r16 ha scritto:Ultima verifica:
Scarica Combofix (usa Internet Explorer)
http://download.bleepingcomputer.com/sUBs/ComboFix.exeSalvalo sul
desktop. (
è obligatorio)
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.
Doppio click su combofix.exe
E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix)
tu ignorali.Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca
NO.
Durante l'operazione di scansione
è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt.
Postalo qui.
ok posto il log, mi pare pulito
ComboFix 11-07-07.06 - augusto 08/07/2011 12:51:57.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.3071.2305 [GMT 2:00]
Eseguito da: c:\users\augusto\Documents\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Files Creati Da 2011-06-08 al 2011-07-08 )))))))))))))))))))))))))))))))))))
.
.
2011-07-05 11:38 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B59384E3-52A9-4FA3-8937-59C73D88D6A2}\mpengine.dll
2011-07-04 15:06 . 2011-05-24 10:44 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-07-04 15:06 . 2011-05-04 04:34 1549312 ----a-w- c:\windows\system32\tquery.dll
2011-07-04 15:06 . 2011-05-04 04:32 337408 ----a-w- c:\windows\system32\mssph.dll
2011-07-04 15:06 . 2011-05-04 04:32 1401344 ----a-w- c:\windows\system32\mssrch.dll
2011-07-04 15:06 . 2011-05-04 04:28 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-07-04 15:06 . 2011-05-04 04:28 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-07-04 15:06 . 2011-05-04 04:32 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-07-04 15:06 . 2011-05-04 04:32 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-07-04 15:06 . 2011-05-04 04:32 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-07-04 15:06 . 2011-05-04 04:28 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-26 14:34 . 2011-06-26 14:34 -------- d-----w- c:\users\augusto\AppData\Roaming\Avira
2011-06-26 14:31 . 2011-04-01 15:09 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-26 14:31 . 2011-06-26 14:31 -------- d-----w- c:\programdata\Avira
2011-06-26 14:31 . 2011-06-26 14:31 -------- d-----w- c:\program files\Avira
2011-06-09 19:55 . 2011-06-09 19:55 -------- d-----w- c:\program files\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-04 15:13 . 2011-05-13 18:51 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-29 07:11 . 2010-01-31 20:24 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 07:11 . 2010-01-31 20:24 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-24 17:14 . 2009-11-09 18:52 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-04 02:52 . 2010-04-16 18:50 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-22 19:14 . 2011-05-26 19:11 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-11-14 17:12 135664 ----atw- c:\users\augusto\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
2006-01-30 16:00 98304 ----a-r- c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe
.
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 8456]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-20 1343400]
S0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\DRIVERS\pssnap.sys [2010-09-28 15328]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
S2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2010-09-28 220128]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-07 378472]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-03-03 139368]
S3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS [2006-12-05 507136]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
.
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1573581122-2838042515-3159818513-1002Core.job
- c:\users\augusto\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-14 17:12]
.
2011-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1573581122-2838042515-3159818513-1002UA.job
- c:\users\augusto\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-14 17:12]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.ilfattoquotidiano.it/
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{7CED9F65-C75E-4322-A327-30A06AEAE0EE}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{EB1FBEF5-8917-4C16-B96E-F7F147132BCE}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\augusto\AppData\Roaming\Mozilla\Firefox\Profiles\4hhkd2eh.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.ilfattoquotidiano.it/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=2a03e115000000000000002522511089&tlver=1.4.19.19&instlRef=sst&ss=1&affID=17982&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Get Mail Plus:
getmail@webdesigns.ms11.net - %profile%\extensions\getmail@webdesigns.ms11.net
FF - Ext: Pearl Crescent Page Saver Basic: {c151d79e-e61b-4a90-a887-5a46d38fba99} - %profile%\extensions\{c151d79e-e61b-4a90-a887-5a46d38fba99}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2011-07-08 12:56:10
ComboFix-quarantined-files.txt 2011-07-08 10:56
.
Pre-Run: 29.009.096.704 byte disponibili
Post-Run: 28.907.167.744 byte disponibili
.
- - End Of File - - BA151E9DC87FBDE785D4E1CBAE8D62F1