Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

rootkit Opzioni
vittorio.sc
Inviato: Sunday, March 15, 2009 8:51:34 AM
Rank: Member

Iscritto dal : 11/11/2006
Posts: 21
Sospettavo la presenza di un virus e ho fatto una scansione sia con avast sia con tojan remover.
La risposta è stata per avsta che esiste un virus con la seguente locazione: C:/RECYCLERS/S-9-8-81-100016989-100015663-2525.COM rootkit.
Trojan remove mi dice che c'è C:/RECYCLERS/S-9-8-81-100016989-100022582-100015663-2525.COM e poi dice in nota THIS FILE IS STARTED AT BOOT TIME BY C:AUTORUN.INF.
Ho provato a far irare sofos ootkit, ma non ha trovato niente e il file è rimasto. Qualcuno può aiutarmi? Grazie
Sponsor
Inviato: Sunday, March 15, 2009 8:51:34 AM

 
r16
Inviato: Sunday, March 15, 2009 10:17:13 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Posta un log di HJT.
vittorio.sc
Inviato: Sunday, March 15, 2009 2:04:49 PM
Rank: Member

Iscritto dal : 11/11/2006
Posts: 21
Grazie ti invio il log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14.03.22, on 15/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Unlocker\UnlockerAssistant.exe
C:\Programmi\ClamWin\bin\ClamTray.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmi\OpenOffice.org 3\program\soffice.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\OpenOffice.org 3\program\soffice.bin
C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/italian
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60341
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Programmi\Orbitdownloader\orbitcth.dll
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Programmi\Orbitdownloader\GrabPro.dll
O3 - Toolbar: Toolbar &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programmi\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ClamWin] "C:\Programmi\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TrojanScanner] C:\Programmi\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Programmi\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Download by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{17848720-FD6B-4820-903B-71A22D8B57A8}: NameServer = 85.255.112.157,85.255.112.63
O17 - HKLM\System\CCS\Services\Tcpip\..\{823ADB4E-0F3E-4CEB-9C49-B66540EA2AB2}: NameServer = 193.70.152.15 193.70.152.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{A3419692-919B-4BB1-8952-B8ED3F4F0D69}: NameServer = 85.255.112.157,85.255.112.63
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.157,85.255.112.63
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.157,85.255.112.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.157,85.255.112.63
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Servizio di Google Update (gupdate1c99a6cf39b029c) (gupdate1c99a6cf39b029c) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 10754 bytes
Grazie
r16
Inviato: Sunday, March 15, 2009 2:53:55 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Avvia in modalità provvisoria http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80122
Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked:
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{17848720-FD6B-4820-903B-71A22D8B57A8}: NameServer = 85.255.112.157,85.255.112.63
O17 - HKLM\System\CCS\Services\Tcpip\..\{A3419692-919B-4BB1-8952-B8ED3F4F0D69}: NameServer = 85.255.112.157,85.255.112.63
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.157,85.255.112.63
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.157,85.255.112.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.157,85.255.112.63
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
Riavvia il pc.
*********************************************************************************************************
Scarica ed installa MalwareBytes:
clicca qui per il download : http://www.aiutamici.com/software?id=80346
Prima di fare la scansione AGGIORNALO.
Esegui una scansione completa del sistema.
Posta il log.
*********************************************************************************************************

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,e dopo aver scaricato COMBOFIX, chiudi la connessione.

Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Salvalo sul desktop.
Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
Digita 1 premi Invio e segui le indicazioni.
Al termine, verrà creato un file log chiamato C:\ComboFix.txt. Postalo qui.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Riferisci se ci sono miglioramenti.
vittorio.sc
Inviato: Sunday, March 15, 2009 6:49:27 PM
Rank: Member

Iscritto dal : 11/11/2006
Posts: 21
llego il log di malwarebytes.
Non ho eseguito la pulizia.
Ora scarico combofix e faccio quello che mi hai detto. poi invio il log.
Grazie.
Malwarebytes' Anti-Malware 1.34
Versione del database: 1851
Windows 5.1.2600 Service Pack 3

15/03/2009 18.40.39
mbam-log-2009-03-15 (18-40-15).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 133981
Tempo trascorso: 19 minute(s), 32 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 1
Elementi dato del registro infetti: 7
Cartelle infette: 0
File infetti: 4

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\adsltaskbar (Trojan.Agent) -> No action taken.

