grazie francesco. ho fatto la scansione con combofix, poi ho riavviato io il pc. provo ad allegare il file...
ComboFix 11-12-03.01 - Admin 03/12/2011 15.36.28.2.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2038.1466 [GMT 1:00]
Eseguito da: c:\documents and settings\Admin\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {7698207D-3FC0-003E-AC1D-9876381E9876}
AV: AntiVir Desktop *Disabled/Updated* {7C926E90-FFFF-FFFF-00E0-FD7FB0F21200}
AV: AntiVir Desktop *Disabled/Updated* {7C926E90-FFFF-FFFF-00F0-FD7FB0F21200}
AV: AntiVir Desktop *Enabled/Updated* {0012F2B4-5C49-7C92-0300-000000000000}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((( Files Creati Da 2011-11-03 al 2011-12-03 )))))))))))))))))))))))))))))))))))
.
.
2011-12-03 14:33 . 2011-12-03 14:33 -------- d-----w- c:\documents and settings\All Users\Preferiti
2011-12-02 19:33 . 2011-12-02 19:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CPA_VA
2011-12-02 19:26 . 2011-12-02 19:26 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Comodo
2011-12-02 19:26 . 2011-12-02 19:26 -------- d-----w- c:\programmi\COMODO
2011-12-02 19:25 . 2011-12-02 19:25 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Comodo Downloader
2011-12-02 14:59 . 2011-12-02 14:59 -------- d-----w- c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\adaware
2011-12-02 08:33 . 2011-12-02 08:33 -------- d-----w- c:\programmi\Toolbar Cleaner
2011-11-30 12:18 . 2011-11-30 12:18 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2011-11-30 12:18 . 2011-11-30 12:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2011-11-26 00:13 . 2011-11-26 00:13 -------- d-----w- c:\documents and settings\Admin\Dati applicazioni\Avira
2011-11-25 23:49 . 2011-07-21 11:26 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-11-25 23:49 . 2011-07-21 11:26 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-25 23:49 . 2010-06-17 14:28 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2011-11-25 23:49 . 2010-06-17 14:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2011-11-25 23:49 . 2011-11-25 23:49 -------- d-----w- c:\programmi\Avira
2011-11-25 23:49 . 2011-11-25 23:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2011-11-25 23:05 . 2011-10-19 21:16 20312 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2011-11-24 16:30 . 2011-11-24 16:30 -------- d-----w- c:\programmi\Loaris
2011-11-24 16:10 . 2011-11-24 16:10 -------- d--h--w- c:\documents and settings\All Users\Dati applicazioni\{ECBE233A-68DB-468A-90EE-84E79FBFC397}
2011-11-23 19:12 . 2011-11-23 19:12 -------- d-----w- c:\programmi\Anti Trojan Elite
2011-11-22 01:05 . 2011-11-22 01:05 -------- d-----w- C:\Software-Lotto.com
2011-11-22 00:30 . 2011-11-22 00:30 -------- d-----w- c:\documents and settings\Admin\Dati applicazioni\Malwarebytes
2011-11-22 00:29 . 2011-11-22 00:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-11-22 00:29 . 2011-11-22 00:29 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-11-22 00:29 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-21 15:53 . 2011-11-21 15:53 -------- d-----w- c:\programmi\Trend Micro
2011-11-20 14:58 . 2011-11-20 14:58 -------- d-----w- c:\programmi\MSECache
2011-11-19 07:50 . 2011-11-19 07:50 -------- d-----w- C:\$AVG
2011-11-06 09:34 . 2007-08-21 12:32 98304 ----a-w- c:\windows\system32\redmonnt.dll
2011-11-05 08:50 . 2011-11-05 08:50 -------- d-----w- c:\programmi\HP Photo Creations
2011-11-05 08:50 . 2011-11-05 08:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP Photo Creations
2011-11-05 08:50 . 2010-06-14 15:04 273256 ------w- c:\windows\system32\HPDiscoPM9311.dll
2011-11-05 08:50 . 2010-06-14 20:43 1907560 ----a-w- c:\windows\system32\HPScanMiniDrv_DJ3050_J610.dll
2011-11-03 21:08 . 2011-11-03 21:08 -------- d-----w- c:\programmi\JDownloader
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-02 19:28 . 2010-08-13 13:58 32336 ----a-w- c:\windows\SCHEDLGU.TXT.TMP
2011-12-01 17:00 . 2011-10-27 16:29 82168 ----a-w- c:\windows\system32\drivers\VIRAGTLT.sys
2011-11-29 12:14 . 2010-07-16 21:41 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-10-20 12:26 . 2011-05-16 15:19 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:23 . 2008-12-17 16:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-07 17:48 . 2011-10-07 17:48 97760 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-10-07 17:48 . 2011-10-07 17:48 492768 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 17:48 . 2011-10-07 17:48 31704 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 17:48 . 2011-10-07 17:48 18056 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 17:47 . 2011-10-07 17:47 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-10-07 17:47 . 2011-10-07 17:47 300200 ----a-w- c:\windows\system32\guard32.dll
2011-09-28 07:06 . 1979-12-31 23:00 603136 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 18:59 613888 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 1979-12-31 23:00 23040 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 10:41 . 1979-12-31 23:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 15:10 . 1979-12-31 23:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-09 22:56 . 2011-07-30 14:30 134104 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-25_18.29.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-03 14:13 . 2011-12-03 14:13 16384 c:\windows\Temp\Perflib_Perfdata_6b0.dat
+ 2011-11-25 23:49 . 2010-06-17 14:28 28520 c:\windows\system32\drivers\ssmdrv.sys
+ 2008-12-17 16:55 . 2011-12-03 14:13 49152 c:\windows\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-19 17:39 . 2011-12-02 19:29 27496 c:\windows\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
