eccomi...allora la scansione con malware l'ho fatta, ma l'avevo gia fatta ieri, infatti non ha trovato niente di anomalo.Quaoto comunque il log:
Malwarebytes' Anti-Malware 1.33
Versione del database: 1713
Windows 5.1.2600 Service Pack 3
02/02/2009 21.15.59
mbam-log-2009-02-02 (21-15-59).txt
Tipo di scansione: Scansione completa (C:\|D:\|H:\|)
Elementi scansionati: 162962
Tempo trascorso: 1 hour(s), 54 minute(s), 35 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
(Nessun elemento malevolo rilevato)
Ho poi effettuato le operazioni con combofix, posto il log:
ComboFix 09-02-02.01 - Utente 2009-02-02 21.20.18.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.1535.844 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090202-0] *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
ADS - WINDOWS: deleted 72 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\tmp49.tmp
.
((((((((((((((((((((((((( Files Creati Da 2009-01-02 al 2009-02-02 )))))))))))))))))))))))))))))))))))
.
2009-02-02 10:37 . 2009-02-02 10:37 <DIR> d-------- c:\programmi\Trend Micro
2009-02-02 00:31 . 2007-10-24 17:36 <DIR> d--h----- c:\documents and settings\Administrator.UTENTE-784E4FCD.000\Risorse di stampa
2009-02-02 00:31 . 2007-10-24 17:36 <DIR> d--h----- c:\documents and settings\Administrator.UTENTE-784E4FCD.000\Risorse di rete
2009-02-02 00:31 . 2009-02-02 00:40 <DIR> d-------- c:\documents and settings\Administrator.UTENTE-784E4FCD.000\Preferiti
2009-02-02 00:31 . 2007-10-24 15:42 <DIR> d--h----- c:\documents and settings\Administrator.UTENTE-784E4FCD.000\Modelli
2009-02-02 00:31 . 2007-10-24 17:36 <DIR> dr------- c:\documents and settings\Administrator.UTENTE-784E4FCD.000\Menu Avvio
2009-02-02 00:31 . 2009-02-02 21:24 <DIR> d--h----- c:\documents and settings\Administrator.UTENTE-784E4FCD.000\Impostazioni locali
2009-02-02 00:31 . 2007-10-24 17:36 <DIR> d-------- c:\documents and settings\Administrator.UTENTE-784E4FCD.000\Documenti
2009-02-02 00:31 . 2007-10-24 17:36 <DIR> dr-h----- c:\documents and settings\Administrator.UTENTE-784E4FCD.000\Dati applicazioni
2009-02-02 00:31 . 2009-02-02 00:31 <DIR> d-------- c:\documents and settings\Administrator.UTENTE-784E4FCD.000
2009-02-01 20:27 . 2009-02-01 20:27 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-02-01 20:27 . 2009-02-01 20:27 <DIR> d-------- c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2009-02-01 20:27 . 2009-02-01 20:27 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-02-01 20:27 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-01 20:27 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-01 15:58 . 2009-02-02 19:20 <DIR> d-------- c:\programmi\Spybot - Search & Destroy
2009-02-01 15:58 . 2009-02-02 19:20 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-01-19 12:09 . 2009-01-19 12:17 <DIR> d-------- c:\windows\system32\NtmsData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-02 19:49 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\Skype
2009-02-02 16:50 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\skypePM
2009-01-21 09:23 --------- d-----w c:\programmi\Elaborate Bytes
2009-01-21 09:22 --------- d-----w c:\programmi\PokerStars.IT
2009-01-15 11:46 --------- d-----w c:\programmi\Messenger Plus! Live
2009-01-14 23:58 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-01-04 15:52 --------- d-----w c:\programmi\Java
2008-12-26 21:25 --------- d-----w c:\programmi\iTunes
2008-12-26 21:25 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\Apple Computer
2008-12-26 21:25 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-26 21:24 --------- d-----w c:\programmi\iPod
2008-12-26 21:24 --------- d-----w c:\programmi\File comuni\Apple
2008-12-26 21:24 --------- d-----w c:\programmi\Bonjour
2008-12-26 21:24 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2008-12-26 21:23 --------- d-----w c:\programmi\QuickTime
2008-12-26 21:22 --------- d-----w c:\programmi\Apple Software Update
2008-12-26 19:11 5,632 ----a-w c:\windows\system32\drivers\StarOpen.sys
