ComboFix 08-12-01.03 - Roberta & Alessandra 2008-12-03 18.14.32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.551 [GMT 1:00]
Eseguito da: c:\documents and settings\Roberta & Alessandra\Desktop\ComboFix.exe
Interruttori di comando utilizzati :: c:\documents and settings\Roberta & Alessandra\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!FILE ::
c:\documents and settings\Roberta & Alessandra\aqiiuwxm.exe
c:\documents and settings\Roberta & Alessandra\ArdaSoftware.GameManagement.dll
c:\documents and settings\Roberta & Alessandra\aubdyiph.exe
c:\documents and settings\Roberta & Alessandra\BurracoWebClient.exe
c:\documents and settings\Roberta & Alessandra\BurracoWebUpdater2.exe
c:\documents and settings\Roberta & Alessandra\cgwrciav.exe
c:\documents and settings\Roberta & Alessandra\Controls.dll
c:\documents and settings\Roberta & Alessandra\dfjptybd.exe
c:\documents and settings\Roberta & Alessandra\dvsqzyqn.exe
c:\documents and settings\Roberta & Alessandra\erzmghqp.exe
c:\documents and settings\Roberta & Alessandra\exntrbxu.exe
c:\documents and settings\Roberta & Alessandra\ggicgksa.exe
c:\documents and settings\Roberta & Alessandra\hnetsogy.exe
c:\documents and settings\Roberta & Alessandra\hwmwaspu.exe
c:\documents and settings\Roberta & Alessandra\ifqaswdp.exe
c:\documents and settings\Roberta & Alessandra\ihlenzzr.exe
c:\documents and settings\Roberta & Alessandra\ijwwpqoa.exe
c:\documents and settings\Roberta & Alessandra\iljgmegf.exe
c:\documents and settings\Roberta & Alessandra\jctjsjer.exe
c:\documents and settings\Roberta & Alessandra\jofjrlck.exe
c:\documents and settings\Roberta & Alessandra\jvzhltrw.exe
c:\documents and settings\Roberta & Alessandra\jyugmzll.exe
c:\documents and settings\Roberta & Alessandra\kdlfdjgu.exe
c:\documents and settings\Roberta & Alessandra\lillrjmv.exe
c:\documents and settings\Roberta & Alessandra\NetDevelop.dll
c:\documents and settings\Roberta & Alessandra\nldefrit.exe
c:\documents and settings\Roberta & Alessandra\nncjeykh.exe
c:\documents and settings\Roberta & Alessandra\oabwrvrw.exe
c:\documents and settings\Roberta & Alessandra\ofnfvmyy.exe
c:\documents and settings\Roberta & Alessandra\PokerCards.dll
c:\documents and settings\Roberta & Alessandra\rcyiowqr.exe
c:\documents and settings\Roberta & Alessandra\tkdmijpe.exe
c:\documents and settings\Roberta & Alessandra\ubomxqtc.exe
c:\documents and settings\Roberta & Alessandra\vfdohdxo.exe
c:\documents and settings\Roberta & Alessandra\wjcfmkyd.exe
c:\documents and settings\Roberta & Alessandra\xbepsjxw.exe
c:\documents and settings\Roberta & Alessandra\xpesdwry.exe
c:\documents and settings\Roberta & Alessandra\xrljhrpu.exe
c:\documents and settings\Roberta & Alessandra\xrvgprzf.exe
c:\documents and settings\Roberta & Alessandra\xwnjuaze.exe
c:\documents and settings\Roberta & Alessandra\xzflcnng.exe
c:\documents and settings\Roberta & Alessandra\ymtcirgd.exe
c:\documents and settings\Roberta & Alessandra\yqvnwhfb.exe
c:\documents and settings\Roberta & Alessandra\zeklfxhh.exe
c:\documents and settings\Roberta & Alessandra\zrkoaaaw.exe
c:\documents and settings\Roberta & Alessandra\zzqqwguq.exe
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\drivers\lvuvc.hs
c:\windows\Tasks\AA8EA8F391895C47.job
f:\.\run\autorun.exe
F:\Knight.exe
.