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Hijack.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{17848720-fd6b-4820-903b-71a22d8b57a8}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.157,85.255.112.63 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{a3419692-919b-4bb1-8952-b8ed3f4f0d69}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.157,85.255.112.63 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{17848720-fd6b-4820-903b-71a22d8b57a8}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.157,85.255.112.63 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{a3419692-919b-4bb1-8952-b8ed3f4f0d69}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.157,85.255.112.63 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{17848720-fd6b-4820-903b-71a22d8b57a8}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.157,85.255.112.63 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{a3419692-919b-4bb1-8952-b8ed3f4f0d69}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.157,85.255.112.63 -> No action taken.

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
C:\Documents and Settings\Pablo\Desktop\ducumenti dekstop\Free_XXX_video.exe (Trojan.DNSChanger) -> No action taken.
C:\System Volume Information\_restore{5830C18E-6DB1-4DCD-815E-E1BA0655FD13}\RP44\A0016205.exe (Trojan.DNSChanger) -> No action taken.
C:\RECYCLER\S-9-8-81-100016989-100022582-100015663-2525.com (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\~.tmp (Trojan.Agent) -> No action taken.
vittorio.sc
Inviato: Sunday, March 15, 2009 7:11:36 PM
Rank: Member

Iscritto dal : 11/11/2006
Posts: 21
Ed ecco il log di combofix.
Ora faccio girare di nuovo malewarebytes e vedo se trova qualcosa.ComboFix 09-03-14.01 - Vittorio 2009-03-15 18.58.24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.1791.1198 [GMT 1:00]
Eseguito da: c:\documents and settings\Vittorio\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090314-0] *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *disabled*
* Creato nuovo punto di ripristino

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-9-8-81-100016989-100022582-100015663-2525.com

.
((((((((((((((((((((((((( Files Creati Da 2009-02-15 al 2009-03-15 )))))))))))))))))))))))))))))))))))
.

