Non chiedermi come mao ora combofix pare vada.
Questo è il report:
ComboFix 11-11-06.01 - Bat-Nano 06/11/2011 15:34:11.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.39.1040.18.3583.2634 [GMT 1:00]
Eseguito da: c:\users\Bat-Nano\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\LP
c:\program files\LP\3C6B\AD8D.tmp
c:\program files\LP\3D7B\4471.tmp
c:\program files\LP\3D7B\7F31.tmp
c:\program files\LP\3D7B\95E8.tmp
c:\program files\LP\3D7B\F0E4.tmp
c:\program files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
c:\program files\OfferBox
c:\program files\OfferBox\OfferBoxBHO.dll
c:\program files\Setup.exe
c:\users\Bat-Nano\AppData\Roaming\Mozilla\Firefox\Profiles\r9bkqwkr.default\searchplugins\SearchquWebSearch.xml
c:\users\Bat-Nano\AppData\Roaming\OfferBox
c:\users\Bat-Nano\AppData\Roaming\OfferBox\config.dat
c:\users\Bat-Nano\AppData\Roaming\OfferBox\config.xml
.
.
((((((((((((((((((((((((( Files Creati Da 2011-10-06 al 2011-11-06 )))))))))))))))))))))))))))))))))))
.
.
2011-11-06 14:40 . 2011-11-06 14:40 -------- d-----w- c:\users\Bat-Nano\AppData\Local\temp
2011-11-06 14:40 . 2011-11-06 14:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-06 11:10 . 2009-10-22 12:54 37392 ----a-w- c:\windows\system32\drivers\44299462.sys
2011-11-06 11:10 . 2009-10-09 22:31 311312 ----a-w- c:\windows\system32\drivers\4429946.sys
2011-11-06 11:10 . 2009-09-25 16:59 128016 ----a-w- c:\windows\system32\drivers\44299461.sys
2011-11-06 11:10 . 2011-11-06 11:47 -------- d-----w- c:\program files\Virus Removal Tool
2011-11-06 11:04 . 2011-11-06 11:47 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-06 11:04 . 2011-11-06 11:04 -------- d-----w- c:\program files\Hitman Pro 3.5
2011-11-06 11:03 . 2011-11-06 11:45 -------- d-----w- c:\programdata\Hitman Pro
2011-11-05 17:01 . 2011-11-05 17:22 2828 --sha-w- c:\programdata\KGyGaAvL.sys
2011-11-05 17:01 . 2011-11-05 17:17 88 --sh--r- c:\programdata\6153A5A654.sys
2011-11-05 17:01 . 2011-11-05 17:08 -------- d-----w- c:\users\Bat-Nano\AppData\Roaming\Corel
2011-11-05 17:01 . 2011-11-05 17:01 -------- d-----w- c:\users\Bat-Nano\Corel
2011-11-05 17:00 . 2011-11-05 17:22 -------- d-----w- c:\users\Bat-Nano\AppData\Roaming\Ulead Systems
2011-11-05 16:59 . 2011-11-05 16:59 -------- d-----w- C:\IExp1.tmp
2011-11-05 16:59 . 2011-11-05 16:59 -------- d--h--w- c:\windows\msdownld.tmp
2011-11-05 16:59 . 2011-11-05 16:59 -------- d-----w- C:\IExp0.tmp
2011-11-05 16:52 . 2007-10-22 02:39 267272 ----a-w- c:\windows\system32\xactengine2_10.dll
2011-11-05 16:51 . 2005-05-26 14:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2011-11-05 16:48 . 2002-07-25 15:07 614532 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe
2011-11-05 16:48 . 2011-11-05 16:48 -------- d-----w- c:\program files\Lang
2011-11-05 16:47 . 2011-11-05 16:48 -------- d-----w- c:\program files\CDS
2011-11-05 16:47 . 2009-08-24 22:54 1878528 ----a-w- c:\program files\ICA.msi
2011-11-05 16:47 . 2009-08-24 22:53 57488 ----a-w- c:\program files\VGPCUNLR.dll
2011-11-05 16:47 . 2009-08-24 22:53 274576 ----a-w- c:\program files\SetupXML.dll
2011-11-05 16:47 . 2009-08-24 22:53 217232 ----a-w- c:\program files\tBar7.dll
2011-11-05 16:47 . 2009-08-24 22:53 258192 ----a-w- c:\program files\SetupIntegration2.dll
2011-11-05 16:47 . 2009-08-24 22:53 663696 ----a-w- c:\program files\SetupARP.exe
2011-11-05 16:47 . 2009-08-24 22:53 237712 ----a-w- c:\program files\SetupIntegration.dll
2011-11-05 16:47 . 2009-08-24 22:53 340112 ----a-w- c:\program files\Script.dll
2011-11-05 16:47 . 2009-08-24 22:53 311440 ----a-w- c:\program files\SerChck.DLL
2011-11-05 16:47 . 2009-08-24 22:53 1704592 ----a-w- c:\program files\gdiplus.dll
2011-11-04 22:43 . 2011-11-06 09:40 691696 ----a-w- c:\windows\system32\drivers\SPTD.SYS.TMP
2011-11-04 14:15 . 2011-11-04 14:15 -------- d-----w- c:\users\Bat-Nano\AppData\Roaming\SUPERAntiSpyware.com
2011-11-04 14:15 . 2011-11-04 14:15 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-11-03 13:54 . 2011-11-03 13:54 -------- dc-h--w- c:\programdata\{3405BE5C-E16E-4B95-8CDA-9BFB98545DF8}
2011-11-03 13:54 . 2011-11-06 11:47 -------- d-----w- C:\VEXPLite
2011-11-01 11:07 . 2011-11-01 11:53 22305 ----a-w- c:\windows\system32\drivers\sfi.dat
