ecco.
non riesco ad allegare il file quindi lo posto diviso in due perchè è troppo lungo.
scusate ma è la prima volta
ComboFix 10-09-16.04 - laura 17/09/2010 10:30:02.1.2 - x86
Microsoft Windows 7 Starter 6.1.7600.0.1252.39.1040.18.1013.296 [GMT 2:00]
Eseguito da: c:\users\laura\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
c:\programdata\.wtav
c:\programdata\FullRemove.exe
c:\programdata\Microsoft\Network\Downloader\qmgr0. dat
c:\programdata\Microsoft\Network\Downloader\qmgr1. dat
c:\windows\SEC
c:\windows\SEC\172100logo.bmp
c:\windows\SEC\banner.png
c:\windows\SEC\Computer.png
c:\windows\SEC\Media _S_ Logo.png
c:\windows\SEC\Samsung.png
c:\windows\SEC\Samsung2.png
c:\windows\SEC\SamsungLogo.png
c:\windows\SEC\Thumbs.db
c:\windows\SEC\Wallpapers\Thumbs.db
c:\windows\SEC\Wallpapers\wallpaper.jpg
c:\windows\SEC\Wallpapers\wallpaper1.jpg
c:\windows\SEC\Wallpapers\Wallpaper2.jpg
----- BITS: Possibili siti infetti -----
hxxp://kameraesmer.com
La copia infetta di c:\windows\explorer.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_5228 3b2af41f3691\explorer.exe
La copia infetta di c:\windows\System32\wininit.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90 ef265a43c13\wininit.exe
La copia infetta di c:\windows\explorer.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_5228 3b2af41f3691\explorer.exe
.
((((((((((((((((((((((((( Files Creati Da 2010-08-17 al 2010-09-17 )))))))))))))))))))))))))))))))))))
.
2010-09-17 09:02 . 2010-09-17 09:19 -------- d-----w- c:\users\laura\AppData\Local\temp
2010-09-17 09:02 . 2010-09-17 09:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-17 06:35 . 2010-09-17 06:35 -------- d-sh--w- c:\windows\system32\%APPDATA%
2010-09-16 17:17 . 2010-09-16 17:17 -------- d-----w- c:\program files\Trend Micro
2010-09-16 16:08 . 2010-09-16 16:08 -------- d-----w- C:\TDSSKiller_Quarantine
2010-09-16 15:17 . 2010-09-16 15:17 -------- d-----w- c:\program files\ESET
2010-09-15 23:49 . 2010-09-15 23:49 -------- d-----w- c:\program files\CCleaner
2010-09-15 23:42 . 2010-09-15 23:42 -------- d-----w- c:\users\laura\AppData\Roaming\Pusoki
2010-09-15 23:01 . 2010-09-15 23:01 -------- d-----w- c:\users\laura\AppData\Roaming\Malwarebytes
2010-09-15 23:01 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-15 23:01 . 2010-09-15 23:01 -------- d-----w- c:\programdata\Malwarebytes
2010-09-15 23:01 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-15 23:01 . 2010-09-15 23:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-15 10:08 . 2010-09-16 14:57 -------- d-----w- c:\program files\Windows Live Safety Center
2010-09-15 08:07 . 2010-09-17 09:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-15 08:07 . 2010-09-16 20:59 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-14 07:33 . 2010-04-21 19:48 1006104 ----a-w- c:\windows\system32\igxpun.exe
2010-08-28 13:38 . 2010-05-31 18:32 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-08-28 13:38 . 2010-05-31 18:32 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-08-28 13:38 . 2010-05-31 18:32 64304 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2010-08-28 13:38 . 2010-05-31 18:32 385880 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-08-28 13:38 . 2010-05-31 18:32 312616 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-08-28 13:38 . 2010-05-31 18:32 160720 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2010-08-28 13:37 . 2010-05-31 18:32 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-08-28 13:37 . 2010-05-31 18:32 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-08-28 13:37 . 2010-05-31 18:32 51688 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-08-28 13:37 . 2010-05-31 18:32 152320 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-08-28 06:37 . 2010-08-28 06:37 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-08-26 23:00 . 2010-08-26 23:00 0 ----a-w- c:\windows\nsreg.dat
2010-08-26 22:59 . 2010-08-26 22:59 -------- d-----w- c:\users\laura\AppData\Local\Mozilla
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
2010-05-31 18:32 . 2010-08-28 13:38 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb 108c86c\WinMail.exe
.
codice:
<pre>
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe
c:\program files\AnyPC Client\APLangApp .exe
c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager .exe
c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility .exe
c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard .exe
c:\program files\Common Files\Java\Java Update\jusched .exe
c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu .exe
c:\program files\iTunes\iTunesHelper .exe
c:\program files\McAfee.com\Agent\mcagent .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\Synaptics\SynTP\SynTPEnh .exe
</pre>
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Google Update"="c:\users\laura\AppData\Local\Google\Updat e\GoogleUpdate.exe" [N/A]
"SunJavaUpdateSched"="c:\users\laura\AppData\Roami ng\jusched.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask .exe -atboottime" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-11-18 8092192]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-26 1713448]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.e xe" [N/A]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-06-30 1193848]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-21 173592]
"Persistence"="c:\windows\system32\igfxpers.ex e" [2010-04-21 150552]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2215064]
c:\users\laura\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Startup\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-10-2 795936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\system]
"npddzjfskcgoffjvdrdgTaskMgr"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
c:\users\laura\AppData\Local\Google\Update\GoogleU pdate.exe [N/A]
R2 gupdate;Servizio di Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-21 135664]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-07-01 43944]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-12-07 201168]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 101120]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-05-31 83496]
R3 netr73;Driver scheda LAN wireless USB RT73 per Vista;c:\windows\system32\DRIVERS\netr73.sys [2009-07-13 545792]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-05-31 64304]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-05-31 160720]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 10752]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.s ys [2010-07-29 136632]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfw wfpr.sys [2010-07-29 96920]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-01-23 203280]
S2 McMPFSvc;McAfee Servizio Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-05-31 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-05-31 141792]
S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [2009-08-13 44312]
S2 Rezip;Rezip;c:\windows\SYSTEM32\Rezip.exe [2009-03-05 311296]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-05-31 55456]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-05-31 312616]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]