Ecco il log di Combofix:.
ComboFix 12-10-18.03 - Simone 19/10/2012 1.11.02.1.1 - x86
Microsoft® Windows Vistaâ„¢ Home Basic 6.0.6002.2.1252.39.1040.18.2813.1983 [GMT 2:00]
Eseguito da: c:\users\Simone\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\aVKb5i6SvuBvOz
c:\programdata\aVKb5i6SvuBvOz.exe
c:\programdata\dsgsdgdsgdsgw.pad
c:\users\Simone\AppData\Roaming\Ceog
c:\users\Simone\AppData\Roaming\Ceog\ycgi.mel
c:\users\Simone\AppData\Roaming\Ceog\ycgi.tmp
c:\users\Simone\AppData\Roaming\Microsoft\Windows\Recent\http--oknotizie.virgilio.it-go.phpus=20a1183da7a51226.url
.
.
((((((((((((((((((((((((( Files Creati Da 2012-09-18 al 2012-10-18 )))))))))))))))))))))))))))))))))))
.
.
2012-10-18 23:19 . 2012-10-18 23:22 -------- d-----w- c:\users\Simone\AppData\Local\temp
2012-10-18 22:55 . 2012-10-18 22:55 -------- d-----w- c:\users\Simone\AppData\Roaming\HPAppData
2012-10-18 09:17 . 2012-10-18 22:21 1486328 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2012-09-27 18:43 . 2012-09-27 18:43 -------- d-----w- c:\users\Simone\AppData\Local\ElevatedDiagnostics
2012-09-27 18:00 . 2012-09-27 18:00 -------- d-----w- c:\program files\Defraggler
2012-09-27 17:39 . 2012-09-27 17:39 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-07 15:04 . 2012-08-18 10:56 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-23 07:15 . 2012-09-14 12:17 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21534EBB-AD43-45F2-B2BF-7C6772D65D5F}\mpengine.dll
2012-08-13 21:05 . 2012-03-19 14:56 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-08-13 21:05 . 2010-02-23 19:09 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-13 6711840]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-26 30192]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-01-13 1833504]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-13 348664]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0410&s=2&o=vb32&d=0809&m=e625
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 8.8.8.8 8.8.4.4
FF - ProfilePath - c:\users\Simone\AppData\Roaming\Mozilla\Firefox\Profiles\p4ludovu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.it
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKCU-Run-aVKb5i6SvuBvOz - c:\programdata\aVKb5i6SvuBvOz.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-10-19 01:22
Windows 6.0.6002 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\WLANExt.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\eMachines\eMachines Power Management\ePowerSvc.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\program files\Macrium\Reflect\ReflectService.exe
c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Avira\AntiVir Desktop\avmailc.exe
c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE
c:\windows\system32\conime.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Ora fine scansione: 2012-10-19 01:33:15 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-10-18 23:33
.
Pre-Run: 76.412.162.048 byte disponibili
Post-Run: 76.436.103.168 byte disponibili
.
- - End Of File - - 6F39C9A0FCA554896C42470B50160881