ciao r16
ho eliminato il S.O. windows 7 e da Windows XP ho fatto la scansione con combofix.
in fine mi e uscito il log che ti posto di seguito.
Scusami tanto se sono svogliato nel leggere i tuoi consigli e poi di seguito sbaglio
Ti ringrazio per la tua immensa pazienza
attendo
ComboFix 11-01-02.04 - Roberto 03/01/2011 14.09.29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1470.1004 [GMT 1:00]
Eseguito da: c:\documents and settings\Roberto\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Roberto\Dati applicazioni\OfferBox
c:\documents and settings\Roberto\Dati applicazioni\OfferBox\config.xml
c:\documents and settings\Roberto\lame_enc_en.dll
c:\documents and settings\Roberto\lametritonus_en.dll
c:\windows\system32\2114508511
.
((((((((((((((((((((((((( Files Creati Da 2010-12-03 al 2011-01-03 )))))))))))))))))))))))))))))))))))
.
2011-01-03 12:57 . 2011-01-03 12:57 709456 ----a-w- c:\windows\isRS-000.tmp
2010-12-16 08:03 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-16 08:03 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2010-12-08 00:27 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-12-08 00:27 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-12-08 00:27 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-12-07 11:45 . 2010-12-07 11:45 -------- d-----w- c:\windows\l2schemas
2010-12-07 11:45 . 2010-12-07 11:45 -------- d-----w- c:\windows\system32\it
2010-12-07 11:45 . 2010-12-07 11:45 -------- d-----w- c:\windows\system32\bits
2010-12-06 11:33 . 2010-12-06 11:33 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\ICS
2010-12-06 11:33 . 2010-12-07 07:02 -------- d-----w- c:\windows\LMI20.tmp
2010-12-06 11:32 . 2010-12-06 11:33 -------- d-----w- c:\documents and settings\Roberto\Impostazioni locali\Dati applicazioni\Deployment
2010-12-05 15:26 . 2010-12-05 15:26 -------- d-----w- c:\documents and settings\Roberto\Dati applicazioni\Malwarebytes
2010-12-05 15:26 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-05 15:26 . 2010-12-05 15:26 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-12-05 15:26 . 2011-01-03 12:57 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-12-05 15:26 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-05 15:12 . 2010-12-05 15:12 -------- d-----w- c:\programmi\CCleaner
2010-12-05 14:24 . 2010-12-05 14:24 388096 ----a-r- c:\documents and settings\Roberto\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-05 14:24 . 2010-12-05 14:24 -------- d-----w- c:\programmi\Trend Micro
2010-12-05 11:13 . 2010-12-05 11:13 -------- d-----w- c:\documents and settings\Roberto\Dati applicazioni\PhotoFiltre
2010-12-05 08:36 . 2010-12-05 08:36 -------- d-----w- c:\windows\system32\XPSViewer
2010-12-05 08:36 . 2010-12-05 08:36 -------- d-----w- c:\programmi\MSBuild
2010-12-05 08:35 . 2010-12-05 08:35 -------- d-----w- c:\programmi\Reference Assemblies
2010-12-05 08:35 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-12-05 08:35 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-12-05 08:35 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-12-05 08:35 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-12-05 08:35 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-12-05 08:35 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-12-05 08:35 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-12-05 08:35 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-12-05 08:35 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-12-05 08:28 . 2010-12-05 08:28 -------- d-----w- c:\programmi\MSXML 6.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:12 . 2009-11-11 18:54 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:46 . 2010-11-09 14:46 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2010-11-06 00:21 . 2004-08-19 13:39 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:21 . 2004-08-19 13:39 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2004-08-19 13:39 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2004-08-19 13:26 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2001-08-31 10:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-11-02 09:56 . 2010-11-02 09:56 293176 ----a-w- c:\programmi\SoftonicDownloader_per_nero-burnlite.exe
2010-10-28 13:13 . 2004-08-19 13:37 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 14:05 . 2004-08-19 13:31 1853312 ----a-w- c:\windows\system32\win32k.sys
2009-11-21 22:21 203776 --sh--w- c:\windows\system32\unrar.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]
"VMonitorVMUVC"="c:\programmi\Vimicro Corporation\VMUVC\VMonitor.exe" [2008-08-29 143360]
"ANIWZCS2Service"="c:\programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-10-19 49152]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Programmi\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"l:\\Nuova cartella\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [29/11/2009 12.50.48 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29/11/2009 12.50.48 17744]
S0 annywl;annywl;c:\windows\system32\drivers\scbp.sys --> c:\windows\system32\drivers\scbp.sys [?]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [02/12/2010 22.41.51 136176]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [09/03/2010 16.24.58 112640]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [09/03/2010 16.29.00 102656]
S3 jrdusbser;Modem Interface Device for Legacy Serial Communication;c:\windows\system32\drivers\jrdusbser.sys [28/05/2010 17.02.35 105344]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [25/10/2010 17.41.22 256512]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [25/10/2010 17.41.22 398720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
2011-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-12-02 21:41]
2011-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-12-02 21:41]
2011-01-03 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
AddRemove-BearShare MediaBar - c:\programmi\BearShare Applications\MediaBar\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-03 14:15
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ñw*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2011-01-03 14:18:51
ComboFix-quarantined-files.txt 2011-01-03 13:18
Pre-Run: 20.828.397.568 byte disponibili
Post-Run: 20.934.078.464 byte disponibili
- - End Of File - - 47DC68816E68228BFF3D5E8ABAE12C76