Ciao! Eccomi ancora dopo un po' di scoraggiamento...
I giorni scorsi dopo aver cominciato le scansioni suggerite, ho pensato che, se prima non avessi pulito bene la memoria esterna e le chiavette, sarei stata sempre da capo a riprendermi le infezioni.. Così ho provatp: ho scansionato tutto (memoria e pen drive) con Malwarebytes e AVG, ho scaricato poi i contenuti sul pc e ho riformattato memoria est. e chiavi...
Poi ormai tardi, ho deciso lasciare i vari file sul desktop senza ricollocarli, in modo che venissero ulteriormente puliti con le successive scansioni del pc. Sono appassionata di foto che conservo nella mem. est. e così prima di chiudere tutto ho voluto rivedere vecchie immagini: le cartelle però non si aprono più! Ecco il motivo della lontananza dal pc...
Stasera ho ripreso. Posto i log e poi farò le pulizie che mi avevi suggerito. Una precisazione: ho messo in quarantena i file individuati da malw., anche se il log non lo precisa...Lì dice 1 file infetto, ma nella videata precedente , quando mi si chiedeva cosa fare, ce n'erano un'intera legione!
Malwarebytes' Anti-Malware 1.41
Versione del database: 2925
Windows 5.1.2600 Service Pack 3
08/10/2009 19.26.19
mbam-log-2009-10-08 (19-26-11).txt
Tipo di scansione: Scansione completa (A:\|C:\|D:\|)
Elementi scansionati: 125172
Tempo trascorso: 20 minute(s), 35 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 1
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
C:\WINDOWS\system32\1C43AE\RegEx.fnr (Worm.AutoRun) -> No action taken.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Maura\IMPOST~1\Temp\E_N4
c:\docume~1\Maura\IMPOST~1\Temp\E_N4\cnvpe.fne
c:\docume~1\Maura\IMPOST~1\Temp\E_N4\dp1.fne
c:\docume~1\Maura\IMPOST~1\Temp\E_N4\eAPI.fne
c:\docume~1\Maura\IMPOST~1\Temp\E_N4\HtmlView.fne
c:\docume~1\Maura\IMPOST~1\Temp\E_N4\internet.fne
c:\docume~1\Maura\IMPOST~1\Temp\E_N4\krnln.fnr
c:\docume~1\Maura\IMPOST~1\Temp\E_N4\shell.fne
c:\docume~1\Maura\IMPOST~1\Temp\E_N4\spec.fne
c:\windows\AUTOLNCH.REG
.
((((((((((((((((((((((((( Files Creati Da 2009-09-08 al 2009-10-08 )))))))))))))))))))))))))))))))))))
.
2009-10-02 19:02 . 2009-10-08 17:25 -------- d--h--w- c:\windows\system32\05CB30
2009-10-01 14:14 . 2009-08-13 15:15 512000 -c----w- c:\windows\system32\dllcache\jscript.dll
2009-09-29 22:53 . 2009-06-25 08:25 54272 -c----w- c:\windows\system32\dllcache\wdigest.dll
2009-09-29 22:53 . 2009-06-25 08:25 301568 -c----w- c:\windows\system32\dllcache\kerberos.dll
2009-09-29 22:53 . 2009-06-25 08:25 136192 -c----w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-29 22:53 . 2009-06-24 11:18 92928 -c----w- c:\windows\system32\dllcache\ksecdd.sys
2009-09-29 22:42 . 2008-09-10 01:14 1307648 -c----w- c:\windows\system32\dllcache\msxml6.dll
2009-09-29 22:42 . 2008-04-13 16:53 92672 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2009-09-29 22:42 . 2008-04-13 16:53 92672 ------w- c:\windows\system32\msxml6r.dll
2009-09-29 22:42 . 2008-09-10 01:14 1307648 ------w- c:\windows\system32\msxml6.dll
2009-09-29 22:42 . 2007-06-25 21:00 22060 -c----w- c:\windows\system32\dllcache\npds.zip
2009-09-29 22:42 . 2007-06-25 20:56 403 -c----w- c:\windows\system32\dllcache\npdrmv2.zip
2009-09-29 22:37 . 2008-04-13 17:14 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2009-09-29 22:28 . 2009-09-29 22:28 -------- d-----w- c:\windows\EHome
2009-09-19 15:39 . 2009-09-19 15:39 -------- d-----w- c:\programmi\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 17:30 . 2009-06-20 11:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-10-02 17:07 . 2009-06-20 11:33 -------- d-----w- c:\programmi\File comuni\Adobe
2009-09-30 07:30 . 2009-06-20 11:39 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-30 07:30 . 2009-06-20 11:39 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-30 07:30 . 2009-06-20 11:39 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-30 06:19 . 2004-08-19 12:00 48568 ----a-w- c:\windows\system32\perfc010.dat
2009-09-30 06:19 . 2004-08-19 12:00 347866 ----a-w- c:\windows\system32\perfh010.dat
2009-09-30 05:50 . 2009-06-20 11:53 42944 ----a-w- c:\documents and settings\Maura\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-18 16:54 . 2009-09-08 13:48 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-09-15 16:11 . 2009-06-20 12:23 -------- d-----w- c:\programmi\FotoStation Easy
2009-09-10 12:54 . 2009-09-08 13:48 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-09-08 13:48 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 17:06 . 2009-09-08 17:06 -------- d-----w- c:\programmi\Unlocker
2009-09-08 15:31 . 2009-09-08 15:31 -------- d-----w- c:\programmi\CCleaner
2009-09-08 13:48 . 2009-09-08 13:48 -------- d-----w- c:\documents and settings\Maura\Dati applicazioni\Malwarebytes
2009-09-08 13:48 . 2009-09-08 13:48 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-08-05 08:59 . 2004-08-19 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2004-08-19 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-12 10:21 . 2004-08-19 12:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 07:55 1090816 ----a-w- c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-27 39408]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-30 2007832]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-30 07:30 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [20/06/2009 13.39.10 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [20/06/2009 13.39.16 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [26/06/2009 22.30.01 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [26/06/2009 22.30.03 297752]
S2 DeviceManager;DeviceManager;c:\programmi\File comuni\DeviceHelper\DeviceManager.exe -start --> c:\programmi\File comuni\DeviceHelper\DeviceManager.exe -start [?]
S3 qcusbser;Modem Interface USB Device for Legacy Serial Communication;c:\windows\system32\drivers\qcusbser.sys [20/06/2009 13.53.06 103552]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-C8714E - c:\windows\system32\05CB30\C8714E.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-08 19:38
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2009-10-08 19.39.22
ComboFix-quarantined-files.txt 2009-10-08 17:39
Pre-Run: 113.692.622.848 byte disponibili
Post-Run: 113.694.199.808 byte disponibili
126 --- E O F --- 2009-10-04 14:00