ecco il log di combofix:
ComboFix 09-12-25.04 - MASSIMO 2009-12-26 21:18:40.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.1023.530 [GMT 1:00]
Eseguito da: c:\programmi\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\H8SRTKLLLOTPQLA.SYS.VIR
c:\windows\system32\H8SRTgrxtmfqhtp.dat
c:\windows\system32\H8SRTkomolimxdq.dll
c:\windows\system32\H8SRTuroumujexs.dll
c:\windows\system32\krl32mainweq.dll
c:\windows\system32\srcr.dat
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_H8SRTd.sys
-------\Service_H8SRTd.sys
((((((((((((((((((((((((( Files Creati Da 2009-11-26 al 2009-12-26 )))))))))))))))))))))))))))))))))))
.
2009-12-26 20:10 . 2009-12-26 20:04 398336 ----a-w- c:\windows\system32\CF22640.exe
2009-12-26 18:27 . 2009-12-26 18:27 1052 ----a-w- C:\prgmonsp.bin
2009-12-26 18:03 . 2009-12-26 18:03 -------- d-----w- c:\documents and settings\MASSIMO\Impostazioni locali\Dati applicazioni\PackageAware
2009-12-26 18:03 . 2009-12-26 18:03 6422072 ----a-w- c:\programmi\vnlt6551.exe
2009-12-26 16:39 . 2009-12-26 16:39 3357024 ----a-w- c:\programmi\ccsetup227.exe
2009-12-26 14:08 . 2009-12-26 14:09 3865929 ----a-r- c:\programmi\ComboFix.exe
2009-12-26 11:19 . 2009-12-26 11:19 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\SACore
2009-12-26 11:17 . 2009-12-26 11:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SiteAdvisor
2009-12-26 11:06 . 2009-11-04 15:54 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-26 11:06 . 2009-11-04 15:54 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-26 11:06 . 2009-11-04 15:54 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-26 11:06 . 2009-07-16 11:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-12-26 10:54 . 2009-12-26 11:06 -------- d-----w- c:\programmi\File comuni\McAfee
2009-12-26 10:54 . 2009-12-26 11:00 -------- d-----w- c:\programmi\McAfee.com
2009-12-26 10:54 . 2009-12-26 13:53 -------- d-----w- c:\programmi\McAfee
2009-12-26 10:47 . 2009-11-04 15:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-12-26 10:39 . 2009-12-26 18:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee
2009-12-26 10:39 . 2009-12-26 10:39 1296288 ----a-w- c:\programmi\DMSetup.exe
2009-12-26 10:18 . 2009-12-26 10:19 -------- d-----w- c:\documents and settings\MASSIMO\Dati applicazioni\QuickScan
2009-12-26 10:14 . 2009-12-26 10:14 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-26 10:11 . 2009-10-05 21:03 15688 ----a-w- c:\windows\system32\lsdelete.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-26 18:04 . 2009-12-26 18:04 -------- dc-h--w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}
2009-12-23 11:28 . 2009-03-21 15:26 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-12-23 11:28 . 2009-03-28 16:28 4844296 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-21 16:35 . 2009-12-26 18:04 2856006 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\vnlt6551.exe
2009-12-18 10:18 . 2009-12-26 18:04 122880 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\OFFLINE\361580F9\76AC2E42\viritupg.dll
2009-12-15 13:34 . 2009-12-26 18:04 274432 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\OFFLINE\D89A54DE\76AC2E42\MONLITE.exe
2009-12-11 19:44 . 2006-09-30 17:16 -------- d-----w- c:\documents and settings\MASSIMO\Dati applicazioni\Skype
2009-12-11 18:27 . 2008-11-30 10:40 -------- d-----w- c:\documents and settings\MASSIMO\Dati applicazioni\skypePM
2009-12-11 18:26 . 2004-09-16 14:31 80688 ----a-w- c:\windows\system32\perfc010.dat
2009-12-11 18:26 . 2004-09-16 14:31 482274 ----a-w- c:\windows\system32\perfh010.dat
2009-12-11 10:38 . 2009-12-26 18:04 352256 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\OFFLINE\BB22A901\76AC2E42\Scan.dll