Error: Cfiles.dat
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\Proxy Long Chin Ping
c:\documents and settings\Roberta & Alessandra\aqiiuwxm.exe
c:\documents and settings\Roberta & Alessandra\ArdaSoftware.GameManagement.dll
c:\documents and settings\Roberta & Alessandra\aubdyiph.exe
c:\documents and settings\Roberta & Alessandra\BurracoWebClient.exe
c:\documents and settings\Roberta & Alessandra\BurracoWebUpdater2.exe
c:\documents and settings\Roberta & Alessandra\cgwrciav.exe
c:\documents and settings\Roberta & Alessandra\Controls.dll
c:\documents and settings\Roberta & Alessandra\Dati applicazioni\ACID MULTI CAKE
c:\documents and settings\Roberta & Alessandra\Dati applicazioni\ACID MULTI CAKE\
0c:\documents and settings\Roberta & Alessandra\Dati applicazioni\ACID MULTI CAKE\DD056BBE
c:\documents and settings\Roberta & Alessandra\dfjptybd.exe
c:\documents and settings\Roberta & Alessandra\dvsqzyqn.exe
c:\documents and settings\Roberta & Alessandra\erzmghqp.exe
c:\documents and settings\Roberta & Alessandra\exntrbxu.exe
c:\documents and settings\Roberta & Alessandra\ggicgksa.exe
c:\documents and settings\Roberta & Alessandra\hnetsogy.exe
c:\documents and settings\Roberta & Alessandra\hwmwaspu.exe
c:\documents and settings\Roberta & Alessandra\ifqaswdp.exe
c:\documents and settings\Roberta & Alessandra\ihlenzzr.exe
c:\documents and settings\Roberta & Alessandra\ijwwpqoa.exe
c:\documents and settings\Roberta & Alessandra\iljgmegf.exe
c:\documents and settings\Roberta & Alessandra\jctjsjer.exe
c:\documents and settings\Roberta & Alessandra\jofjrlck.exe
c:\documents and settings\Roberta & Alessandra\jvzhltrw.exe
c:\documents and settings\Roberta & Alessandra\jyugmzll.exe
c:\documents and settings\Roberta & Alessandra\kdlfdjgu.exe
c:\documents and settings\Roberta & Alessandra\lillrjmv.exe
c:\documents and settings\Roberta & Alessandra\NetDevelop.dll
c:\documents and settings\Roberta & Alessandra\nldefrit.exe
c:\documents and settings\Roberta & Alessandra\nncjeykh.exe
c:\documents and settings\Roberta & Alessandra\oabwrvrw.exe
c:\documents and settings\Roberta & Alessandra\ofnfvmyy.exe
c:\documents and settings\Roberta & Alessandra\PokerCards.dll
c:\documents and settings\Roberta & Alessandra\rcyiowqr.exe
c:\documents and settings\Roberta & Alessandra\tkdmijpe.exe
c:\documents and settings\Roberta & Alessandra\ubomxqtc.exe
c:\documents and settings\Roberta & Alessandra\vfdohdxo.exe
c:\documents and settings\Roberta & Alessandra\wjcfmkyd.exe
c:\documents and settings\Roberta & Alessandra\xbepsjxw.exe
c:\documents and settings\Roberta & Alessandra\xpesdwry.exe
c:\documents and settings\Roberta & Alessandra\xrljhrpu.exe
c:\documents and settings\Roberta & Alessandra\xrvgprzf.exe
c:\documents and settings\Roberta & Alessandra\xwnjuaze.exe
c:\documents and settings\Roberta & Alessandra\xzflcnng.exe
c:\documents and settings\Roberta & Alessandra\ymtcirgd.exe
c:\documents and settings\Roberta & Alessandra\yqvnwhfb.exe
c:\documents and settings\Roberta & Alessandra\zeklfxhh.exe
c:\documents and settings\Roberta & Alessandra\zrkoaaaw.exe
c:\documents and settings\Roberta & Alessandra\zzqqwguq.exe
c:\programmi\ACID MULTI CAKE
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\drivers\lvuvc.hs
c:\windows\Tasks\AA8EA8F391895C47.job
.
((((((((((((((((((((((((( Files Creati Da 2008-11-03 al 2008-12-03 )))))))))))))))))))))))))))))))))))
.