2008-12-26 18:02 --------- d--h--w c:\programmi\InstallShield Installation Information
2008-12-26 18:02 --------- d-----w c:\programmi\Samsung
2008-12-22 15:32 --------- d-----w c:\programmi\Windows Live SkyDrive
2008-12-22 15:32 --------- d-----w c:\programmi\Microsoft
2008-12-22 15:31 --------- d-----w c:\programmi\Windows Live
2008-12-22 15:24 --------- d-----w c:\programmi\File comuni\Windows Live
2008-12-18 14:36 --------- d-----w c:\programmi\Warcraft III
2008-12-17 14:50 2,829 ----a-w c:\windows\War3Unin.pif
2008-12-17 14:50 139,264 ----a-w c:\windows\War3Unin.exe
2008-12-16 09:26 --------- d-----w c:\programmi\eMule AdunanzA
2008-12-15 21:54 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\uTorrent
2008-12-15 08:59 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\Samsung
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-09 13:44 --------- d-----w c:\programmi\SlySoft
2008-12-04 18:57 --------- d-----w c:\programmi\MSXML 4.0
2008-12-04 11:15 --------- d-----w c:\programmi\Paint.NET
2008-12-03 18:54 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Elaborate Bytes
2008-12-03 18:38 --------- d-----w c:\documents and settings\Utente\Dati applicazioni\Ahead
2008-12-03 18:38 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\LightScribe
2008-12-03 13:04 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Philips
2008-12-03 13:03 --------- d-----w c:\programmi\Philips
2008-12-03 11:38 --------- d-----w c:\programmi\File comuni\LightScribe
2008-12-03 11:35 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Ahead
2008-12-03 11:34 --------- d-----w c:\programmi\File comuni\Ahead
2008-12-03 11:30 --------- d-----w c:\programmi\Nero
2008-12-03 11:30 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Nero
2008-12-03 11:24 --------- d-----w c:\programmi\Ahead
2008-12-02 21:37 49,480 ----a-w c:\windows\system32\sirenacm.dll
2008-11-10 04:43 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-04-22 11:57 32 ----a-w c:\documents and settings\All Users\Dati applicazioni\ezsid.dat
2007-11-16 09:44 62,328 ----a-w c:\documents and settings\Utente\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-09-08 09:06 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008090820080909\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-25 68856]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2008-02-29 21898024]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"Philips Intelligent Agent"="c:\programmi\Philips\Intelligent Agent\Philips Intelligent Agent.exe" [2008-02-21 613792]
"LightScribe Control Panel"="c:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-17 81920]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 63712]
"DAEMON Tools"="c:\programmi\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"Ad-Watch"="c:\programmi\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2007-06-13 4177920]
"Acrobat Assistant 8.0"="c:\programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992]
"WinampAgent"="c:\programmi\Winamp\winampa.exe" [2008-08-04 36352]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"nwiz"="nwiz.exe" [2007-09-17 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-10-24 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-04 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-04 20560]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.sys [2005-02-24 162176]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'
2009-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-02-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.juventus.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-02 21:27:18
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
**************************************************************************
.
Ora fine scansione: 2009-02-02 21.30.48
ComboFix-quarantined-files.txt 2009-02-02 20:29:28
Pre-Run: 11.334.934.528 byte disponibili
Post-Run: 12,779,823,104 byte disponibili
186 --- E O F --- 2009-02-02 09:34:54
Per ora sembra andare.....se noti qualcosa di anomalo dimmi tutto!!!
Ti ringrazio davvero!