vediamo un po avendo spammato un po in giro me fa incolla il log
ComboFix 11-12-27.01 - Andropov 27/12/2011 16:36:14.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.3839.1978 [GMT 1:00]
Eseguito da: C:\Users\Andropov\Downloads\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: COMODO Antivirus *Enabled/Updated* {7554F4C5-5EC0-2FC6-8192-8DF831DBED51}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
FW: ZoneAlarm Free Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
SP: AntiVir Desktop *Enabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
---- Esecuzione precedente -------
C:\Users\Andropov\Desktop\Internet Explorer.lnk
C:\Windows\security\Database\tmp.edb
C:\Windows\system32\java.exe
((((((((((((((((((((((((( Files Creati Da 2011-11-27 al 2011-12-27 )))))))))))))))))))))))))))))))))))
2011-12-27 15:53:42 . 2011-12-27 15:53:42 -------- d-----w- C:\Users\Default\AppData\Local\temp
2011-12-27 15:53:41 . 2011-12-27 15:53:41 -------- d-----w- C:\Users\Gagarin\AppData\Local\temp
2011-12-27 14:49:13 . 2011-12-27 14:49:15 -------- d-----w- C:\ProgramData\CPA_VA
2011-12-27 14:47:51 . 2011-12-27 14:47:51 -------- d-----w- C:\VritualRoot
2011-12-27 12:33:57 . 2011-12-27 12:35:16 -------- d-----w- C:\ProgramData\Comodo
2011-12-27 12:33:51 . 2011-12-27 12:34:06 -------- d-----w- C:\Program Files\COMODO
2011-12-27 12:33:47 . 2011-12-27 12:33:47 -------- d-----w- C:\Program Files (x86)\Comodo
2011-12-27 12:32:50 . 2011-12-27 12:32:50 1060864 ----a-w- C:\Windows\SysWow64\mfc71.dll
2011-12-27 12:32:32 . 2011-12-27 12:32:32 -------- d-sh--w- C:\Windows\system32\%APPDATA%
2011-12-27 12:20:17 . 2011-11-21 11:40:38 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{494B5A54-56AE-4BCA-8278-3F3910237326}\mpengine.dll
2011-12-26 14:19:05 . 2011-12-26 14:37:19 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-12-26 14:19:05 . 2011-12-26 14:21:09 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-12-26 13:49:47 . 2011-12-26 13:49:47 388096 ----a-r- C:\Users\Andropov\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-26 13:49:47 . 2011-12-26 13:49:47 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-12-19 17:59:20 . 2011-12-19 17:59:20 93200 ----a-w- C:\Windows\system32\drivers\inspect.sys
2011-12-19 17:59:18 . 2011-12-19 17:59:18 577824 ----a-w- C:\Windows\system32\drivers\cmdGuard.sys
2011-12-19 17:59:18 . 2011-12-19 17:59:18 43248 ----a-w- C:\Windows\system32\drivers\cmdhlp.sys
2011-12-19 17:59:16 . 2011-12-19 17:59:16 22696 ----a-w- C:\Windows\system32\drivers\cmderd.sys
2011-12-19 17:58:58 . 2011-12-19 17:58:58 41200 ----a-w- C:\Windows\system32\cmdcsr.dll
2011-12-19 17:58:56 . 2011-12-19 17:58:56 389840 ----a-w- C:\Windows\system32\guard64.dll
2011-12-19 17:58:56 . 2011-12-19 17:58:56 301224 ----a-w- C:\Windows\SysWow64\guard32.dll
2011-12-15 18:57:24 . 2011-12-15 18:57:24 375632 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-12-15 11:24:41 . 2011-10-15 06:31:56 723456 ----a-w- C:\Windows\system32\EncDec.dll
2011-12-15 11:24:40 . 2011-10-15 05:38:59 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-15 11:24:33 . 2011-11-05 05:32:50 2048 ----a-w- C:\Windows\system32\tzres.dll
2011-12-15 11:24:33 . 2011-11-05 04:26:03 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-12-14 19:43:10 . 2011-12-14 19:43:10 -------- d-----w- C:\Program Files (x86)\Common Files\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
2011-11-19 19:32:32 . 2011-11-19 19:32:32 48648 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2011-11-14 11:25:41 . 2011-07-03 08:29:02 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-03 04:06:03 . 2011-06-06 10:09:19 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-09-29 16:29:28 . 2011-11-09 19:48:26 1923952 ----a-w- C:\Windows\system32\drivers\tcpip.sys
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "C:\Program Files (x86)\Vuze_Remote\tbVuze.dll" [2010-04-15 10:33:48 2515552]
"{59506042-42a8-4ef6-82c9-35177bfb7f6f}"= "C:\Program Files (x86)\ZoneAlarm_IT\prxtbZone.dll" [2011-05-09 09:49:38 176936]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CLASSES_ROOT\clsid\{59506042-42a8-4ef6-82c9-35177bfb7f6f}]
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{59506042-42a8-4ef6-82c9-35177bfb7f6f}]
2011-05-09 09:49:38 176936 ----a-w- C:\Program Files (x86)\ZoneAlarm_IT\prxtbZone.dll
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-04-15 10:33:48 2515552 ----a-w- C:\Program Files (x86)\Vuze_Remote\tbVuze.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "C:\Program Files (x86)\Vuze_Remote\tbVuze.dll" [2010-04-15 10:33:48 2515552]
"{59506042-42a8-4ef6-82c9-35177bfb7f6f}"= "C:\Program Files (x86)\ZoneAlarm_IT\prxtbZone.dll" [2011-05-09 09:49:38 176936]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CLASSES_ROOT\clsid\{59506042-42a8-4ef6-82c9-35177bfb7f6f}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"="C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-09-29 14:26:44 1685048]
"swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-05-03 23:54:19 39408]
"SpybotSD TeaTimer"="C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 15:07:20 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 09:47:28 62768]
"HP Remote Solution"="C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe" [2009-08-25 02:11:15 656896]
"HP Software Update"="c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 13:50:04 54576]
"Easybits Recovery"="C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe" [2009-09-02 11:00:00 60464]
"avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-09-01 13:22:01 281768]
"hpqSRMon"="C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 16:33:36 150528]
"Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 22:58:10 37296]
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 04:59:06 937920]
"ZoneAlarm"="C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-09 19:01:38 73360]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 12:06:06 254696]
"COMODO"="C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 10:27:10 213304]
"CPA"="C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 10:27:12 184120]
C:\Users\Gagarin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
C:\Users\Andropov\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\Windows\SysWOW64\guard32.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 12:16:28 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 13:27:14 138576]
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe [2009-07-14 01:39:46 27136]
R2 gupdate;Servizio di Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-04 10:17:32 135664]
R3 dump_wmimmc;dump_wmimmc;C:\Program Files (x86)\Gpotato\Flyff\GameGuard\dump_wmimmc.sys [x]
R3 gupdatem;Servizio Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-04 10:17:32 135664]
R3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2009-09-17 05:57:46 23536]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;C:\Windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 17:10:10 57184]
S0 sptd;sptd;C:\Windows\System32\Drivers\sptd.sys [x]
S1 cmderd;COMODO Internet Security Eradication Driver;C:\Windows\system32\DRIVERS\cmderd.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys [x]
S2 CLPSLS;COMODO livePCsupport Service;C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 10:27:10 1267000]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 16:27:38 92216]
S2 ISWKL;ZoneAlarm Toolbar ISWKL;C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [2011-11-03 14:44:22 33672]
S2 IswSvc;ZoneAlarm Toolbar IswSvc;C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [2011-11-03 14:44:42 827520]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 14:31:10 1153368]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - CMDERD
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
Contenuto della cartella 'Scheduled Tasks'
2011-12-27 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-04 10:17:33 . 2010-05-04 10:17:32]
2011-12-27 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-04 10:17:33 . 2010-05-04 10:17:32]
2010-05-03 C:\Windows\Tasks\PCDRScheduledMaintenance.job
- C:\Program Files\PC-Doctor for Windows\pcdrcui.exe [2009-09-18 07:11:04 . 2009-09-18 07:11:04]
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2009-07-29 09:21:26 16333856]
"PC-Doctor for Windows localizer"="C:\Program Files\PC-Doctor for Windows\localizer.exe" [2009-09-17 05:57:42 95728]
"Windows Mobile Device Center"="C:\Windows\WindowsMobile\wmdc.exe" [2007-05-31 08:11:56 660360]
"ISW"="C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" [2011-11-03 14:44:38 1125504]
"COMODO Internet Security"="C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" [2011-12-20 23:41:46 9454920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=C:\Windows\System32\guard64.dll
------- Scansione supplementare -------
uLocal Page = C:\Windows\system32\blank.htm
mLocal Page = C:\Windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - C:\Users\Andropov\AppData\Roaming\Mozilla\Firefox\Profiles\k5c07l8v.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/firefox?client=fir ... t:officialFF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
- - - - CHIAVI ORFANE RIMOSSE - - - -
URLSearchHooks-{91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file)
Wow6432Node-HKCU-Run-{8C237BA5-9BDE-92CC-3B4B-F24A327887D5} - C:\Users\Andropov\AppData\Roaming\Yxguyl\vezuriv.exe
WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)
WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - (no file)
WebBrowser-{59506042-42A8-4EF6-82C9-35177BFB7F6F} - (no file)
AddRemove-EasyBits Magic Desktop - C:\Windows\system32\ezMDUninstall.exe
AddRemove-{08DB3902-2CE0-474D-BCE3-0177766CE9F1} - C:\Program Files (x86)\InstallShield Installation Information\{08DB3902-2CE0-474D-BCE3-0177766CE9F1}\setup.exe
allora che dice questo log? quale problema rileva?
ciao e grazie