2009-03-15 17:27 . 2009-03-15 17:27 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-03-15 17:27 . 2009-03-15 17:27 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Malwarebytes
2009-03-15 17:27 . 2009-03-15 17:27 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-03-15 17:27 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-15 17:27 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-15 08:36 . 2009-03-15 08:36 <DIR> d-------- c:\programmi\Sophos
2009-03-15 08:26 . 2009-03-15 08:26 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Simply Super Software
2009-03-15 03:21 . 2009-03-15 03:23 <DIR> d-------- c:\programmi\Trojan Remover
2009-03-15 03:21 . 2009-03-15 03:21 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Simply Super Software
2009-03-15 03:21 . 2009-03-15 03:21 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Simply Super Software
2009-03-15 03:21 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-03-15 03:21 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-03-15 03:21 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-03-15 03:21 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-03-15 03:21 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-03-15 03:13 . 2009-03-15 03:22 344 --a------ C:\autorun.inf.vir
2009-03-14 13:33 . 2009-03-14 13:33 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\ChessBase
2009-03-13 23:23 . 2009-03-15 19:00 10,635,296 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-03-13 23:23 . 2009-03-15 17:22 124,724 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-03-13 23:20 . 2008-07-09 09:05 75,248 --a------ c:\windows\zllsputility.exe
2009-03-13 23:20 . 2008-07-09 09:05 54,672 --a------ c:\windows\system32\vsutil_loc0410.dll
2009-03-13 23:20 . 2008-07-09 09:05 42,384 --a------ c:\windows\zllsputility_loc0410.dll
2009-03-13 23:20 . 2008-07-09 09:05 21,904 --a------ c:\windows\system32\imsinstall_loc0410.dll
2009-03-13 23:20 . 2008-07-09 09:05 17,808 --a------ c:\windows\system32\imslsp_install_loc0410.dll
2009-03-13 23:19 . 2009-03-13 23:20 <DIR> d-------- c:\windows\system32\ZoneLabs
2009-03-13 23:19 . 2009-03-13 23:19 <DIR> d-------- c:\programmi\Zone Labs
2009-03-13 23:19 . 2008-07-09 09:05 1,086,952 --a------ c:\windows\system32\zpeng24.dll
2009-03-13 23:19 . 2009-03-15 17:23 358,382 --a------ c:\windows\system32\vsconfig.xml
2009-03-13 23:16 . 2009-03-15 03:15 <DIR> d-------- c:\programmi\Spyware Terminator
2009-03-13 23:16 . 2009-03-13 23:20 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Spyware Terminator
2009-03-13 23:16 . 2009-03-15 09:22 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spyware Terminator
2009-03-13 23:16 . 2009-03-13 23:16 142,592 --a------ c:\windows\system32\drivers\sp_rsdrv2.sys
2009-03-12 03:32 . 2009-03-12 03:32 <DIR> d-------- c:\programmi\MyFree Codec
2009-03-08 17:58 . 2009-03-08 17:59 <DIR> d-------- c:\programmi\Windows Live Safety Center
2009-03-08 10:29 . 2009-03-13 21:51 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\Orbit
2009-03-07 20:06 . 2009-03-14 09:28 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\Spyware Terminator
2009-03-07 17:58 . 2009-03-15 03:15 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Spyware Terminator
2009-03-07 15:05 . 2009-03-10 17:30 <DIR> d-------- c:\documents and settings\Orietta\Dati applicazioni\Spyware Terminator
2009-03-07 14:08 . 2009-03-07 14:08 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\MailFrontier
2009-03-07 14:08 . 2004-04-27 04:40 11,264 --a------ c:\windows\system32\SpOrder.dll
2009-03-07 14:08 . 2009-03-13 23:21 4,212 ---h----- c:\windows\system32\zllictbl.dat
2009-03-07 14:07 . 2009-03-15 18:51 <DIR> d-------- c:\windows\Internet Logs
2009-03-07 14:07 . 2009-03-15 17:27 312 --a------ c:\windows\system32\BIN_STRSBW.SPT
2009-03-07 14:06 . 2009-03-07 14:06 <DIR> d-------- c:\programmi\Trend Micro
2009-03-07 14:05 . 2009-03-07 14:05 <DIR> d-------- c:\programmi\SpywareBlaster
2009-03-07 14:05 . 2009-03-15 14:09 <DIR> d-a------ c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-03-07 14:05 . 2005-08-25 19:18 118,784 --a------ c:\windows\system32\MSSTDFMT.DLL
2009-03-07 14:01 . 2009-03-07 14:01 <DIR> d-------- c:\programmi\Crawler
2009-03-07 03:36 . 2009-03-07 03:36 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\EstSoft
2009-03-05 07:41 . 2009-03-05 07:41 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Creative
2009-03-04 21:04 . 2009-03-04 21:04 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\.clamwin
2009-03-04 15:31 . 2009-03-04 15:31 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\.clamwin
2009-03-04 14:31 . 2009-03-04 14:31 <DIR> d-------- c:\documents and settings\Orietta\Dati applicazioni\.clamwin
2009-03-04 01:19 . 2009-03-04 01:19 <DIR> d-------- c:\programmi\ESTsoft
2009-03-04 01:19 . 2009-03-04 01:19 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\ESTsoft
2009-03-04 00:57 . 2009-03-04 00:57 <DIR> d-------- c:\programmi\ClamWin
2009-03-04 00:57 . 2009-03-04 00:57 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\.clamwin
2009-03-04 00:57 . 2009-03-04 00:57 <DIR> d-------- c:\documents and settings\All Users\.clamwin
2009-03-03 23:53 . 2009-03-03 23:53 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Auslogics
2009-03-02 15:32 . 2009-03-10 17:34 44,401 --a------ c:\windows\system32\~.tmp
2009-03-02 15:32 . 2009-03-10 17:34 127 --a------ c:\windows\system32\~.inf
2009-03-01 16:35 . 2009-03-01 16:35 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\Ahead
