r16 grazie per l'aiuto. Ti posto il log di Malwarebytes e di combofix
Malwarebytes' Anti-Malware 1.36
Versione del database: 2145
Windows 5.1.2600 Service Pack 2
18/05/2009 21.01.36
mbam-log-2009-05-18 (21-01-26).txt
Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 183057
Tempo trascorso: 44 minute(s), 59 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 1
Valori di registro infetti: 0
Elementi dato del registro infetti: 2
Cartelle infette: 0
File infetti: 3
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> No action taken.
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
D:\XPKey.exe (Trojan.Downloader) -> No action taken.
D:\(app) windows xp KeyGens & Cracks & Appz\MSKey4in1.exe (Malware.Tool) -> No action taken.
C:\WINDOWS\system32\nvs2.inf (Adware.EGDAccess) -> No action taken.
ComboFix 09-05-17.08 - FILIPPO QUATTRINI 18/05/2009 21.07.06.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.1270.682 [GMT 2:00]
Eseguito da: c:\documents and settings\FILIPPO QUATTRINI\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\FILIPPO QUATTRINI\Impostazioni locali\Dati applicazioni\ggooo.dat
c:\documents and settings\FILIPPO QUATTRINI\Impostazioni locali\Dati applicazioni\ggooo_nav.dat
c:\documents and settings\FILIPPO QUATTRINI\Impostazioni locali\Dati applicazioni\ggooo_navps.dat
c:\documents and settings\FILIPPO QUATTRINI\Impostazioni locali\Dati applicazioni\gscamsc.dat
c:\documents and settings\FILIPPO QUATTRINI\Impostazioni locali\Dati applicazioni\gscamsc.exe
c:\documents and settings\FILIPPO QUATTRINI\Impostazioni locali\Dati applicazioni\gscamsc_nav.dat
c:\documents and settings\FILIPPO QUATTRINI\Impostazioni locali\Dati applicazioni\gscamsc_navps.dat
c:\windows\system32\autorun.ini
c:\windows\system32\nvs2.inf
----- BITS: Possibili siti infetti -----
hxxp://gllto.glpals.com
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NNSERV
-------\Service_NNServ
((((((((((((((((((((((((( Files Creati Da 2009-04-18 al 2009-05-18 )))))))))))))))))))))))))))))))))))
.
2009-05-17 21:32 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-17 21:32 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-17 21:32 . 2009-05-17 21:32 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-05-17 21:32 . 2009-05-17 21:32 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-05-17 16:25 . 2009-05-17 16:25 -------- d-----w c:\programmi\Trend Micro
2009-05-13 16:33 . 2009-05-13 16:34 -------- d-----w c:\programmi\File comuni\Application
2009-05-13 16:33 . 2009-05-13 16:33 -------- d-----w c:\programmi\SPAMfighter
2009-04-29 17:27 . 2009-04-29 17:27 -------- d-sh--w C:\FOUND.000
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-16 20:11 . 2009-04-16 20:11 -------- d-----w c:\programmi\nLite
2009-03-31 20:50 . 2009-03-31 20:50 -------- d-----w c:\programmi\Auralog
2009-03-30 18:24 . 2005-09-26 00:22 69856 ----a-w c:\documents and settings\FILIPPO QUATTRINI\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-03-28 15:41 . 2009-03-28 15:41 -------- d-----w c:\programmi\File comuni\GeoVid
2009-03-22 19:29 . 2009-03-22 19:29 56 ---ha-w c:\windows\system32\ezsidmv.dat
2009-03-22 19:27 . 2009-03-22 19:27 -------- d-----w c:\programmi\File comuni\Skype
2009-03-22 19:27 . 2009-03-22 19:27 -------- d-----r c:\programmi\Skype
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"H/PC Connection Agent"="c:\programmi\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 1204224]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-02 68856]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-10-02 1124352]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2009-03-16 24095528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-02-08 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-02-08 126976]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
"RemoteControl"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-14 32768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-03-28 188416]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-24 2880512]
"LManager"="c:\programmi\Launch Manager\QtZgAcer.EXE" [2005-03-28 319488]
"eRecoveryService"="c:\windows\System32\Check.exe" [2005-03-23 245760]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2004-02-02 495616]
"Lto Manager"="c:\programmi\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe" [2005-06-29 53248]
"Acrobat Assistant 7.0"="c:\programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2008-09-06 413696]
"nod32kui"="c:\programmi\Eset\nod32kui.exe" [2008-04-27 778240]
"SPAMfighter Agent"="c:\programmi\SPAMfighter\SFAgent.exe" [2009-03-12 326792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Acrobat.lnk - c:\windows\Installer\{AC76BA86-1034-4700-7760-000000000002}\SC_Acrobat.exe [2007-10-16 25214]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\WCESMgr.exe"=
"c:\programmi\Microsoft ActiveSync\rapimgr.exe"= c:\programmi\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\FILIPPO QUATTRINI\\Desktop\\utorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:eMule_TCP
"4672:UDP"= 4672:UDP:eMule_UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\programmi\SPAMfighter\sfus.exe [12/03/2009 10.44.32 184968]
S3 CosmUSB;Cosmed All-models USB driver;c:\windows\system32\drivers\COSMUSB.sys [18/05/2007 10.32.18 16768]
.
Contenuto della cartella 'Scheduled Tasks'
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-gscamsc - c:\documents and settings\filippo quattrini\impostazioni locali\dati applicazioni\gscamsc.exe
HKLM-Run-SunJavaUpdateSched - c:\programmi\Java\jre1.6.0_05\bin\jusched.exe
HKLM-Run-Office SturtUp - osa9.exe
HKU-Default-Run-Nokia.PCSync - c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 151.100.4.24:8080
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti nel file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: eBay Search - c:\programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
LSP: imon.dll
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://89.97.241.232/activex/AMC.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-18 21:20
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(860)
c:\windows\system32\imon.dll
c:\programmi\Eset\pr_imon.dll
- - - - - - - > 'explorer.exe'(920)
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\phonebrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\acer\eManager\anbmServ.exe
c:\programmi\Eset\nod32krn.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\programmi\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\msiexec.exe
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
c:\programmi\acer\eRecovery\Monitor.exe
c:\programmi\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Ora fine scansione: 2009-05-18 21.24.53 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-05-18 19:24
Pre-Run: 2.038.022.144 byte disponibili
Post-Run: 4.408.819.712 byte disponibili
185 --- E O F --- 2009-04-01 14:31