Non sono un grande esperto e penso di avere dei virus sul pc. Non riesco a installare più nessun antivirus e ho il task manager disabilitato dall'amministatore. Vi posto il log di Combofix.
Qualcuno sa aiutarmi?
ComboFix 12-03-22.01 - Administrator 22/03/2012 14.13.13.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.766.412 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator.-0D538E7E\Documenti\abc.exe
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\documents and settings\Administrator-0D538E7E\WINDOWS
c:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
C:\Install.exe
c:\program files\SGPSA\BHO.dll
c:\programmi\Shared
c:\windows\system32\a
c:\windows\system32\Cache
c:\windows\system32\SET38.tmp
c:\windows\system32\SET44.tmp
c:\windows\system32\SET51.tmp
c:\windows\unin0410.exe
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_AMSINT32
-------\Legacy_ASC3360PR
-------\Service_amsint32
-------\Service_asc3360pr
.
.
((((((((((((((((((((((((( Files Creati Da 2012-02-22 al 2012-03-22 )))))))))))))))))))))))))))))))))))
.
.
2012-03-21 20:04 . 2012-03-21 20:04 103140 ----a-w- C:\yyoqdr.exe
2012-02-25 10:38 . 2012-02-25 10:38 1409 ----a-w- c:\windows\QTFont.for
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-22 13:28 . 2012-03-22 13:28 103140 --sh--r- C:\ixdg.pif
2012-02-16 16:04 . 2011-09-07 07:03 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 229376]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-06-11 1286144]
"LogitechCommunicationsManager"="c:\programmi\File comuni\Logitech\LComMgr\Communications_Helper.exe" [2006-10-30 353816]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam10\QuickCam10.exe" [2006-11-15 746520]
"LVCOMSX"="c:\programmi\File comuni\Logitech\LComMgr\LVComSX.exe" [2006-11-15 244512]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-26 136600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 225280]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 109680]
"AdobeAAMUpdater-1.0"="c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 573936]
"SwitchBoard"="c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\programmi\File comuni\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 484816]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-30 15360]
.
c:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Microsoft Office OneNote 2003.lnk - c:\programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 121408]
uninstall.exe [2012-3-22 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\HelpCtr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Administrator.NATALE-0D538E7E\\Desktop\\Skype.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\Programmi\\File comuni\\Adobe\\CS5ServiceManager\\CS5ServiceManager.exe"=
"c:\\Programmi\\QuickTime\\qttask.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\jusched.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Programmi\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Programmi\\File comuni\\Logitech\\LComMgr\\LVComSX.exe"=
"c:\\Programmi\\File comuni\\Logishrd\\LQCVFX\\COCIManager.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\jucheck.exe"=
"c:\\Programmi\\File comuni\\Logitech\\LComMgr\\Communications_Helper.exe"=
"c:\\Programmi\\Logitech\\QuickCam10\\QuickCam10.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\PROGRA~1\\MICROS~2\\OFFICE11\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Documents and Settings\\Administrator.NATALE-0D538E7E\\Documenti\\NO$GBA\\NO$GBA (Emulatore DS...by Cpl23 e Cippo97).EXE"=
"c:\\WINDOWS\\system32\\NeroCheck.exe"=
"c:\\Programmi\\Adobe\\Reader 8.0\\Reader\\AcroRd32Info.exe"=
"c:\\Programmi\\Adobe\\Reader 8.0\\Reader\\AcroRd32.exe"=
"c:\\Programmi\\File comuni\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe"=
"c:\\Documents and Settings\\All Users.WINDOWS\\Menu Avvio\\Programmi\\Esecuzione automatica\\uninstall.exe"=
"c:\\yyoqdr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Google\\Update\\GoogleUpdate.exe"=
"c:\\Programmi\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Programmi\\File comuni\\Logitech\\SrvLnch\\SrvLnch.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:Porta TCP ooVoo 443
"443:UDP"= 443:UDP:*:Disabled:Porta UDP ooVoo 443
"37674:TCP"= 37674:TCP:*:Disabled:Porta TCP ooVoo 37674
"37674:UDP"= 37674:UDP:*:Disabled:Porta UDP ooVoo 37674
"37675:UDP"= 37675:UDP:*:Disabled:Porta UDP ooVoo 37675
.
S1 busduvis;busduvis;\??\c:\windows\system32\drivers\busduvis.sys
c:\windows\system32\drivers\busduvis.sys ![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S1 czjgzvvs;czjgzvvs;\??\c:\windows\system32\drivers\czjgzvvs.sys
c:\windows\system32\drivers\czjgzvvs.sys ![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S2 gupdate1c9e102a8519d78;Servizio di Google Update (gupdate1c9e102a8519d78);c:\programmi\Google\Update\GoogleUpdate.exe [30/05/2009 9.43.07 210928]
S2 Remote Instrumentation;RpcS;c:\windows\system32\fing.exe [22/04/2010 8.08.19 35840]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [30/05/2009 9.43.07 210928]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [07/07/2011 9.27.06 39984]
S3 SwitchBoard;SwitchBoard;c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 12.37.14 517096]
S3 zlportio;zlportio;\??\c:\documents and settings\Administrator.NATALE-0D538E7E\Documenti\File ricevuti\Giochi\ultrastardx-101a-full\zlportio.sys
c:\documents and settings\Administrator.NATALE-0D538E7E\Documenti\File ricevuti\Giochi\ultrastardx-101a-full\zlportio.sys ![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - AMSINT32
*NewlyCreated* - WS2IFSL
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-07-12 c:\windows\Tasks\AdobeAAMUpdater-1.0-NATALE-0D538E7E-Administrator.job
- c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-07-12 01:44]
.
