fatto tutto....e forse ho risolto il problema dell'errore rundll che compariva in continuazione
ora come ora però non si riavvia avira...forse dovrò riavviare...
intanto posto il log
ComboFix 11-01-16.04 - _vale_ 17/01/2011 22.23.49.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1015.587 [GMT 1:00]
Eseguito da: c:\documents and settings\_vale_\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {00000002-0002-0000-6C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *Enabled/Updated* {7FFDDBF8-2F40-0025-0000-00006CEE1200}
AV: AntiVir Desktop *Enabled/Updated* {7FFDEBF8-2F40-0025-0000-00006CEE1200}
AV: AntiVir Desktop *Enabled/Updated* {7FFDFBF8-2F40-0025-0000-00006CEE1200}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\_vale_\Dati applicazioni\OfferBox
c:\documents and settings\_vale_\Dati applicazioni\OfferBox\config.dat
c:\documents and settings\_vale_\Dati applicazioni\OfferBox\config.xml
c:\documents and settings\All Users\Menu Avvio\Programmi\OfferBox Browser.lnk
c:\documents and settings\LocalService\Dati applicazioni\OfferBox
c:\documents and settings\LocalService\Dati applicazioni\OfferBox\config.xml
c:\programmi\OfferBox
c:\programmi\OfferBox\OfferBox.exe
c:\programmi\OfferBox\OfferBoxBHO.dll
c:\programmi\OfferBox\OfferBoxChromeExtension.crx
c:\programmi\OfferBox\OfferBoxEngine.dll
c:\programmi\OfferBox\offerboxffx@offerbox.com\chrome.manifest
c:\programmi\OfferBox\offerboxffx@offerbox.com\chrome\content\events.js
c:\programmi\OfferBox\offerboxffx@offerbox.com\chrome\content\overlay.xul
c:\programmi\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.dll
c:\programmi\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.xpt
c:\programmi\OfferBox\offerboxffx@offerbox.com\install.rdf
c:\programmi\OfferBox\OfferBoxLauncher.exe
c:\programmi\OfferBox\res\language.xml
c:\programmi\OfferBox\res\loader.gif
c:\programmi\OfferBox\uninst.exe
c:\windows\system32\Thumbs.db
c:\windows\Wuiasgr.dll
.
((((((((((((((((((((((((( Files Creati Da 2010-12-17 al 2011-01-17 )))))))))))))))))))))))))))))))))))
.
2011-01-17 21:00 . 2011-01-17 21:00 -------- d-----w- c:\documents and settings\_vale_\Dati applicazioni\Uniblue
2011-01-17 21:00 . 2011-01-17 21:00 -------- dc-h--w- c:\documents and settings\All Users\Dati applicazioni\{DE8EABB5-1C85-4410-A68D-79BD8A4518F4}
2011-01-17 21:00 . 2011-01-17 21:00 -------- d-----w- c:\programmi\Uniblue
2011-01-17 21:00 . 2011-01-17 21:00 -------- d-----w- c:\documents and settings\_vale_\Impostazioni locali\Dati applicazioni\PackageAware
2011-01-17 18:48 . 2011-01-17 18:48 388096 ----a-r- c:\documents and settings\_vale_\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-01-17 18:48 . 2011-01-17 18:48 -------- d-----w- c:\programmi\Trend Micro
2011-01-17 11:31 . 2011-01-17 11:31 -------- d-----r- c:\documents and settings\NetworkService\Preferiti
2011-01-17 11:30 . 2011-01-17 11:30 -------- d-----r- c:\documents and settings\LocalService\Documenti
2011-01-17 11:30 . 2011-01-17 11:33 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Adobe
2011-01-17 11:27 . 2011-01-17 11:27 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Mozilla
2011-01-16 22:20 . 2011-01-16 22:20 -------- d-----w- c:\documents and settings\_vale_\Dati applicazioni\Helpnew
2011-01-16 12:16 . 2011-01-16 12:16 -------- d-----w- C:\My Games
2011-01-16 12:16 . 2011-01-16 12:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AlawarGameBox
2011-01-16 12:15 . 2011-01-16 12:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AlawarWrapper
2011-01-16 12:15 . 2011-01-16 12:16 -------- d-----w- c:\programmi\Alawar
2010-12-21 21:49 . 2010-12-21 21:49 -------- d-----w- c:\documents and settings\_vale_\Dati applicazioni\Adobe Mini Bridge CS5
2010-12-21 12:16 . 2010-12-21 12:16 -------- d-----w- c:\documents and settings\_vale_\Dati applicazioni\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:12 . 2009-08-25 09:35 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:51 . 2009-08-25 11:24 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:21 . 2009-08-25 11:24 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:21 . 2009-08-25 11:24 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2009-08-25 11:24 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2009-08-25 11:24 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2009-08-25 11:24 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2009-08-25 11:24 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 14:05 . 2009-08-25 11:24 1853312 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\programmi\ASUS\Eee Docking\Eee Docking.exe" [2009-07-27 397312]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-02-11 39408]
