Grazie ancora per l'aiuto.
Ho fatto tutto ciò che mi avete detto.
Copio il log di Combofix:
ComboFix 10-06-03.01 - AmiCo 05/06/2010 13.30.54.1.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.1022.490 [GMT 2:00]
Eseguito da: c:\documents and settings\AmiCo\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
I seguenti file sono stati disabilitati durante la scansione:
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\WinPCap
c:\programmi\WinPCap\daemon_mgm.exe
c:\programmi\WinPCap\npf_mgm.exe
c:\programmi\WinPCap\rpcapd.exe
c:\windows\system\msvcr71.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000011_.tmp.dll
c:\windows\system32\_000014_.tmp.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Files Creati Da 2010-05-05 al 2010-06-05 )))))))))))))))))))))))))))))))))))
.
2010-06-05 09:22 . 2010-06-05 09:22 -------- d-----w- c:\documents and settings\AmiCo\Dati applicazioni\Malwarebytes
2010-06-05 09:22 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-05 09:22 . 2010-06-05 09:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-06-05 09:22 . 2010-06-05 09:22 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-06-05 09:22 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-05 08:02 . 2010-06-05 08:02 388096 ----a-r- c:\documents and settings\AmiCo\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-05 08:02 . 2010-06-05 08:02 -------- d-----w- c:\programmi\Trend Micro
2010-06-05 07:58 . 2010-06-05 07:58 -------- d-----w- c:\documents and settings\AmiCo\Dati applicazioni\.clamwin
2010-06-05 07:58 . 2010-06-05 07:58 -------- d-----w- c:\programmi\ClamWin
2010-06-05 07:58 . 2010-06-05 07:58 -------- d-----w- c:\documents and settings\All Users\.clamwin
2010-06-05 07:21 . 2010-06-05 07:22 -------- d-----w- c:\documents and settings\AmiCo\Dati applicazioni\Yahoo!
2010-06-05 07:21 . 2010-06-05 07:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2010-06-05 07:21 . 2010-06-05 07:21 -------- d-----w- c:\programmi\Yahoo!
2010-06-05 07:21 . 2010-06-05 07:21 -------- d-----w- c:\programmi\CCleaner
2010-06-05 07:19 . 2010-06-05 07:19 -------- d-----w- c:\documents and settings\AmiCo\Dati applicazioni\AVG8
2010-06-05 07:00 . 2010-06-05 07:00 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2010-06-05 06:29 . 2010-06-05 06:29 -------- d-----w- C:\FOUND.020
2010-06-05 06:08 . 2010-06-05 06:08 -------- d-----w- C:\FOUND.019
2010-06-04 08:25 . 2010-06-04 08:25 -------- d-----w- C:\FOUND.018
2010-06-03 13:57 . 2010-06-03 13:57 -------- d-----w- C:\FOUND.017
2010-06-03 13:39 . 2010-06-03 13:39 -------- d-----w- C:\FOUND.016
2010-06-03 07:55 . 2010-06-03 07:55 -------- d-----w- C:\FOUND.015
2010-06-02 15:50 . 2010-06-02 15:50 -------- d-----w- C:\FOUND.014
2010-06-02 15:46 . 2010-06-02 15:46 -------- d-----w- C:\FOUND.013
2010-06-02 07:47 . 2010-06-02 07:47 -------- d-----w- C:\FOUND.012
2010-06-02 07:43 . 2010-06-02 07:43 -------- d-----w- C:\FOUND.011
2010-06-01 08:07 . 2010-06-01 08:07 -------- d-----w- C:\FOUND.010
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-05 06:38 . 2005-10-18 07:11 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-04-10 13:35 . 2010-04-10 13:35 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-04-10 13:35 . 2010-04-10 13:35 -------- d-----w- c:\documents and settings\AmiCo\Dati applicazioni\skypePM
2010-04-10 13:24 . 2010-04-10 13:24 -------- d-----w- c:\documents and settings\AmiCo\Dati applicazioni\Skype
2010-04-10 13:24 . 2010-04-10 13:24 -------- d-----w- c:\programmi\Google
2010-04-10 13:24 . 2010-04-10 13:24 -------- d-----w- c:\programmi\File comuni\Skype
2010-04-10 13:24 . 2010-04-10 13:24 -------- d-----r- c:\programmi\Skype
2010-04-10 13:24 . 2010-04-10 13:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2006-07-05 09:56 . 2004-08-19 03:00 163879 --sh--r- c:\windows\system32\bfjaeezt.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2005-11-01 102491]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-11-01 692315]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2005-12-13 151552]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-02 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-02 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-02 118784]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
