Salve ragazzi! Sono disperato. :(
Credo di essere infetto da qualche virus e ciò mi impedisce di installare antivirus come avira e altri programmi scaricati.
Ad esempio se scarico flash player o avira, l'installazione non parte (pur non uscendo nessun messaggio d'errore). Ho fatto la scansione con comofix e questo è il report che ne è venuto fuori:
Ho provato anche a reinstallare windows vista dal cd di recovery che feci quando acquistai il computer, ma niente.
Qualcuno potrebbe aiutarmi? :(
Grazie.
Credo di essere infetto da qualche virus e ciò mi impedisce di installare antivirus come avira e altri programmi scaricati.
Ad esempio se scarico flash player o avira, l'installazione non parte (pur non uscendo nessun messaggio d'errore). Ho fatto la scansione con comofix e questo è il report che ne è venuto fuori:
ComboFix 17-01-04.01 - PC 09/01/2017 0.02.20.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.39.1040.18.3038.1829 [GMT 1:00]
Eseguito da: c:\users\PC\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\security\logs\scecomp.log
.
.
((((((((((((((((((((((((( Files Creati Da 2016-12-08 al 2017-01-08 )))))))))))))))))))))))))))))))))))
.
.
2017-01-08 23:09 . 2017-01-08 23:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-01-08 18:03 . 2016-11-17 12:56 9834504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5F12061D-BA68-4A22-8C38-6AE9B50D041E}\mpengine.dll
2017-01-08 18:03 . 2016-10-26 15:29 407720 ------w- c:\windows\system32\MpSigStub.exe
2017-01-08 17:42 . 2008-04-30 05:36 454656 ----a-w- c:\program files\Common Files\System\msadc\msadce.dll
2017-01-08 17:21 . 2017-01-08 17:21 802904 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2017-01-08 17:21 . 2017-01-08 17:21 144472 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2017-01-08 17:21 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-01-08 17:21 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2017-01-08 17:21 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2017-01-08 17:21 . 2008-06-20 01:14 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2017-01-08 17:21 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2017-01-08 17:21 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2017-01-08 17:21 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2017-01-08 17:21 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2017-01-08 17:13 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2017-01-08 17:13 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2017-01-08 17:13 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2017-01-08 17:13 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2017-01-08 17:13 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2017-01-08 17:10 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2017-01-08 17:10 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2017-01-08 17:10 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2017-01-08 17:09 . 2017-01-08 17:09 -------- d-----w- c:\program files\MSXML 4.0
2017-01-08 17:07 . 2017-01-08 17:07 -------- d-----w- c:\program files\Microsoft Silverlight
2017-01-08 17:05 . 2008-04-05 01:21 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2017-01-08 17:05 . 2008-04-05 03:34 15360 ----a-w- c:\windows\system32\pacerprf.dll
2017-01-08 17:05 . 2010-05-04 18:39 248832 ----a-w- c:\windows\system32\msshsq.dll
2017-01-08 17:05 . 2011-03-02 14:49 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2017-01-08 17:05 . 2009-05-04 10:11 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2017-01-08 17:05 . 2010-10-12 15:48 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2017-01-08 17:05 . 2010-10-12 13:52 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2017-01-08 17:05 . 2010-10-12 13:52 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2017-01-08 17:05 . 2011-02-16 15:35 430080 ----a-w- c:\windows\system32\vbscript.dll
2017-01-08 17:04 . 2008-06-26 01:45 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2017-01-08 17:04 . 2008-06-26 01:45 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2017-01-08 17:04 . 2008-06-26 03:29 801280 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2017-01-08 17:02 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2017-01-08 17:02 . 2010-08-31 15:41 954752 ----a-w- c:\windows\system32\mfc40.dll
