![Approvazione [^]](http://www.megalab.it/forum/images/smilies/Oh-yea.gif)
Il mio problemaa è il seguente, non riesco a installare gli antivirus e nemmeno a rimuovere i virus presenti.
Ho cercato di seguire la guida PC infetto da virus e altro malware? Vediamo come intervenire
Purtroppo non sono riuscito a fare correttamente il "Terzo Step: Scansione con AntiVir" in quanto sia avira che altri antivirus non si installano nemmeno in modalità provvisoria e purtroppo non ho il masterizzatore con cui creare il cd
Quello che son riuscito ad eseguire dopo vari tentativi è:
- ccleaner
- Microsoft Safety Scanner (scansione completa ed eliminazione)
- malwarebytes
- combofix
- HijackThis
ho ritentato poi di installare avira o avg ma nessuno dei due si è installato, l'installazione "scompare" dopo aver iniziato
ora non riesco più a usare nemmeno Microsoft Safety Scanner, inizia ma poi anche lui "scompare"
inoltre all'avvio (normale) mi appaiono i seguenti messaggi:
- WMIServi application ha smesso di funzionare
- windows defender impossibile inizializzare l'applicazione 0x800106ba
HijackThis
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8.22.44, on 07/03/2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Safe mode with network support
Running processes:
C:\Windows\Explorer.EXE
C:\park\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.intl.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://it.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - .DEFAULT User Startup: ovfe.exe (User 'Default user')
O4 - .DEFAULT User Startup: yfokko.exe (User 'Default user')
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 4236 bytes
Scan saved at 8.22.44, on 07/03/2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Safe mode with network support
Running processes:
C:\Windows\Explorer.EXE
C:\park\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.intl.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://it.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - .DEFAULT User Startup: ovfe.exe (User 'Default user')
O4 - .DEFAULT User Startup: yfokko.exe (User 'Default user')
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 4236 bytes
ComboFix
ComboFix 14-03-05.01 - adriano 07/03/2014 7.52.37.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.1790.1342 [GMT 1:00]
Eseguito da: c:\park\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\DFRB455.tmp
c:\drv\TVtuner\Liteon\Resources\_desktop.ini
c:\programdata\fefcffde31.nls
c:\users\adriano\AppData\Local\ServicePack
c:\users\adriano\AppData\Roaming\Nakod
c:\users\adriano\AppData\Roaming\Nakod\erkum.tmp
c:\users\adriano\AppData\Roaming\Sidu
c:\users\adriano\AppData\Roaming\Sidu\avson.elu
c:\windows\security\Database\tmp.edb
c:\windows\system32\spsys.log
c:\windows\system64
c:\windows\system64\msvcp100.dll
c:\windows\system64\msvcr100.dll
.
c:\windows\system32\spoolsv.exe . . . è infetto!!
.
c:\windows\bfsvc.exe . . . è infetto!!
.
c:\windows\fveupdate.exe . . . è infetto!!
.
c:\windows\HelpPane.exe . . . è infetto!!
.
c:\windows\hh.exe . . . è infetto!!
.
c:\windows\notepad.exe . . . è infetto!!
.
c:\windows\regedit.exe . . . è infetto!!
.
La copia infetta di c:\windows\DigitalLocker\digitalx.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-digitallocker_31bf3856ad364e35_6.0.6000.16386_none_029b1eaf2d7e8f60\digitalx.exe
.
La copia infetta di c:\windows\ehome\ehmsas.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehmsas_31bf3856ad364e35_6.0.6000.16386_none_28dc127d6ff3c7fa\ehmsas.exe
.
La copia infetta di c:\windows\ehome\ehprivjob.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehprivjob_31bf3856ad364e35_6.0.6000.16386_none_f2dc6ebc34e04866\ehprivjob.exe
.
La copia infetta di c:\windows\ehome\ehrec.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehrec_31bf3856ad364e35_6.0.6000.16386_none_48bccf19581cd2d8\ehrec.exe
.
La copia infetta di c:\windows\ehome\ehrecvr.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-services-ehrecvr_31bf3856ad364e35_6.0.6000.16386_none_bb32bc0824b34955\ehrecvr.exe
.
c:\windows\ehome\ehsched.exe . . . è infetto!!
.
c:\windows\ehome\ehshell.exe . . . è infetto!!
