Malwarebytes ha rimosso una trentina di schifezze, tra rootkit e porcherie varie, ora il pc sembra funzionare, prima non mi faceva nemmeno partire l'antivirus, apriva programmi da solo, mi aveva installato un falso antivirus che mi consigliava di scaricare un softwre di sicurezza, ora resta il problema che anche quando installo un'antivirus mi dice che c'è gia un software attivo (Antivir Desktop) e che si sconsiglia di utilizzarli entrambi. Grazie infinite.
Ecco il log aggiornato:
ComboFix 10-03-05.03 - Utente 06/03/2010 14.49.52.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1789.1250 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Utente\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {00000000-EE24-0012-5251-927CA0101600}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-14EF-9D7C08000A00}
FILE ::
"c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgcorex.dll"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\avg8
c:\documents and settings\All Users\Dati applicazioni\avg8\Cfg\erd.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\Cfg\krnl.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\Cfg\mail.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\Cfg\scan.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\Cfg\sched.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\Cfg\update.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\Cfg\user.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\cfgall\changecfgreg.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\cfgall\updateall.cfg
c:\documents and settings\All Users\Dati applicazioni\avg8\emc\Log\emc.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcfg.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcfg.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcfg.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcfg.log.4
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcfg.log.5
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcfg.log.6
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcfg.log.7
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcfg.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.10
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.4
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.5
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.6
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.7
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.8
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.9
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgcore.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgldr.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgldr.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgldr.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avglng.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avglng.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avglng.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avglng.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avglng.log.4
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avglng.log.5
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avglng.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgns.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgns.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgns.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgns.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgns.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.10
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.4
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.5
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.6
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.7
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.8
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.9
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgrs.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgscan.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgscan.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.10
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.4
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.5
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.6
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.7
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.8
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.9
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsched.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsrm.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgsrm.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgui.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgui.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgui.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgui.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgui.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgupd.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgupd.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgupd.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgupd.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.10
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.4
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.5
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.6
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.7
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.8
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.9
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwd.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwdsvc.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwdsvc.log.1
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwdsvc.log.2
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwdsvc.log.3
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwdsvc.log.4
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avgwdsvc.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\avildr.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\commonpriv.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\commonpriv.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\fixcfg.log
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\fixcfg.log.lock
c:\documents and settings\All Users\Dati applicazioni\avg8\Log\history.xml
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000001.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000003.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000005.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000006.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000007.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000008.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000009.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000010.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000011.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000012.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000013.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000014.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000015.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000016.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000017.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000018.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000019.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000020.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000021.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000022.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000023.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000024.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000025.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000026.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\I_00000027.log
c:\documents and settings\All Users\Dati applicazioni\avg8\scanlogs\srm.idx
c:\documents and settings\All Users\Dati applicazioni\avg8\temp\a92fce4c-ec33-4c91-91a9-8a190bc97f7a-57c-oopp.tmp
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgcorex.dll
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgfree_us.mht
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgtray.exe
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgui.exe
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\incavi.avm
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\microavi.avg
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\sb.dat
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\sb2.dat
c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\sc.dat
c:\documents and settings\All Users\Dati applicazioni\avg8\update\prepare\incavi.avm
c:\documents and settings\All Users\Dati applicazioni\avg8\update\prepare\sb.dat.prepare
c:\documents and settings\All Users\Dati applicazioni\avg8\update\prepare\sc.dat.prepare
.
((((((((((((((((((((((((( Files Creati Da 2010-02-06 al 2010-03-06 )))))))))))))))))))))))))))))))))))
.
2010-03-06 12:46 . 2010-03-06 12:46 -------- d-----w- c:\programmi\Trend Micro
2010-03-06 12:00 . 2010-03-06 12:09 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-03-06 11:51 . 2010-03-06 11:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-06 11:49 . 2010-03-06 11:49 152576 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2010-03-06 11:49 . 2010-03-06 11:49 79488 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-06 11:45 . 2010-03-06 11:45 -------- d-----w- c:\programmi\VS Revo Group
2010-03-06 11:22 . 2010-02-15 10:24 369952 ----a-w- c:\windows\system32\yk51x86.dll
2010-03-06 11:03 . 2010-03-06 11:03 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2010-03-06 11:03 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-06 11:03 . 2010-03-06 11:03 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-03-06 11:03 . 2010-03-06 11:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-03-06 11:03 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-06 11:50 . 2008-10-11 13:52 -------- d-----w- c:\programmi\Java
2010-03-06 10:32 . 2006-03-02 11:00 850390 ----a-w- c:\windows\system32\perfh010.dat
2010-03-06 10:32 . 2006-03-02 11:00 288430 ----a-w- c:\windows\system32\perfc010.dat
2010-02-26 15:50 . 2008-10-11 13:55 1 ----a-w- c:\documents and settings\Utente\Dati applicazioni\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-02-26 15:50 . 2008-10-11 13:55 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\OpenOffice.org2
2010-02-15 10:24 . 2008-04-04 08:57 304928 ----a-w- c:\windows\system32\drivers\yk51x86.sys
2010-01-21 13:34 . 2010-01-21 13:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MumboJumbo
2010-01-21 13:31 . 2010-01-21 13:31 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Trymedia
2010-01-21 13:30 . 2010-01-21 13:30 -------- d-----w- c:\programmi\MumboJumbo
2010-01-10 12:16 . 2010-01-10 12:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Absolutist
2010-01-06 19:17 . 2010-01-06 19:17 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\CyberLink
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\documents and settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]
"QuickTrans"="c:\programmi\Power Translator\Applications\QuickTrans.exe" [2005-09-12 2195456]
"L09IXLRD_7154687"="c:\programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" [2009-03-06 351000]
"MsnMsgr"="c:\programmi\MSN Messenger\MsnMsgr.Exe" [2007-09-04 6856704]
"Advanced SystemCare 3"="c:\programmi\IObit\Advanced SystemCare 3\AWC.exe" [2009-11-20 2335880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2008-04-04 1044480]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1040384]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2010-03-06 149280]
"hpWirelessAssistant"="c:\programmi\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2008-11-5 212992]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"wmsnmsgrs.exe"= wmsnmsgrs.exe:Messenger Update
R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [26/10/2007 18.25.14 174600]
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [11/10/2008 13.16.54 24064]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [04/11/2008 19.26.22 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [04/11/2008 19.26.22 3072]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys --> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [21/06/2007 3.40.02 56448]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = hxxp://go.divx.com/divx/webplayerdemo/en?yrv=1&yoc=divx&ydt=divxdotcom&ybt=DFW&ybv=6.8&yo=ietyie7
uInternet Settings,ProxyOverride = 127.0.0.1
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-06 14:52
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2010-03-06 14:53:57
ComboFix-quarantined-files.txt 2010-03-06 13:53
ComboFix2.txt 2010-03-06 12:37
Pre-Run: 37.296.685.056 byte disponibili
Post-Run: 37.280.468.992 byte disponibili
- - End Of File - - 0FF21EBCBA2B310AEA8E0A3DBBC62B3F