Eccomi amici: come mi hai consigliato Paolopa; ho eliminato ciò che ha trovato malwarebytes e scaricato combofix come da te richiesto. Ho eseguito tutto alla lettera: ecco il report
ComboFix 10-07-11.03 - Salvatore 12/07/2010 14.22.58.2.8 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3062.2620 [GMT 2:00]
Eseguito da: c:\documents and settings\Salvatore\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((( Files Creati Da 2010-06-12 al 2010-07-12 )))))))))))))))))))))))))))))))))))
.
2010-07-12 06:06 . 2010-07-12 06:06 388096 ----a-r- c:\documents and settings\Salvatore\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-12 06:06 . 2010-07-12 06:06 -------- d-----w- c:\programmi\Trend Micro
2010-07-12 05:36 . 2010-07-12 05:36 -------- d-----w- c:\documents and settings\Salvatore\Dati applicazioni\Malwarebytes
2010-07-12 05:35 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-12 05:35 . 2010-07-12 05:36 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-07-12 05:35 . 2010-07-12 05:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-07-12 05:35 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-11 16:14 . 2010-07-11 16:14 53319 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Temp\{8C20787A-7402-4FA7-BF25-6E5750930FDC}\PostBuild.exe
2010-07-11 09:18 . 2010-07-11 15:32 -------- d-----w- c:\documents and settings\Salvatore\Impostazioni locali\Dati applicazioni\Cyberlink
2010-07-11 09:08 . 2010-07-11 09:24 53319 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2010-07-11 08:51 . 2010-07-11 15:32 -------- d-----w- c:\documents and settings\Salvatore\Dati applicazioni\CyberLink
2010-07-11 08:51 . 2010-07-11 16:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CyberLink
2010-07-11 08:49 . 2010-07-11 16:21 53319 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Temp\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\PostBuild.exe
2010-07-11 08:49 . 2010-07-11 16:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Temp
2010-07-11 07:57 . 2010-07-11 07:57 -------- d-----w- c:\documents and settings\Salvatore\Dati applicazioni\dvdcss
2010-07-10 17:31 . 2010-07-10 17:31 -------- d-----w- c:\programmi\PowerQuest
2010-06-27 07:43 . 2010-06-27 07:43 -------- d-----w- c:\programmi\File comuni\SWF Studio
2010-06-27 07:43 . 2010-06-27 07:43 -------- d-----w- c:\programmi\Riva
2010-06-12 14:32 . 2010-06-12 14:32 -------- d-----w- c:\documents and settings\Salvatore\LocalLow
2010-06-12 14:32 . 2010-06-12 14:32 -------- d-----w- c:\programmi\TVUPlayer
2010-06-12 14:26 . 2010-06-12 14:26 -------- d-----w- c:\documents and settings\Salvatore\Impostazioni locali\Dati applicazioni\TVU Networks
2010-06-12 14:26 . 2010-06-12 14:26 -------- d-----w- c:\documents and settings\Salvatore\Impostazioni locali\Dati applicazioni\LocalLow
2010-06-12 14:26 . 2010-06-12 14:26 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TVU Networks
2010-06-12 14:26 . 2010-06-12 14:26 -------- d-----w- c:\windows\system32\TVUAx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-12 12:26 . 2010-02-27 13:54 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-07-12 12:26 . 2010-02-27 13:53 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-07-12 11:21 . 2001-08-31 12:00 80490 ----a-w- c:\windows\system32\perfc010.dat
2010-07-12 11:21 . 2001-08-31 12:00 482036 ----a-w- c:\windows\system32\perfh010.dat
2010-07-12 05:27 . 2010-03-02 09:22 -------- d-----w- c:\programmi\uTorrent
2010-07-11 16:22 . 2010-02-24 20:18 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-07-11 16:14 . 2010-01-12 05:48 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-07-11 16:14 . 2010-01-12 05:48 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-07-11 15:23 . 2010-03-02 09:20 -------- d-----w- c:\documents and settings\Salvatore\Dati applicazioni\uTorrent
2010-07-11 07:58 . 2010-02-27 17:21 -------- d-----w- c:\documents and settings\Salvatore\Dati applicazioni\vlc
2010-06-26 16:50 . 2010-02-27 14:14 -------- d-----w- c:\programmi\CCleaner
2010-06-21 23:27 . 2010-02-27 14:10 -------- d-----w- c:\documents and settings\Salvatore\Dati applicazioni\Skype
