Ho installato Combofix e questo è il report:
ComboFix 10-01-25.06 - C.S.I.Gaiola 26/01/2010 15.02.09.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1023.569 [GMT 1:00]
Eseguito da: c:\documents and settings\C.S.I.Gaiola\Desktop\toto.exe
AV: avast! antivirus 4.8.1368 [VPS 100125-2] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall Pro *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\4.tmp
c:\windows\d.ini
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\system32\mswins.sys
.
((((((((((((((((((((((((( Files Creati Da 2009-12-26 al 2010-01-26 )))))))))))))))))))))))))))))))))))
.
2010-01-23 15:39 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-23 15:39 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-23 15:39 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-23 15:39 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-01-23 15:39 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-23 15:39 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-23 15:39 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-23 15:39 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-23 15:38 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-23 15:38 . 2010-01-23 15:38 -------- d-----w- c:\programmi\Alwil Software
2010-01-22 18:18 . 2010-01-22 18:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-01-17 13:25 . 2010-01-17 13:25 -------- d-----w- c:\documents and settings\C.S.I.Gaiola\Dati applicazioni\Malwarebytes
2010-01-17 13:25 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-17 13:25 . 2010-01-17 13:25 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-17 13:25 . 2010-01-17 13:25 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-01-17 13:25 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-17 12:20 . 2010-01-17 12:20 -------- d-----w- c:\programmi\Trend Micro
2010-01-17 12:20 . 2010-01-17 12:20 -------- d-----w- c:\documents and settings\LocalService\Menu Avvio
2010-01-16 12:07 . 2010-01-17 12:08 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-16 12:07 . 2010-01-16 12:07 -------- d-----w- c:\programmi\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-22 18:12 . 2007-02-03 14:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-01-17 12:20 . 2008-12-09 10:33 -------- d-----w- c:\programmi\TeaTimer (Spybot - Search & Destroy)
2010-01-16 12:16 . 2009-12-10 09:13 923167 --sha-w- c:\windows\system32\mswins.DLL
2009-12-03 12:05 . 2005-07-25 08:12 -------- d-----w- c:\programmi\MSN Messenger
2008-02-01 12:17 . 2008-02-01 12:17 2700345 ----a-w- c:\programmi\ccleaner.zip
2008-02-01 12:13 . 2008-02-01 12:13 651276 ----a-w- c:\programmi\Recuva.zip
2007-12-22 12:09 . 2006-05-11 08:49 66408 ----a-w- c:\programmi\mozilla firefox\components\jar50.dll
2007-12-22 12:09 . 2006-05-11 08:49 54112 ----a-w- c:\programmi\mozilla firefox\components\jsd3250.dll
2007-12-22 12:09 . 2007-12-22 12:09 34688 ----a-w- c:\programmi\mozilla firefox\components\myspell.dll
2007-12-22 12:09 . 2007-12-22 12:09 46456 ----a-w- c:\programmi\mozilla firefox\components\spellchk.dll
2007-12-22 12:09 . 2006-05-11 08:49 171880 ----a-w- c:\programmi\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2004-08-19 1667584]
"pdfSaver3"="c:\programmi\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe" [2004-09-05 380928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\programmi\Intel\Intel Application Accelerator\iaanotif.exe" [2003-07-02 126976]
"SoundMAXPnP"="c:\programmi\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-08-25 4554752]
"nwiz"="nwiz.exe" [2004-08-25 921600]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-08-25 86016]
"StatusClient 2.6"="c:\programmi\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2004-02-27 61440]
"TomcatStartup 2.5"="c:\programmi\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-05-11 188416]
"HP Software Update"="c:\programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-01-07 49152]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\programmi\Ahead\InCD\InCD.exe" [2004-04-06 1298542]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-07-20 100056]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2006-10-20 185896]
