Ecco il Log:
ComboFix 12-01-23.02 - greta 23/01/2012 19.07.08.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1023.695 [GMT 1:00]
Eseguito da: c:\documents and settings\greta\desktop\combofix.exe
Opzioni usate :: /killall
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\greta\Impostazioni locali\Dati applicazioni\43ce8f9a\U
c:\documents and settings\greta\Impostazioni locali\Dati applicazioni\43ce8f9a\U\000000c0.@
c:\documents and settings\greta\Impostazioni locali\Dati applicazioni\43ce8f9a\U\000000cb.@
c:\documents and settings\greta\Impostazioni locali\Dati applicazioni\43ce8f9a\U\800000c0.$
c:\documents and settings\greta\Impostazioni locali\Dati applicazioni\43ce8f9a\X
c:\windows\$NtUninstallKB13227$
c:\windows\$NtUninstallKB13227$\1137610650\@
c:\windows\$NtUninstallKB13227$\1137610650\L(2)\nisihpqm
c:\windows\$NtUninstallKB13227$\236841299
c:\windows\EventSystem.log
c:\windows\IsUn0410.exe
c:\windows\system32\F5D7051.dll
c:\windows\system32\mrobeservice.dll
c:\windows\system32\TBM8E.tmp
.
La copia infetta di c:\windows\system32\drivers\mrxsmb.sys è stata trovata e disinfettata
ipristinata copia da - The cat found it
c:\windows\system32\drivers\netbt.sys was missing
ipristinata copia da - c:\windows\ServicePackFiles\i386\netbt.sys
.
c:\windows\system32\drivers\cdrom.sys was missing
ipristinata copia da - c:\windows\system32\dllcache\cdrom.sys
.
c:\windows\system32\drivers\ipsec.sys was missing
ipristinata copia da - c:\windows\ServicePackFiles\i386\ipsec.sys
.
.
((((((((((((((((((((((((( Files Creati Da 2011-12-23 al 2012-01-23 )))))))))))))))))))))))))))))))))))
.
.
2012-01-23 18:14 . 2008-04-13 19:19 75264 -c--a-w- c:\windows\system32\dllcache\ipsec.sys
2012-01-23 18:14 . 2008-04-13 19:19 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys
2012-01-23 18:14 . 2008-04-13 19:40 62976 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2012-01-23 18:14 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2012-01-23 18:14 . 2008-04-13 19:21 162816 -c--a-w- c:\windows\system32\dllcache\netbt.sys
2012-01-23 18:14 . 2008-04-13 19:21 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2012-01-23 18:04 . 2011-07-15 13:29 457856 -c--a-w- c:\windows\system32\dllcache\mrxsmb.sys
2012-01-22 23:07 . 2012-01-22 23:07 -------- d-----w- c:\documents and settings\greta\Dati applicazioni\Malwarebytes
2012-01-22 23:07 . 2012-01-22 23:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2012-01-22 23:07 . 2012-01-22 23:07 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2012-01-22 23:07 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-22 22:24 . 2012-01-22 22:24 388096 ----a-r- c:\documents and settings\greta\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-01-22 22:24 . 2012-01-22 22:24 -------- d-----w- c:\programmi\Trend Micro
2012-01-22 17:51 . 2012-01-22 17:51 -------- d-----w- c:\windows\system32\wbem\Repository
2012-01-22 16:50 . 2004-08-03 21:41 129535 -c--a-w- c:\windows\system32\dllcache\slnt7554.sys
2012-01-22 02:26 . 2012-01-22 02:26 -------- d--h--w- c:\windows\system32\GroupPolicy
2012-01-22 02:12 . 2012-01-22 02:12 -------- d-----w- c:\windows\Temp5C52ED0A-8E20-B9BF-7A93-E4D3C79011FF-Signatures
2012-01-21 04:56 . 2012-01-21 04:56 2106216 ----a-w- c:\programmi\Mozilla Firefox\D3DCompiler_43.dll
2012-01-21 04:56 . 2012-01-21 04:56 121816 ----a-w- c:\programmi\Mozilla Firefox\components\browsercomps.dll
2012-01-21 04:56 . 2012-01-21 04:56 1998168 ----a-w- c:\programmi\Mozilla Firefox\d3dx9_43.dll
2012-01-21 04:56 . 2012-01-21 04:56 97240 ----a-w- c:\programmi\Mozilla Firefox\libEGL.dll
2012-01-21 04:56 . 2012-01-21 04:56 486360 ----a-w- c:\programmi\Mozilla Firefox\libGLESv2.dll
2012-01-21 04:56 . 2012-01-21 04:56 2124760 ----a-w- c:\programmi\Mozilla Firefox\mozjs.dll