2017-01-08 17:02 . 2010-08-31 15:41 954288 ----a-w- c:\windows\system32\mfc40u.dll
2017-01-08 17:02 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll
2017-01-08 17:02 . 2010-09-10 16:35 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2017-01-08 17:02 . 2010-09-10 16:37 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2017-01-08 17:00 . 2010-08-20 15:21 866816 ----a-w- c:\windows\system32\wmpmde.dll
2017-01-08 17:00 . 2011-04-14 14:24 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2017-01-08 17:00 . 2010-01-21 15:59 62464 ----a-w- c:\windows\system32\l3codeca.acm
2017-01-08 16:58 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2017-01-08 16:57 . 2010-10-28 12:56 2048 ----a-w- c:\windows\system32\tzres.dll
2017-01-08 16:56 . 2010-08-26 16:07 157184 ----a-w- c:\windows\system32\t2embed.dll
2017-01-08 16:48 . 2011-04-29 14:54 276992 ----a-w- c:\windows\system32\schannel.dll
2017-01-08 16:34 . 2017-01-08 16:34 -------- d-----w- C:\$GetCurrent
2017-01-08 16:34 . 2017-01-08 16:34 -------- d-----w- C:\Windows10Upgrade
2017-01-08 16:28 . 2017-01-08 16:28 -------- d-----w- c:\programdata\Oracle
2017-01-08 16:28 . 2017-01-08 16:28 -------- d-----w- c:\program files\Common Files\Java
2017-01-08 16:27 . 2017-01-08 16:27 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2017-01-08 16:27 . 2017-01-08 16:27 -------- d-----w- c:\program files\Java
2017-01-08 16:22 . 2017-01-08 16:22 -------- d-----w- c:\program files\Mozilla Maintenance Service
2017-01-08 16:14 . 2017-01-08 16:14 -------- d-----w- c:\programdata\Viewpoint
2017-01-08 16:14 . 2017-01-08 16:14 -------- d-----w- c:\program files\Viewpoint
2017-01-08 16:14 . 2017-01-08 16:14 -------- d-----w- c:\program files\Common Files\AOL
2017-01-08 16:14 . 2017-01-08 16:14 -------- d-----w- c:\program files\AIM6
2017-01-08 16:10 . 2017-01-08 16:17 -------- d-----w- c:\users\PC
2017-01-08 14:57 . 2017-01-08 14:57 -------- d-----w- c:\programdata\NVIDIA
2017-01-08 14:56 . 2017-01-08 14:56 -------- d-----w- c:\programdata\CyberLink
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\tr
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\ru
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\ko
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\ja
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\fr
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\es
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\de
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\DPDrv
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\programdata\Macrovision
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\program files\DigitalPersona
2017-01-08 14:44 . 2008-02-01 08:41 80936 ----a-w- c:\windows\system32\drivers\btwavdt.sys
2017-01-08 14:44 . 2008-02-01 08:41 80424 ----a-w- c:\windows\system32\drivers\btwaudio.sys
2017-01-08 14:44 . 2008-02-01 08:41 16168 ----a-w- c:\windows\system32\drivers\btwrchid.sys
2017-01-08 14:44 . 2008-02-01 08:41 233472 ----a-w- c:\windows\system32\BtwRSupport.dll
2017-01-08 14:44 . 2017-01-08 14:44 -------- d-----w- c:\windows\system32\es-MX
2017-01-08 14:44 . 2017-01-08 14:44 -------- d-----w- c:\windows\system32\es-AR
2017-01-08 14:44 . 2017-01-08 14:44 -------- d-----w- c:\program files\WIDCOMM
2017-01-08 14:43 . 2008-02-12 20:05 372736 ----a-w- c:\windows\system32\aestecap.dll
2017-01-08 14:42 . 2017-01-08 14:42 125 ----a-w- c:\windows\xUninstall.bat
2017-01-08 14:41 . 2017-01-08 14:42 -------- d-----w- c:\windows\JMCR_DIR
2017-01-08 14:40 . 2017-01-08 14:40 -------- d-----w- c:\program files\Synaptics
2017-01-08 14:40 . 2017-01-08 14:40 -------- d-----w- c:\program files\Validity Sensors, Inc
2017-01-08 14:40 . 2006-03-09 09:58 1060424 ----a-w- c:\windows\system32\WdfCoInstaller01000.dll
2017-01-08 14:40 . 2008-01-18 11:31 196784 ----a-w- c:\windows\system32\drivers\SynTP.sys
2017-01-08 14:40 . 2008-01-18 11:30 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2017-01-08 14:40 . 2008-01-18 11:03 147456 ----a-w- c:\windows\system32\SynTPAPI.dll
2017-01-08 14:40 . 2008-01-18 10:52 196608 ----a-w- c:\windows\system32\SynCtrl.dll
2017-01-08 14:40 . 2008-01-18 10:51 163840 ----a-w- c:\windows\system32\SynCOM.dll
2017-01-08 14:39 . 2008-04-15 10:05 118784 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2017-01-08 14:39 . 2017-01-08 14:39 -------- d-----w- c:\program files\Realtek
