Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

mi controllate il LOG di Hijack Opzioni
nuvolaneuve
Inviato: Tuesday, November 18, 2008 10:38:01 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
purtroppo quando avvio il pc mi si apre una finestra per inserire un codice, quando la chiudo avast mi avverte che il file "C:\a.bat è infetto da VBS:Malware-gen"; lo sposto nel cestino come suggerito ma non riesco ad eliminare questa scocciatura!
grazie dell'aiuto

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.36.13, on 18/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Lavasoft\Ad-Aware\aawservice.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmi\Windows Defender\MSASCui.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
F:\Programmi\HP\HP Software Update\HPWuSchd.exe
C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\WindowANTasdIVRI.exe
C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\wcescomm.exe
F:\rapimgr.exe
F:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gw.aliceadsl.it/home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://gw.aliceadsl.it/minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gw.aliceadsl.it/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [OpwareSE2] "C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [eitcba.exe] C:\DOCUME~1\enrico\IMPOST~1\Temp\eitcba.exe
O4 - HKLM\..\Run: [cyuzba.exe] C:\DOCUME~1\enrico\IMPOST~1\Temp\cyuzba.exe
O4 - HKLM\..\Run: [vuzjca.exe] C:\DOCUME~1\enrico\IMPOST~1\Temp\vuzjca.exe
O4 - HKLM\..\Run: [hqozfa.exe] C:\DOCUME~1\enrico\IMPOST~1\Temp\hqozfa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] "F:\Programmi\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\Run: [AliceRE_McciTrayApp] C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunServices: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\RunOnce: [InstallHelper C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer] "C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer\InstallHelper.exe" "/DIR=C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmi\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BitComet] "F:\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_7 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\wcescomm.exe"
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
O4 - Global Startup: Digisoft AntiDialer.lnk = F:\Digisoft AntiDialer\AntiDialer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = F:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\Programmi\MP3 Player Utilities 4.15\AMVConverter\grab.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Programmi\MP3 Player Utilities 4.15\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra 'Tools' menuitem: Crea preferito portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: Alice - {AD01FB3B-8AD7-4994-82BE-3B7E6F4E14C1} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197568262529
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://www.tele2mail.com/static/apps/utils/AccountHelper.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6449E0AC-867A-4BD8-9DC5-B2AA42499B9D}: NameServer = 85.37.17.44 85.38.28.90
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A92480-049C-48EC-A329-D43338B1B63C}: NameServer = 192.168.1.1
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Network WanMiniport First Position - Unknown owner - C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 13888 bytes
Sponsor
Inviato: Tuesday, November 18, 2008 10:38:01 PM

 
r16
Inviato: Tuesday, November 18, 2008 11:17:04 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Installa Super Antispyware : http://www.aiutaamici.com/software?ID=11397
una volta installato, da Preferences, accedi al Pannello Control Center, apri la sezione Scanning Control e spunta, esclusivamente, questi voci: (togli le altre)

Ignore files larger than 4MB (recommended)
Ignore non executable files (recommended)
Scan only known file types (exe,.com,dll ecc...)
Scan for tracking cookies
Resolve link/shortcuts during scan
Scan alternate data streams
Use kernel direct file access
Use kernel direct registry access
Use Direct Disk Access (recommended)
Display scan option in explorer context


e, conferma le impostazioni cliccando su Close, poi, clicca sulla voce Scan you computer e, nella finestra successiva:

nel menu a sinistra nella sezione Scan location spunta solo la voce C:\fixed drive (ntfs)
nel menu a destra, spunta la voce Perform complete scan
clicca su Avanti e verrà avviata la scansione
al termine della scansione avrai la possibilità di salvare il relativo log
salva il log che verrà rilasciato

Terminate le scansioni, devi riavviare il sistema .

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,e dopo aver scaricato COMBOFIX, chiudi la connessione.

Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Salvalo sul desktop.
Doppio click su combofix.exe (comparirà una videata.)
Digita 1 premi Invio e segui le indicazioni.
Al termine, verrà creato un file log chiamato C:\ComboFix.txt. Postalo qui.
Durante l'operazione di scansione è importante non usare il PC e attendere pazientemente la fine delle operazioni.
Posta un nuovo log di HijackThis .Sempre in questo topic.
N.B: Prima della scansione Aggiornalo cliccando su "Check for Updates"
Poi fai una scansione con MBAM e posta i log.
nuvolaneuve
Inviato: Wednesday, November 19, 2008 10:22:19 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
ho fatto come mi hai detto, tranne aggiornamento hijackthis non lo ho trovato (sono novellino......)
comunque ecco il log combofix:

ComboFix 08-11-18.A2 - enrico 2008-11-19 22:02:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.561 [GMT 1:00]
Eseguito da: c:\documents and settings\enrico\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\enrico\Dati applicazioni\inst.exe
C:\setup.exe

.
((((((((((((((((((((((((( Files Creati Da 2008-10-19 al 2008-11-19 )))))))))))))))))))))))))))))))))))
.

2008-11-19 21:01 . 2008-11-19 21:42 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2008-11-19 21:01 . 2008-11-19 21:01 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\SUPERAntiSpyware.com
2008-11-19 21:01 . 2008-11-19 21:01 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-11-19 21:00 . 2008-11-19 21:00 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di stampa
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di rete
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d-------- c:\documents and settings\Administrator\Preferiti
2008-11-18 21:42 . 2007-05-03 16:44 <DIR> d--h----- c:\documents and settings\Administrator\Modelli
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> dr------- c:\documents and settings\Administrator\Menu Avvio
2008-11-18 21:42 . 2008-11-19 22:04 <DIR> d--h----- c:\documents and settings\Administrator\Impostazioni locali
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d-------- c:\documents and settings\Administrator\Documenti
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> dr-h----- c:\documents and settings\Administrator\Dati applicazioni
2008-11-18 21:42 . 2008-11-18 21:42 <DIR> d-------- c:\documents and settings\Administrator
2008-11-18 21:36 . 2008-11-18 21:36 <DIR> d-------- c:\programmi\Trend Micro
2008-11-18 21:23 . 2008-11-18 21:23 <DIR> d-------- c:\programmi\CCleaner
2008-11-18 17:44 . 2008-11-18 17:45 <DIR> d-------- c:\programmi\ReflexiveArcade
2008-11-18 17:44 . 2008-11-18 17:46 <DIR> d-------- c:\programmi\Aqua Pearls
2008-11-15 22:05 . 2008-11-15 22:05 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-11-15 22:05 . 2008-11-15 22:05 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\Malwarebytes
2008-11-15 22:05 . 2008-11-15 22:05 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-11-15 22:05 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-15 22:05 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-13 16:42 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-13 16:41 . 2008-09-04 18:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 22:18 . 2008-11-12 22:20 <DIR> d-------- c:\programmi\eToro
2008-11-08 22:08 . 2008-11-08 22:08 <DIR> d--h----- c:\windows\PIF
2008-11-01 20:01 . 2008-11-01 20:01 <DIR> d-------- c:\programmi\K-Lite Codec Pack
2008-11-01 19:41 . 2008-07-12 08:18 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2008-11-01 19:41 . 2008-07-12 08:18 1,493,528 --a------ c:\windows\system32\D3DCompiler_39.dll
2008-11-01 19:41 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-11-01 19:41 . 2008-07-31 10:40 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2008-11-01 19:41 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-01 19:41 . 2008-07-12 08:18 467,984 --a------ c:\windows\system32\d3dx10_39.dll
2008-11-01 19:41 . 2008-07-31 10:41 238,088 --a------ c:\windows\system32\xactengine3_2.dll
2008-11-01 19:41 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-01 19:41 . 2008-07-31 10:41 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2008-11-01 19:41 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-01 19:41 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-01 19:38 . 2008-11-01 19:38 <DIR> d-------- c:\windows\Logs
2008-11-01 14:33 . 2008-11-01 19:48 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\Media Player Classic
2008-10-23 19:29 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-22 19:59 . 2008-10-22 19:59 <DIR> d-------- c:\documents and settings\manuela\Dati applicazioni\DivX
2008-10-21 20:45 . 2008-10-21 20:45 42,771 --a------ c:\windows\CSTBox.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 20:50 --------- d---a-w c:\documents and settings\All Users\Dati applicazioni\TEMP
2008-11-12 20:54 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2008-11-10 20:53 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Motive
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 19:45 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\Canon
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-07 14:09 --------- d-----w c:\programmi\NOS
2008-10-07 14:09 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\NOS
2008-10-06 17:29 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\ArcSoft
2008-10-06 17:28 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\ArcSoft
2008-10-06 17:26 --------- d-----w c:\programmi\File comuni\Adobe
2008-10-06 17:09 --------- d--h--w c:\programmi\InstallShield Installation Information
2008-10-06 17:09 --------- d-----w c:\programmi\File comuni\ArcSoft
2008-10-06 17:09 --------- d-----w c:\programmi\ArcSoft
2008-10-06 17:08 --------- d-----w c:\programmi\Philips
2008-10-06 17:08 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\InstallShield
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-29 19:05 --------- d-----w c:\documents and settings\manuela\Dati applicazioni\Nokia Multimedia Player
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\divx.dll
2008-09-15 15:24 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-26 07:57 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-10 19:17 47,360 ----a-w c:\documents and settings\enrico\Dati applicazioni\pcouffin.sys
2008-04-14 02:14 786,432 --sh--r c:\windows\system32\WindowANTasdIVRI.exe
2008-05-22 17:39 32,768 -csha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008052220080523\index.dat
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 483,328 2004-12-14 00:12:02 c:\programmi\Adobe\Acrobat 7.0\Distillr\bak\Acrotray.exe
----a-w 483,328 2006-01-12 19:52:32 c:\programmi\Adobe\Acrobat 7.0\Distillr\AcroTray.exe

-c--a-w 155,648 2006-01-12 13:40:44 c:\programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe

-c--a-w 139,264 2006-11-16 17:04:20 c:\programmi\File comuni\Ahead\Lib\bak\NMBgMonitor.exe

-c--a-w 31,016 2006-10-26 22:47:42 c:\programmi\Microsoft Office\Office12\bak\GrooveMonitor.exe

-c--a-w 227,328 2007-03-23 11:20:52 c:\programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe
----a-w 227,328 2007-03-23 11:20:52 c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe

-c--a-w 49,152 2003-05-08 10:00:58 c:\programmi\ScanSoft\OmniPageSE2.0\bak\OpwareSE2.exe

-c--a-w 15,360 2004-08-19 13:39:36 c:\windows\system32\bak\ctfmon.exe
----a-w 15,360 2008-04-14 02:14:03 c:\windows\system32\ctfmon.exe