2009-12-10 22:03 . 2009-05-29 18:24 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-03 15:14 . 2009-03-21 15:26 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 15:13 . 2009-03-21 15:26 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-30 22:03 . 2009-10-05 21:03 3695616 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-27 23:46 . 2006-01-13 14:01 -------- d-----w- c:\programmi\File comuni\Adobe
2009-11-27 14:10 . 2009-12-26 18:04 69632 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\OFFLINE\__Nas01_sviluppo_varie\Setup\VIRITLite\Files\viritsvc.exe
2009-11-27 14:06 . 2009-12-26 18:04 815104 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\OFFLINE\5BF53870\76AC2E42\viritexp.exe
2009-11-13 17:26 . 2006-02-24 16:29 55848 ----a-w- c:\documents and settings\MASSIMO\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-11-13 17:25 . 2009-11-13 17:25 -------- d-----w- c:\programmi\MSECache
2009-11-13 17:25 . 2009-11-13 17:24 28868320 ----a-w- c:\programmi\FileFormatConverters.exe
2009-11-11 23:03 . 2009-11-11 23:03 3310608 ----a-w- c:\programmi\ccsetup225.exe
2009-11-11 07:53 . 2009-12-26 18:04 45312 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\OFFLINE\931FE753\76AC2E42\VIRAGTLT.sys
2009-11-11 07:53 . 2009-12-26 18:04 45312 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\OFFLINE\277632B2\76AC2E42\VIRAGTLT.sys
2009-11-11 07:53 . 2009-11-11 07:53 45312 --s-a-w- c:\windows\system32\drivers\VIRAGTLT.sys
2009-11-10 20:37 . 2009-11-10 20:37 -------- d-----w- c:\programmi\Microsoft
2009-11-08 15:40 . 2009-12-26 18:04 49152 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{5EE5232A-BD09-4BCA-91DC-774E5F3CFFA9}\OFFLINE\22028FD3\76AC2E42\tgdlg.dll
2009-11-04 15:54 . 2009-11-04 15:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-29 07:40 . 2004-09-16 14:31 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-24 21:03 . 2009-06-27 21:05 2353992 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-10-21 05:38 . 2004-09-16 14:31 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-09-16 14:31 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-03 22:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:33 . 2004-09-16 14:31 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-09-16 14:31 150016 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-09-16 14:31 79872 ----a-w- c:\windows\system32\raschap.dll
2009-06-30 14:11 . 2009-04-28 19:28 1878888 ----a-w- c:\programmi\install_flash_player.exe
2009-05-29 18:18 . 2009-05-29 18:18 30113824 ----a-w- c:\programmi\avira_antivir_personal_it.exe
2009-05-12 09:03 . 2009-05-12 09:03 3227248 ----a-w- c:\programmi\ccsetup219.exe
2009-04-04 14:33 . 2009-04-04 14:33 3342809 ----a-w- c:\programmi\eMule0.49c-Installer.exe
2009-03-28 23:33 . 2009-03-28 23:32 3190688 ----a-w- c:\programmi\ccsetup218.exe
2009-03-21 15:25 . 2009-03-21 15:25 2876720 ----a-w- c:\programmi\mbam-setup.exe
2009-03-21 12:39 . 2006-09-30 17:15 2267944 ----a-w- c:\programmi\SkypeSetup.exe
2009-03-20 17:30 . 2009-03-20 17:30 977683 ----a-w- c:\programmi\tesseract-2.00.ita.tar.gz
2009-03-20 17:27 . 2009-03-20 17:27 171008 ----a-w- c:\programmi\freeocr26.exe
2009-03-18 14:21 . 2009-03-18 14:21 812344 ----a-w- c:\programmi\HJTInstall.exe
2009-03-11 17:30 . 2009-03-11 17:30 1159512 ----a-w- c:\programmi\wlsetup-custom.exe
2009-02-14 21:56 . 2009-02-14 21:48 34543112 ----a-w- c:\programmi\Ad-AwareAE.exe
2009-02-13 23:02 . 2009-02-13 23:02 3171208 ----a-w- c:\programmi\ccsetup216.exe
2008-11-21 18:13 . 2008-11-21 18:13 3231826 ----a-w- c:\programmi\eMule0.49b-Installer1.exe
2008-11-01 12:03 . 2008-11-01 12:02 1355112 ----a-w- c:\programmi\msnemoticons4.exe
2008-09-29 19:50 . 2008-09-29 19:49 21431024 ----a-w- c:\programmi\VeohSetup-3.9.8.1077.exe
