Si, si. dopo aver finito tutto, iintendo. intanto ecco il log di combofix.
ComboFix 09-04-03.01 - Leonardo 2009-04-04 14.30.54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.511.191 [GMT 2:00]
Eseguito da: c:\documents and settings\Leonardo\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Leonardo\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
.
((((((((((((((((((((((((( Files Creati Da 2009-03-04 al 2009-04-04 )))))))))))))))))))))))))))))))))))
.
2009-04-04 14:20 . 2009-04-04 14:27 7,168 --a------ c:\windows\system32\winxp.exe
2009-04-04 14:02 . 2009-04-04 14:02 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-04-04 14:02 . 2009-04-04 14:02 <DIR> d-------- c:\documents and settings\Leonardo\Dati applicazioni\Malwarebytes
2009-04-04 14:02 . 2009-04-04 14:02 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-04-04 14:02 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-04 14:02 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-04-04 14:00 . 2009-04-04 14:00 <DIR> d-------- c:\programmi\Trend Micro
2009-04-04 13:46 . 2009-04-04 14:30 1,038,984 --a------ C:\winfile.jpg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-04 12:17 --------- d-----w c:\programmi\File comuni\Acronis
2009-04-04 12:06 --------- d-----w c:\programmi\Java
2009-04-04 11:57 --------- d-----w c:\programmi\CCleaner
2009-03-22 12:39 --------- d-----w c:\documents and settings\Leonardo\Dati applicazioni\Skype
2009-03-22 12:34 --------- d-----w c:\documents and settings\Leonardo\Dati applicazioni\skypePM
2009-03-09 03:19 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-02-25 18:00 --------- d-----w c:\documents and settings\Leonardo\Dati applicazioni\Acronis
2009-02-25 17:56 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Acronis
2009-02-25 17:53 971,584 ----a-w c:\windows\system32\drivers\tdrpm147.sys
2009-02-25 17:53 540,000 ----a-w c:\windows\system32\drivers\timntr.sys
2009-02-25 17:53 44,704 ----a-w c:\windows\system32\drivers\tifsfilt.sys
2009-02-25 17:52 --------- d-----w c:\programmi\Acronis
2009-02-09 20:33 --------- d-----w c:\documents and settings\Leonardo\Dati applicazioni\CyberLink
2009-02-09 18:55 --------- d-----w c:\programmi\Watchtower
2009-02-09 14:04 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-01-30 18:04 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-11-23 19:28 4,900,376 ----a-w c:\programmi\LimeWireWin.exe
2008-11-24 21:17 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008112420081125\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-04-04_ 9.46.21,23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-05 06:55:51 144,896 -c----w c:\windows\system32\dllcache\schannel.dll
- 2008-09-15 15:24:38 1,846,400 -c----w c:\windows\system32\dllcache\win32k.sys
+ 2009-02-09 14:04:21 1,846,784 -c----w c:\windows\system32\dllcache\win32k.sys
- 2008-11-24 21:16:51 243,920 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-04-04 12:08:18 243,920 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2008-11-23 19:34:33 144,792 ----a-w c:\windows\system32\java.exe
+ 2009-03-09 03:19:11 144,792 ----a-w c:\windows\system32\java.exe
- 2008-11-23 19:34:33 144,792 ----a-w c:\windows\system32\javaw.exe
+ 2009-03-09 03:19:13 144,792 ----a-w c:\windows\system32\javaw.exe
- 2008-11-23 19:34:33 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2009-03-09 03:19:13 148,888 ----a-w c:\windows\system32\javaws.exe
- 2009-02-12 04:56:17 21,244,872 ----a-w c:\windows\system32\MRT.exe
+ 2009-02-25 20:54:59 24,768,960 ----a-w c:\windows\system32\MRT.exe
- 2009-02-03 11:54:03 52,900 ----a-w c:\windows\system32\perfc009.dat
+ 2009-04-04 12:05:54 52,900 ----a-w c:\windows\system32\perfc009.dat
- 2009-02-03 11:54:03 63,402 ----a-w c:\windows\system32\perfc010.dat
+ 2009-04-04 12:05:54 63,402 ----a-w c:\windows\system32\perfc010.dat
- 2009-02-03 11:54:03 380,486 ----a-w c:\windows\system32\perfh009.dat
+ 2009-04-04 12:05:54 380,486 ----a-w c:\windows\system32\perfh009.dat
- 2009-02-03 11:54:03 425,804 ----a-w c:\windows\system32\perfh010.dat
+ 2009-04-04 12:05:54 425,804 ----a-w c:\windows\system32\perfh010.dat
- 2008-04-14 02:13:49 144,384 ----a-w c:\windows\system32\schannel.dll
+ 2008-12-05 06:55:51 144,896 ----a-w c:\windows\system32\schannel.dll
- 2008-07-09 07:42:34 18,808 ------w c:\windows\system32\spmsg.dll
+ 2007-11-30 11:19:29 18,808 ------w c:\windows\system32\spmsg.dll
+ 2009-04-04 12:20:00 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_658.dat
+ 2008-04-15 17:47:48 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\programmi\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-30 1601304]
"CTFMON"="c:\windows\system32\wscript.exe" [2008-05-08 155648]
"regdiit"="c:\windows\system32\winxp.exe" [2009-04-04 7168]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
NETGEAR WG111v2 Smart Wizard.lnk - c:\programmi\NETGEAR\WG111v2\WG111v2.exe [2008-11-16 1261568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-30 20:04 10520 c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2003-12-22 08:38 241664 c:\programmi\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-09 18:53 153136 c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 ALiAGP;ALi AGP Bus Filter Driver;c:\windows\system32\drivers\ALiAGP.SYS [2004-10-07 29056]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-11-16 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-11-16 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-11-16 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-16 298264]
R3 ALI5261;ALi Based Ethernet NT Driver;c:\windows\system32\drivers\ALILAN.SYS [2004-10-07 29184]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2008-11-16 194304]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-04 14:32:56
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\RtlGina2.dll
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-04-04 14.35.12
ComboFix-quarantined-files.txt 2009-04-04 12:34:57
ComboFix2.txt 2009-04-04 07:48:10
Pre-Run: 107.775.541.248 byte disponibili
Post-Run: 107,768,205,312 byte disponibili
157 --- E O F --- 2009-04-04 11:56:13
Sto facendo la scansione con malwarebytes...