Ho fatto tutto. Allego qui sotto il report ottenuto con COMBOFIX:
ComboFix 10-08-27.03 - Generoso 28/08/2010 21.10.18.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1022.734 [GMT 2:00]
Eseguito da: c:\documents and settings\Generoso\Desktop\abc.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Davide\RavMonLog
c:\documents and settings\Generoso\Dati applicazioni\EurekaLog
c:\documents and settings\Generoso\Dati applicazioni\Microsoft\~DFK9ae968.tmp
c:\documents and settings\Generoso\Dati applicazioni\Microsoft\1eaadjc.dll
c:\documents and settings\Generoso\Dati applicazioni\Microsoft\bass.dll
c:\documents and settings\Generoso\Dati applicazioni\Microsoft\kfgresk.dll
c:\documents and settings\Generoso\Dati applicazioni\Microsoft\mjcriu.dll
c:\documents and settings\Generoso\Dati applicazioni\Microsoft\peaadje.dll
c:\documents and settings\Generoso\Dati applicazioni\Microsoft\qwadjb.dll
c:\documents and settings\Generoso\Dati applicazioni\Microsoft\rsaadjd.dll
c:\documents and settings\Generoso\Impostazioni locali\Dati applicazioni\kseoi.dat
c:\documents and settings\Generoso\Impostazioni locali\Dati applicazioni\kseoi_nav.dat
c:\documents and settings\Generoso\Impostazioni locali\Dati applicazioni\kseoi_navps.dat
c:\documents and settings\Generoso\RavMonLog
c:\programmi\autorun.inf
c:\programmi\version.txt
c:\windows\recover.reg
c:\windows\system32\fjhdyfhsn.bat
.
((((((((((((((((((((((((( Files Creati Da 2010-07-28 al 2010-08-28 )))))))))))))))))))))))))))))))))))
.
2010-08-28 18:56 . 2010-08-28 18:59 -------- d-----w- C:\abc
2010-08-28 17:39 . 2010-08-28 17:39 -------- d-----w- c:\windows\LastGood
2010-08-28 17:38 . 2010-08-28 17:38 -------- d-----w- c:\windows\LastGood.Tmp
2010-08-28 14:52 . 2010-08-28 14:52 -------- d-----w- c:\programmi\SDHelper (Spybot - Search & Destroy)
2010-08-28 14:52 . 2010-08-28 14:52 -------- d-----w- c:\programmi\TeaTimer (Spybot - Search & Destroy)
2010-08-28 14:52 . 2010-08-28 14:52 -------- d-----w- c:\programmi\Misc. Support Library (Spybot - Search & Destroy)
2010-08-28 14:52 . 2010-08-28 14:52 -------- d-----w- c:\programmi\File Scanner Library (Spybot - Search & Destroy)
2010-08-28 13:05 . 2010-08-28 13:05 -------- d-----w- c:\documents and settings\Generoso\Impostazioni locali\Dati applicazioni\VS Revo Group
2010-08-28 13:05 . 2009-12-30 10:20 27064 ----a-w- c:\windows\system32\drivers\revoflt.sys
2010-08-28 13:05 . 2010-08-28 13:05 -------- d-----w- c:\programmi\VS Revo Group
2010-08-27 13:10 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-27 13:10 . 2010-08-27 13:10 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-08-27 13:10 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-26 15:06 . 2004-08-03 20:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-08-26 15:06 . 2004-08-03 20:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-08-26 15:06 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-08-26 15:06 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-08-26 15:06 . 2001-08-17 18:13 27165 -c--a-w- c:\windows\system32\dllcache\fetnd5.sys
2010-08-26 15:06 . 2001-08-17 18:13 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
2010-08-26 15:06 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-08-26 10:35 . 2010-08-26 10:35 2944904 ----a-w- c:\documents and settings\Generoso\Dati applicazioni\Mozilla\Firefox\Profiles\7d125c26.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe
2010-08-14 10:47 . 2010-08-14 10:47 -------- d-----w- c:\documents and settings\Generoso\Impostazioni locali\Dati applicazioni\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-28 19:00 . 2010-05-29 11:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Alwil Software
2010-08-28 17:46 . 2007-12-04 18:32 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-08-28 17:45 . 2007-12-04 18:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-08-28 17:37 . 2010-01-13 22:09 -------- d-----w- c:\documents and settings\Generoso\Dati applicazioni\Tor
2010-08-28 11:01 . 2005-08-03 15:27 -------- d-----w- c:\programmi\Servizi in linea
