Ok, la scansione con Malawarebytes ha trovato 1 file infetto che ho cancellato, dopo ho riavviato.Ecco il log
Malwarebytes' Anti-Malware 1.41
Versione del database: 3105
Windows 5.1.2600 Service Pack 2
05/11/2009 19.21.44
mbam-log-2009-11-05 (19-21-37).txt
Tipo di scansione: Scansione completa (C:\|D:\|F:\|)
Elementi scansionati: 180322
Tempo trascorso: 2 hour(s), 11 minute(s), 0 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 1
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
C:\WINDOWS\system32\idm.dat (Malware.Trace) -> No action taken.
E' lo stesso della precedente scansione che avevo eliminato!
Questo il log di Combofix, speriamo sia integrale
ComboFix 09-11-03.03 - RITA 05/11/2009 19.54.55.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1023.609 [GMT 1:00]
Eseguito da: c:\documents and settings\RITA\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\RITA\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
FILE ::
"c:\windows\system32\fcd.dat"
"c:\windows\system32\kpcfer.dll"
"c:\windows\system32\qsf.dat"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\fcd.dat
c:\windows\system32\idm.dat
c:\windows\system32\kpcfer.dll
c:\windows\system32\qsf.dat
.
((((((((((((((((((((((((( Files Creati Da 2009-10-05 al 2009-11-05 )))))))))))))))))))))))))))))))))))
.
2009-11-05 18:33 . 2009-11-05 18:33 5112 ----a-w- c:\windows\system32\lk.dat
2009-11-05 13:25 . 2009-11-05 18:29 45 ----a-w- c:\windows\system32\pog.dat
2009-11-04 16:18 . 2003-12-09 07:43 45568 ----a-w- c:\windows\system32\drivers\SiSRaid.sys
2009-11-03 19:40 . 2009-11-03 19:46 -------- d-----w- c:\documents and settings\RITA\Dati applicazioni\vlc
2009-11-02 23:51 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2009-11-01 19:47 . 2009-11-01 19:51 -------- dc-h--w- c:\windows\ie8
2009-10-26 22:19 . 2009-10-26 22:19 -------- d-----w- c:\documents and settings\RITA\Dati applicazioni\Malwarebytes
2009-10-26 22:19 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-26 22:19 . 2009-10-26 22:19 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-10-26 22:19 . 2009-10-26 22:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-10-26 22:19 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-26 20:39 . 2009-11-01 20:11 -------- d-----w- c:\programmi\ImageShackToolbar
2009-10-26 19:48 . 2009-10-26 19:48 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-26 13:32 . 2009-10-26 13:32 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-15 21:12 . 2009-10-15 21:13 -------- d-----w- c:\programmi\Ulead GIF-X.Plugin 2.0
2009-10-15 21:05 . 2009-10-15 21:05 -------- d-----w- c:\programmi\Ulead Particle.Plugin
2009-10-15 20:59 . 1995-10-21 08:37 35328 ------w- c:\windows\INETWH32.DLL
2009-10-15 20:59 . 1995-10-16 14:55 9136 ------w- c:\windows\INETWH16.DLL
2009-10-15 20:59 . 1995-10-13 14:28 4528 ------w- c:\windows\SETBROWS.EXE
2009-10-15 20:59 . 1995-07-19 22:00 26832 ------w- c:\windows\CTL3DV2.DLL
2009-10-15 20:59 . 2009-10-15 20:59 -------- d-----w- c:\programmi\Ulead FantasyWarp.Plugin
2009-10-12 21:51 . 2009-10-12 21:51 -------- d-----w- c:\programmi\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-03 18:57 . 2009-03-20 19:33 -------- d-----w- c:\documents and settings\RITA\Dati applicazioni\uTorrent
2009-10-26 17:35 . 2009-02-12 15:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-10-25 03:03 . 2001-08-31 14:00 79406 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 03:03 . 2001-08-31 14:00 479166 ----a-w- c:\windows\system32\perfh010.dat
2009-10-04 11:53 . 2009-10-04 11:53 -------- d-----w- c:\programmi\CCleaner
2009-10-01 08:29 . 2009-10-02 19:00 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-27 09:51 . 2009-02-15 10:17 -------- d-----w- c:\documents and settings\RITA\Dati applicazioni\LimeWire
2009-09-24 22:32 . 2009-02-03 20:41 -------- d-----w- c:\documents and settings\RITA\Dati applicazioni\dvdcss
2009-09-11 17:43 . 2009-02-02 20:51 -------- d-----w- c:\programmi\Symantec
2009-09-11 17:43 . 2009-02-02 20:51 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-09-11 17:43 . 2009-02-02 20:51 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-09-11 17:43 . 2009-02-01 19:37 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-09-11 17:43 . 2009-02-01 19:37 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-09-11 14:34 . 2001-08-31 14:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45 . 2001-08-31 14:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2001-08-31 14:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:14 . 2001-08-31 14:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 19:57 . 2009-08-25 19:57 3414 ----a-w- c:\programmi\GrObjects.ini
2009-08-25 19:57 . 2009-08-25 19:50 529 ----a-w- c:\programmi\param.ini
2009-08-22 07:21 . 2009-02-02 20:51 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-08-20 13:09 . 2009-08-20 13:09 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-08 12:57 . 2009-02-01 23:11 45744 ----a-w- c:\documents and settings\RITA\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-02-08 14:26 . 2009-02-08 14:24 1056 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((
SnapShot@2009-11-04_16.28.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-05 13:22 . 2009-11-05 13:22 16384 c:\windows\Temp\Perflib_Perfdata_1d8.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-12-18 3022848]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"Windows Defender"="c:\programmi\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-12-18 753664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
TrayMin300.exe.lnk - c:\programmi\Philips\SPC 200NC PC Camera\TrayMin200.exe [2009-2-1 278528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Photo Express Calendar Checker SE.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Photo Express Calendar Checker SE.lnk
backup=c:\windows\pss\Photo Express Calendar Checker SE.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11480:TCP"= 11480:TCP:BitComet 11480 TCP
"11480:UDP"= 11480:UDP:BitComet 11480 UDP
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1007020.00B\SymEFA.sys [09/09/2009 13.24.03 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1007020.00B\BHDrvx86.sys [09/09/2009 13.24.02 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1007020.00B\cchpx86.sys [09/09/2009 13.23.28 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091102.002\IDSXpx86.sys [28/10/2009 23.37.22 329592]
R2 Norton Internet Security;Norton Internet Security;c:\programmi\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe [09/09/2009 13.23.45 117640]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [03/11/2006 19.19.58 13592]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [01/11/2009 17.23.05 102448]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;"c:\programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe" --> c:\programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe [?]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-11-05 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
2009-11-05 c:\windows\Tasks\User_Feed_Synchronization-{9D6EEF3F-181C-4BA8-8EBB-0B5E46A9DF57}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.virgilio.it/
IE: Post Image to Blog - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5003
IE: Tag This Image - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5002
IE: Transload Image to ImageShack - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5004
IE: Upload All Images to ImageShack - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5000
IE: Upload Image to ImageShack - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5001
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{D7C2854D-9515-4E70-BDE7-A57C7B48BBFA} - kpcfer.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-05 20:00
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\programmi\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\programmi\Norton Internet Security\Engine\16.7.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140710900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\l3codeca.acm
.
Ora fine scansione: 2009-11-05 20.02.39
ComboFix-quarantined-files.txt 2009-11-05 19:02
ComboFix2.txt 2009-11-04 16:30
Pre-Run: 8.962.248.704 byte disponibili
Post-Run: 8.931.155.968 byte disponibili
Grazie!