Combofix ha funzionato. Prima della scansione mi sono comparse solo due finestre riguardanti l'antivirus (AVG) che comunque avevo disattivato, in cui l'unica opzione disponibile era quella di cliccare OK.
Comunque posto il log secondo le tue indicazioni.
Grazie.
ComboFix 09-05-28.07 - Administrator 29/05/2009 12.11.40.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.874.39.1033.18.767.407 [GMT 7:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\QUAD Utilities
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\Ijl11.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-29 )))))))))))))))))))))))))))))))
.
2009-05-28 05:21 . 2009-05-28 05:21 71680 ----a-w C:\mbr.exe
2009-05-28 04:54 . 2009-05-28 04:54 -------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles
2009-05-27 12:14 . 2009-05-27 12:14 -------- d-----w c:\documents and settings\Administrator\Application Data\dvdcss
2009-05-27 11:14 . 2009-05-27 11:16 -------- d-----w c:\program files\Softoria Capture
2009-05-27 10:52 . 2009-05-28 04:53 -------- d-----w c:\windows\nview
2009-05-27 10:52 . 2006-10-22 04:22 208896 ----a-w c:\windows\system32\nvudisp.exe
2009-05-26 07:35 . 2009-05-26 07:35 -------- d-sh--w C:\found.000
2009-05-26 05:15 . 2009-05-26 05:15 -------- d-----w c:\program files\SIW
2009-05-22 11:34 . 2009-05-22 11:34 -------- d-----w c:\documents and settings\All Users\Application Data\NVIDIA
2009-05-22 08:35 . 2007-10-12 08:14 3734536 ----a-w c:\windows\system32\d3dx9_36.dll
2009-05-22 08:34 . 2009-05-22 08:34 -------- d-----w c:\windows\Logs
2009-05-19 05:03 . 2009-05-10 03:31 2051864 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-05-19 05:03 . 2009-05-10 03:31 354584 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-05-19 05:03 . 2009-05-10 03:31 424472 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwdwsc.dll
2009-05-19 05:03 . 2009-05-10 03:31 177432 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmail.dll
2009-05-19 05:03 . 2009-05-10 03:31 486168 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgrsx.exe
2009-05-19 05:03 . 2009-05-10 03:31 3288344 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-05-19 05:03 . 2009-05-10 03:31 312088 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avglngx.dll
2009-05-15 05:10 . 2009-05-10 03:31 2302232 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-05-15 05:10 . 2009-05-10 03:31 3399960 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-05-10 03:27 . 2009-05-10 03:27 755992 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-05-10 03:27 . 2009-05-10 03:27 1437464 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-05-10 03:27 . 2009-05-09 03:42 1085208 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-05-10 03:27 . 2009-05-09 03:42 587032 ----a-w c:\documents and settings\All Users\Application Data\avg8\update\backup\avgiproxy.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-28 11:22 . 2009-01-16 05:38 -------- d-----w c:\program files\eMule
2009-05-27 17:17 . 2008-10-03 16:42 -------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2009-05-27 16:11 . 2008-10-03 16:44 -------- d-----w c:\documents and settings\Administrator\Application Data\skypePM
2009-05-26 05:28 . 2008-10-04 11:36 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-25 18:57 . 2008-10-02 09:16 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-25 18:57 . 2008-10-02 09:25 2967799 ----a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-10 03:31 . 2008-10-04 10:29 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-05-10 03:31 . 2008-10-04 10:28 27784 ----a-w c:\windows\system32\drivers\avgmfx86.sys
2009-05-10 03:31 . 2008-10-04 10:28 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-10 03:31 . 2008-10-04 10:29 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-27 05:43 . 2009-04-27 05:33 -------- d-----w c:\program files\Free Web Buttons
2009-04-24 16:54 . 2009-04-17 06:30 -------- d-----w c:\documents and settings\Administrator\Application Data\gtk-2.0
2009-04-21 11:13 . 2009-04-21 11:13 -------- d-----w c:\program files\CSS Tab Designer 2
2009-04-20 19:31 . 2009-01-01 05:52 -------- d-----w c:\program files\Macromedia
2009-04-20 19:31 . 2008-10-02 08:27 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-17 07:42 . 2009-02-12 06:57 -------- d-----w c:\program files\Google
2009-04-17 06:25 . 2009-04-17 06:25 -------- d-----w c:\program files\GIMP-2.0
2009-04-06 08:32 . 2008-10-02 09:16 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 08:32 . 2008-10-02 09:16 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-26 11:12 . 2009-01-26 11:11 24 --sh--w c:\windows\S3648A81E.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-05-18 14336]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"FreeRAM XP"="c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-22 1591808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-05-18 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"UseDesktopIniCache"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-15 04:19 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-10 03:31 11952 ----a-w c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^PartMetBackup.lnk]
backup=c:\windows\pss\PartMetBackup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^IDW Logging Tool.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"DisplayTrayIcon"=c:\windows\system32\TrayIcon.exe
"flockbox"=c:\program files\My Lockbox\flockbox.exe /a
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\LinkCreator.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [05/01/2009 18.12.53 17264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [04/10/2008 17.28.48 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [04/10/2008 17.29.03 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [03/09/2008 14.07.14 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [03/09/2008 14.07.12 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [04/10/2008 17.28.48 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [04/10/2008 17.28.47 298776]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [03/09/2008 14.07.16 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-03-25 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-12-07 02:38]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.msn.it/
uInternet Connection Wizard,ShellNext = hxxp://www.tot.co.th/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\b37eqjo7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1210541&SearchSource=3&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.daemon-search.com/startpage
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\b37eqjo7.default\extensions\{bc4be15d-6a34-4356-9e97-79e43da32b1d}\components\FFAlert.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-29 12:16
Windows 5.1.2600 Service Pack 2, v.2135 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'lsass.exe'(824)
c:\windows\system32\dssenh.dll
.
Completion time: 2009-05-29 12.19.56
ComboFix-quarantined-files.txt 2009-05-29 05:19
ComboFix2.txt 2009-01-17 16:13
Pre-Run: 13.176.016.896 bytes free
Post-Run: 13.616.431.104 bytes free
163