2011-11-01 10:37 . 2011-11-01 10:37 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-11-01 10:37 . 2011-11-01 11:06 -------- d-----w- c:\programdata\Comodo Downloader
2011-10-31 15:06 . 2011-11-01 11:50 -------- d-----w- c:\program files\89DF4
2011-10-31 14:28 . 2011-10-31 14:28 -------- d-----w- c:\users\Bat-Nano\AppData\Roaming\Malwarebytes
2011-10-31 14:28 . 2011-10-31 14:28 -------- d-----w- c:\programdata\Malwarebytes
2011-10-31 12:21 . 2011-10-31 15:14 -------- d-----w- c:\users\Bat-Nano\AppData\Roaming\B7489
2011-10-17 08:14 . 2011-10-17 08:14 -------- d-----w- c:\users\Bat-Nano\AppData\Roaming\Nokia Ovi Suite
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-04 15:53 . 2011-09-13 09:39 82168 ----a-w- c:\windows\system32\drivers\VIRAGTLT.sys
2011-10-26 07:41 . 2011-06-13 11:50 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-13 20:58 . 2009-08-18 09:30 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2011-10-13 20:57 . 2009-03-30 15:20 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-12 02:44 . 2011-09-13 08:07 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D792E37E-0772-44E9-89CF-002F1231B381}\mpengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TClockEx"="c:\program files\TClockEx\TCLOCKEX.EXE" [2000-03-09 89088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-05-23 7514656]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"VIRIT LITE MONITOR"="c:\vexplite\MONLITE.EXE" [2011-11-04 299008]
"CorelGadget"="c:\program files\Common Files\Ulead Systems\Gadget\GadgetEB.dll" [2009-08-24 154256]
"Standby"="c:\program files\Common Files\Corel\Standby\Standby.exe" [2009-08-24 105616]
.
c:\users\Bat-Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
setup_9.0.0.722_06.11.2011_12-48.lnk - c:\program files\Virus Removal Tool\setup_9.0.0.722_06.11.2011_12-48\startup.exe [2011-11-6 72208]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Pitaschio.exe - collegamento.lnk - c:\program files\Pitaschio (programma tray icon)\Pitaschio.exe [2010-6-20 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
"HideSCAHealth"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Servizio Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 136176]
R3 gupdatem;Servizio Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 136176]
R3 netr73;Driver scheda LAN wireless USB RT73 per Vista;c:\windows\system32\DRIVERS\netr73.sys [2009-07-13 545792]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2011-05-18 137600]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2011-05-18 8576]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-18 1343400]
S0 44299462;44299462 Boot Guard Driver;c:\windows\system32\DRIVERS\44299462.sys [2009-10-22 37392]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-05 691696]
S0 VIRAGTLT;VIRAGTLT;c:\windows\system32\drivers\VIRAGTLT.SYS [2011-11-04 82168]
S1 44299461;44299461;c:\windows\system32\DRIVERS\44299461.sys [2009-09-25 128016]
S1 SASDIFSV;SASDIFSV;c:\users\Bat-Nano\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\users\Bat-Nano\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.SYS [x]
S1 setup_9.0.0.722_06.11.2011_12-48drv;setup_9.0.0.722_06.11.2011_12-48drv;c:\windows\system32\DRIVERS\4429946.sys [2009-10-09 311312]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-24 167936]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 18:09]
.
2011-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 18:09]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Bat-Nano\AppData\Roaming\Mozilla\Firefox\Profiles\r9bkqwkr.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
.
------- Associazioni dei file -------
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKCU-Run-UpdateMyDrivers - c:\program files\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe
AddRemove-Fotolibro Pixum - c:\users\Bat-Nano\Desktop\Fotolibro Pixum\uninstall.exe
AddRemove-Windows Media Player 12 with Toolbar 12.00 - c:\program files\Windows Media Player\Uninstall.exe
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2011-11-06 15:42:05
ComboFix-quarantined-files.txt 2011-11-06 14:42
.
Pre-Run: 150.743.977.984 byte disponibili
Post-Run: 150.771.429.376 byte disponibili
.
- - End Of File - - 806A42307A5AE527DCD195B96A7D8349