Dimenticavo.... il log file di ComboFix:
ComboFix 09-05-15.06 - Fabio Mori 16/05/2009 19.50.33.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.478.130 [GMT 2:00]
Eseguito da: c:\documents and settings\Fabio Mori\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lucia Mori\Impostazioni locali\Dati applicazioni\sogcq.dat
c:\documents and settings\Lucia Mori\Impostazioni locali\Dati applicazioni\sogcq.exe
c:\documents and settings\Lucia Mori\Impostazioni locali\Dati applicazioni\sogcq_nav.dat
c:\documents and settings\Lucia Mori\Impostazioni locali\Dati applicazioni\sogcq_navps.dat
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc1.exe
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc10.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc11.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc12.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc13.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc14.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc15.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc16.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc17.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc18.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc19.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc20.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc21.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc22.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc23.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc24.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc25.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc3.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc4.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc5.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc6.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc7.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc8.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\Dc9.bak
c:\recycler\S-1-5-21-1085031214-688789844-1343024091-1004\INFO2
.
((((((((((((((((((((((((( Files Creati Da 2009-04-16 al 2009-05-16 )))))))))))))))))))))))))))))))))))
.
2009-05-16 16:54 . 2009-05-16 16:54 -------- d-----w c:\documents and settings\Fabio Mori\Dati applicazioni\Malwarebytes
2009-05-16 16:54 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-16 16:54 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-16 16:54 . 2009-05-16 16:54 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-05-16 16:54 . 2009-05-16 16:54 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-05-15 14:07 . 2009-05-15 14:07 -------- d-----w c:\documents and settings\Fabio Mori\Dati applicazioni\Image Zone Express
2009-04-22 12:36 . 2009-04-22 12:36 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\1245
2009-04-17 06:18 . 2009-05-11 12:25 -------- d-----w c:\documents and settings\Lucia Mori\Dati applicazioni\AVGTOOLBAR
2009-04-16 18:28 . 2009-05-02 07:13 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-16 18:28 . 2009-05-02 07:13 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-16 18:28 . 2009-05-02 07:13 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-16 18:28 . 2009-05-16 07:59 -------- d-----w c:\windows\system32\drivers\Avg
2009-04-16 18:28 . 2009-05-06 07:50 -------- d-----w c:\documents and settings\Fabio Mori\Dati applicazioni\AVGTOOLBAR
2009-04-16 18:27 . 2009-04-16 18:27 -------- d-----w c:\programmi\AVG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 10:22 . 2008-06-12 07:14 -------- d-----w c:\programmi\DaneaEasyfatt2006
2009-05-15 14:17 . 2008-07-10 19:17 108608 ----a-w c:\documents and settings\Lucia Mori\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-05-08 18:46 . 2008-06-10 09:21 -------- d-----w c:\programmi\eMule
2009-04-17 08:15 . 2001-08-31 18:00 77686 ----a-w c:\windows\system32\perfc010.dat
2009-04-17 08:15 . 2001-08-31 18:00 455618 ----a-w c:\windows\system32\perfh010.dat
2009-04-08 16:46 . 2009-04-08 16:46 -------- d-----w c:\programmi\Trend Micro
2009-04-07 16:19 . 2009-04-07 16:17 -------- d-----w c:\programmi\Windows Live Safety Center
2009-04-02 12:55 . 2009-04-02 11:38 -------- d-----w c:\programmi\eboost
2009-04-02 12:55 . 2001-04-23 08:49 790528 ----a-w c:\programmi\eboostBK_Dati.DAT
2009-04-02 12:20 . 2009-04-02 12:20 24576 ----a-w c:\windows\system32\NINOUT32.dll
2009-04-02 12:20 . 2009-04-02 12:20 180224 ----a-w c:\windows\system32\ijl15.dll
2009-04-02 11:37 . 2009-04-02 11:37 249856 ------w c:\windows\Setup1.exe
2009-04-02 11:37 . 2009-04-02 11:37 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-02 11:37 . 2009-04-02 11:37 -------- d-----w c:\programmi\Setup eboost
2009-03-18 17:13 . 2009-03-18 17:13 -------- d-----w c:\programmi\eBay
2009-03-18 17:11 . 2008-06-12 06:56 -------- d-----w c:\programmi\File comuni\InstallShield
2009-03-06 14:19 . 2004-08-19 13:39 286208 ----a-w c:\windows\system32\pdh.dll
2001-08-31 12:00 . 2001-08-31 12:00 94816 --sh--w c:\windows\twain.dll
2008-04-13 17:13 . 2004-08-19 13:39 50688 --sh--w c:\windows\twain_32.dll
2008-04-13 17:13 . 2004-08-19 13:39 1028096 --sh--w c:\windows\system32\mfc42.dll
2008-04-13 17:13 . 2004-08-19 13:39 57344 --sh--w c:\windows\system32\msvcirt.dll
2008-04-13 17:13 . 2004-08-19 13:39 413696 --sh--w c:\windows\system32\msvcp60.dll
2008-04-13 17:13 . 2004-08-19 13:39 343040 --sh--w c:\windows\system32\msvcrt.dll
2008-04-13 17:13 . 2004-08-19 13:39 551936 --sh--w c:\windows\system32\oleaut32.dll
2008-04-13 17:13 . 2004-08-19 13:39 84992 --sh--w c:\windows\system32\olepro32.dll
2008-04-13 17:14 . 2004-08-19 13:39 12288 --sh--w c:\windows\system32\regsvr32.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-13 1695232]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-11 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-08 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-08 126976]
"SynTPStart"="c:\programmi\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"Share-to-Web Namespace Daemon"="c:\programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 172032]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2008-2-8 394856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-02 07:13 11952 ----a-w c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Programmi\\eboost\\ScaricaDati.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\italian\\setup.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16756:TCP"= 16756:TCP:NortonAV
"13336:TCP"= 13336:TCP:NortonAV
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [16/04/2009 20.28.38 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [16/04/2009 20.28.45 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [16/04/2009 20.27.42 298776]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\programmi\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-16 19:54
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2009-05-16 19.57.04
ComboFix-quarantined-files.txt 2009-05-16 17:56
Pre-Run: 22.703.468.544 byte disponibili
Post-Run: 23.761.387.520 byte disponibili
164 --- E O F --- 2009-05-14 06:56