"MMReminderService"="c:\programmi\Mindjet\MindManager 6\MMReminderService.exe" [2005-09-13 28672]
"COMODO Firewall Pro"="c:\programmi\COMODO\Firewall\cfp.exe" [2009-07-21 1481472]
"EPSON PictureMate 100"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAKE.EXE" [2005-05-06 98304]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2006-2-28 113664]
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
InterVideo WinCinema Manager.lnk - c:\programmi\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-7-4 184320]
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2007-7-5 118784]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [23/01/2010 16.39.50 114768]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [21/07/2009 15.10.20 81272]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [21/07/2009 15.10.20 23672]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [23/01/2010 16.39.50 20560]
R2 CAPI;CAPI 2.0 Service;c:\windows\system32\drivers\capi.sys [16/12/2004 23.20.11 27699]
R2 NDISCAPI;NDIS CAPI Service;c:\windows\system32\drivers\ndiscapi.sys [16/12/2004 23.20.11 26684]
R3 colmpa;PCI ISDN Card NDIS WAN Driver;c:\windows\system32\drivers\colmpa.sys [16/12/2004 23.20.10 304694]
R3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;c:\windows\system32\drivers\yukonx86.sys [16/12/2004 23.16.34 176256]
S2 QBaThg;QBaThg;"c:\programmi\File comuni\System\Gym.exe" --> c:\programmi\File comuni\System\Gym.exe [?]
S3 PIXMCV;JVC Communication PIX-MCV Driver;c:\windows\system32\drivers\pixmcvc.sys [19/06/2007 15.05.53 32000]
S3 PIXMCVA;JVC PIX-MCV Audio Capture;c:\windows\system32\drivers\pixmcva.sys [19/06/2007 15.07.13 28057]
S3 PIXMCVV;JVC PIX-MCV Video Capture;c:\windows\system32\drivers\pixmcvv.sys [19/06/2007 15.06.30 21081]
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-26 c:\windows\Tasks\Symantec NetDetect.job
- c:\programmi\Symantec\LiveUpdate\NDETECT.EXE [2005-07-20 12:57]
2010-01-25 c:\windows\Tasks\WebReg 20050526191953.job
- c:\programmi\Hewlett-Packard\hp LaserJet 1160_1320 series\WebReg\bin\hpqwrg.exe [2002-10-16 15:39]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
IE: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414YYITIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1F831FA9-42FC-11D4-95A6-0080AD30DCE1} - file://c:\programmi\AutoCAD 2002 Ita\InstFred.ocx
DPF: {AE563729-B4F5-11D4-A415-00108302FDFD} - file://c:\programmi\AutoCAD 2002 Ita\InstBanr.ocx
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://88.41.58.162/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\C.S.I.Gaiola\Dati applicazioni\Mozilla\Firefox\Profiles\2rk7hao6.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.google.itFF - component: c:\programmi\Mozilla Firefox\components\xpinstal.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{D1B60A35-CC7E-D197-7BAE-9A0CD05C324F} - (no file)
HKLM-Run-NWEReboot - (no file)
HKLM-Run-pdfSaver3 - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-26 15:08
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\QBaThg]
"ImagePath"="\"c:\programmi\File comuni\System\Gym.exe\""
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-583907252-1409082233-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\URLSearchHooks]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) ) (Everyone)
"{D1B60A35-CC7E-D197-7BAE-9A0CD05C324F}"=""
[HKEY_LOCAL_MACHINE\software\Microsoft\iscyc]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) ) (Everyone)
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
"{AA7CA5BE-E257-38B5-AAC1-9B8AF41AFD1A}"=""
[HKEY_LOCAL_MACHINE\software\Microsoft\kdivl]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) ) (Everyone)
.
Ora fine scansione: 2010-01-26 15:10:08
ComboFix-quarantined-files.txt 2010-01-26 14:10
Pre-Run: 98.147.942.400 byte disponibili
Post-Run: 98.403.418.112 byte disponibili
- - End Of File - - FFFAF73E2AD886EFE57D37EA85872F8B