Ecco il log:
ComboFix 09-12-06.A3 - Administrator 07/12/2009 21.10.30.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1603 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Menu Avvio\Programmi\Esecuzione automatica\siszyd32.exe
c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\windows\system32\SystemRes13.sm.SYS
.
((((((((((((((((((((((((( Files Creati Da 2009-11-07 al 2009-12-07 )))))))))))))))))))))))))))))))))))
.
2009-12-06 23:45 . 2009-12-06 23:45 4844296 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-06 22:31 . 2009-12-06 22:31 116 -c--a-w- c:\windows\system32\fjhdyfhsn.bat
2009-12-03 19:57 . 2009-12-03 19:57 -------- dc----w- c:\documents and settings\Administrator\Dati applicazioni\AVG8
2009-11-30 19:03 . 2009-11-30 19:03 -------- d-----w- c:\programmi\Realtek AC97
2009-11-30 10:18 . 2006-08-01 07:02 49152 -c--a-w- c:\windows\system32\ChCfg.exe
2009-11-30 10:14 . 2006-07-31 03:27 217088 -c--a-w- c:\windows\Alcrmv.exe
2009-11-27 08:25 . 2009-10-29 10:57 105472 -c--a-w- c:\windows\PreConvert.dll
2009-11-27 08:24 . 2009-11-28 20:32 -------- d-----w- c:\programmi\Simpo PDF Creator
2009-11-27 08:23 . 2009-11-15 08:55 2064152 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgcorex.dll
2009-11-27 08:23 . 2009-11-15 08:54 3513624 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgui.exe
2009-11-27 08:23 . 2009-11-15 08:54 2028312 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgtray.exe
2009-11-25 16:55 . 2009-11-25 16:55 -------- dc----w- c:\windows\SysResources Manager
2009-11-25 16:55 . 2009-11-26 07:30 -------- d-----w- c:\programmi\SysResources Manager
2009-11-22 20:50 . 2009-12-07 19:14 -------- dc----w- c:\documents and settings\Administrator\Dati applicazioni\vlc
2009-11-20 00:03 . 2009-11-20 00:03 -------- dc----w- c:\documents and settings\All Users\Dati applicazioni\explauncher
2009-11-15 13:00 . 2009-03-30 14:58 7 -c--a-w- c:\windows\sysres10.dat
2009-11-13 14:55 . 2009-11-13 14:55 -------- dc----w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GWSoftware
2009-11-13 11:35 . 2009-11-13 11:36 -------- dc----w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 19:50 . 2008-03-22 07:32 4212 -c-ha-w- c:\windows\system32\zllictbl.dat
2009-12-07 19:22 . 2008-03-30 16:57 -------- dc----w- c:\documents and settings\Administrator\Dati applicazioni\uTorrent
2009-12-07 19:07 . 2008-07-04 12:56 -------- dc----w- c:\programmi\PeerGuardian2
2009-12-07 01:56 . 2009-12-07 07:29 2712576 -c--a-w- c:\windows\Internet Logs\xDB3A.tmp
2009-12-06 23:48 . 2009-08-24 09:55 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-12-06 23:10 . 2008-03-28 18:03 -------- dc----w- c:\programmi\FlashGet
2009-12-06 22:31 . 2009-12-06 22:31 16 -c--a-w- c:\windows\system32\config\systemprofile\Dati applicazioni\fvgqad.dat
2009-12-06 22:31 . 2009-12-06 22:31 4 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\avdrn.dat
2009-12-06 18:46 . 2009-08-27 09:13 48 -c--a-w- c:\windows\wpd99.drv
2009-12-06 18:46 . 2008-04-10 11:21 -------- dc----w- c:\documents and settings\All Users\Dati applicazioni\pdf995
2009-12-03 23:29 . 2008-06-28 18:59 -------- dc----w- c:\programmi\AVG
2009-12-03 23:27 . 2008-06-28 18:59 -------- dc----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-12-03 15:14 . 2009-08-24 09:55 38224 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 15:13 . 2009-08-24 09:55 19160 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-11-30 19:21 . 2009-11-30 19:28 8192 -c--a-w- c:\windows\Internet Logs\xDB38.tmp
2009-11-30 19:10 . 2009-11-30 19:21 36352 -c--a-w- c:\windows\Internet Logs\xDB36.tmp
2009-11-30 19:10 . 2009-11-30 19:28 2791424 -c--a-w- c:\windows\Internet Logs\xDB39.tmp
2009-11-30 19:10 . 2009-11-30 19:22 2791424 -c--a-w- c:\windows\Internet Logs\xDB37.tmp
2009-11-30 19:03 . 2008-12-08 10:50 -------- dc----w- c:\programmi\AvRack