2010-08-28 08:13 . 2005-08-05 09:52 -------- d-----w- c:\programmi\Google
2010-08-28 08:11 . 2009-09-11 16:19 -------- d-----w- c:\programmi\Ask.com
2010-08-27 14:12 . 2010-07-05 15:09 717296 ----a-w- c:\windows\system32\drivers\SPTD.SYS.TMP
2010-08-27 12:39 . 2010-01-14 11:15 -------- d-----w- c:\programmi\CCleaner
2010-08-26 17:19 . 2010-08-26 17:19 12 ----a-w- c:\windows\system32\config\systemprofile\Dati applicazioni\bawuho.dat
2010-08-26 17:19 . 2010-01-13 22:09 -------- d-----w- c:\documents and settings\Generoso\Dati applicazioni\Vidalia
2010-08-26 15:06 . 2010-08-26 15:06 12 ----a-w- c:\documents and settings\Davide\Dati applicazioni\bawuho.dat
2010-08-25 19:17 . 2007-09-21 08:47 -------- d-----w- c:\programmi\eMule
2010-08-06 18:10 . 2010-05-30 13:17 -------- d-----w- c:\documents and settings\Generoso\Dati applicazioni\Shareaza
2010-08-06 18:10 . 2010-05-30 13:17 -------- d-----w- c:\programmi\Shareaza
2010-07-23 18:20 . 2010-07-23 18:20 -------- d-----w- c:\programmi\vanBasco's Karaoke Player
2010-07-21 19:01 . 2009-07-15 16:09 45312 ----a-w- c:\windows\system32\drivers\VIRAGTLT.SYS
2010-07-19 11:00 . 2009-09-16 09:05 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-07-14 10:36 . 2009-11-24 14:06 47564 ----a-w- C:\NTDETECT.COM.TMP
2010-07-14 10:36 . 2009-11-24 14:06 251072 ----a-w- C:\NTLDR.TMP
2010-07-05 15:09 . 2009-11-25 16:48 32458 -c--a-w- c:\windows\SCHEDLGU.TXT.TMP
2010-07-03 14:06 . 2010-07-03 14:06 664 ----a-w- c:\documents and settings\Davide\Impostazioni locali\Dati applicazioni\d3d9caps.dat
2010-06-23 16:35 . 2010-06-23 16:35 501936 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Google\Google Toolbar\Update\gtbB.tmp.exe
2010-06-13 19:04 . 2010-06-13 19:04 286352 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-06-09 08:01 . 2010-06-09 08:01 20330720 ----a-w- c:\documents and settings\Generoso\Dati applicazioni\TomTom\HOME\Profiles\apl857js.default\Updates\v2_7_4_1962_win.exe
2010-04-01 11:17 . 2010-04-01 11:17 604 ---ha-w- c:\programmi\STLL Notifier
2009-07-16 08:00 . 2008-03-16 17:10 6144 --sha-w- c:\programmi\Thumbs.db
2003-05-16 00:31 . 2003-05-16 00:31 2508645 ----a-w- c:\programmi\sonnet-9519.cab
2003-05-16 00:31 . 2003-05-16 00:31 198 ----a-w- c:\programmi\sonnet.ver
2003-05-16 00:31 . 2003-05-16 00:31 1078 ----a-w- c:\programmi\cdicon.ico
2003-05-16 00:31 . 2003-05-16 00:31 2620680 ----a-w- c:\programmi\sonnet-9518.cab
2003-05-16 00:31 . 2003-05-16 00:31 2620827 ----a-w- c:\programmi\sonnet-9517.cab
2003-05-16 00:31 . 2003-05-16 00:31 2618403 ----a-w- c:\programmi\sonnet-9516.cab
2003-05-16 00:31 . 2003-05-16 00:31 3064571 ----a-w- c:\programmi\sonnet-9515.cab
2003-05-16 00:31 . 2003-05-16 00:31 4065692 ----a-w- c:\programmi\sonnet-9514.cab
2003-05-16 00:31 . 2003-05-16 00:31 3256077 ----a-w- c:\programmi\sonnet-9513.cab
2003-05-16 00:30 . 2003-05-16 00:30 2858977 ----a-w- c:\programmi\sonnet-9512.cab
2003-05-16 00:30 . 2003-05-16 00:30 20880 ----a-w- c:\programmi\sonnet-9511.cab
2003-05-16 00:30 . 2003-05-16 00:30 1538048 ----a-w- c:\programmi\sonnet-951.msi
2003-05-16 00:30 . 2003-05-16 00:30 740 -c--a-w- c:\programmi\setup.ini
2003-05-16 00:30 . 2003-05-16 00:30 1499904 ----a-w- c:\programmi\instmsiw.exe
2003-05-16 00:30 . 2003-05-16 00:30 1489152 ----a-w- c:\programmi\instmsi.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vidalia"="c:\programmi\Vidalia Bundle\Vidalia\vidalia.exe" [2009-11-20 5262834]
"VeohPlugin"="c:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2010-04-28 2633976]
"updatemgr"="c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"tomtomhome.exe"="c:\programmi\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-31 68856]
"softauto.exe"="c:\programmi\Creative\Software Update 3\SoftAuto.exe" [2008-05-28 401408]
"launchlist"="c:\programmi\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]
"ea core"="c:\programmi\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
"alcoholautomount"="c:\programmi\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-02 203928]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="c:\programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"virit lite monitor"="c:\vexplite\MONLITE.EXE" [2010-07-21 278528]