2008-09-26 21:39 . 2008-09-26 21:39 1440832 ----a-w- c:\programmi\Silverlight.exe
2008-08-31 18:19 . 2008-08-31 18:17 63530280 ----a-w- c:\programmi\iTunesSetup.exe
2008-08-26 11:05 . 2008-08-26 11:04 2928600 ----a-w- c:\programmi\ccsetup211.exe
2008-07-17 18:06 . 2008-07-17 18:07 382352 ----a-w- c:\programmi\xpiinstall.exe
2008-06-22 08:52 . 2008-06-22 08:51 454336 ----a-w- c:\programmi\msnemoticons3.exe
2008-06-20 13:43 . 2008-06-20 13:43 2914296 ----a-w- c:\programmi\ccsetup208.exe
2008-06-20 13:38 . 2008-06-20 13:38 9547110 ----a-w- c:\programmi\FirefoxPortableUnibo-2.0.0.5.exe
2008-05-17 14:18 . 2008-05-17 14:17 21031280 ----a-w- c:\programmi\Lavasoft_Adaware_multi.exe
2008-05-16 20:50 . 2008-05-16 20:50 2897456 ----a-w- c:\programmi\ccsetup207.exe
2008-05-15 17:13 . 2008-05-15 17:13 3309160 ----a-w- c:\programmi\eMule0.49a-Installer11.exe
2008-04-23 18:36 . 2008-04-23 18:36 2600640 ----a-w- c:\programmi\msnemoticons2.exe
2008-03-28 20:47 . 2008-03-28 20:47 2751368 ----a-w- c:\programmi\ccsetup206.exe
2008-02-06 15:08 . 2008-02-06 15:07 3526336 ----a-w- c:\programmi\msnemoticons.exe
2007-12-28 17:09 . 2007-12-28 17:09 13413048 ----a-w- c:\programmi\Google_Earth_BZXD.exe
2007-12-22 18:10 . 2007-12-22 18:10 4722512 ----a-w- c:\programmi\MsgPlusLive-450.exe
2007-12-21 17:10 . 2007-12-21 17:10 2402320 ----a-w- c:\programmi\WLinstaller.exe
2007-12-13 22:31 . 2007-12-13 22:31 17788920 ----a-w- c:\programmi\antivir_workstation_win7u_en_h.exe
2007-12-13 21:26 . 2007-12-13 21:26 5152256 ----a-w- c:\programmi\WindowsDefender.msi
2007-12-09 18:00 . 2007-12-09 18:00 2724328 ----a-w- c:\programmi\ccsetup203.exe
2007-12-08 09:17 . 2008-07-19 19:20 184449 ----a-w- c:\programmi\mp3DC207.exe
2007-11-28 20:29 . 2007-11-28 20:28 2592448 ----a-w- c:\programmi\emoticons2.exe
2007-10-27 12:06 . 2007-10-27 11:46 51422520 ----a-w- c:\programmi\iTunes743Setup.exe
2007-09-13 18:54 . 2007-09-13 18:53 2600640 ----a-w- c:\programmi\emoticons.exe
2007-06-04 21:59 . 2007-06-04 21:59 14874584 ----a-w- c:\programmi\setupita.exe
2006-11-26 13:57 . 2006-11-26 13:57 17515272 ----a-w- c:\programmi\avg75free_430a848.exe
2006-11-25 14:46 . 2006-11-25 14:45 24074080 ----a-w- c:\programmi\AdbeRdr708_it_IT.exe
2006-10-03 13:59 . 2006-10-03 13:59 5197088 ----a-w- c:\programmi\SUPERAntiSpyware.exe
2006-10-03 13:25 . 2006-10-03 13:25 92672 ----a-w- c:\programmi\KillBox.exe
2006-10-02 22:20 . 2006-10-02 22:20 212849 ----a-w- c:\programmi\hijackthis.zip
2006-09-28 18:25 . 2006-09-28 18:25 2855080 ----a-w- c:\programmi\aawsepersonal.exe
2006-04-30 18:37 . 2006-04-30 18:37 1094021 ----a-w- c:\programmi\dvdshrink32setup.zip
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-30 68856]
"NBJ"="c:\programmi\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 1937408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2005-05-12 102400]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-23 7286784]
"nwiz"="nwiz.exe" [2005-09-23 1519616]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"NB Probe"="c:\programmi\ASUS\NB Probe\NBProbe.exe" [2005-07-27 765952]
"Wireless Console"="c:\programmi\ASUS\Wireless Console\wcourier.exe" [2005-07-22 57344]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-12-22 98394]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-12-22 688218]
"IntelZeroConfig"="c:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2005-05-31 401408]
"IntelWireless"="c:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2005-06-03 385024]
"EOUApp"="c:\programmi\Intel\Wireless\Bin\EOUWiz.exe" [2005-05-31 356352]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"Power_Gear"="c:\programmi\ASUS\Power4 Gear\BatteryLife.exe" [2007-06-05 86016]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-10-03 39792]