2017-01-08 14:39 . 2017-01-08 14:39 -------- d-----w- c:\windows\system32\HPMDP
2017-01-08 14:39 . 2017-01-08 14:39 -------- d-----w- c:\windows\Driver Cache
2017-01-08 14:39 . 2008-03-14 06:51 280192 ----a-w- c:\windows\system32\drivers\AVerAF15.sys
2017-01-08 14:39 . 2008-03-06 03:39 252 ----a-w- c:\windows\system32\AP6RMJH.BIN
2017-01-08 14:39 . 2007-03-21 15:19 350 ----a-w- c:\windows\system32\AP6RMHV.BIN
2017-01-08 14:39 . 2007-03-21 15:19 238 ----a-w- c:\windows\system32\AP6RMFP.BIN
2017-01-08 14:39 . 2007-03-21 15:19 126 ----a-w- c:\windows\system32\AP6RMHR.BIN
2017-01-08 14:39 . 2017-01-08 14:39 -------- d-----w- c:\program files\AVerMedia
2017-01-08 14:38 . 2008-05-14 02:09 768544 ----a-w- c:\windows\system32\nvcplui.exe
2017-01-08 14:38 . 2008-05-14 02:09 420384 ----a-w- c:\windows\system32\nvcpl.cpl
2017-01-08 14:38 . 2008-05-14 02:09 313888 ----a-w- c:\windows\system32\nvexpbar.dll
2017-01-08 14:38 . 2008-05-14 02:09 1079840 ----a-w- c:\windows\system32\nvcpluir.dll
2017-01-08 14:37 . 2008-05-08 14:54 446464 ----a-w- c:\windows\system32\NVUNINST.EXE
2017-01-08 14:37 . 2003-11-10 17:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2017-01-08 14:37 . 2003-11-10 17:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2017-01-08 14:37 . 2003-11-10 17:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2017-01-08 14:37 . 2017-01-08 14:37 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2017-01-08 14:37 . 2017-01-08 14:37 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2017-01-08 14:37 . 2003-11-10 17:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2017-01-08 14:37 . 2003-11-10 17:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2017-01-08 14:34 . 2017-01-08 14:34 -------- d-----w- c:\program files\Intel
2017-01-08 14:34 . 2008-03-26 11:15 53248 ----a-w- c:\windows\system32\CSVer.dll
2017-01-08 14:34 . 2017-01-08 14:34 -------- d-----w- C:\Intel
2017-01-08 14:33 . 2008-04-28 06:29 3658752 ----a-w- c:\windows\system32\drivers\NETw5v32.sys
2017-01-08 14:33 . 2008-04-18 16:09 2756608 ----a-w- c:\windows\system32\NETw5r32.dll
2017-01-08 14:33 . 2008-04-18 16:08 659456 ----a-w- c:\windows\system32\NETw5c32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-01-08 18:48 . 2008-06-19 08:41 588472 ----a-w- c:\windows\system32\ezsvc7x.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 2153472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-14 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-14 92704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-12 699456]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-23 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-04-10 271744]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-16 727592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe [2008-02-12 73728]
.
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - ESPROTECTIONDRIVER
*Deregistered* - ESProtectionDriver
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - SRTSPX
*Deregistered* - SymIM
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contenuto della cartella 'Scheduled Tasks'
.
2017-01-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-08 17:21]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=83&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=83&bd=Pavilion&pf=cnnb
IE: &AOL Toolbar Cerca - c:\programdata\AOL\ieToolbar\resources\it-IT\local\search.html
IE: Invia immagine alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Invia pagina alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\97armh8m.default\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKLM-RunOnce-isDeleteMe - c:\users\PC\AppData\Local\Temp\isDel.bat
SafeBoot-Wdf01000.sys
SafeBoot-MBAMService
AddRemove-AVerMedia A309 (MiniCard, DVB-T) - c:\program files\AVerMedia\AVerMedia A309 (MiniCard
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2017-01-09 00:09
Windows 6.0.6001 Service Pack 1 NTFS
.
scansione processi nascosti ...
.
ØYßÍõ\ØZßÍz\ [484393944] 0x00780069
ØYßÍõ\ØZßÍz\ [484393944] 0x007E006E
[0] 0x8955C3C9
[0] 0x4589E455
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
.
c:\users\PC\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
Scansione completata con successo
Files nascosti: 1
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'lsass.exe'(672)
c:\windows\system32\DPPWDFLT.dll
.