.
La copia infetta di c:\windows\ehome\ehtray.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehtray_31bf3856ad364e35_6.0.6000.16386_none_28a24bc3701e0760\ehtray.exe
.
La copia infetta di c:\windows\ehome\ehvid.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22670_none_4ba6b5206e120937\ehvid.exe
.
La copia infetta di c:\windows\ehome\McrMgr.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22670_none_3467df3ef350874f\McrMgr.exe
.
c:\windows\ehome\mcspad.exe . . . è infetto!!
.
La copia infetta di c:\windows\ehome\mcupdate.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\3bd8fe73c6fda64a95e9e60ac46184d4\x86_mcupdate_31bf3856ad364e35_6.0.6002.18005_none_ca884acba8f029e4\mcupdate.exe
.
La copia infetta di c:\windows\ehome\Mcx2Prov.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\3bd8fe73c6fda64a95e9e60ac46184d4\x86_microsoft-windows-ehome-devices-mcx2prov_31bf3856ad364e35_6.0.6002.18005_none_da78aae016329fa4\Mcx2Prov.exe
.
La copia infetta di c:\windows\ehome\CreateDisc\SBEServer.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-sonic-sbeserver_31bf3856ad364e35_6.0.6002.18005_none_1efd804d565c1928\SBEServer.exe
.
c:\windows\Help\Tablet PC\PenTraining.exe . . . è infetto!!
.
c:\windows\Help\Tablet PC\TouchTraining.exe . . . è infetto!!
.
La copia infetta di c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-netfxsbs10_exe_31bf3856ad364e35_6.0.6002.18005_none_3d7a6880ab163624\NETFXSBS10.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-applaunch_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_c512442c6b4566d7\AppLaunch.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-aspnet_regiis_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_120341a3224c03b8\aspnet_regiis.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-aspnet_state_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_80f871a1c32de056\aspnet_state.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_netfx-aspnet_wp_exe_b03f5f7f11d50a3a_6.0.6001.22477_none_ae219242a5eb019d\aspnet_wp.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-csharp_compiler_csc_b03f5f7f11d50a3a_6.0.6002.18005_none_fe5428b22d6c0e79\csc.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-cvtres_for_vc_and_vb_b03f5f7f11d50a3a_6.0.6002.18005_none_e59ba05e346044a2\cvtres.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-dw_b03f5f7f11d50a3a_6.0.6002.18005_none_cd77f4151b8ac157\dw20.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-clr_ilasm_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_02ebab318e2004bf\ilasm.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_1fd1ab49e8ca6ebb\mscorsvw.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-ngen_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_779867b84af56065\ngen.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-vb_compiler_b03f5f7f11d50a3a_6.0.6002.18005_none_3fca9527a692e5a2\vbc.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\3bd8fe73c6fda64a95e9e60ac46184d4\x86_infocard_b77a5c561934e089_6.0.6002.18005_none_cb66ec8b18dd702e\infocard.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMConfigInstaller.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_wcf-m_sm_cfg_ins_exe_31bf3856ad364e35_6.0.6002.18005_none_020cd51c1a47b5b7\SMConfigInstaller.exe
.
La copia infetta di c:\windows\MSAgent\AgentSvr.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-agentsvr_31bf3856ad364e35_6.0.6000.16386_none_31188d362f02982e\AgentSvr.exe
.
La copia infetta di c:\windows\System32\alg.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-alg_31bf3856ad364e35_6.0.6000.16386_none_a6b290245e337868\alg.exe
.
La copia infetta di c:\windows\System32\dfsr.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\3bd8fe73c6fda64a95e9e60ac46184d4\x86_microsoft-windows-dfsr-core-clientonly_31bf3856ad364e35_6.0.6002.18005_none_b86505b69725e0c7\dfsr.exe
.
c:\windows\System32\dllhost.exe . . . è infetto!!
.
c:\windows\System32\Locator.exe . . . è infetto!!
.
La copia infetta di c:\windows\System32\msdtc.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-com-dtc-runtime_31bf3856ad364e35_6.0.6000.16386_none_171c40e96317eaae\msdtc.exe
.
La copia infetta di c:\windows\System32\SearchIndexer.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_windowssearchengine_31bf3856ad364e35_7.0.6002.18005_none_3d746908b76294a3\SearchIndexer.exe
.
