Ecco i due log che mi hai chiesto, spero di non aver fatto casini visto che ho trovato difficoltà a disabilitare AVG 8.5
Malwarebytes' Anti-Malware 1.37
Versione del database: 2234
Windows 5.1.2600 Service Pack 2
06/06/2009 0.38.27
mbam-log-2009-06-06 (00-38-15).txt
Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 170307
Tempo trascorso: 43 minute(s), 14 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 1
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
c:\programmi\cradle of persia\FFF-ReflexV2.exe (Trojan.Backdoor) -> No action taken.
ComboFix 09-06-05.03 - principale 06/06/2009 1.22.11.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.2047.1522 [GMT 2:00]
Eseguito da: c:\documents and settings\principale\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\PRINCI~1\IMPOST~1\Temp\IadHide5.dll
c:\documents and settings\principale\Impostazioni locali\Temp\IadHide5.dll
c:\windows\IE4 Error Log.txt
c:\windows\system32\config\49440520.Evt
c:\windows\system32\Drivers\sptd.sys
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3550P
-------\Service_asc3550p
((((((((((((((((((((((((( Files Creati Da 2009-05-05 al 2009-06-05 )))))))))))))))))))))))))))))))))))
.
2009-06-05 21:52 . 2009-06-05 21:52 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Malwarebytes
2009-06-05 21:52 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-05 21:52 . 2009-06-05 21:52 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-06-05 21:52 . 2009-06-05 21:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-06-05 21:52 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-05 19:46 . 2009-06-05 20:52 -------- d-----w- c:\windows\BDOSCAN8
2009-06-05 11:52 . 2009-04-03 09:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-06-05 11:52 . 2008-12-18 10:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-06-05 11:52 . 2008-12-10 09:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-06-05 11:52 . 2009-06-05 11:52 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\PC Tools
2009-06-05 11:52 . 2009-06-05 11:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Tools
2009-06-05 11:51 . 2009-06-05 12:07 -------- d-----w- c:\programmi\File comuni\Symantec Shared
2009-06-05 11:51 . 2009-06-05 13:00 -------- d-----w- c:\programmi\Norton Security Scan
2009-06-05 11:50 . 2009-06-05 11:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-06-05 11:50 . 2009-06-05 11:50 -------- d-----w- c:\programmi\Google
2009-06-05 11:43 . 2009-06-05 14:56 -------- d-----w- c:\programmi\File comuni\PC Tools
2009-06-05 11:43 . 2009-06-05 12:44 -------- d-----w- c:\programmi\Spyware Doctor
2009-06-03 20:20 . 2009-06-03 20:20 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-06-03 20:20 . 2009-06-03 20:20 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-06-01 20:00 . 2009-06-01 20:00 -------- d-----w- c:\programmi\Adventure Productions
2009-05-28 15:44 . 2009-05-28 15:44 -------- d-----w- c:\programmi\Lighthouse Interactive
2009-05-27 21:25 . 2009-05-27 21:25 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Games
2009-05-27 21:24 . 2009-05-27 21:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Tages
2009-05-27 21:22 . 2009-05-27 21:22 -------- d-----w- c:\windows\system32\AGEIA
2009-05-27 21:22 . 2009-05-27 21:22 -------- d-----w- c:\programmi\AGEIA Technologies
2009-05-27 21:22 . 2009-05-27 21:22 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-05-27 21:22 . 2009-05-27 21:22 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-05-27 21:22 . 2009-05-27 21:22 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-05-14 13:43 . 2009-05-14 13:43 -------- d-----w- c:\programmi\Momentum DMT
2009-05-14 07:30 . 2009-05-14 07:30 2051864 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgcorex.dll
2009-05-11 07:32 . 1998-09-02 08:28 38160 ----a-w- c:\windows\system32\LMRTREND.dll
2009-05-11 07:32 . 1998-08-27 04:51 182032 ----a-w- c:\windows\system32\dxtmsft3.dll
2009-05-11 07:32 . 1998-09-02 08:28 63488 ----a-w- c:\windows\system32\unam4ie.exe
