ho fatto quello che dicevi..........per nn essermi fatta viva ultimamente concordo meglio per me, niente virus, anche se devo dire che ho passato dei momenti grigi.
ecco ill log:
ComboFix 09-07-22.01 - franco benvenuti 22/07/2009 21.33.22.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.510.253 [GMT 2:00]
Eseguito da: c:\documents and settings\franco benvenuti\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\Search Spider
c:\programmi\Search Spider\dbghelp.dll
c:\programmi\Search Spider\DownloadGnutella.exe
c:\programmi\Search Spider\SearchSpider.dll
c:\programmi\Search Spider\SearchSpider.url
c:\programmi\Search Spider\searchspidersvc.exe
c:\programmi\Search Spider\SpiderUpdate.exe
c:\programmi\Search Spider\unins000.dat
c:\programmi\Search Spider\unins000.exe
c:\windows\Installer\de65c6.msi
.
((((((((((((((((((((((((( Files Creati Da 2009-06-22 al 2009-07-22 )))))))))))))))))))))))))))))))))))
.
2009-07-19 11:45 . 2009-07-19 11:45 -------- d-----w- c:\programmi\BestShoppingTipsProgram
2009-07-19 08:54 . 2002-07-01 02:02 62464 ----a-w- c:\windows\system32\E_S00RP2.EXE
2009-07-06 12:21 . 2008-04-14 02:13 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-22 19:29 . 2009-07-19 11:48 839 ----a-w- c:\windows\system32\nodes.txt.tmp
2009-07-22 12:17 . 2009-01-09 19:43 -------- d-----w- c:\programmi\eMule
2009-07-22 12:11 . 2009-04-29 16:09 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-07-21 19:57 . 2008-08-31 17:16 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Spybot - Search & Destroy
2009-07-19 08:23 . 2009-01-10 17:03 1 ----a-w- c:\documents and settings\franco benvenuti\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-06 12:22 . 2009-07-06 12:22 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-06 12:22 . 2009-07-06 12:22 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-06-29 18:02 . 2008-08-10 19:10 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-29 18:02 . 2008-08-10 19:10 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-29 18:02 . 2008-08-10 19:10 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:36 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2006-03-02 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-14 16:28 . 2009-06-14 16:28 -------- d-----w- c:\programmi\Elaborate Bytes
2009-06-14 09:22 . 2009-06-14 09:22 -------- d-----w- c:\programmi\DVD Decrypter
2009-06-11 19:01 . 2006-03-02 12:00 69568 ----a-w- c:\windows\system32\perfc010.dat
2009-06-11 19:01 . 2006-03-02 12:00 437272 ----a-w- c:\windows\system32\perfh010.dat
2009-06-03 19:09 . 2006-03-02 12:00 1296384 ----a-w- c:\windows\system32\quartz.dll
2009-05-15 15:55 . 2008-08-10 19:10 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-08 23:14 . 2009-05-08 23:14 1418120 ----a-w- c:\windows\system32\wdfcoinstaller01005.dll
2009-05-08 23:14 . 2009-05-08 23:14 14736 ----a-w- c:\windows\system32\drivers\nuidfltr.sys
2009-05-07 15:32 . 2006-03-02 12:00 347648 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:33 . 2006-03-02 12:00 669184 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:33 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"TomTomHOME.exe"="c:\programmi\TomTom HOME 2\TomTomHOMERunner.exe" [2009-04-24 251240]
"EPSON Stylus C86 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE" [2003-11-25 99840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-29 1948440]
"EPSON Stylus C86 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE" [2003-11-25 99840]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-22 339968]
"Tvs"="c:\programmi\TOSHIBA\Tvs\TvsTray.exe" [2004-11-12 73728]
"CreativeMouse "="c:\programmi\Mouse Driver\MouseDrv.exe" [2004-06-27 503808]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-12-07 136600]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\franco benvenuti\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-29 18:02 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Ares\\Ares.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/08/2008 21.10.44 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/08/2008 21.10.50 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [15/07/2008 21.45.13 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [15/07/2008 21.45.10 298776]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [29/04/2009 18.09.32 55152]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [11/12/2008 16.58.13 8192]
R2 Start BT in service;Start BT in service;c:\programmi\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [30/09/2007 9.16.38 51816]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmi\TomTom HOME 2\TomTomHOMEService.exe [24/04/2009 13.57.30 92008]
S2 SearchSpiderSvc;SearchSpiderSvc;"c:\programmi\Search Spider\searchspidersvc.exe" --> c:\programmi\Search Spider\searchspidersvc.exe [?]
S3 fsssvc;Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18.08.58 533360]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\programmi\NOS\bin\getPlus_HelperSvc.exe [11/05/2009 21.54.35 33176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [24/08/2008 16.25.21 38472]
S3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [07/03/2008 11.32.10 333328]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - RPCLOCATOR
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-AliceRE_McciTrayApp - c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://rossoalice.alice.it/
TCP: {A51FF135-51E9-4BE9-A2B0-5BC52C8E45CF} = 85.37.17.55 85.38.28.93
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-22 21:42
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON Stylus C86 Series = c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE /P23 "EPSON Stylus C86 Series" /M "Stylus C86" /EF "HKCU"???????=? ??0??;???W????????????I:~f???????????????`????????????????????J:~????`???????+???8?????????????;~????`?????????;~`??????????????|???????
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(620)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-07-22 21.46.10
ComboFix-quarantined-files.txt 2009-07-22 19:46
ComboFix2.txt 2008-08-24 06:55
Pre-Run: 35.152.760.832 byte disponibili
Post-Run: 35.128.979.456 byte disponibili
139 --- E O F --- 2009-07-22 01:00