La copia infetta di c:\windows\System32\SLsvc.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-security-licensing-slc_31bf3856ad364e35_6.0.6002.18005_none_5062f685f6a7c614\SLsvc.exe
.
c:\windows\System32\snmptrap.exe . . . è infetto!!
.
La copia infetta di c:\windows\System32\UI0Detect.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-session0viewer_31bf3856ad364e35_6.0.6000.16386_none_dfb0260649c2ed9e\UI0Detect.exe
.
La copia infetta di c:\windows\System32\vds.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-virtualdiskservice_31bf3856ad364e35_6.0.6002.18005_none_6cd64babf7d06785\vds.exe
.
La copia infetta di c:\windows\System32\VSSVC.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-vssservice_31bf3856ad364e35_6.0.6002.18005_none_5cb8478314f93f13\VSSVC.exe
.
La copia infetta di c:\windows\System32\wbem\WmiApSrv.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-wmi-core_31bf3856ad364e35_6.0.6002.18005_none_bb3f7c211cba6b3f\WmiApSrv.exe
.
.
((((((((((((((((((((((((( Files Creati Da 2014-02-07 al 2014-03-07 )))))))))))))))))))))))))))))))))))
.
.
2014-03-07 07:08 . 2014-03-07 07:09 -------- d-----w- c:\users\adriano\AppData\Local\temp
2014-03-07 07:08 . 2014-03-07 07:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-06 16:20 . 2014-03-06 16:20 -------- d-----w- c:\users\adriano\AppData\Roaming\Malwarebytes
2014-03-06 16:20 . 2014-03-06 16:20 -------- d-----w- c:\programdata\Malwarebytes
2014-03-06 16:20 . 2014-03-06 21:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-03-06 16:20 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-06 15:58 . 2014-03-07 06:23 -------- d-----w- c:\program files\CCleaner
2014-03-06 14:18 . 2014-03-06 16:26 -------- d-----w- c:\users\adriano\AppData\Roaming\Leugip
2014-03-06 13:43 . 2014-03-06 13:57 912384 ----atw- c:\users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\ovfe.exe
2014-03-06 12:05 . 2014-03-06 16:26 -------- d-----w- c:\users\adriano\AppData\Roaming\Omygxe
2014-03-06 11:55 . 2014-03-06 11:55 -------- d-----w- c:\windows\system32\ca-ES
2014-03-06 11:55 . 2014-03-06 11:55 -------- d-----w- c:\windows\system32\eu-ES
2014-03-06 11:55 . 2014-03-06 11:55 -------- d-----w- c:\windows\system32\vi-VN
2014-03-06 11:51 . 2014-03-06 11:51 -------- d-----w- c:\windows\system32\SPReview
2014-03-06 11:35 . 2009-04-10 22:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2014-03-06 11:35 . 2009-04-10 22:27 57856 ----a-w- c:\windows\system32\compcln.exe
2014-03-06 11:28 . 2009-04-10 22:32 141288 ----a-w- c:\windows\system32\drivers\ecache.sys
2014-03-06 11:27 . 2014-03-06 13:39 678912 ----atw- c:\program files\Internet Explorer\iedw.exe
2014-03-06 11:26 . 2009-04-10 22:28 558080 ----a-w- c:\windows\system32\sysmain.dll
2014-03-06 11:22 . 2014-03-06 11:22 -------- d-----w- c:\windows\system32\EventProviders
2014-03-06 11:22 . 2014-03-06 11:51 -------- d-----w- C:\8e580ee915bcadb062e86915e94fc5
2014-03-06 11:10 . 2014-03-06 14:46 204288 ----atw- c:\windows\RegBootClean.exe
2014-03-06 11:02 . 2014-03-06 13:57 912384 ----atw- c:\users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\yfokko.exe
2014-03-06 10:19 . 2014-03-06 10:19 -------- d-----w- c:\users\adriano\AppData\Local\PowerCinema
2014-03-06 10:13 . 2014-03-06 16:02 -------- d-----w- c:\programdata\MFAData
