Ciao R16, ti ringrazio per la risposta che ho trovato molto esaudiente, ti posto i due log. Per il problema della stampante credo di essere riuscito a rimediare, il problema era che era stato disattivato lo spooler di stampa, non so da chi, una volta riattivato, come per incanto, nella cartella delle stampanti e fax mi è riapparsa la stampante. Di nuovo tante grazie Aldo
Malwarebytes' Anti-Malware 1.34
Versione del database: 1898
Windows 5.1.2600 Service Pack 3
26/03/2009 0.06.45
mbam-log-2009-03-26 (00-06-45).txt
Tipo di scansione: Scansione rapida
Elementi scansionati: 66373
Tempo trascorso: 3 minute(s), 53 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
(Nessun elemento malevolo rilevato)
ComboFix 09-03-23.01 - Aldo 2009-03-25 23.49.02.1 - NTFSx86
Eseguito da: g:\documents and settings\Aldo\Desktop\Download\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
g:\documents and settings\Aldo\Impostazioni locali\Dati applicazioni\yeqcncmx.dat
g:\documents and settings\Aldo\Impostazioni locali\Dati applicazioni\yeqcncmx.exe
g:\documents and settings\Aldo\Impostazioni locali\Dati applicazioni\yeqcncmx_nav.dat
g:\documents and settings\Aldo\Impostazioni locali\Dati applicazioni\yeqcncmx_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Creati Da 2009-02-25 al 2009-03-25 )))))))))))))))))))))))))))))))))))
.
2009-03-25 23:25 . 2009-03-25 23:25 <DIR> d-------- g:\programmi\Malwarebytes' Anti-Malware
2009-03-25 23:25 . 2009-03-25 23:25 <DIR> d-------- g:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-03-25 23:25 . 2009-03-25 23:25 <DIR> d-------- g:\documents and settings\Aldo\Dati applicazioni\Malwarebytes
2009-03-25 23:25 . 2009-02-11 10:19 38,496 --a------ g:\windows\system32\drivers\mbamswissarmy.sys
2009-03-25 23:25 . 2009-02-11 10:19 15,504 --a------ g:\windows\system32\drivers\mbam.sys
2009-03-25 23:03 . 2009-03-25 23:03 <DIR> d-------- g:\programmi\CCleaner
2009-03-03 15:16 . 2009-03-03 15:16 <DIR> d-------- g:\documents and settings\Aldo\Dati applicazioni\Zylom
2009-03-03 15:11 . 2009-03-03 15:11 <DIR> d-------- g:\programmi\Zylom Games
2009-03-03 15:11 . 2009-03-03 15:11 <DIR> d-------- g:\documents and settings\All Users\Dati applicazioni\Zylom
2009-03-03 14:09 . 2009-03-03 14:09 <DIR> d-------- g:\programmi\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-25 22:15 --------- d-----w g:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-03-24 13:03 --------- d-----w g:\programmi\Spybot - Search & Destroy
2009-03-24 08:37 10,240 --sha-w g:\programmi\Thumbs.db
2009-03-24 08:37 --------- d-----w g:\programmi\TG 6.0
2009-03-24 08:37 --------- d-----w g:\programmi\PhotoZoom Pro 2
2009-03-24 08:37 --------- d-----w g:\programmi\eMule
2009-03-24 08:37 --------- d-----w g:\programmi\Devices
2009-03-11 17:38 --------- d-----w g:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-02-22 12:25 --------- d-----w g:\documents and settings\Aldo\Dati applicazioni\DMCache
2009-02-10 22:41 --------- d-----w g:\programmi\library
2009-02-08 18:53 --------- d--h--w g:\programmi\InstallShield Installation Information
2009-02-05 21:31 --------- d-----w g:\programmi\OfficePowerT
2009-01-30 19:14 325,128 ----a-w g:\windows\system32\drivers\avgldx86.sys
2009-01-30 19:14 107,272 ----a-w g:\windows\system32\drivers\avgtdix.sys
2009-01-30 19:14 --------- d-----w g:\documents and settings\All Users\Dati applicazioni\avg8
2008-11-08 23:43 102 --sha-w g:\programmi\desktop.ini
2008-10-27 22:07 32,768 --sha-w g:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008102020081027\index.dat
2008-10-27 22:07 32,768 --sha-w g:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008102720081028\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="g:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="g:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-30 1601304]
"EPSON Stylus Photo R240 Series"="g:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE" [2005-04-25 98304]
"MSConfig"="g:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 172032]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-30 20:14 10520 g:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\G:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Traduttore di E-Mail.lnk]
path=g:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Traduttore di E-Mail.lnk
backup=g:\windows\pss\Traduttore di E-Mail.lnkCommon Startup
[HKLM\~\startupfolder\G:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Traduttore in Internet.lnk]
path=g:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Traduttore in Internet.lnk
backup=g:\windows\pss\Traduttore in Internet.lnkCommon Startup
[HKLM\~\startupfolder\G:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Traduttore In-Linea.lnk]
path=g:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Traduttore In-Linea.lnk
backup=g:\windows\pss\Traduttore In-Linea.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanRegistry]
G:\W [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StillImageMonitor]
