ciao Francesco FDAC ho eseguito ComboFix
vorrei allegarti il log per avere da te altri consigli, ma non l'abilitazione "attachment".
lo allego come testo del messaggio. scusatemi.
GRAZIEEEEEEEEE
PS
non fare caso alla data di esecuzione, devo cambiare la batteria tampone.
ComboFix 12-09-27.03 - Utente 01/01/2002 0.10.38.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.2047.1440 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\DragToDiscUserNameD.txt
c:\documents and settings\All Users\Dati applicazioni\QTSBandwidthCache
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\All Users\Dati applicazioni\TEMP\{89A43E80-AC6C-4DA8-9800-F4B30ED577C0}\PostBuild.exe
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\assembly\tmp
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\fepoohfx.dat
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\fepoohfx_nav.dat
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\fepoohfx_navps.dat
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\I Want This
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\I Want This\Chrome\I Want This.crx
c:\documents and settings\Utente\WINDOWS
c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
c:\programmi\ESET\EGUI.exe
c:\programmi\I Want This
c:\programmi\I Want This\appAPIinternalWrapper.js
c:\programmi\I Want This\fb.js
c:\programmi\I Want This\I Want This.dll
c:\programmi\I Want This\I Want This.exe
c:\programmi\I Want This\I Want This.ico
c:\programmi\I Want This\I Want ThisGui.exe
c:\programmi\I Want This\jquery.js
c:\programmi\I Want This\json.js
c:\programmi\I Want This\Uninstall.exe
c:\recycler\S-1-5-18\$8f60bd97cacf62c6284292526e1f5161\@
c:\recycler\S-1-5-18\$8f60bd97cacf62c6284292526e1f5161\n
c:\windows\assembly\GAC\Desktop.ini
c:\windows\IsUn0410.exe
c:\windows\system\WINSPOOL.DRV
c:\windows\system32\AutoRun.inf
c:\windows\system32\roboot.exe
c:\windows\system32\SET534.tmp
c:\windows\system32\SET540.tmp
c:\windows\system32\spool\prtprocs\w32x86\BuEProNT.dll
c:\windows\system32\UNWISE.EXE
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
.
La copia infetta di c:\windows\system32\msgsvc.dll è stata trovata e disinfettata
ipristinata copia da - c:\system volume information\_restore{6C4A8D7A-1893-46AA-8A44-102727A90E48}\RP447\A0126572.dll
.
c:\windows\system32\proquota.exe . . . is missing!!
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-08 03:22 . 2001-08-31 12:00 156160 ----a-w- c:\windows\system32\msls31.dll
2008-05-08 12:28 . 2001-08-31 12:00 202752 ----a-w- c:\windows\system32\drivers\rmcast.sys
2006-11-01 19:18 . 2001-08-31 12:00 927504 ----a-w- c:\windows\system32\mfc40u.dll
2006-10-16 16:15 . 2001-08-31 12:00 124928 ----a-w- c:\windows\system32\oledlg.dll
2006-10-13 12:35 . 2001-08-31 12:00 64000 ----a-w- c:\windows\system32\nwapi32.dll
2006-10-04 14:05 . 2008-10-07 21:52 39424 ------w- c:\windows\apppatch\acadproc.dll
2006-07-21 08:27 . 2001-08-31 12:00 72704 ----a-w- c:\windows\system32\hlink.dll
2006-06-23 06:48 . 2008-05-26 14:47 32768 ----a-r- c:\windows\inf\UpdateUSB.exe
2005-10-17 21:20 . 2001-08-31 12:00 80896 ----a-w- c:\windows\system32\fontsub.dll
2005-07-26 04:40 . 2001-08-31 12:00 75264 ----a-w- c:\windows\system32\olecli32.dll
2005-07-26 04:40 . 2001-08-31 12:00 37888 ----a-w- c:\windows\system32\olecnv32.dll
2004-08-19 13:39 . 2008-05-24 22:20 151040 ----a-w- c:\windows\pchealth\UploadLB\Binaries\UploadM.exe
2004-08-19 13:39 . 2008-05-24 22:20 160256 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
2004-08-19 13:39 . 2008-05-24 22:20 18944 ----a-w- c:\windows\pchealth\helpctr\binaries\HscUpd.exe
2004-08-19 13:39 . 2008-05-24 22:20 768512 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpCtr.exe
2004-08-19 13:39 . 2008-05-24 22:20 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
2004-08-19 13:39 . 2004-08-19 13:39 33280 ----a-w- c:\windows\help\sstub.dll
2004-08-19 13:39 . 2004-08-19 13:39 279040 ----a-w- c:\windows\help\tshoot.dll
2004-08-19 13:39 . 2008-05-24 22:20 726590 ----a-w- c:\windows\srchasst\srchui.dll
2004-08-19 13:39 . 2008-05-24 22:20 58434 ----a-w- c:\windows\srchasst\srchctls.dll
2004-08-19 13:39 . 2004-08-19 13:39 34816 ----a-w- c:\windows\help\sniffpol.dll
2004-08-19 13:39 . 2008-05-24 22:20 38912 ----a-w- c:\windows\pchealth\helpctr\binaries\pchsvc.dll
2004-08-19 13:39 . 2008-05-24 22:20 102400 ----a-w- c:\windows\pchealth\helpctr\binaries\pchshell.dll
2004-08-19 13:39 . 2008-05-24 22:20 3166208 ----a-w- c:\windows\srchasst\msgr3en.dll
2004-08-19 13:39 . 2008-05-24 22:20 379904 ----a-w- c:\windows\pchealth\helpctr\binaries\msinfo.dll
2004-08-19 13:39 . 2004-08-19 13:39 450048 ----a-w- c:\windows\apppatch\AcLayers.dll
2004-08-19 13:39 . 2004-08-19 13:39 244736 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2004-08-19 13:39 . 2004-08-19 13:39 1852416 ----a-w- c:\windows\apppatch\AcGenral.dll
2004-08-19 13:39 . 2004-08-19 13:39 137728 ----a-w- c:\windows\apppatch\AcLua.dll
2004-08-19 13:39 . 2004-08-19 13:39 116224 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2004-03-08 21:00 . 2000-05-22 14:58 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2004-03-08 21:00 . 2000-05-22 14:58 152848 ----a-w- c:\windows\system32\COMDLG32.OCX
