Saluti a tutti.
Utilizzando maldestramente U Torrent mi sono beccato questo maledetto virus.
Resomene conto ho utilizzato (previo aggiornamento) Malware byte con questo risultato
Ho pulito il registro con Ccleaner.
Usando i miei browser (Explorer, Firefox, Chrome) mi si apriva sempre una pagina indesiderata.
Preso da urgenza, unita a rabbia, ho cominciato a cercare in rete delle soluzioni che penso mi abbiano ulteriormente incasinato. Ed ora, come avrei dovuto fare subito, mi rivolgo ad Aiutamici che, invece, mi ha sempre aiutato saggiamente.
Ecco cosa ho fatto:
- ho eliminato con Installazioni Applicazioni/Cambia rimuovi programmi:
esafe security control che, a detta dei suggerimenti, sembrava essere il responsabile dell'infezione. Avrei dovuto però (sempre secondo il suggeritore) eliminare anche
Desk 365.
Ma quest'ultimo non compare in Applicazioni/Cambia rimuovi programmi, mentre risulta nelle cartelle dei programmi.
Ho provato a
disinstallare Desk 365 con Revo Unstaller, ma non ci sono riuscito perché anche lì non compare.
A questo punto non mi resta altro che allegare il log di HiJackThis e chiedere, cortesemente,che qualche esperto mi aiuti.
Chi lo farà dovrà avere molta pazienza perché (come si è capito) in informatica sono un vero "somaro".
Infatti leggendo le istruzioni di HiJackThis su Aiutamici ho visto come si passa a modalità provvisoria e subito mi sono reso conto che non saprei
come fare a tornare alla modalità normale.Insomma, dovrete guidarmi passo a passo tenendomi per mano come un bambino ignorante.
Ecco il log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16.16.32, on 02/06/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\AVAST Software\Avast\avastUI.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Freemake\CaptureLib\CaptureLibService.exe
C:\Programmi\Java\jre7\bin\jqs.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Programmi\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Google\Chrome\Application\chrome.exe
C:\Programmi\Google\Chrome\Application\chrome.exe
C:\Programmi\Google\Chrome\Application\chrome.exe
C:\Programmi\Google\Chrome\Application\chrome.exe
C:\Programmi\Google\Chrome\Application\chrome.exe
C:\Programmi\Google\Chrome\Application\chrome.exe
C:\Programmi\FastStone Capture\FSCapture.exe
C:\Documents and Settings\Sandro\Desktop\PortableApps\ImageShackUploaderPortable\ImageShackUploaderPortable.exe
C:\Documents and Settings\Sandro\Desktop\PortableApps\ImageShackUploaderPortable\App\ImageShackUploader\ImageShackUploader.exe
C:\Programmi\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=ST500DM002-1BD142_W2AH4XAQXXXXW2AH4XAQ&ts=1370117601R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=IT&userid=214459d6-b33f-40a8-8fb7-116d334277f5&searchtype=ds&q={searchTerms}&installDate=01/01/1970
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=IT&userid=214459d6-b33f-40a8-8fb7-116d334277f5&searchtype=ds&q={searchTerms}&installDate=01/01/1970
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=ST500DM002-1BD142_W2AH4XAQXXXXW2AH4XAQ&ts=1370117601R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=ST500DM002-1BD142_W2AH4XAQXXXXW2AH4XAQ&ts=1370117601R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=IT&userid=214459d6-b33f-40a8-8fb7-116d334277f5&searchtype=ds&q={searchTerms}&installDate=01/01/1970
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=IT&userid=214459d6-b33f-40a8-8fb7-116d334277f5&searchtype=ds&q={searchTerms}&installDate=01/01/1970
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=ST500DM002-1BD142_W2AH4XAQXXXXW2AH4XAQ&ts=0R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=ST500DM002-1BD142_W2AH4XAQXXXXW2AH4XAQ&ts=0R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Programmi\Outlook Express\msimn.exe" //mailurl:mailto:?subject=You've%20got%20to%20see%20this&body=http://www.metacafe.com/channels/nhsandro/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmi\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmi\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
O4 - HKLM\..\Run: [avast] "C:\Programmi\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Programmi\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1350749627984O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1360075152199O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Programmi\AVAST Software\Avast\AvastSvc.exe
O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Programmi\Freemake\CaptureLib\CaptureLibService.exe
O23 - Service: Servizio Google Update (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programmi\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programmi\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NMSAccess - Unknown owner - C:\Programmi\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Programmi\TomTom HOME 2\TomTomHOMEService.exe
--
End of file - 8495 bytes
Ringrazio anticipatamente e di cuore chi mi vorrà aiutare.