ecco il log .
l'antivirus non sono riuscita a disativarlo anzi per essere sincera non capisco neanche se ce lo abbia?
SEMBRA E DICO SEMBRA che abbiamo risolto, anzi hai risolto il problema del mio amico
GRAZIEEEEEEEEEEE
ComboFix 08-11-01.06 - Angelo 2467 2008-11-02 16.20.51.1 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1040.18.1848 [GMT 1:00]
Eseguito da: F:\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Angelo 2467\AppData\Local\hpqjs.dat
C:\Users\Angelo 2467\AppData\Local\hpqjs.exe
C:\Users\Angelo 2467\AppData\Local\hpqjs_nav.dat
C:\Users\Angelo 2467\AppData\Local\hpqjs_navps.dat
C:\Windows\dialerexe.ini
C:\Windows\system32\x64
C:\Windows\system32\x64\csnp2uvc.dll
C:\Windows\system32\x64\rsnpvc64.dll
C:\Windows\system32\x64\sncduvc.sys
C:\Windows\system32\x64\snp2uvc.sys
C:\Windows\system32\x64\vsnpvc64.dll
.
((((((((((((((((((((((((( Files Creati Da 2008-10-02 al 2008-11-02 )))))))))))))))))))))))))))))))))))
.
2008-10-28 22:44 . 2008-08-05 10:49 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-10-28 22:44 . 2008-08-05 10:49 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-10-28 22:44 . 2008-08-05 10:48 217,088 --a------ C:\Windows\System32\psisrndr.ax
2008-10-28 22:44 . 2008-08-05 10:48 177,664 --a------ C:\Windows\System32\mpg2splt.ax
2008-10-28 22:44 . 2008-08-05 10:48 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-10-28 22:42 . 2008-08-12 04:39 443,392 --a------ C:\Windows\System32\win32spl.dll
2008-10-28 22:42 . 2008-09-18 05:56 147,456 --a------ C:\Windows\System32\Faultrep.dll
2008-10-28 22:42 . 2008-09-18 05:56 125,952 --a------ C:\Windows\System32\wersvc.dll
2008-10-26 19:43 . 2008-10-26 19:43 <DIR> d-------- C:\Program Files\CCleaner
2008-10-26 19:07 . 2008-10-26 19:07 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-26 18:43 . 2008-10-26 18:43 <DIR> d-------- C:\Program Files\WOT
2008-10-26 17:20 . 2008-10-26 17:20 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-10-26 17:20 . 2007-09-04 17:56 164,352 --a------ C:\Windows\System32\unrar.dll
2008-10-26 17:20 . 2008-07-30 20:09 38 --a------ C:\Windows\avisplitter.ini
2008-10-26 17:18 . 2008-10-26 17:18 <DIR> d-------- C:\Users\Angelo 2467\AppData\Roaming\Malwarebytes
2008-10-26 17:18 . 2008-10-26 17:18 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-10-26 17:18 . 2008-10-26 17:18 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-10-26 17:18 . 2008-10-26 17:18 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-26 17:18 . 2008-10-22 16:10 38,496 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-26 17:18 . 2008-10-22 16:10 15,504 --a------ C:\Windows\System32\drivers\mbam.sys
2008-10-26 17:17 . 2008-10-26 17:17 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-10-19 19:38 . 2008-10-26 21:20 <DIR> d-------- C:\Program Files\Digisoft AntiDialer
2008-10-19 17:06 . 2008-10-26 21:24 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-10-19 17:06 . 2008-10-26 21:24 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-10-19 16:40 . 2008-10-20 19:53 <DIR> d-a------ C:\Users\All Users\TEMP
2008-10-19 16:40 . 2008-10-20 19:53 <DIR> d-a------ C:\ProgramData\TEMP
2008-10-19 16:40 . 2008-10-19 16:40 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-10-14 21:01 . 2008-10-02 02:32 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-10-14 21:01 . 2008-10-02 04:49 827,392 --a------ C:\Windows\System32\wininet.dll
2008-10-14 20:57 . 2008-09-18 03:16 2,032,640 --a------ C:\Windows\System32\win32k.sys
2008-10-14 20:53 . 2008-09-18 06:09 3,601,464 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-10-14 20:53 . 2008-09-18 06:09 3,549,240 --a------ C:\Windows\System32\ntoskrnl.exe
2008-10-14 20:50 . 2008-08-27 02:06 288,768 --a------ C:\Windows\System32\drivers\srv.sys
2008-10-12 16:14 . 2008-10-12 16:14 <DIR> d-------- C:\Users\Angelo 2467\AppData\Roaming\Lavasoft
2008-10-12 16:13 . 2008-10-12 16:13 <DIR> d-------- C:\Program Files\Lavasoft
2008-10-12 14:27 . 2008-10-12 14:27 <DIR> d-------- C:\Users\All Users\eMule
2008-10-12 14:27 . 2008-10-12 14:27 <DIR> d-------- C:\ProgramData\eMule
2008-10-12 12:22 . 2008-10-12 12:22 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-10-07 20:06 . 2008-10-07 20:06 <DIR> d-------- C:\Users\All Users\Office Genuine Advantage
2008-10-07 20:06 . 2008-10-07 20:06 <DIR> d-------- C:\ProgramData\Office Genuine Advantage
2008-10-04 21:48 . 2008-10-12 14:27 <DIR> d-------- C:\Program Files\eMule
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 15:14 --------- d-----w C:\Program Files\McAfee
2008-10-26 20:22 --------- d-----w C:\Program Files\Acer GameZone
