Ho completato anche l'ultima fase con la scansione tramite COMBOFIX come mi hai detto!
Ti devo
precisare 3 cose:
- mentre lo usavo combofix mi ha detto che nn avevo punto di ripristino di emergenza e che se volevo potevo connettermi e farlo ma dato che mi hai scritto che era meglio nn connettersi ho cliccato sul no.
- ho controllato su installazione programmi e Favorit c'era di nuovo ... allora l'ho rimosso di nuovo
- mi ero dimenticato di specificarti che da quando ho questo problema di favorit ogni volta che apro Firefox la pagina iniziale è Trovarapido.com magari nn son legate le due cose pero mi sembrava giusto specificarlo.
Grazie Mille di tutto!
Aspettando buone nuove
Daniele
ORA TI POSTO IL LOG di COMBOFIXComboFix 09-08-10.04 - daniele1 11/08/2009 11.37.28.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.957.595 [GMT 2:00]
Eseguito da: c:\documents and settings\daniele1\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\daniele1\Impostazioni locali\Dati applicazioni\kwbxd.dat
c:\documents and settings\daniele1\Impostazioni locali\Dati applicazioni\kwbxd_nav.dat
c:\documents and settings\daniele1\Impostazioni locali\Dati applicazioni\kwbxd_navps.dat
c:\windows\Installer\1160b07.msi
c:\windows\system32\CmdLineExt.dll
c:\windows\system32\Drivers\btgmm.sys
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_aqhtcbg
((((((((((((((((((((((((( Files Creati Da 2009-07-11 al 2009-08-11 )))))))))))))))))))))))))))))))))))
.
2009-08-11 08:15 . 2009-08-11 08:15 -------- d-----w- c:\documents and settings\daniele1\Dati applicazioni\Malwarebytes
2009-08-11 08:15 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-11 08:15 . 2009-08-11 08:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-08-11 08:15 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-11 08:15 . 2009-08-11 08:15 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-08-10 11:48 . 2009-08-10 11:48 -------- d-----w- c:\programmi\Trend Micro
2009-08-10 08:11 . 2009-08-10 08:11 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-08-10 08:11 . 2009-08-10 08:11 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-08-10 08:00 . 2009-08-10 08:00 -------- d-----w- c:\programmi\CCleaner
2009-08-07 14:36 . 2009-08-07 14:36 -------- d-----w- C:\APPS
2009-08-07 14:02 . 2004-06-24 12:52 7552 ----a-w- c:\windows\system32\drivers\MS-5530.sys
2009-08-07 14:02 . 2002-10-30 09:21 246424 ------w- c:\windows\system32\unicows.dll
2009-08-07 14:02 . 2009-08-07 14:02 -------- d-----w- c:\programmi\Windows Media Player plug-in
2009-08-07 13:40 . 2009-08-07 13:40 -------- d-----w- c:\documents and settings\daniele1\Dati applicazioni\.clamwin
2009-08-07 13:40 . 2009-08-07 13:40 -------- d-----w- c:\programmi\ClamWin
2009-08-07 13:40 . 2009-08-07 13:40 -------- d-----w- c:\documents and settings\All Users\.clamwin
2009-08-07 07:43 . 2009-08-07 07:43 -------- d-----w- C:\HattrickOrganizer
2009-08-05 13:01 . 2009-08-05 13:01 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-05 07:12 . 2009-08-05 07:12 -------- d-----w- c:\programmi\Safari
2009-08-05 07:10 . 2009-08-05 07:11 -------- d-----w- c:\programmi\iPod
2009-08-05 07:10 . 2009-08-05 07:10 -------- d-----w- c:\programmi\iTunes
2009-08-05 07:10 . 2009-08-05 07:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-05 07:06 . 2009-07-09 10:16 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-05 07:03 . 2009-08-05 07:03 75040 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-08-05 07:03 . 2009-08-05 07:03 -------- d-----w- c:\programmi\Bonjour
2009-08-04 17:09 . 2009-08-04 17:10 -------- d-----w- c:\programmi\Incomplete
2009-07-25 11:27 . 2009-06-29 15:55 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-25 11:27 . 2009-06-29 15:55 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-10 20:29 . 2008-03-27 12:11 4212 ---h--w- c:\windows\system32\zllictbl.dat
2009-08-07 15:36 . 2009-08-07 15:39 4380672 ------w- c:\windows\Internet Logs\xDB13.tmp
2009-08-07 15:36 . 2009-08-07 15:39 2832384 ------w- c:\windows\Internet Logs\xDB12.tmp
2009-07-17 11:56 . 2008-01-11 19:10 71544 ----a-w- c:\documents and settings\daniele1\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-07-15 13:29 . 2008-05-18 22:14 21622689 ------w- c:\windows\Internet Logs\tvDebug.zip
2009-07-09 15:05 . 2009-07-10 11:51 1030656 ------w- c:\windows\Internet Logs\xDB10.tmp
2009-07-09 15:05 . 2009-07-10 11:51 4180992 ------w- c:\windows\Internet Logs\xDB11.tmp
2009-07-09 10:16 . 2008-12-09 19:16 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-07-03 12:48 . 2009-07-03 12:47 41026660 ------w- c:\windows\Internet Logs\vsmon_on_demand_2009_07_02_15_06_25_full.dmp.zip
2009-07-02 13:31 . 2009-07-03 12:42 4155904 ------w- c:\windows\Internet Logs\xDBF.tmp