Ora fine scansione: 2017-01-09 00:14:27
ComboFix-quarantined-files.txt 2017-01-08 23:14
.
Pre-Run: 277.304.672.256 byte disponibili
Post-Run: 277.405.466.624 byte disponibili
.
- - End Of File - - 489A170DA7C71A4126DF94601C22D9B4
79E02E9917193B964C2C201958B60544
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.39.1040.18.3038.1829 [GMT 1:00]
Eseguito da: c:\users\PC\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\security\logs\scecomp.log
.
.
((((((((((((((((((((((((( Files Creati Da 2016-12-08 al 2017-01-08 )))))))))))))))))))))))))))))))))))
.
.
2017-01-08 23:09 . 2017-01-08 23:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-01-08 18:03 . 2016-11-17 12:56 9834504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5F12061D-BA68-4A22-8C38-6AE9B50D041E}\mpengine.dll
2017-01-08 18:03 . 2016-10-26 15:29 407720 ------w- c:\windows\system32\MpSigStub.exe
2017-01-08 17:42 . 2008-04-30 05:36 454656 ----a-w- c:\program files\Common Files\System\msadc\msadce.dll
2017-01-08 17:21 . 2017-01-08 17:21 802904 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2017-01-08 17:21 . 2017-01-08 17:21 144472 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2017-01-08 17:21 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-01-08 17:21 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2017-01-08 17:21 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2017-01-08 17:21 . 2008-06-20 01:14 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2017-01-08 17:21 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2017-01-08 17:21 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2017-01-08 17:21 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2017-01-08 17:21 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2017-01-08 17:13 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2017-01-08 17:13 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2017-01-08 17:13 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2017-01-08 17:13 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2017-01-08 17:13 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2017-01-08 17:10 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2017-01-08 17:10 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2017-01-08 17:10 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2017-01-08 17:09 . 2017-01-08 17:09 -------- d-----w- c:\program files\MSXML 4.0
2017-01-08 17:07 . 2017-01-08 17:07 -------- d-----w- c:\program files\Microsoft Silverlight
2017-01-08 17:05 . 2008-04-05 01:21 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2017-01-08 17:05 . 2008-04-05 03:34 15360 ----a-w- c:\windows\system32\pacerprf.dll
2017-01-08 17:05 . 2010-05-04 18:39 248832 ----a-w- c:\windows\system32\msshsq.dll
2017-01-08 17:05 . 2011-03-02 14:49 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2017-01-08 17:05 . 2009-05-04 10:11 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2017-01-08 17:05 . 2010-10-12 15:48 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2017-01-08 17:05 . 2010-10-12 13:52 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2017-01-08 17:05 . 2010-10-12 13:52 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2017-01-08 17:05 . 2011-02-16 15:35 430080 ----a-w- c:\windows\system32\vbscript.dll
2017-01-08 17:04 . 2008-06-26 01:45 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2017-01-08 17:04 . 2008-06-26 01:45 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2017-01-08 17:04 . 2008-06-26 03:29 801280 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2017-01-08 17:02 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2017-01-08 17:02 . 2010-08-31 15:41 954752 ----a-w- c:\windows\system32\mfc40.dll
2017-01-08 17:02 . 2010-08-31 15:41 954288 ----a-w- c:\windows\system32\mfc40u.dll
2017-01-08 17:02 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll
2017-01-08 17:02 . 2010-09-10 16:35 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2017-01-08 17:02 . 2010-09-10 16:37 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2017-01-08 17:00 . 2010-08-20 15:21 866816 ----a-w- c:\windows\system32\wmpmde.dll
2017-01-08 17:00 . 2011-04-14 14:24 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2017-01-08 17:00 . 2010-01-21 15:59 62464 ----a-w- c:\windows\system32\l3codeca.acm
