OK, ho fatto la scansione, ecco il log:
ComboFix 09-10-01.05 - Proprietario 02/10/2009 17.51.17.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.511.247 [GMT 2:00]
Eseguito da: c:\documents and settings\Proprietario\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-09-02 al 2009-10-02 )))))))))))))))))))))))))))))))))))
.
2009-10-02 00:49 . 2009-10-02 00:49 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Malwarebytes
2009-10-02 00:49 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-02 00:49 . 2009-10-02 00:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-10-02 00:49 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-02 00:49 . 2009-10-02 00:49 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-10-01 22:57 . 2009-10-01 22:57 -------- d-----w- c:\programmi\CCleaner
2009-09-12 19:35 . 2009-09-12 19:35 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-09-12 19:34 . 2009-09-12 19:34 -------- d-sh--w- c:\documents and settings\Proprietario\IECompatCache
2009-09-12 19:32 . 2009-09-12 19:32 -------- d-sh--w- c:\documents and settings\Proprietario\PrivacIE
2009-09-12 19:28 . 2009-09-12 19:28 -------- d-sh--w- c:\documents and settings\Proprietario\IETldCache
2009-09-12 19:25 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-09-12 19:25 . 2009-09-14 01:01 -------- d-----w- c:\windows\ie8updates
2009-09-12 19:24 . 2009-07-03 16:55 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-09-12 19:24 . 2009-07-03 16:55 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-12 19:21 . 2009-09-12 19:23 -------- dc-h--w- c:\windows\ie8
2009-09-08 22:29 . 2009-06-21 21:47 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-02 18:03 . 2009-06-25 08:25 54272 -c----w- c:\windows\system32\dllcache\wdigest.dll
2009-09-02 18:03 . 2009-06-25 08:25 136192 -c----w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-02 18:03 . 2009-06-24 11:18 92928 -c----w- c:\windows\system32\dllcache\ksecdd.sys
2009-09-02 18:03 . 2009-06-25 08:25 301568 -c----w- c:\windows\system32\dllcache\kerberos.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-01 21:34 . 2009-03-11 19:00 17864 ----a-w- c:\documents and settings\Proprietario\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-01 13:37 . 2009-03-09 20:08 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\SACore
2009-09-23 15:01 . 2009-05-20 13:25 -------- d-----w- c:\programmi\DNA
2009-09-23 14:26 . 2009-03-09 19:28 -------- d-----w- c:\programmi\McAfee
2009-09-17 14:46 . 2009-03-09 19:04 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\U3
2009-09-12 18:57 . 2009-02-16 22:43 -------- d-----w- c:\programmi\Java
2009-09-01 01:20 . 2001-08-31 15:00 79826 ----a-w- c:\windows\system32\perfc010.dat
2009-09-01 01:20 . 2001-08-31 15:00 479776 ----a-w- c:\windows\system32\perfh010.dat
2009-09-01 01:13 . 2009-09-01 01:13 -------- d-----w- c:\programmi\MSBuild
2009-09-01 01:13 . 2009-09-01 01:13 -------- d-----w- c:\programmi\Reference Assemblies
2009-09-01 00:59 . 2009-09-01 00:59 -------- d-----w- c:\programmi\MSXML 4.0
2009-08-05 20:54 . 2009-08-05 20:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\InstallShield
2009-08-05 20:51 . 2009-08-05 20:51 -------- d-----w- c:\programmi\Mindscape
2009-08-05 20:51 . 2009-02-16 22:33 -------- d-----w- c:\programmi\File comuni\InstallShield
2009-08-05 20:51 . 2009-02-16 22:33 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-08-05 08:59 . 2004-08-19 13:39 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 18:24 . 2009-08-03 18:24 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Nero
2009-08-03 18:23 . 2009-08-03 18:20 -------- d-----w- c:\programmi\File comuni\Nero
2009-08-03 18:20 . 2009-08-03 18:20 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2009-08-03 18:20 . 2009-08-03 18:20 -------- d-----w- c:\programmi\Nero
2009-07-25 03:23 . 2009-03-15 21:53 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2004-08-19 13:39 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 10:32 . 2009-03-09 19:29 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-07-12 10:21 . 2004-08-19 13:39 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 11:44 . 2009-03-09 19:29 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-07-08 11:44 . 2009-03-09 19:29 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-07-08 11:44 . 2009-03-09 19:29 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-07-08 11:44 . 2009-01-09 11:03 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-07-08 11:43 . 2009-03-09 19:21 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 339968]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2003-04-24 110592]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2003-04-24 610304]
"mcagent_exe"="c:\programmi\McAfee.com\Agent\mcagent.exe" [2009-07-09 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-07 1176808]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2009-02-16 67584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Sitecom Wireless Utility.lnk - c:\programmi\Sitecom\Common\RaUI.exe [2009-3-9 1527808]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\File comuni\\McAfee\\MNA\\McNASvc.exe"=
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\programmi\McAfee\SiteAdvisor\McSACore.exe [09/03/2009 21.32.45 210216]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [09/03/2009 21.09.11 564480]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenuto della cartella 'Scheduled Tasks'
2009-09-14 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-09 19:26]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://google.it/
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\programmi\PokerStars.IT\PokerStarsUpdate.exe
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-02 17:56
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3968)
c:\windows\system32\WININET.dll
c:\programmi\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\webcheck.dll
.
Ora fine scansione: 2009-10-02 17.58.20
ComboFix-quarantined-files.txt 2009-10-02 15:58
Pre-Run: 54.590.631.936 byte disponibili
Post-Run: 54.580.621.312 byte disponibili
133 --- E O F --- 2009-09-14 01:01