Ok grazie, nel frattempo mi ero portato avanti seguendo le istruzioni di un post precedente di Luke57.
Ecco il contenuto di Combofix.txt:
ComboFix 09-12-04.05 - gilibaus 05/12/2009 21.10.12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.2038.1579 [GMT 1:00]
Eseguito da: c:\documents and settings\gilibaus\desktop\abc.exe
Opzioni usate :: /killall
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\LOG.TXT
c:\windows\AegisP.inf
c:\windows\system32\armaz.dll
c:\windows\system32\sqlite3.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_UTDEMTUC
-------\Service_utdemtuc
((((((((((((((((((((((((( Files Creati Da 2009-11-05 al 2009-12-05 )))))))))))))))))))))))))))))))))))
.
2009-12-05 19:51 . 2009-12-05 19:51 -------- d-----w- c:\documents and settings\gilibaus\Dati applicazioni\Malwarebytes
2009-12-05 19:51 . 2009-12-05 19:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-12-05 16:38 . 2009-12-05 16:38 -------- d-----w- c:\programmi\Windows Live Safety Center
2009-12-05 10:33 . 2009-12-05 10:33 -------- d-----w- c:\programmi\CCleaner
2009-12-01 17:04 . 2009-11-19 10:48 872960 ----a-w- c:\documents and settings\gilibaus\Dati applicazioni\Mozilla\Firefox\Profiles\rqq2rgkm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-01 17:04 . 2009-11-19 10:48 43008 ----a-w- c:\documents and settings\gilibaus\Dati applicazioni\Mozilla\Firefox\Profiles\rqq2rgkm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-01 17:04 . 2009-11-19 10:48 340480 ----a-w- c:\documents and settings\gilibaus\Dati applicazioni\Mozilla\Firefox\Profiles\rqq2rgkm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-01 17:04 . 2009-11-19 10:48 346624 ----a-w- c:\documents and settings\gilibaus\Dati applicazioni\Mozilla\Firefox\Profiles\rqq2rgkm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-25 08:30 . 2009-12-05 07:26 -------- d-----w- c:\programmi\Inkscape
2009-11-24 09:22 . 2009-11-24 09:22 -------- d-----w- c:\programmi\Safari
2009-11-24 09:22 . 2009-11-24 09:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2009-11-24 09:22 . 2009-11-24 09:22 -------- d-----w- c:\programmi\File comuni\Apple
2009-11-23 21:00 . 2009-11-23 21:00 152576 ----a-w- c:\documents and settings\gilibaus\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-23 20:59 . 2009-11-23 20:59 79488 ----a-w- c:\documents and settings\gilibaus\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-05 21:25 . 2009-11-05 21:25 -------- d-----w- c:\programmi\Sony Setup
2009-11-05 20:16 . 2009-11-05 20:16 73728 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-05 19:57 . 2008-01-07 15:50 -------- d-----w- c:\documents and settings\gilibaus\Dati applicazioni\Wave Systems Corp
2009-12-05 15:53 . 2008-10-25 16:50 -------- d-----w- c:\programmi\Flock
2009-12-05 09:09 . 2007-12-28 21:56 67640 ----a-w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-12-04 12:54 . 2008-01-28 10:59 -------- d-----w- c:\documents and settings\gilibaus\Dati applicazioni\FileZilla
2009-12-04 12:30 . 2008-01-07 16:49 -------- d-----w- c:\programmi\Opera
2009-12-03 12:49 . 2008-01-07 22:14 48 ----a-w- c:\windows\wpd99.drv
2009-12-02 10:41 . 2004-09-09 08:37 76322 ----a-w- c:\windows\system32\perfc010.dat
2009-12-02 10:41 . 2004-09-09 08:37 452218 ----a-w- c:\windows\system32\perfh010.dat
2009-11-30 18:28 . 2008-01-28 10:59 -------- d-----w- c:\programmi\FileZillaFTP
2009-11-25 08:33 . 2008-10-12 14:30 -------- d-----w- c:\documents and settings\gilibaus\Dati applicazioni\Inkscape
2009-11-23 21:01 . 2007-12-28 21:35 -------- d-----w- c:\programmi\Java
2009-11-06 11:58 . 2009-11-05 13:16 -------- d-----w- c:\documents and settings\gilibaus\Dati applicazioni\Publish Providers
2009-11-05 13:20 . 2009-11-05 13:15 -------- d-----w- c:\documents and settings\gilibaus\Dati applicazioni\Sony
2009-11-05 13:09 . 2009-11-05 13:08 -------- d-----w- c:\programmi\NewBlue
2009-11-05 13:00 . 2009-11-05 12:58 -------- d-----w- c:\programmi\Sony
2009-11-05 12:58 . 2009-11-05 12:58 -------- d-----w- c:\programmi\Vstplugins
2009-11-05 12:58 . 2009-11-05 12:58 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Sony
2009-10-31 21:31 . 2007-12-28 21:39 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-10-31 21:30 . 2009-10-31 21:30 -------- d-----w- c:\programmi\Picture Package
2009-10-30 20:35 . 2009-10-30 20:35 -------- d-----w- c:\programmi\jEdit
2009-10-24 18:48 . 2009-10-24 18:48 152576 ----a-w- c:\documents and settings\gilibaus\Dati applicazioni\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-11 03:17 . 2009-01-13 14:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-03 11:01 . 2009-10-03 11:01 152576 ----a-w- c:\documents and settings\gilibaus\Dati applicazioni\Sun\Java\jre1.6.0_15\lzma.dll
2007-04-16 15:54 . 2004-09-09 08:36 173318 --sha-r- c:\windows\system32\cuomfwrc.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\programmi\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Google Update"="c:\documents and settings\gilibaus\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-05-29 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programmi\DellTPad\Apoint.exe" [2007-09-09 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-10 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-10 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-10 137752]
