Prima di tutto grazie per il suggerimento. Ho fatto come hai detto, ti posto il log. Spero di aver fatto tutto OK, però durante la fase di riavvio (comboFix non ancora terminato) mi ha riattivato sia il firewall che l'antivirus, ho dovuto quindi utilizzare il mouse per permettere l'accesso al firewall. Spero di non aver causato problemi.
Ciao e di nuovo grazie
ComboFix 12-04-07.02 - Utente 07/04/2012 12.46.23.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1977.1399 [GMT 2:00]
Eseguito da: G:\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {7698207D-3A40-003E-AC1D-9876381E9876}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {0012F2B4-5C49-7C92-0300-000000000000}
FW: Outpost Firewall *Enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Utente\Dati applicazioni\OfferBox
c:\documents and settings\Utente\Dati applicazioni\OfferBox\config.dat
c:\documents and settings\Utente\Dati applicazioni\OfferBox\config.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\1.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\a.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\b.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\c.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\d.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\e.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\f.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\g.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\h.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\i.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\J.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\k.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\l.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\m.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\mru.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\n.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\o.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\p.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\q.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\r.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\s.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\t.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\u.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\v.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\w.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\x.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\y.xml
c:\documents and settings\Utente\Dati applicazioni\PriceGong\Data\z.xml
c:\programmi\OfferBox
c:\programmi\OfferBox\OfferBoxBHO.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_NPF
.
.
((((((((((((((((((((((((( Files Creati Da 2012-03-07 al 2012-04-07 )))))))))))))))))))))))))))))))))))
.
.
2012-04-01 09:37 . 2012-04-07 10:42 -------- d-----w- c:\windows\system32\CatRoot2
2012-03-31 11:36 . 2012-03-31 11:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2012-03-29 20:25 . 2012-03-29 20:25 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Mozilla
2012-03-29 15:46 . 2012-03-29 15:54 -------- d-----w- c:\programmi\Eusing Free Registry Cleaner
2012-03-29 15:40 . 2009-04-06 09:37 704384 ----a-w- c:\windows\system32\drivers\SandBox.sys
2012-03-29 15:40 . 2009-02-10 14:15 257432 ----a-w- c:\windows\system32\drivers\afwcore.sys
2012-03-29 15:39 . 2009-02-18 15:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys
2012-03-29 15:39 . 2012-03-29 15:39 -------- d-----w- c:\programmi\Agnitum
2012-03-29 15:38 . 2012-03-29 16:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Agnitum
2012-03-29 10:35 . 2012-03-29 10:35 -------- d-----w- c:\windows\Downloaded Program Files
2012-03-29 08:37 . 2012-03-29 08:38 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\LockHunter
2012-03-28 17:08 . 2012-03-28 17:08 388096 ----a-r- c:\documents and settings\Utente\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-03-28 17:00 . 2012-03-28 17:00 -------- d-----w- c:\programmi\Trend Micro
2012-03-28 10:30 . 2012-03-29 09:59 -------- d-sh--w- c:\documents and settings\Utente\UserData
2012-03-28 10:30 . 2012-03-28 10:30 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\AskToolbar
2012-03-28 10:01 . 2012-03-29 19:42 -------- d-----w- c:\programmi\GridinSoft Trojan Killer
2012-03-28 09:58 . 2012-03-28 18:45 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\AskToolbar
2012-03-28 09:55 . 2012-03-28 09:55 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Avira
2012-03-28 09:49 . 2012-03-28 09:49 -------- d-----w- c:\programmi\Ask.com
2012-03-28 09:49 . 2012-03-28 09:49 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\APN
2012-03-28 09:49 . 2012-02-03 13:26 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-03-28 09:49 . 2012-02-03 13:26 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-03-28 09:49 . 2012-02-03 13:26 137416 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-03-28 09:49 . 2012-04-03 12:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2012-03-28 09:49 . 2012-03-28 09:49 -------- d-----w- c:\programmi\Avira
2012-03-27 21:03 . 2012-03-27 21:03 -------- d-----w- C:\TDSSKiller_Quarantine
2012-03-27 20:23 . 2012-04-07 10:52 -------- d-----w- c:\windows\system32\wbem\Logs
2012-03-27 20:05 . 2012-03-27 20:05 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\DriverCure
2012-03-27 20:05 . 2012-03-27 20:05 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\SpeedyPC Software
2012-03-27 20:05 . 2012-03-27 20:05 -------- d-----w- c:\programmi\SpeedyPC Software
2012-03-27 20:05 . 2012-03-27 20:05 -------- d-----w- c:\programmi\File comuni\SpeedyPC Software
2012-03-27 20:05 . 2012-03-27 20:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SpeedyPC Software
2012-03-25 15:17 . 2012-03-29 12:10 -------- d-----w- c:\programmi\Sunbelt Software
2012-03-23 17:40 . 2012-03-23 17:40 1491 ----a-w- C:\user.js
2012-03-23 17:40 . 2012-03-23 17:40 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Babylon
