Ciao Luke,
ecco il log di ComboFix:
ComboFix 13-01-04.01 - Giancarlo 04/01/2013 8.23.26.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.2047.1409 [GMT -5:00]
Eseguito da: c:\documents and settings\Giancarlo\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\Giancarlo\g2mdlhlpx.exe
c:\documents and settings\Giancarlo\WINDOWS
C:\Documents
C:\prefs.js
c:\windows\system32\dllcache\wmpvis.dll
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MpKsl8a6646c5
-------\Legacy_Skype_C2C_Service
-------\Service_MpKsl8a6646c5
-------\Service_Skype C2C Service
.
.
((((((((((((((((((((((((( Files Creati Da 2012-12-04 al 2013-01-04 )))))))))))))))))))))))))))))))))))
.
.
2013-01-04 13:20 . 2013-01-04 13:20 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\PCHealth
2013-01-04 12:53 . 2012-11-08 18:00 6812136 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{1FAF5295-B876-48D4-98FE-4BA74C811522}\mpengine.dll
2013-01-03 02:22 . 2012-11-08 18:00 6812136 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-12-31 13:16 . 2012-12-31 13:16 -------- d-sh--w- c:\documents and settings\All Users\Dati applicazioni\SecuROM
2012-12-31 04:50 . 2012-12-31 04:50 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-12-31 04:50 . 2012-12-31 04:50 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-12-31 04:50 . 2012-12-31 04:21 3123272 ----a-w- c:\windows\system32\pbsvc.exe
2012-12-26 17:58 . 2012-12-26 17:58 -------- d-----w- c:\documents and settings\Giancarlo\Dati applicazioni\Malwarebytes
2012-12-26 17:57 . 2012-09-30 00:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-26 17:57 . 2012-12-26 17:58 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2012-12-13 18:54 . 2012-12-13 18:54 15728568 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-12-13 01:32 . 2012-12-13 01:32 -------- d-----w- c:\programmi\iPod
2012-12-13 01:31 . 2012-12-13 01:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-12-12 13:20 . 2012-12-12 13:20 -------- d-----w- c:\programmi\File comuni\Steam
2012-12-12 13:20 . 2013-01-03 16:48 -------- d-----w- c:\programmi\Steam
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-16 12:23 . 2003-04-08 12:00 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-12-13 18:54 . 2012-04-14 19:10 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-13 18:54 . 2011-06-12 18:05 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-19 14:24 . 2012-11-19 14:24 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2012-11-13 11:55 . 2003-04-08 12:00 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-02 02:02 . 2011-06-12 13:18 375296 ----a-w- c:\windows\system32\dpnet.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\documents and settings\Giancarlo\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\documents and settings\Giancarlo\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\documents and settings\Giancarlo\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\documents and settings\Giancarlo\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Core Temp"="c:\programmi\Core Temp\Core Temp.exe" [2011-08-01 715216]
"GoogleChromeAutoLaunch_2BB3AFA32B8D002B966E47028FA85756"="c:\documents and settings\Giancarlo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe" [2012-12-05 1242728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 16806912]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"APSDaemon"="c:\programmi\File comuni\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"MSC"="c:\programmi\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
"NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]
"nwiz"="c:\programmi\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2012-04-19 421888]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-07-03 252848]
"amd_dc_opt"="c:\programmi\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2012-11-29 151952]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Giancarlo^Menu Avvio^Programmi^Esecuzione automatica^Dropbox.lnk]
path=c:\documents and settings\Giancarlo\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 17:14 1695232 ------w- c:\programmi\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-04-19 01:56 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\DUE-3.0\\java\\bin\\javaw.exe"=
"c:\\Programmi\\DUE-3.0\\java\\bin\\java.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"c:\\Programmi\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Programmi\\Ubisoft\\Assassin's Creed Revelations\\ACRSP.exe"=