2014-03-06 10:13 . 2014-03-06 10:13 -------- d--h--w- c:\programdata\Common Files
2014-03-06 10:13 . 2014-03-06 10:13 -------- d-----w- c:\users\adriano\AppData\Local\MFAData
2014-03-06 10:13 . 2014-03-06 10:13 -------- d-----w- c:\users\adriano\AppData\Local\Avg2014
2014-03-05 15:49 . 2014-03-05 15:49 -------- d-----w- c:\programdata\Lavasoft
2014-03-05 15:31 . 2014-03-05 15:31 -------- d-----w- c:\windows\system32\MRT
2014-03-05 14:49 . 2014-03-05 14:49 -------- d-----w- c:\users\adriano\AppData\Local\Macromedia
2014-03-05 14:48 . 2014-03-05 14:48 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-05 14:48 . 2014-03-05 14:48 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-05 14:43 . 2014-03-07 06:21 -------- d-----w- c:\program files\Mozilla Thunderbird
2014-03-05 14:43 . 2014-03-06 13:44 603648 ----atw- c:\program files\Mozilla Firefox\plugin-container.exe
2014-03-04 16:41 . 2014-02-06 07:08 7947048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F8F25FC1-D46B-4168-9865-C446B050F3F6}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-07 07:10 . 2014-03-07 07:10 653312 ----atw- c:\windows\system32\aqfjkhnk.tmp
2014-03-07 05:24 . 2007-07-28 00:58 909312 ----atw- c:\windows\HideWin.exe
2014-03-06 16:18 . 2007-07-28 09:30 979456 ----atw- c:\windows\system32\drivers\XAudio.exe
2014-03-06 16:18 . 2010-09-17 14:49 719872 ----atw- c:\windows\system32\spoolsv.exe
2014-03-06 16:18 . 2008-12-03 19:12 790528 ----atw- c:\windows\system32\nvvsvc.exe
2014-03-06 14:46 . 2007-07-28 00:59 1826816 ----atw- c:\windows\SkyTel.exe
2014-03-06 14:46 . 2007-07-28 00:59 1191936 ----atw- c:\windows\RtlUpd.exe
2014-03-06 14:09 . 2008-06-20 06:50 728064 -----tw- c:\windows\regedit.exe
2014-03-06 14:09 . 2008-06-20 06:50 745472 ----atw- c:\windows\notepad.exe
2014-03-06 14:05 . 2008-06-20 06:51 1091072 ----atw- c:\windows\HelpPane.exe
2014-03-06 14:05 . 2006-11-02 09:11 608256 ----atw- c:\windows\hh.exe
2014-03-06 14:05 . 2006-11-02 12:35 825344 ----atw- c:\windows\help\Tablet PC\PenTraining.exe
2014-03-06 14:05 . 2006-11-02 12:35 752640 ----atw- c:\windows\help\Tablet PC\TouchTraining.exe
2014-03-06 14:05 . 2008-06-20 06:49 606208 ----atw- c:\windows\fveupdate.exe
2014-03-06 14:04 . 2008-06-20 06:53 653312 ----atw- c:\windows\bfsvc.exe
2014-03-05 14:28 . 2006-11-02 08:58 605696 ----atw- c:\windows\system32\snmptrap.exe
2014-03-05 14:28 . 2006-11-02 08:50 601088 ----atw- c:\windows\system32\Locator.exe
2013-12-18 05:13 . 2009-10-05 08:55 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2014-03-06 1825280]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-18 4468736]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"eAudio"="c:\acer\Empowering Technology\eAudio\eAudio.exe" [2014-03-06 1880064]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2014-03-06 1339392]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2014-03-06 753664]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-03 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-03 92704]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-03-06 1546752]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ovfe.exe [2014-3-6 912384]
yfokko.exe [2014-3-6 912384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 0 (0x0)
"HideSCAHealth"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
.
Contenuto della cartella 'Scheduled Tasks'
.
