OK GRAZIE.
Intanto ho fatto andare il combofix e questo è il log. Che dici?
ComboFix 08-05-12.1 - Frankie 2008-05-14 7.33.46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.70 [GMT 2:00]
Eseguito da: C:\Programmi\Accessori\ComboFix.exe
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\fad.sys
.
((((((((((((((((((((((((( Files Creati Da 2008-04-14 al 2008-05-14 )))))))))))))))))))))))))))))))))))
.
2008-05-14 07:18 . 2008-05-14 07:18 488 --a------ C:\hpfr3420.xml
2008-05-14 07:14 . 2008-05-14 07:14 <DIR> d-------- C:\Programmi\Hewlett-Packard
2008-05-14 07:14 . 2008-05-14 07:14 82,380 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
2008-05-14 07:11 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-05-14 07:11 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-05-14 07:10 . 2008-05-14 07:10 <DIR> d-------- C:\Programmi\File comuni\Hewlett-Packard
2008-05-14 07:08 . 2008-05-14 07:14 20,448 --a------ C:\WINDOWS\hpoins01.dat
2008-05-14 07:08 . 2003-04-05 14:33 16,622 --------- C:\WINDOWS\hpomdl01.dat
2008-05-14 07:06 . 2008-05-14 07:11 <DIR> d-------- C:\WINDOWS\LastGood
2008-05-14 07:05 . 2001-08-08 11:45 2,641,973 --a------ C:\WINDOWS\system32\opapi11.dll
2008-05-14 07:05 . 2001-08-07 13:54 74,665 --a------ C:\WINDOWS\system32\openpage.msg
2008-05-14 07:05 . 2008-05-14 07:05 0 --a------ C:\WINDOWS\OPPRIN~1.INI
2008-05-14 07:04 . 2008-05-14 07:07 <DIR> d-------- C:\Programmi\Canon
2008-05-14 07:02 . 2008-05-14 07:02 <DIR> d-------- C:\Documents and Settings\Frankie\WINDOWS
2008-05-11 20:48 . 2008-05-11 20:48 <DIR> d-------- C:\Documents and Settings\Frankie\Dati applicazioni\Hewlett-Packard
2008-05-11 17:50 . 2008-05-11 17:50 <DIR> dr------- C:\Documents and Settings\NetworkService\Preferiti
2008-05-11 17:50 . 2008-05-11 17:50 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-11 17:02 . 2008-05-11 17:02 <DIR> d-------- C:\Programmi\Lavasoft
2008-05-11 16:26 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-05-11 16:26 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-05-11 16:26 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-05-11 16:26 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2008-05-11 16:26 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2008-05-11 16:26 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2008-05-11 16:26 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-05-11 16:25 . 2008-05-11 16:54 <DIR> d-------- C:\Programmi\File comuni\Wise Installation Wizard
2008-05-10 07:59 . 2005-06-28 09:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-05-10 06:46 . 2008-05-11 20:06 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-05-09 07:21 . 2008-05-09 07:21 <DIR> d-------- C:\Documents and Settings\Frankie\Dati applicazioni\Logitech
2008-05-09 07:18 . 2008-05-09 07:18 <DIR> d-------- C:\Programmi\File comuni\Logitech
2008-05-09 07:18 . 2005-05-25 02:40 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-05-09 07:18 . 2005-05-25 02:40 1,047,552 --a------ C:\WINDOWS\system32\MFC71u.dll
2008-05-09 07:18 . 2005-05-25 02:40 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-05-09 07:18 . 2005-05-25 02:40 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-05-09 07:18 . 2005-05-25 02:40 258,352 --a------ C:\WINDOWS\system32\unicows.dll
