ciao ti mando il og di combofix, anche se dopo la scansione ho riavviato il pc ma il problema persiste.
ComboFix 09-05-19.08 - Utente 20/05/2009 15.51.26.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1441 [GMT 2:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-04-20 al 2009-05-20 )))))))))))))))))))))))))))))))))))
.
2009-05-05 13:21 . 2009-05-05 13:21 -------- d-----w c:\documents and settings\Utente\Dati applicazioni\vlc
2009-05-02 20:30 . 2009-05-20 12:12 -------- d-----w c:\documents and settings\Utente\Dati applicazioni\dvdcss
2009-04-28 15:40 . 2009-05-16 17:32 -------- d-----w c:\programmi\Graffiti Studio 2.0
2009-04-27 17:36 . 2009-04-27 17:36 -------- d-----w c:\programmi\VideoLAN
2009-04-24 18:26 . 2008-04-13 17:13 21504 ----a-w c:\windows\system32\dllcache\hidserv.dll
2009-04-24 18:26 . 2008-04-13 17:13 21504 ----a-w c:\windows\system32\hidserv.dll
2009-04-24 10:37 . 2009-04-24 10:37 -------- d-----w c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\WMTools Downloaded Files
2009-04-23 21:54 . 2009-04-23 21:54 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2009-04-23 21:53 . 2009-04-23 21:53 -------- d-----w c:\windows\system32\xircom
2009-04-23 21:53 . 2009-04-23 21:53 -------- d-----w c:\programmi\microsoft frontpage
2009-04-23 16:19 . 2009-04-23 16:19 -------- d-----w c:\programmi\Trend Micro
2009-04-23 11:28 . 2009-04-23 11:28 -------- d-----w c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2009-04-23 11:28 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-23 11:28 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-23 11:28 . 2009-04-23 11:28 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-04-23 11:28 . 2009-04-23 11:28 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-04-21 17:07 . 2005-08-16 10:23 38422 ----a-w c:\windows\system32\drivers\StMp3Rec.sys
2009-04-21 17:07 . 2009-04-21 17:07 -------- d-----w c:\programmi\Creative
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-20 09:30 . 2009-04-10 10:57 319520 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-20 09:30 . 2009-04-10 10:57 3220 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-20 00:31 . 2009-04-10 10:57 1827872 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-20 00:31 . 2009-04-10 10:57 17456 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-03 12:37 . 2001-08-31 12:00 85330 ----a-w c:\windows\system32\perfc010.dat
2009-05-03 12:37 . 2001-08-31 12:00 492504 ----a-w c:\windows\system32\perfh010.dat
2009-04-23 16:58 . 2009-02-22 13:40 -------- d-----w c:\programmi\uusee
2009-04-16 11:28 . 2009-04-16 11:28 -------- d-----w c:\programmi\eMule AdunanzA
2009-04-14 09:43 . 2008-01-29 16:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-14 09:43 . 2009-04-10 10:58 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-14 09:43 . 2009-04-10 10:58 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-10 10:57 . 2009-04-10 10:57 -------- d-----w c:\programmi\Kaspersky Lab
2009-04-10 10:54 . 2009-04-08 13:43 -------- d-----w c:\programmi\SUPERAntiSpyware
2009-04-08 16:12 . 2008-09-23 16:36 66904 ----a-w c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-08 13:43 . 2009-04-08 13:43 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2009-04-08 13:43 . 2009-04-08 13:43 -------- d-----w c:\documents and settings\Utente\Dati applicazioni\SUPERAntiSpyware.com
2009-03-25 10:56 . 2008-09-25 15:11 -------- d-----w c:\programmi\Spybot - Search & Destroy
2009-03-25 10:53 . 2008-09-25 14:08 -------- d-----w c:\programmi\CCleaner
2009-03-06 14:19 . 2008-04-13 17:13 286208 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:03 . 2008-03-01 12:58 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-27 09:27 . 2009-02-27 09:27 487979 ----a-w c:\windows\system32\imagens1234.exe
2009-02-20 17:08 . 2008-04-30 11:55 78336 ----a-w c:\windows\system32\ieencode.dll
.
------- Sigcheck -------
[-] 2008-04-30 11:56 1571840 3316C8A8EC07A9D4C0BE10310809A9E5 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl8"="c:\programmi\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\programmi\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"ATKMEDIA"="c:\programmi\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"ATKOSD2"="c:\programmi\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-21 544768]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2007-11-16 1024000]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"ACU"="c:\programmi\Atheros\ACU.exe" [2007-10-23 376921]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-11 136600]
"WinampAgent"="c:\programmi\Winamp\winampa.exe" [2008-08-03 36352]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-04-10 201992]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-06-20 16872448]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-02-20 124928]
c:\documents and settings\Utente\Menu Avvio\Programmi\Esecuzione automatica\
CCC.lnk - c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-7-17 49152]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Graffiti Studio 2.0\\Graffiti Studio.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:*:Disabled:emule_tcp
"4672:UDP"= 4672:UDP:emule_udp
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 18.29.38 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [25/03/2008 20.07.10 24592]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [23/09/2008 19.16.17 57344]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - ALERTER
*NewlyCreated* - MESSENGER
.
Contenuto della cartella 'Scheduled Tasks'
2009-05-19 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
2009-05-20 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-20 15:53
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(324)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(12388)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Ora fine scansione: 2009-05-20 15.54.42
ComboFix-quarantined-files.txt 2009-05-20 13:54
ComboFix2.txt 2009-04-25 10:14
Pre-Run: 52.431.659.008 byte disponibili
Post-Run: 52.460.777.472 byte disponibili
156 --- E O F --- 2009-04-29 18:08