2009-11-30 15:07 . 2008-03-21 20:30 -------- dc----w- c:\programmi\C-Media 3D Audio
2009-11-30 14:21 . 2009-11-30 14:21 102240 -c--a-w- c:\windows\Internet Logs\vsmon_2nd_2009_11_30_15_13_03_small.dmp.zip
2009-11-30 14:12 . 2009-11-30 14:16 960512 -c--a-w- c:\windows\Internet Logs\xDB35.tmp
2009-11-30 11:10 . 2009-11-30 11:30 2944000 -c--a-w- c:\windows\Internet Logs\xDB33.tmp
2009-11-30 11:10 . 2009-11-30 11:30 2788864 -c--a-w- c:\windows\Internet Logs\xDB34.tmp
2009-11-30 10:17 . 2008-11-14 14:00 -------- dc----w- c:\documents and settings\Administrator\Dati applicazioni\Skype
2009-11-30 10:07 . 2008-04-04 10:19 -------- dc----w- c:\documents and settings\Administrator\Dati applicazioni\skypePM
2009-11-24 12:03 . 2008-09-10 06:51 -------- dc----w- c:\programmi\winfax
2009-11-15 13:07 . 2009-03-02 17:40 -------- dc----w- c:\programmi\DebugMode
2009-11-13 14:21 . 2008-04-01 13:57 -------- dc----w- c:\programmi\GWSoftware
2009-11-06 19:15 . 2009-11-07 13:44 2780160 -c--a-w- c:\windows\Internet Logs\xDB32.tmp
2009-11-01 18:58 . 2009-01-10 01:28 -------- dc----w- c:\documents and settings\Administrator\Dati applicazioni\dvdcss
2009-11-01 18:58 . 2008-08-27 16:40 -------- dc----w- c:\programmi\AudioConvert
2009-11-01 18:48 . 2008-08-27 16:50 3126 -c--a-w- c:\windows\system32\tempimg.tmp
2009-11-01 09:09 . 2009-11-01 09:12 3041280 -c--a-w- c:\windows\Internet Logs\xDB30.tmp
2009-11-01 09:09 . 2009-11-01 09:12 2688512 -c--a-w- c:\windows\Internet Logs\xDB31.tmp
2009-10-25 06:55 . 2001-08-31 15:00 79172 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 06:55 . 2001-08-31 15:00 458528 ----a-w- c:\windows\system32\perfh010.dat
2009-10-22 18:01 . 2009-10-22 18:01 -------- d-----w- c:\programmi\IZArc
2009-10-20 17:43 . 2009-08-17 14:54 -------- d-----w- c:\programmi\EarthWatcher
2009-10-20 12:33 . 2009-10-30 13:46 103424 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-10-20 12:33 . 2009-10-30 13:45 545280 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-10-20 12:33 . 2009-10-30 13:45 4716544 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\piclens@cooliris.com\components\cooliris.dll
2009-10-20 12:33 . 2009-10-30 13:45 344064 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-10-20 12:33 . 2009-10-30 13:45 153600 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2009-10-17 08:32 . 2008-10-29 09:20 -------- dc----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-10-17 08:31 . 2008-10-29 09:20 -------- dc----w- c:\programmi\NOS
2009-10-14 15:14 . 2009-10-14 15:14 -------- d-----w- c:\programmi\AnVir Task Manager
2009-09-23 14:37 . 2009-10-17 08:30 34112 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-09-23 14:37 . 2009-10-17 08:30 32448 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-09-23 14:37 . 2009-10-17 08:30 22352 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-09-23 08:25 . 2009-09-23 08:25 1924440 -c--a-w- c:\documents and settings\Administrator\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-09-14 07:52 . 2009-07-05 17:08 11952 -c--a-w- c:\windows\system32\avgrsstx.dll
2009-09-14 07:52 . 2009-07-05 17:07 335240 -c--a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-14 07:52 . 2009-07-05 17:07 27784 -c--a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-11 17:26 . 2009-09-12 09:34 2847744 -c--a-w- c:\windows\Internet Logs\xDB2F.tmp
2008-12-02 23:47 . 2008-09-30 16:45 48 --sh--w- c:\windows\SAAA4EF1E.tmp
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkinClock"="c:\programmi\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-09-11 1739264]
"ATnotes.exe"="c:\programmi\ATnotes\ATnotes.exe" [2005-01-05 1015808]
"EarthWatcher"="c:\programmi\EarthWatcher\EarthWatcher.exe" [2002-12-13 612864]
"SysResources Manager"="c:\programmi\SysResources Manager\SysResManager.exe" [2009-11-15 598016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DSLAGENTEXE"="dslagent.exe" [2002-03-07 16384]