G:\W [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 g:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-11-16 19:04 139264 g:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 03:14 15360 g:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 07:00 33648 g:\programmi\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 2007-09-11 22:38 2540976 g:\programmi\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-14 03:14 1695232 g:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 g:\programmi\File comuni\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-09 10:30 282624 g:\programmi\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--------- 2009-03-05 16:07 2260480 g:\programmi\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TGPro Office]
--a------ 2003-06-18 11:07 241664 g:\programmi\TG 6.0\IdxOffice.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-11-01 19:12 185872 g:\programmi\File comuni\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra------ 2004-02-09 09:54 65024 g:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
-ra------ 2004-01-15 13:33 49152 g:\windows\system32\VTTimer.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"g:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"g:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"g:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"g:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"g:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R2 OMSCAN;OMSCAN; [x]
R3 KS-959;Kingsun KS-959 USB Infrared Adapter;g:\windows\system32\DRIVERS\KS-959.sys [2005-09-05 19034]
S0 PQV2i;PQV2i; [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;g:\windows\System32\Drivers\avgldx86.sys [2009-01-30 325128]
S1 AvgTdiX;AVG Free8 Network Redirector;g:\windows\System32\Drivers\avgtdix.sys [2009-01-30 107272]
S1 PQIMount;PQIMount; [x]
S2 avg8emc;AVG Free8 E-mail Scanner;g:\progra~1\AVG\AVG8\avgemc.exe [2009-01-30 903960]
S2 avg8wd;AVG Free8 WatchDog;g:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-30 298264]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - a347bus
*Deregistered* - a347scsi
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avg8emc
*Deregistered* - avg8wd
*Deregistered* - AvgLdx86
*Deregistered* - AvgMfx86
*Deregistered* - AvgTdiX
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - GEARSecurity
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - irda
*Deregistered* - Irmon
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - mdmxsdk
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - PQIMount
*Deregistered* - PQV2i
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasirda
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RichVideo
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8cf38994-cd32-11dd-863a-00115b03e09b}]
\Shell\Auto\command - K:\bittorrent.exe e
\Shell\AutoRun\command - g:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d61b1530-ab52-11dd-85f2-00115b03e09b}]
\Shell\Auto\command - K:\bittorrent.exe e
\Shell\AutoRun\command - g:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-Polar Sync - (no file)
MSConfigStartUp-RecSche - g:\programmi\LifeView TVR\RecSche.exe
MSConfigStartUp-WinDVRCtrl - g:\windows\WDVRCtrl.exe
MSConfigStartUp-yeqcncmx - g:\documents and settings\aldo\impostazioni locali\dati applicazioni\yeqcncmx.exe
MSConfigStartUp-Device Detector - DevDetect.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: Download All Links with IDM - g:\programmi\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - g:\programmi\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - g:\programmi\Internet Download Manager\IEExt.htm
IE: E&sporta in Microsoft Excel - g:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{C873E82E-A38B-45AB-8C74-6F4947BE77B7} - g:\programmi\TG 6.0\TGWeb.exe
TCP: {9CA1777D-F14A-4431-8E5E-DAE35959BA62} = 208.67.222.222,208.67.220.220
FF - ProfilePath - g:\documents and settings\Aldo\Dati applicazioni\Mozilla\Firefox\Profiles\ogvany5d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1460988&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.repubblica.it/index.html
FF - component: g:\documents and settings\Aldo\Dati applicazioni\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: g:\documents and settings\Aldo\Dati applicazioni\Mozilla\Firefox\Profiles\ogvany5d.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\FFAlert.dll
FF - plugin: g:\documents and settings\All Users\Dati applicazioni\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: g:\programmi\Mozilla Firefox\plugins\npzylomgamesplayer.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-25 23:53:40
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2ffd0c1a-9676-4506-b501-893a24ae79b1}]
@Denied: (Full) (Everyone)
"Model"=dword:0000001a
"Therad"=dword:00000008
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,70,75,7f,a6,4e,b3,db,e0,92,2d,3a,f2,f8,fd,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):f1,3e,3b,27,ba,57,01,fc,e4,b2,09,6a,c0,1f,2e,ae,07,af,59,2f,5c,
40,39,3e,0b,a0,a3,eb,e6,0c,28,5c,69,7a,5e,53,3e,c0,bb,e2,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
------------------------ Altri processi in esecuzione ------------------------
.
g:\programmi\AVG\AVG8\avgrsx.exe
g:\windows\system32\gearsec.exe
g:\programmi\CyberLink\Shared Files\RichVideo.exe
g:\programmi\AVG\AVG8\avgrsx.exe
g:\progra~1\AVG\AVG8\avgnsx.exe
g:\programmi\AVG\AVG8\avgcsrvx.exe
g:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2009-03-25 23:57:54 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-03-25 22:57:47
Pre-Run: 3.920.404.480 byte disponibili
Post-Run: 3,842,965,504 byte disponibili
306 --- E O F --- 2009-03-14 18:03:40