2012-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-05-30 08:42]
.
2012-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-05-30 08:42]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.macromedia.com/shockwave/dow ... fault.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Free YouTube Download - c:\documents and settings\Administrator.NATALE-0D538E7E\Dati applicazioni\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
TCP: DhcpNameServer = 83.103.25.250 62.101.93.101
DPF: {1F831FA9-42FC-11D4-95A6-0080AD30DCE1} - file://c:\programmi\AutoCAD 2002 Ita\InstFred.ocx
DPF: {AE563729-B4F5-11D4-A415-00108302FDFD} - file://c:\programmi\AutoCAD 2002 Ita\InstBanr.ocx
.
.
------- Associazioni dei file -------
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
BHO-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
Toolbar-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
HKCU-Run-TomTomHOME.exe - c:\programmi\TomTom HOME 2\TomTomHOMERunner.exe
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-C-Media Speaker Configuration - d:\driver\xp-2k-me\drv\Setup.exe
HKLM-Run-NWEReboot - (no file)
AddRemove-FoxTab PDF Converter - c:\programmi\FoxTabPDFConverter\\ftpdf_inst.exe
AddRemove-Kalender - c:\windows\Uninstall_tkexe -kalender
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-22 14:28
Windows 5.1.2600 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Maxtor_6G160P0 rev.KA201V00 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\Disk -> 0x82522038
NDIS: Intel(R) PRO/1000 MT Network Connection -> SendCompleteHandler -> 0x82558e00
user != kernel MBR !!!
malicious code @ sector 0x12a18ac1 size 0x1e4 !
copy of MBR has been found in sector 62 !
Warning: possible MBR rootkit infection !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-220523388-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,67,a5,97,4e,f4,aa,b5,4b,be,08,82,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,67,a5,97,4e,f4,aa,b5,4b,be,08,82,\
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(8176)
c:\windows\system32\WININET.dll
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\windows\system32\DRIVERS\CDANTSRV.EXE
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Logishrd\LQCVFX\COCIManager.exe
c:\programmi\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Ora fine scansione: 2012-03-22 14:34:16 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-03-22 13:34
.
Pre-Run: 79.964.008.448 byte disponibili
Post-Run: 84.800.928.256 byte disponibili
.
- - End Of File - - 14A37354E2F228A037E84BCBEBCD4AAF
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.766.412 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator.-0D538E7E\Documenti\abc.exe
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\documents and settings\Administrator-0D538E7E\WINDOWS
c:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
C:\Install.exe
c:\program files\SGPSA\BHO.dll
c:\programmi\Shared
c:\windows\system32\a
c:\windows\system32\Cache
c:\windows\system32\SET38.tmp
c:\windows\system32\SET44.tmp
c:\windows\system32\SET51.tmp
c:\windows\unin0410.exe
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_AMSINT32
-------\Legacy_ASC3360PR
-------\Service_amsint32
-------\Service_asc3360pr
.
.
((((((((((((((((((((((((( Files Creati Da 2012-02-22 al 2012-03-22 )))))))))))))))))))))))))))))))))))
.
.
2012-03-21 20:04 . 2012-03-21 20:04 103140 ----a-w- C:\yyoqdr.exe
2012-02-25 10:38 . 2012-02-25 10:38 1409 ----a-w- c:\windows\QTFont.for
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-22 13:28 . 2012-03-22 13:28 103140 --sh--r- C:\ixdg.pif
2012-02-16 16:04 . 2011-09-07 07:03 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 229376]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-06-11 1286144]
"LogitechCommunicationsManager"="c:\programmi\File comuni\Logitech\LComMgr\Communications_Helper.exe" [2006-10-30 353816]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam10\QuickCam10.exe" [2006-11-15 746520]
"LVCOMSX"="c:\programmi\File comuni\Logitech\LComMgr\LVComSX.exe" [2006-11-15 244512]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-26 136600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 225280]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 109680]
"AdobeAAMUpdater-1.0"="c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 573936]
"SwitchBoard"="c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\programmi\File comuni\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 484816]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-30 15360]
.
c:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Microsoft Office OneNote 2003.lnk - c:\programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 121408]
uninstall.exe [2012-3-22 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\HelpCtr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Administrator.NATALE-0D538E7E\\Desktop\\Skype.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\Programmi\\File comuni\\Adobe\\CS5ServiceManager\\CS5ServiceManager.exe"=
"c:\\Programmi\\QuickTime\\qttask.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\jusched.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Programmi\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Programmi\\File comuni\\Logitech\\LComMgr\\LVComSX.exe"=
"c:\\Programmi\\File comuni\\Logishrd\\LQCVFX\\COCIManager.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\jucheck.exe"=
"c:\\Programmi\\File comuni\\Logitech\\LComMgr\\Communications_Helper.exe"=
"c:\\Programmi\\Logitech\\QuickCam10\\QuickCam10.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\PROGRA~1\\MICROS~2\\OFFICE11\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Documents and Settings\\Administrator.NATALE-0D538E7E\\Documenti\\NO$GBA\\NO$GBA (Emulatore DS...by Cpl23 e Cippo97).EXE"=
"c:\\WINDOWS\\system32\\NeroCheck.exe"=
"c:\\Programmi\\Adobe\\Reader 8.0\\Reader\\AcroRd32Info.exe"=
"c:\\Programmi\\Adobe\\Reader 8.0\\Reader\\AcroRd32.exe"=
"c:\\Programmi\\File comuni\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe"=
"c:\\Documents and Settings\\All Users.WINDOWS\\Menu Avvio\\Programmi\\Esecuzione automatica\\uninstall.exe"=
"c:\\yyoqdr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Google\\Update\\GoogleUpdate.exe"=
"c:\\Programmi\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Programmi\\File comuni\\Logitech\\SrvLnch\\SrvLnch.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:Porta TCP ooVoo 443
"443:UDP"= 443:UDP:*:Disabled:Porta UDP ooVoo 443
"37674:TCP"= 37674:TCP:*:Disabled:Porta TCP ooVoo 37674
"37674:UDP"= 37674:UDP:*:Disabled:Porta UDP ooVoo 37674
"37675:UDP"= 37675:UDP:*:Disabled:Porta UDP ooVoo 37675
.
S1 busduvis;busduvis;\??\c:\windows\system32\drivers\busduvis.sys

![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S1 czjgzvvs;czjgzvvs;\??\c:\windows\system32\drivers\czjgzvvs.sys

![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S2 gupdate1c9e102a8519d78;Servizio di Google Update (gupdate1c9e102a8519d78);c:\programmi\Google\Update\GoogleUpdate.exe [30/05/2009 9.43.07 210928]
S2 Remote Instrumentation;RpcS;c:\windows\system32\fing.exe [22/04/2010 8.08.19 35840]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [30/05/2009 9.43.07 210928]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [07/07/2011 9.27.06 39984]
S3 SwitchBoard;SwitchBoard;c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 12.37.14 517096]
S3 zlportio;zlportio;\??\c:\documents and settings\Administrator.NATALE-0D538E7E\Documenti\File ricevuti\Giochi\ultrastardx-101a-full\zlportio.sys

![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - AMSINT32
*NewlyCreated* - WS2IFSL
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-07-12 c:\windows\Tasks\AdobeAAMUpdater-1.0-NATALE-0D538E7E-Administrator.job
- c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-07-12 01:44]
.
2012-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-05-30 08:42]
.
2012-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-05-30 08:42]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.macromedia.com/shockwave/dow ... fault.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Free YouTube Download - c:\documents and settings\Administrator.NATALE-0D538E7E\Dati applicazioni\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
TCP: DhcpNameServer = 83.103.25.250 62.101.93.101
DPF: {1F831FA9-42FC-11D4-95A6-0080AD30DCE1} - file://c:\programmi\AutoCAD 2002 Ita\InstFred.ocx
DPF: {AE563729-B4F5-11D4-A415-00108302FDFD} - file://c:\programmi\AutoCAD 2002 Ita\InstBanr.ocx
.
.
------- Associazioni dei file -------
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
BHO-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
Toolbar-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
HKCU-Run-TomTomHOME.exe - c:\programmi\TomTom HOME 2\TomTomHOMERunner.exe
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-C-Media Speaker Configuration - d:\driver\xp-2k-me\drv\Setup.exe
HKLM-Run-NWEReboot - (no file)
AddRemove-FoxTab PDF Converter - c:\programmi\FoxTabPDFConverter\\ftpdf_inst.exe
AddRemove-Kalender - c:\windows\Uninstall_tkexe -kalender
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-22 14:28
Windows 5.1.2600 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Maxtor_6G160P0 rev.KA201V00 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\Disk -> 0x82522038
NDIS: Intel(R) PRO/1000 MT Network Connection -> SendCompleteHandler -> 0x82558e00
user != kernel MBR !!!
malicious code @ sector 0x12a18ac1 size 0x1e4 !
copy of MBR has been found in sector 62 !
Warning: possible MBR rootkit infection !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-220523388-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,67,a5,97,4e,f4,aa,b5,4b,be,08,82,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,67,a5,97,4e,f4,aa,b5,4b,be,08,82,\
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(8176)
c:\windows\system32\WININET.dll
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\windows\system32\DRIVERS\CDANTSRV.EXE
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Logishrd\LQCVFX\COCIManager.exe
c:\programmi\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Ora fine scansione: 2012-03-22 14:34:16 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-03-22 13:34
.
Pre-Run: 79.964.008.448 byte disponibili
Post-Run: 84.800.928.256 byte disponibili
.
- - End Of File - - 14A37354E2F228A037E84BCBEBCD4AAF