2014-03-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-05 15:37]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://it.intl.acer.yahoo.com
uSearchURL,(Default) = hxxp://it.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\adriano\AppData\Roaming\Mozilla\Firefox\Profiles\xqijfx91.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: security.warn_entering_secure - false
FF - user.js: security.warn_entering_weak - false
FF - user.js: security.warn_leaving_secure - false
FF - user.js: browser.startup.homepage - about:blank
FF - user.js: browser.startup.page - 1
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKLM-Run-eRecoveryService - (no file)
SafeBoot-Wdf01000.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-07 08:12
Windows 6.0.6002 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'Explorer.exe'(1628)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\conime.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\acer\ALaunch\ALaunchSvc.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\windows\RtHDVCpl.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\program files\Launch Manager\LManager.exe
c:\windows\System32\rundll32.exe
c:\program files\Apoint2K\ApMsgFwd.exe
c:\program files\Apoint2K\Apntex.exe
c:\windows\ehome\ehmsas.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\windows\system32\UI0Detect.exe
c:\windows\System32\vds.exe
c:\windows\system32\wbem\WmiApSrv.exe
c:\windows\system32\wermgr.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\vssvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Ora fine scansione: 2014-03-07 08:17:52 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2014-03-07 07:17
.
Pre-Run: 43.261.485.056 byte disponibili
Post-Run: 41.594.388.480 byte disponibili
.
- - End Of File - - 4575F1C02ADAD30F46A4B9CB0EA21D18
A863475757CC50891AA8458C415E4B25
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.1790.1342 [GMT 1:00]
Eseguito da: c:\park\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\DFRB455.tmp
c:\drv\TVtuner\Liteon\Resources\_desktop.ini
c:\programdata\fefcffde31.nls
c:\users\adriano\AppData\Local\ServicePack
c:\users\adriano\AppData\Roaming\Nakod
c:\users\adriano\AppData\Roaming\Nakod\erkum.tmp
c:\users\adriano\AppData\Roaming\Sidu
c:\users\adriano\AppData\Roaming\Sidu\avson.elu
c:\windows\security\Database\tmp.edb
c:\windows\system32\spsys.log
c:\windows\system64
c:\windows\system64\msvcp100.dll
c:\windows\system64\msvcr100.dll
.
c:\windows\system32\spoolsv.exe . . . è infetto!!
.
c:\windows\bfsvc.exe . . . è infetto!!
.
c:\windows\fveupdate.exe . . . è infetto!!
.
c:\windows\HelpPane.exe . . . è infetto!!
.
c:\windows\hh.exe . . . è infetto!!
.
c:\windows\notepad.exe . . . è infetto!!
.
c:\windows\regedit.exe . . . è infetto!!
.
La copia infetta di c:\windows\DigitalLocker\digitalx.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-digitallocker_31bf3856ad364e35_6.0.6000.16386_none_029b1eaf2d7e8f60\digitalx.exe
.
La copia infetta di c:\windows\ehome\ehmsas.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehmsas_31bf3856ad364e35_6.0.6000.16386_none_28dc127d6ff3c7fa\ehmsas.exe
.
La copia infetta di c:\windows\ehome\ehprivjob.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehprivjob_31bf3856ad364e35_6.0.6000.16386_none_f2dc6ebc34e04866\ehprivjob.exe
.
La copia infetta di c:\windows\ehome\ehrec.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehrec_31bf3856ad364e35_6.0.6000.16386_none_48bccf19581cd2d8\ehrec.exe
.
La copia infetta di c:\windows\ehome\ehrecvr.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-services-ehrecvr_31bf3856ad364e35_6.0.6000.16386_none_bb32bc0824b34955\ehrecvr.exe
.
c:\windows\ehome\ehsched.exe . . . è infetto!!
.
c:\windows\ehome\ehshell.exe . . . è infetto!!
.
La copia infetta di c:\windows\ehome\ehtray.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehtray_31bf3856ad364e35_6.0.6000.16386_none_28a24bc3701e0760\ehtray.exe
.
La copia infetta di c:\windows\ehome\ehvid.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22670_none_4ba6b5206e120937\ehvid.exe
.
La copia infetta di c:\windows\ehome\McrMgr.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22670_none_3467df3ef350874f\McrMgr.exe
.
c:\windows\ehome\mcspad.exe . . . è infetto!!
.
La copia infetta di c:\windows\ehome\mcupdate.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\3bd8fe73c6fda64a95e9e60ac46184d4\x86_mcupdate_31bf3856ad364e35_6.0.6002.18005_none_ca884acba8f029e4\mcupdate.exe
.
La copia infetta di c:\windows\ehome\Mcx2Prov.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\3bd8fe73c6fda64a95e9e60ac46184d4\x86_microsoft-windows-ehome-devices-mcx2prov_31bf3856ad364e35_6.0.6002.18005_none_da78aae016329fa4\Mcx2Prov.exe
.