.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"BitTorrent DNA"="c:\programmi\BitTorrent_DNA\dna.exe" [N/A]
"BitComet"="f:\bitcomet\BitComet.exe" [N/A]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2005-10-24 307200]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-29 68856]
"H/PC Connection Agent"="F:\wcescomm.exe" [2005-08-05 1200128]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-11-17 1805552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Acrobat Assistant 7.0"="c:\programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 483328]
"OpwareSE2"="c:\programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [N/A]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"HP Software Update"="f:\programmi\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-03-28 413696]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"ArcSoft Connection Service"="c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AliceRE_McciTrayApp"="c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe" [2006-11-21 936960]
"Malwarebytes' Anti-Malware"="c:\programmi\Malwarebytes' Anti-Malware\mbamgui.exe" [2008-10-22 399504]
"VTTimer"="VTTimer.exe" [2003-05-07 c:\windows\system32\VTTimer.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"nwiz"="nwiz.exe" [2007-09-17 c:\windows\system32\nwiz.exe]
"Windowfdgfds DasdLL fgfdg Verifier"="WindowANTasdIVRI.exe" [2008-04-14 c:\windows\system32\WindowANTasdIVRI.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Windowfdgfds DasdLL fgfdg Verifier"="WindowANTasdIVRI.exe" [2008-04-14 c:\windows\system32\WindowANTasdIVRI.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\programmi\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"f:\rapimgr.exe"= f:\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"f:\wcescomm.exe"= f:\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"f:\wcesmgr.exe"= f:\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\emule\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"2263:TCP"= 2263:TCP:messenger

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-04 78416]
R2 ACDaemon;ArcSoft Connect Daemon;c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe [2008-10-06 102712]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-04 20560]
R2 MBAMService;MBAMService;"c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe" [2008-11-15 170640]
R3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys [2008-11-15 15504]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe []
S3 MEMSWEEP2;MEMSWEEP2; []
S4 hpt3xx;hpt3xx; []

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'

2007-12-14 c:\windows\Tasks\abmjmpu.job
- c:\windows\system32\netqqzwm.exe []

2007-12-05 c:\windows\Tasks\abrplmzg.job
- c:\windows\system32\netqqzwm.exe []

2007-07-06 c:\windows\Tasks\aibhpgy.job
- c:\windows\system32\netqqzwm.exe []

2007-08-31 c:\windows\Tasks\akgblg.job
- c:\windows\system32\netqqzwm.exe []

2008-01-27 c:\windows\Tasks\aleoagwt.job
- c:\windows\system32\netqqzwm.exe []

2007-12-09 c:\windows\Tasks\ank.job
- c:\windows\system32\netqqzwm.exe []

2007-12-03 c:\windows\Tasks\aob.job
- c:\windows\system32\netqqzwm.exe []

2008-01-20 c:\windows\Tasks\aqrgwoxx.job
- c:\windows\system32\netqqzwm.exe []

2007-09-07 c:\windows\Tasks\awhjj.job
- c:\windows\system32\netqqzwm.exe []

2008-02-19 c:\windows\Tasks\aycln.job
- c:\windows\system32\netqqzwm.exe []

2008-01-21 c:\windows\Tasks\bbigva.job
- c:\windows\system32\netqqzwm.exe []

2007-12-16 c:\windows\Tasks\bcpdi.job
- c:\windows\system32\netqqzwm.exe []

2007-10-16 c:\windows\Tasks\bhqzcnda.job
- c:\windows\system32\netqqzwm.exe []

2007-12-11 c:\windows\Tasks\bqtbw.job
- c:\windows\system32\netqqzwm.exe []

2007-07-13 c:\windows\Tasks\bujcnx.job
- c:\windows\system32\netqqzwm.exe []

2007-07-16 c:\windows\Tasks\bwinnt.job
- c:\windows\system32\netqqzwm.exe []

2008-01-23 c:\windows\Tasks\cbffaztp.job
- c:\windows\system32\netqqzwm.exe []

2007-08-30 c:\windows\Tasks\ccmchju.job
- c:\windows\system32\netqqzwm.exe []

2008-01-31 c:\windows\Tasks\cgh.job
- c:\windows\system32\netqqzwm.exe []

2007-11-16 c:\windows\Tasks\cmvcuxx.job
- c:\windows\system32\netqqzwm.exe []

2007-10-10 c:\windows\Tasks\ctid.job
- c:\windows\system32\netqqzwm.exe []

2007-09-10 c:\windows\Tasks\cvmh.job
- c:\windows\system32\netqqzwm.exe []

2008-01-31 c:\windows\Tasks\ddj.job
- c:\windows\system32\netqqzwm.exe []

2008-01-24 c:\windows\Tasks\deadlquf.job
- c:\windows\system32\netqqzwm.exe []

2008-01-25 c:\windows\Tasks\dgncrj.job
- c:\windows\system32\netqqzwm.exe []

2007-12-05 c:\windows\Tasks\dlfpt.job
- c:\windows\system32\netqqzwm.exe []

2007-06-28 c:\windows\Tasks\dlsmca.job
- c:\windows\system32\netqqzwm.exe []

2007-12-07 c:\windows\Tasks\dsnbzvbm.job
- c:\windows\system32\netqqzwm.exe []

2007-12-08 c:\windows\Tasks\dvabcl.job
- c:\windows\system32\netqqzwm.exe []

2007-09-06 c:\windows\Tasks\dxlfteg.job
- c:\windows\system32\netqqzwm.exe []

2007-10-26 c:\windows\Tasks\eakar.job
- c:\windows\system32\netqqzwm.exe []

2008-01-24 c:\windows\Tasks\ejoxnaph.job
- c:\windows\system32\netqqzwm.exe []

2007-07-08 c:\windows\Tasks\elha.job
- c:\windows\system32\netqqzwm.exe []

2007-12-10 c:\windows\Tasks\erep.job
- c:\windows\system32\netqqzwm.exe []

2008-02-15 c:\windows\Tasks\errsj.job
- c:\windows\system32\netqqzwm.exe []

2007-10-14 c:\windows\Tasks\erxk.job
- c:\windows\system32\netqqzwm.exe []

2007-11-09 c:\windows\Tasks\exermd.job
- c:\windows\system32\netqqzwm.exe []

2007-08-28 c:\windows\Tasks\exqy.job
- c:\windows\system32\netqqzwm.exe []

2008-01-29 c:\windows\Tasks\fapgx.job
- c:\windows\system32\netqqzwm.exe []

2007-09-16 c:\windows\Tasks\fla.job
- c:\windows\system32\netqqzwm.exe []

2008-02-12 c:\windows\Tasks\flin.job
- c:\windows\system32\netqqzwm.exe []

2007-12-12 c:\windows\Tasks\fnw.job
- c:\windows\system32\netqqzwm.exe []

2008-01-13 c:\windows\Tasks\ftfwzr.job
- c:\windows\system32\netqqzwm.exe []

2008-02-13 c:\windows\Tasks\fyse.job
- c:\windows\system32\netqqzwm.exe []

2007-10-16 c:\windows\Tasks\fyusrb.job
- c:\windows\system32\netqqzwm.exe []

2007-12-31 c:\windows\Tasks\fztcjz.job
- c:\windows\system32\netqqzwm.exe []

2007-10-18 c:\windows\Tasks\gbgdtjs.job
- c:\windows\system32\netqqzwm.exe []

2007-11-03 c:\windows\Tasks\gckccpbw.job
- c:\windows\system32\netqqzwm.exe []

2008-01-19 c:\windows\Tasks\ggdfi.job
- c:\windows\system32\netqqzwm.exe []

2008-01-08 c:\windows\Tasks\gonkaonz.job
- c:\windows\system32\netqqzwm.exe []

2008-02-17 c:\windows\Tasks\guux.job
- c:\windows\system32\netqqzwm.exe []

2007-12-27 c:\windows\Tasks\hbjef.job
- c:\windows\system32\netqqzwm.exe []

2007-10-04 c:\windows\Tasks\hbptjbc.job
- c:\windows\system32\netqqzwm.exe []

2008-02-05 c:\windows\Tasks\hexu.job
- c:\windows\system32\netqqzwm.exe []

2008-01-04 c:\windows\Tasks\hjqkgfh.job
- c:\windows\system32\netqqzwm.exe []

2008-02-17 c:\windows\Tasks\hkcpddt.job
- c:\windows\system32\netqqzwm.exe []

2007-07-24 c:\windows\Tasks\hkpaqkha.job
- c:\windows\system32\netqqzwm.exe []

2008-02-21 c:\windows\Tasks\hrvbe.job
- c:\windows\system32\netqqzwm.exe []

2007-10-03 c:\windows\Tasks\huo.job
- c:\windows\system32\netqqzwm.exe []

2007-11-17 c:\windows\Tasks\huw.job
- c:\windows\system32\netqqzwm.exe []

2007-09-06 c:\windows\Tasks\hxpy.job
- c:\windows\system32\netqqzwm.exe []

2007-10-14 c:\windows\Tasks\icw.job
- c:\windows\system32\netqqzwm.exe []

2007-10-03 c:\windows\Tasks\ieqxhvyv.job
- c:\windows\system32\netqqzwm.exe []

2007-11-25 c:\windows\Tasks\ijok.job
- c:\windows\system32\netqqzwm.exe []

2007-10-15 c:\windows\Tasks\inoud.job
- c:\windows\system32\netqqzwm.exe []

2007-09-02 c:\windows\Tasks\irvs.job
- c:\windows\system32\netqqzwm.exe []

2008-02-29 c:\windows\Tasks\isvw.job
- c:\windows\system32\netqqzwm.exe []

2007-11-08 c:\windows\Tasks\iuj.job
- c:\windows\system32\netqqzwm.exe []

2007-12-10 c:\windows\Tasks\ixqei.job
- c:\windows\system32\netqqzwm.exe []

2007-07-05 c:\windows\Tasks\javzhet.job
- c:\windows\system32\netqqzwm.exe []

2007-12-23 c:\windows\Tasks\jehqffdt.job
- c:\windows\system32\netqqzwm.exe []

2007-12-06 c:\windows\Tasks\jhu.job
- c:\windows\system32\netqqzwm.exe []

2007-08-08 c:\windows\Tasks\jixkgfwm.job
- c:\windows\system32\netqqzwm.exe []

2007-07-21 c:\windows\Tasks\jkakqk.job
- c:\windows\system32\netqqzwm.exe []

2007-08-30 c:\windows\Tasks\jngogkhd.job
- c:\windows\system32\netqqzwm.exe []

2007-07-20 c:\windows\Tasks\jryy.job
- c:\windows\system32\netqqzwm.exe []

2007-12-27 c:\windows\Tasks\jupzy.job
- c:\windows\system32\netqqzwm.exe []

2008-03-01 c:\windows\Tasks\kct.job
- c:\windows\system32\netqqzwm.exe []

