...
Eseguito da: c:\x\ComboFix.exe
AV: COMODO Antivirus *Disabled/Updated*
AV: Returnil System Safe 2011 *Disabled/Updated*
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\x
...
c:\x\Varie\TUBI3D.TXT
D:\x.txt
.
.
((((((((((((((((((((((((( Files Creati Da 2012-09-13 al 2012-10-13 )))))))))))))))))))))))))))))))))))
.
.
2012-10-13 14:38 . 2012-10-13 14:40 -------- d-----w- c:\programmi\Emsisoft HiJackFree
2012-10-07 10:57 . 2012-10-07 10:57 -------- d-----w- c:\documents and settings\Proprietario\Impostazioni locali\Dati applicazioni\Opera
2012-10-07 10:57 . 2012-10-07 10:57 -------- d-----w- c:\programmi\Opera
2012-10-06 23:35 . 2012-10-07 00:02 -------- d-----w- c:\programmi\Antivirus e simili
2012-10-05 11:55 . 2012-10-06 14:43 -------- d-----w- c:\documents and settings\Proprietario\Impostazioni locali\Dati applicazioni\Adobe
2012-10-01 20:56 . 2012-10-06 23:34 -------- d-----w- c:\programmi\Programmi in avvìo e in esecuzione
2012-10-01 19:04 . 2012-10-01 23:44 -------- d-----w- c:\programmi\CCleaner
2012-09-21 22:34 . 2012-09-21 22:36 -------- d-----w- c:\windows\system32\NtmsData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-07 15:04 . 2012-04-16 14:58 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 18:24 . 2012-07-14 17:00 477168 ------w- c:\windows\system32\npdeployJava1.dll
2012-08-28 18:24 . 2010-10-19 21:04 473072 ------w- c:\windows\system32\deployJava1.dll
2012-08-28 16:39 . 2012-07-14 17:00 73728 ------w- c:\windows\system32\javacpl.cpl
2012-08-28 15:05 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:05 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-08-28 15:05 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2008-04-14 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-08-23 11:32 . 2012-04-06 22:18 696520 ------w- c:\windows\system32\FlashPlayerApp.exe
2012-08-23 11:32 . 2011-05-17 10:52 73416 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-23 06:27 . 2008-04-14 12:00 2152448 ------w- c:\windows\system32\ntoskrnl.exe
2012-08-23 06:27 . 2008-04-13 18:55 2031104 ------w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-04-29 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-04-29 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-04-29 142872]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"COMODO Internet Security"="c:\programmi\Comodo Antivirus\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
.
c:\documents and settings\Proprietario\Menu Avvio\Programmi\Esecuzione automatica\
Copia di sicurezza....lnk - c:\util\Copia.bat [2010-4-17 266]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programmi\\Opera\\opera.exe"=
.
R0 rvsystem;rvsystem;c:\windows\system32\drivers\rvsystem.sys [01/07/2011 15.41.20 58808]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [11/03/2012 21.13.44 18056]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [11/03/2012 21.13.46 494968]
R1 rvsmon;rvsmon;c:\windows\system32\drivers\rvsmon.sys [24/06/2011 13.50.28 276104]
R1 rvsmonf;rvsmonf;c:\windows\system32\drivers\rvsmonf.sys [24/06/2011 13.50.30 43712]
R1 rvsmonn;rvsmonn;c:\windows\system32\drivers\rvsmonn1.sys [24/06/2011 13.50.32 31096]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [22/07/2011 18.27.02 12880]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [12/07/2011 23.55.22 67664]
R2 !SASCORE;SAS Core Service;c:\programmi\SUPERAntiSpyware\SASCore.exe [11/07/2012 20.54.49 116608]
R2 RVSMONBL;Returnil System Safe Core Service;c:\programmi\Returnil System Safe\RSS\rvsmon.exe [01/07/2011 15.52.58 1801504]
R3 rvseng;rvseng;c:\windows\system32\drivers\rvseng.sys [24/06/2011 13.50.32 1091992]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [17/08/2010 9.48.29 8192]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [25/02/2010 2.42.40 1684736]
S3 esihdrv;esihdrv;\??\c:\docume~1\PROPRI~1\IMPOST~1\Temp\esihdrv.sys

c:\docume~1\PROPRI~1\IMPOST~1\Temp\esihdrv.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 u9usbser;MYWAVEU9 USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\u9usbser.sys

c:\windows\system32\DRIVERS\u9usbser.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Connection Wizard,ShellNext = "c:\programmi\Outlook Express\msimn.exe"
uInternet Settings,ProxyOverride = 127.0.0.1
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: telecomitalia.it\web.ebill-a
TCP: DhcpNameServer = ...
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-02033617.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-10-13 18:06
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'lsass.exe'(764)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'csrss.exe'(680)
c:\windows\system32\cmdcsr.dll
.
Ora fine scansione: 2012-10-13 18:08:11
ComboFix-quarantined-files.txt 2012-10-13 16:08
.
Pre-Run: 117.922.009.088 byte disponibili
Post-Run: 117.863.362.560 byte disponibili
.
- - End Of File - - 923A6BD6F8892F98828B1659CF436F22