"ntiMUI"="c:\programmi\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 16120832]
"AzMixerSel"="c:\programmi\Realtek\InstallShield\AzMixerSel.exe" [2005-08-24 53248]
"ATICCC"="c:\programmi\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-09 352256]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-05-08 3080704]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2006-04-03 471040]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 397312]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2006-03-31 225280]
"LogitechCameraAssistant"="c:\programmi\Acer\OrbiCam\CameraAssistant.exe" [2006-03-31 331776]
"LogitechVideo[inspector]"="c:\programmi\Acer\OrbiCam\InstallHelper.exe" [2006-03-31 08:32 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2006-09-08 77824]
"EPSON Stylus DX4800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE" [2005-02-02 98304]
"ClamWin"="c:\programmi\ClamWin\bin\ClamTray.exe" [2010-05-24 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2006-9-8 113664]
ScheduleTV.lnk - c:\programmi\honestech\honestech TVR\scheduleTV.exe [2006-9-8 307200]
Adobe Reader Speed Launch.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Messenger\\MSMSGS.EXE"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3453:TCP"= 3453:TCP:huxutzgk
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [30/11/2005 5.28.58 1097472]
S2 evpkfkgz;zdtrgywu;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 5.00.00 14336]
S2 gupdate1cad8b12bbedce5;Servizio di Google Update (gupdate1cad8b12bbedce5);c:\programmi\Google\Update\GoogleUpdate.exe [10/04/2010 15.24.38 133104]
S2 ytbfilc;Monitor Task;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 5.00.00 14336]
S3 AVerE506;AVerE506 service;c:\windows\system32\drivers\AVerE506.sys [19/03/2006 20.29.00 520192]
S3 AVerM115;AVerM115 service;c:\windows\system32\drivers\AVerM115.sys [19/03/2006 20.28.00 1274880]
S3 hawhx;hawhx;\??\c:\windows\system32\05.tmp --> c:\windows\system32\05.tmp [?]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [22/03/2010 19.47.23 100736]
S3 ubafzw;ubafzw;\??\c:\windows\system32\05.tmp --> c:\windows\system32\05.tmp [?]
S3 uigpkmuk;uigpkmuk;\??\c:\windows\system32\03.tmp --> c:\windows\system32\03.tmp [?]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - EVPKFKGZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ricajradq
ytbfilc
evpkfkgz
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://global.acer.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
Notify-WgaLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-05 13:35
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hawhx]
"ImagePath"="\??\c:\windows\system32\05.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ubafzw]
"ImagePath"="\??\c:\windows\system32\05.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uigpkmuk]
"ImagePath"="\??\c:\windows\system32\03.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\evpkfkgz]
"ServiceDll"="c:\windows\system32\bfjaeezt.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ytbfilc]
"ServiceDll"="c:\windows\system32\bfjaeezt.dll"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(4296)
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\MSNChatHook.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\MSVCR71.dll
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
c:\acer\Empowering Technology\admServ.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\programmi\CyberLink\Shared Files\RichVideo.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\docume~1\AmiCo\IMPOST~1\Temp\RtkBtMnt.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2010-06-05 13:37:26 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-06-05 11:37
Pre-Run: 38.155.255.808 byte disponibili
Post-Run: 38.089.981.952 byte disponibili
- - End Of File - - 83DA199999E4C16A8929B8A202EFE1FE