ciao luke 57 intanto ti ringrazio x aver risposto al mio topic...
Ho seguito passo passo quello ke mi hai detto e di seguito si riporto i due logfile di Hijackthis e di vir:
Logfile of HijackThis v1.99.1
Scan saved at 13.09.01, on 12/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\MessengerPlus! 3\MsgPlus.exe
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\VEXPLITE\MONLITE.EXE
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\VEXPLITE\viritsvc.exe
C:\Programmi\VMware\VMware Workstation\vmware-authd.exe
C:\Programmi\File comuni\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\VEXPLITE\VIRITEXP.EXE
C:\Programmi\VideoLAN\VLC\vlc.exe
C:\WINDOWS\system32\NOTEPAD.exe
H:\winmx\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.overture.com/d/search/p/befr ... omo=befree
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.overture.com/d/search/p/befr ... omo=befree
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,"c:\windows\lexmark-center.exe",
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {45FF61C5-BFA8-D105-A87A-F6F252964450} - C:\WINDOWS\vxuvh1.dll (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll (file missing)
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Programmi\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &Capture Page to Onfolio... -
res://C:\Programmi\Onfolio\Onfolio.WindowsResources.dll/AddLinkEntryFromDocument.html
O8 - Extra context menu item: Capt&ure Target to Onfolio... -
res://C:\Programmi\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture &Snippet to Onfolio... -
res://C:\Programmi\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentSelection.html
O8 - Extra context menu item: Capture Ima&ge to Onfolio... -
res://C:\Programmi\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture Page and Selected &Links to Onfolio... -
res://C:\Programmi\Onfolio\Onfolio.WindowsResources.dll/AddSiteSnippetFromDocumentSelection.html
O8 - Extra context menu item: Capture Selected Ite&ms to Onfolio... -
res://C:\Programmi\Onfolio\Onfolio.WindowsResources.dll/AddMultipleEntriesFromDocumentSelection.html
O8 - Extra context menu item: Capture Site to &Onfolio... -
res://C:\Programmi\Onfolio\Onfolio.WindowsResources.dll/AddSiteFromDocument.html
O14 - IERESET.INF: START_PAGE_URL=http://www.overture.com/d/search/p/befree/?Promo=befree00088981906563281284&Keywords=Home+Page&Go=Go&Promo=befree
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {EC52F7A4-27A7-4319-9BA1-E7FE5C90D3AC} -
http://td8eau9td.com/f5705372/50310/1/xp/FreeAccess.ocx
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.aol.com/downloads/aol ... _en_dl.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared files\RichVideo.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas
http://www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Programmi\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Programmi\File comuni\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
con virt ti riporto sia il logfile della scansione in modalità provvisoria ( riscontrati alcuni errori) e sia il logfile della scansione eseguita in ultimo in modalità normale
VirIT eXplorer Lite Log
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: Trojan.Win32.RootKit.E
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: Trojan.Win32.RootKit.E
--------------------------------------------------------
12/10/2006 - 11:09:24
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: Trojan.Win32.RootKit.E
[SCANSIONE DEL REGISTRO]
{2a6af021-17a2-4014-8624-cf6015f82fad} Infetto da BHO.Agent.BA
* * * RIMOSSO * * *
[A:]
BOOT SECTOR: OK
[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
C:\Documents and Settings\francesco\Preferiti\Collegamenti\Office XP.url Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\Documents and Settings\francesco\Preferiti\Collegamenti\Search.url Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\Documents and Settings\francesco\Preferiti\Collegamenti\Streaming Music.url Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\Documents and Settings\francesco\Preferiti\Collegamenti\Streaming Video.url Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\Documents and Settings\francesco\Preferiti\Collegamenti\Technical Wizard.url Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\Documents and Settings\francesco\Preferiti\Collegamenti\Windows XP.url Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\Documents and Settings\francesco\Preferiti\Downloads.url Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\Documents and Settings\francesco\Preferiti\Search.url Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\WINDOWS\127.tmp Infetto da BHO.LinkOptimizer.I
* * * RIMOSSO * * *
C:\WINDOWS\166.tmp Infetto da BHO.Agent.BC
* * * RIMOSSO * * *
[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
[E:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
[F:]
[G:]
[H:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
[I:]
[J:]
BOOT SECTOR: OK
[K:]
BOOT SECTOR: OK
[L:]
BOOT SECTOR: OK
[M:]
BOOT SECTOR: OK
Chiavi Registro infette: 1.
Files Infetti: 10.
Files Sospetti: 0.
Files Analizzati: 139801.
Files Totali: 139801.
Chiavi Registro rimosse: 1.
Virus Rimossi: 10.
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
--------------------------------------------------------
12/10/2006 - 11:59:39
[SCANSIONE DEL REGISTRO]
OK
[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
C:\WINDOWS\vxuvh1.dll Infetto da BHO.LinkOptimizer.I
* * * RIMOSSO * * *
Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 89520.
Files Totali: 89520.
Chiavi Registro rimosse: 0.
Virus Rimossi: 1.
--------------------------------------------------------
12/10/2006 - 12:25:07
[SCANSIONE DEL REGISTRO]
OK
[A:]
BOOT SECTOR: OK
[G:]
[H:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 601.
Files Totali: 601.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.
--------------------------------------------------------
12/10/2006 - 12:26:01
[SCANSIONE DEL REGISTRO]
OK
[A:]
BOOT SECTOR: OK
[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
[E:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
[F:]
[G:]
[H:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
[I:]
[J:]
BOOT SECTOR: OK
[K:]
BOOT SECTOR: OK
[L:]
BOOT SECTOR: OK
[M:]
BOOT SECTOR: OK
Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 139752.
Files Totali: 139752.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.