Ho fixato le voci.
Log Combofix, prima di fixare. Ho provato a fare una scansione con Combofix dopo aver fixat ma il modalità provvisoria Combofix non mi da il log, il computer rimane impiantato con la dicitura attendi il log senza fare nulla...
ComboFix 11-01-20.03 - User 21/01/2011 19.47.43.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.256.108 [GMT 1:00]
Eseguito da: c:\documents and settings\User\desktop\abc.exe
Opzioni usate :: /killall
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-12-21 al 2011-01-21 )))))))))))))))))))))))))))))))))))
.
2011-01-21 08:52 . 2011-01-21 08:52 -------- d-----w- c:\windows\LastGood.Tmp
2011-01-21 07:31 . 2011-01-21 07:31 -------- d-----w- c:\windows\system32\wbem\Repository
2011-01-21 07:30 . 2011-01-21 07:30 -------- d-----w- c:\documents and settings\User\Dati applicazioni\vlc
2011-01-16 17:15 . 2011-01-16 17:15 -------- d-----w- c:\documents and settings\User\Dati applicazioni\Malwarebytes
2011-01-16 17:14 . 2011-01-16 17:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-01-16 17:14 . 2011-01-21 07:29 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-01-15 22:12 . 2011-01-21 07:29 -------- d-s---w- c:\documents and settings\Administrator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7757CBCC-0975-4b79-A519-90B142CA3A23}"= "c:\programmi\IObitBar\toolbar\1.bin\i0SrcAs.dll" [2010-07-11 49152]
[HKEY_CLASSES_ROOT\clsid\{7757cbcc-0975-4b79-a519-90b142ca3a23}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EFA17361-CDC0-4927-9AFC-BAAD1F96B2AE}]
2010-07-11 11:18 638976 ----a-w- c:\programmi\IObitBar\toolbar\1.bin\i0bar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE}"= "c:\programmi\IObitBar\toolbar\1.bin\i0bar.dll" [2010-07-11 638976]
[HKEY_CLASSES_ROOT\clsid\{efa17369-cdc0-4927-9afc-baad1f96b2ae}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE}"= "c:\programmi\IObitBar\toolbar\1.bin\i0bar.dll" [2010-07-11 638976]
[HKEY_CLASSES_ROOT\clsid\{efa17369-cdc0-4927-9afc-baad1f96b2ae}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\programmi\IObit\Advanced SystemCare 3\AWC.exe" [2010-07-02 2347216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Disc Detector"="c:\programmi\Creative\ShareDLL\CtNotify.exe" [1998-12-16 185856]
"AudioHQ"="c:\programmi\Creative\SBLive\AudioHQ\AHQTB.EXE" [1999-04-12 203264]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"LogitechCommunicationsManager"="c:\programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"ArcSoft Connection Service"="c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"IObit Toolbar"="c:\progra~1\IObitBar\toolbar\1.bin\i0bar.dll" [2010-07-11 638976]
"IObitBar Browser Plugin Loader"="c:\progra~1\IObitBar\toolbar\1.bin\i0brmon.exe" [2010-07-11 20480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2010-5-28 212992]
Logitech Desktop Messenger.lnk - c:\programmi\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-3-19 66864]
Philips GoGear VIBE Device Manager.lnk - c:\programmi\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe [2009-12-13 1611152]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\VideoLAN\\VLC\\vlc.exe"=
R2 IObitBarService;IObit Toolbar Service;c:\progra~1\IObitBar\toolbar\1.bin\i0barsvc.exe [2010-07-11 28766]
S0 28986642;28986642 Boot Guard Driver;c:\windows\system32\DRIVERS\28986642.sys [2009-10-22 37392]
S1 aswSP;aswSP; [x]
S1 setup_9.0.0.722_20.03.2010_16-46drv;setup_9.0.0.722_20.03.2010_16-46drv;c:\windows\system32\DRIVERS\3724687.sys [2009-10-09 315408]
S2 aswFsBlk;aswFsBlk; [x]
.
Contenuto della cartella 'Scheduled Tasks'
2010-11-24 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-07-11 20:18]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://results.myway.com/default.jhtml?kl=y&ptb=080A886E-3BFF-4D25-9327-F404DAAAE099
uInternet Connection Wizard,ShellNext = iexplore
IE: Cerca -
http://edits.myway.com/menusearch.jhtml?s=100000379&p=YI&si=&a=080A886E-3BFF-4D25-9327-F404DAAAE099&n=2010082104IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {7E088910-469A-4311-BC8D-8D4A734156BC} = 151.99.125.2,151.99.125.3
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\programmi\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\User\Dati applicazioni\Mozilla\Firefox\Profiles\s1q3a8to.default\
FF - prefs.js: browser.search.selectedEngine - My Way
FF - prefs.js: browser.startup.homepage - hxxp://www.virgilio.it
FF - prefs.js: keyword.URL - hxxp://results.myway.com/GGmain.jhtml?id=YI&ptb=080A886E-3BFF-4D25-9327-F404DAAAE099&psa=&ind=2010082104&ptnrS=YI&si=&st=kwd&n=&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: IObit:
i0ffxtbr@IObitBar.com - c:\programmi\IObitBar\toolbar\1.bin
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
AddRemove-Incomedia Pro 6.0 - c:\windows\system32\I6Setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-21 20:05
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = c:\programmi\Creative\ShareDLL\CtNotify.exe?????X?????????????????B?????Disc Detector?B???A???????A?p?????B???@???@???B???????@?????????0?B???A???????A???????B???@?????P?????@?????????~?:~??????????@???????????????????B???????????????????????????????????B
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(4468)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\IObitBar\toolbar\1.bin\i0brstub.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Alwil Software\Avast5\AvastSvc.exe
c:\programmi\Creative\ShareDLL\MediaDet.Exe
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
c:\programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
c:\programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\devldr32.exe
c:\programmi\File comuni\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Ora fine scansione: 2011-01-21 20:12:02 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-01-21 19:11
Pre-Run: 10.706.792.448 byte disponibili
Post-Run: 10.649.538.560 byte disponibili
- - End Of File - - D5CCF3F86BBCB3541A78498C2AB78E9B