2007-10-30 c:\windows\Tasks\kfvqpuqs.job
- c:\windows\system32\netqqzwm.exe []

2007-11-23 c:\windows\Tasks\kigcb.job
- c:\windows\system32\netqqzwm.exe []

2007-10-17 c:\windows\Tasks\kjjbt.job
- c:\windows\system32\netqqzwm.exe []

2007-10-13 c:\windows\Tasks\kogkvwpc.job
- c:\windows\system32\netqqzwm.exe []

2007-11-27 c:\windows\Tasks\lcrxhgqv.job
- c:\windows\system32\netqqzwm.exe []

2007-08-31 c:\windows\Tasks\lgkmi.job
- c:\windows\system32\netqqzwm.exe []

2007-11-18 c:\windows\Tasks\liajreo.job
- c:\windows\system32\netqqzwm.exe []

2007-09-26 c:\windows\Tasks\lpkiqudp.job
- c:\windows\system32\netqqzwm.exe []

2008-01-11 c:\windows\Tasks\lra.job
- c:\windows\system32\netqqzwm.exe []

2008-01-12 c:\windows\Tasks\lrhvm.job
- c:\windows\system32\netqqzwm.exe []

2007-12-15 c:\windows\Tasks\lrjecna.job
- c:\windows\system32\netqqzwm.exe []

2008-11-16 c:\windows\Tasks\Malwarebytes' Scheduled Scan for enrico.job
- c:\programmi\Malwarebytes' Anti-Malware\mbam.exe [2008-10-22 16:10]

2008-11-16 c:\windows\Tasks\Malwarebytes' Scheduled Update for enrico.job
- c:\programmi\Malwarebytes' Anti-Malware\mbam.exe [2008-10-22 16:10]

2008-02-09 c:\windows\Tasks\mbgid.job
- c:\windows\system32\netqqzwm.exe []

2008-01-03 c:\windows\Tasks\mcrwgmfv.job
- c:\windows\system32\netqqzwm.exe []

2007-11-10 c:\windows\Tasks\mfvo.job
- c:\windows\system32\netqqzwm.exe []

2008-01-10 c:\windows\Tasks\mgyxem.job
- c:\windows\system32\netqqzwm.exe []

2007-10-25 c:\windows\Tasks\mjyrgt.job
- c:\windows\system32\netqqzwm.exe []

2007-12-31 c:\windows\Tasks\mktmwtt.job
- c:\windows\system32\netqqzwm.exe []

2008-02-13 c:\windows\Tasks\mlqx.job
- c:\windows\system32\netqqzwm.exe []

2008-02-17 c:\windows\Tasks\mnudfnxa.job
- c:\windows\system32\netqqzwm.exe []

2007-12-23 c:\windows\Tasks\moivky.job
- c:\windows\system32\netqqzwm.exe []

2008-11-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

2007-12-15 c:\windows\Tasks\mrmguo.job
- c:\windows\system32\netqqzwm.exe []

2007-10-01 c:\windows\Tasks\mvtpi.job
- c:\windows\system32\netqqzwm.exe []

2007-12-09 c:\windows\Tasks\mxp.job
- c:\windows\system32\netqqzwm.exe []

2007-07-19 c:\windows\Tasks\mzerwr.job
- c:\windows\system32\netqqzwm.exe []

2007-12-06 c:\windows\Tasks\nfgdcki.job
- c:\windows\system32\netqqzwm.exe []

2007-10-05 c:\windows\Tasks\ngu.job
- c:\windows\system32\netqqzwm.exe []

2007-09-16 c:\windows\Tasks\nocm.job
- c:\windows\system32\netqqzwm.exe []

2007-12-28 c:\windows\Tasks\noiyrh.job
- c:\windows\system32\netqqzwm.exe []

2008-01-22 c:\windows\Tasks\nonxpu.job
- c:\windows\system32\netqqzwm.exe []

2007-12-22 c:\windows\Tasks\oajltytd.job
- c:\windows\system32\netqqzwm.exe []

2008-01-16 c:\windows\Tasks\oaprb.job
- c:\windows\system32\netqqzwm.exe []

2007-10-09 c:\windows\Tasks\oct.job
- c:\windows\system32\netqqzwm.exe []

2007-07-06 c:\windows\Tasks\ogacfmf.job
- c:\windows\system32\netqqzwm.exe []

2007-12-06 c:\windows\Tasks\olbs.job
- c:\windows\system32\netqqzwm.exe []

2008-02-29 c:\windows\Tasks\olkduggz.job
- c:\windows\system32\netqqzwm.exe []

2007-12-14 c:\windows\Tasks\oxhwydh.job
- c:\windows\system32\netqqzwm.exe []

2007-09-16 c:\windows\Tasks\pec.job
- c:\windows\system32\netqqzwm.exe []

2007-08-09 c:\windows\Tasks\pmlxonn.job
- c:\windows\system32\netqqzwm.exe []

2008-01-02 c:\windows\Tasks\pmxkm.job
- c:\windows\system32\netqqzwm.exe []

2007-09-16 c:\windows\Tasks\pnlnld.job
- c:\windows\system32\netqqzwm.exe []

2007-11-10 c:\windows\Tasks\poe.job
- c:\windows\system32\netqqzwm.exe []

2007-12-13 c:\windows\Tasks\pogvr.job
- c:\windows\system32\netqqzwm.exe []

2007-12-01 c:\windows\Tasks\ppbrphmo.job
- c:\windows\system32\netqqzwm.exe []

2007-12-18 c:\windows\Tasks\pqdwhfmx.job
- c:\windows\system32\netqqzwm.exe []

2008-02-20 c:\windows\Tasks\pry.job
- c:\windows\system32\netqqzwm.exe []

2008-01-13 c:\windows\Tasks\puxnnpqr.job
- c:\windows\system32\netqqzwm.exe []

2007-12-03 c:\windows\Tasks\pvsaxg.job
- c:\windows\system32\netqqzwm.exe []

2007-07-07 c:\windows\Tasks\pyyskpuq.job
- c:\windows\system32\netqqzwm.exe []

2007-08-02 c:\windows\Tasks\pzhtm.job
- c:\windows\system32\netqqzwm.exe []

2007-11-10 c:\windows\Tasks\pzsf.job
- c:\windows\system32\netqqzwm.exe []

2007-08-04 c:\windows\Tasks\qbwoorn.job
- c:\windows\system32\netqqzwm.exe []

2007-10-05 c:\windows\Tasks\qdotnai.job
- c:\windows\system32\netqqzwm.exe []

2007-09-24 c:\windows\Tasks\qemk.job
- c:\windows\system32\netqqzwm.exe []

2007-11-29 c:\windows\Tasks\qmsinqbd.job
- c:\windows\system32\netqqzwm.exe []

2007-11-03 c:\windows\Tasks\qny.job
- c:\windows\system32\netqqzwm.exe []

2007-12-09 c:\windows\Tasks\qoe.job
- c:\windows\system32\netqqzwm.exe []

2007-12-25 c:\windows\Tasks\qsqqijcu.job
- c:\windows\system32\netqqzwm.exe []

2007-09-30 c:\windows\Tasks\qtje.job
- c:\windows\system32\netqqzwm.exe []

2007-07-08 c:\windows\Tasks\qxiyhxoe.job
- c:\windows\system32\netqqzwm.exe []

2007-12-15 c:\windows\Tasks\qysvkwpp.job
- c:\windows\system32\netqqzwm.exe []

2008-02-23 c:\windows\Tasks\qzzwal.job
- c:\windows\system32\netqqzwm.exe []

2008-02-17 c:\windows\Tasks\rgojn.job
- c:\windows\system32\netqqzwm.exe []

2008-01-26 c:\windows\Tasks\rltzrmj.job
- c:\windows\system32\netqqzwm.exe []

2007-12-07 c:\windows\Tasks\rlwj.job
- c:\windows\system32\netqqzwm.exe []

2007-09-16 c:\windows\Tasks\rpandv.job
- c:\windows\system32\netqqzwm.exe []

2008-01-05 c:\windows\Tasks\rrboqlw.job
- c:\windows\system32\netqqzwm.exe []

2007-07-22 c:\windows\Tasks\rwqtix.job
- c:\windows\system32\netqqzwm.exe []

2007-12-27 c:\windows\Tasks\saqs.job
- c:\windows\system32\netqqzwm.exe []

2007-12-02 c:\windows\Tasks\sbyupr.job
- c:\windows\system32\netqqzwm.exe []

2008-02-08 c:\windows\Tasks\scqkf.job
- c:\windows\system32\netqqzwm.exe []

2007-07-27 c:\windows\Tasks\sehnbfq.job
- c:\windows\system32\netqqzwm.exe []

2007-09-17 c:\windows\Tasks\ski.job
- c:\windows\system32\netqqzwm.exe []

2007-08-07 c:\windows\Tasks\smjp.job
- c:\windows\system32\netqqzwm.exe []

2008-02-09 c:\windows\Tasks\soxcdlll.job
- c:\windows\system32\netqqzwm.exe []

2007-12-20 c:\windows\Tasks\spkjv.job
- c:\windows\system32\netqqzwm.exe []

2007-07-12 c:\windows\Tasks\spyy.job
- c:\windows\system32\netqqzwm.exe []

2008-01-29 c:\windows\Tasks\ssoaksda.job
- c:\windows\system32\netqqzwm.exe []

2007-11-18 c:\windows\Tasks\syp.job
- c:\windows\system32\netqqzwm.exe []

2007-09-16 c:\windows\Tasks\szao.job
- c:\windows\system32\netqqzwm.exe []

2007-11-13 c:\windows\Tasks\thyqg.job
- c:\windows\system32\netqqzwm.exe []

2007-08-05 c:\windows\Tasks\tinsnj.job
- c:\windows\system32\netqqzwm.exe []

2007-12-04 c:\windows\Tasks\tohj.job
- c:\windows\system32\netqqzwm.exe []

2007-09-20 c:\windows\Tasks\tqfg.job
- c:\windows\system32\netqqzwm.exe []

2007-12-19 c:\windows\Tasks\trxskhag.job
- c:\windows\system32\netqqzwm.exe []

2007-12-08 c:\windows\Tasks\tuqvpsr.job
- c:\windows\system32\netqqzwm.exe []

2007-12-09 c:\windows\Tasks\tvmzoluv.job
- c:\windows\system32\netqqzwm.exe []

2007-09-25 c:\windows\Tasks\twum.job
- c:\windows\system32\netqqzwm.exe []

2008-01-24 c:\windows\Tasks\txic.job
- c:\windows\system32\netqqzwm.exe []

2008-01-31 c:\windows\Tasks\uohyc.job
- c:\windows\system32\netqqzwm.exe []

