forse con il vostro aiuto ho risolto tutto ... perche riesco d'inuovo a vedere le cartelle nascoste comunque ecco il log fatto da combofix
(però non riesco a rimettere avazt all'avvio)
VI RINGRAZZIO INFINITAMENTE!!!!!!!!!!!!! ecco il log (anche se non ho capito niente di cosa ci sia scritto , ho solo capito che tutte le scritte sono indirizzi delle mie cartelle e dei miei documenti )
ComboFix 08-06-20.4 - marco 2008-06-28 0:30:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.17 [GMT 2:00]
Eseguito da: C:\Documents and Settings\marco\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\marco\Impostazioni locali\Dati applicazioni\jfrnqmi.dat
C:\Documents and Settings\marco\Impostazioni locali\Dati applicazioni\jfrnqmi_nav.dat
C:\Documents and Settings\marco\Impostazioni locali\Dati applicazioni\jfrnqmi_navps.dat
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\downld\1295218.exe
C:\WINDOWS\system32\drivers\downld\1383171.exe
C:\WINDOWS\system32\drivers\downld\1410156.exe
C:\WINDOWS\system32\drivers\downld\16387093.exe
C:\WINDOWS\system32\drivers\downld\16634796.exe
C:\WINDOWS\system32\drivers\downld\16657562.exe
C:\WINDOWS\system32\drivers\downld\16712406.exe
C:\WINDOWS\system32\drivers\downld\16741187.exe
C:\WINDOWS\system32\drivers\downld\16764750.exe
C:\WINDOWS\system32\drivers\downld\16795343.exe
C:\WINDOWS\system32\drivers\downld\1775500.exe
C:\WINDOWS\system32\drivers\downld\1897062.exe
C:\WINDOWS\system32\drivers\downld\1932812.exe
C:\WINDOWS\system32\drivers\downld\1951640.exe
C:\WINDOWS\system32\drivers\downld\1975968.exe
C:\WINDOWS\system32\drivers\downld\31203609.exe
C:\WINDOWS\system32\drivers\downld\32265109.exe
C:\WINDOWS\system32\drivers\downld\32295078.exe
C:\WINDOWS\system32\drivers\downld\32352468.exe
C:\WINDOWS\system32\drivers\downld\32380328.exe
C:\WINDOWS\system32\drivers\downld\32407671.exe
C:\WINDOWS\system32\drivers\downld\32427937.exe
C:\WINDOWS\system32\drivers\downld\329484.exe
C:\WINDOWS\system32\drivers\downld\335796.exe
C:\WINDOWS\system32\drivers\downld\46835312.exe
C:\WINDOWS\system32\drivers\downld\809265.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-05-27 al 2008-06-27 )))))))))))))))))))))))))))))))))))
.
2008-06-27 21:48 . 2008-06-27 21:48 244 --ah----- C:\sqmnoopt02.sqm
2008-06-27 21:48 . 2008-06-27 21:48 232 --ah----- C:\sqmdata02.sqm
2008-06-27 21:45 . 2008-06-27 21:45 244 --ah----- C:\sqmnoopt01.sqm
2008-06-27 21:45 . 2008-06-27 21:45 232 --ah----- C:\sqmdata01.sqm
2008-06-26 19:20 . 2008-06-26 19:20 332 --a------ C:\WINDOWS\desctemp.dat
2008-06-26 13:36 . 2008-06-26 13:36 24,400 --a------ C:\Documents and Settings\marco\lrzvzvxo.exe
2008-06-26 13:29 . 2008-06-26 13:29 24,400 --a------ C:\Documents and Settings\marco\mhoeejnl.exe
2008-06-26 13:23 . 2008-06-26 13:23 24,400 --a------ C:\Documents and Settings\marco\lhdrumcf.exe
2008-06-26 13:17 . 2008-06-26 13:17 24,400 --a------ C:\Documents and Settings\marco\mwiqngsr.exe
2008-06-26 13:11 . 2008-06-26 13:11 24,400 --a------ C:\Documents and Settings\marco\gcfcftfi.exe
2008-06-26 13:05 . 2008-06-26 13:05 24,400 --a------ C:\Documents and Settings\marco\wktdusfb.exe
2008-06-26 12:59 . 2008-06-26 12:59 24,400 --a------ C:\Documents and Settings\marco\fszwjuoj.exe
2008-06-26 12:51 . 2008-06-26 12:51 24,400 --a------ C:\Documents and Settings\marco\zmxhunek.exe
2008-06-26 12:45 . 2008-06-26 12:45 24,400 --a------ C:\Documents and Settings\marco\skcjibdf.exe
2008-06-25 20:25 . 2008-06-25 20:34 <DIR> d-------- C:\Programmi\Web Photo Album
2008-06-25 20:25 . 2008-06-25 20:25 <DIR> d-------- C:\Programmi\Cartoonist
2008-06-25 19:28 . 2008-06-25 19:28 <DIR> d-------- C:\Programmi\Er Finestra
2008-06-24 21:52 . 2008-06-24 21:52 <DIR> d-------- C:\Programmi\Panda Security
2008-06-24 18:55 . 2005-07-08 14:44 159,616 --a------ C:\WINDOWS\system32\drivers\vax347b.sys
2008-06-24 18:55 . 2004-04-30 09:33 5,248 --a------ C:\WINDOWS\system32\drivers\vax347s.sys
2008-06-24 18:37 . 2008-06-24 18:37 <DIR> d-------- C:\Programmi\Alcohol Soft
2008-06-13 22:20 . 2008-06-13 22:34 <DIR> d-------- C:\Programmi\BestPractice
2008-06-13 20:56 . 2008-06-13 20:56 <DIR> d-------- C:\Programmi\mp3DirectCut
2008-06-12 22:16 . 2008-06-19 15:30 <DIR> d-------- C:\Programmi\softxpansion
2008-06-12 22:14 . 2004-01-01 09:34 24,576 --------- C:\WINDOWS\system32\msxml3a.dll
2008-06-10 19:20 . 2008-06-10 19:20 <DIR> d-------- C:\SIERRA
2008-06-10 19:20 . 2008-06-10 19:20 <DIR> d-------- C:\Programmi\Windows Media Connect 2
2008-05-31 12:22 . 2008-06-25 11:08 7,680 --ahs---- C:\WINDOWS\Thumbs.db
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 19:51 --------- d-----w C:\Programmi\Metin2_Italiano
2008-06-24 17:14 --------- d-----w C:\Documents and Settings\marco\Dati applicazioni\stopgreat
2008-06-24 16:44 --------- d-----w C:\Documents and Settings\marco\Dati applicazioni\uTorrent
2008-06-12 21:40 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-06-08 11:33 --------- d-----w C:\Programmi\Playboy - The Mansion
2008-05-31 10:23 --------- d-----w C:\Programmi\Windows Live Toolbar
2008-05-16 19:37 --------- d--h--w C:\Programmi\FX Uninstall Information
2008-05-15 14:18 --------- d-----w C:\Documents and Settings\marco\Dati applicazioni\Ahead
2008-05-15 14:12 --------- d-----w C:\Programmi\FDRLab
2008-05-07 13:55 --------- d-----w C:\Programmi\File comuni\Ahead
2008-05-07 13:49 --------- d-----w C:\Programmi\Nero
2008-05-07 13:11 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Nero
2008-05-04 12:50 --------- d-----w C:\Programmi\Google
2008-04-29 21:48 --------- d-----w C:\Programmi\uTorrent
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 07:03 221184]
"ISUSScheduler"="C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-06-16 07:03 81920]
"D-Link AirPlus G"="C:\Programmi\D-Link\AirPlus G\AirGCFG.exe" [2007-08-03 12:29 1552384]
"ANIWZCS2Service"="C:\Programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 12:49 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15:39 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^BlueSoleil.lnk]
path=C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\BlueSoleil.lnk
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
--a------ 2004-09-30 08:44 7957504 C:\Programmi\VIAudioi\SBADeck\ADeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverUpdaterPro]
C:\Programmi\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\drvsyskit]
C:\WINDOWS\system32\drivers\hldrrr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flag Owns Live Grim]
--a------ 2008-05-03 07:55 5541888 C:\Documents and Settings\All Users\Dati applicazioni\Software rule flag owns\mp3 gpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jfrnqmi]
c:\documents and settings\marco\impostazioni locali\dati applicazioni\jfrnqmi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jugseach]
--a------ 2008-04-29 19:54 425984 C:\DOCUME~1\marco\DATIAP~1\STOPGR~1\DENT ANTI FLAP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 12:34 5724184 C:\Programmi\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mule_st_key]
C:\Documents and Settings\marco\Dati applicazioni\m\flec006.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 12:43 2097488 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 04:25 144784 C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
-ra------ 2004-10-01 10:31 53248 C:\WINDOWS\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
-ra------ 2004-06-21 20:57 143360 C:\WINDOWS\system32\VTTrayp.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\uTorrent\\uTorrent.exe"=
"C:\\Programmi\\Sitecom\\IVT BlueSoleil\\BlueSoleil.exe"=
"C:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"C:\\Programmi\\Metin2_Italiano\\metin2.bin"=
"C:\\Documents and Settings\\marco\\Desktop\\COSE NUOVE\\eMule.v0.48a.Applejuice.vn\\eMule Applejuice\\emule.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
S3 SetupNTGLM7X;SetupNTGLM7X;G:\NTGLM7X.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69a9ea06-0b9b-11dd-9847-001cf09954bb}]
\Shell\AutoRun\command - setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b51beae-fc0e-11dc-982d-001cf09954bb}]
\Shell\AutoRun\command - setupSNK.exe
.
Contenuto della cartella 'Scheduled Tasks'
"2008-06-27 22:11:07 C:\WINDOWS\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job"
- C:\Programmi\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-28 00:38:00
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\Programmi\Sitecom\IVT BlueSoleil\BTNtService.exe
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2008-06-28 0:43:19 - machine was rebooted [marco]
ComboFix-quarantined-files.txt 2008-06-27 22:43:08
7 Directory 11,171,966,976 byte disponibili
11 Directory 11,448,127,488 byte disponibili
194 --- E O F --- 2008-03-21 08:14:18