Ecco il LOG di conbofix:
ComboFix 09-06-20.04 - Davide 21/06/2009 17.26.14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1527.1136 [GMT 2:00]
Eseguito da: c:\documents and settings\Davide\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-3C24-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\driver
c:\documents and settings\Davide\Dati applicazioni\inst.exe
c:\documents and settings\Davide\Impostazioni locali\Temporary Internet Files\lsn_6FBA808F-2580-48c3-8C6B-C08BBB800B8E.xml
c:\programmi\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DRIVER
-------\Legacy_DRIVERDRV
((((((((((((((((((((((((( Files Creati Da 2009-05-21 al 2009-06-21 )))))))))))))))))))))))))))))))))))
.
2009-06-21 14:12 . 2009-06-21 14:12 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\Malwarebytes
2009-06-21 14:12 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-21 14:12 . 2009-06-21 14:12 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-06-21 14:12 . 2009-06-21 14:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-06-21 14:12 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-21 14:10 . 2009-06-21 14:11 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\.clamwin
2009-06-21 14:10 . 2009-06-21 14:10 -------- d-----w- c:\programmi\ClamWin
2009-06-21 14:10 . 2009-06-21 14:10 -------- d-----w- c:\documents and settings\All Users\.clamwin
2009-06-21 13:16 . 2009-06-21 13:16 -------- d-----w- c:\programmi\Trend Micro
2009-06-21 12:58 . 2009-06-21 12:58 -------- d-----w- c:\programmi\Online Solutions
2009-06-21 12:58 . 2009-06-21 12:58 -------- d-----w- c:\programmi\File comuni\Online Solutions Shared
2009-06-21 12:49 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-21 12:49 . 2009-03-24 14:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-21 12:49 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-21 12:49 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-21 12:49 . 2009-06-21 12:49 -------- d-----w- c:\programmi\Avira
2009-06-21 12:49 . 2009-06-21 12:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-06-20 12:02 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-06-20 12:02 . 2009-06-20 12:02 -------- d-----w- c:\programmi\Alwil Software
2009-06-19 07:21 . 2009-06-19 07:21 -------- d-----w- c:\programmi\iPod
2009-06-19 07:21 . 2009-06-19 07:22 -------- d-----w- c:\programmi\iTunes
2009-06-19 07:21 . 2009-06-19 07:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-19 07:19 . 2009-06-19 07:19 -------- d-----w- c:\programmi\QuickTime
2009-06-19 07:13 . 2009-06-19 07:13 75048 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-09 17:01 . 2009-06-09 17:01 -------- d-----w- c:\windows\system32\NtmsData
2009-06-02 13:46 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2009-06-02 13:46 . 1998-08-05 06:45 122128 ----a-w- c:\windows\system32\VB6IT.DLL
2009-06-02 13:46 . 1998-08-05 06:45 150528 ----a-w- c:\windows\system32\MSCMCIT.DLL
2009-06-02 13:46 . 1998-08-05 06:45 63488 ----a-w- c:\windows\system32\MSCC2IT.DLL
2009-06-02 13:46 . 2009-06-02 13:47 -------- d-----w- c:\programmi\PDFCreator
2009-06-02 13:46 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2009-05-31 18:50 . 2009-05-31 19:06 -------- d-----w- c:\programmi\PhotoFiltre
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 12:47 . 2008-12-11 15:49 -------- d-----w- c:\programmi\Yahoo!
2009-06-21 12:33 . 2009-04-03 12:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-06-21 11:27 . 2008-12-21 16:59 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\uTorrent
2009-06-21 10:48 . 2009-04-06 18:52 -------- d-----w- c:\programmi\Lavasoft
2009-06-21 10:48 . 2009-04-06 18:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2009-06-19 10:36 . 2009-01-22 20:39 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\Apple Computer
2009-06-19 07:21 . 2009-01-22 20:36 -------- d-----w- c:\programmi\File comuni\Apple
2009-06-09 16:57 . 2008-12-18 11:13 -------- d-----w- c:\programmi\File comuni\Adobe
2009-05-26 12:34 . 2009-05-08 21:36 -------- d-----w- c:\programmi\Metin2_Italiano
2009-05-24 13:40 . 2008-12-10 13:54 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\U3
2009-05-16 12:54 . 2009-05-16 12:54 463360 ----a-w- c:\documents and settings\Davide\Dati applicazioni\Techno Design IP\LiveSearch Notification.exe
2009-05-16 12:54 . 2009-05-16 12:54 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\Techno Design IP
2009-05-07 15:41 . 2003-04-08 12:00 346112 ----a-w- c:\windows\system32\localspl.dll
2009-04-30 18:08 . 2009-04-30 18:08 360320 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-04-30 18:08 . 2003-04-08 12:00 360320 ----a-w- c:\windows\system32\drivers\TCPIP.SYS
2009-04-29 04:51 . 2003-04-08 12:00 662016 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:51 . 2008-12-10 14:00 81920 ------w- c:\windows\system32\ieencode.dll
2009-04-26 18:23 . 2008-12-22 17:24 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\Ahead
2009-04-26 11:47 . 2009-04-26 11:43 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\gtk-2.0
2009-04-26 09:46 . 2009-04-26 09:39 -------- d-----w- c:\programmi\Eicos Deluxe Edition
2009-04-26 09:39 . 2009-04-26 09:41 737280 ----a-w- c:\windows\iun6002.exe
2009-04-25 18:15 . 2008-12-14 15:15 -------- d-----w- c:\programmi\eMule
2009-04-22 18:50 . 2008-12-10 14:06 72480 ----a-w- c:\documents and settings\Davide\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-22 15:49 . 2009-04-22 15:49 -------- d-----w- c:\programmi\temp
2009-04-19 20:08 . 2003-04-08 12:00 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 11:55 . 2003-04-08 12:00 70892 ----a-w- c:\windows\system32\perfc010.dat
2009-04-17 11:55 . 2003-04-08 12:00 440460 ----a-w- c:\windows\system32\perfh010.dat
2009-04-15 15:16 . 2003-04-08 12:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2009-01-20 14:36 . 2009-01-20 14:36 0 ----a-w- c:\programmi\File comuni\dht342126
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ISUSPM"="c:\documents and settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"LightScribe Control Panel"="c:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe" [2007-07-18 451872]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-07-09 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-07-09 114688]
"Sunkist2k"="c:\programmi\Multimedia Card Reader\shwicon2k.exe" [2003-11-26 135168]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-16 136600]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ClamWin"="c:\programmi\ClamWin\bin\ClamTray.exe" [2009-06-11 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2008-12-10 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [27/03/2009 22.53.20 55152]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [10/12/2008 21.18.45 59466]
R3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [10/12/2008 21.18.45 538925]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S3 fsssvc;Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19.08.58 533360]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-06-21 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-06-21 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-LiveSearchNotification - c:\programmi\Techno Design IP\LiveSearch Notification.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://it.msn.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-21 17:32
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1993962763-1123561945-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ñw*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(616)
c:\programmi\File comuni\Ahead\Lib\NeroSearchBar.dll
c:\programmi\File comuni\Ahead\Lib\MFC71U.DLL
c:\programmi\File comuni\Ahead\Lib\BCGCBPRO860un71.dll
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\WgaTray.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\File comuni\Ahead\Lib\NMIndexingService.exe
c:\programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Ora fine scansione: 2009-06-21 17.36.57 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-06-21 15:36
Pre-Run: 8.289.017.856 byte disponibili
Post-Run: 16.325.746.688 byte disponibili
197 --- E O F --- 2009-06-10 16:55