2007-12-21 c:\windows\Tasks\utq.job
- c:\windows\system32\netqqzwm.exe []

2007-10-16 c:\windows\Tasks\uuuquuao.job
- c:\windows\system32\netqqzwm.exe []

2007-07-23 c:\windows\Tasks\uvvbr.job
- c:\windows\system32\netqqzwm.exe []

2008-01-12 c:\windows\Tasks\vadadc.job
- c:\windows\system32\netqqzwm.exe []

2008-01-07 c:\windows\Tasks\vca.job
- c:\windows\system32\netqqzwm.exe []

2007-08-03 c:\windows\Tasks\vemj.job
- c:\windows\system32\netqqzwm.exe []

2008-01-12 c:\windows\Tasks\vjrssyjc.job
- c:\windows\system32\netqqzwm.exe []

2007-09-10 c:\windows\Tasks\vzdufno.job
- c:\windows\system32\netqqzwm.exe []

2008-02-21 c:\windows\Tasks\vzfx.job
- c:\windows\system32\netqqzwm.exe []

2007-12-09 c:\windows\Tasks\whpd.job
- c:\windows\system32\netqqzwm.exe []

2007-08-01 c:\windows\Tasks\wiw.job
- c:\windows\system32\netqqzwm.exe []

2008-02-07 c:\windows\Tasks\wlr.job
- c:\windows\system32\netqqzwm.exe []

2007-12-01 c:\windows\Tasks\wnjmty.job
- c:\windows\system32\netqqzwm.exe []

2007-08-01 c:\windows\Tasks\wnulaw.job
- c:\windows\system32\netqqzwm.exe []

2007-11-01 c:\windows\Tasks\wophd.job
- c:\windows\system32\netqqzwm.exe []

2007-12-02 c:\windows\Tasks\wpybkn.job
- c:\windows\system32\netqqzwm.exe []

2008-01-13 c:\windows\Tasks\wqnpmgvl.job
- c:\windows\system32\netqqzwm.exe []

2007-12-29 c:\windows\Tasks\wqxbke.job
- c:\windows\system32\netqqzwm.exe []

2008-01-12 c:\windows\Tasks\wtzr.job
- c:\windows\system32\netqqzwm.exe []

2007-11-13 c:\windows\Tasks\wwcodxq.job
- c:\windows\system32\netqqzwm.exe []

2007-11-07 c:\windows\Tasks\wxft.job
- c:\windows\system32\netqqzwm.exe []

2007-11-18 c:\windows\Tasks\wzqxek.job
- c:\windows\system32\netqqzwm.exe []

2008-01-28 c:\windows\Tasks\xaaariut.job
- c:\windows\system32\netqqzwm.exe []

2007-12-26 c:\windows\Tasks\xbychnij.job
- c:\windows\system32\netqqzwm.exe []

2007-12-02 c:\windows\Tasks\xpnbaeg.job
- c:\windows\system32\netqqzwm.exe []

2007-11-08 c:\windows\Tasks\xqusvowh.job
- c:\windows\system32\netqqzwm.exe []

2008-01-31 c:\windows\Tasks\xrhbtvb.job
- c:\windows\system32\netqqzwm.exe []

2008-01-13 c:\windows\Tasks\xtkbb.job
- c:\windows\system32\netqqzwm.exe []

2007-07-20 c:\windows\Tasks\xyrui.job
- c:\windows\system32\netqqzwm.exe []

2007-12-23 c:\windows\Tasks\xzfqsmhx.job
- c:\windows\system32\netqqzwm.exe []

2008-02-07 c:\windows\Tasks\ybxd.job
- c:\windows\system32\netqqzwm.exe []

2007-10-15 c:\windows\Tasks\ydiowwn.job
- c:\windows\system32\netqqzwm.exe []

2008-01-21 c:\windows\Tasks\yipgom.job
- c:\windows\system32\netqqzwm.exe []

2007-09-18 c:\windows\Tasks\ykzwmcx.job
- c:\windows\system32\netqqzwm.exe []

2007-11-15 c:\windows\Tasks\ylfwzilm.job
- c:\windows\system32\netqqzwm.exe []

2008-02-23 c:\windows\Tasks\yvey.job
- c:\windows\system32\netqqzwm.exe []

2007-07-22 c:\windows\Tasks\zbebu.job
- c:\windows\system32\netqqzwm.exe []

2007-07-23 c:\windows\Tasks\zgrbz.job
- c:\windows\system32\netqqzwm.exe []

2007-09-29 c:\windows\Tasks\zis.job
- c:\windows\system32\netqqzwm.exe []

2007-09-09 c:\windows\Tasks\zlpnnta.job
- c:\windows\system32\netqqzwm.exe []

2007-11-15 c:\windows\Tasks\zoxum.job
- c:\windows\system32\netqqzwm.exe []

2007-11-19 c:\windows\Tasks\zrbqka.job
- c:\windows\system32\netqqzwm.exe []

2007-12-02 c:\windows\Tasks\zxhbiskx.job
- c:\windows\system32\netqqzwm.exe []

2008-02-22 c:\windows\Tasks\zym.job
- c:\windows\system32\netqqzwm.exe []

2007-10-23 c:\windows\Tasks\zzbv.job
- c:\windows\system32\netqqzwm.exe []
.
.
------- Supplementare di scansione -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to AMV Converter... - c:\programmi\MP3 Player Utilities 4.15\AMVConverter\grab.html
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti nel file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\programmi\MP3 Player Utilities 4.15\MediaManager\grab.html
TCP: {B1A92480-049C-48EC-A329-D43338B1B63C} = 192.168.1.1

O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\Account.dll - O16 -: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4}
hxxp://www.tele2mail.com/static/apps/utils/AccountHelper.cab
c:\windows\Downloaded Program Files\Account.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-19 22:04:43
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-11-19 22:07:59
ComboFix-quarantined-files.txt 2008-11-19 21:07:55

Pre-Run: 16,783,593,472 byte disponibili
Post-Run: 17,077,219,328 byte disponibili

WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

656 --- E O F --- 2008-11-13 16:08:09

questo invece è il log hijack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.12.59, on 19/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmi\Windows Defender\MSASCui.exe
F:\Programmi\HP\HP Software Update\HPWuSchd.exe
C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\wcescomm.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
F:\rapimgr.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
F:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [OpwareSE2] "C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] "F:\Programmi\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\Run: [AliceRE_McciTrayApp] C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunServices: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\RunOnce: [InstallHelper C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer] "C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer\InstallHelper.exe" "/DIR=C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmi\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BitComet] "F:\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_7 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\wcescomm.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
O4 - Global Startup: Digisoft AntiDialer.lnk = F:\Digisoft AntiDialer\AntiDialer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = F:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\Programmi\MP3 Player Utilities 4.15\AMVConverter\grab.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Programmi\MP3 Player Utilities 4.15\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra 'Tools' menuitem: Crea preferito portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: Alice - {AD01FB3B-8AD7-4994-82BE-3B7E6F4E14C1} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197568262529
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://www.tele2mail.com/static/apps/utils/AccountHelper.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6449E0AC-867A-4BD8-9DC5-B2AA42499B9D}: NameServer = 85.37.17.44 85.38.28.90
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A92480-049C-48EC-A329-D43338B1B63C}: NameServer = 192.168.1.1
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Network WanMiniport First Position - Unknown owner - C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 12850 bytes

attendo disposizioni !!!!!!!!!!!!!!!!
ciao e grazie
r16
Inviato: Wednesday, November 19, 2008 10:50:30 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Mi viene da piangere..........Sick
Oltre a infezioni varie, hai anche un grosso Dialer.
Scarica FindAWF:
http://noahdfear.geekstogo.com/FindAWF.exe 3. Esegui FindAWF,premi un tasto qualsiasi,poi premi il tasto 1 e INVIO, aspetti il log che FindAWF stamperà su un file di testo alla fine della ricerca.
Il filelog lo posti in questa discussione.
Poi ci sarà da fare un lungo script con Avenger, dovrai pazientare.
nuvolaneuve
Inviato: Wednesday, November 19, 2008 11:06:34 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
ecco fatto, scusami non volevo essere irruente!
se a te vien da pingere io ke faccio?
il log di findawf:


