Sono ancora deibilitatuccio e confermo che il PC mi sembra infetto e quindi la causa anche della mia infezione.
Comunque ecco il log di combofix appena effettuato, attendo vs illuminazioni con ansia..
ComboFix 08-12-06.06 - Utente 2008-12-08 9.04.30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.600 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\desktop\combofix.exe
Interruttori di comando utilizzati :: /killall
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\AutoRun.inf
c:\windows\system32\com5.jdb
.
((((((((((((((((((((((((( Files Creati Da 2008-11-08 al 2008-12-08 )))))))))))))))))))))))))))))))))))
.
2008-12-01 13:57 . 2008-12-01 13:57 <DIR> d-------- c:\programmi\CCleaner
2008-11-28 17:58 . 2008-11-28 17:58 <DIR> d-------- c:\programmi\Trend Micro
2008-11-28 08:24 . 2008-11-28 08:24 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2008-11-28 08:03 . 2008-11-28 08:03 17,905,664 --a------ c:\programmi\IKEA_Home_Planner_K09.exe
2008-11-25 12:24 . 2008-12-01 13:56 <DIR> d-------- c:\programmi\Spybot - Search & Destroy
2008-11-25 12:24 . 2008-12-01 19:09 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-11-12 07:48 . 2008-09-04 18:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 07:45 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-28 13:49 71,147 ----a-w c:\programmi\date_AIL.pdf
2008-11-28 08:37 --------- d-----w c:\programmi\IKEA HomePlanner
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2004-08-19 11:00 114,688 ----a-w c:\programmi\calc.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-01-05 176128]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"HP Component Manager"="c:\programmi\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"avgnt"="c:\programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 c:\windows\SOUNDMAN.EXE]
"DXDllRegExe"="dxdllreg.exe" [2002-12-11 c:\windows\system32\dxdllreg.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-01-05 176128]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2008-07-08 185896]
"hpqSRMon"="c:\programmi\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-06-24 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=\\?\c:\windows\system32\com5.jdb
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programmi\\UCLES\\EFLCOMMS For Windows v2.0\\bin\\EFLCOMMS.exe"=
R2 procguard;procguard;\??\c:\windows\system32\drivers\procguard.sys [2006-11-30 26688]
S2 WebGkv;WebGkv;"c:\programmi\File comuni\System\egtt.exe" [2004-08-19 173568]
S4 DCSPGSRV;DiamondCS ProcessGuard Service v3.410; []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3815f724-34f0-11dc-80ca-000fea328a03}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{555e8c86-9500-11dd-82f1-000fea328a03}]
\Shell\AutoRun\command - F:\Installer.exe
.
Contenuto della cartella 'Scheduled Tasks'
2008-11-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
2008-12-05 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-04-23 16:17]
2008-12-08 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-04-23 16:17]
.
- - - - ORFÃOS REMOVIDOS - - - -
HKCU-Run-Cmaudio - cmicnfg.cpl
.
------- Supplementare di scansione -------
.
uStart Page =
hxxp://www.google.it/IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {B4BE51C1-2115-4423-A38B-D65B7EC58A6A} = 151.99.125.2,151.99.0.100
c:\windows\system32\mfc42.dll - c:\windows\system32\msvcrt.dll
c:\windows\Downloaded Program Files\pdftotext.txt
c:\windows\Downloaded Program Files\COPYING
c:\windows\Downloaded Program Files\README
c:\windows\Downloaded Program Files\pdf2text.exe
c:\windows\Downloaded Program Files\msconv.exe
c:\windows\Downloaded Program Files\iw.ocx
O16 -: {ED5D2306-0FF4-11D2-B37C-0000C000D50D}
hxxp://www.ausl.ra.it/aur4/code/iwfull.cabc:\windows\Downloaded Program Files\IW.INF
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-08 09:17:43
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebGkv]
"ImagePath"="\"c:\programmi\File comuni\System\egtt.exe\""
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
.
**************************************************************************
.
Ora fine scansione: 2008-12-08 9:22:27 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-12-08 08:22:24
Pre-Run: 60.304.257.024 byte disponibili
Post-Run: 60,332,404,736 byte disponibili
123 --- E O F --- 2008-11-13 19:02:55