"ulead autodetector v2"="c:\programmi\File comuni\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 90112]
"sunjavaupdatesched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-09-23 149280]
"soundman"="SOUNDMAN.EXE" [2004-10-27 73728]
"smserial"="sm56hlpr.exe" [2004-06-29 569344]
"remotecontrol"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"nerofiltercheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DataMngr"="c:\progra~1\SHAREA~1\MediaBar\\DataMngr\DataMngrUI.exe" [2010-02-23 786368]
"controllo del calendario di ulead photo express"="c:\programmi\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe" [2004-01-12 69632]
"atipta"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Color Calibration.lnk - c:\programmi\SEC\MagicTune3.5_Client\GammaTray.exe [2007-8-1 36864]
Digisoft AntiDialer.lnk - c:\programmi\Digisoft AntiDialer\AntiDialer.exe [2003-8-19 730112]
MagicTune 3.5.lnk - c:\programmi\SEC\MagicTune3.5_Client\MagicTuneTray.exe [2007-8-1 45056]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
NaturalColorLoad.lnk - c:\programmi\SEC\Natural Color\NaturalColorLoad.exe [2007-8-1 155715]
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2005-8-3 118784]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\philipsdm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\philipsdm\sa1916]
2008-05-30 17:07 1512448 ----a-w- c:\programmi\Philips\SA19xx\Philips Device Manager\bin\DeviceManager.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Wolfram Research\\Mathematica\\5.1\\Mathematica.exe"=
"c:\\Programmi\\Wolfram Research\\Mathematica\\5.1\\MathKernel.exe"=
"c:\\Programmi\\Wolfram Research\\Mathematica\\5.1\\math.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\umi.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Electronic Arts\\EADM\\Core.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13352:TCP"= 13352:TCP:NortonAV
"12601:TCP"= 12601:TCP:NortonAV
R0 VIRAGTLT;VIRAGTLT;c:\windows\system32\drivers\VIRAGTLT.SYS [15/07/2009 18.09.47 45312]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [08/02/2010 23.17.11 135664]
S2 LVPORTIO;LV Port IO;c:\windows\system32\drivers\Lvportio.sys [04/06/2007 18.49.22 3936]
S2 RTWTKRNL;Real-Time Windows Target;c:\windows\system32\drivers\RTWTKRNL.sys [02/05/2008 10.05.45 27520]
S2 tomtomhomeservice;TomTomHOMEService;c:\programmi\TomTom HOME 2\TomTomHOMEService.exe [13/11/2009 13.31.14 92008]
S2 viritsvclite;Virit eXplorer Lite;c:\vexplite\VIRITSVC.EXE [10/10/2007 12.12.34 81920]
S3 CTUPnPSv;Creative Centrale Media Server;c:\programmi\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 13.42.56 64000]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [28/08/2010 15.05.42 27064]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25/11/2008 17.19.42 717296]
.
Contenuto della cartella 'Scheduled Tasks'
2010-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-08 21:17]
2010-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-08 21:17]
2010-08-27 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\programmi\Ask.com\UpdateTask.exe [2009-07-10 15:29]
2010-08-28 c:\windows\Tasks\User_Feed_Synchronization-{24343FE9-0665-4401-B136-5EAFF619D475}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 16:36]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-skytel - SkyTel.EXE
HKLM-Run-rthdcpl - RTHDCPL.EXE
AddRemove-RealTimeWindowsTarget - c:\windows\rtwintgt -uninstall
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-28 21:15
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(700)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\mobilev.acm
c:\windows\system32\vorbis.acm
c:\windows\system32\ac3acm.acm
c:\windows\system32\sirenacm.dll
.
Ora fine scansione: 2010-08-28 21:18:21
ComboFix-quarantined-files.txt 2010-08-28 19:18
Pre-Run: 11.128.393.728 byte disponibili
Post-Run: 12.822.880.256 byte disponibili
- - End Of File - - 1E94DE518307B2D2BD3E6B2EC71D376E
Attendo ulteriori suggerimenti.