- 2008-12-17 16:55 . 2011-11-15 17:09 32768 c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
+ 2008-12-17 16:55 . 2011-12-03 14:13 32768 c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
- 2008-12-17 16:55 . 2011-11-15 17:09 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-11-29 12:14 . 2011-12-03 14:13 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-12-02 19:26 . 2011-12-02 19:26 8685568 c:\windows\Installer\5b3e2ab.msi
+ 2011-12-02 19:30 . 2011-12-02 19:32 10877072 c:\windows\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\39TCZ7L5\gb_setup_3.3.217083.59[1].exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"Advanced SystemCare 5"="c:\programmi\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-11-12 1647448]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-08 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-08 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-08 131072]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"McAfeeUpdaterUI"="c:\programmi\McAfee\Common Framework\UdaterUI.exe" [2009-02-24 136512]
"OpwareSE2"="c:\programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 110592]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-29 937920]
"HP Software Update"="c:\programmi\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Anti Trojan Elite"="c:\programmi\Anti Trojan Elite\TJEnder.exe" [2009-06-14 4076544]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
"COMODO Internet Security"="c:\programmi\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 2497352]
"COMODO"="c:\programmi\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 208184]
"CPA"="c:\programmi\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 182584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Programmi\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Programmi\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Programmi\\File comuni\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Programmi\\Java\\JRE6\\BIN\\javaw.exe"=
"c:\\WINDOWS\\System32\\java.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Gestione remota Windows
.
R0 VIRAGTLT;VIRAGTLT;c:\windows\system32\drivers\VIRAGTLT.sys [27/10/2011 17.29.30 82168]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [07/10/2011 18.48.02 492768]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [07/10/2011 18.48.02 31704]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\programmi\IObit\Advanced SystemCare 5\ASCService.exe [25/11/2011 19.41.11 490840]
R2 CLPSLS;COMODO livePCsupport Service;c:\programmi\COMODO\COMODO GeekBuddy\CLPSLS.exe [23/11/2011 11.27.04 1052472]
R2 PfFilter;PfFilter;c:\programmi\IObit\Protected Folder\pffilter.sys [14/08/2011 9.21.38 140848]
R2 viritsvclite;VirIT eXplorer Lite;c:\vexplite\VIRITSVC.EXE [14/03/2011 12.54.14 86016]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 ATE_PROCMON;ATE_PROCMON;\??\c:\programmi\Anti Trojan Elite\ATEPMon.sys --> c:\programmi\Anti Trojan Elite\ATEPMon.sys [?]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [10/02/2010 15.41.02 135664]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [14/08/2010 1.00.43 37296]
S3 GTwinUSB;GTwinUSB;c:\windows\system32\drivers\GTwinUSB.sys [18/12/2008 8.38.44 61840]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [10/02/2010 15.41.02 135664]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [01/01/1980 14336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 12:23 452136 ----a-w- c:\programmi\File comuni\LightScribe\LSRunOnce.exe
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-12-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-10 14:40]
.
2011-12-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-10 14:40]
.
2011-11-05 c:\windows\Tasks\hpwebreg_CN08U1D11F05HX.job
- c:\programmi\HP\HP Deskjet 3050 J610 series\Bin\hpwebreg.exe [2010-06-14 15:10]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Scarica con Free Download Manager -
file://c:\programmi\Free Download Manager\dllink.htm
IE: Scarica con Mipony -
file://c:\programmi\MiPony\Browser\IEContext.htm
IE: Scarica i video con Free Download Manager -
file://c:\programmi\Free Download Manager\dlfvideo.htm
IE: Scarica selezionati con Free Download Manager -
file://c:\programmi\Free Download Manager\dlselected.htm
IE: Scarica tutto con Free Download Manager -
file://c:\programmi\Free Download Manager\dlall.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Admin\Dati applicazioni\Mozilla\Firefox\Profiles\tc0qz2zi.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage -
hxxp://search.babylon.com/?babsrc=HP_ss ... 0cf660de12FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-12-03 15:40
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
detected NTDLL code modification:
ZwClose
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4b,4a,2a,86,74,e5,eb,4b,bd,92,e7,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4b,4a,2a,86,74,e5,eb,4b,bd,92,e7,\
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'lsass.exe'(856)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'explorer.exe'(2352)
c:\windows\system32\WININET.dll
c:\windows\system32\guard32.dll
c:\programmi\ScanSoft\OmniPageSE2.0\ophookSE2.dll
c:\windows\system32\webcheck.dll
.
- - - - - - - > 'csrss.exe'(772)
c:\windows\system32\cmdcsr.dll
.
Ora fine scansione: 2011-12-03 15:41:17
ComboFix-quarantined-files.txt 2011-12-03 14:41
ComboFix2.txt 2011-11-25 18:30
.
Pre-Run: 43.560.239.104 byte disponibili
Post-Run: 43.574.099.968 byte disponibili
.
- - End Of File - - 4D35515CF286DEF2FC737FCD532D854E