ti posto qui il log di combofix....eccolo :
Eseguito da: g:\combofix\ComboFix.exe
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Admin\WINDOWS
c:\documents and settings\F spakkiuso\Desktop\Videos.url
c:\documents and settings\F spakkiuso\Impostazioni locali\Dati applicazioni\kqiwy.dat
c:\documents and settings\F spakkiuso\Impostazioni locali\Dati applicazioni\kqiwy_nav.dat
c:\documents and settings\F spakkiuso\Impostazioni locali\Dati applicazioni\kqiwy_navps.dat
c:\documents and settings\F spakkiuso\Menu Avvio\Programmi\Videos.url
c:\documents and settings\F spakkiuso\Preferiti\Videos.url
c:\documents and settings\F spakkiuso\WINDOWS
c:\programmi\Setup.exe
.
.
((((((((((((((((((((((((( Files Creati Da 2011-05-19 al 2011-06-19 )))))))))))))))))))))))))))))))))))
.
.
2011-06-17 08:02 . 2011-06-17 08:02 -------- d-----w- c:\documents and settings\Administrator
2011-06-09 11:12 . 2011-06-09 11:12 -------- d-----w- C:\tagliavast
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2001-05-04 18:05 . 2006-05-04 19:47 431376 ----a-w- c:\programmi\RICHED20.DLL
2001-05-04 18:05 . 2006-05-04 19:47 290869 ----a-w- c:\programmi\MSVCRT.DLL
2000-06-08 23:00 . 2006-05-04 19:47 995383 ----a-w- c:\programmi\Mfc42.dll
1999-12-07 18:00 . 2006-05-04 19:47 3856 ----a-w- c:\programmi\RICHED32.DLL
1999-12-07 18:00 . 2006-05-04 19:47 253952 ----a-w- c:\programmi\MSVCRT20.DLL
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-24 68856]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"BitTorrent DNA"="c:\programmi\DNA\btdna.exe" [2009-11-18 323392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-10-06 5058560]
"nwiz"="nwiz.exe" [2003-10-06 741376]
"Smapp"="c:\programmi\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\programmi\Ahead\InCD\InCD.exe" [2003-09-05 1200178]
"ccApp"="c:\programmi\File comuni\Symantec Shared\ccApp.exe" [2007-01-09 58984]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2007-07-03 100056]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"SpywareTerminator"="c:\programmi\Spyware Terminator\SpywareTerminatorShield.exe" [2007-09-21 2778112]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BlueSoleil.lnk - c:\programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe [2005-9-20 1200128]
ZDWLan Utility.lnk - c:\programmi\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2009-1-27 487424]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Programmi\\eMule\\eMule.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\DNA\\btdna.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\FrostWire\\FrostWire.exe"=
.
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [28/04/2004 15.35.52 9344]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [03/07/2007 18.00.00 138624]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [07/02/2010 22.58.10 135664]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-06-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-07 20:58]
.
2011-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-07 20:58]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://it.yahoo.comuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://it.rd.yahoo.com/customize/ie/def ... .yahoo.comIE: Crawler Search - tbr:iemenu
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\programmi\Crawler\Toolbar\ctbr.dll
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKCU-Run-DriverMax - (no file)
HKCU-Run-DriverMax_RESTART - (no file)
HKLM-Run-YeppStudioAgent - c:\programmi\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
AddRemove-kqiwy - c:\documents and settings\f spakkiuso\impostazioni locali\dati applicazioni\kqiwy.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9c.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-06-19 11:06
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(216)
c:\windows\System32\l3codeca.acm
c:\windows\system32\sirenacm.dll
c:\windows\system32\lameACM.acm
c:\windows\system32\ac3acm.acm
.
Ora fine scansione: 2011-06-19 11:08:40
ComboFix-quarantined-files.txt 2011-06-19 09:08
.
Pre-Run: 81.635.180.544 byte disponibili
Post-Run: 83.179.307.008 byte disponibili
.
- - End Of File - - 323FCB172D30E20F8A10BE9BC69B0A06