomationLabs
2010-01-18 01:05 . 2006-06-29 12:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-01-18 01:03 . 2010-01-18 01:03 -------- d-----w- c:\windows\system32\it-IT
2010-01-18 01:00 . 2010-01-18 01:00 63904 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-01-18 01:00 . 2010-01-18 01:00 -------- d-----w- c:\windows\system32\XPSViewer
2010-01-18 01:00 . 2010-01-18 01:00 -------- d-----w- c:\programmi\MSBuild
2010-01-18 00:59 . 2010-01-18 00:59 -------- d-----w- c:\programmi\Reference Assemblies
2010-01-18 00:59 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-18 00:58 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-18 00:58 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-01-18 00:58 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-18 00:58 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-01-18 00:58 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-18 00:58 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-01-18 00:58 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-01-18 00:58 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-18 00:44 . 2010-01-18 00:44 -------- d-----w- c:\programmi\MSXML 6.0
2010-01-11 23:04 . 2010-01-11 23:04 -------- d-----w- c:\windows\system32\LogFiles
2010-01-06 16:30 . 2010-01-08 13:47 -------- d-----w- c:\programmi\DAEMON Tools Toolbar
2010-01-06 16:29 . 2010-01-06 16:29 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-01-06 16:29 . 2010-01-06 16:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DAEMON Tools Lite
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-27 18:57 . 2009-12-09 20:19 18496 ----a-w- c:\documents and settings\Alessia\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-01-24 17:43 . 2010-01-18 23:26 341 ----a-w- c:\documents and settings\Alessia\Dati applicazioni\settings.dat
2010-01-18 01:01 . 2004-09-16 14:31 79712 ----a-w- c:\windows\system32\perfc010.dat
2010-01-18 01:01 . 2004-09-16 14:31 479418 ----a-w- c:\windows\system32\perfh010.dat
2010-01-11 12:38 . 2009-12-09 21:47 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-01-01 17:15 . 2009-12-09 19:41 -------- d-----w- c:\programmi\Intel
2009-12-31 17:24 . 2009-12-31 17:24 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\SharePod
2009-12-31 01:35 . 2009-12-31 01:35 -------- d-----w- c:\programmi\Free Audio Pack
2009-12-31 01:35 . 2009-12-31 01:35 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\FreeAudioPack
2009-12-30 15:59 . 2009-12-30 15:59 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\Toshiba
2009-12-30 15:54 . 2009-12-30 15:54 -------- d-----w- c:\programmi\Toshiba
2009-12-29 22:29 . 2009-12-29 22:29 -------- d-----w- c:\programmi\Panda Security
2009-12-29 20:13 . 2009-12-29 11:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-12-29 11:53 . 2009-12-29 11:51 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-12-27 17:51 . 2009-12-27 17:44 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\PhotoFiltre
2009-12-27 17:44 . 2009-12-27 17:44 -------- d-----w- c:\programmi\PhotoFiltre
2009-12-26 14:09 . 2009-12-26 14:06 175080 ------w- c:\windows\hpoins29.dat
2009-12-26 14:09 . 2009-12-26 14:09 -------- d-----w- c:\programmi\File comuni\HP
2009-12-26 14:09 . 2009-12-26 14:09 -------- d-----w- c:\programmi\Hewlett-Packard
2009-12-26 14:09 . 2009-12-26 14:09 -------- d-----w- c:\programmi\File comuni\Hewlett-Packard
2009-12-26 14:08 . 2009-12-26 14:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Hewlett-Packard
2009-12-26 14:07 . 2009-12-26 14:07 -------- d-----w- c:\programmi\HP
2009-12-24 00:31 . 2009-12-24 00:31 -------- d-----w- c:\programmi\Google
2009-12-10 10:47 . 2009-12-10 10:47 -------- d-----w- c:\programmi\QuickTime
2009-12-10 10:47 . 2009-12-10 10:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2009-12-10 10:46 . 2009-12-10 10:46 -------- d-----w- c:\programmi\File comuni\Apple
2009-12-10 10:46 . 2009-12-10 10:46 -------- d-----w- c:\programmi\Apple Software Update
2009-12-10 10:46 . 2009-12-10 10:46 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple
2009-12-09 23:11 . 2009-12-09 23:11 -------- d-----w- c:\programmi\MSN BackUp
2009-12-09 22:55 . 2009-12-09 22:55 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\vlc
2009-12-09 22:55 . 2009-12-09 22:55 -------- d-----w- c:\programmi\VideoLAN
2009-12-09 22:52 . 2009-12-09 22:52 69632 ----a-r- c:\documents and settings\Alessia\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\NewShortcut2_B358DA4D0918436EA0E64813B1E5965A.exe
2009-12-09 22:52 . 2009-12-09 22:52 69632 ----a-r- c:\documents and settings\Alessia\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\NewShortcut1_B358DA4D0918436EA0E64813B1E5965A.exe
2009-12-09 22:52 . 2009-12-09 22:52 10134 ----a-r- c:\documents and settings\Alessia\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\ARPPRODUCTICON.exe
2009-12-09 22:30 . 2009-12-09 22:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2009-12-09 22:29 . 2009-12-09 22:29 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\ACD Systems
2009-12-09 22:27 . 2009-12-09 22:27 -------- d-----w- c:\programmi\Yahoo!