2017-01-08 16:58 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2017-01-08 16:57 . 2010-10-28 12:56 2048 ----a-w- c:\windows\system32\tzres.dll
2017-01-08 16:56 . 2010-08-26 16:07 157184 ----a-w- c:\windows\system32\t2embed.dll
2017-01-08 16:48 . 2011-04-29 14:54 276992 ----a-w- c:\windows\system32\schannel.dll
2017-01-08 16:34 . 2017-01-08 16:34 -------- d-----w- C:\$GetCurrent
2017-01-08 16:34 . 2017-01-08 16:34 -------- d-----w- C:\Windows10Upgrade
2017-01-08 16:28 . 2017-01-08 16:28 -------- d-----w- c:\programdata\Oracle
2017-01-08 16:28 . 2017-01-08 16:28 -------- d-----w- c:\program files\Common Files\Java
2017-01-08 16:27 . 2017-01-08 16:27 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2017-01-08 16:27 . 2017-01-08 16:27 -------- d-----w- c:\program files\Java
2017-01-08 16:22 . 2017-01-08 16:22 -------- d-----w- c:\program files\Mozilla Maintenance Service
2017-01-08 16:14 . 2017-01-08 16:14 -------- d-----w- c:\programdata\Viewpoint
2017-01-08 16:14 . 2017-01-08 16:14 -------- d-----w- c:\program files\Viewpoint
2017-01-08 16:14 . 2017-01-08 16:14 -------- d-----w- c:\program files\Common Files\AOL
2017-01-08 16:14 . 2017-01-08 16:14 -------- d-----w- c:\program files\AIM6
2017-01-08 16:10 . 2017-01-08 16:17 -------- d-----w- c:\users\PC
2017-01-08 14:57 . 2017-01-08 14:57 -------- d-----w- c:\programdata\NVIDIA
2017-01-08 14:56 . 2017-01-08 14:56 -------- d-----w- c:\programdata\CyberLink
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\tr
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\ru
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\ko
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\ja
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\fr
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\es
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\system32\de
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\windows\DPDrv
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\programdata\Macrovision
2017-01-08 14:55 . 2017-01-08 14:55 -------- d-----w- c:\program files\DigitalPersona
2017-01-08 14:44 . 2008-02-01 08:41 80936 ----a-w- c:\windows\system32\drivers\btwavdt.sys
2017-01-08 14:44 . 2008-02-01 08:41 80424 ----a-w- c:\windows\system32\drivers\btwaudio.sys
2017-01-08 14:44 . 2008-02-01 08:41 16168 ----a-w- c:\windows\system32\drivers\btwrchid.sys
2017-01-08 14:44 . 2008-02-01 08:41 233472 ----a-w- c:\windows\system32\BtwRSupport.dll
2017-01-08 14:44 . 2017-01-08 14:44 -------- d-----w- c:\windows\system32\es-MX
2017-01-08 14:44 . 2017-01-08 14:44 -------- d-----w- c:\windows\system32\es-AR
2017-01-08 14:44 . 2017-01-08 14:44 -------- d-----w- c:\program files\WIDCOMM
2017-01-08 14:43 . 2008-02-12 20:05 372736 ----a-w- c:\windows\system32\aestecap.dll
2017-01-08 14:42 . 2017-01-08 14:42 125 ----a-w- c:\windows\xUninstall.bat
2017-01-08 14:41 . 2017-01-08 14:42 -------- d-----w- c:\windows\JMCR_DIR
2017-01-08 14:40 . 2017-01-08 14:40 -------- d-----w- c:\program files\Synaptics
2017-01-08 14:40 . 2017-01-08 14:40 -------- d-----w- c:\program files\Validity Sensors, Inc
2017-01-08 14:40 . 2006-03-09 09:58 1060424 ----a-w- c:\windows\system32\WdfCoInstaller01000.dll
2017-01-08 14:40 . 2008-01-18 11:31 196784 ----a-w- c:\windows\system32\drivers\SynTP.sys
2017-01-08 14:40 . 2008-01-18 11:30 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2017-01-08 14:40 . 2008-01-18 11:03 147456 ----a-w- c:\windows\system32\SynTPAPI.dll
2017-01-08 14:40 . 2008-01-18 10:52 196608 ----a-w- c:\windows\system32\SynCtrl.dll
2017-01-08 14:40 . 2008-01-18 10:51 163840 ----a-w- c:\windows\system32\SynCOM.dll
2017-01-08 14:39 . 2008-04-15 10:05 118784 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2017-01-08 14:39 . 2017-01-08 14:39 -------- d-----w- c:\program files\Realtek
2017-01-08 14:39 . 2017-01-08 14:39 -------- d-----w- c:\windows\system32\HPMDP
2017-01-08 14:39 . 2017-01-08 14:39 -------- d-----w- c:\windows\Driver Cache
2017-01-08 14:39 . 2008-03-14 06:51 280192 ----a-w- c:\windows\system32\drivers\AVerAF15.sys
2017-01-08 14:39 . 2008-03-06 03:39 252 ----a-w- c:\windows\system32\AP6RMJH.BIN
2017-01-08 14:39 . 2007-03-21 15:19 350 ----a-w- c:\windows\system32\AP6RMHV.BIN
2017-01-08 14:39 . 2007-03-21 15:19 238 ----a-w- c:\windows\system32\AP6RMFP.BIN
2017-01-08 14:39 . 2007-03-21 15:19 126 ----a-w- c:\windows\system32\AP6RMHR.BIN
2017-01-08 14:39 . 2017-01-08 14:39 -------- d-----w- c:\program files\AVerMedia
2017-01-08 14:38 . 2008-05-14 02:09 768544 ----a-w- c:\windows\system32\nvcplui.exe
2017-01-08 14:38 . 2008-05-14 02:09 420384 ----a-w- c:\windows\system32\nvcpl.cpl
2017-01-08 14:38 . 2008-05-14 02:09 313888 ----a-w- c:\windows\system32\nvexpbar.dll
2017-01-08 14:38 . 2008-05-14 02:09 1079840 ----a-w- c:\windows\system32\nvcpluir.dll
2017-01-08 14:37 . 2008-05-08 14:54 446464 ----a-w- c:\windows\system32\NVUNINST.EXE
2017-01-08 14:37 . 2003-11-10 17:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2017-01-08 14:37 . 2003-11-10 17:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2017-01-08 14:37 . 2003-11-10 17:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2017-01-08 14:37 . 2017-01-08 14:37 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2017-01-08 14:37 . 2017-01-08 14:37 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2017-01-08 14:37 . 2003-11-10 17:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2017-01-08 14:37 . 2003-11-10 17:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2017-01-08 14:34 . 2017-01-08 14:34 -------- d-----w- c:\program files\Intel
2017-01-08 14:34 . 2008-03-26 11:15 53248 ----a-w- c:\windows\system32\CSVer.dll
2017-01-08 14:34 . 2017-01-08 14:34 -------- d-----w- C:\Intel
2017-01-08 14:33 . 2008-04-28 06:29 3658752 ----a-w- c:\windows\system32\drivers\NETw5v32.sys
2017-01-08 14:33 . 2008-04-18 16:09 2756608 ----a-w- c:\windows\system32\NETw5r32.dll
2017-01-08 14:33 . 2008-04-18 16:08 659456 ----a-w- c:\windows\system32\NETw5c32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-01-08 18:48 . 2008-06-19 08:41 588472 ----a-w- c:\windows\system32\ezsvc7x.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 2153472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-14 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-14 92704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-12 699456]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-23 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-04-10 271744]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-16 727592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe [2008-02-12 73728]
.
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - ESPROTECTIONDRIVER
*Deregistered* - ESProtectionDriver
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - SRTSPX
*Deregistered* - SymIM
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contenuto della cartella 'Scheduled Tasks'
.
2017-01-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-08 17:21]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=83&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=83&bd=Pavilion&pf=cnnb
IE: &AOL Toolbar Cerca - c:\programdata\AOL\ieToolbar\resources\it-IT\local\search.html
IE: Invia immagine alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Invia pagina alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\97armh8m.default\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKLM-RunOnce-isDeleteMe - c:\users\PC\AppData\Local\Temp\isDel.bat
SafeBoot-Wdf01000.sys
SafeBoot-MBAMService
AddRemove-AVerMedia A309 (MiniCard, DVB-T) - c:\program files\AVerMedia\AVerMedia A309 (MiniCard
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2017-01-09 00:09
Windows 6.0.6001 Service Pack 1 NTFS
.
scansione processi nascosti ...
.
ØYßÍõ\ØZßÍz\ [484393944] 0x00780069
ØYßÍõ\ØZßÍz\ [484393944] 0x007E006E
[0] 0x8955C3C9
[0] 0x4589E455
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
.
c:\users\PC\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
Scansione completata con successo
Files nascosti: 1
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'lsass.exe'(672)
c:\windows\system32\DPPWDFLT.dll
.
Ora fine scansione: 2017-01-09 00:14:27
ComboFix-quarantined-files.txt 2017-01-08 23:14
.
Pre-Run: 277.304.672.256 byte disponibili
Post-Run: 277.405.466.624 byte disponibili
.
- - End Of File - - 489A170DA7C71A4126DF94601C22D9B4
79E02E9917193B964C2C201958B60544
Qualcuno potrebbe aiutarmi? :(
Grazie.
Ultima modifica da un moderatore: