Guarda ti diró adesso sto con il tabetica e non Andró a cliccare su quel link!
Guarda ti ripeto prova combofix, ci vuole tempo ma andrà tutto bene!
I dns che ti ho dato sono quelli di google e quindi per andare su internet stai usando quelli, non è strettamente necessario metterli sul router. Cosa accade?
Tu userai quelli google e gli altri che si collegano quelli di Telecom.
Ma non avevi anche un altro portatile? Allora su uno di questi prova combofix che poi dobbiamo installare un altro software e poi sarà impossibile che non funzioni
il log di combofix spero do aver fatto tutto giusto
Eseguito da: c:\users\Armando\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\OfferBox
c:\program files\OfferBox\language.xml
c:\program files\OfferBox\OfferBox.exe
c:\program files\OfferBox\OfferBoxHTTPProxy.exe
c:\program files\OfferBox\uninstaller.exe
c:\program files\Windows Searchqu Toolbar
c:\program files\Windows Searchqu Toolbar\sysid.ini
c:\program files\Windows Searchqu Toolbar\uninstall.exe
c:\users\Armando\AppData\Local\unins000.exe
c:\users\Armando\AppData\Roaming\OfferBox
c:\users\Armando\AppData\Roaming\OfferBox\config.dat
c:\users\Armando\AppData\Roaming\OfferBox\config.xml
c:\users\Armando\AppData\Roaming\OfferBox\run.log
c:\users\Armando\AppData\Roaming\OfferBox\temp.ico
c:\windows\system32\DEBUG.log
c:\windows\system32\pt
c:\windows\system32\pt\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((( Files Creati Da 2012-07-24 al 2012-08-24 )))))))))))))))))))))))))))))))))))
.
.
2012-08-24 00:05 . 2012-08-24 00:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-23 00:08 . 2012-08-23 00:08 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{50A1D3BE-B755-46E3-BD84-E18718CDD2C2}\offreg.dll
2012-08-21 16:20 . 2012-08-22 14:11 -------- d-----w- c:\program files\ChatZum Toolbar
2012-08-21 14:56 . 2012-08-21 14:55 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-21 14:55 . 2012-08-21 14:55 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-21 09:30 . 2012-08-01 22:51 7023536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{50A1D3BE-B755-46E3-BD84-E18718CDD2C2}\mpengine.dll
2012-08-18 11:58 . 2012-08-21 09:25 -------- d-----w- c:\users\Armando\AppData\Local\SoftwareUpdater
2012-08-18 11:57 . 2012-05-29 15:19 31584 ----a-w- c:\windows\system32\TURegOpt.exe
2012-08-18 11:57 . 2012-05-29 15:19 21344 ----a-w- c:\windows\system32\authuitu.dll
2012-08-18 11:56 . 2012-08-18 11:57 -------- d-----w- c:\program files\TuneUp Utilities 2012
2012-08-18 11:56 . 2012-08-18 11:56 -------- d--h--w- c:\programdata\Common Files
2012-08-17 18:58 . 2012-08-17 18:58 -------- d-----w- c:\programdata\Malwarebytes
2012-08-17 18:58 . 2012-08-17 18:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-17 18:58 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-17 12:01 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\08711232.sys
2012-08-17 12:01 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\08711231.sys
2012-08-17 09:14 . 2012-08-17 09:14 -------- d-----w- c:\users\Armando\AppData\Roaming\Simply Super Software
2012-08-17 09:14 . 2012-06-15 14:39 169744 ----a-w- c:\windows\system32\ztvunrar36.dll
2012-08-17 09:14 . 2012-06-15 14:35 185616 ----a-w- c:\windows\system32\ztvunrar39.dll
2012-08-17 09:14 . 2012-06-15 14:33 605968 ----a-w- c:\windows\system32\ztv7z.dll
2012-08-17 09:14 . 2012-06-15 14:33 77072 ----a-w- c:\windows\system32\ztvcabinet.dll
2012-08-17 09:14 . 2005-08-25 23:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2012-08-17 09:14 . 2002-03-05 23:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2012-08-17 09:14 . 2003-02-02 18:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2012-08-17 09:14 . 2012-08-17 09:14 -------- d-----w- c:\program files\Trojan Remover
2012-08-17 09:14 . 2012-08-17 09:14 -------- d-----w- c:\programdata\Simply Super Software
2012-08-15 14:42 . 2012-08-15 14:42 -------- d-----w- c:\users\Armando\AppData\Roaming\Sony Corporation
2012-08-15 14:40 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2012-08-15 14:34 . 2012-08-15 14:34 -------- d-----w- c:\program files\Sony
2012-08-15 14:34 . 2012-08-15 14:34 -------- d-----w- c:\programdata\Sony Corporation
2012-08-15 13:59 . 2012-08-15 13:59 -------- d-----w- c:\users\Armando\AppData\Roaming\Ulead Systems
2012-08-15 09:48 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-08-14 14:55 . 2012-08-14 14:55 388096 ----a-r- c:\users\Armando\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-14 14:55 . 2012-08-14 14:55 -------- d-----w- c:\program files\Trend Micro
2012-08-11 10:14 . 2012-08-11 10:14 -------- d-----w- C:\output
2012-08-10 13:37 . 2012-08-21 09:13 113776 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-08-10 13:36 . 2012-08-21 09:13 202928 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-08-10 13:36 . 2012-08-21 09:13 18544 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-08-10 13:36 . 2012-06-27 20:33 12112 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-08-10 13:27 . 2012-08-21 09:13 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-10 13:27 . 2012-08-21 09:13 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-10 13:27 . 2012-08-21 09:13 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-10 13:27 . 2012-08-21 09:13 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-10 13:27 . 2012-08-21 09:13 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-10 13:27 . 2012-08-21 09:13 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-10 13:27 . 2012-08-21 09:12 41224 ----a-w- c:\windows\avastSS.scr
2012-08-10 13:27 . 2012-08-21 09:12 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-10 13:26 . 2012-08-10 13:26 -------- d-----w- c:\programdata\AVAST Software
2012-08-10 13:26 . 2012-08-10 13:26 -------- d-----w- c:\program files\AVAST Software
2012-08-10 09:46 . 2012-08-10 09:46 -------- d-----w- c:\program files\Common Files\Skype
2012-08-08 15:36 . 2012-08-10 12:24 -------- d-----w- c:\program files\Microsoft Silverlight
2012-08-08 15:36 . 2012-08-08 15:36 6260088 ----a-w- c:\program files\Common Files\Windows Live\.cache\838177fd1cd757b02\Silverlight.4.0.exe
2012-08-08 15:33 . 2012-08-11 09:53 -------- d-----w- c:\users\Armando\AppData\Local\Windows Live
2012-08-08 13:48 . 2012-08-08 13:48 -------- d-----w- c:\users\Armando\AppData\Roaming\Malwarebytes
2012-08-08 13:40 . 2012-08-08 13:40 -------- d-----w- c:\users\Armando\temp
2012-08-08 13:40 . 2012-08-08 13:40 -------- d-----w- c:\users\Armando\AppData\Roaming\TeamViewer
2012-08-08 13:05 . 2012-08-08 13:05 -------- d-----w- c:\windows\Sun
2012-08-03 18:36 . 2012-08-10 22:11 -------- d-----w- c:\programdata\InstallBrainService
2012-08-03 17:57 . 2012-08-03 17:57 -------- d-----w- c:\users\Armando\AppData\Roaming\PeerNetworking
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-21 14:55 . 2012-01-03 01:20 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-08 15:37 . 2011-03-28 16:36 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-07-04 03:48 . 2012-07-04 03:48 3861472 ----a-w- C:\chatzum.exe
2012-06-25 14:04 . 2012-06-25 14:04 1394248 ----a-w- c:\windows\system32\msxml4.dll
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 16:47 . 2012-07-11 20:57 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 16:47 . 2012-07-11 20:57 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 15:26 . 2012-07-11 20:57 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 22:19 . 2012-06-21 09:24 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 09:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 09:24 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 09:24 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-21 09:24 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-21 09:24 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-21 09:24 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-21 09:24 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-21 09:24 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 00:04 . 2012-07-11 20:57 278528 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 00:03 . 2012-07-11 20:57 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-05-31 10:25 . 2012-01-03 03:21 237072 ------w- c:\windows\system32\MpSigStub.exe
2011-09-16 13:12 . 2012-02-26 17:30 3623592 ----a-w- c:\program files\Common Files\ApnToolbarInstaller.exe
2011-09-16 13:12 . 2012-02-26 17:30 143240 ----a-w- c:\program files\Common Files\ApnStub.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"Toshiba TEMPO"="c:\program files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe" [2008-04-24 103824]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-05-09 716800]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-09-26 417792]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-26 648032]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2012-07-03 1244432]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-11 29744]
"NDSTray.exe"="NDSTray.exe" [BU]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"PosService"="c:\users\Public\Documents\AppData\PoApp\PLauncher.exe" [2011-12-16 218624]
.
c:\users\Armando\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
tcbhn.lnk - c:\users\Armando\AppData\Roaming\BrowserCompanion\tcbhn.exe [2012-3-27 692888]
TRDCReminder.lnk - c:\program files\TOSHIBA\TRDCReminder\TRDCReminder.exe [2008-3-5 393216]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files\TOSHIBA\TRDCReminder\TRDCReminder.exe [2008-3-5 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Armando\AppData\Local\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PosService"=c:\users\Public\Documents\AppData\PoApp\PLauncher.exe
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
S0 08711232;08711232 Boot Guard Driver;c:\windows\system32\DRIVERS\08711232.sys [x]
S1 08711231;08711231;c:\windows\system32\DRIVERS\08711231.sys [x]
.
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - MBAMSwissArmy
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2147181629-1796238689-3658862881-1000Core.job
- c:\users\Armando\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-02 16:07]
.
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2147181629-1796238689-3658862881-1000UA.job
- c:\users\Armando\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-02 16:07]
.
.
------- Scansione supplementare -------
.
uStart Page =
mStart Page = hxxp://search.chatzum.com/
uInternet Settings,ProxyServer = http=127.0.0.1:56847
uInternet Settings,ProxyOverride = <local>
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{319DFFAD-45BC-446E-8677-E3A769DE2AC0}: NameServer = 176.31.229.24,176.31.229.25
TCP: Interfaces\{8C2876B7-6591-4FEA-9F3E-5B7CFDE2BDD6}: NameServer = 8.8.8.8,8.8.4.4
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
URLSearchHooks-{53946e11-7744-445b-8869-ec6a4dd06e71} - (no file)
Toolbar-10 - (no file)
Toolbar-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
Toolbar-!{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
Toolbar-!{cd8812d4-e5b8-41c6-94d4-59872a484bf1} - (no file)
Toolbar-!{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
AddRemove-OfferBox - c:\program files\OfferBox\uninstaller.exe
AddRemove-{0B500125-92A7-40BF-ACF0-45A9221ADE21}_is1 - c:\users\Armando\AppData\Local\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-24 02:06
Windows 6.0.6002 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Ora fine scansione: 2012-08-24 02:18:28
ComboFix-quarantined-files.txt 2012-08-24 00:18
.
Pre-Run: 61.111.906.304 byte disponibili
Post-Run: 60.436.066.304 byte disponibili
.
- - End Of File - - E40037114721E60DF0185FF4C36FEB81