2001-11-09 16:01 . 2001-11-09 16:01 24064 ----a-w- c:\windows\system32\ativcoxx.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{f4035115-6152-4901-a81d-f4e0a0479615}"= "c:\programmi\ilcorsaronero\prxtbilc0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{f4035115-6152-4901-a81d-f4e0a0479615}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f4035115-6152-4901-a81d-f4e0a0479615}]
2011-05-09 09:49 176936 ----a-w- c:\programmi\ilcorsaronero\prxtbilc0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{f4035115-6152-4901-a81d-f4e0a0479615}"= "c:\programmi\ilcorsaronero\prxtbilc0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{f4035115-6152-4901-a81d-f4e0a0479615}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{F4035115-6152-4901-A81D-F4E0A0479615}"= "c:\programmi\ilcorsaronero\prxtbilc0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{f4035115-6152-4901-a81d-f4e0a0479615}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchList"="c:\programmi\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-05-14 1479680]
"AliceMessenger"="c:\programmi\Alice Messenger\alicemessenger.exe" [2009-02-05 3657728]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-03-17 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2006-05-18 843776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"RoxioDragToDisc"="c:\programmi\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-10-30 1116920]
"Media Codec Update Service"="c:\programmi\Essentials Codec Pack\update.exe" [2007-04-08 303104]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2010-06-20 202256]
"avast5"="c:\programmi\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2011-07-19 421736]
"Olympus ib"="c:\programmi\Olympus\ib\olycamdetect.exe" [2010-09-30 93360]
"MDS_Menu"="c:\programmi\Olympus\ib\MUITransfer\MUIStartMenu.exe" [2010-07-01 220336]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [25/11/2009 21.07.52 294608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [25/11/2009 21.07.52 17744]
R2 SMART Display Controller;SMART Display Controller;c:\programmi\SMART Technologies\SMART Product Drivers\UCService.exe [15/07/2010 15.48.22 844688]
R3 BENDER;Pinnacle DV/AV Capture;c:\windows\system32\drivers\bender.sys [28/05/2008 15.27.12 203264]
R3 PAC7311;Cammaestro 1.0PT build 146;c:\windows\system32\drivers\PA707UCM.sys [27/06/2005 17.09.24 140800]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [28/10/2010 16.49.51 136176]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [28/10/2010 16.49.51 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\programmi\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 13.49.20 227232]
S3 SMART SNMP Agent Service;SMART SNMP Agent Service;c:\programmi\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe [15/07/2010 15.48.48 1662352]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-08-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2001-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-10-28 15:49]
.
2012-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-10-28 15:49]
.
2001-12-31 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-789336058-1303643608-839522115-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
.
2002-01-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-1303643608-839522115-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
URLSearchHooks-{fc600575-3013-4e8e-941c-4b00dafce730} - c:\programmi\myBabylon_English4\tbmyBa.dll
BHO-{fc600575-3013-4e8e-941c-4b00dafce730} - c:\programmi\myBabylon_English4\tbmyBa.dll
Toolbar-{fc600575-3013-4e8e-941c-4b00dafce730} - c:\programmi\myBabylon_English4\tbmyBa.dll
WebBrowser-{FC600575-3013-4E8E-941C-4B00DAFCE730} - c:\programmi\myBabylon_English4\tbmyBa.dll
HKLM-Run-StartCCC - c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
HKLM-Run-NWEReboot - (no file)
Notify-WgaLogon - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-I Want This - c:\programmi\I Want This\Uninstall.exe
AddRemove-Roma Antica - c:\windows\IsUn0410.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2002-01-01 00:25
Windows 5.1.2600 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(972)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2612)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\programmi\ArcSoft\WebCam Companion\PhotoImpression 5\share\pihook.dll
c:\programmi\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\programmi\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\Alwil Software\Avast5\AvastSvc.exe
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programmi\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe
c:\windows\System32\PAStiSvc.exe
c:\programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
c:\programmi\Canon\CAL\CALMAIN.exe
c:\progra~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~1.EXE
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclMSBTSrv.exe
c:\programmi\HP\Digital Imaging\bin\hpqSTE08.exe
c:\programmi\HP\Digital Imaging\bin\hpqbam08.exe
.
**************************************************************************
.
Ora fine scansione: 2002-01-01 00:28:58 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2001-12-31 23:28
.
Pre-Run: 197.825.630.208 byte disponibili
Post-Run: 212.262.846.464 byte disponibili
.
- - End Of File - - BDC2D2D615E44AADBC911AEA34172637