ciao, ti ringrazio nuovamente per il tempo che mi stai dedicando, di seguito ti allego i tre log.
Combofix:
ComboFix 08-11-16.05 - Marione12 2008-11-17 19.14.14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1505 [GMT 1:00]
Eseguito da: c:\documents and settings\Marione12\Desktop\ComboFix.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((( Files Creati Da 2008-10-17 al 2008-11-17 )))))))))))))))))))))))))))))))))))
.
2008-11-17 18:55 . 2008-11-17 18:55 <DIR> d-------- c:\windows\LastGood
2008-11-16 16:35 . 2008-11-16 16:35 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2008-11-16 16:34 . 2008-01-10 12:41 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di stampa
2008-11-16 16:34 . 2008-01-10 12:41 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di rete
2008-11-16 16:34 . 2008-01-10 12:41 <DIR> d-------- c:\documents and settings\Administrator\Preferiti
2008-11-16 16:34 . 2008-01-10 11:49 <DIR> d--h----- c:\documents and settings\Administrator\Modelli
2008-11-16 16:34 . 2008-01-10 12:41 <DIR> dr------- c:\documents and settings\Administrator\Menu Avvio
2008-11-16 16:34 . 2008-11-17 19:15 <DIR> d--h----- c:\documents and settings\Administrator\Impostazioni locali
2008-11-16 16:34 . 2008-01-10 12:41 <DIR> d-------- c:\documents and settings\Administrator\Documenti
2008-11-16 16:34 . 2008-11-16 16:35 <DIR> dr-h----- c:\documents and settings\Administrator\Dati applicazioni
2008-11-16 16:34 . 2008-11-16 16:34 <DIR> d-------- c:\documents and settings\Administrator
2008-11-16 12:40 . 2008-11-16 12:40 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-11-16 12:40 . 2008-11-16 12:40 <DIR> d-------- c:\documents and settings\Marione12\Dati applicazioni\Malwarebytes
2008-11-16 12:40 . 2008-11-16 12:40 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-11-16 12:40 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-16 12:40 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-16 12:28 . 2008-11-16 12:28 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\TEMP
2008-11-15 14:48 . 2008-11-15 14:48 <DIR> d-------- c:\programmi\Trend Micro
2008-11-12 22:23 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 19:05 . 2008-09-04 18:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-10-24 18:39 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-19 16:53 . 2008-10-19 16:58 <DIR> d-------- c:\documents and settings\Marione12\Dati applicazioni\Vso
2008-10-19 16:53 . 2008-10-19 16:53 47,360 --a------ c:\windows\system32\drivers\pcouffin.sys
2008-10-19 16:53 . 2008-10-19 16:58 47,360 --a------ c:\documents and settings\Marione12\Dati applicazioni\pcouffin.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 10:15 --------- d-----w c:\programmi\Microsoft Windows OneCare Live
2008-10-31 09:29 --------- d-----w c:\programmi\Glary Utilities
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 06:32 --------- d-----w c:\programmi\Microsoft Silverlight
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 21:32 --------- d-----w c:\programmi\Photo Story 3 for Windows
2008-10-15 21:31 --------- d-----w c:\documents and settings\Marione12\Dati applicazioni\OpenOffice.org
2008-10-15 21:29 --------- d-----w c:\programmi\OpenOffice.org 3
2008-10-15 21:29 --------- d-----w c:\programmi\JRE
2008-10-13 16:30 --------- d-----w c:\documents and settings\Marione12\Dati applicazioni\VUPlayer
2008-10-11 20:46 --------- d-----w c:\documents and settings\Marione12\Dati applicazioni\uTorrent
2008-10-09 15:58 --------- d-----w c:\documents and settings\Marione12\Dati applicazioni\OpenOffice.org2
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:24 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-26 07:57 826,368 ----a-w c:\windows\system32\wininet.dll
2008-04-11 17:04 32 ----a-w c:\documents and settings\All Users\Dati applicazioni\ezsid.dat
2008-05-14 07:39 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008051420080515\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RocketDock"="c:\programmi\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="c:\windows\ATK0100\Hcontrol.exe" [2004-07-19 61440]
"AzMixerSel"="c:\programmi\Realtek\InstallShield\AzMixerSel.exe" [2005-02-14 53248]
"SonyPowerCfg"="c:\programmi\Sony\VAIO Power Management\SPMgr.exe" [2005-05-15 184320]
"ISBMgr.exe"="c:\programmi\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"Switcher.exe"="c:\programmi\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-01-20 167936]
"OneCareUI"="c:\programmi\Microsoft Windows OneCare Live\winssnotify.exe" [2008-11-05 64880]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"StatusClient"="c:\programmi\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\programmi\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-06-03 49152]
winsched.exe [2008-09-23 274418]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 17:42 73728 c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\FILECO~1\SONYSH~1\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 c:\windows\system32\NeroCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
R2 OcHealthMon;Windows Live OneCare Health Monitor;"c:\programmi\Microsoft Windows OneCare Live\OcHealthMon.exe" [2008-11-05 25968]
R3 SPI;Periferica di controllo I/O Sony Programmable;c:\windows\system32\DRIVERS\SonyPI.sys [2008-01-10 37040]
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
2008-11-17 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2008-10-29 17:58]
.
**************************************************************************
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti:
**************************************************************************
.
Ora fine scansione: 2008-11-17 19.15.45
ComboFix-quarantined-files.txt 2008-11-17 18:15:43
ComboFix2.txt 2008-11-17 18:12:40
Pre-Run: 14.075.551.744 byte disponibili
Post-Run: 14,063,431,680 byte disponibili
120 --- E O F --- 2008-11-13 20:51:35
Malwarebytes':
Malwarebytes' Anti-Malware 1.30
Versione del database: 1401
Windows 5.1.2600 Service Pack 3
16/11/2008 12.46.16
mbam-log-2008-11-16 (12-45-59).txt
Tipo di scansione: Scansione rapida
Elementi scansionati: 43944
Tempo trascorso: 3 minute(s), 43 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 2
Cartelle infette: 0
File infetti: 0
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page\Start Page (Hijack.Homepage) -> Bad: (http://www.lookanddiscover.com/) Good: (http://www.google.com/) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://www.lookanddiscover.com/) Good: (http://www.google.com/) -> No action taken.
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
(Nessun elemento malevolo rilevato)
SUPERAntispyreware:
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 11/17/2008 at 09:43 PM
Application Version : 4.21.1004
Core Rules Database Version : 3640
Trace Rules Database Version: 1623
Scan type : Complete Scan
Total Scan Time : 00:16:12
Memory items scanned : 470
Memory threats detected : 0
Registry items scanned : 4300
Registry threats detected : 0
File items scanned : 15177
File threats detected : 3
Adware.Tracking Cookie
C:\Documents and Settings\Marione12\Cookies\marione12@imrworldwide[2].txt
C:\Documents and Settings\Marione12\Cookies\marione12@eas.apm.emediate[2].txt
Browser Hijacker.LookAndDiscover
C:\DOCUMENTS AND SETTINGS\ALL USERS\MENU AVVIO\PROGRAMMI\ESECUZIONE AUTOMATICA\WINSCHED.EXE
ti ringrazio ancora, saluti Mario.