Find AWF report by noahdfear ©2006
Version 1.40



bak folders found
~~~~~~~~~~~

Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\MESSEN~1\BAK

0 File 0 byte
2 Directory 17.096.880.128 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\WINDOWS\SYSTEM32\BAK

19/08/2004 14.39 15.360 ctfmon.exe
1 File 15.360 byte
2 Directory 17.096.880.128 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\MICROS~3\OFFICE12\BAK

26/10/2006 23.47 31.016 GrooveMonitor.exe
1 File 31.016 byte
2 Directory 17.096.876.032 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\NOKIA\NOKIAP~1\BAK

23/03/2007 12.20 227.328 LaunchApplication.exe
1 File 227.328 byte
2 Directory 17.096.876.032 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\SCANSOFT\OMNIPA~1.0\BAK

08/05/2003 11.00 49.152 OpwareSE2.exe
1 File 49.152 byte
2 Directory 17.096.876.032 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\ADOBE\ACROBA~1.0\DISTILLR\BAK

14/12/2004 01.12 483.328 Acrotray.exe
1 File 483.328 byte
2 Directory 17.096.876.032 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\FILECO~1\AHEAD\LIB\BAK

12/01/2006 14.40 155.648 NeroCheck.exe
16/11/2006 18.04 139.264 NMBgMonitor.exe
2 File 294.912 byte
2 Directory 17.096.876.032 byte disponibili


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

15360 14 Apr 2008 "C:\WINDOWS\system32\ctfmon.exe"
15360 19 Aug 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
31016 26 Oct 2006 "C:\Programmi\Microsoft Office\Office12\bak\GrooveMonitor.exe"
227328 23 Mar 2007 "C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe"
227328 23 Mar 2007 "C:\Programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe"
49152 8 May 2003 "C:\Programmi\ScanSoft\OmniPageSE2.0\bak\OpwareSE2.exe"
483328 12 Jan 2006 "C:\Programmi\Adobe\Acrobat 7.0\Distillr\AcroTray.exe"
483328 14 Dec 2004 "C:\Programmi\Adobe\Acrobat 7.0\Distillr\bak\Acrotray.exe"
153136 1 Mar 2007 "C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe"
155648 12 Jan 2006 "C:\Programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe"
202024 20 Sep 2007 "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
139264 16 Nov 2006 "C:\Programmi\File comuni\Ahead\Lib\bak\NMBgMonitor.exe"


end of report
ciao e ancora grazie
r16
Inviato: Thursday, November 20, 2008 12:17:34 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Non ho più lacrime.........Drool
Scarica questo:Avenger, scompatta Avenger all'interno di una apposita cartella.
http://swandog46.geekstogo.com/avenger.zip

Avvia AVENGER
Clicca Ok
Inserisci queste righe (fai capia-incolla) nel riquadro bianco: (quelle in neretto)

Files to delete:
c:\windows\Tasks\abmjmpu.job
c:\windows\Tasks\abrplmzg.job
c:\windows\Tasks\aibhpgy.job
c:\windows\Tasks\akgblg.job
c:\windows\Tasks\aleoagwt.job
c:\windows\Tasks\ank.job
c:\windows\Tasks\aob.job
c:\windows\Tasks\aqrgwoxx.job
c:\windows\Tasks\awhjj.job
c:\windows\Tasks\aycln.job
c:\windows\Tasks\bbigva.job
c:\windows\Tasks\bcpdi.job
c:\windows\Tasks\bhqzcnda.job
c:\windows\Tasks\bqtbw.job
c:\windows\Tasks\bujcnx.job
c:\windows\Tasks\bwinnt.job
c:\windows\Tasks\cbffaztp.job
c:\windows\Tasks\ccmchju.job
c:\windows\Tasks\cgh.job
c:\windows\Tasks\cmvcuxx.job
c:\windows\Tasks\ctid.job
c:\windows\Tasks\cvmh.job
c:\windows\Tasks\ddj.job
c:\windows\Tasks\deadlquf.job
c:\windows\Tasks\dgncrj.job
c:\windows\Tasks\dlfpt.job
c:\windows\Tasks\dlsmca.job
c:\windows\Tasks\dsnbzvbm.job
c:\windows\Tasks\dvabcl.job
c:\windows\Tasks\dxlfteg.job
c:\windows\Tasks\eakar.job
c:\windows\Tasks\ejoxnaph.job
c:\windows\Tasks\elha.job
c:\windows\Tasks\erep.job
c:\windows\Tasks\errsj.job
c:\windows\Tasks\erxk.job
c:\windows\Tasks\exermd.job
c:\windows\Tasks\exqy.job
c:\windows\Tasks\fapgx.job
c:\windows\Tasks\fla.job
c:\windows\Tasks\flin.job
c:\windows\Tasks\fnw.job
c:\windows\Tasks\ftfwzr.job
c:\windows\Tasks\fyse.job
c:\windows\Tasks\fyusrb.job
c:\windows\Tasks\fztcjz.job
c:\windows\Tasks\gbgdtjs.job
c:\windows\Tasks\gckccpbw.job
c:\windows\Tasks\ggdfi.job
c:\windows\Tasks\gonkaonz.job
c:\windows\Tasks\guux.job
c:\windows\Tasks\hbjef.job
c:\windows\Tasks\hbptjbc.job
c:\windows\Tasks\hexu.job
c:\windows\Tasks\hjqkgfh.job
c:\windows\Tasks\hkcpddt.job
c:\windows\Tasks\hkpaqkha.job
c:\windows\Tasks\hrvbe.job
c:\windows\Tasks\huo.job
c:\windows\Tasks\huw.job
c:\windows\Tasks\hxpy.job
c:\windows\Tasks\icw.job
c:\windows\Tasks\ieqxhvyv.job
c:\windows\Tasks\ijok.job
c:\windows\Tasks\inoud.job
c:\windows\Tasks\irvs.job
c:\windows\Tasks\isvw.job
c:\windows\Tasks\iuj.job
c:\windows\Tasks\ixqei.job
c:\windows\Tasks\javzhet.job
c:\windows\Tasks\jehqffdt.job
c:\windows\Tasks\jhu.job
c:\windows\Tasks\jixkgfwm.job
c:\windows\Tasks\jkakqk.job
c:\windows\Tasks\jngogkhd.job
c:\windows\Tasks\jryy.job
c:\windows\Tasks\jupzy.job
c:\windows\Tasks\kct.job
c:\windows\Tasks\kfvqpuqs.job
c:\windows\Tasks\kigcb.job
c:\windows\Tasks\kjjbt.job
c:\windows\Tasks\kogkvwpc.job
c:\windows\Tasks\lcrxhgqv.job
c:\windows\Tasks\lgkmi.job
c:\windows\Tasks\liajreo.job
c:\windows\Tasks\lpkiqudp.job
c:\windows\Tasks\lra.job
c:\windows\Tasks\lrhvm.job
c:\windows\Tasks\lrjecna.job
c:\windows\Tasks\Malwarebytes' Scheduled Scan for enrico.job
c:\windows\Tasks\Malwarebytes' Scheduled Update for enrico.job
c:\windows\Tasks\mbgid.job
c:\windows\Tasks\mcrwgmfv.job
c:\windows\Tasks\mfvo.job
c:\windows\Tasks\mgyxem.job
c:\windows\Tasks\mjyrgt.job
c:\windows\Tasks\mktmwtt.job
c:\windows\Tasks\mlqx.job
c:\windows\Tasks\mnudfnxa.job
c:\windows\Tasks\moivky.job
c:\windows\Tasks\MP Scheduled Scan.job
c:\windows\Tasks\mrmguo.job
c:\windows\Tasks\mvtpi.job
c:\windows\Tasks\mxp.job
c:\windows\Tasks\mzerwr.job
c:\windows\Tasks\nfgdcki.job
c:\windows\Tasks\ngu.job
c:\windows\Tasks\nocm.job
c:\windows\Tasks\noiyrh.job
c:\windows\Tasks\nonxpu.job
c:\windows\Tasks\oajltytd.job
c:\windows\Tasks\oaprb.job
c:\windows\Tasks\oct.job
c:\windows\Tasks\ogacfmf.job
c:\windows\Tasks\olbs.job
c:\windows\Tasks\olkduggz.job
c:\windows\Tasks\oxhwydh.job
c:\windows\Tasks\pec.job
c:\windows\Tasks\pmlxonn.job
c:\windows\Tasks\pmxkm.job
c:\windows\Tasks\pnlnld.job
c:\windows\Tasks\poe.job
c:\windows\Tasks\pogvr.job
c:\windows\Tasks\ppbrphmo.job
c:\windows\Tasks\pqdwhfmx.job
c:\windows\Tasks\pry.job
c:\windows\Tasks\puxnnpqr.job
c:\windows\Tasks\pvsaxg.job
c:\windows\Tasks\pyyskpuq.job
c:\windows\Tasks\pzhtm.job
c:\windows\Tasks\pzsf.job
c:\windows\Tasks\qbwoorn.job
c:\windows\Tasks\qdotnai.job
c:\windows\Tasks\qemk.job
c:\windows\Tasks\qmsinqbd.job
c:\windows\Tasks\qny.job
c:\windows\Tasks\qoe.job
c:\windows\Tasks\qsqqijcu.job
c:\windows\Tasks\qtje.job
c:\windows\Tasks\qxiyhxoe.job
c:\windows\Tasks\qysvkwpp.job
c:\windows\Tasks\qzzwal.job
c:\windows\Tasks\rgojn.job
c:\windows\Tasks\rltzrmj.job
c:\windows\Tasks\rlwj.job
c:\windows\Tasks\rpandv.job
c:\windows\Tasks\rrboqlw.job
c:\windows\Tasks\rwqtix.job
c:\windows\Tasks\saqs.job
c:\windows\Tasks\sbyupr.job
c:\windows\Tasks\scqkf.job
c:\windows\Tasks\sehnbfq.job
c:\windows\Tasks\ski.job
c:\windows\Tasks\smjp.job
c:\windows\Tasks\soxcdlll.job
c:\windows\Tasks\spkjv.job
c:\windows\Tasks\spyy.job
c:\windows\Tasks\ssoaksda.job
c:\windows\Tasks\syp.job
c:\windows\Tasks\szao.job
c:\windows\Tasks\thyqg.job
c:\windows\Tasks\tinsnj.job
c:\windows\Tasks\tohj.job
c:\windows\Tasks\tqfg.job
c:\windows\Tasks\trxskhag.job
c:\windows\Tasks\tuqvpsr.job
c:\windows\Tasks\tvmzoluv.job
c:\windows\Tasks\twum.job
c:\windows\Tasks\txic.job
c:\windows\Tasks\uohyc.job
c:\windows\Tasks\utq.job
c:\windows\Tasks\uuuquuao.job
c:\windows\Tasks\uvvbr.job
c:\windows\Tasks\vadadc.job
c:\windows\Tasks\vca.job
c:\windows\Tasks\vemj.job
c:\windows\Tasks\vjrssyjc.job
c:\windows\Tasks\vzdufno.job
c:\windows\Tasks\vzfx.job
c:\windows\Tasks\whpd.job
c:\windows\Tasks\wiw.job
c:\windows\Tasks\wlr.job
c:\windows\Tasks\wnjmty.job
c:\windows\Tasks\wnulaw.job
c:\windows\Tasks\wophd.job
c:\windows\Tasks\wpybkn.job
c:\windows\Tasks\wqnpmgvl.job
c:\windows\Tasks\wqxbke.job
c:\windows\Tasks\wtzr.job
c:\windows\Tasks\wwcodxq.job
c:\windows\Tasks\wxft.job
c:\windows\Tasks\wzqxek.job
c:\windows\Tasks\xaaariut.job
c:\windows\Tasks\xbychnij.job
c:\windows\Tasks\xpnbaeg.job
c:\windows\Tasks\xqusvowh.job
c:\windows\Tasks\xrhbtvb.job
c:\windows\Tasks\xtkbb.job
c:\windows\Tasks\xyrui.job
c:\windows\Tasks\xzfqsmhx.job
c:\windows\Tasks\ybxd.job
c:\windows\Tasks\ydiowwn.job
c:\windows\Tasks\yipgom.job
c:\windows\Tasks\ykzwmcx.job
c:\windows\Tasks\ylfwzilm.job
c:\windows\Tasks\yvey.job
c:\windows\Tasks\zbebu.job
c:\windows\Tasks\zgrbz.job
c:\windows\Tasks\zis.job
c:\windows\Tasks\zlpnnta.job
c:\windows\Tasks\zoxum.job
c:\windows\Tasks\zrbqka.job
c:\windows\Tasks\zxhbiskx.job
c:\windows\Tasks\zym.job
c:\windows\Tasks\zzbv.job
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\AcroTray.exe
C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe


Files to move:
C:\WINDOWS\system32\bak\ctfmon.exe|C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Microsoft Office\Office12\bak\GrooveMonitor.exe|C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe|C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\ScanSoft\OmniPageSE2.0\bak\OpwareSE2.exe|C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\bak\Acrotray.exe|C:\Programmi\Adobe\Acrobat 7.0\Distillr\AcroTray.exe
C:\Programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe|C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
C:\Programmi\File comuni\Ahead\Lib\bak\NMBgMonitor.exe|C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe




Clicca su Execute
Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
Al termine dell'operazione, posta qui il risultato di Avenger

Poi disistalla Malwarebytes, che è infettato, RIAVVIA IL PC, dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
REISTALLA Malwarebytes, lo AGGIORNI, fai una scansione completa, e mi posti il log.
RIFAI LA SCANSIONE CON FindAWF e mi posti il log.
Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO

Rifai un'altra scansione con Combofix e mi posti il log.


nuvolaneuve
Inviato: Thursday, November 20, 2008 11:36:05 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
ecco r16, ho impiegato un pò di tempo ma ho fatto tutto

- log avenger:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "c:\windows\Tasks\abmjmpu.job" deleted successfully.
File "c:\windows\Tasks\abrplmzg.job" deleted successfully.
File "c:\windows\Tasks\aibhpgy.job" deleted successfully.
File "c:\windows\Tasks\akgblg.job" deleted successfully.
File "c:\windows\Tasks\aleoagwt.job" deleted successfully.
File "c:\windows\Tasks\ank.job" deleted successfully.
File "c:\windows\Tasks\aob.job" deleted successfully.
File "c:\windows\Tasks\aqrgwoxx.job" deleted successfully.
File "c:\windows\Tasks\awhjj.job" deleted successfully.
File "c:\windows\Tasks\aycln.job" deleted successfully.
File "c:\windows\Tasks\bbigva.job" deleted successfully.
File "c:\windows\Tasks\bcpdi.job" deleted successfully.
File "c:\windows\Tasks\bhqzcnda.job" deleted successfully.
File "c:\windows\Tasks\bqtbw.job" deleted successfully.
File "c:\windows\Tasks\bujcnx.job" deleted successfully.
File "c:\windows\Tasks\bwinnt.job" deleted successfully.
File "c:\windows\Tasks\cbffaztp.job" deleted successfully.
File "c:\windows\Tasks\ccmchju.job" deleted successfully.
File "c:\windows\Tasks\cgh.job" deleted successfully.
File "c:\windows\Tasks\cmvcuxx.job" deleted successfully.
File "c:\windows\Tasks\ctid.job" deleted successfully.
File "c:\windows\Tasks\cvmh.job" deleted successfully.
File "c:\windows\Tasks\ddj.job" deleted successfully.
File "c:\windows\Tasks\deadlquf.job" deleted successfully.
File "c:\windows\Tasks\dgncrj.job" deleted successfully.
File "c:\windows\Tasks\dlfpt.job" deleted successfully.
File "c:\windows\Tasks\dlsmca.job" deleted successfully.
File "c:\windows\Tasks\dsnbzvbm.job" deleted successfully.
File "c:\windows\Tasks\dvabcl.job" deleted successfully.
File "c:\windows\Tasks\dxlfteg.job" deleted successfully.
File "c:\windows\Tasks\eakar.job" deleted successfully.
File "c:\windows\Tasks\ejoxnaph.job" deleted successfully.
File "c:\windows\Tasks\elha.job" deleted successfully.
File "c:\windows\Tasks\erep.job" deleted successfully.
File "c:\windows\Tasks\errsj.job" deleted successfully.
File "c:\windows\Tasks\erxk.job" deleted successfully.