2009-05-11 07:32 . 1998-09-02 08:02 194320 ----a-w- c:\windows\system32\qcut.dll
2009-05-11 07:32 . 1998-08-17 09:21 10240 ----a-w- c:\windows\system32\vidx16.dll
2009-05-11 07:32 . 1998-08-17 09:21 11776 ----a-w- c:\windows\system32\mciqtz.drv
2009-05-11 07:32 . 2009-05-11 07:32 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-05-11 07:32 . 2009-05-11 07:32 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-05-11 07:31 . 2009-05-11 07:31 -------- d-----w- C:\Sierra
2009-05-10 21:15 . 2009-05-10 21:15 -------- d-----w- c:\programmi\Ubi Soft
2009-05-10 21:15 . 2009-05-11 07:29 -------- d--h--w- c:\programmi\Zero G Registry
2009-05-10 21:15 . 2009-05-10 21:15 -------- d--h--w- c:\documents and settings\principale\InstallAnywhere
2009-05-07 17:24 . 2009-05-09 20:56 -------- d-----w- c:\programmi\Private Moon Studios
2009-05-07 17:17 . 2009-05-27 21:28 -------- d-----w- c:\programmi\The Adventure Company
2009-05-07 16:36 . 2005-05-26 13:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-05 23:15 . 2008-11-12 11:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-06-05 22:44 . 2009-04-17 07:29 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-06-01 19:42 . 2009-06-01 19:42 0 ----a-w- c:\windows\DXT13B.tmp
2009-06-01 19:42 . 2009-06-01 19:42 0 ----a-w- c:\windows\DXT13A.tmp
2009-06-01 19:42 . 2009-06-01 19:42 0 ----a-w- c:\windows\DXT139.tmp
2009-06-01 19:42 . 2009-06-01 19:42 0 ----a-w- c:\windows\DXT138.tmp
2009-06-01 19:42 . 2009-06-01 19:42 0 ----a-w- c:\windows\DXT137.tmp
2009-06-01 19:42 . 2009-06-01 19:42 0 ----a-w- c:\windows\DXT136.tmp
2009-05-28 15:43 . 2008-11-12 10:48 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-05-27 21:23 . 2009-05-27 21:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\InstallShield
2009-05-07 17:06 . 2009-05-07 17:06 96704 ----a-w- c:\windows\~GLC0001.TMP
2009-05-07 17:06 . 2009-05-07 17:06 96704 ----a-w- c:\windows\~GLC0000.TMP
2009-05-07 16:32 . 2009-05-05 20:13 -------- d-----w- c:\programmi\Nobilis
2009-05-05 19:59 . 2009-05-05 19:57 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-05-05 19:59 . 2009-05-05 19:57 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-05-05 19:59 . 2009-05-05 19:57 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-05-04 10:16 . 2009-05-04 10:16 -------- d-----w- c:\programmi\Blue Label Entertainment
2009-05-03 17:29 . 2009-05-03 17:29 -------- d-----w- c:\programmi\Artematica
2009-05-03 16:39 . 2009-05-03 16:39 -------- d-----w- c:\programmi\directx
2009-04-30 13:31 . 2009-03-30 07:43 -------- d-----w- c:\programmi\PopCap Games
2009-04-29 20:05 . 2009-04-29 20:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PopCapv1004
2009-04-29 20:04 . 2009-04-24 18:58 -------- d-----w- c:\programmi\Hidden Wonders of the Depths
2009-04-25 19:02 . 2009-04-25 19:02 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NeptunesAdve
2009-04-24 07:58 . 2008-11-13 13:49 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-04-24 07:58 . 2008-11-13 13:49 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-04-24 07:58 . 2008-11-13 13:49 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-04-24 07:58 . 2008-11-13 13:49 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-04-24 07:58 . 2008-11-13 13:49 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-17 07:29 . 2009-04-17 07:29 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Divo Games
2009-04-17 07:29 . 2009-04-17 07:29 -------- d-----w- c:\programmi\Sea Journey
2009-04-16 12:51 . 2004-08-30 20:00 80114 ----a-w- c:\windows\system32\perfc010.dat
2009-04-16 12:51 . 2004-08-30 20:00 460034 ----a-w- c:\windows\system32\perfh010.dat
2009-04-02 17:01 . 2009-04-02 17:01 4096 ----a-w- c:\windows\d3dx.dat
2009-04-02 17:00 . 2009-04-02 17:00 1024 ----a-w- c:\windows\library_game_ra.dat
2009-03-30 07:43 . 2009-03-30 07:43 0 ----a-w- c:\windows\popcinfo.dat
2004-03-11 12:27 . 2008-11-12 10:48 40960 ----a-w- c:\programmi\Uninstall_CDS.exe
2009-03-01 15:59 . 2009-03-01 15:57 56 --sh--r- c:\windows\system32\B14B0ECACF.sys
