Sì hai ragione mi ero dimenticato di attivare l'opzione ma anche così non è cambiato nulla , è pazzesco , pensavo fosse un problemino da nulla e non riesco a risolvere . Ho fatto anche gli scan in mod prov come da istruzioni , w combofix ma è sempre come prima con entrambi gli hd , le icone lampeggiano e ciccia . Vorrei far notare agli utenti che gli strumenti di rimozione di kaspersky non funzionano se non sono a pagamento , quindi inutili , molto meglio clamwin che ti becca anche i falsi positivi . A questo punto mi viene il sospetto che in tune up utilites ci sia una opzione che riguarda le icone e che sia corrotta o che sia impostata male , però uso regolarmente anche asc che dovrebbe riparare gli errori . Non so più cosa pensare , il problema è solo " fastidioso " ma a questo punto mi fa impazzire il non risolvere . Una precisazione : nell'ultima scansione combofix mi ha praticamente eliminato antivir e anche clamwin diceva che ................ , troyan e falsi positivi ? Alla fine ho installato il vecchio e sano nod32 e a fine mese lo acquisto regolarmente . Allego i log . Saluti .
Scan Started Thu Mar 31 00:35:02 2011
-------------------------------------------------------------------------------
C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aerdl.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\aerdl.dll.infected'
C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aerdl.dll.gz: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\aerdl.dll.gz.infected'
C:\Documents and Settings\claudio\Desktop\Installazioni Software\TU2009TrialIT.exe: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\TU2009TrialIT.exe.infected'
C:\Documents and Settings\claudio\Desktop\Installazioni Software\TuneUp Utilities 2009\WinStyler.exe: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\WinStyler.exe.infected'
WARNING: Can't open file C:\hiberfil.sys: Permission denied
WARNING: Can't open file C:\pagefile.sys: Permission denied
WARNING: Can't open file C:\System Volume Information\setup_9.0.0.722_14.02.2011_20-13drv.isw: Permission denied
WARNING: Can't open file C:\System Volume Information\setup_9.0.0.722_15.02.2011_22-22drv.isw: Permission denied
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP314\A0052111.rbf: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0052111.rbf.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP338\A0054931.rbf: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0054931.rbf.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP348\A0055387.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055387.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP349\A0055419.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055419.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP350\A0055462.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055462.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP351\A0055492.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055492.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP352\A0055519.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055519.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP353\A0055561.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055561.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP354\A0055589.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055589.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP355\A0055613.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055613.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP356\A0055640.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055640.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP357\A0055667.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055667.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP358\A0055696.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0055696.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP359\A0056462.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0056462.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP362\A0057513.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0057513.dll.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP362\A0057514.exe: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0057514.exe.infected'
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP362\A0057515.exe: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0057515.exe.infected'
C:\System Volume Information\_restoreC0D4ADC2-DC66-4187-B2E7-8AB84EB1ACFD\RP139\A0050397.exe: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0050397.exe.infected'
C:\System Volume Information\_restoreC0D4ADC2-DC66-4187-B2E7-8AB84EB1ACFD\RP139\A0050398.exe: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0050398.exe.infected'
C:\System Volume Information\_restoreC0D4ADC2-DC66-4187-B2E7-8AB84EB1ACFD\RP139\A0050474.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0050474.dll.infected'
C:\System Volume Information\_restoreC0D4ADC2-DC66-4187-B2E7-8AB84EB1ACFD\RP139\A0050573.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\A0050573.dll.infected'
C:\WINDOWS\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\WinStyler.exe: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\WinStyler.exe.infected.000'
WARNING: Can't open file C:\WINDOWS\system32\CatRoot2\tmp.edb: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\default: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\SAM: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\SECURITY: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\software: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\system: Permission denied
C:\WINDOWS\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\vcomp90.dll.infected'
C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aerdl.dll: Trojan.Fakesec-310 FOUND
C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aerdl.dll.gz: Trojan.Fakesec-310 FOUND
C:\Documents and Settings\claudio\Desktop\Installazioni Software\TU2009TrialIT.exe: Trojan.Fakesec-310 FOUND
