Ecco io due log
HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23.11.17, on 02/03/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17093)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\System32\WLTRYSVC.EXE
C:\windows\System32\bcmwltry.exe
C:\windows\system32\spoolsv.exe
C:\Programmi\SUPERAntiSpyware\SASCORE.EXE
C:\windows\System32\svchost.exe
C:\windows\System32\Ati2evxx.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\HPConfig.exe
C:\Programmi\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Microsoft LifeCam\MSCamS32.exe
C:\Programmi\CDBurnerXP\NMSAccessU.exe
C:\Programmi\File comuni\PC Tools\sMonitor\StartManSvc.exe
C:\Programmi\FS\Spyro Portal\FlashPortal.exe
C:\windows\System32\svchost.exe
C:\windows\system32\wuauclt.exe
C:\windows\Explorer.EXE
C:\Programmi\HPQ\One-Touch\OneTouch.EXE
C:\windows\system32\ctfmon.exe
C:\Programmi\Microsoft ActiveSync\wcescomm.exe
C:\Programmi\NETGEAR\WG111T\wlan111t.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\windows\system32\wscntfy.exe
C:\windows\System32\svchost.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.libero.itR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://it.rd.yahoo.com/customize/ycomp/ ... .yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Programmi\Reganam\prxtbReg2.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Programmi\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Reganam - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Programmi\Reganam\prxtbReg2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: TBSB04717 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Programmi\Playboost Gamebar\tbunsn133.tmp\tbcore3.dll
O3 - Toolbar: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Programmi\Reganam\prxtbReg2.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Playboost Gamebar - {1ACC87D6-CB2B-4CAF-9280-6549842407C9} - C:\Programmi\Playboost Gamebar\tbunsn133.tmp\tbcore3.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QT4HPOT] C:\Programmi\HPQ\One-Touch\OneTouch.EXE
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Zancanella\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmi\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O8 - Extra context menu item: Add to Evernote -
res://C:\Programmi\Evernote\Evernote3\enbar.dll/2000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Programmi\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\System32\Ati2evxx.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Servizio Google Update (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Programmi\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Programmi\CDBurnerXP\NMSAccessU.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Programmi\File comuni\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyro Portal Service (SpyroService) - FS - C:\Programmi\FS\Spyro Portal\FlashPortal.exe
O23 - Service: U.S. Robotics Wireless LAN Service (wltrysvc) - Unknown owner - C:\windows\System32\WLTRYSVC.EXE
--
End of file - 7486 bytes
Ed il log di Malwarebytes(aggiornato)
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.orgVersione database: v2012.03.02.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Zancanella :: ZANCANEL-WTCCMU [amministratore]
02/03/2012 21.44.46
mbam-log-2012-03-02 (23-06-05).txt
Tipo di scansione: Scansione completa
Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File system | Euristica/Extra | Euristica/Shuriken | PUP | PUM
Opzioni di scansione disattivate: P2P
Elementi esaminati: 247862
Tempo impiegato: 1 ore, 20 minuti, 49 secondi
Processi rilevati in memoria: 0
(non sono stati rilevati elementi nocivi)
Moduli di memoria rilevati: 0
(non sono stati rilevati elementi nocivi)
Chiavi di registro rilevate: 0
(non sono stati rilevati elementi nocivi)
Valori di registro rilevati: 0
(non sono stati rilevati elementi nocivi)
Voci rilevate nei dati di registro: 0
(non sono stati rilevati elementi nocivi)
Cartelle rilevate: 0
(non sono stati rilevati elementi nocivi)
File rilevati: 39
C:\Programmi\cacaoweb\cacaoweb.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP273\A0258505.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP273\A0258515.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP273\A0258522.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP273\A0258528.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP273\A0259529.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP273\A0259554.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP273\A0259557.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP273\A0259562.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP274\A0262574.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP274\A0262667.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP274\A0262674.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP274\A0263675.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP274\A0264676.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP274\A0264686.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0279027.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0279034.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0280035.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0281034.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0281041.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0281059.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0281081.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0281087.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0281104.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0281111.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP280\A0281142.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP292\A0298546.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP292\A0298589.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP292\A0298595.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP292\A0299594.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP292\A0300595.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP292\A0301594.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP292\A0301598.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP292\A0301603.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP314\A0340737.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP320\A0346038.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP320\A0347043.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP320\A0347045.exe (Trojan.Agent) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{B5491EB0-8A1A-4C19-9C57-3D424FA65B10}(2)\RP320\A0347051.exe (Trojan.Agent) -> Nessuna azione intrapresa.
(fine)
Dopo che ho salvato il log, ho eliminato gli elementi infetti(in tutto 39)
Ciao
Gianni