2009-03-01 16:02 . 2009-03-01 15:57 5224 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-30 15360]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"LDM"="c:\programmi\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2009-03-04 36864]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-05 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-24 1947928]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"LogitechCommunicationsManager"="c:\programmi\File comuni\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LVCOMSX"="c:\programmi\File comuni\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-09-12 16264192]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2006-03-28 94208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-30 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio rapido HP Photosmart Premier.lnk - c:\programmi\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
BlueSoleil.lnk - c:\programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe [2009-2-25 1048576]
DSLMON.lnk - c:\programmi\ADSL\StarModem ADSL USB MODEM\dslmon.exe [2008-11-12 929861]
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Logitech Desktop Messenger.lnk - c:\programmi\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2009-3-4 196608]
Logitech SetPoint.lnk - c:\programmi\Logitech\SetPoint\SetPoint.exe [2009-3-4 573440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-24 07:58 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"d:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [13/11/2008 15.49.20 12552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [05/06/2009 13.52.27 130936]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [12/11/2008 17.34.06 11264]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/11/2008 15.49.17 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/11/2008 15.49.20 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [13/11/2008 15.49.04 908568]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [13/11/2008 15.49.04 298776]
S3 sdAuxService;PC Tools Auxiliary Service;c:\programmi\Spyware Doctor\pctsAuxs.exe [05/06/2009 13.52.09 348752]
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-05 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-05 11:50]
2009-06-05 c:\windows\Tasks\Norton Security Scan for principale.job
- c:\programmi\Norton Security Scan\Nss.exe [2008-09-19 18:20]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-PowerBar - (no file)
HKLM-Run-9xadiras - 9xadiras.exe
HKLM-Run-2kadiras - 2kadiras.exe
SafeBoot-procexp90.Sys
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\programmi\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-06 01:28
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1547161642-152049171-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:6c,7b,75,18,b4,c3,f3,4c,18,04,03,58,e6,4f,7a,d3,d8,d2,5d,df,33,44,b6,
cf,3c,b1,0b,3b,0f,31,6e,7a,95,22,87,55,ac,17,7c,e6,6f,ef,af,a8,5e,8c,e5,e7,\
"??"=hex:8f,dc,f4,61,ef,f9,30,3d,ec,8a,26,9e,3d,7b,e4,ed
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(6404)
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
c:\programmi\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcSrv.exe
c:\programmi\IVT Corporation\BlueSoleil\BTNtService.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\progra~1\AVG\AVG8\avgam.exe
c:\programmi\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\programmi\AVG\AVG8\avgcsrvx.exe
c:\programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\programmi\File comuni\Logitech\KhalShared\KHALMNPR.exe
c:\programmi\HP\Digital Imaging\bin\hpqimzone.exe
c:\programmi\Logitech\QuickCam10\COCIManager.exe
.
**************************************************************************
.
Ora fine scansione: 2009-06-05 1.31.36 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-06-05 23:31
Pre-Run: 211.096.526.848 byte disponibili
Post-Run: 212.489.891.840 byte disponibili
238 --- E O F --- 2009-04-22 20:09