"WinPatrol"="c:\programmi\BillP Studios\WinPatrol\winpatrol.exe" [2008-07-04 333120]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-25 13680640]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"mouseElf"="c:\progra~1\Genius NetScroll+ Optical Mouse\GNETMOUS.EXE" [2003-05-13 163840]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-27 2029336]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2006-08-16 503808]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= "c:\programmi\winfax\WfxSeh32.Dll" [1998-07-27 38400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-14 07:52 11952 -c--a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2006-08-02 21:12 577536 -c--a-w- c:\windows\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Samsung PanelMgr"=c:\windows\Samsung\PanelMgr\ssmmgr.exe /autorun
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe"
"Device Detector"=DevDetect.exe -autorun
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\FlashGet\\FlashGet.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\Genius NetScroll+ Optical Mouse\\gnetmous.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
R0 vax347s;vax347s;c:\windows\system32\drivers\vax347s.sys [29/01/2009 22.49.36 5248]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [05/07/2009 18.07.50 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [05/07/2009 18.08.01 108552]
R1 GhPciScan;GhostPciScanner;c:\programmi\Symantec\Norton Ghost 2003\GhPciScan.sys [14/08/2002 14.11.16 5632]
R1 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\OXSER.SYS [28/04/2003 9.31.18 51169]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [05/07/2009 18.07.11 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [05/07/2009 18.07.06 297752]
R3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [05/07/2008 10.04.18 129535]
S0 vax347b;vax347b;c:\windows\system32\drivers\vax347b.sys [29/01/2009 22.49.36 159616]
S2 gafwload;D-Link DSL-200 USB ADSL Loader;c:\windows\system32\drivers\gafwload.sys [21/03/2008 21.24.14 27147]
S2 PMJ151NM;Panasonic DVC Web Camera;c:\windows\system32\DRIVERS\PMJ151NM.sys --> c:\windows\system32\DRIVERS\PMJ151NM.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [24/08/2009 10.55.46 38224]
S3 MTDVC;Panasonic DVC USB-SERIAL Driver for NT Technology;c:\windows\system32\DRIVERS\mtdv2ku1.sys --> c:\windows\system32\DRIVERS\mtdv2ku1.sys [?]
S3 MTDVC_ENUM;Panasonic DVC COM Driver for NT Technology;c:\windows\system32\DRIVERS\mtdv2ks1.sys --> c:\windows\system32\DRIVERS\mtdv2ks1.sys [?]
S4 ASKService;ASKService;c:\programmi\AskBarDis\bar\bin\AskService.exe [12/01/2009 10.01.50 464264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Scarica con FlashGet - c:\programmi\FlashGet\jc_link.htm
IE: &Scarica tutto con FlashGet - c:\programmi\FlashGet\jc_all.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {7C7EED03-01F2-4D56-9865-22F85A8B5B19} = 193.121.150.2,212.247.152.2
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.it/s/v/56.12/uploader2.cab
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://it.giveawayoftheday.com/
FF - plugin: c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\tkh5vx6q.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\np_gp.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npOGAPlugin.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-swg - c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
AddRemove-Mozilla Firefox (3.0.10) - f:\browser\FirefoxPortable\App\firefox\uninstall\helper.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-07 21:26
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2009-12-07 21:30
ComboFix-quarantined-files.txt 2009-12-07 20:30
ComboFix2.txt 2009-08-24 21:50
Pre-Run: 620.806.144 byte disponibili
Post-Run: 587.874.304 byte disponibili
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - E80AEB1E65E7C5B6CD3F9555F4E2AE76