2008-05-09 07:18 . 2005-05-25 02:40 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-05-09 07:16 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-05-09 07:16 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-05-09 07:16 . 2004-08-19 15:39 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-05-09 07:16 . 2004-08-19 15:39 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-05-09 07:16 . 2004-08-19 15:30 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-05-09 07:16 . 2004-08-19 15:30 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-05-09 07:16 . 2001-08-30 20:41 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-05-09 07:16 . 2001-08-30 20:41 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-05-09 07:16 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-05-09 07:16 . 2001-08-17 22:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-05-08 16:30 . 2008-05-08 16:52 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-05-08 16:27 . 2008-05-11 17:02 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-05-08 16:26 . 2008-05-08 19:17 39,808 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-05-08 16:25 . 2008-05-11 17:48 <DIR> d-------- C:\VEXPLITE
2008-05-08 16:25 . 2008-05-08 16:25 <DIR> d-------- C:\Programmi\VirIT eXplorer Lite
2008-05-08 15:12 . 2008-05-08 15:12 <DIR> d-------- C:\Programmi\ADOBE Acrobat 5 ITA full version (Reader, Writer, Distiller)
2008-05-08 15:10 . 2008-05-08 15:10 <DIR> d-------- C:\Documents and Settings\Frankie\Dati applicazioni\Leadertech
2008-05-08 15:08 . 2008-05-08 15:08 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-05-08 15:08 . 1993-07-23 00:00 210,944 --a------ C:\WINDOWS\system32\Msvcrt10.dll
2008-05-08 15:08 . 2001-04-27 14:02 101,200 --a------ C:\WINDOWS\system32\pdfshell.dll
2008-05-08 15:08 . 2001-03-15 08:18 65,536 --a------ C:\WINDOWS\system32\adistres.dll
2008-05-08 15:08 . 2001-03-15 08:18 20,584 --a------ C:\WINDOWS\system32\PdfPorts.dll
2008-05-08 15:08 . 2001-05-18 02:08 12,288 --a------ C:\WINDOWS\system32\PDFShell.ITA
2008-05-08 15:05 . 2008-05-08 15:05 <DIR> d-------- C:\Documents and Settings\Frankie\Dati applicazioni\InterTrust
2008-05-08 14:47 . 2008-05-08 14:47 <DIR> d-------- C:\WINDOWS\system32\dla
2008-05-08 14:47 . 2008-05-08 14:47 <DIR> d-------- C:\Programmi\File comuni\Sonic
2008-05-08 14:47 . 2003-08-06 01:04 98,352 --a------ C:\WINDOWS\dla.exe
2008-05-08 14:47 . 2003-07-31 03:21 84,576 --a------ C:\WINDOWS\system32\drivers\drvmcdb.sys
2008-05-08 14:47 . 2003-08-06 01:04 61,492 --a------ C:\WINDOWS\system32\tfswapi.dll
2008-05-08 14:47 . 2003-06-20 02:56 40,448 --a------ C:\WINDOWS\system32\drivers\drvnddm.sys
2008-05-08 14:47 . 2003-07-14 11:28 23,219 --a------ C:\WINDOWS\system32\drivers\ssrtln.sys
2008-05-08 14:47 . 2003-07-14 11:28 5,621 --a------ C:\WINDOWS\system32\drivers\sscdbhk5.sys
2008-05-08 14:47 . 2008-05-08 14:47 138 --a------ C:\WINDOWS\wininit.ini
2008-05-08 14:46 . 2008-05-08 14:46 <DIR> d-------- C:\Programmi\File comuni\SureThing Shared
2008-05-08 13:01 . 2005-05-20 15:01 68,352 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys
2008-05-08 13:01 . 2005-05-20 15:00 54,528 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys
2008-05-08 13:01 . 2005-05-20 14:46 28,160 --a------ C:\WINDOWS\KHALMNPR.Exe
2008-05-08 13:01 . 2005-05-20 15:01 25,600 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys
2008-05-08 13:01 . 2005-05-20 15:00 13,056 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.sys