File "c:\windows\Tasks\exermd.job" deleted successfully.
File "c:\windows\Tasks\exqy.job" deleted successfully.
File "c:\windows\Tasks\fapgx.job" deleted successfully.
File "c:\windows\Tasks\fla.job" deleted successfully.
File "c:\windows\Tasks\flin.job" deleted successfully.
File "c:\windows\Tasks\fnw.job" deleted successfully.
File "c:\windows\Tasks\ftfwzr.job" deleted successfully.
File "c:\windows\Tasks\fyse.job" deleted successfully.
File "c:\windows\Tasks\fyusrb.job" deleted successfully.
File "c:\windows\Tasks\fztcjz.job" deleted successfully.
File "c:\windows\Tasks\gbgdtjs.job" deleted successfully.
File "c:\windows\Tasks\gckccpbw.job" deleted successfully.
File "c:\windows\Tasks\ggdfi.job" deleted successfully.
File "c:\windows\Tasks\gonkaonz.job" deleted successfully.
File "c:\windows\Tasks\guux.job" deleted successfully.
File "c:\windows\Tasks\hbjef.job" deleted successfully.
File "c:\windows\Tasks\hbptjbc.job" deleted successfully.
File "c:\windows\Tasks\hexu.job" deleted successfully.
File "c:\windows\Tasks\hjqkgfh.job" deleted successfully.
File "c:\windows\Tasks\hkcpddt.job" deleted successfully.
File "c:\windows\Tasks\hkpaqkha.job" deleted successfully.
File "c:\windows\Tasks\hrvbe.job" deleted successfully.
File "c:\windows\Tasks\huo.job" deleted successfully.
File "c:\windows\Tasks\huw.job" deleted successfully.
File "c:\windows\Tasks\hxpy.job" deleted successfully.
File "c:\windows\Tasks\icw.job" deleted successfully.
File "c:\windows\Tasks\ieqxhvyv.job" deleted successfully.
File "c:\windows\Tasks\ijok.job" deleted successfully.
File "c:\windows\Tasks\inoud.job" deleted successfully.
File "c:\windows\Tasks\irvs.job" deleted successfully.
File "c:\windows\Tasks\isvw.job" deleted successfully.
File "c:\windows\Tasks\iuj.job" deleted successfully.
File "c:\windows\Tasks\ixqei.job" deleted successfully.
File "c:\windows\Tasks\javzhet.job" deleted successfully.
File "c:\windows\Tasks\jehqffdt.job" deleted successfully.
File "c:\windows\Tasks\jhu.job" deleted successfully.
File "c:\windows\Tasks\jixkgfwm.job" deleted successfully.
File "c:\windows\Tasks\jkakqk.job" deleted successfully.
File "c:\windows\Tasks\jngogkhd.job" deleted successfully.
File "c:\windows\Tasks\jryy.job" deleted successfully.
File "c:\windows\Tasks\jupzy.job" deleted successfully.
File "c:\windows\Tasks\kct.job" deleted successfully.
File "c:\windows\Tasks\kfvqpuqs.job" deleted successfully.
File "c:\windows\Tasks\kigcb.job" deleted successfully.
File "c:\windows\Tasks\kjjbt.job" deleted successfully.
File "c:\windows\Tasks\kogkvwpc.job" deleted successfully.
File "c:\windows\Tasks\lcrxhgqv.job" deleted successfully.
File "c:\windows\Tasks\lgkmi.job" deleted successfully.
File "c:\windows\Tasks\liajreo.job" deleted successfully.
File "c:\windows\Tasks\lpkiqudp.job" deleted successfully.
File "c:\windows\Tasks\lra.job" deleted successfully.
File "c:\windows\Tasks\lrhvm.job" deleted successfully.
File "c:\windows\Tasks\lrjecna.job" deleted successfully.
File "c:\windows\Tasks\Malwarebytes' Scheduled Scan for enrico.job" deleted successfully.
File "c:\windows\Tasks\Malwarebytes' Scheduled Update for enrico.job" deleted successfully.
File "c:\windows\Tasks\mbgid.job" deleted successfully.
File "c:\windows\Tasks\mcrwgmfv.job" deleted successfully.
File "c:\windows\Tasks\mfvo.job" deleted successfully.
File "c:\windows\Tasks\mgyxem.job" deleted successfully.
File "c:\windows\Tasks\mjyrgt.job" deleted successfully.
File "c:\windows\Tasks\mktmwtt.job" deleted successfully.
File "c:\windows\Tasks\mlqx.job" deleted successfully.
File "c:\windows\Tasks\mnudfnxa.job" deleted successfully.
File "c:\windows\Tasks\moivky.job" deleted successfully.
File "c:\windows\Tasks\MP Scheduled Scan.job" deleted successfully.
File "c:\windows\Tasks\mrmguo.job" deleted successfully.
File "c:\windows\Tasks\mvtpi.job" deleted successfully.
File "c:\windows\Tasks\mxp.job" deleted successfully.
File "c:\windows\Tasks\mzerwr.job" deleted successfully.
File "c:\windows\Tasks\nfgdcki.job" deleted successfully.
File "c:\windows\Tasks\ngu.job" deleted successfully.
File "c:\windows\Tasks\nocm.job" deleted successfully.
File "c:\windows\Tasks\noiyrh.job" deleted successfully.
File "c:\windows\Tasks\nonxpu.job" deleted successfully.
File "c:\windows\Tasks\oajltytd.job" deleted successfully.
File "c:\windows\Tasks\oaprb.job" deleted successfully.
File "c:\windows\Tasks\oct.job" deleted successfully.
File "c:\windows\Tasks\ogacfmf.job" deleted successfully.
File "c:\windows\Tasks\olbs.job" deleted successfully.
File "c:\windows\Tasks\olkduggz.job" deleted successfully.
File "c:\windows\Tasks\oxhwydh.job" deleted successfully.
File "c:\windows\Tasks\pec.job" deleted successfully.
File "c:\windows\Tasks\pmlxonn.job" deleted successfully.
File "c:\windows\Tasks\pmxkm.job" deleted successfully.
File "c:\windows\Tasks\pnlnld.job" deleted successfully.
File "c:\windows\Tasks\poe.job" deleted successfully.
File "c:\windows\Tasks\pogvr.job" deleted successfully.
File "c:\windows\Tasks\ppbrphmo.job" deleted successfully.
File "c:\windows\Tasks\pqdwhfmx.job" deleted successfully.
File "c:\windows\Tasks\pry.job" deleted successfully.
File "c:\windows\Tasks\puxnnpqr.job" deleted successfully.
File "c:\windows\Tasks\pvsaxg.job" deleted successfully.
File "c:\windows\Tasks\pyyskpuq.job" deleted successfully.
File "c:\windows\Tasks\pzhtm.job" deleted successfully.
File "c:\windows\Tasks\pzsf.job" deleted successfully.
File "c:\windows\Tasks\qbwoorn.job" deleted successfully.
File "c:\windows\Tasks\qdotnai.job" deleted successfully.
File "c:\windows\Tasks\qemk.job" deleted successfully.
File "c:\windows\Tasks\qmsinqbd.job" deleted successfully.
File "c:\windows\Tasks\qny.job" deleted successfully.
File "c:\windows\Tasks\qoe.job" deleted successfully.
File "c:\windows\Tasks\qsqqijcu.job" deleted successfully.
File "c:\windows\Tasks\qtje.job" deleted successfully.
File "c:\windows\Tasks\qxiyhxoe.job" deleted successfully.
File "c:\windows\Tasks\qysvkwpp.job" deleted successfully.
File "c:\windows\Tasks\qzzwal.job" deleted successfully.
File "c:\windows\Tasks\rgojn.job" deleted successfully.
File "c:\windows\Tasks\rltzrmj.job" deleted successfully.
File "c:\windows\Tasks\rlwj.job" deleted successfully.
File "c:\windows\Tasks\rpandv.job" deleted successfully.
File "c:\windows\Tasks\rrboqlw.job" deleted successfully.
File "c:\windows\Tasks\rwqtix.job" deleted successfully.
File "c:\windows\Tasks\saqs.job" deleted successfully.
File "c:\windows\Tasks\sbyupr.job" deleted successfully.
File "c:\windows\Tasks\scqkf.job" deleted successfully.
File "c:\windows\Tasks\sehnbfq.job" deleted successfully.
File "c:\windows\Tasks\ski.job" deleted successfully.
File "c:\windows\Tasks\smjp.job" deleted successfully.
File "c:\windows\Tasks\soxcdlll.job" deleted successfully.
File "c:\windows\Tasks\spkjv.job" deleted successfully.
File "c:\windows\Tasks\spyy.job" deleted successfully.
File "c:\windows\Tasks\ssoaksda.job" deleted successfully.
File "c:\windows\Tasks\syp.job" deleted successfully.
File "c:\windows\Tasks\szao.job" deleted successfully.
File "c:\windows\Tasks\thyqg.job" deleted successfully.
File "c:\windows\Tasks\tinsnj.job" deleted successfully.
File "c:\windows\Tasks\tohj.job" deleted successfully.
File "c:\windows\Tasks\tqfg.job" deleted successfully.
File "c:\windows\Tasks\trxskhag.job" deleted successfully.
File "c:\windows\Tasks\tuqvpsr.job" deleted successfully.
File "c:\windows\Tasks\tvmzoluv.job" deleted successfully.
File "c:\windows\Tasks\twum.job" deleted successfully.
File "c:\windows\Tasks\txic.job" deleted successfully.
File "c:\windows\Tasks\uohyc.job" deleted successfully.
File "c:\windows\Tasks\utq.job" deleted successfully.
File "c:\windows\Tasks\uuuquuao.job" deleted successfully.
File "c:\windows\Tasks\uvvbr.job" deleted successfully.
File "c:\windows\Tasks\vadadc.job" deleted successfully.
File "c:\windows\Tasks\vca.job" deleted successfully.
File "c:\windows\Tasks\vemj.job" deleted successfully.
File "c:\windows\Tasks\vjrssyjc.job" deleted successfully.
File "c:\windows\Tasks\vzdufno.job" deleted successfully.
File "c:\windows\Tasks\vzfx.job" deleted successfully.
File "c:\windows\Tasks\whpd.job" deleted successfully.
File "c:\windows\Tasks\wiw.job" deleted successfully.
File "c:\windows\Tasks\wlr.job" deleted successfully.
File "c:\windows\Tasks\wnjmty.job" deleted successfully.
File "c:\windows\Tasks\wnulaw.job" deleted successfully.
File "c:\windows\Tasks\wophd.job" deleted successfully.
File "c:\windows\Tasks\wpybkn.job" deleted successfully.
File "c:\windows\Tasks\wqnpmgvl.job" deleted successfully.
File "c:\windows\Tasks\wqxbke.job" deleted successfully.
File "c:\windows\Tasks\wtzr.job" deleted successfully.
File "c:\windows\Tasks\wwcodxq.job" deleted successfully.
File "c:\windows\Tasks\wxft.job" deleted successfully.
File "c:\windows\Tasks\wzqxek.job" deleted successfully.
File "c:\windows\Tasks\xaaariut.job" deleted successfully.
File "c:\windows\Tasks\xbychnij.job" deleted successfully.
File "c:\windows\Tasks\xpnbaeg.job" deleted successfully.
File "c:\windows\Tasks\xqusvowh.job" deleted successfully.
File "c:\windows\Tasks\xrhbtvb.job" deleted successfully.
File "c:\windows\Tasks\xtkbb.job" deleted successfully.
File "c:\windows\Tasks\xyrui.job" deleted successfully.
File "c:\windows\Tasks\xzfqsmhx.job" deleted successfully.
File "c:\windows\Tasks\ybxd.job" deleted successfully.
File "c:\windows\Tasks\ydiowwn.job" deleted successfully.
File "c:\windows\Tasks\yipgom.job" deleted successfully.
File "c:\windows\Tasks\ykzwmcx.job" deleted successfully.
File "c:\windows\Tasks\ylfwzilm.job" deleted successfully.
File "c:\windows\Tasks\yvey.job" deleted successfully.
File "c:\windows\Tasks\zbebu.job" deleted successfully.
File "c:\windows\Tasks\zgrbz.job" deleted successfully.
File "c:\windows\Tasks\zis.job" deleted successfully.
File "c:\windows\Tasks\zlpnnta.job" deleted successfully.
File "c:\windows\Tasks\zoxum.job" deleted successfully.
File "c:\windows\Tasks\zrbqka.job" deleted successfully.
File "c:\windows\Tasks\zxhbiskx.job" deleted successfully.
File "c:\windows\Tasks\zym.job" deleted successfully.
File "c:\windows\Tasks\zzbv.job" deleted successfully.
File "C:\WINDOWS\system32\ctfmon.exe" deleted successfully.
File "C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" deleted successfully.
File "C:\Programmi\Adobe\Acrobat 7.0\Distillr\AcroTray.exe" deleted successfully.
File "C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe" deleted successfully.
File "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe" deleted successfully.
File move operation "C:\WINDOWS\system32\bak\ctfmon.exe|C:\WINDOWS\system32\ctfmon.exe" completed successfully.
File move operation "C:\Programmi\Microsoft Office\Office12\bak\GrooveMonitor.exe|C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe" completed successfully.
File move operation "C:\Programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe|C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" completed successfully.
File move operation "C:\Programmi\ScanSoft\OmniPageSE2.0\bak\OpwareSE2.exe|C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" completed successfully.
File move operation "C:\Programmi\Adobe\Acrobat 7.0\Distillr\bak\Acrotray.exe|C:\Programmi\Adobe\Acrobat 7.0\Distillr\AcroTray.exe" completed successfully.
File move operation "C:\Programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe|C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe" completed successfully.
File move operation "C:\Programmi\File comuni\Ahead\Lib\bak\NMBgMonitor.exe|C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" completed successfully.

Completed script processing.

*******************

Finished! Terminate.

- log malwarebytes:
Malwarebytes' Anti-Malware 1.30
Versione del database: 1414
Windows 5.1.2600 Service Pack 3

20/11/2008 23.10.38
mbam-log-2008-11-20 (23-10-38).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 101384
Tempo trascorso: 53 minute(s), 15 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)

- log findawd:

Find AWF report by noahdfear ©2006
Version 1.40



bak folders found
~~~~~~~~~~~

Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\MESSEN~1\BAK

0 File 0 byte
2 Directory 17.042.976.768 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\WINDOWS\SYSTEM32\BAK

0 File 0 byte
2 Directory 17.042.976.768 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\MICROS~3\OFFICE12\BAK

0 File 0 byte
2 Directory 17.042.972.672 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\NOKIA\NOKIAP~1\BAK

0 File 0 byte
2 Directory 17.042.972.672 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\SCANSOFT\OMNIPA~1.0\BAK

0 File 0 byte
2 Directory 17.042.972.672 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\ADOBE\ACROBA~1.0\DISTILLR\BAK

0 File 0 byte
2 Directory 17.042.972.672 byte disponibili
Il volume nell'unità C non ha etichetta.
Numero di serie del volume: 8819-A171

Directory di C:\PROGRA~1\FILECO~1\AHEAD\LIB\BAK

0 File 0 byte
2 Directory 17.042.972.672 byte disponibili


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~



end of report

- log combofix:
ComboFix 08-11-18.A2 - enrico 2008-11-20 23.22.08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.582 [GMT 1:00]
Eseguito da: c:\documents and settings\enrico\Desktop\antidialer\ComboFix.exe
.

((((((((((((((((((((((((( Files Creati Da 2008-10-20 al 2008-11-20 )))))))))))))))))))))))))))))))))))
.