C:\Documents and Settings\claudio\Desktop\Installazioni Software\TuneUp Utilities 2009\WinStyler.exe: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP314\A0052111.rbf: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP338\A0054931.rbf: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP348\A0055387.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP349\A0055419.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP350\A0055462.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP351\A0055492.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP352\A0055519.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP353\A0055561.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP354\A0055589.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP355\A0055613.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP356\A0055640.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP357\A0055667.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP358\A0055696.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP359\A0056462.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP362\A0057513.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP362\A0057514.exe: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restore506B45BE-D1B9-4670-A3CD-373E031D1893\RP362\A0057515.exe: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restoreC0D4ADC2-DC66-4187-B2E7-8AB84EB1ACFD\RP139\A0050397.exe: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restoreC0D4ADC2-DC66-4187-B2E7-8AB84EB1ACFD\RP139\A0050398.exe: Trojan.GenericFF-1 FOUND
C:\System Volume Information\_restoreC0D4ADC2-DC66-4187-B2E7-8AB84EB1ACFD\RP139\A0050474.dll: Trojan.Fakesec-310 FOUND
C:\System Volume Information\_restoreC0D4ADC2-DC66-4187-B2E7-8AB84EB1ACFD\RP139\A0050573.dll: Trojan.Fakesec-310 FOUND
C:\WINDOWS\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\WinStyler.exe: Trojan.Fakesec-310 FOUND
C:\WINDOWS\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll: Trojan.GenericFF-1 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 932016
Engine version: 0.96.1
Scanned directories: 4903
Scanned files: 55721
Infected files: 27
Data scanned: 25868.85 MB
Data read: 43069.25 MB (ratio 0.60:1)
Time: 25771.688 sec (429 m 31 s)
The following files are Digitally Signed by Microsoft and have been incorrectly detected as viruses:
C:\Programmi\Windows Media Player\wmplayer.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wscript.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\pdh.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\explorer.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\fxswzrd.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\grpconv.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\ieakeng.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\imekrcic.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\msident.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\mup.sys: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\pdh.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\sfloppy.sys: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\snmpapi.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\unimdmat.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\unimdmat.dll.000: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\wmplayer.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\wscript.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtServicePackUninstall$\xrxwiadr.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtUninstallKB951978$\wscript.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\$NtUninstallKB956572$\pdh.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\Driver Cache\i386\sp2.cab: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\Driver Cache\i386\sp3.cab: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ERDNT\cache\explorer.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\explorer.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ie8\ieakeng.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\dhcpmon.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\explorer.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\fxswzrd.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\grpconv.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\ieakeng.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\lang\imekrcic.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\msident.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\msoobe.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\olecli32.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\pdh.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\sfloppy.sys: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\snmpapi.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\sp2.cab: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\sp3.cab: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\unimdmat.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\wmplayer.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\wscript.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\ServicePackFiles\i386\xrxwiadr.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\dhcpmon.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\dllcache\imekrcic.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\dllcache\pdh.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\dllcache\wmplayer.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\dllcache\wscript.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\drivers\sfloppy.sys: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\grpconv.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\msident.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\olecli32.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\oobe\msoobe.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\pdh.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\SET17.tmp: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\SET57.tmp: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\SET6BD.tmp: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\SETF.tmp: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\snmpapi.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\unimdmat.dll: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
C:\WINDOWS\system32\wscript.exe: [Trojan.GenericFF-1] FALSE POSITIVE FOUND
Please do not be alarmed and help us by submitting the files identified above as FALSE POSITIVE at
http://www.clamav.net/sendvirus/--------------------------------------
Completed
--------------------------------------
ComboFix 11-03-30.02 - claudio 31/03/2011 9.42.25.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1791.1351 [GMT 2:00]
Eseguito da: c:\documents and settings\claudio\Documenti\Download\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {00000002-0002-0000-6C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-7C25-9E7C08000A00}
FW: PC Tools Firewall Plus *Disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((( Files Creati Da 2011-02-28 al 2011-03-31 )))))))))))))))))))))))))))))))))))
.
.