2009-06-29 15:55 . 2004-08-19 03:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:55 . 2004-08-19 03:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-22 09:46 . 2008-01-11 21:54 4990 ----a-w- c:\windows\Help\hhcolreg.dat
2009-06-19 14:07 . 2009-06-19 14:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-06-17 10:49 . 2009-06-17 12:15 2819072 ------w- c:\windows\Internet Logs\xDBE.tmp
2009-06-16 14:36 . 2004-08-19 03:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-19 03:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 07:48 . 2009-01-16 11:51 1878984 ----a-w- c:\documents and settings\daniele1\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-06-04 14:43 . 2009-06-04 14:51 4060160 ------w- c:\windows\Internet Logs\xDBD.tmp
2009-06-03 19:09 . 2004-08-19 03:00 1296384 ----a-w- c:\windows\system32\quartz.dll
2009-05-31 07:46 . 2009-05-31 07:50 4051456 ------w- c:\windows\Internet Logs\xDBC.tmp
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-08-03 202024]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"AlcoholAutomount"="c:\programmi\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-22 203720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"LManager"="c:\programmi\Launch Manager\QtZgAcer.EXE" [2005-03-28 315392]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 393216]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-08-30 286720]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 1828136]
"Google IME Autoupdater"="c:\programmi\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"ClamWin"="c:\programmi\ClamWin\bin\ClamTray.exe" [2009-06-11 86016]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-02-25 49152]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-02-23 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Reader Speed Launch.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\TVAnts\\Tvants.exe"=
"c:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\WINDOWS\\System32\\ZoneLabs\\vsmon.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
R3 HSFHWSIS;HSFHWSIS;c:\windows\system32\drivers\HSFHWSIS.sys [15/12/2004 0.18.34 200576]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;c:\windows\system32\drivers\bsusbser.sys [01/07/2008 15.47.48 94848]
S3 PortlUSB;PortlUSB;c:\windows\system32\drivers\MS-5530.sys [07/08/2009 16.02.41 7552]
.
Contenuto della cartella 'Scheduled Tasks'
2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\programmi\Uniblue\RegistryBooster\RegistryBooster.exe
HKLM-Run-PWRISOVM.EXE - c:\programmi\PowerISO\PWRISOVM.EXE
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.trovarapido.com/?t=Q0908051339&s=h
uInternet Settings,ProxyOverride = *.local
IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://livekuva.suomi.net/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\daniele1\Dati applicazioni\Mozilla\Firefox\Profiles\8uyngqhb.default\
FF - prefs.js: browser.search.selectedEngine - Trova Rapido
FF - prefs.js: browser.startup.homepage - hxxp://www.trovarapido.com/?t=Q0908051339&s=h
FF - prefs.js: keyword.URL - hxxp://www.ffsearch.net/s/?ref=adr&q=
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\documents and settings\daniele1\Dati applicazioni\Mozilla\Firefox\Profiles\8uyngqhb.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\programmi\Veetle\plugins\npVeetle.dll
FF - plugin: c:\programmi\Veetle\VLC\npvlc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-11 11:47
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1867568145-1672018170-801050997-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ff,b7,d8,a8,85,4e,79,42,9e,a7,d7,ad,65,15,13,b2,e6,47,cb,4f,69,a6,67,
94,42,c7,ba,60,9c,c1,82,a5,f7,c5,26,e0,85,b3,93,ac,e5,9b,b5,bd,cf,fa,9e,49,\
"??"=hex:3c,8d,8e,1e,60,b2,a5,84,75,e8,e8,4d,a3,02,ec,8d
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(240)
c:\windows\system32\WININET.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\AVIRA\ANTIVIR DESKTOP\SCHED.EXE
c:\acer\EMANAGER\ANBMSERV.EXE
c:\programmi\AVIRA\ANTIVIR DESKTOP\AVGUARD.EXE
c:\programmi\FILE COMUNI\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\programmi\BONJOUR\MDNSRESPONDER.EXE
c:\programmi\NERO\NERO8\NERO BACKITUP\NBSERVICE.EXE
c:\programmi\ALCOHOL SOFT\ALCOHOL 120\STARWIND\STARWINDSERVICEAE.EXE
c:\windows\SYSTEM32\ZONELABS\VSMON.EXE
c:\programmi\File comuni\Nero\Lib\NMIndexingService.exe
c:\programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
c:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2009-08-11 11.51.04 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-08-11 09:51
Pre-Run: 15.858.761.728 byte disponibili
Post-Run: 15.777.857.536 byte disponibili
202 --- E O F --- 2009-08-10 07:25