"DAEMON Tools Pro Agent"="c:\programmi\DAEMON Tools Pro\DTAgent.exe" [2010-04-15 427328]
"Linkpnp"="c:\documents and settings\_vale_\Dati applicazioni\Helpnew\netres.exe" [2011-01-17 279040]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusEPCMonitor"="c:\programmi\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\programmi\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2009-04-09 1512744]
"SynAsusAcpi"="c:\programmi\Synaptics\SynTP\SynAsusAcpi.exe" [2009-04-09 79144]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-27 17881088]
"AdobeCS4ServiceManager"="c:\programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"AdobeAAMUpdater-1.0"="c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\programmi\File comuni\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\_vale_\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
SuperHybridEngine.lnk - c:\programmi\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-8-25 376832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\mIRC\\mirc.exe"=
"c:\\Programmi\\File comuni\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [06/06/2010 13.12.32 697328]
R2 DeviceManager;DeviceManager;c:\programmi\File comuni\DeviceHelper\DeviceManager.exe -start --> c:\programmi\File comuni\DeviceHelper\DeviceManager.exe -start [?]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [18/08/2009 22.44.33 38912]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29/09/2009 8.11.22 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29/09/2009 8.11.20 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29/09/2009 8.11.20 12928]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [11/02/2010 15.23.58 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [25/08/2009 12.05.30 1684736]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [29/09/2010 18.37.18 114432]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [29/09/2010 18.37.18 100736]
S3 qcusbser;Modem Interface USB Device for Legacy Serial Communication;c:\windows\system32\drivers\qcusbser.sys [31/01/2010 23.52.41 103552]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [25/08/2009 12.08.18 1015424]
S3 SwitchBoard;SwitchBoard;c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13.37.14 517096]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [12/08/2009 7.57.17 39040]
S3 zlportio;zlportio; [x]
.
Contenuto della cartella 'Scheduled Tasks'
2010-12-31 c:\windows\Tasks\AdobeAAMUpdater-1.0-VALENTINA-_vale_.job
- c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-12-20 02:44]
2011-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-11 14:23]
2011-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-11 14:23]
2011-01-17 c:\windows\Tasks\RegistryBooster.job
- c:\programmi\Uniblue\RegistryBooster\rbmonitor.exe [2010-12-27 21:00]
2011-01-17 c:\windows\Tasks\User_Feed_Synchronization-{143A0FE7-A26F-4DC7-8E6D-7055C50E6952}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://search.findeer.it/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Invia a Bluetooth
IE: Invia a periferica &Bluetooth...
FF - ProfilePath - c:\documents and settings\_vale_\Dati applicazioni\Mozilla\Firefox\Profiles\vt0xc20v.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.findeer.it/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: PowerOffer:
powerofferffx@poweroffer.net - c:\documents and settings\All Users\Documenti\PowerOffer\powerofferffx@poweroffer.net
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-LG LinkAir - (no file)
HKCU-Run-PoService - (no file)
HKCU-Run-AdobeBridge - (no file)
HKCU-Run-Ozahacupodovu - c:\windows\Wuiasgr.dll
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-OfferBox Browser - c:\programmi\OfferBox\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-17 22:35
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(3168)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\DeviceHelper\DeviceManager.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\igfxext.exe
.
**************************************************************************
.
Ora fine scansione: 2011-01-17 22:40:41 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-01-17 21:40
Pre-Run: 8.556.818.432 byte disponibili
Post-Run: 9.743.941.632 byte disponibili
Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 6292416517B68A3F29587B38B6B99015
che ne dite? siamo apposto???
intanto rinnovo i ringraziamenti...veramente siete fantastice e troppo troppo troppo efficienti;)