bat66 ha scritto:cbbusto ha scritto:Prova a controllare, il log di combofix si trova in C:\ComboFix.txt. Se non lo trovi devi rifare la scansione, rispetta tutti i passaggi descritti.
Combofix va eliminarlo quando è tutto finito perchè con la rimozione viene eliminato sia il backup creato e i file in quarantena.
Quindi attendi.
Niente ha eliminato anche il .log domani lo rifaccio
Mi spieghi come rimuovere la cartella Qoobox che anche in modalità provvisoria nn la fa eliminare: accesso negato protetto da scrittura o utilizzato da altro programma.
Grazie :(
Ok cartella Qoobox eliminata a domani per il resto
Su questa 2° scansione non ha eliminato nulla, posto il log.
ComboFix 12-01-19.02 - Utente 20/01/2012 15.51.41.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1493 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((( Files Creati Da 2011-12-20 al 2012-01-20 )))))))))))))))))))))))))))))))))))
.
.
2012-01-16 23:13 . 2012-01-16 23:13 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Auslogics
2012-01-16 23:12 . 2012-01-16 23:12 -------- d-----w- c:\programmi\Auslogics
2012-01-15 14:17 . 2012-01-15 14:17 388096 ----a-r- c:\documents and settings\Utente\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-01-15 12:18 . 2012-01-15 12:18 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2012-01-15 12:18 . 2012-01-15 12:18 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2012-01-15 12:18 . 2012-01-15 12:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2012-01-15 12:18 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-13 20:32 . 2012-01-13 20:32 -------- d-----w- c:\programmi\CCleaner
2012-01-10 20:55 . 2012-01-10 20:55 -------- d-----w- c:\programmi\Astroburn Toolbar
2012-01-10 20:55 . 2012-01-10 20:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Astroburn Lite
2012-01-10 20:55 . 2012-01-10 20:55 -------- d-----w- c:\programmi\Astroburn Lite
2012-01-10 20:20 . 2012-01-10 20:20 295424 ----a-w- c:\windows\system32\bwmedia1.dll
2012-01-10 20:20 . 2012-01-10 20:20 150016 ----a-w- c:\windows\system32\bwmedia.dll
2012-01-10 20:16 . 2012-01-10 20:16 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Registry Mechanic
2012-01-10 20:12 . 2012-01-10 20:16 239168 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-10 20:12 . 2012-01-10 20:12 -------- d-----w- c:\programmi\DAEMON Tools Lite
2012-01-10 20:11 . 2012-01-13 20:39 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\DAEMON Tools Lite
2012-01-10 20:11 . 2012-01-10 20:11 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DAEMON Tools Lite
2012-01-10 18:52 . 2012-01-10 19:14 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\foobar2000
2012-01-09 14:44 . 2012-01-09 14:44 626688 ----a-w- c:\programmi\Mozilla Firefox\msvcr80.dll
2012-01-09 14:44 . 2012-01-09 14:44 548864 ----a-w- c:\programmi\Mozilla Firefox\msvcp80.dll
2012-01-09 14:44 . 2012-01-09 14:44 479232 ----a-w- c:\programmi\Mozilla Firefox\msvcm80.dll
2012-01-09 14:44 . 2012-01-09 14:44 43992 ----a-w- c:\programmi\Mozilla Firefox\mozutils.dll
2012-01-07 20:11 . 2012-01-07 20:11 11776 ----a-w- c:\programmi\Mozilla Firefox\plugins\nprjplug.dll
2012-01-07 20:11 . 2012-01-07 20:11 -------- d-----w- c:\programmi\File comuni\xing shared
2012-01-07 20:11 . 2012-01-07 20:11 150696 ----a-w- c:\programmi\Mozilla Firefox\plugins\nppl3260.dll
2012-01-07 20:11 . 2012-01-07 20:11 108544 ----a-w- c:\programmi\Mozilla Firefox\plugins\nprpjplug.dll
2012-01-07 20:10 . 2012-01-07 20:10 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-01-07 20:10 . 2012-01-07 20:10 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-01-03 07:22 . 2012-01-03 07:22 103864 ----a-w- c:\programmi\Mozilla Firefox\plugins\nppdf32.dll
2012-01-03 07:22 . 2012-01-03 07:22 103864 ----a-w- c:\programmi\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-19 18:59 . 2011-01-06 16:37 97760 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-12-19 18:59 . 2011-01-06 16:37 31704 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-12-19 18:59 . 2011-01-06 16:37 494816 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-12-19 18:59 . 2011-01-06 16:37 18056 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-12-19 18:58 . 2011-12-08 16:08 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-12-19 18:58 . 2010-12-29 00:42 301224 ----a-w- c:\windows\system32\guard32.dll
2011-11-29 21:17 . 2011-11-29 21:17 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-28 18:01 . 2011-09-04 12:13 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-09-04 12:13 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-09-04 12:13 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-09-04 12:13 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-09-04 12:13 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-09-04 12:13 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-09-04 12:13 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2011-09-04 12:13 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2011-09-04 12:13 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2011-09-04 12:13 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2004-08-19 13:39 293888 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 14:40 . 2004-08-19 13:31 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-20 06:12 . 2004-08-19 13:39 60928 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:22 . 2004-08-19 13:39 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:22 . 2004-08-19 13:39 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-03 15:28 . 2004-08-19 13:39 386560 ----a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-08-19 13:39 1297408 ----a-w- c:\windows\system32\quartz.dll
2011-11-01 20:35 . 2004-08-19 13:39 669696 ----a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35 . 2004-08-19 13:39 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-11-01 20:35 . 2004-08-03 20:59 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-11-01 20:34 . 2004-08-19 13:26 371200 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-19 13:39 1288192 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-19 13:39 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-26 10:49 . 2004-08-19 15:34 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-26 10:49 . 2004-08-19 13:34 2152448 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-01-09 14:44 . 2011-06-15 16:48 121816 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\programmi\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Six Engine"="c:\program files\ASUS\Six Engine\SixEngine.exe" [2008-06-03 5964800]
"IAAnotif"="c:\programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712]
"COMODO Internet Security"="c:\programmi\COMODO\COMODO Internet Security\cfp.exe" [2011-12-21 6676808]
"avast"="c:\programmi\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"COMODO"="c:\programmi\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 208184]
"CPA"="c:\programmi\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 182584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
.
