Ciao ho postato anche il log post combofix anche se non lo vedo...comunque te lo copio anche qui.
Ciao e grazie mille.
codice:
ComboFix 11-11-13.01 - Luca 13/11/2011 14.14.09.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.511.293 [GMT 1:00] Eseguito da: c:\documents and settings\Luca\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66} * Creato nuovo punto di ripristino . ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !! . . ((((((((((((((((((((((((((((((((((((( Altre eliminazioni ))))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Luca\Dati applicazioni\PriceGong c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\1.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\a.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\b.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\c.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\d.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\e.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\f.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\g.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\h.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\i.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\J.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\k.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\l.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\m.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\mru.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\n.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\o.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\p.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\q.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\r.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\s.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\t.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\u.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\v.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\w.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\x.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\y.xml c:\documents and settings\Luca\Dati applicazioni\PriceGong\Data\z.xml D:\install.exe . . ((((((((((((((((((((((((( Files Creati Da 2011-10-13 al 2011-11-13 ))))))))))))))))))))))))))))))))))) . . 2011-11-12 13:16 . 2011-11-12 13:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy 2011-11-12 13:16 . 2011-11-12 13:16 -------- d-----w- c:\programmi\Spybot - Search & Destroy 2011-11-12 12:37 . 2011-11-12 12:37 -------- d-----w- c:\programmi\Trend Micro 2011-11-01 10:32 . 2011-11-01 10:33 -------- d-----w- c:\documents and settings\Luca\Impostazioni locali\Dati applicazioni\WinZip 2011-11-01 08:36 . 2011-11-01 10:35 -------- d-----w- c:\documents and settings\Luca\Dati applicazioni\DAEMON Tools Lite 2011-11-01 08:36 . 2011-11-01 08:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DAEMON Tools Lite 2011-10-27 11:11 . 2011-10-27 11:11 -------- d-----w- c:\documents and settings\Luca\Dati applicazioni\AVG2012 2011-10-27 11:10 . 2011-10-27 11:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AVG2012 2011-10-21 10:50 . 2011-10-21 10:50 -------- d-----w- c:\programmi\File comuni\Java 2011-10-20 11:28 . 2011-10-20 11:28 -------- d-----w- c:\programmi\HD Tune . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-12 09:58 . 2011-05-14 11:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-10 14:22 . 2011-01-13 17:54 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-10-07 05:23 . 2010-12-08 03:12 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2011-10-04 05:21 . 2010-08-03 14:23 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys 2011-10-03 03:06 . 2011-07-13 11:20 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-10-03 00:37 . 2011-07-13 11:20 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-09-28 07:06 . 2008-04-14 12:00 603136 ----a-w- c:\windows\system32\crypt32.dll 2011-09-26 09:41 . 2008-07-29 18:59 613888 ----a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 09:41 . 2008-04-14 12:00 23040 ----a-w- c:\windows\system32\oleaccrc.dll 2011-09-26 09:41 . 2008-04-14 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll 2011-09-13 04:30 . 2010-09-07 02:48 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys 2011-09-06 14:10 . 2008-04-14 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys 2011-08-31 16:00 . 2011-03-23 15:14 22216 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-08-22 23:41 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll 2011-08-22 23:41 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll 2011-08-22 23:41 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-08-22 11:56 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec 2011-08-17 13:49 . 2008-04-14 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys 2011-11-10 21:52 . 2011-05-07 22:09 134104 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Punti Reg Caricati )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* i valori vuoti & legittimi/default non sono visualizzati. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{e84cc2c1-b722-48fc-a39c-edb8b525c777}"= "c:\programmi\Productivity_2.2\prxtbPro0.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{e84cc2c1-b722-48fc-a39c-edb8b525c777}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2011-01-17 14:54 175912 ----a-w- c:\programmi\ConduitEngine\prxConduitEngin0.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e84cc2c1-b722-48fc-a39c-edb8b525c777}] 2011-01-17 14:54 175912 ----a-w- c:\programmi\Productivity_2.2\prxtbPro0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{e84cc2c1-b722-48fc-a39c-edb8b525c777}"= "c:\programmi\Productivity_2.2\prxtbPro0.dll" [2011-01-17 175912] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\programmi\ConduitEngine\prxConduitEngin0.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{e84cc2c1-b722-48fc-a39c-edb8b525c777}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{E84CC2C1-B722-48FC-A39C-EDB8B525C777}"= "c:\programmi\Productivity_2.2\prxtbPro0.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{e84cc2c1-b722-48fc-a39c-edb8b525c777}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="c:\documents and settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128] "SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RIMBBLaunchAgent.exe"="c:\programmi\File comuni\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192] "Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "AVG_TRAY"="c:\programmi\AVG\AVG2012\avgtray.exe" [2011-10-24 2415456] "SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2011-06-09 254696] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\ Hamlet HNW300NU2.lnk - c:\programmi\Hamlet\Common\RaUI.exe [2011-1-18 1515520] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Programmi\\eMule\\emule.exe"= "c:\\Programmi\\uTorrent\\uTorrent.exe"= "c:\\Programmi\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"= "c:\\Programmi\\AVG\\AVG2012\\avgmfapx.exe"= "c:\\Programmi\\AVG\\AVG2012\\avgnsx.exe"= "c:\\Programmi\\AVG\\AVG2012\\avgdiagex.exe"= "c:\\Programmi\\AVG\\AVG2012\\avgemcx.exe"= . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13/09/2010 15.27.24 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [07/09/2010 3.48.50 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [08/12/2010 4.12.38 230608] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [12/11/2010 13.19.38 295248] R2 avgwd;AVG WatchDog;c:\programmi\AVG\AVG2012\avgwdsvc.exe [02/08/2011 5.09.08 192776] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [03/08/2010 15.23.34 134608] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [03/08/2010 15.23.32 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [03/08/2010 15.23.36 16720] R3 STAC97NA;SigmaTel 3D Environmental Audio;c:\windows\system32\drivers\stac97na.sys [20/09/2002 18.42.32 296179] R3 STAC97NH;STAC97NH;c:\windows\system32\drivers\stac97nh.sys [20/09/2002 18.43.18 231983] S2 CoSslvpn;ZyXEL ZyWALL SecuExtender Adapter;c:\windows\system32\drivers\secuextender32.sys [15/01/2010 8.49.12 55360] S3 AVGIDSAgent;AVGIDSAgent;c:\programmi\AVG\AVG2012\AVGIDSAgent.exe [12/10/2011 6.25.22 4433248] S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [05/03/2011 11.17.13 112640] S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [05/03/2011 11.23.44 100480] . . ------- Scansione supplementare ------- . uStart Page = hxxp://www.google.it/ IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: {{4B21E152-BA59-4ebf-B522-8C55B265EE1A} - c:\documents and settings\Luca\Desktop\PartyPoker.it.lnk IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\programmi\PokerStars.IT\PokerStarsUpdate.exe TCP: Interfaces\{879A10BF-3328-4003-B146-3B9E4424D9E2}: NameServer = 192.168.1.1 FF - ProfilePath - c:\documents and settings\Luca\Dati applicazioni\Mozilla\Firefox\Profiles\z2eexonb.default\ FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=1010ede800000000000000026f52a842&tlver=1.4.19.19&instlRef=sst&ss=1&affID=17982&q= FF - prefs.js: network.proxy.type - 0 . - - - - CHIAVI ORFANE RIMOSSE - - - - . HKCU-Run-DriverScanner - c:\programmi\Uniblue\DriverScanner\launcher.exe HKLM-Run-AlcFDMonitor - c:\windows\ALCFDRTM.EXE . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-11-13 14:20 Windows 5.1.2600 Service Pack 3 NTFS . scansione processi nascosti ... . scansione entrate autostart nascoste ... . Scansione files nascosti ... . Scansione completata con successo Files nascosti: 0 . ************************************************************************** . --------------------- CHIAVI DI REGISTRO BLOCCATE --------------------- . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\|˙˙˙˙À|ù9~*] "0140111900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . Ora fine scansione: 2011-11-13 14:22:39 ComboFix-quarantined-files.txt 2011-11-13 13:22 . Pre-Run: 5.135.388.672 byte disponibili Post-Run: 5.854.846.976 byte disponibili . - - End Of File - - B450EC1E210060991FBE56185B518655