2008-12-03 17:39 . 2008-12-03 17:40 <DIR> d-------- c:\windows\LastGood
2008-12-02 17:20 . 2008-12-02 17:20 <DIR> d-------- c:\programmi\Trend Micro
2008-11-28 20:49 . 2008-11-28 20:52 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2008-11-28 20:49 . 2008-11-28 20:49 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-11-28 20:49 . 2008-11-28 20:49 <DIR> d-------- c:\documents and settings\Roberta & Alessandra\Dati applicazioni\SUPERAntiSpyware.com
2008-11-28 20:49 . 2008-11-28 20:49 <DIR> d-------- c:\documents and settings\Roberta & Alessandra\Dati applicazioni\Malwarebytes
2008-11-28 20:49 . 2008-11-28 20:49 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-11-28 20:49 . 2008-11-28 20:49 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-11-28 20:49 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-28 20:49 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-23 21:37 . 2008-11-23 21:37 <DIR> d-------- c:\programmi\CCleaner
2008-11-23 16:57 . 2008-12-02 20:04 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-11-23 16:51 . 2008-11-23 16:51 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-11-23 16:51 . 2008-11-23 16:51 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-11-23 16:50 . 2008-11-23 16:50 <DIR> d-------- c:\programmi\Kaspersky Lab
2008-11-23 16:50 . 2008-12-03 17:38 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2008-11-23 16:50 . 2008-12-03 16:03 2,960,416 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-11-23 16:50 . 2008-12-03 18:13 778,272 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-11-23 16:50 . 2008-12-03 16:03 25,256 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-11-23 16:50 . 2008-12-03 18:13 3,740 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2008-11-23 16:45 . 2008-11-23 16:59 <DIR> d-------- c:\programmi\Spybot - Search & Destroy
2008-11-23 16:43 . 2008-11-25 19:30 <DIR> d-------- c:\programmi\a-squared Free
2008-11-20 21:16 . 2008-11-20 21:16 <DIR> d-------- c:\windows\system32\LogFiles
2008-11-17 14:16 . 2008-07-26 16:23 195,096 --a------ c:\windows\system32\lvci11801048.dll
2008-11-17 14:13 . 2008-11-17 14:13 <DIR> d-------- c:\programmi\Logitech
2008-11-12 11:25 . 2008-09-04 18:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 11:25 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 21:12 --------- d-----w c:\documents and settings\Roberta & Alessandra\Dati applicazioni\Skype
2008-12-02 19:21 --------- d-----w c:\documents and settings\Roberta & Alessandra\Dati applicazioni\skypePM
2008-11-28 22:39 88,116 --sha-w c:\windows\system32\delidubu.dll
2008-11-28 19:48 --------- d-----w c:\programmi\File comuni\Wise Installation Wizard
2008-11-23 20:46 --------- d-----w c:\programmi\Windows Live Toolbar
2008-11-23 15:21 --------- d-----w c:\programmi\COMODO
2008-11-23 15:21 --------- d-----w c:\documents and settings\Roberta & Alessandra\Dati applicazioni\Comodo
2008-11-17 23:04 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Motive
2008-11-17 13:18 --------- d-----w c:\programmi\File comuni\LogiShrd
2008-11-17 13:13 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Logishrd
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-12 19:25 --------- d-----w c:\programmi\iTunes
2008-10-12 19:25 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-12 19:24 --------- d-----w c:\programmi\iPod
2008-10-10 22:50 --------- d-----w c:\programmi\eMule
2008-10-07 14:33 --------- d-----w c:\programmi\Skype
2008-10-07 14:33 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Skype
2008-10-07 14:32 --------- d-----w c:\programmi\File comuni\Skype
2008-10-07 14:29 --------- d-----w c:\documents and settings\Roberta & Alessandra\Dati applicazioni\TeamViewer
2008-10-07 13:43 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Logitech
2008-10-06 11:39 --------- d-----w c:\programmi\MSN Messenger
2008-10-05 18:08 --------- d-----w c:\programmi\Circle Developement
2008-10-05 17:33 --------- d-----w c:\documents and settings\Roberta & Alessandra\Dati applicazioni\TuneUp Software
2008-10-05 11:21 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2008-10-04 22:45 --------- d-----w c:\programmi\Java
2008-10-04 22:38 --------- d-----w c:\programmi\Avira
2008-10-03 19:06 --------- d-----w c:\programmi\ACIDMU~4
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:24 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-04-17 14:11 131,072 ----a-w c:\documents and settings\Roberta & Alessandra\ArdaSoftware.CommunicationLayer.dll
2007-03-23 18:31 71,320 ----a-w c:\documents and settings\Roberta & Alessandra\Dati applicazioni\GDIPFONTCACHEV1.DAT
2005-11-11 18:37 12,991,481 ----a-w c:\programmi\DirectX.cab
2004-07-19 21:58 1,156,363 ----a-w c:\programmi\BDANT.cab
2004-07-19 21:53 976,020 ----a-w c:\programmi\BDAXP.cab
2004-07-09 08:13 703,080 ----a-w c:\programmi\BDA.cab
.