"d:\\Programmi\\Ubisoft\\Assassin's Creed Revelations\\ACRMP.exe"=
"d:\\Programmi\\Ubisoft\\Assassin's Creed Revelations\\AssassinsCreedRevelations.exe"=
"d:\\Programmi\\Ubisoft\\Assassin's Creed Revelations\\ACRPR.exe"=
"c:\\Documents and Settings\\Giancarlo\\Dati applicazioni\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Documents and Settings\\Giancarlo\\Impostazioni locali\\Dati applicazioni\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"d:\\Programmi\\Ubisoft\\Assassin's Creed Brotherhood\\ACBSP.exe"=
"d:\\Programmi\\Ubisoft\\Assassin's Creed Brotherhood\\ACBMP.exe"=
"d:\\Programmi\\Ubisoft\\Assassin's Creed Brotherhood\\AssassinsCreedBrotherhood.exe"=
"d:\\Programmi\\Ubisoft\\Assassin's Creed Brotherhood\\UPlayBrowser.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Steam\\Steam.exe"=
"c:\\Programmi\\File comuni\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Steam\\SteamApps\\common\\borderlands\\Binaries\\Borderlands.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/06/2011 11.43.31 685816]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\programmi\Nitro PDF\Professional\NitroPDFDriverService.exe [15/09/2009 4.20.30 188736]
R3 ALSysIO;ALSysIO;\??\c:\docume~1\GIANCA~1\IMPOST~1\Temp\ALSysIO.sys --> c:\docume~1\GIANCA~1\IMPOST~1\Temp\ALSysIO.sys [?]
S2 SkypeUpdate;Skype Updater;c:\programmi\Skype\Updater\Updater.exe [09/11/2012 11.21.24 160944]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [19/07/2011 6.18.42 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - ALSYSIO
.
Contenuto della cartella 'Scheduled Tasks'
.
2013-01-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 18:54]
.
2012-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2013-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-06-12 16:35]
.
2013-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-06-12 16:35]
.
2013-01-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-484763869-725345543-1004Core.job
- c:\documents and settings\Giancarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2012-05-20 19:13]
.
2013-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-484763869-725345543-1004UA.job
- c:\documents and settings\Giancarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2012-05-20 19:13]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\documents and settings\Giancarlo\Dati applicazioni\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: Interfaces\{5DCFFB5C-EB80-4B79-9385-46EA9C8D7ADA}: NameServer = 212.216.112.112,212.216.172.62
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
MSConfigStartUp-DUE 3 - c:\programmi\DUE-3.0\java\bin\javaw -jar c:\programmi\DUE-3.0\due_tray.jar
AddRemove-Batman Arkham Asylum GOTY Repack - d:\programmi\VictorVal\Batman Arkham Asylum GOTY Repack\Desinstalar.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2013-01-04 08:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-1757981266-484763869-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:e9,ff,da,cb,f6,d5,68,a3,d4,f6,c8,c6,ec,fd,27,f2,05,50,ce,f5,23,
0d,5c,f1,88,c4,a0,5c,61,38,58,af,0d,00,4c,c6,6d,8f,31,c4,53,bc,ff,68,18,f2,\
"rkeysecu"=hex:e6,0b,cf,9d,d3,83,e9,01,cc,63,28,ed,52,3a,aa,95
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:ôwjY*]
"DisplayName"="??\08\17?\11\09"
"DeviceDesc"="??\08\17?\11\09"
"ProviderName"="?A?\11?\16?\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.8"
"DeviceInstanceIds"=multi:"e:\\drivers\\chipset\\xp\\smbus\\smbusati.inf\00"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(3392)
c:\documents and settings\Giancarlo\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
c:\programmi\Microsoft Office\OFFICE11\msohev.dll
c:\programmi\File comuni\Microsoft Shared\OFFICE11\MSOXEV.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Microsoft Security Client\MsMpEng.exe
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\ASTSRV.EXE
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre7\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\system32\PnkBstrA.exe
c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\wscntfy.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RunDLL32.exe
c:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2013-01-04 08:33:22 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2013-01-04 13:33
.
Pre-Run: 23.884.644.352 byte disponibili
Post-Run: 25.758.670.848 byte disponibili
.
- - End Of File - - C6E15322CA134CD8F0999F1B4169D33D