2012-01-21 04:56 . 2012-01-21 04:56 15832 ----a-w- c:\programmi\Mozilla Firefox\mozalloc.dll
2012-01-21 04:56 . 2012-01-21 04:56 814040 ----a-w- c:\programmi\Mozilla Firefox\mozsqlite3.dll
2012-01-21 04:56 . 2012-01-21 04:56 626688 ----a-w- c:\programmi\Mozilla Firefox\msvcr80.dll
2012-01-21 04:56 . 2012-01-21 04:56 548864 ----a-w- c:\programmi\Mozilla Firefox\msvcp80.dll
2012-01-21 04:56 . 2012-01-21 04:56 479232 ----a-w- c:\programmi\Mozilla Firefox\msvcm80.dll
2012-01-21 04:56 . 2012-01-21 04:56 43992 ----a-w- c:\programmi\Mozilla Firefox\mozutils.dll
2012-01-21 04:28 . 2012-01-21 04:28 -------- d-----w- c:\windows\system32\drivers\NSS
2012-01-21 04:28 . 2012-01-21 04:28 -------- d-----w- c:\programmi\NortonInstaller
2012-01-21 01:59 . 2012-01-22 04:19 0 --sha-w- c:\windows\system32\dds_log_trash.cmd
2012-01-21 01:58 . 2012-01-23 18:14 -------- d-sh--w- c:\documents and settings\greta\Impostazioni locali\Dati applicazioni\43ce8f9a
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-04 09:26 . 2011-08-12 22:10 236576 ------w- c:\windows\system32\MpSigStub.exe
2011-12-22 03:30 . 2011-12-22 03:30 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57 . 2004-09-07 12:00 293888 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 14:40 . 2004-09-07 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-20 06:12 . 2004-09-07 12:00 60928 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:22 . 2004-09-07 12:00 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:22 . 2004-09-07 12:00 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-03 15:28 . 2004-09-07 12:00 386560 ----a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-09-07 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2004-09-07 12:00 1288192 ----a-w- c:\windows\system32\ole32.dll
2011-10-31 23:37 . 2004-09-07 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2011-10-31 23:37 . 2004-09-07 12:00 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2011-10-31 23:37 . 2004-09-07 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-10-31 23:37 . 2004-09-07 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2011-10-28 05:31 . 2004-09-07 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-26 10:50 . 2004-09-07 12:00 2196480 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-26 10:50 . 2004-08-04 00:48 2073088 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-01-21 04:56 . 2012-01-21 04:56 121816 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2004-09-07 12:00 . 2AEAD5031A06726376E86A5669933336 . 25600 . . [10.0.3790.3646] . . c:\windows\system32\mspmsnsv.dll
[-] 2004-09-07 12:00 . 2AEAD5031A06726376E86A5669933336 . 25600 . . [10.0.3790.3646] . . c:\windows\system32\dllcache\mspmsnsv.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2006-12-18 25365032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"Apoint"="c:\programmi\Apoint\Apoint.exe" [2005-10-07 176128]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-06-27 148888]
"IntelZeroConfig"="c:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"h"="c:\windows\system32\MsiExec.exe" [2008-04-14 78848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
QuickTV6.lnk - c:\programmi\AVerTV 6.0\AVerQT.exe [2005-11-7 512000]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 01:06 40048 -c--a-w- c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-06 16:52 3885408 ----a-w- c:\programmi\Windows Live\Messenger\msnmsgr.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3014:TCP"= 3014:TCP:qcjdbqz
.
S1 MpKsl1a2c2854;MpKsl1a2c2854;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{C8E0FC89-EAC9-495E-9BFD-9BB4EA354A96}\MpKsl1a2c2854.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{C8E0FC89-EAC9-495E-9BFD-9BB4EA354A96}\MpKsl1a2c2854.sys [?]
