Ecco il log di Combofix:
ComboFix 09-05-25.A2 - Francesco 26/05/2009 19.55.56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.512.266 [GMT 2:00]
Eseguito da: c:\documents and settings\Francesco\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-3C24-9E7C08000A00}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\Francesco\Menu Avvio\Programmi\Videos.url
c:\documents and settings\Francesco\Preferiti\Videos.url
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\system\oeminfo.ini
c:\windows\system32\Cache
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Creati Da 2009-04-26 al 2009-05-26 )))))))))))))))))))))))))))))))))))
.
2009-05-25 19:34 . 2009-03-30 08:33 96104 ----a-w c:\windows\system32\drivers\avipbb.sys
2009-05-25 19:34 . 2009-03-24 14:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-25 19:34 . 2009-02-13 10:29 22360 ----a-w c:\windows\system32\drivers\avgntmgr.sys
2009-05-25 19:34 . 2009-02-13 10:17 45416 ----a-w c:\windows\system32\drivers\avgntdd.sys
2009-05-25 19:33 . 2009-05-25 19:33 -------- d-----w c:\programmi\Avira
2009-05-25 19:33 . 2009-05-25 19:33 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 17:52 . 2008-01-07 10:58 -------- d-----w c:\documents and settings\Francesco\Dati applicazioni\Skype
2009-05-26 14:36 . 2008-01-07 11:01 -------- d-----w c:\documents and settings\Francesco\Dati applicazioni\skypePM
2009-05-25 21:41 . 2004-03-01 18:48 -------- d-----w c:\programmi\Downloader 1.8
2009-05-25 21:41 . 2004-06-02 08:01 -------- d-----w c:\programmi\ClonyXXL
2009-05-25 19:12 . 2004-02-26 19:32 -------- d-----w c:\programmi\File comuni\Symantec Shared
2009-05-25 19:12 . 2004-02-26 19:32 -------- d-----w c:\programmi\Symantec
2009-05-25 19:09 . 2004-02-26 19:32 -------- d-----w c:\programmi\Norton AntiVirus
2009-05-25 19:04 . 2004-02-26 19:32 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Symantec
2009-05-04 16:02 . 2001-08-31 10:00 68462 ----a-w c:\windows\system32\perfc010.dat
2009-05-04 16:02 . 2001-08-31 10:00 402026 ----a-w c:\windows\system32\perfh010.dat
2009-03-06 14:44 . 2002-09-09 11:51 285696 ----a-w c:\windows\system32\pdh.dll
2007-06-06 09:41 . 2004-11-12 19:11 61038 ----a-w c:\programmi\mozilla firefox\components\jar50.dll
2007-06-06 09:41 . 2004-11-12 19:11 49256 ----a-w c:\programmi\mozilla firefox\components\jsd3250.dll
2007-06-06 09:41 . 2004-11-12 19:11 166000 ----a-w c:\programmi\mozilla firefox\components\xpinstal.dll
2008-04-25 11:42 . 2008-04-25 11:25 48 --sh--w c:\windows\S36D56E48.tmp
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\programmi\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"Copernic Desktop Search"="c:\programmi\Copernic Desktop Search\CopernicDesktopSearch.exe" [2006-05-31 5252392]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2007-12-12 21686568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-09-24 5033984]
"HTpatch"="c:\windows\htpatch.exe" [2002-10-30 28672]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2004-02-24 151597]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"CloneCDElbyCDFL"="c:\programmi\Elaborate Bytes\CloneCD\ElbyCheck.exe" [2001-12-06 45056]
"CloneCDTray"="c:\programmi\Elaborate Bytes\CloneCD\CloneCDTray.exe" [2002-04-15 57344]
"CnxDslTaskBar"="c:\programmi\Conexant\AccessRunner ADSL\CnxDslTb.exe" [2003-05-12 454656]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"Zone Labs Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2006-07-09 968696]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\programmi\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
"IndexSearch"="c:\programmi\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
"PPort11reminder"="c:\programmi\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="c:\programmi\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\programmi\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-09-24 741376]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-17 19968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Acrobat Assistant.lnk - c:\programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Adobe Gamma Loader.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2004-3-17 110592]
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 01000000
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"MIDI1"= SYNCOR11.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"c:\\Programmi\\mirc6.03-ITA\\mirc.exe"=
"c:\\Programmi\\Soulseek\\slsk.exe"=
"c:\\Programmi\\WinMX\\WinMX.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Programmi\\ViaVoice\\Bin\\engine.exe"=
"c:\\Programmi\\Microsoft Office\\Office10\\WINWORD.EXE"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 DLPortIO;DriverLINX Port I/O Driver;c:\windows\system32\drivers\DLPortIO.SYS [04/03/2004 15.11.38 3584]
R2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;c:\programmi\Symantec\LiveUpdate\AluSchedulerSvc.exe [26/09/2006 22.37.49 100032]
R3 uscsc108;uscsc108;c:\windows\system32\drivers\uscsc108.sys [09/03/2003 19.41.38 102336]
S3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [06/07/2004 12.40.53 60288]
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\drivers\CnxEtU.sys [06/07/2004 12.40.53 643200]
S3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [06/07/2004 12.40.53 108547]
S3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys --> c:\windows\system32\Drivers\mtk.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
2009-05-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-26 20:18]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-WillPolo - c:\windows\WillPolo.vbs
SafeBoot-procexp90.Sys
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Point&&Go - c:\programmi\File comuni\Expert System\PGPlatform\PGPlatform.htm
IE: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZNxdm87541ITIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Salva oggetto con Net Transport - c:\programmi\Xi\NetTransport 2\NTAddLink.html
IE: Salva tutti gli oggetti con Net Transport - c:\programmi\Xi\NetTransport 2\NTAddList.html
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {10F76067-C352-473B-94C9-5EE691429C48} - hxxp://agentsetup.paginebianche.virgilio.it/PBCab/VBRunTimeInstaller.CAB
DPF: {FA6B2C55-F067-4895-A0D0-536168798883} - hxxp://agentsetup.paginebianche.virgilio.it/PBCab/install.cab
FF - ProfilePath - c:\documents and settings\Francesco\Dati applicazioni\Mozilla\Firefox\Profiles\ws4ccozf.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.google.itFF - component: c:\programmi\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\programmi\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-26 19:58
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HTpatch = c:\windows\htpatch.exe?ows\CurrentVersion\Run???\??????[????`??[???[`??[???????????????[???[???[???[$??????[???????????????[???????????[???w????(????3?w???w?????3?w ??w???[:???????d???r??[1??[???[d??????[?-?[????z??w8h?[\2?[?1?[htinst.INI?[?u?[????d????????F?
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2009-05-26 20.02.07
ComboFix-quarantined-files.txt 2009-05-26 18:00
Pre-Run: 2.205.827.072 byte disponibili
Post-Run: 2.251.812.864 byte disponibili
165 --- E O F --- 2009-04-26 13:05