2008-05-08 13:00 . 2008-05-14 07:32 <DIR> d-------- C:\Programmi\Accessori
2008-05-08 12:34 . 2008-05-08 12:34 5,831,808 --a------ C:\Programmi\Firefox Setup 2.0.0.14.exe
2008-05-08 11:52 . 2008-05-08 11:52 <DIR> d-------- C:\WINDOWS\system32\InsFiles
2008-05-08 11:52 . 2003-04-02 13:25 538,925 -ra------ C:\WINDOWS\system32\drivers\torususb.sys
2008-05-08 11:52 . 2003-07-25 10:09 286,720 -ra------ C:\WINDOWS\system32\stmadsl.cpl
2008-05-08 11:52 . 2003-03-27 14:11 86,019 -ra------ C:\WINDOWS\stmtrace.exe
2008-05-08 11:52 . 2003-03-27 14:11 59,466 -ra------ C:\WINDOWS\system32\drivers\stmatm.sys
2008-05-08 11:50 . 2008-05-08 11:50 <DIR> d-------- C:\WINDOWS\Motive
2008-05-08 11:50 . 2008-05-08 11:50 <DIR> d-------- C:\Programmi\Motive
2008-05-08 11:50 . 2008-05-08 11:50 <DIR> d-------- C:\Programmi\HELPExpress
2008-05-08 11:50 . 2008-05-08 11:50 <DIR> d-------- C:\Programmi\Common Files
2008-05-08 11:05 . 2008-05-08 11:05 <DIR> d-------- C:\WINDOWS\Provisioning
2008-05-08 11:05 . 2008-05-08 11:11 <DIR> d-------- C:\WINDOWS\PeerNet
2008-05-08 11:05 . 2008-05-08 11:12 <DIR> d-------- C:\WINDOWS\ehome
2008-05-08 10:45 . 2008-05-08 10:45 <DIR> d-------- C:\Programmi\Broadcom
2008-05-08 10:45 . 2002-12-17 11:41 42,368 -ra------ C:\WINDOWS\system32\drivers\bcm4sbxp.sys
2008-05-08 10:41 . 1998-11-13 12:07 307,712 --a------ C:\WINDOWS\IsUn0410.exe
2008-05-08 10:39 . 2008-05-08 15:08 <DIR> d-------- C:\Programmi\File comuni\Adobe
2008-05-08 10:38 . 2008-05-08 10:38 8,407 --a------ C:\WINDOWS\system32\nvModes.dat
2008-05-08 10:38 . 2008-05-14 06:32 8,407 --a------ C:\WINDOWS\system32\nvModes.001
2008-05-08 10:36 . 2008-05-08 10:36 <DIR> d-------- C:\Programmi\Broadcom Advanced Control Suite
2008-05-08 10:34 . 2008-05-08 10:34 <DIR> d-------- C:\Programmi\Intel
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\Softwin
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\Sleep Manager
2008-05-08 10:32 . 2008-05-11 08:44 <DIR> d-------- C:\Programmi\Rescue Disk
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\QuickTime
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\QMgr
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\Plus!
2008-05-08 10:32 . 2008-05-10 06:47 <DIR> d-------- C:\Programmi\PCDR
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\Opera
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\OfficeUpdate11
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\Notebook Manager
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\Navnt
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\MUSICMATCH
2008-05-08 10:32 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\MSN Messenger
2008-05-08 10:31 . 2008-05-08 10:31 <DIR> d-------- C:\Programmi\Trust
2008-05-08 10:31 . 2008-05-10 06:46 <DIR> d-------- C:\Programmi\Transfer MyPC
2008-05-08 10:31 . 2008-05-08 10:31 <DIR> d-------- C:\Programmi\Tin.it
2008-05-08 10:31 . 2008-05-08 10:31 <DIR> d-------- C:\Programmi\Synaptics
2008-05-08 10:31 . 2008-05-08 10:31 <DIR> d-------- C:\Programmi\Symantec
2008-05-08 10:31 . 2008-05-08 10:31 <DIR> d-------- C:\Programmi\Sygate
2008-05-08 10:31 . 2008-05-08 10:31 <DIR> d-------- C:\Programmi\Spybot - Search & Destroy
2008-05-08 10:31 . 2008-05-08 10:31 <DIR> d-------- C:\Programmi\Speed Access USB
2008-05-08 10:31 . 2008-05-08 10:32 <DIR> d-------- C:\Programmi\Sonic
2008-05-08 10:24 . 2008-05-08 10:24 <DIR> d-------- C:\Programmi\Yahoo!