La copia infetta di c:\windows\ehome\CreateDisc\SBEServer.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-sonic-sbeserver_31bf3856ad364e35_6.0.6002.18005_none_1efd804d565c1928\SBEServer.exe
.
c:\windows\Help\Tablet PC\PenTraining.exe . . . è infetto!!
.
c:\windows\Help\Tablet PC\TouchTraining.exe . . . è infetto!!
.
La copia infetta di c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-netfxsbs10_exe_31bf3856ad364e35_6.0.6002.18005_none_3d7a6880ab163624\NETFXSBS10.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-applaunch_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_c512442c6b4566d7\AppLaunch.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-aspnet_regiis_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_120341a3224c03b8\aspnet_regiis.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-aspnet_state_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_80f871a1c32de056\aspnet_state.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_netfx-aspnet_wp_exe_b03f5f7f11d50a3a_6.0.6001.22477_none_ae219242a5eb019d\aspnet_wp.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-csharp_compiler_csc_b03f5f7f11d50a3a_6.0.6002.18005_none_fe5428b22d6c0e79\csc.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-cvtres_for_vc_and_vb_b03f5f7f11d50a3a_6.0.6002.18005_none_e59ba05e346044a2\cvtres.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-dw_b03f5f7f11d50a3a_6.0.6002.18005_none_cd77f4151b8ac157\dw20.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-clr_ilasm_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_02ebab318e2004bf\ilasm.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_1fd1ab49e8ca6ebb\mscorsvw.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-ngen_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_779867b84af56065\ngen.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_netfx-vb_compiler_b03f5f7f11d50a3a_6.0.6002.18005_none_3fca9527a692e5a2\vbc.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\3bd8fe73c6fda64a95e9e60ac46184d4\x86_infocard_b77a5c561934e089_6.0.6002.18005_none_cb66ec8b18dd702e\infocard.exe
.
La copia infetta di c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMConfigInstaller.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_wcf-m_sm_cfg_ins_exe_31bf3856ad364e35_6.0.6002.18005_none_020cd51c1a47b5b7\SMConfigInstaller.exe
.
La copia infetta di c:\windows\MSAgent\AgentSvr.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-agentsvr_31bf3856ad364e35_6.0.6000.16386_none_31188d362f02982e\AgentSvr.exe
.
La copia infetta di c:\windows\System32\alg.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-alg_31bf3856ad364e35_6.0.6000.16386_none_a6b290245e337868\alg.exe
.
La copia infetta di c:\windows\System32\dfsr.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\3bd8fe73c6fda64a95e9e60ac46184d4\x86_microsoft-windows-dfsr-core-clientonly_31bf3856ad364e35_6.0.6002.18005_none_b86505b69725e0c7\dfsr.exe
.
c:\windows\System32\dllhost.exe . . . è infetto!!
.
c:\windows\System32\Locator.exe . . . è infetto!!
.
La copia infetta di c:\windows\System32\msdtc.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-com-dtc-runtime_31bf3856ad364e35_6.0.6000.16386_none_171c40e96317eaae\msdtc.exe
.
La copia infetta di c:\windows\System32\SearchIndexer.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_windowssearchengine_31bf3856ad364e35_7.0.6002.18005_none_3d746908b76294a3\SearchIndexer.exe
.
La copia infetta di c:\windows\System32\SLsvc.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-security-licensing-slc_31bf3856ad364e35_6.0.6002.18005_none_5062f685f6a7c614\SLsvc.exe
.
c:\windows\System32\snmptrap.exe . . . è infetto!!
.
La copia infetta di c:\windows\System32\UI0Detect.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-session0viewer_31bf3856ad364e35_6.0.6000.16386_none_dfb0260649c2ed9e\UI0Detect.exe
.
La copia infetta di c:\windows\System32\vds.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-virtualdiskservice_31bf3856ad364e35_6.0.6002.18005_none_6cd64babf7d06785\vds.exe
.
La copia infetta di c:\windows\System32\VSSVC.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-vssservice_31bf3856ad364e35_6.0.6002.18005_none_5cb8478314f93f13\VSSVC.exe
.
La copia infetta di c:\windows\System32\wbem\WmiApSrv.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-wmi-core_31bf3856ad364e35_6.0.6002.18005_none_bb3f7c211cba6b3f\WmiApSrv.exe
.