2010-06-21 23:26 . 2010-02-27 14:11 -------- d-----w- c:\documents and settings\Salvatore\Dati applicazioni\skypePM
2010-06-10 21:57 . 2010-02-27 14:41 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-06-04 14:01 . 2010-03-06 17:00 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-05-26 04:43 . 2010-05-26 04:43 503808 ----a-w- c:\documents and settings\Salvatore\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20e04cf5-n\msvcp71.dll
2010-05-26 04:43 . 2010-05-26 04:43 499712 ----a-w- c:\documents and settings\Salvatore\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20e04cf5-n\jmc.dll
2010-05-26 04:43 . 2010-05-26 04:43 348160 ----a-w- c:\documents and settings\Salvatore\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20e04cf5-n\msvcr71.dll
2010-05-26 04:43 . 2010-05-26 04:43 61440 ----a-w- c:\documents and settings\Salvatore\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-66d94a9f-n\decora-sse.dll
2010-05-26 04:43 . 2010-05-26 04:43 12800 ----a-w- c:\documents and settings\Salvatore\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-66d94a9f-n\decora-d3d.dll
2010-05-06 10:32 . 2008-04-13 17:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:06 . 2008-04-13 16:50 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-25 10:04 . 2010-04-24 13:37 47360 ----a-w- c:\documents and settings\Salvatore\Dati applicazioni\pcouffin.sys
2010-04-25 10:04 . 2010-04-24 13:37 47360 ----a-w- c:\documents and settings\Salvatore\Dati applicazioni\pcouffin.sys
2010-04-24 17:56 . 2010-04-24 13:37 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-04-20 05:30 . 2008-04-13 17:11 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 21:48 . 2010-04-16 21:48 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-16 20:12 . 2010-04-16 20:12 48464 ----a-w- c:\windows\system32\sirenacm.dll
.
(((((((((((((((((((((((((((((
SnapShot@2010-07-12_12.10.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-12 12:26 . 2010-07-12 12:26 16384 c:\windows\Temp\Perflib_Perfdata_578.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"Google Update"="c:\documents and settings\Salvatore\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2010-04-10 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-03 17567744]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2009-03-09 36864]
"TurboV"="c:\programmi\ASUS\TurboV\TurboV.exe" [2009-05-25 5391872]
"Ai Nap"="c:\programmi\ASUS\AI Suite\AiNap\AiNap.exe" [2009-05-25 1431040]
"QFan Help"="c:\programmi\ASUS\AI Suite\QFan3\QFanHelp.exe" [2009-04-30 598528]
"Cpu Level Up help"="c:\programmi\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"Six Engine"="c:\programmi\ASUS\EPU-6 Engine\SixEngine.exe" [2009-05-25 6017024]
"nwiz"="c:\programmi\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\File comuni\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R2 AsSysCtrlService;ASUS System Control Service;c:\programmi\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [24/02/2010 22.34.46 90112]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [18/02/2009 16.31.56 294912]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [24/02/2010 22.19.18 1684736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenuto della cartella 'Scheduled Tasks'
2010-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-839522115-1801674531-1003Core.job
- c:\documents and settings\Salvatore\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-10 05:33]
2010-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-839522115-1801674531-1003UA.job
- c:\documents and settings\Salvatore\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-10 05:33]
2010-07-12 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-12 14:27
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(5516)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
c:\programmi\File comuni\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Ora fine scansione: 2010-07-12 14:28:56 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-07-12 12:28
Pre-Run: 197.592.059.904 byte disponibili
Post-Run: 197.594.615.808 byte disponibili
- - End Of File - - F2D6A6C1EE78C7B963459BA3E5A7D3BB