((((((((((((((((((((((((((((( snapshot@2008-12-02_20.22.11.89 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-18 20:10:48 94,920 ----a-w c:\windows\LastGood\system32\cdm.dll
+ 2008-07-18 20:07:34 270,880 ----a-w c:\windows\LastGood\system32\mucltui.dll
+ 2008-07-18 20:07:32 210,976 ----a-w c:\windows\LastGood\system32\muweb.dll
+ 2008-07-18 20:09:44 563,912 ----a-w c:\windows\LastGood\system32\wuapi.dll
+ 2008-07-18 20:10:42 53,448 ----a-w c:\windows\LastGood\system32\wuauclt.exe
+ 2008-07-18 20:09:42 1,811,656 ----a-w c:\windows\LastGood\system32\wuaueng.dll
+ 2008-07-18 20:09:46 325,832 ----a-w c:\windows\LastGood\system32\wucltui.dll
+ 2008-07-18 20:10:20 36,552 ----a-w c:\windows\LastGood\system32\wups.dll
+ 2008-07-18 20:10:40 45,768 ----a-w c:\windows\LastGood\system32\wups2.dll
+ 2008-07-18 20:09:44 205,000 ----a-w c:\windows\LastGood\system32\wuweb.dll
- 2008-07-18 20:10:48 94,920 -c--a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 13:09:44 92,696 -c--a-w c:\windows\system32\dllcache\cdm.dll
- 2008-07-18 20:09:44 563,912 -c--a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 13:12:20 561,688 -c--a-w c:\windows\system32\dllcache\wuapi.dll
- 2008-07-18 20:10:42 53,448 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 13:09:44 51,224 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
- 2008-07-18 20:09:42 1,811,656 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 13:13:40 1,809,944 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
- 2008-07-18 20:09:46 325,832 -c--a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 13:12:22 323,608 -c--a-w c:\windows\system32\dllcache\wucltui.dll
- 2008-07-18 20:09:44 205,000 -c--a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 13:13:40 202,776 -c--a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 13:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 13:09:44 43,544 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
+ 2008-09-05 22:30:52 267,304 ------w c:\windows\system32\WgaLogon.dll
+ 2008-09-05 22:30:06 952,360 ------w c:\windows\system32\WgaTray.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-11-17 1805552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 57344]
"AliceRE_McciTrayApp"="c:\programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer\McciTrayApp.exe" [2006-11-21 936960]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"LogitechCommunicationsManager"="c:\programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-07-29 206088]
"Collegamento alla pagina delle proprietà di High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-09-23 c:\windows\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-09-24 c:\windows\ALCWZRD.EXE]
"ISDN Monitor"="Linksts.exe" [2000-06-02 c:\windows\system32\linksts.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
c:\documents and settings\Roberta & Alessandra\Menu Avvio\Programmi\Esecuzione automatica\
Logitech . Registrazione prodotti.lnk - c:\programmi\Logitech\QuickCam\eReg.exe [2008-02-13 493832]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2008-03-04 217088]
Avvio rapido di HP Image Zone.lnk - c:\programmi\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 73728]
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\Roberta & Alessandra\\Desktop\\utorrent.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\iPod\\bin\\iPodService.exe"=
"c:\\Programmi\\File comuni\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Programmi\\MSN Messenger\\usnsvc.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\WINDOWS\\system32\\services.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 isdnlink;isdnlink;c:\windows\system32\DRIVERS\linkisdn.sys [2005-11-20 646795]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R1 SASDIFSV;SASDIFSV;\??\c:\programmi\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\programmi\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 SASENUM;SASENUM;\??\c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
S3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-10-07 627864]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\NSNDIS5.SYS []
S3 vmdmc;Intelligent VComm+ Port Driver;c:\windows\system32\DRIVERS\vmdmc.sys []
S3 wanlink;wanlink;c:\windows\system32\DRIVERS\wanlink.sys [2005-11-20 61320]
S4 hpt3xx;hpt3xx; []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78e02ca-3ce3-11db-a04f-0013d455129e}]
\Shell\AutoRun\command - f:\jdsecure\Windows\JDSecure31.exe
.
Contenuto della cartella 'Scheduled Tasks'
2008-11-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-28 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-04-23 16:17]
2008-12-03 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-04-23 16:17]
2008-12-03 c:\windows\Tasks\Verifica e correzione automatica.job
- c:\programmi\TuneUp Utilities 2008\OneClickStarter.exe []
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-03 18:17:26
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(1052)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2008-12-03 18.18.41
ComboFix-quarantined-files.txt 2008-12-03 17:18:38
ComboFix2.txt 2008-12-02 19:28:06
Pre-Run: 51.398.230.016 byte disponibili
Post-Run: 51,383,214,080 byte disponibili
343 --- E O F --- 2008-12-02 21:17:44