2008-05-08 10:24 . 2008-05-10 06:46 <DIR> d-------- C:\Programmi\Wisdom-soft ScreenHunter 5 Free
2008-05-08 10:24 . 2008-05-08 10:24 <DIR> d-------- C:\Programmi\WinMX
2008-05-08 10:24 . 2008-05-10 06:47 <DIR> d-------- C:\Programmi\vanBasco's Karaoke Player
2008-05-08 10:24 . 2005-01-29 14:31 9,228,440 --a------ C:\Programmi\spf.exe
2008-05-08 10:24 . 2005-02-12 11:18 7,683,569 --a------ C:\Programmi\nentitst.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 07:11 17 ----a-w C:\Programmi\stinger.opt
2008-05-11 07:04 499 ----a-w C:\Programmi\Collegamento a WinRAR.lnk
2008-05-08 09:49 155,995 ----a-w C:\WINDOWS\java\Packages\HB5BRDZN.ZIP
2008-05-07 09:58 --------- d-----w C:\Programmi\Servizi in linea
2008-05-04 09:44 522 ----a-w C:\Programmi\hpfr3420.xml
2008-05-04 09:44 177,174 ----a-w C:\Programmi\hpfr3425.log
2008-03-20 08:06 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:50 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:33 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:01 662,016 ----a-w C:\WINDOWS\system32\wininet.dll
2007-04-04 09:52 227 ----a-w C:\Programmi\gromozon_removal.log
2006-07-26 17:48 10,786 ----a-w C:\Programmi\release_notes.txt
2005-03-29 09:53 241 ----a-w C:\Programmi\stinger.txt
2005-02-23 13:27 56,320 ----a-w C:\Programmi\allegato.jhtml.doc
2005-01-29 20:56 8,263 ----a-w C:\Programmi\Uninst.isu
2004-05-02 21:28 15 ----a-w C:\Programmi\win2.log
2004-05-01 10:48 12 ----a-w C:\Programmi\win.log
2002-07-29 20:46 4,514 ----a-w C:\Programmi\SETUPXLG.TXT
2001-01-31 11:15 5,071 ----a-w C:\Programmi\Documento recuperato.txt
2000-11-21 16:02 70,008 ----a-w C:\Programmi\BOOTLOG.TXT
2000-04-24 11:40 225 ----a-w C:\Programmi\RESETLOG.TXT
2000-04-20 13:10 15,563 ----a-w C:\Programmi\NETLOG.TXT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 14:00 15360]
"Sonic RecordNow!"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 05:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"nwiz"="nwiz.exe" [2003-11-20 08:10 323584 C:\WINDOWS\system32\nwiz.exe]
"AdslTaskBar"="stmctrl.dll" [2003-03-27 14:11 151552 C:\WINDOWS\system32\stmctrl.dll]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-05-11 16:05 245760]
"SmcService"="C:\PROGRA~1\ACCESS~1\smc.exe" [2004-10-15 19:40 2577632]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 14:00 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Acrobat Assistant.lnk - C:\Programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2008-05-08 15:08:32 49254]
Logitech SetPoint.lnk - C:\Programmi\Accessori\SetPoint\SetPoint.exe [2008-05-08 13:01:57 450560]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"Logitech Hardware Abstraction Layer"=KHALMNPR.EXE
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe
"StorageGuard"="C:\Programmi\File comuni\Sonic\Update Manager\sgtray.exe" /r
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-05-08 19:17]
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-05-11 16:05]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2003-03-27 14:11]
S3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2003-04-02 13:25]
*Newly Created Service* - CATCHME
*Newly Created Service* - PML_DRIVER_HPZ12
.
Contenuto della cartella 'Scheduled Tasks'
"2008-05-14 05:15:38 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1210742096.job"
- C:\Programmi\Accessori\Digital Imaging\Bin\hpqfrucl.exe4-I
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-14 07:36:40
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Ora fine scansione: 2008-05-14 7.38.53
ComboFix-quarantined-files.txt 2008-05-14 05:38:49
14 Directory 62,915,584,000 byte disponibili
16 Directory 62,919,958,528 byte disponibili
220 --- E O F --- 2008-05-11 18:07:51