2009-03-01 16:27 . 2009-03-01 16:27 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\DivX
2009-03-01 16:20 . 2009-03-01 16:20 <DIR> d-------- c:\documents and settings\Ivano\Bluetooth Software
2009-03-01 13:58 . 2009-03-01 16:17 <DIR> d-------- c:\programmi\Orbitdownloader
2009-03-01 13:58 . 2009-03-01 13:59 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Orbit
2009-03-01 13:58 . 2009-03-01 13:58 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\GrabPro
2009-03-01 13:55 . 2009-03-01 13:55 <DIR> d-------- c:\programmi\File comuni\xing shared
2009-03-01 13:55 . 2009-03-01 13:55 <DIR> d-------- c:\programmi\File comuni\Real
2009-03-01 13:55 . 2009-03-01 13:55 <DIR> d-------- C:\Program Files
2009-03-01 09:04 . 2009-03-13 08:57 <DIR> d-------- c:\programmi\Unlocker
2009-03-01 09:03 . 2009-03-01 09:03 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\GlarySoft
2009-03-01 08:54 . 2009-03-01 08:54 <DIR> d-------- c:\programmi\Glary Utilities
2009-03-01 08:54 . 2009-03-01 08:54 <DIR> d-------- c:\programmi\CCleaner
2009-02-28 13:35 . 2009-03-12 00:15 <DIR> d-------- c:\programmi\TubeSucker
2009-02-28 10:49 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-28 10:49 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-02-28 10:49 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-28 07:13 . 2009-02-28 07:13 <DIR> d-------- c:\documents and settings\Orietta\Bluetooth Software
2009-02-27 21:37 . 2009-02-27 21:37 <DIR> d-------- c:\documents and settings\Pablo\Bluetooth Software
2009-02-27 19:07 . 2009-02-27 19:07 <DIR> d-------- c:\documents and settings\Vittorio\Bluetooth Software
2009-02-27 19:07 . 2008-04-13 19:13 21,504 --a------ c:\windows\system32\hidserv.dll
2009-02-27 19:07 . 2008-04-13 19:13 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll
2009-02-27 19:06 . 2008-04-13 18:53 14,720 --a------ c:\windows\system32\drivers\kbdhid.sys
2009-02-27 19:06 . 2008-04-13 18:53 14,720 --a--c--- c:\windows\system32\dllcache\kbdhid.sys
2009-02-27 19:05 . 2009-02-27 19:05 <DIR> d-------- c:\programmi\WIDCOMM
2009-02-27 19:05 . 2007-08-14 02:38 862,922 --a------ c:\windows\system32\drivers\btkrnl.sys
2009-02-27 19:05 . 2007-08-14 02:38 329,901 --a------ c:\windows\system32\drivers\btaudio.sys
2009-02-27 19:05 . 2007-08-14 02:38 149,123 --a------ c:\windows\system32\drivers\btwdndis.sys
2009-02-27 19:05 . 2007-08-14 02:38 106,557 --a------ c:\windows\system32\btw_ci.dll
2009-02-27 19:05 . 2007-08-14 02:38 67,672 --a------ c:\windows\system32\drivers\btwusb.sys
2009-02-27 19:05 . 2007-08-14 02:38 47,875 --a------ c:\windows\system32\drivers\btwhid.sys
2009-02-27 19:05 . 2007-08-14 02:38 30,459 --a------ c:\windows\system32\drivers\btport.sys
2009-02-27 19:05 . 2007-08-14 02:38 30,285 --a------ c:\windows\system32\drivers\btwmodem.sys
2009-02-27 16:58 . 2009-02-27 17:11 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\GetRightToGo
2009-02-27 16:03 . 2009-03-15 14:14 <DIR> d-------- c:\documents and settings\Pablo\Tracing
2009-02-27 16:00 . 2009-02-27 16:00 <DIR> d-------- c:\programmi\Windows Live SkyDrive
2009-02-27 16:00 . 2009-02-27 16:00 <DIR> d-------- c:\programmi\Windows Live
2009-02-27 16:00 . 2009-02-27 16:00 <DIR> d-------- c:\programmi\Microsoft
2009-02-27 15:55 . 2009-02-27 15:55 <DIR> d-------- c:\programmi\File comuni\Windows Live
2009-02-27 01:19 . 2009-03-13 21:36 <DIR> d-------- C:\downloads
2009-02-27 01:19 . 2009-03-13 21:58 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Orbit
2009-02-27 01:19 . 2009-03-01 14:19 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\GrabPro
2009-02-25 21:31 . 2009-03-07 17:12 16 --a------ c:\windows\popcinfo.dat
2009-02-25 17:46 . 2008-04-13 11:46 37,888 --a------ c:\windows\system32\drivers\bthmodem.sys
2009-02-25 17:46 . 2008-04-13 11:46 37,888 --a--c--- c:\windows\system32\dllcache\bthmodem.sys
2009-02-25 00:33 . 2009-02-25 00:33 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Ahead
2009-02-24 17:49 . 2009-02-24 17:49 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\OpenOffice.org
2009-02-23 22:18 . 2008-04-13 19:14 152,576 --a------ c:\windows\system32\irftp.exe
2009-02-23 01:27 . 2009-03-15 15:48 <DIR> d-------- c:\programmi\eMule
2009-02-21 02:12 . 2009-02-21 02:12 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Creative
2009-02-21 02:09 . 2006-10-05 23:17 53,248 --------- c:\windows\Ctregrun.exe
2009-02-21 02:09 . 2003-06-12 23:25 7,062 --a------ c:\windows\system32\audiopid.vxd
2009-02-21 02:08 . 2009-02-21 02:08 <DIR> d-------- c:\programmi\File comuni\Creative
2009-02-21 02:08 . 2009-02-21 02:08 <DIR> d--h----- c:\programmi\Creative Installation Information
2009-02-21 02:08 . 2009-02-21 02:12 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Creative
2009-02-21 02:08 . 1999-12-12 18:01 44,032 --------- c:\windows\system32\CTSVCCDA.EXE
2009-02-21 02:08 . 1999-11-17 18:00 25,088 --------- c:\windows\system32\CTSVCCTL.EXE
2009-02-21 02:07 . 2009-02-21 02:07 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-21 02:07 . 2009-02-21 02:12 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-02-21 02:07 . 2009-02-21 02:09 <DIR> d-------- c:\programmi\Creative
2009-02-20 21:43 . 2009-03-12 10:40 65 --a------ c:\windows\FISHUI.INI
2009-02-20 21:03 . 2009-02-20 21:03 <DIR> d-------- c:\documents and settings\Orietta\Dati applicazioni\OpenOffice.org
2009-02-20 20:01 . 2009-02-20 20:01 <DIR> d-------- C:\My Video
2009-02-20 20:00 . 2009-02-20 20:00 <DIR> d-------- c:\programmi\Samsung