2011-03-10 18:03 . 2011-03-10 18:03 -------- d-----w- c:\programmi\Bonjour
2011-03-04 19:08 . 2011-03-04 19:08 -------- d-----w- c:\documents and settings\Administrator
2011-03-04 18:46 . 2011-03-04 18:46 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2011-03-04 18:46 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2011-03-04 18:46 . 2011-03-04 18:46 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-09 13:54 . 2010-02-26 13:47 186880 ------w- c:\windows\system32\encdec.dll
2011-02-09 13:54 . 2010-02-26 13:46 270848 ------w- c:\windows\system32\sbe.dll
2011-02-02 07:58 . 2010-02-26 11:39 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2010-02-26 11:39 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-23 09:38 . 2011-01-23 09:35 253952 ------w- c:\windows\Setup1.exe
2011-01-23 09:38 . 2011-01-23 09:35 74752 ----a-w- c:\windows\ST6UNST.EXE
2011-01-22 16:54 . 2011-01-22 16:54 101888 ----a-w- c:\windows\system32\X_linkerexdsk2.dll
2011-01-21 14:44 . 2001-08-31 12:00 440832 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2001-08-31 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2001-08-31 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-01-16 17:36 . 2010-01-16 17:36 8755648 ----a-w- c:\programmi\Vuze_Installer.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-02-12_15.02.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-30 08:15 . 2011-03-30 08:15 16384 c:\windows\Temp\Perflib_Perfdata_79c.dat
+ 2001-08-31 12:00 . 2011-03-27 03:28 63180 c:\windows\system32\perfc010.dat
- 2001-08-31 12:00 . 2010-10-31 07:25 63180 c:\windows\system32\perfc010.dat
+ 2001-08-31 12:00 . 2011-03-27 03:28 52764 c:\windows\system32\perfc009.dat
- 2001-08-31 12:00 . 2010-10-31 07:25 52764 c:\windows\system32\perfc009.dat
+ 2011-02-14 19:32 . 2009-10-22 11:54 37392 c:\windows\system32\drivers\56666902.sys
+ 2011-02-15 21:47 . 2009-10-22 11:54 37392 c:\windows\system32\drivers\09829952.sys
+ 2010-10-07 11:23 . 2010-10-07 11:23 91424 c:\windows\system32\dnssd.dll
+ 2008-12-11 12:31 . 2008-12-11 12:31 27904 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\uxtuneupx86.dll
+ 2008-12-12 15:20 . 2008-12-12 15:20 11008 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\tux64thk.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 15104 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\TUMessages.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 68352 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\TUInstallHelper.exe
+ 2008-12-11 12:32 . 2008-12-11 12:32 27392 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\SDShelEx86.dll
+ 2008-12-12 15:20 . 2008-12-12 15:20 85760 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\RegWiz.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 16640 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\RegistryDefragHelper.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 37632 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\PMLauncher.exe
+ 2008-12-11 12:31 . 2008-12-11 12:31 25856 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\DseShExtx86.dll
+ 2008-12-11 12:31 . 2008-12-11 12:31 17152 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\authuitu_x86.dll
- 2001-08-31 12:00 . 2008-04-13 18:13 135168 c:\windows\system32\shsvcs.dll
+ 2001-08-31 12:00 . 2009-07-27 23:16 135168 c:\windows\system32\shsvcs.dll
- 2001-08-31 12:00 . 2010-10-31 07:25 425432 c:\windows\system32\perfh010.dat
+ 2001-08-31 12:00 . 2011-03-27 03:28 425432 c:\windows\system32\perfh010.dat
+ 2001-08-31 12:00 . 2011-03-27 03:28 380350 c:\windows\system32\perfh009.dat
- 2001-08-31 12:00 . 2010-10-31 07:25 380350 c:\windows\system32\perfh009.dat
+ 2011-02-14 19:32 . 2009-09-25 15:59 128016 c:\windows\system32\drivers\56666901.sys
+ 2011-02-14 19:32 . 2009-10-09 21:31 315408 c:\windows\system32\drivers\5666690.sys
+ 2011-02-15 21:47 . 2009-09-25 15:59 128016 c:\windows\system32\drivers\09829951.sys
+ 2011-02-15 21:47 . 2009-10-09 21:31 315408 c:\windows\system32\drivers\0982995.sys
+ 2010-10-07 11:23 . 2010-10-07 11:23 197920 c:\windows\system32\dnssdX.dll
+ 2010-10-07 11:23 . 2010-10-07 11:23 107808 c:\windows\system32\dns-sd.exe
+ 2009-07-27 23:16 . 2009-07-27 23:16 135168 c:\windows\system32\dllcache\shsvcs.dll
+ 2011-02-09 13:54 . 2011-02-09 13:54 270848 c:\windows\system32\dllcache\sbe.dll
+ 2011-01-27 11:57 . 2011-01-27 11:57 677888 c:\windows\system32\dllcache\lhmstsc.exe
+ 2011-02-09 13:54 . 2011-02-09 13:54 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-03-10 18:02 . 2011-03-10 18:02 811520 c:\windows\Installer\c509852.msi
+ 2011-03-10 18:04 . 2011-03-10 18:04 897024 c:\windows\Installer\{C73F2967-062E-48F2-A462-D335B8950183}\SafariIco.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 220416 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\UpdateWizard.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 280832 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\UninstallManager.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 238848 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\Undelete.exe
+ 2008-12-11 12:33 . 2008-12-11 12:33 884992 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\TUDefragService.dll
+ 2008-12-12 15:20 . 2008-12-12 15:20 343808 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\SystemInformation.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 129792 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\SystemControl.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 355072 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\StartUpManager.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 924928 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\SilentUpdater.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 174336 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\Shredder.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 230656 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\ShortcutCleaner.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 199424 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\RescueCenter.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 169216 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\RepairWizard.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 328960 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\RegistryEditor.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 161024 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\RegistryDefrag.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 513792 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\RegistryCleaner.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 435448 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\ProductInfo.dat
+ 2008-12-12 15:20 . 2008-12-12 15:20 398080 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\ProcessManager.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 980736 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\OneClickStarter.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 600320 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\OneClick.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 156416 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\MemOptimizer.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 222464 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\DriveDefrag.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 461568 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\DiskExplorer.exe
+ 2008-12-12 15:20 . 2008-12-12 15:20 164096 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\DiskDoctor.exe
+ 2011-02-02 07:58 . 2011-02-02 07:58 2067456 c:\windows\system32\dllcache\lhmstscx.dll
+ 2011-03-10 18:04 . 2011-03-10 18:04 3140608 c:\windows\Installer\c509894.msi
+ 2011-03-10 18:03 . 2011-03-10 18:03 1984000 c:\windows\Installer\c509865.msi
+ 2009-04-27 15:49 . 2009-04-27 15:49 8212480 c:\windows\Installer\24e89f8e.msp
+ 2008-12-12 15:20 . 2008-12-12 15:20 1214208 c:\windows\Installer\$PatchCache$\Managed\86092A55EC2FC65419848C9678E93275\8.0.2000\SpeedOptimizer.exe
+ 2010-02-28 08:07 . 2011-03-10 02:02 37943240 c:\windows\system32\MRT.exe
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="soundman.exe" [2001-05-29 124416]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
.