"Ad-Watch"="c:\programmi\Lavasoft\Ad-Aware\AAWTray.exe" [2009-10-05 520024]
"Samsung Common SM"="c:\windows\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 372736]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"mcagent_exe"="c:\programmi\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-07 1176808]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-05-27 413696]
"VIRIT LITE MONITOR"="c:\vexplite\MONLITE.EXE" [2009-12-26 274432]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
ASUS ChkMail.lnk - c:\programmi\Asus\Asus ChkMail\ChkMail.exe [2006-1-13 32768]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-06-22 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-23 12:58 356352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2005-05-31 21:46 110592 ----a-w- c:\programmi\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\MSMSGS.EXE"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Asus\\ASUS Live Update\\LiveUpdt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\File comuni\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:127.0.0.1
"4672:UDP"= 4672:UDP:127.0.0.1
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-14 64160]
R0 R592;R592;c:\windows\system32\drivers\R592.sys [2004-10-15 57088]
R0 risdpntk;risdpntk;c:\windows\system32\drivers\risdpntk.sys [2004-10-15 27264]
R0 VIRAGTLT;VIRAGTLT;c:\windows\system32\drivers\VIRAGTLT.sys [2009-11-11 45312]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\SASDIFSV.SYS [2006-02-16 8944]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [2006-06-09 55024]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 1028432]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\programmi\McAfee\SiteAdvisor\McSACore.exe [2009-12-26 203280]
R2 viritsvclite;VirIT eXplorer Lite;c:\vexplite\VIRITSVC.EXE [2009-11-27 69632]
S3 Asushwio;Asushwio;c:\windows\system32\drivers\ASUSHWIO.SYS [2006-04-14 5824]
S3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096]
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.libero.it/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: Yahoo! Poker -
hxxp://origin.games.yahoo.net/games/clients/y/pt3_x.cab.
- - - - CHIAVI ORFANE RIMOSSE - - - -
SafeBoot-AVG Anti-Spyware Driver
AddRemove-CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10431966 - c:\programmi\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10431966\HXFSETUP.EXE -U -IHDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_10431966
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-26 21:30
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1060)
c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\programmi\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(3912)
c:\windows\system32\WININET.dll
c:\programmi\McAfee\SiteAdvisor\saHook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\FILECO~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\progra~1\mcafee\msk\msksrver.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\Intel\Wireless\Bin\OProtSvc.exe
c:\programmi\Raxco\PerfectDisk\PDAgent.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\programmi\ASUS\NB Probe\SPM\spmgr.exe
c:\programmi\Raxco\PerfectDisk\PDEngine.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\WgaTray.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\windows\RTHDCPL.EXE
c:\windows\ATK0100\ATKOSD.exe
.
**************************************************************************
.
Ora fine scansione: 2009-12-26 21:37:01 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-12-26 20:36
Pre-Run: 19,532,658,176 byte disponibili
Post-Run: 19,413,393,408 byte disponibili
- - End Of File - - 2D51F936148986E6FAED34F7A6A9284E