Ho provato e adesso funziona! Combofix ha eliminato il solito autorun in C: che però io non riuscivo ad individuare. ùPosto il report, che però è lungo come la fame e devo dividerlo
Parte prima
ComboFix 10-07-23.01 - Bruna 23/07/2010 23.07.40.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.511.278 [GMT 2:00]
Eseguito da: c:\documents and settings\Bruna\Desktop\ComboFix.exe
AV: Kaspersky PURE *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky PURE *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
C:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Creati Da 2010-06-23 al 2010-07-23 )))))))))))))))))))))))))))))))))))
.
2010-07-23 18:42 . 2010-07-23 18:42 -------- d-----w- c:\programmi\Trend Micro
2010-07-23 16:17 . 2010-07-23 16:17 -------- d-----w- c:\documents and settings\Bruna\Dati applicazioni\Malwarebytes
2010-07-23 16:17 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-23 16:17 . 2010-07-23 16:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-07-23 16:17 . 2010-07-23 16:17 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-07-23 16:17 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-23 08:31 . 2001-08-17 19:52 18688 -c--a-w- c:\windows\system32\dllcache\cdaudio.sys
2010-07-23 08:31 . 2001-08-17 19:52 18688 ----a-w- c:\windows\system32\drivers\cdaudio.sys
2010-07-23 08:27 . 2010-07-23 08:27 932368 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2010-07-23 08:27 . 2010-07-23 08:27 678416 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2010-07-23 08:27 . 2010-07-23 08:27 604688 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2010-07-23 08:27 . 2010-07-23 08:27 522768 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2010-07-23 08:27 . 2010-07-23 08:27 1096208 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2010-07-23 08:11 . 2010-07-23 08:24 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-07-23 08:11 . 2010-07-23 08:24 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-07-23 08:10 . 2009-12-14 10:44 39352 ----a-w- c:\windows\system32\drivers\CSVirtualDiskDrv.sys
2010-07-23 08:10 . 2009-12-14 10:44 88632 ----a-w- c:\windows\system32\drivers\CSCrySec.sys
2010-07-23 08:09 . 2010-07-23 08:09 -------- d-----w- c:\programmi\File comuni\InfoWatch
2010-07-23 08:09 . 2010-07-23 21:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2010-07-23 08:09 . 2010-07-23 08:09 -------- d-----w- c:\programmi\Kaspersky Lab
2010-07-23 08:07 . 2010-07-23 08:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2010-07-16 13:28 . 2010-07-16 13:28 -------- d-----r- c:\documents and settings\LocalService\Preferiti
2010-07-16 13:27 . 2010-07-16 13:27 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-07-16 13:19 . 2009-11-25 10:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-07-14 15:56 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
2010-07-23 20:54 . 2010-02-10 13:52 -------- d-----w- c:\documents and settings\Bruna\Dati applicazioni\uTorrent
2010-06-14 14:31 . 2010-02-09 22:01 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-06 10:32 . 2006-03-02 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:06 . 2006-03-02 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\KA VOverlayIcon]
@="{dd230880-495a-11d1-b064-008048ec2fc5}"
[HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}]
2009-12-25 14:42 129552 ----a-w- c:\programmi\Kaspersky Lab\Kaspersky PURE\shellex.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.e xe" [2010-01-22 141608]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"AudioDeck"="c:\programmi\VIAudioi\SBADeck\ADeck.e xe" [2010-02-11 516096]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"OpwareSE4"="c:\programmi\ScanSoft\OmniPageSE4.0\O pwareSE4.exe" [2006-03-21 69632]
"ScanSoft OmniPage SE 4.0-reminder"="c:\programmi\ScanSoft\OmniPageSE4.0\Ere g\Ereg.exe" [2005-06-03 729088]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky PURE\avp.exe" [2009-12-25 340456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;c:\windows\system32\drivers\CSCrySec.sys [23/07/2010 10.10.22 88632]
R0 KLBG;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [14/10/2009 20.18.34 36880]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;c:\windows\system32\drivers\CSVirtualDiskDr v.sys [23/07/2010 10.10.25 39352]
R2 CSObjectsSrv;Servizio di controllo CryptoStorage;c:\programmi\File comuni\InfoWatch\CryptoStorage\ProtectedObjectsSrv .exe [21/12/2009 17.34.38 743992]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 13.42.46 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/10/2009 18.39.44 19472]
.
Contenuto della cartella 'Scheduled Tasks'
2010-03-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-07-23 c:\windows\Tasks\User_Feed_Synchronization-{E2E0D807-45AF-4E0A-8AC1-A7C6CAABC267}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]

Rispondi quotando
