ecco il log:
ComboFix 09-09-18.02 - ANTONELLA 22/09/2009 19.58.17.1.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3327.2685 [GMT 2:00]
Eseguito da: c:\documents and settings\ANTONELLA\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Sunbelt Kerio Personal Firewall *disabled* {E659E0EE-10E6-49B7-8696-60F38D0EB174}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Alcmtr.exe
c:\windows\Installer\595929b.msp
c:\windows\Installer\59592b2.msp
c:\windows\Installer\59592d0.msp
c:\windows\Installer\59592e6.msp
c:\windows\Installer\5959302.msp
c:\windows\Installer\59593c3.msp
c:\windows\Installer\59593cc.msp
c:\windows\Installer\59593e0.msp
c:\windows\Installer\59593ee.msp
c:\windows\Installer\595942b.msp
c:\windows\Installer\5959432.msp
c:\windows\Installer\595943b.msp
c:\windows\Installer\595945f.msp
c:\windows\Installer\5959476.msp
c:\windows\Installer\595949c.msp
c:\windows\Installer\59594b3.msp
c:\windows\Installer\59594cc.msp
c:\windows\Installer\59594e3.msp
c:\windows\Installer\59594fb.msp
c:\windows\Installer\5959512.msp
c:\windows\Installer\5959528.msp
.
((((((((((((((((((((((((( Files Creati Da 2009-08-22 al 2009-09-22 )))))))))))))))))))))))))))))))))))
.
2009-09-14 16:03 . 2009-06-21 21:47 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-08-31 06:22 . 2009-08-31 06:22 -------- d-----w- c:\programmi\Xvid
2009-08-31 06:22 . 2008-12-04 19:46 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2009-08-31 06:22 . 2008-12-04 19:42 815104 ----a-w- c:\windows\system32\xvidcore.dll
2009-08-31 06:22 . 2009-08-31 06:22 -------- d-----w- c:\programmi\FDRLab
2009-08-26 00:36 . 2009-08-26 00:36 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-08-26 00:36 . 2009-08-26 00:36 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-26 00:36 . 2009-08-26 00:36 -------- d-----w- c:\programmi\Reference Assemblies
2009-08-26 00:36 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-26 00:36 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-26 00:36 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-26 00:36 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-26 00:36 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-26 00:36 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-26 00:36 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-21 09:44 . 2009-02-22 18:43 -------- d-----w- c:\programmi\Microsoft Encarta
2009-09-19 17:26 . 2009-02-22 18:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-09-19 17:26 . 2009-02-28 15:40 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-09-19 17:25 . 2009-02-22 18:24 -------- d-----w- c:\programmi\SpywareBlaster
2009-09-16 14:46 . 2009-02-22 16:39 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-09-16 14:46 . 2009-04-26 10:27 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-09-16 14:43 . 2009-02-22 16:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-09-10 12:54 . 2009-04-26 10:27 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-04-26 10:27 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 13:00 . 2009-03-30 10:00 -------- d-----w- c:\programmi\Java
2009-08-30 14:52 . 2009-02-22 18:23 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-08-26 08:38 . 2009-02-17 09:43 74856 ----a-w- c:\documents and settings\ANTONELLA\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-08-26 00:38 . 2004-08-19 16:27 79514 ----a-w- c:\windows\system32\perfc010.dat
2009-08-26 00:38 . 2004-08-19 16:27 479180 ----a-w- c:\windows\system32\perfh010.dat
2009-08-22 06:00 . 2009-02-22 09:32 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-22 06:00 . 2009-02-22 09:32 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-22 06:00 . 2009-02-22 09:32 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-05 08:59 . 2004-08-19 16:27 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 13:23 . 2009-03-30 10:00 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2004-08-19 16:27 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-03 16:55 . 2004-08-19 16:27 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-19 16:27 735744 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-19 16:27 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-19 16:27 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-19 16:27 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-19 16:27 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-19 16:27 136192 ----a-w- c:\windows\system32\msv1_0.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-22 2007832]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Ad-Watch"="c:\programmi\Lavasoft\Ad-Aware\AAWTray.exe" [2009-09-21 520024]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"DSLSTATEXE"="c:\program files\D-Link\DSL-200\dslstat.exe" [2004-11-26 356352]
"DSLAGENTEXE"="c:\program files\D-Link\DSL-200\dslagent.exe" [2004-11-26 16384]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-06-13 16377344]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-22 06:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [22/02/2009 20.24.04 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [22/02/2009 11.32.30 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [22/02/2009 11.32.31 108552]
R1 fwdrv;Firewall Driver;c:\windows\system32\drivers\fwdrv.sys [18/07/2006 13.02.50 284184]
R1 khips;Kerio HIPS Driver;c:\windows\system32\drivers\khips.sys [18/07/2006 13.02.52 91672]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [22/02/2009 11.32.26 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [22/02/2009 11.32.25 297752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 23.34.37 1028432]
R3 PAC207;Trust WB-1200p Mini Webcam;c:\windows\system32\drivers\PFC027.sys [24/02/2005 13.29.14 162176]
S3 AtmElan;LAN ATM emulata;c:\windows\system32\drivers\atmlane.sys [19/08/2004 18.27.00 55808]
S3 AtmLane;Emulazione LAN ATM;c:\windows\system32\drivers\atmlane.sys [19/08/2004 18.27.00 55808]
S3 atmusb;D-Link DSL-200 USB ADSL ATM Modem;c:\windows\system32\drivers\gaausb.sys [17/04/2009 18.24.32 129857]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenuto della cartella 'Scheduled Tasks'
2009-09-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:24]
2009-09-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {35F708AD-746B-4862-9AD9-37271FC32F86} = 212.216.112.112,212.216.172.62
FF - ProfilePath - c:\documents and settings\ANTONELLA\Dati applicazioni\Mozilla\Firefox\Profiles\hr9tlpag.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/webhp?hl=it
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-E07IXLRD_94921062 - c:\programmi\Microsoft Encarta\Microsoft Encarta 2007 - Premium DVD\EDICT.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-22 20:03
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2009-09-22 20.05.35
ComboFix-quarantined-files.txt 2009-09-22 18:05
Pre-Run: 163.446.947.840 byte disponibili
Post-Run: 163.471.978.496 byte disponibili
168 --- E O F --- 2009-09-16 14:45
domande è normale che il combofix mi impedisca il riavvio del firewall, e che mi metta un icona di explorer sul desktop e mi cambi il browaser predifinito come ha appena fatto in soli dieci secondi... spero non faccia altri danni