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-14 07:36 1,373,696 ----a-w c:\windows\Internet Logs\xDB1.tmp
2009-03-13 21:11 --------- d-----w c:\programmi\Java
2009-03-01 12:55 --------- d-----w c:\programmi\Google
2009-02-21 04:04 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-20 15:24 --------- d-----w c:\documents and settings\Vittorio\Dati applicazioni\Ahead
2009-02-19 16:54 --------- d-----w c:\programmi\Alwil Software
2009-02-19 16:52 --------- d-----w c:\programmi\OpenOffice.org 3
2009-02-19 16:52 --------- d-----w c:\programmi\JRE
2009-02-19 16:52 --------- d-----w c:\programmi\File comuni\Java
2009-02-19 16:48 --------- d-----w c:\programmi\PDFCreator
2009-02-19 16:48 --------- d-----w c:\programmi\DivX
2009-02-19 16:47 --------- d-----w c:\programmi\File comuni\Adobe
2009-02-19 16:47 --------- d-----w c:\programmi\AusLogics Disk Defrag
2009-02-19 16:38 --------- d-----w c:\programmi\File comuni\LightScribe
2009-02-19 16:37 --------- d-----w c:\programmi\File comuni\Ahead
2009-02-19 16:37 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Ahead
2009-02-19 16:35 --------- d-----w c:\programmi\Nero
2009-02-19 16:35 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Nero
2009-02-19 16:01 --------- d-----w c:\documents and settings\Vittorio\Dati applicazioni\ATI
2009-02-19 16:01 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\ATI
2009-02-19 16:00 --------- d-----w c:\programmi\ATI Technologies
2009-02-19 15:56 --------- d-----w c:\programmi\File comuni\InstallShield
2009-02-19 15:51 --------- d-----w c:\programmi\microsoft frontpage
2009-02-19 15:50 --------- d-----w c:\programmi\Servizi in linea
2009-02-09 14:04 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 17:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LightScribe Control Panel"="c:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe" [2007-07-18 451872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"UnlockerAssistant"="c:\programmi\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"ClamWin"="c:\programmi\ClamWin\bin\ClamTray.exe" [2008-11-09 86016]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-13 148888]
"SpywareTerminator"="c:\progra~1\SPYWAR~1\SpywareTerminatorShield.exe" [2009-03-13 2233856]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"TrojanScanner"="c:\programmi\Trojan Remover\Trjscan.exe" [2009-03-15 1303432]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 c:\windows\SkyTel.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 c:\windows\system32\stmctrl.dll]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 c:\windows\system32\bthprops.cpl]

