Grazie r16 per l'aiuto, scusa se non ho risposto prima, ma il pc è peggiorato, lo accendo e dopo poco si spegne, ho lanciato combofix una 50 di volte, ma il pc si riavviava prima che finisse, ma alla vine è riuscito ad elaborare il report. che allego di seguito.
Una cosa, l'immagine che avevo scelto per il descktop era sparita e non c'era modo di sostituirla, semplicemente non la prendeva, ma durante l'elaborazione di combofix è riapparsa miracolosamente, non sò cosa perchè, ma ho pensato che ti fosse utile saperlo.
Ho notato che lavorando con l'antivirus spento il pc impiega più tempo a riavviarsi rispetto a quando è in funzione
ComboFix 09-06-26.02 - Massy 27/06/2009 13.43.21.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.2303.1873 [GMT 2:00]
Eseguito da: c:\documents and settings\Massy\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-05-27 al 2009-06-27 )))))))))))))))))))))))))))))))))))
.
2009-06-26 20:13 . 2009-06-26 20:13 152576 ----a-w- c:\documents and settings\Massy\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-18 12:59 . 2009-06-18 20:10 33808 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\klbg.sys
2009-06-18 12:59 . 2009-06-18 20:10 213520 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\XP\klif.sys
2009-06-18 12:59 . 2009-06-18 20:10 21256 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\vkbd.dll
2009-06-18 12:58 . 2009-06-18 20:10 861448 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\updater.dll
2009-06-18 12:58 . 2009-06-18 20:10 83208 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\mzvkbd.dll
2009-06-18 12:58 . 2009-06-18 20:10 62728 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ievkbd.dll
2009-06-18 12:58 . 2009-06-18 20:10 43784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\fssync.dll
2009-06-18 12:58 . 2009-06-18 20:10 365832 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ckahum.dll
2009-06-18 12:58 . 2009-06-18 20:10 201992 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\avp.exe
2009-06-18 12:46 . 2009-06-18 12:59 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-18 12:46 . 2009-06-18 12:59 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-18 12:46 . 2009-06-27 11:41 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-06-18 12:46 . 2009-06-27 11:40 344096 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-18 12:46 . 2009-06-27 11:40 1813536 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-18 12:46 . 2009-06-18 12:46 -------- d-----w- c:\programmi\Kaspersky Lab
2009-06-06 21:54 . 2009-06-06 21:54 -------- d-----w- C:\Documenws and Settings
2009-06-06 11:42 . 2009-06-06 11:42 -------- d-----w- c:\windows\system32\%PersonalRootCertificateFolder%
2009-06-03 19:54 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2009-06-03 19:54 . 2009-06-03 19:54 -------- d-----w- c:\programmi\PDFCreator
2009-06-03 19:54 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 11:41 . 2009-03-17 12:35 117760 ----a-w- c:\documents and settings\Massy\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-27 11:40 . 2009-06-18 12:46 2256 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-27 11:40 . 2009-06-18 12:46 16296 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-27 10:50 . 2008-04-07 20:30 -------- d-----w- c:\programmi\eMule
2009-06-26 20:13 . 2008-11-21 10:02 -------- d-----w- c:\programmi\Java
2009-06-26 20:12 . 2008-04-07 20:34 -------- d-----w- c:\documents and settings\Massy\Dati applicazioni\Skype
2009-06-25 11:35 . 2008-12-06 11:09 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-06-25 11:35 . 2009-01-08 10:42 3561743 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-24 11:36 . 2009-01-02 11:20 -------- d-----w- c:\programmi\Upsmon
2009-06-18 20:10 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-06-17 09:27 . 2008-12-06 11:09 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2008-12-06 11:09 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-09 19:08 . 2008-04-07 19:40 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-06-08 18:55 . 2009-03-28 15:46 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Autodesk
2009-06-06 21:50 . 2006-03-02 12:00 69790 ----a-w- c:\windows\system32\perfc010.dat
2009-06-06 21:50 . 2006-03-02 12:00 437644 ----a-w- c:\windows\system32\perfh010.dat
2009-06-01 20:28 . 2009-03-13 21:40 -------- d-----w- c:\programmi\FTP Commander
2009-05-07 15:41 . 2006-03-02 12:00 346112 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:45 . 2006-03-02 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:44 . 2006-03-02 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 20:08 . 2006-03-02 12:00 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:16 . 2006-03-02 12:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2009-03-07 08:03 . 2009-03-07 07:57 24 --sh--w- c:\windows\S6E5D15AA.tmp
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-28 39408]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-06-13 16377344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2008-06-17 185896]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-09-06 413696]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-06-18 201992]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2007-02-28 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
DSLMON.lnk - c:\programmi\ADSL\StarModem ADSL USB MODEM\dslmon.exe [2008-5-22 929861]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05 356352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 18.29.38 33808]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [15/01/2009 17.17.40 8944]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [15/01/2009 17.17.38 55024]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [21/07/2008 19.07.26 279552]
R2 Upsagent;Upsagent - UPS Monitor;c:\programmi\Upsmon\Upsag_nt.exe [14/11/2008 16.07.54 680544]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [21/07/2008 19.07.45 25984]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 19.02.46 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [25/03/2008 20.07.10 24592]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.sys [24/02/2005 12.29.14 162176]
R3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [15/01/2009 17.17.42 7408]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\11.tmp --> c:\windows\system32\11.tmp [?]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [07/04/2008 19.34.33 37616]
.
Contenuto della cartella 'Scheduled Tasks'
2009-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-06-27 c:\windows\Tasks\AWC AutoSweep.job
- c:\programmi\IObit\Advanced SystemCare 3\AutoSweep.exe [2008-12-05 15:35]
2009-05-01 c:\windows\Tasks\AWC Update.job
- c:\programmi\IObit\Advanced SystemCare 3\IObitUpdate.exe [2008-12-05 15:12]
2009-06-27 c:\windows\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- c:\programmi\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 09:20]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.futuraelettronic.com/
mStart Page = about:blank
IE: &Windows Live Search - c:\programmi\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: Download Video -
http://www.viloader.net/addon.htmIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Massy\Dati applicazioni\Mozilla\Firefox\Profiles\e2btwn51.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - MyStart Cerca
FF - prefs.js: browser.startup.homepage -
www.futuraelettronic.comFF - prefs.js: keyword.URL - hxxp://mystart.magentic.com/?loc=FF_Magentic_AddressBar&search=
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\programmi\QuickTime\Plugins\npqtplugin8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-27 13:45
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\11.tmp"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6D835690-900B-11D0-9484************\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]
@=""
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6D835690-900B-11D0-9484************\ProgId]
@="MSSTDFMT.StdDataFormat.1"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6D835690-900B-11D0-9484************\Programmable]
@=""
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6D835690-900B-11D0-9484************\TypeLib]
@="{6B263850-900B-11D0-9484-00A0C91110ED}"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6D835690-900B-11D0-9484************\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6D835690-900B-11D0-9484************\VersionIndependentProgID]
@="MSSTDFMT.StdDataFormat"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(788)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(1920)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2009-06-27 13.47.53
ComboFix-quarantined-files.txt 2009-06-27 11:47
Pre-Run: 65.180.438.528 byte disponibili
Post-Run: 65.167.007.744 byte disponibili
175