Risultato combofix da allegato log che mi si è aperto da solo.
ComboFix 10-01-17.02 - Admin 18/01/2010 12.00.56.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.446.266 [GMT 1:00]
Eseguito da: c:\documents and settings\Admin\desktop\abc.exe
Opzioni usate :: /killall
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-6C25-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\mswins.sys
.
((((((((((((((((((((((((( Files Creati Da 2009-12-18 al 2010-01-18 )))))))))))))))))))))))))))))))))))
.
2010-01-16 10:28 . 2010-01-16 10:28 -------- d-----w- c:\documents and settings\User\Dati applicazioni\Yahoo!
2010-01-14 15:12 . 2010-01-14 15:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2010-01-14 15:12 . 2010-01-14 15:12 -------- d-----w- c:\documents and settings\Admin\Dati applicazioni\Yahoo!
2010-01-14 15:12 . 2010-01-14 15:12 -------- d-----w- c:\programmi\Yahoo!
2010-01-14 15:12 . 2010-01-14 15:12 -------- d-----w- c:\programmi\CCleaner
2010-01-14 15:09 . 2010-01-14 15:09 -------- d-----w- c:\programmi\Trend Micro
2010-01-14 14:08 . 2010-01-14 14:08 -------- d-----w- c:\documents and settings\Admin\Dati applicazioni\Malwarebytes
2010-01-14 14:08 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-14 14:08 . 2010-01-14 14:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-01-14 14:08 . 2010-01-14 14:08 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-14 14:08 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-13 18:01 . 2003-03-18 19:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2010-01-13 18:01 . 2010-01-13 18:01 -------- d-----w- c:\programmi\Alwil Software
2010-01-11 10:57 . 2010-01-11 11:00 -------- d-----w- c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\Temp
2010-01-11 10:57 . 2010-01-11 11:00 -------- d-----w- c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-18 11:08 . 2009-03-26 18:52 -------- d-----w- c:\documents and settings\Admin\Dati applicazioni\Skype
2010-01-18 09:41 . 2009-11-13 13:02 79488 ----a-w- c:\documents and settings\Admin\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-16 10:33 . 2009-11-14 06:46 79488 ----a-w- c:\documents and settings\User\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-14 16:04 . 2009-03-31 13:49 1 ----a-w- c:\documents and settings\Admin\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-14 11:26 . 2009-05-09 09:24 -------- d-----w- c:\programmi\Mozilla Thunderbird
2010-01-11 10:44 . 2009-11-09 13:59 441921 --sha-w- c:\windows\system32\mswins.DLL
2009-12-14 12:30 . 2009-12-14 12:30 -------- d-----w- c:\programmi\Avira
2009-12-14 12:30 . 2009-12-14 12:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-12-10 23:47 . 2009-05-01 20:35 -------- d-----w- c:\programmi\PokerStars.IT
2009-11-25 13:59 . 2009-11-25 13:59 -------- d-----w- c:\programmi\Google
2009-11-25 10:19 . 2009-12-14 12:31 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-25 09:03 . 2008-04-14 12:00 47592 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 09:03 . 2008-04-14 12:00 345010 ----a-w- c:\windows\system32\perfh010.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2009-03-11 24095528]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2010-01-11 135664]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"nwiz"="nwiz.exe" [2006-10-31 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\programmi\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\programmi\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\programmi\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\programmi\Brother\Brmfcmon\BrMfcWnd.exe" [2007-11-05 741376]
"ControlCenter3"="c:\programmi\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Admin\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [17/02/2009 9.41.44 13696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [17/02/2009 15.27.53 1684736]
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1004336348-1417001333-1003Core.job
- c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-01-11 10:57]
2010-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1004336348-1417001333-1003UA.job
- c:\documents and settings\Admin\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-01-11 10:57]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\programmi\PokerStars.IT\PokerStarsUpdate.exe
.
.
------- Associazioni dei file -------
.
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-18 12:07
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\programmi\Brother\ControlCenter3\brccMCtl.exe
c:\programmi\Brother\Brmfcmon\BrMfcmon.exe
c:\programmi\OpenOffice.org 3\program\soffice.exe
c:\programmi\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-18 12:12:27 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-18 11:12
Pre-Run: 74.502.963.200 byte disponibili
Post-Run: 74.492.530.688 byte disponibili
- - End Of File - - 3E76A152D24AD84EF22A5F226E6EBF9E