.
((((((((((((((((((((((((( Files Creati Da 2014-02-07 al 2014-03-07 )))))))))))))))))))))))))))))))))))
.
.
2014-03-07 07:08 . 2014-03-07 07:09 -------- d-----w- c:\users\adriano\AppData\Local\temp
2014-03-07 07:08 . 2014-03-07 07:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-06 16:20 . 2014-03-06 16:20 -------- d-----w- c:\users\adriano\AppData\Roaming\Malwarebytes
2014-03-06 16:20 . 2014-03-06 16:20 -------- d-----w- c:\programdata\Malwarebytes
2014-03-06 16:20 . 2014-03-06 21:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-03-06 16:20 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-06 15:58 . 2014-03-07 06:23 -------- d-----w- c:\program files\CCleaner
2014-03-06 14:18 . 2014-03-06 16:26 -------- d-----w- c:\users\adriano\AppData\Roaming\Leugip
2014-03-06 13:43 . 2014-03-06 13:57 912384 ----atw- c:\users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\ovfe.exe
2014-03-06 12:05 . 2014-03-06 16:26 -------- d-----w- c:\users\adriano\AppData\Roaming\Omygxe
2014-03-06 11:55 . 2014-03-06 11:55 -------- d-----w- c:\windows\system32\ca-ES
2014-03-06 11:55 . 2014-03-06 11:55 -------- d-----w- c:\windows\system32\eu-ES
2014-03-06 11:55 . 2014-03-06 11:55 -------- d-----w- c:\windows\system32\vi-VN
2014-03-06 11:51 . 2014-03-06 11:51 -------- d-----w- c:\windows\system32\SPReview
2014-03-06 11:35 . 2009-04-10 22:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2014-03-06 11:35 . 2009-04-10 22:27 57856 ----a-w- c:\windows\system32\compcln.exe
2014-03-06 11:28 . 2009-04-10 22:32 141288 ----a-w- c:\windows\system32\drivers\ecache.sys
2014-03-06 11:27 . 2014-03-06 13:39 678912 ----atw- c:\program files\Internet Explorer\iedw.exe
2014-03-06 11:26 . 2009-04-10 22:28 558080 ----a-w- c:\windows\system32\sysmain.dll
2014-03-06 11:22 . 2014-03-06 11:22 -------- d-----w- c:\windows\system32\EventProviders
2014-03-06 11:22 . 2014-03-06 11:51 -------- d-----w- C:\8e580ee915bcadb062e86915e94fc5
2014-03-06 11:10 . 2014-03-06 14:46 204288 ----atw- c:\windows\RegBootClean.exe
2014-03-06 11:02 . 2014-03-06 13:57 912384 ----atw- c:\users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\yfokko.exe
2014-03-06 10:19 . 2014-03-06 10:19 -------- d-----w- c:\users\adriano\AppData\Local\PowerCinema
2014-03-06 10:13 . 2014-03-06 16:02 -------- d-----w- c:\programdata\MFAData
2014-03-06 10:13 . 2014-03-06 10:13 -------- d--h--w- c:\programdata\Common Files
2014-03-06 10:13 . 2014-03-06 10:13 -------- d-----w- c:\users\adriano\AppData\Local\MFAData
2014-03-06 10:13 . 2014-03-06 10:13 -------- d-----w- c:\users\adriano\AppData\Local\Avg2014
2014-03-05 15:49 . 2014-03-05 15:49 -------- d-----w- c:\programdata\Lavasoft
2014-03-05 15:31 . 2014-03-05 15:31 -------- d-----w- c:\windows\system32\MRT
2014-03-05 14:49 . 2014-03-05 14:49 -------- d-----w- c:\users\adriano\AppData\Local\Macromedia
2014-03-05 14:48 . 2014-03-05 14:48 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-05 14:48 . 2014-03-05 14:48 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-05 14:43 . 2014-03-07 06:21 -------- d-----w- c:\program files\Mozilla Thunderbird
2014-03-05 14:43 . 2014-03-06 13:44 603648 ----atw- c:\program files\Mozilla Firefox\plugin-container.exe
2014-03-04 16:41 . 2014-02-06 07:08 7947048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F8F25FC1-D46B-4168-9865-C446B050F3F6}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-07 07:10 . 2014-03-07 07:10 653312 ----atw- c:\windows\system32\aqfjkhnk.tmp
2014-03-07 05:24 . 2007-07-28 00:58 909312 ----atw- c:\windows\HideWin.exe
2014-03-06 16:18 . 2007-07-28 09:30 979456 ----atw- c:\windows\system32\drivers\XAudio.exe
2014-03-06 16:18 . 2010-09-17 14:49 719872 ----atw- c:\windows\system32\spoolsv.exe
2014-03-06 16:18 . 2008-12-03 19:12 790528 ----atw- c:\windows\system32\nvvsvc.exe
