ciao, ho eliminato Avast antivirus anche perchè se lo lasciavo attivo il browser SR Ware Iron non apriva più nessuna pagina, con NOD invece tutto ok.
alcune toolbar che ho visto di avere dal log di HiJackThis non le ho potute disinstallare perchè in pannello di controllo>installazione applicazioni non c'erano
rapporto di combofix
ComboFix 10-03-09.06 - Gualtiero 12/03/2010 19.29.46.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.255.7 [GMT 1:00]
Eseguito da: c:\documents and settings\Gualtiero\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
c:\windows\system32\_000212_.tmp.dll
.
((((((((((((((((((((((((( Files Creati Da 2010-02-12 al 2010-03-12 )))))))))))))))))))))))))))))))))))
.
2010-03-06 22:25 . 2010-03-06 22:25 388096 ----a-r- c:\documents and settings\Gualtiero\Dati applicazioni\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-03-06 21:58 . 2001-08-30 21:28 6912 -c--a-w- c:\windows\system32\dllcache\serscan.sys
2010-03-06 21:58 . 2001-08-30 21:28 6912 ----a-w- c:\windows\system32\drivers\serscan.sys
2010-03-06 21:58 . 2001-08-30 22:07 81408 -c--a-w- c:\windows\system32\dllcache\dc210usd.dll
2010-03-06 21:58 . 2001-08-30 22:07 81408 ----a-w- c:\windows\system32\dc210usd.dll
2010-03-06 21:58 . 2001-08-30 22:07 25600 -c--a-w- c:\windows\system32\dllcache\dc210_32.dll
2010-03-06 21:58 . 2001-08-30 22:07 25600 ----a-w- c:\windows\system32\dc210_32.dll
2010-03-03 17:53 . 2010-03-03 17:53 -------- d-----w- c:\programmi\ElcomSoft
2010-03-02 17:43 . 2010-03-02 17:43 -------- d-----w- c:\documents and settings\Gualtiero\Dati applicazioni\Malwarebytes
2010-03-02 17:43 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 17:43 . 2010-03-02 17:43 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-03-02 17:43 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-01 12:15 . 2010-03-01 12:15 -------- d-----w- c:\documents and settings\Gualtiero\Impostazioni locali\Dati applicazioni\ESET
2010-03-01 12:12 . 2010-03-01 12:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ESET
2010-02-26 12:51 . 2010-03-12 18:00 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Alwil Software
2010-02-16 21:24 . 2010-02-16 21:24 793 ---ha-w- C:\hpothb07.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
2010-03-04 18:33 . 2009-03-21 10:50 -------- d-----w- c:\documents and settings\Gualtiero\Dati applicazioni\U3
2010-02-26 18:56 . 2008-07-07 21:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2010-01-23 18:07 . 2010-01-12 16:24 -------- d-----w- c:\documents and settings\Gualtiero\Dati applicazioni\gtk-2.0
2009-12-24 17:27 . 2008-10-22 09:09 1960 ----a-w- c:\windows\system32\d3d9caps.dat
2009-01-26 19:29 . 2009-01-26 19:29 15251 ----a-w- c:\programmi\settings.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"AtiPTA"="atiptaxx.exe" [2000-04-07 151552]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.e xe" [2001-07-09 155648]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"Sony Ericsson PC Suite"="g:\programmi\Ripping\cellulari\SonyEricsso n\K320 i\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"egui"="g:\programmi\Antivirus\NOD32 ESET\NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - g:\programmi\Acrobat 7.05\Reader\reader_sl.exe [2005-9-23 29696]
hp psc 1000 series.lnk - g:\programmi\Stampante\Ewlett packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - g:\programmi\Stampante\Ewlett packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Microsoft Office.lnk - g:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"g:\\Programmi\\FotoCamere\\Fotocamera_Kodak\\Koda k EasyShare software\\bin\\EasyShare.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16/11/2009 9.03.36 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfw tdir.sys [16/11/2009 9.06.50 96408]
R2 ekrn;ESET Service;g:\programmi\Antivirus\NOD32 ESET\NOD32 Antivirus\ekrn.exe [16/11/2009 9.04.30 735960]
S3 K320bus;Sony Ericsson K320 driver (WDM);c:\windows\system32\drivers\K320bus.sys [14/01/2009 17.44.16 61504]
S3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter;c:\windows\system32\drivers\K320mdfl.sys [14/01/2009 17.44.22 9328]
S3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver;c:\windows\system32\drivers\K320mdm.sys [14/01/2009 17.44.21 97056]
S3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\K320mgmt.sys [14/01/2009 17.44.38 88560]
S3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface;c:\windows\system32\drivers\K320obex.sys [14/01/2009 17.44.34 86368]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - avast! Antivirus
.
Contenuto della cartella 'Scheduled Tasks'
2009-02-13 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B82270 47792.job
- g:\programmi\Stampante\Ewlett packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
2009-01-15 c:\windows\Tasks\Sony Ericsson PC Suite.job
- c:\documents and settings\All Users\Menu Avvio\Programmi\Accessori\Sony Ericsson\Sony Ericsson PC Suite.lnk [2009-01-14 16:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - g:\progra~1\MICROS~1\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Gualtiero\Dati applicazioni\Mozilla\Firefox\Profiles\1yj6jpuc.def ault\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - plugin: g:\programmi\Acrobat 7.05\Reader\browser\nppdf32.dll
FF - plugin: g:\programmi\browser mozilla3\plugins\npFoxitReaderPlugin.dll
FF - plugin: g:\programmi\Riproduzione video\VLC\VideoLAN\VLC\npvlc.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-DriverUpdaterPro - g:\programmi\Stampante\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-12 19:36
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
************************************************** ************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\Documents and Settings\\All Users\\Dati applicazioni\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="g:\\Programmi\\Antivirus\\NOD32 ESET\\NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{6864ABC3-A982-436B-BEF1-5652D6303361}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.0.474.0"
"UniqueId"="000FE8064B8BAF8E"
"ScannerBuild"=dword:00001a4a
"ScannerVersionId"=dword:00001344
"ScannerVersion"="Locked/open ESET for status."
"FixId"=dword:00000005
.
Ora fine scansione: 2010-03-12 19:40:07
ComboFix-quarantined-files.txt 2010-03-12 18:40
Pre-Run: 6.491.295.744 byte disponibili
Post-Run: 6.472.802.304 byte disponibili
- - End Of File - - E4926E022B7C534C1D6D870E3DC18D89

Rispondi quotando