guarda.. il pc al momento non presenta problemi anche perchè tempo fa ho preso un virus anzi si e presentato come antivirus360 ho fatto una scansione con malwarebytes e mi ha rimosso tutti i file infetti percio' dopo di che' ho impostato un log di hjt e ho letto che mi avevi riscontrato un'infezione e che valeva la pena tentare di rimuovere. in teoria non mi da nessun problema ma essendo che sto seguendo il tuo consiglio come mi avevi detto precedentemente. cmq ti posto il log di combofix come da te detto e scusa per la pazienza che mi dedichi. grazie.
ComboFix 09-01-02.01 - Luigi 2009-01-04 0.40.08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.959.641 [GMT 1:00]
Eseguito da: c:\documents and settings\Luigi\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((( Files Creati Da 2008-12-03 al 2009-01-03 )))))))))))))))))))))))))))))))))))
.
2008-12-31 01:59 . 2008-12-31 01:59 <DIR> d-------- C:\VundoFix Backups
2008-12-31 01:38 . 2004-05-19 06:42 <DIR> d-------- c:\documents and settings\Administrator\WINDOWS
2008-12-31 01:38 . 2004-05-18 16:16 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di stampa
2008-12-31 01:38 . 2008-05-05 17:59 <DIR> d-------- c:\documents and settings\Administrator\Risorse di rete
2008-12-31 01:38 . 2004-05-19 05:27 <DIR> dr------- c:\documents and settings\Administrator\Preferiti
2008-12-31 01:38 . 2004-05-18 15:20 <DIR> d--h----- c:\documents and settings\Administrator\Modelli
2008-12-31 01:38 . 2004-05-18 16:16 <DIR> dr------- c:\documents and settings\Administrator\Menu Avvio
2008-12-31 01:38 . 2009-01-04 00:41 <DIR> d--h----- c:\documents and settings\Administrator\Impostazioni locali
2008-12-31 01:38 . 2004-05-19 05:27 <DIR> dr------- c:\documents and settings\Administrator\Documenti
2008-12-31 01:38 . 2004-05-19 07:02 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\toshiba
2008-12-31 01:38 . 2004-05-19 07:10 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\AdobeUM
2008-12-31 01:38 . 2004-05-19 07:10 <DIR> dr-h----- c:\documents and settings\Administrator\Dati applicazioni
2008-12-31 01:38 . 2008-12-31 01:38 <DIR> d-------- c:\documents and settings\Administrator
2008-12-28 22:15 . 2008-12-28 22:15 <DIR> d-------- c:\programmi\Trend Micro
2008-12-16 01:49 . 2008-12-16 01:49 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-12-16 01:49 . 2008-12-16 01:49 <DIR> d-------- c:\documents and settings\Luigi\Dati applicazioni\Malwarebytes
2008-12-16 01:49 . 2008-12-16 01:49 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-12-16 01:49 . 2008-12-03 19:53 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-16 01:49 . 2008-12-03 19:53 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-15 19:03 . 2008-12-15 19:03 1,025 --a------ C:\noi.exe
2008-12-08 23:30 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuapi.dll.mui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-07 21:35 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-12-07 21:35 339,968 ----a-w c:\windows\system32\pythoncom25.dll
2008-12-07 21:35 2,117,632 ----a-w c:\windows\system32\python25.dll
2008-12-07 21:35 114,688 ----a-w c:\windows\system32\pywintypes25.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:04 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:07 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-01-22 98304]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-01-22 495616]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"THotkey"="c:\programmi\Toshiba\Toshiba Applet\thotkey.exe" [2004-04-30 430080]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2007-10-19 286720]
"TFncKy"="TFncKy.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 c:\windows\agrsmmsg.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll foikmk.dll rsyqgl.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Controllo del Calendario di Ulead Photo Express.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Controllo del Calendario di Ulead Photo Express.lnk
backup=c:\windows\pss\Controllo del Calendario di Ulead Photo Express.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSLauncher
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-07-07 17:41 57344 c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-04-13 10:09 49152 c:\programmi\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-10-19 19:16 286720 c:\programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2005-12-07 21:57 30208 c:\programmi\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"ose"=3 (0x3)
"NMIndexingService"=3 (0x3)
"MDM"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\SEAT\\PBO\\CD\\ServerHttp.exe"=
"c:\\ASShared\\Downloadtmp.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2004-05-19 5632]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-05 97928]
R4 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-03 875288]
R4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-03 231704]
R4 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-05-05 76040]
S0 kiie;kiie;c:\windows\system32\drivers\vleur.sys --> c:\windows\system32\drivers\vleur.sys [?]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\docume~1\Luigi\IMPOST~1\Temp\RarSFX0\kerneld.wnt --> c:\docume~1\Luigi\IMPOST~1\Temp\RarSFX0\kerneld.wnt [?]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2008-10-20 207616]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63cb2a34-6321-11dd-baf8-00a0d1da002f}]
\Shell\AutoRun\command - .\run\autorun.exe
\Shell\open\Command - .\run\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ba0c79ea-752b-11dd-bb31-00a0d1da002f}]
\Shell\AutoRun\command - F:\xn1i9x.com
\Shell\explore\Command - F:\xn1i9x.com
\Shell\open\Command - F:\xn1i9x.com
*Newly Created Service* - PROCEXP90
.
- - - - ORFÃOS REMOVIDOS - - - -
MSConfigStartUp-28523947552774242623470966504747 - c:\programmi\A360\av360.exe
MSConfigStartUp-TOSCDSPD - c:\programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
.
------- Supplementare di scansione -------
.
uStart Page = about:blank
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\InstallerControl.dll - O16 -: CabBuilder
hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
c:\windows\Downloaded Program Files\OSDC5.OSD
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-04 00:41:53
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\docume~1\Luigi\IMPOST~1\Temp\RarSFX0\kerneld.wnt"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\avgrsstx.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\avgrsstx.dll
.
Ora fine scansione: 2009-01-04 0.43.06
ComboFix-quarantined-files.txt 2009-01-03 23:42:40
Pre-Run: 32.259.223.552 byte disponibili
Post-Run: 32,256,475,136 byte disponibili
157