2009-12-09 22:24 . 2009-12-09 22:24 -------- d-----w- c:\programmi\File comuni\ACD Systems
2009-12-09 22:24 . 2009-12-09 22:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ACD Systems
2009-12-09 22:24 . 2009-12-09 22:24 -------- d-----w- c:\programmi\ACD Systems
2009-12-09 22:23 . 2009-12-09 22:23 10368 ----a-w- c:\windows\system32\drivers\pfc.sys
2009-12-09 22:15 . 2009-12-09 22:10 -------- d-----w- c:\programmi\File comuni\Ahead
2009-12-09 22:14 . 2009-12-09 22:14 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\Ahead
2009-12-09 22:10 . 2009-12-09 22:10 -------- d-----w- c:\programmi\Nero
2009-12-09 22:05 . 2009-12-09 22:05 -------- d-----w- c:\programmi\AC3Filter
2009-12-09 22:04 . 2009-12-09 22:04 -------- d-----w- c:\programmi\Xvid
2009-12-09 21:53 . 2009-12-09 21:53 -------- d-----w- c:\programmi\File comuni\Adobe
2009-12-09 21:46 . 2009-12-09 21:46 -------- d-----w- c:\programmi\Microsoft
2009-12-09 21:46 . 2009-12-09 21:45 -------- d-----w- c:\programmi\Windows Live
2009-12-09 21:46 . 2009-12-09 21:46 -------- d-----w- c:\programmi\Windows Live SkyDrive
2009-12-09 21:40 . 2009-12-09 21:40 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-12-09 20:48 . 2009-12-09 20:48 -------- d-----w- c:\programmi\eMule
2009-12-09 20:37 . 2009-12-09 20:37 0 ----a-w- c:\windows\nsreg.dat
2009-12-09 20:26 . 2009-12-09 19:43 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Symantec
2009-12-09 20:25 . 2009-12-09 19:36 -------- d-----w- c:\programmi\ASUS
2009-12-09 20:04 . 2009-12-09 20:04 -------- d-----w- c:\programmi\CONEXANT
2009-12-09 20:00 . 2009-12-09 20:00 -------- d-----w- c:\programmi\ATI Technologies
2009-12-09 20:00 . 2009-12-09 19:34 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-12-09 19:44 . 2009-12-09 20:09 -------- d-----w- c:\documents and settings\Alessia\Dati applicazioni\Symantec
2009-12-09 19:39 . 2009-12-09 19:39 -------- d-----w- c:\programmi\Synaptics
2009-12-09 19:34 . 2009-12-09 19:34 -------- d-----w- c:\programmi\Realtek
2009-12-09 19:34 . 2009-12-09 19:34 -------- d-----w- c:\programmi\File comuni\InstallShield
2009-12-09 19:32 . 2009-12-09 19:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SBSI
2009-12-09 19:32 . 2009-12-09 19:26 76875 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-09 19:27 . 2009-12-09 19:27 -------- d-----w- c:\programmi\microsoft frontpage
2009-12-09 19:25 . 2009-12-09 19:25 -------- d-----w- c:\programmi\Servizi in linea
2009-12-09 19:24 . 2009-12-09 19:24 21840 ----a-w- c:\windows\system32\emptyregdb.dat
2009-03-21 14:18 . 2004-09-16 14:31 162569 --sha-r- c:\windows\system32\lcebzg.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Alessia\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-12-09 133104]
"googletalk"="c:\programmi\Google\Google Talk\googletalk.exe" [2007-11-21 3293184]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2005-05-11 102400]
"RTHDCPL"="RTHDCPL.EXE" [2005-05-24 14477312]
"Power_Gear"="c:\programmi\ASUS\Power4 Gear\BatteryLife.exe" [2004-09-21 81920]
"Wireless Console"="c:\programmi\ASUS\Wireless Console\wcourier.exe" [2005-03-02 57344]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-12-21 98394]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-12-21 688218]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 339968]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-11-10 417792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 45056]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Messenger\\Msmsgs.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN BackUp\\MSNBackup.exe"=
"c:\\Programmi\\Google\\Google Talk\\googletalk.exe"=
"svchost.exe"= c:\windows\\svchost.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2736:TCP"= 2736:TCP:ffncq
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [29/12/2009 23.31.19 28552]
R0 R592;R592;c:\windows\system32\drivers\R592.sys [09/12/2009 20.04.01 57088]
R0 risdpntk;risdpntk;c:\windows\system32\drivers\risdpntk.sys [09/12/2009 20.04.01 27264]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [06/01/2010 17.29.31 691696]
S2 cfxgsqp;Update Network;c:\windows\system32\svchost.exe -k netsvcs [16/09/2004 15.31.20 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
cfxgsqp
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-180221306-2647937500-2557348874-1005Core.job
- c:\documents and settings\Alessia\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-12-09 20:38]
2010-02-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-180221306-2647937500-2557348874-1005UA.job
- c:\documents and settings\Alessia\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-12-09 20:38]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
TCP: {F3BD2A21-8407-48C9-9E30-5549CEBE21F9} = 62.149.128.4,62.149.132.4
FF - ProfilePath - c:\documents and settings\Alessia\Dati applicazioni\Mozilla\Firefox\Profiles\y06ax6ns.default\
FF - prefs.js: browser.startup.homepage -
FF - plugin: c:\documents and settings\Alessia\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-02 13:44
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86F6D1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75c0fc3
\Driver\ACPI -> ACPI.sys @ 0xf7328cb8
\Driver\atapi -> 0x86f6d1f8
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x8057807e
ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x8057807e
ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\cfxgsqp]
"ServiceDll"="c:\windows\system32\lcebzg.dll"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1024)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3120)
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\RTHDCPL.EXE
c:\windows\ATK0100\ATKOSD.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
.
**************************************************************************
.
Ora fine scansione: 2010-02-02 13:47:28 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-02-02 12:47
ComboFix2.txt 2010-02-02 12:12
Pre-Run: 32.706.200.064 byte disponibili
Post-Run: 32.671.122.432 byte disponibili
- - End Of File - - 0B6CFC3D68CE6070217F06CE98932902
------------------------------------------------------------------------------------
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK