Ciao Elektra, grazie per l'intervento.
Ho seguito i tuoi consigli, ecco come richiesto il rapporto di Combofix:
ComboFix 10-05-10.03 - Falco 11/05/2010 21.08.27.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1022.743 [GMT 2:00]
Eseguito da: d:\documents and settings\Falco\Desktop\ComboFix.exe
AV: avast! Internet Security *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-04-11 al 2010-05-11 )))))))))))))))))))))))))))))))))))
.
2010-05-11 09:53 . 2010-05-11 09:53 397824 ----a-w- d:\windows\system32\CF1716.exe
2010-05-06 20:28 . 2010-05-06 20:28 -------- d-----w- d:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
2010-05-06 20:23 . 2010-05-06 20:23 -------- d-----w- d:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Google
2010-05-06 20:22 . 2010-05-06 20:49 -------- d-----w- d:\programmi\Google
2010-05-05 20:21 . 2010-05-05 20:21 -------- d-----w- d:\documents and settings\Falco\Dati applicazioni\AVS4YOU
2010-05-05 20:20 . 2010-05-05 20:20 -------- d-----w- d:\docume~1\ALLUSE~1\DATIAP~1\AVS4YOU
2010-05-05 20:16 . 2010-05-05 20:17 -------- d-----w- d:\programmi\File comuni\AVSMedia
2010-05-05 20:16 . 2003-05-21 22:50 1700352 ----a-w- d:\windows\system32\GdiPlus.dll
2010-05-05 20:14 . 2010-05-05 20:14 -------- d-----w- d:\windows\system32\drivers\umdf
2010-05-05 20:14 . 2006-08-11 18:14 22752 ----a-w- d:\windows\system32\spupdsvc.exe
2010-05-05 20:13 . 2003-05-21 10:50 24576 ----a-w- d:\windows\system32\msxml3a.dll
2010-05-05 20:13 . 2010-05-05 22:01 -------- d-----w- d:\programmi\AVS4YOU
2010-05-02 18:40 . 2010-05-02 18:40 -------- d-----w- d:\documents and settings\Falco\Dati applicazioni\AccurateRip
2010-05-02 18:39 . 2010-05-02 18:40 -------- d-----w- d:\programmi\Exact Audio Copy
2010-04-30 20:36 . 2010-04-30 20:36 -------- d-----w- d:\programmi\Alwil Software
2010-04-30 20:36 . 2010-04-30 20:36 -------- d-----w- d:\docume~1\ALLUSE~1\DATIAP~1\Alwil Software
2010-04-30 10:12 . 2010-04-30 10:12 -------- d--h--w- d:\windows\PIF
2010-04-28 12:33 . 2010-04-28 12:33 -------- d-----w- d:\documents and settings\Falco\Dati applicazioni\Malwarebytes
2010-04-28 12:32 . 2010-04-29 13:39 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-04-28 12:32 . 2010-04-28 12:32 -------- d-----w- d:\docume~1\ALLUSE~1\DATIAP~1\Malwarebytes
2010-04-28 12:32 . 2010-04-29 13:39 20952 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-04-28 12:32 . 2010-04-30 05:47 -------- d-----w- d:\programmi\Malwarebytes' Anti-Malware
2010-04-27 20:32 . 2010-04-27 20:32 -------- d-----w- d:\documents and settings\Falco\Impostazioni locali\Dati applicazioni\ESET
2010-04-27 12:49 . 2010-04-27 12:49 -------- d-----w- d:\docume~1\ALLUSE~1\DATIAP~1\ESET
2010-04-27 10:59 . 2010-04-27 10:59 -------- d-----w- d:\programmi\Trend Micro
2010-04-26 21:26 . 2010-04-26 21:26 -------- d-----w- d:\windows\system32\wbem\Repository
2010-04-26 07:45 . 2010-04-26 07:45 -------- d-----w- d:\documents and settings\NetworkService\Menu Avvio
2010-04-25 22:11 . 2009-03-24 14:08 55640 ----a-w- d:\windows\system32\drivers\avgntflt.sys
2010-04-25 22:11 . 2010-04-26 20:52 -------- d-----w- d:\docume~1\ALLUSE~1\DATIAP~1\Avira
2010-04-25 08:05 . 2010-04-25 08:05 -------- d-----w- d:\programmi\uTorrent
2010-04-25 08:04 . 2010-05-11 18:10 -------- d-----w- d:\documents and settings\Falco\Dati applicazioni\uTorrent
2010-04-25 07:17 . 2010-04-25 07:17 -------- d-----w- d:\programmi\EasyPrediction
2010-04-24 18:34 . 2010-04-24 18:34 -------- d-----w- d:\programmi\eMule
2010-04-22 19:53 . 2010-05-06 20:30 -------- d-----w- d:\documents and settings\Falco\Impostazioni locali\Dati applicazioni\Temp
2010-04-22 19:53 . 2010-05-06 20:31 -------- d-----w- d:\documents and settings\Falco\Impostazioni locali\Dati applicazioni\Google
2010-04-22 15:16 . 2010-04-22 15:16 184320 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\wlan4.dll
2010-04-22 15:16 . 2010-04-22 15:16 10752 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\system.dll
2010-04-22 15:16 . 2010-04-22 15:16 90624 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\secure.dll
2010-04-22 15:16 . 2010-04-22 15:16 116736 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\roting4.dll
2010-04-22 15:16 . 2010-04-22 15:16 71168 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\mpls.dll
2010-04-22 15:16 . 2010-04-22 15:16 109056 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\ppp.dll
2010-04-22 15:16 . 2010-04-22 15:16 69632 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\dhcp.dll
2010-04-22 15:16 . 2010-04-22 15:16 69632 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\advtool.dll
2010-04-22 15:15 . 2010-04-22 15:16 1531904 ----a-w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik\Winbox\4.5\roteros.dll
2010-04-22 15:15 . 2010-04-22 15:15 -------- d-----w- d:\documents and settings\Falco\Dati applicazioni\Mikrotik
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-25 21:45 . 2009-11-01 14:45 -------- d-----w- d:\docume~1\ALLUSE~1\DATIAP~1\avg9
2010-04-25 21:45 . 2009-06-20 20:33 -------- d-----w- d:\programmi\AVG
2010-04-25 05:36 . 2010-03-15 08:53 -------- d---a-w- d:\docume~1\ALLUSE~1\DATIAP~1\TEMP
2010-04-25 05:35 . 2010-03-15 08:53 -------- d-----w- d:\programmi\SpywareBlaster
2010-04-15 20:37 . 2010-04-08 09:29 -------- d-----w- d:\documents and settings\Falco\Dati applicazioni\Vso
2010-04-14 16:47 . 2010-04-30 20:37 38848 ----a-w- d:\windows\system32\avastSS.scr
2010-04-14 16:47 . 2010-04-30 20:37 153184 ----a-w- d:\windows\system32\aswBoot.exe
2010-04-14 16:37 . 2010-04-30 20:37 102736 ----a-w- d:\windows\system32\drivers\aswFW.sys
2010-04-14 16:37 . 2010-04-30 20:37 297552 ----a-w- d:\windows\system32\drivers\aswSnx.sys
2010-04-14 16:36 . 2010-04-30 20:37 196048 ----a-w- d:\windows\system32\drivers\aswNdis2.sys
2010-04-14 16:35 . 2010-04-30 20:37 46672 ----a-w- d:\windows\system32\drivers\aswTdi.sys
2010-04-14 16:35 . 2010-04-30 20:37 162768 ----a-w- d:\windows\system32\drivers\aswSP.sys
2010-04-14 16:31 . 2010-04-30 20:37 23376 ----a-w- d:\windows\system32\drivers\aswRdr.sys
2010-04-14 16:31 . 2010-04-30 20:37 100432 ----a-w- d:\windows\system32\drivers\aswmon2.sys
2010-04-14 16:31 . 2010-04-30 20:37 94800 ----a-w- d:\windows\system32\drivers\aswmon.sys
2010-04-14 16:31 . 2010-04-30 20:37 19024 ----a-w- d:\windows\system32\drivers\aswFsBlk.sys
2010-04-14 16:30 . 2010-04-30 20:37 28880 ----a-w- d:\windows\system32\drivers\aavmker4.sys
2010-04-10 18:48 . 2009-07-05 18:26 69224 ----a-w- d:\documents and settings\Falco\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-04-08 09:29 . 2010-04-08 09:29 47360 ----a-w- d:\windows\system32\drivers\pcouffin.sys
2010-04-08 09:29 . 2010-04-08 09:29 47360 ----a-w- d:\documents and settings\Falco\Dati applicazioni\pcouffin.sys
2010-04-08 09:29 . 2010-04-08 09:29 47360 ----a-w- d:\documents and settings\Falco\Dati applicazioni\pcouffin.sys
2010-04-08 09:29 . 2010-04-08 09:29 -------- d-----w- d:\programmi\vso
2010-03-28 08:36 . 2001-08-31 18:00 48568 ----a-w- d:\windows\system32\perfc010.dat
2010-03-28 08:36 . 2001-08-31 18:00 347866 ----a-w- d:\windows\system32\perfh010.dat
2010-03-19 19:10 . 2010-04-30 20:37 12112 ----a-w- d:\windows\system32\drivers\aswNdis.sys
.
------- Sigcheck -------
[-] 2006-04-11 . 744BE027C16680791A6AC13E0EF35F8F . 1548288 . . [5.1.2600.2180] . . d:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-04-14 16:33 140288 ----a-w- d:\programmi\Alwil Software\Avast5\snxPlugins.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="d:\documents and settings\Falco\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2010-04-22 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"Malwarebytes' Anti-Malware"="d:\programmi\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
"avast5"="d:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-04-14 2790472]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="d:\windows\system32\tscupgrd.exe" [2004-08-19 44544]
d:\documents and settings\Falco\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - d:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
d:\docume~1\ALLUSE~1\MENUAV~1\PROGRA~1\ESECUZ~1\
Avvio veloce di Adobe Reader.lnk - d:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Programmi\\eMule\\emule.exe"=
"d:\\Programmi\\uTorrent\\uTorrent.exe"=
R0 aswNdis;avast! Firewall NDIS Filter Service;d:\windows\system32\drivers\aswNdis.sys [30/04/2010 22.37.02 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;d:\windows\system32\drivers\aswNdis2.sys [30/04/2010 22.37.23 196048]
R1 aswFW;avast! TDI Firewall driver;d:\windows\system32\drivers\aswFW.sys [30/04/2010 22.37.35 102736]
R1 aswSnx;aswSnx;d:\windows\system32\drivers\aswSnx.sys [30/04/2010 22.37.35 297552]
R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [30/04/2010 22.37.36 162768]
R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [01/10/2009 15.06.40 108792]
R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [01/10/2009 15.07.30 96408]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [30/04/2010 22.37.36 19024]
R3 MBAMProtector;MBAMProtector;d:\windows\system32\drivers\mbam.sys [28/04/2010 14.32.54 20952]
S2 avast! Firewall;avast! Firewall;d:\programmi\Alwil Software\Avast5\afwServ.exe [30/04/2010 22.37.02 119200]
S2 MBAMService;MBAMService;d:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe [28/04/2010 14.33.01 304464]
.
Contenuto della cartella 'Scheduled Tasks'
2010-05-11 d:\windows\Tasks\AWC AutoSweep.job
- d:\programmi\IObit\Advanced SystemCare 3\AutoSweep.exe [2009-10-01 10:17]
2010-05-10 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-606747145-1801674531-1003Core.job
- d:\documents and settings\Falco\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-22 19:53]
2010-05-11 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-606747145-1801674531-1003UA.job
- d:\documents and settings\Falco\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-22 19:53]
.
.
------- Scansione supplementare -------
.
IE: E&sporta in Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {34791712-14DF-4B36-B393-769A0DB611A4} = 217.12.180.19,217.12.181.97
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-11 21:23
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2432)
d:\windows\system32\msi.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-05-11 21:24:54
ComboFix-quarantined-files.txt 2010-05-11 19:24
ComboFix2.txt 2010-05-11 10:38
ComboFix3.txt 2009-10-02 07:12
ComboFix4.txt 2009-10-01 20:16
Pre-Run: 3.943.571.456 byte disponibili
Post-Run: 3.916.386.304 byte disponibili
- - End Of File - - 16C5954F24ED0A17C6CD6F3983E1CFA9