2008-11-20 22:10 . 2008-11-20 22:10 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-11-20 22:10 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-20 22:10 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-19 21:01 . 2008-11-19 21:42 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2008-11-19 21:01 . 2008-11-19 21:01 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\SUPERAntiSpyware.com
2008-11-19 21:01 . 2008-11-19 21:01 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-11-19 21:00 . 2008-11-19 21:00 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di stampa
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di rete
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d-------- c:\documents and settings\Administrator\Preferiti
2008-11-18 21:42 . 2007-05-03 16:44 <DIR> d--h----- c:\documents and settings\Administrator\Modelli
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> dr------- c:\documents and settings\Administrator\Menu Avvio
2008-11-18 21:42 . 2008-11-20 23:23 <DIR> d--h----- c:\documents and settings\Administrator\Impostazioni locali
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d-------- c:\documents and settings\Administrator\Documenti
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> dr-h----- c:\documents and settings\Administrator\Dati applicazioni
2008-11-18 21:42 . 2008-11-18 21:42 <DIR> d-------- c:\documents and settings\Administrator
2008-11-18 21:36 . 2008-11-18 21:36 <DIR> d-------- c:\programmi\Trend Micro
2008-11-18 21:23 . 2008-11-18 21:23 <DIR> d-------- c:\programmi\CCleaner
2008-11-18 17:44 . 2008-11-18 17:45 <DIR> d-------- c:\programmi\ReflexiveArcade
2008-11-18 17:44 . 2008-11-18 17:46 <DIR> d-------- c:\programmi\Aqua Pearls
2008-11-15 22:05 . 2008-11-15 22:05 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\Malwarebytes
2008-11-15 22:05 . 2008-11-15 22:05 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-11-13 16:42 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-13 16:41 . 2008-09-04 18:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 22:18 . 2008-11-12 22:20 <DIR> d-------- c:\programmi\eToro
2008-11-08 22:08 . 2008-11-08 22:08 <DIR> d--h----- c:\windows\PIF
2008-11-01 20:01 . 2008-11-01 20:01 <DIR> d-------- c:\programmi\K-Lite Codec Pack
2008-11-01 19:41 . 2008-07-12 08:18 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2008-11-01 19:41 . 2008-07-12 08:18 1,493,528 --a------ c:\windows\system32\D3DCompiler_39.dll
2008-11-01 19:41 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-11-01 19:41 . 2008-07-31 10:40 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2008-11-01 19:41 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-01 19:41 . 2008-07-12 08:18 467,984 --a------ c:\windows\system32\d3dx10_39.dll
2008-11-01 19:41 . 2008-07-31 10:41 238,088 --a------ c:\windows\system32\xactengine3_2.dll
2008-11-01 19:41 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-01 19:41 . 2008-07-31 10:41 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2008-11-01 19:41 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-01 19:41 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-01 19:38 . 2008-11-01 19:38 <DIR> d-------- c:\windows\Logs
2008-11-01 14:33 . 2008-11-01 19:48 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\Media Player Classic
2008-10-23 19:29 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-22 19:59 . 2008-10-22 19:59 <DIR> d-------- c:\documents and settings\manuela\Dati applicazioni\DivX
2008-10-21 20:45 . 2008-10-21 20:45 42,771 --a------ c:\windows\CSTBox.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 21:01 --------- d---a-w c:\documents and settings\All Users\Dati applicazioni\TEMP
2008-11-12 20:54 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2008-11-10 20:53 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Motive
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 19:45 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\Canon
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-07 14:09 --------- d-----w c:\programmi\NOS
2008-10-07 14:09 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\NOS
2008-10-06 17:29 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\ArcSoft
2008-10-06 17:28 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\ArcSoft
2008-10-06 17:26 --------- d-----w c:\programmi\File comuni\Adobe
2008-10-06 17:09 --------- d--h--w c:\programmi\InstallShield Installation Information
2008-10-06 17:09 --------- d-----w c:\programmi\File comuni\ArcSoft
2008-10-06 17:09 --------- d-----w c:\programmi\ArcSoft
2008-10-06 17:08 --------- d-----w c:\programmi\Philips
2008-10-06 17:08 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\InstallShield
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-29 19:05 --------- d-----w c:\documents and settings\manuela\Dati applicazioni\Nokia Multimedia Player
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\divx.dll
2008-09-15 15:24 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-26 07:57 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-10 19:17 47,360 ----a-w c:\documents and settings\enrico\Dati applicazioni\pcouffin.sys
2008-04-14 02:14 786,432 --sh--r c:\windows\system32\WindowANTasdIVRI.exe
2008-05-22 17:39 32,768 -csha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008052220080523\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-11-19_22.05.34.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-14 02:14:03 15,360 ----a-w c:\windows\system32\ctfmon.exe
+ 2004-08-19 13:39:36 15,360 -c--a-w c:\windows\system32\ctfmon.exe
+ 2004-08-19 13:39:36 15,360 -c--a-w c:\windows\system32\ctfmon.exe1180467958
+ 2008-11-20 20:59:58 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_620.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2005-10-24 307200]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-29 68856]
"H/PC Connection Agent"="F:\wcescomm.exe" [2005-08-05 1200128]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-11-17 1805552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Acrobat Assistant 7.0"="c:\programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"OpwareSE2"="c:\programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"HP Software Update"="f:\programmi\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-03-28 413696]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"ArcSoft Connection Service"="c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AliceRE_McciTrayApp"="c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe" [2006-11-21 936960]
"Malwarebytes' Anti-Malware"="c:\programmi\Malwarebytes' Anti-Malware\mbamgui.exe" [2008-10-22 399504]
"VTTimer"="VTTimer.exe" [2003-05-07 c:\windows\system32\VTTimer.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"nwiz"="nwiz.exe" [2007-09-17 c:\windows\system32\nwiz.exe]
"Windowfdgfds DasdLL fgfdg Verifier"="WindowANTasdIVRI.exe" [2008-04-14 c:\windows\system32\WindowANTasdIVRI.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Windowfdgfds DasdLL fgfdg Verifier"="WindowANTasdIVRI.exe" [2008-04-14 c:\windows\system32\WindowANTasdIVRI.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\programmi\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"f:\rapimgr.exe"= f:\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"f:\wcescomm.exe"= f:\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"f:\wcesmgr.exe"= f:\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\emule\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"2263:TCP"= 2263:TCP:messenger

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-04 78416]
R2 ACDaemon;ArcSoft Connect Daemon;c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe [2008-10-06 102712]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-04 20560]
R2 MBAMService;MBAMService;"c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe" [2008-11-20 170640]
R3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys [2008-11-20 15504]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe []
S3 MEMSWEEP2;MEMSWEEP2; []
S4 hpt3xx;hpt3xx; []
.
Contenuto della cartella 'Scheduled Tasks'

2008-11-20 c:\windows\Tasks\Malwarebytes' Scheduled Scan for enrico.job
- c:\programmi\Malwarebytes' Anti-Malware\mbam.exe [2008-10-22 16:10]

2008-11-20 c:\windows\Tasks\Malwarebytes' Scheduled Update for enrico.job
- c:\programmi\Malwarebytes' Anti-Malware\mbam.exe [2008-10-22 16:10]

2008-11-20 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORFÃOS REMOVIDOS - - - -

HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe
HKCU-Run-BitTorrent DNA - c:\programmi\BitTorrent_DNA\dna.exe
HKCU-Run-BitComet - f:\bitcomet\BitComet.exe
HKLM-Run-NeroFilterCheck - c:\programmi\File comuni\Nero\Lib\NeroCheck.exe


.
------- Supplementare di scansione -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to AMV Converter... - c:\programmi\MP3 Player Utilities 4.15\AMVConverter\grab.html
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti nel file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\programmi\MP3 Player Utilities 4.15\MediaManager\grab.html
TCP: {B1A92480-049C-48EC-A329-D43338B1B63C} = 192.168.1.1

O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\Account.dll - O16 -: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4}
hxxp://www.tele2mail.com/static/apps/utils/AccountHelper.cab
c:\windows\Downloaded Program Files\Account.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-20 23:24:09
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

PROCESSO: c:\windows\explorer.exe
-> c:\windows\system32\nview.dll
.
Ora fine scansione: 2008-11-20 23.26.07
ComboFix-quarantined-files.txt 2008-11-20 22:25:57
ComboFix2.txt 2008-11-19 21:08:00

Pre-Run: 17.034.788.864 byte disponibili
Post-Run: 17,068,388,352 byte disponibili

218 --- E O F --- 2008-11-20 20:49:34

speriamo non ci sia più da piangere
ciao e grazie

r16
Inviato: Thursday, November 20, 2008 11:44:49 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Come và il pc....
nuvolaneuve
Inviato: Thursday, November 20, 2008 11:47:28 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
mi sembra bene, il problema si manifesta quando accendo o riavvio il pc
che faccio provo!
r16
Inviato: Thursday, November 20, 2008 11:48:20 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
nuvolaneuve ha scritto:
mi sembra bene, il problema si manifesta quando accendo o riavvio il pc
che faccio provo!

Che problema.
Posta un nuovo log di HJT.
nuvolaneuve
Inviato: Thursday, November 20, 2008 11:49:38 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
quando avvio il pc mi si apre una finestra per inserire un codice, quando la chiudo avast mi avverte che il file "C:\a.bat è infetto da VBS:Malware-gen"; lo sposto nel cestino come suggerito ma non riesco ad eliminare
nuvolaneuve
Inviato: Thursday, November 20, 2008 11:52:18 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
ecco il log hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23.50.33, on 20/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
F:\Programmi\HP\HP Software Update\HPWuSchd.exe
C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\wcescomm.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
F:\rapimgr.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
F:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\explorer.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [OpwareSE2] "C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] "F:\Programmi\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\Run: [AliceRE_McciTrayApp] C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunServices: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\RunOnce: [InstallHelper C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer] "C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer\InstallHelper.exe" "/DIR=C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_7 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\wcescomm.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
O4 - Global Startup: Digisoft AntiDialer.lnk = F:\Digisoft AntiDialer\AntiDialer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = F:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\Programmi\MP3 Player Utilities 4.15\AMVConverter\grab.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Programmi\MP3 Player Utilities 4.15\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra 'Tools' menuitem: Crea preferito portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: Alice - {AD01FB3B-8AD7-4994-82BE-3B7E6F4E14C1} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197568262529
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://www.tele2mail.com/static/apps/utils/AccountHelper.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6449E0AC-867A-4BD8-9DC5-B2AA42499B9D}: NameServer = 85.37.17.44 85.38.28.90
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A92480-049C-48EC-A329-D43338B1B63C}: NameServer = 192.168.1.1
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Network WanMiniport First Position - Unknown owner - C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 12392 bytes
nuvolaneuve
Inviato: Thursday, November 20, 2008 11:52:53 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
cosa ne pensi!!!
r16
Inviato: Thursday, November 20, 2008 11:59:50 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Non ci sono tracce di quello che racconta Avast.
Comunque segui il percorso che ti indica Avast e elimina questo file.
C:\a.bat
Se non lo vedi (dovrebbe esserci) visualizza i file e le cartelle nascoste.
nuvolaneuve
Inviato: Friday, November 21, 2008 12:09:29 AM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
nel frattempo ho provato a riavviarlo, ma purtroppo mi si apre ancora la finestra per inserire un codice, quando la chiudo avast mi avverte che il file "C:\a.bat è infetto da VBS:Malware-gen"; lo sposto nel cestino come suggerito ............
tutti i file e cartelle sono visibili
r16
Inviato: Friday, November 21, 2008 12:11:57 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Comunque, Per vedere se veramente lo hai questo dannato C:\a.bat , proviamo con Avenger:
Avvia AVENGER
Clicca Ok
Inserisci queste righe (fai capia-incolla) nel riquadro bianco: (quelle in neretto)

Files to delete:
C:\a.bat


Clicca su Execute
Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
Al termine dell'operazione, posta qui il risultato di Avenger

Poi esegui queste operazioni:
Elimina queste voci di HJT:
O4 - HKLM\..\Run: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\RunServices: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\RunOnce: [InstallHelper C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer] "C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer\InstallHelper.exe" "/DIR=C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer"
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Alice - {AD01FB3B-8AD7-4994-82BE-3B7E6F4E14C1} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223

Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO


Disinstalla combofix in questo modo:
Start
Esegui
nella finestra di dialogo, digita (oppure, copia ed incolla) questo comando: Combofix /u e premi invio poi cancella le cartelle in "C" di combofix (qoobox)
*********************************************************************************************************
Scarica Norman:
http://download.norman.no/public/Norman_Malware_Cleaner.exe
Avvia in MODALITA PROVVISORIA

Si avvia
si accetta la licenza
si clicca Start Scan
si attende la fine della scansione
Viene generato un log sul desktop, postalo qui.
In alcuni casi Norman Malware Cleaner potrebbe richiedere il riavvio del computer per rimuovere completamente l'infezione, in
questo caso è raccomandata una seconda esecuzione del programma dopo aver riavviato il PC per garantire la completa rimozione di tutti i files infetti.
Postami il log.
nuvolaneuve
Inviato: Sunday, November 23, 2008 6:42:03 PM
Rank: Member

Iscritto dal : 6/9/2007
Posts: 0
ti comunico, che oggi ho acceso il pc (domenica 23/11/2008) e finalmente è sparita la finestra per inserire un codice e l'avviso di avast!
grazie mille dell'aiuto sei stato fantastico
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.