2008-10-20 18:42 --------- d-----w C:\ProgramData\Microsoft Help
2008-10-15 12:51 --------- d-----w C:\Program Files\Windows Mail
2008-10-08 19:50 --------- d-----w C:\ProgramData\SiteAdvisor
2008-10-08 19:50 --------- d-----w C:\ProgramData\McAfee
2008-10-02 19:31 --------- d-----w C:\Program Files\Microsoft Works
2008-09-28 17:06 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-28 17:06 --------- d-----w C:\Program Files\Windows Live
2008-09-28 17:02 --------- d-----w C:\ProgramData\WLInstaller
2008-09-15 14:56 --------- d-----w C:\ProgramData\Yahoo!
2008-09-15 14:53 --------- d-----w C:\Program Files\Yahoo!
2008-09-15 13:59 --------- d-----w C:\Users\Angelo 2467\AppData\Roaming\Yahoo!
2008-09-11 19:27 --------- d-----w C:\Program Files\MSXML 4.0
2008-08-02 03:26 36,864 ----a-w C:\Windows\System32\cdd.dll
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 01:00 39472 --a------ C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 517632]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-02-29 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 525360]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-10-10 1286144]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 40048]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-05 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-05 8534560]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-05 81920]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-10-17 768520]
"PlayMovie"="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2008-01-22 200704]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-07-21 159744]
"WarReg_PopUp"="C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"RtHDVCpl"="RtHDVCpl.exe" [2007-12-05 C:\Windows\RtHDVCpl.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2008-04-15 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{51E1C875-B0C5-4683-9212-75193BE81FB0}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{4816E315-F2A5-4392-B633-FE257EFBC9AF}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B93445C-A457-418F-AE52-B10F07944ED8}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{69EF9026-E012-4ABA-A01F-9C3FDAA2F9D3}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{7996B80A-54DB-4164-B256-2A45760321ED}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{C164E460-7EDE-4F00-8D43-CBCE0DE4605A}"= C:\Program Files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{48546F2B-A5D1-460B-8F28-B922FAFC1283}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{41C6D27F-20B2-4CEC-B4BC-AB3BB40F0325}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{BB0F2513-424A-461C-9DF5-2D17BD04BE49}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{8AD35151-43C5-4B11-9C3B-883A41EB0C2A}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{6CBA6D23-243C-4258-B8C9-80E23DA0BB49}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{11C3F9DB-650C-45EE-9B23-C8E9C089CB59}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{94EAA713-53E9-4173-B7E7-F831C5E8D69D}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{C316B564-AC43-4040-A741-F4A8BB0451E3}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FD3A2B76-8079-44FD-9707-286F6DAD8728}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\
000.fcl [2008-01-04 16:15 41456]
R2 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [2007-09-19 51200]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys [2007-05-16 32256]
S3 qcusbser;Mobile Connector USB Device for Legacy Serial Communication;C:\Windows\system32\DRIVERS\cmusbser.sys [2007-10-16 97408]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\.\ShowModem.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\.\ShowModem.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2de117eb-7de5-11dd-ba5f-001b38e3e8e1}]
\shell\AutoRun\command - G:\.\ShowModem.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
2008-09-14 C:\Windows\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-04-15 C:\Windows\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORFÃOS REMOVIDOS - - - -
HKCU-Run-hpqjs - c:\users\angelo 2467\appdata\local\hpqjs.exe
HKLM-Run-eRecoveryService - (no file)
.
------- Supplementare di scansione -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.tiscali.it/
R0 -: HKLM-Main,Start Page = hxxp://it.intl.acer.yahoo.com
O18 -: Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-02 16:23:42
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-11-02 16.24.53
ComboFix-quarantined-files.txt 2008-11-02 15:24:47
Pre-Run: 99.191.083.008 byte disponibili
Post-Run: 99,161,702,400 byte disponibili
188 --- E O F --- 2008-10-29 13:32:18