S1 MpKsl1d6b9652;MpKsl1d6b9652;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{F1826A22-6477-48AD-8E55-8323EE90EEED}\MpKsl1d6b9652.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{F1826A22-6477-48AD-8E55-8323EE90EEED}\MpKsl1d6b9652.sys [?]
S1 MpKsl32c005ad;MpKsl32c005ad;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{F1826A22-6477-48AD-8E55-8323EE90EEED}\MpKsl32c005ad.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{F1826A22-6477-48AD-8E55-8323EE90EEED}\MpKsl32c005ad.sys [?]
S1 MpKsl525237f5;MpKsl525237f5;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{59AE2BB5-1B02-457F-BDCC-FE56B914650A}\MpKsl525237f5.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{59AE2BB5-1B02-457F-BDCC-FE56B914650A}\MpKsl525237f5.sys [?]
S1 MpKsl8b1d2a47;MpKsl8b1d2a47;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{6C5BA51E-9CE9-40FC-8EB2-A1921BD91A6F}\MpKsl8b1d2a47.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{6C5BA51E-9CE9-40FC-8EB2-A1921BD91A6F}\MpKsl8b1d2a47.sys [?]
S1 MpKslc448dbdd;MpKslc448dbdd;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{6D2D03ED-9AB0-44DA-926B-334E58528DE7}\MpKslc448dbdd.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{6D2D03ED-9AB0-44DA-926B-334E58528DE7}\MpKslc448dbdd.sys [?]
S1 MpKslffa3d1cf;MpKslffa3d1cf;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{F1826A22-6477-48AD-8E55-8323EE90EEED}\MpKslffa3d1cf.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{F1826A22-6477-48AD-8E55-8323EE90EEED}\MpKslffa3d1cf.sys [?]
S2 gupdate;Servizio Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [16/12/2011 17.28.39 136176]
S2 jffiytq;Driver Security;c:\windows\system32\svchost.exe -k netsvcs [07/09/2004 13.00.00 14336]
S3 avera800;AVerMedia DVB-T BDA Video Capture(A800);c:\windows\system32\drivers\avera800.sys [22/05/2010 19.33.11 41600]
S3 DCALEXICO;DCALEXICO;c:\windows\system32\drivers\DCalexico.sys --> c:\windows\system32\drivers\DCalexico.sys [?]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [16/12/2011 17.28.39 136176]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [12/08/2011 9.32.41 114688]
S3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\drivers\zteusbvoice.sys [12/08/2011 9.32.27 105088]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
jffiytq
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-12-16 16:28]
.
2012-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-12-16 16:28]
.
2012-01-21 c:\windows\Tasks\Norton Security Scan for greta.job
- c:\progra~1\NORTON~1\Engine\351~1.10\Nss.exe [2012-01-21 07:02]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{604E3C02-9762-4529-8263-C15C3D59EE57}: NameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\greta\Dati applicazioni\Mozilla\Firefox\Profiles\sqpt17r7.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage -
www.google.it.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
AddRemove-Adolix Split and Merge PDF_is1 - c:\programmi\Adolix\Adolix Split and Merge PDF\unins000.exe
AddRemove-GarminPOIUpdater_is1 - c:\garminpoiupdater\unins000.exe
AddRemove-Microsoft Security Essentials - c:\programmi\Microsoft Security Essentials\setup.exe
AddRemove-Ulead Photo Express 3.0 SE - c:\windows\IsUn0410.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-01-23 19:18
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
h? = 63 00 3A 00 5C 00 57 00 49 00
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(848)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(2768)
c:\windows\system32\WININET.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\Intel\Wireless\Bin\WLKeeper.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\programmi\Belkin\F5D7051\WLService.exe
c:\programmi\Belkin\F5D7051\WLanCfgG.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\CDBurnerXP\NMSAccessU.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\programmi\Apoint\HidFind.exe
c:\programmi\Apoint\Apntex.exe
c:\programmi\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Ora fine scansione: 2012-01-23 19:26:08 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-01-23 18:25
.
Pre-Run: 11.843.162.112 byte disponibili
Post-Run: 12.629.651.456 byte disponibili
.
- - End Of File - - 829263F758BA05143239515DC3CD0F7B