2014-03-06 14:46 . 2007-07-28 00:59 1826816 ----atw- c:\windows\SkyTel.exe
2014-03-06 14:46 . 2007-07-28 00:59 1191936 ----atw- c:\windows\RtlUpd.exe
2014-03-06 14:09 . 2008-06-20 06:50 728064 -----tw- c:\windows\regedit.exe
2014-03-06 14:09 . 2008-06-20 06:50 745472 ----atw- c:\windows\notepad.exe
2014-03-06 14:05 . 2008-06-20 06:51 1091072 ----atw- c:\windows\HelpPane.exe
2014-03-06 14:05 . 2006-11-02 09:11 608256 ----atw- c:\windows\hh.exe
2014-03-06 14:05 . 2006-11-02 12:35 825344 ----atw- c:\windows\help\Tablet PC\PenTraining.exe
2014-03-06 14:05 . 2006-11-02 12:35 752640 ----atw- c:\windows\help\Tablet PC\TouchTraining.exe
2014-03-06 14:05 . 2008-06-20 06:49 606208 ----atw- c:\windows\fveupdate.exe
2014-03-06 14:04 . 2008-06-20 06:53 653312 ----atw- c:\windows\bfsvc.exe
2014-03-05 14:28 . 2006-11-02 08:58 605696 ----atw- c:\windows\system32\snmptrap.exe
2014-03-05 14:28 . 2006-11-02 08:50 601088 ----atw- c:\windows\system32\Locator.exe
2013-12-18 05:13 . 2009-10-05 08:55 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2014-03-06 1825280]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-18 4468736]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"eAudio"="c:\acer\Empowering Technology\eAudio\eAudio.exe" [2014-03-06 1880064]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2014-03-06 1339392]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2014-03-06 753664]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-03 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-03 92704]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-03-06 1546752]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ovfe.exe [2014-3-6 912384]
yfokko.exe [2014-3-6 912384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 0 (0x0)
"HideSCAHealth"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
.
Contenuto della cartella 'Scheduled Tasks'
.
2014-03-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-05 15:37]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://it.intl.acer.yahoo.com
uSearchURL,(Default) = hxxp://it.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\adriano\AppData\Roaming\Mozilla\Firefox\Profiles\xqijfx91.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: security.warn_entering_secure - false
FF - user.js: security.warn_entering_weak - false
FF - user.js: security.warn_leaving_secure - false
FF - user.js: browser.startup.homepage - about:blank
FF - user.js: browser.startup.page - 1
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKLM-Run-eRecoveryService - (no file)
SafeBoot-Wdf01000.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-07 08:12
Windows 6.0.6002 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'Explorer.exe'(1628)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\conime.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\acer\ALaunch\ALaunchSvc.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\windows\RtHDVCpl.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\program files\Launch Manager\LManager.exe
c:\windows\System32\rundll32.exe
c:\program files\Apoint2K\ApMsgFwd.exe
c:\program files\Apoint2K\Apntex.exe
c:\windows\ehome\ehmsas.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\windows\system32\UI0Detect.exe
c:\windows\System32\vds.exe
c:\windows\system32\wbem\WmiApSrv.exe
c:\windows\system32\wermgr.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\vssvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Ora fine scansione: 2014-03-07 08:17:52 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2014-03-07 07:17
.
Pre-Run: 43.261.485.056 byte disponibili
Post-Run: 41.594.388.480 byte disponibili
.
- - End Of File - - 4575F1C02ADAD30F46A4B9CB0EA21D18
A863475757CC50891AA8458C415E4B25
![Grazie [grazie]](http://www.megalab.it/forum/images/smilies/Grazie.gif)