c:\documents and settings\claudio\Menu Avvio\Programmi\Esecuzione automatica\
setup_9.0.0.722_14.02.2011_20-13.lnk - c:\documents and settings\claudio\Desktop\Virus Removal Tool1\setup_9.0.0.722_14.02.2011_20-13\startup.exe [2011-2-14 72208]
setup_9.0.0.722_15.02.2011_22-22.lnk - c:\documents and settings\claudio\Desktop\Virus Removal Tool2\setup_9.0.0.722_15.02.2011_22-22\startup.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
2010-05-24 12:10 86016 ----a-w- c:\programmi\ClamWin\bin\ClamTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SamsungSM PanelMgr]
2008-07-31 07:09 536576 ----a-w- c:\windows\SamsungSM\PanelMgr\SSMMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WHITNEY_S2P]
2006-03-27 06:35 229376 ----a-w- c:\programmi\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" -atboottime
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
.
R0 09829952;09829952 Boot Guard Driver;c:\windows\system32\drivers\09829952.sys [15/02/2011 23.47.50 37392]
R0 56666902;56666902 Boot Guard Driver;c:\windows\system32\drivers\56666902.sys [14/02/2011 21.32.03 37392]
R1 09829951;09829951;c:\windows\system32\drivers\09829951.sys [15/02/2011 23.47.50 128016]
R1 56666901;56666901;c:\windows\system32\drivers\56666901.sys [14/02/2011 21.32.03 128016]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [24/04/2010 15.37.44 159600]
R1 setup_9.0.0.722_14.02.2011_20-13drv;setup_9.0.0.722_14.02.2011_20-13drv;c:\windows\system32\drivers\5666690.sys [14/02/2011 21.32.03 315408]
R1 setup_9.0.0.722_15.02.2011_22-22drv;setup_9.0.0.722_15.02.2011_22-22drv;c:\windows\system32\drivers\0982995.sys [15/02/2011 23.47.50 315408]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [24/04/2010 15.37.59 73840]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [06/01/2011 13.02.12 136176]
S2 SSPORT;SSPORT;\??\c:\windows\System32\Drivers\SSPORT.sys --> c:\windows\System32\Drivers\SSPORT.sys [?]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [24/04/2010 15.36.58 95640]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2011-03-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-01-06 11:01]
.
2011-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-01-06 11:01]
.
2011-03-31 c:\windows\Tasks\Manutenzione in 1 clic.job
- c:\programmi\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:55]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\claudio\Dati applicazioni\Mozilla\Firefox\Profiles\f011y73a.default\
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
------- Associazioni dei file -------
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKLM-Run-avgnt - c:\programmi\Avira\AntiVir Desktop\avgnt.exe
AddRemove-Avira AntiVir Desktop - c:\programmi\Avira\AntiVir Desktop\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-03-31 09:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(3436)
c:\windows\system32\WININET.dll
c:\programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA
c:\programmi\Adobe\Reader 9.0\Reader\viewerps.dll
c:\windows\system32\webcheck.dll
.
Ora fine scansione: 2011-03-31 09:54:32
ComboFix-quarantined-files.txt 2011-03-31 07:54
.
Pre-Run: 81.064.263.680 byte disponibili
Post-Run: 81.050.103.808 byte disponibili
.
- - End Of File - - B521797F2D400DB1C4AD4A87DB3F8B15