Cavolo, ComboFix manda dei messaggi terrorizzanti simili a quelli sull'autostrada (1000000 di morti a causa dell'alta velocità, rallenta!), inoltre mi segnalava AVG Scanning ancora attivo, allora ho premuto sulla X ma lui è partito ugualmente... speriamo bene.
Ecco il Log di Combofix, aspetto info, Grazie 1000, ciao.
ComboFix 09-11-24.02 - User 25/11/2009 11.10.02.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3071.2475 [GMT 1:00]
Eseguito da: c:\documents and settings\User\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\User\Dati applicazioni\inst.exe
c:\windows\system32\tmp10.tmp
c:\windows\system32\tmp11.tmp
c:\windows\system32\tmp16.tmp
c:\windows\system32\tmp17.tmp
.
((((((((((((((((((((((((( Files Creati Da 2009-10-25 al 2009-11-25 )))))))))))))))))))))))))))))))))))
.
2009-11-23 22:45 . 2008-04-14 02:13 26624 ----a-w- c:\documents and settings\LocalService\Dati applicazioni\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-11-23 22:43 . 2009-11-23 22:43 -------- d-----w- c:\documents and settings\User\Dati applicazioni\eMule AdunanzA
2009-11-23 11:00 . 2009-11-23 11:00 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-11-23 10:01 . 2009-11-23 10:01 -------- d-----w- c:\documents and settings\User\Dati applicazioni\Malwarebytes
2009-11-23 10:01 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-23 10:01 . 2009-11-23 10:01 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-11-23 10:01 . 2009-11-23 10:01 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-11-23 10:01 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-23 09:31 . 2009-11-23 09:31 -------- d-----w- c:\programmi\Trend Micro
2009-11-22 22:21 . 2009-11-22 22:21 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-11-22 22:19 . 2009-11-23 20:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2009-11-22 13:33 . 2009-11-22 13:33 -------- d-----w- c:\programmi\IKEA HomePlanner
2009-11-22 13:33 . 2009-11-22 13:33 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-11-20 17:39 . 2009-11-20 17:39 4096 ----a-w- c:\windows\d3dx.dat
2009-11-20 17:23 . 2009-11-20 17:23 -------- d-----w- c:\programmi\CPUID
2009-11-20 16:40 . 2009-11-18 18:26 497944 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgchjwx.dll
2009-11-20 16:40 . 2009-11-18 18:26 3963648 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgcorex.dll
2009-11-20 16:39 . 2009-11-18 18:26 877848 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.exe
2009-11-20 16:39 . 2009-11-18 18:26 1657112 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.dll
2009-11-18 18:27 . 2009-11-18 18:34 -------- d-----w- C:\$AVG
2009-11-18 18:27 . 2009-11-18 18:27 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-18 18:27 . 2009-11-18 18:27 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-18 18:27 . 2009-11-18 18:27 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-18 18:27 . 2009-11-18 18:27 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-18 18:27 . 2009-11-25 10:07 -------- d-----w- c:\windows\system32\drivers\Avg
2009-11-18 18:26 . 2009-11-25 10:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2009-11-18 18:03 . 2009-11-23 20:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-11-18 18:03 . 2009-11-18 18:05 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-11-18 15:52 . 2009-11-18 15:52 -------- d-----w- c:\documents and settings\HelpAssistant\IECompatCache
2009-11-18 15:43 . 2009-11-18 15:43 -------- d-sh--w- c:\documents and settings\User\IECompatCache
2009-11-17 08:38 . 2009-11-17 08:39 -------- d--h--w- c:\documents and settings\HelpAssistant\Impostazioni locali
2009-11-17 08:38 . 2008-11-11 02:29 -------- d--h--w- c:\documents and settings\HelpAssistant\Risorse di stampa
2009-11-17 08:38 . 2008-11-11 02:29 -------- d--h--w- c:\documents and settings\HelpAssistant\Risorse di rete
2009-11-17 08:38 . 2008-11-11 02:29 -------- d-----w- c:\documents and settings\HelpAssistant\Documenti
2009-11-17 08:38 . 2008-11-11 01:34 -------- d--h--w- c:\documents and settings\HelpAssistant\Modelli
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-23 22:44 . 2008-12-04 21:19 -------- d-----w- c:\programmi\eMule AdunanzA
2009-11-23 21:16 . 2008-11-10 18:46 -------- d-----w- c:\programmi\File comuni\Adobe
2009-11-23 08:59 . 2009-01-22 21:33 -------- d-----w- c:\documents and settings\User\Dati applicazioni\Skype
2009-11-18 18:26 . 2008-11-10 18:54 -------- d-----w- c:\programmi\AVG
2009-11-18 18:10 . 2008-12-04 21:05 -------- d-----w- c:\documents and settings\User\Dati applicazioni\DNA
2009-11-18 17:54 . 2008-11-10 18:47 -------- d-----w- c:\programmi\CCleaner
2009-11-18 17:40 . 2008-12-04 21:05 -------- d-----w- c:\programmi\DNA
2009-11-17 14:51 . 2009-01-22 21:37 -------- d-----w- c:\documents and settings\User\Dati applicazioni\skypePM
2009-10-25 21:09 . 2001-08-31 11:00 80268 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 21:09 . 2001-08-31 11:00 481664 ----a-w- c:\windows\system32\perfh010.dat
2009-09-11 14:17 . 2004-08-19 13:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-19 13:39 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-08-19 13:39 916480 ----a-w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-02-25 148888]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-18 2020120]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2009-01-05 413696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-16 16855552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-10 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-18 18:27 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\DNA\\btdna.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Adobe\\Adobe Dreamweaver CS3\\Dreamweaver.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18/11/2009 19.27.11 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18/11/2009 19.27.16 360584]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [11/11/2008 2.43.44 13696]
R2 avg9wd;AVG Free WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [18/11/2009 19.26.48 285392]
S3 magpsc;magpsc;c:\windows\system32\drivers\magpsc.sys [29/04/2009 14.34.25 53719]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\User\Dati applicazioni\Mozilla\Firefox\Profiles\z6efph6w.default\
FF - component: c:\programmi\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
AddRemove-CanonMyPrinter - c:\programmi\Canon\MyPrinter\uninst.exe uninst.ini
AddRemove-CanonSolutionMenu - c:\programmi\Canon\SolutionMenu\uninst.exe uninst.ini
AddRemove-Easy-PhotoPrint EX - c:\programmi\Canon\Easy-PhotoPrint EX\uninst.exe uninst.ini
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-25 11:14
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x89635F30]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> 0x89635f30
\Driver\atapi -> prosync1.sys @ 0xba5b06c1
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8102E Family PCI-E Fast Ethernet NIC -> SendCompleteHandler -> 0x89672480
PacketIndicateHandler -> NDIS.sys @ 0xb9e0ca0d
SendHandler -> NDIS.sys @ 0xb9e20b40
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x03A384C41
malicious code @ sector 0x03A384C44 !
PE file found in sector at 0x03A384C5A !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(760)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-11-25 11:15
ComboFix-quarantined-files.txt 2009-11-25 10:15
Pre-Run: 127.743.803.392 byte disponibili
Post-Run: 127.742.578.688 byte disponibili
- - End Of File - - 8FB1BCDD6BE77531C34B0CCAA787C0E1