"IntelZeroConfig"="c:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 823296]
"IntelWireless"="c:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 974848]
"Document Manager"="c:\programmi\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2007-02-28 102400]
"SecureUpgrade"="c:\programmi\Wave Systems Corp\SecureUpgrade.exe" [2007-01-22 212992]
"Dell QuickSet"="c:\programmi\Dell\QuickSet\quickset.exe" [2007-09-07 1236992]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"RoxioDragToDisc"="c:\programmi\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\programmi\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"WFXSwtch"="c:\progra~1\WinFax\WFXSWTCH.exe" [2001-09-19 27648]
"EVENTLISTENER"="c:\programmi\File comuni\FotoNation\EvLstnr.exe" [2000-06-20 53248]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2007-09-13 405504]
"WinFaxAppPortStarter"="wfxsnt40.exe" - c:\windows\system32\WFXSNT40.EXE [2001-09-19 45568]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2008-12-18 217088]
Digital Line Detect.lnk - c:\programmi\Digital Line Detect\DLG.exe [2007-12-28 50688]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= "c:\programmi\WinFax\WfxSeh32.Dll" [1998-07-27 38400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wxvault.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Opera\\opera.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7864:TCP"= 7864:TCP:WWW
"3733:TCP"= 3733:TCP:rbxxw
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\programmi\Broadcom\ASFIPMon\AsfIpMon.exe -service --> c:\programmi\Broadcom\ASFIPMon\AsfIpMon.exe -service [?]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [18/12/2008 11.53.16 8192]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [09/09/2004 9.36.44 5120]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [02/11/2006 13.32.32 97536]
S2 fkyhjary;Security Microsoft;c:\windows\system32\svchost.exe -k netsvcs [09/09/2004 9.37.15 14336]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
fkyhjary
.
Contenuto della cartella 'Scheduled Tasks'
2009-12-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1182062469-2684362251-302392456-1005Core.job
- c:\documents and settings\gilibaus\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-05-29 14:29]
2009-12-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1182062469-2684362251-302392456-1005UA.job
- c:\documents and settings\gilibaus\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-05-29 14:29]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/mStart Page =
hxxp://www1.euro.dell.com/content/defau ... l=it&s=genuInternet Settings,ProxyOverride = 127.0.0.1
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\gilibaus\Dati applicazioni\Mozilla\Firefox\Profiles\rqq2rgkm.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.itFF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\gilibaus\Dati applicazioni\Mozilla\Firefox\Profiles\rqq2rgkm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\gilibaus\Dati applicazioni\Mozilla\Firefox\Profiles\rqq2rgkm.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\documents and settings\gilibaus\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\XStandard\Bin\NPXStandard.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
AddRemove-Alice ti aiuta - c:\progra~1\ALICET~1\Uninstall.exe AliceRE
AddRemove-Pdf995 - c:\pdf995\setup.exe uninstall
AddRemove-{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD} - c:\programmi\DellTPad\Uninstap.exe ADDREMOVE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-05 21:15
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fkyhjary]
"ServiceDll"="c:\windows\system32\cuomfwrc.dll"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(904)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
- - - - - - - > 'explorer.exe'(1116)
c:\progra~1\ALICET~1\SMARTB~1\SBHook.dll
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\Broadcom\ASFIPMon\AsfIpMon.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
c:\programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
c:\programmi\Dell\QuickSet\NICCONFIGSVC.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\StacSV.exe
c:\programmi\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
c:\windows\system32\WFXSVC.EXE
c:\programmi\Intel\Wireless\Bin\WLKeeper.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\igfxsrvc.exe
c:\programmi\DellTPad\ApMsgFwd.exe
c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\MCCITR~1.EXE
c:\programmi\DellTPad\Apntex.exe
c:\programmi\DellTPad\HidFind.exe
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
c:\programmi\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Ora fine scansione: 2009-12-05 21:18 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-12-05 20:18
Pre-Run: 104.741.531.648 byte disponibili
Post-Run: 104.648.192.000 byte disponibili
- - End Of File - - 2B7B94E2916CA1BD8A60C598BC58BAAA