c:\documents and settings\Utente\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-02 09:07 843712 ----a-r- c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-01-03 21:51 37296 ----a-w- c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 ----a-w- c:\programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Greenshot]
2010-07-01 20:41 540672 ----a-w- c:\programmi\Greenshot\Greenshot.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 23:47 31016 -c--a-w- c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:14 1695232 ------w- c:\programmi\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-05-16 18:31 13529088 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PosService]
2011-12-03 10:04 218624 ----a-w- c:\documents and settings\All Users\Documenti\AppData\PoApp\PLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2012-01-07 20:10 296056 ----a-w- c:\programmi\Real\RealPlayer\Update\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-06-24 14:41 247144 ----a-w- c:\programmi\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
.
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [23/06/2008 23.21.48 150568]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [04/09/2011 13.13.27 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [04/09/2011 13.13.28 314456]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [06/01/2011 17.37.02 494816]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [06/01/2011 17.37.04 31704]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [04/09/2011 13.13.28 20568]
R2 CLPSLS;COMODO livePCsupport Service;c:\programmi\COMODO\COMODO GeekBuddy\CLPSLS.exe [23/11/2011 11.27.04 1052472]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmi\TomTom HOME 2\TomTomHOMEService.exe [24/06/2010 15.41.38 92008]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [10/01/2012 21.12.34 239168]
R3 SNXPCARD;Golden Series Multiport Adapter Driver;c:\windows\system32\drivers\snxpcard.sys [20/10/2009 19.25.57 17536]
R3 SNXPPALX;Golden Parallel Port Driver;c:\windows\system32\drivers\snxppalx.sys [20/10/2009 19.25.57 78848]
S2 CPUSB;CPUsb.Sys driver;c:\windows\system32\drivers\CPUSB.sys [22/10/2009 20.54.46 17080]
S2 gupdate1ca9616b4d9b476;Servizio di Google Update (gupdate1ca9616b4d9b476);c:\programmi\Google\Update\GoogleUpdate.exe [15/01/2010 20.12.38 133104]
S2 PowerOffer Service;Pos Service;"c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\PosService\Pos.exe" --> c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\PosService\Pos.exe [?]
S2 ServUpdater;Serv Updater;c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\ServUpdater\ServiceUpd.exe [22/11/2011 16.52.51 156160]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [25/02/2010 17.02.47 377920]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [15/01/2010 20.12.38 133104]
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2012-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-15 19:12]
.
2012-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-15 19:12]
.
2012-01-20 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1292428093-1532298954-839522115-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2011-11-29 15:02]
.
2012-01-14 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1292428093-1532298954-839522115-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2011-11-29 15:02]
.
2012-01-19 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\programmi\Spybot - Search & Destroy\SpybotSD.exe [2010-02-26 14:31]
.
2012-01-19 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\programmi\Spybot - Search & Destroy\SDUpdate.exe [2010-02-26 14:31]
.
.
------- Scansione supplementare -------
.
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{17208D67-BFFE-4F89-A7DB-D8071F776C19}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\0k7sqe1c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1460988&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ast Customized Web Search
FF - prefs.js: browser.startup.homepage -
www.google.itFF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT314288&SearchSource=2&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-01-20 15:57
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(856)
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Ora fine scansione: 2012-01-20 16:00:14
ComboFix-quarantined-files.txt 2012-01-20 15:00
.
Pre-Run: 10.677.530.624 byte disponibili
Post-Run: 10.774.892.544 byte disponibili
.
- - End Of File - - 4F6AC17BE617139F6B2ACA609C4C6A66