2012-03-23 17:40 . 2012-03-23 17:40 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Babylon
2012-03-23 17:40 . 2012-03-23 17:40 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Babylon
2012-03-18 11:12 . 2012-03-18 11:12 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2012-03-18 11:12 . 2012-03-18 11:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2012-03-18 11:12 . 2012-03-18 11:12 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2012-03-18 11:12 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-18 10:53 . 2012-03-18 11:04 -------- d-----w- c:\programmi\CCleaner
2012-03-18 10:48 . 2012-03-18 10:48 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Uniblue
2012-03-18 09:23 . 2012-03-18 09:23 -------- d-----w- c:\windows\system32\wbem\Repository
2012-03-18 08:33 . 2012-03-18 08:33 1409 ----a-w- c:\windows\QTFont.for
2012-03-16 19:37 . 2012-03-16 19:37 126976 --sha-r- c:\windows\system32\stdole2O.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-27 21:04 . 2008-04-14 12:00 188416 ----a-w- c:\windows\system32\drivers\acpi.sys
2012-02-03 09:57 . 2008-04-14 12:00 1860096 ----a-w- c:\windows\system32\win32k.sys
2012-01-11 19:06 . 2012-02-16 18:20 3072 ------w- c:\windows\system32\iacenc.dll
2012-01-09 16:20 . 2010-07-29 00:40 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-13 04:38 . 2012-03-29 20:24 97208 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-05-08 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-05-08 142872]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2009-03-05 1434920]
"MobileConnect"="c:\programmi\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2008-07-04 2072576]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2012-02-03 258512]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 00:38 34672 ----a-w- c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2008-03-21 08:21 91432 ----a-w- c:\programmi\CyberLink\Shared Files\brs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 07:27 153136 ----a-w- c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
2007-12-14 09:36 50472 ------w- c:\programmi\CyberLink\PowerDVD8\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
2008-03-20 18:23 83240 ------w- c:\programmi\CyberLink\PowerDVD8\PDVD8Serv.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\Halto\\Halto.exe"=
"c:\\Programmi\\File comuni\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Gestione remota Windows
"35453:TCP"= 35453:TCP:Windows Core Service
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [28/03/2012 11.49.21 36000]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [29/03/2012 17.40.44 704384]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\programmi\CyberLink\PowerDVD8\000.fcl [01/02/2008 17.24.04 41456]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [29/03/2012 17.39.13 1195008]
R2 AntiVirSchedulerService;Avira Pianificatore;c:\programmi\Avira\AntiVir Desktop\sched.exe [28/03/2012 11.49.21 86224]
R2 AntiVirWebService;Avira Web Protection;c:\programmi\Avira\AntiVir Desktop\avwebgrd.exe [28/03/2012 11.49.21 463824]
R2 VMCService;Vodafone Mobile Connect Service;c:\programmi\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [04/07/2008 13.52.18 14336]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [29/03/2012 17.39.16 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [29/03/2012 17.40.38 257432]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [08/04/2009 4.04.00 39424]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [01/08/2010 13.26.41 135664]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [01/08/2010 13.26.41 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\programmi\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\programmi\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [28/07/2010 22.41.18 164864]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;c:\windows\system32\drivers\gtkdrv.sys [04/01/2012 16.28.36 16128]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14/04/2008 14.00.00 14336]
S4 PowerOffer Service;Pos Service; [x]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-04-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-04-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-08-01 11:26]
.
2012-04-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-08-01 11:26]
.
2012-04-07 c:\windows\Tasks\QENLHE.job
- c:\windows\system32\stdole2O.dll [2012-03-16 19:37]
.
2012-04-07 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\programmi\Ask.com\UpdateTask.exe [2012-01-04 18:20]
.
2012-03-27 c:\windows\Tasks\SpeedyPC Pro.job
- c:\programmi\SpeedyPC Software\SpeedyPC\SpeedyPC.exe [2012-01-30 22:17]
.
2012-03-27 c:\windows\Tasks\SpeedyPC Registration3.job
- c:\programmi\File comuni\SpeedyPC Software\UUS3\UUS3.dll [2012-01-30 22:17]
.
2012-04-07 c:\windows\Tasks\SpeedyPC Update Version3.job
- c:\programmi\File comuni\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe [2012-01-30 22:17]
.
2012-04-07 c:\windows\Tasks\User_Feed_Synchronization-{178E7CA2-C96E-4B01-BA5A-25D4EBF220CE}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = *.local
LSP: c:\programmi\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{843962A3-82E9-4683-9EA3-B933DD1EACF3}: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\7p24sv4v.default\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-42858495.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-04-07 12:56
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\programmi\CyberLink\PowerDVD8\000.fcl"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'lsass.exe'(1208)
c:\programmi\Avira\AntiVir Desktop\avsda.dll
.
- - - - - - - > 'explorer.exe'(3648)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\igfxsrvc.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2012-04-07 12:58:34 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-04-07 10:58
.
Pre-Run: 43.198.930.944 byte disponibili
Post-Run: 43.267.641.344 byte disponibili
.
- - End Of File - - F5B43D397A24CD8BB0C5AB1795234768