c:\documents and settings\Orietta\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\Pablo\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\Vittorio\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-13 561213]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"IncrediMail"=c:\programmi\IncrediMail\bin\IncMail.exe /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MP10_EnsureFileVer"=c:\windows\inf\unregmp2.exe /EnsureFileVersions
"Alcmtr"=ALCMTR.EXE
"SMSTray"=c:\programmi\Samsung\EmoDio\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitdm.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitnet.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-19 114768]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2009-02-19 13696]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2009-03-13 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-19 20560]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [2009-02-20 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;c:\windows\system32\drivers\torususb.sys [2009-02-20 527980]
S2 gupdate1c99a6cf39b029c;Servizio di Google Update (gupdate1c99a6cf39b029c);c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-01 133104]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-02-23 37296]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'

2009-03-15 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2009-02-12 17:10]

2009-03-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-01 13:55]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://mystart.incredimail.com/italian
IE: &Download by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search - tbr:iemenu
IE: Do&wnload selected by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/202
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\programmi\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Vittorio\Dati applicazioni\Mozilla\Firefox\Profiles\52m0hmc0.default\
FF - component: c:\programmi\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\programmi\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\programmi\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\programmi\Crawler\Toolbar\firefox\components\xwsg.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmi\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 18:59:55
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(792)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-03-15 19.00.51
ComboFix-quarantined-files.txt 2009-03-15 18:00:49

Pre-Run: 437.806.440.448 byte disponibili
Post-Run: 437,809,188,864 byte disponibili

286 --- E O F --- 2009-03-11 16:21:09
vittorio.sc
Inviato: Sunday, March 15, 2009 7:43:07 PM
Rank: Member

Iscritto dal : 11/11/2006
Posts: 21
ora ho fato girare malarebytes e gli ho detto di eliminare gli elementi trovati.
Ecco il log
Malwarebytes' Anti-Malware 1.34
Versione del database: 1851
Windows 5.1.2600 Service Pack 3

15/03/2009 19.39.01
mbam-log-2009-03-15 (19-39-01).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 133127
Tempo trascorso: 14 minute(s), 1 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 1
Elementi dato del registro infetti: 3
Cartelle infette: 0
File infetti: 3

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\adsltaskbar (Trojan.Agent) -> Quarantined and deleted successfully.

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Hijack.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{17848720-fd6b-4820-903b-71a22d8b57a8}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.157,85.255.112.63 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{a3419692-919b-4bb1-8952-b8ed3f4f0d69}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.157,85.255.112.63 -> Quarantined and deleted successfully.

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
C:\Documents and Settings\Pablo\Desktop\ducumenti dekstop\Free_XXX_video.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5830C18E-6DB1-4DCD-815E-E1BA0655FD13}\RP44\A0016205.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\~.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
vittorio.sc
Inviato: Sunday, March 15, 2009 7:51:04 PM
Rank: Member

Iscritto dal : 11/11/2006
Posts: 21
Ho fatto girare di nuovo combofix.
Ecco l'ulteriore log
ComboFix 09-03-14.01 - Vittorio 2009-03-15 19.44.33.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.1791.1008 [GMT 1:00]
Eseguito da: c:\documents and settings\Vittorio\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090314-0] *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *disabled*

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((( Files Creati Da 2009-02-15 al 2009-03-15 )))))))))))))))))))))))))))))))))))
.

2009-03-15 19:39 . 2009-03-15 19:39 61,440 --a------ c:\windows\system32\drivers\djkmmv.sys
2009-03-15 17:27 . 2009-03-15 17:27 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-03-15 17:27 . 2009-03-15 17:27 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Malwarebytes
2009-03-15 17:27 . 2009-03-15 17:27 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-03-15 17:27 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-15 17:27 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-15 08:36 . 2009-03-15 08:36 <DIR> d-------- c:\programmi\Sophos
2009-03-15 08:26 . 2009-03-15 08:26 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Simply Super Software
2009-03-15 03:21 . 2009-03-15 03:23 <DIR> d-------- c:\programmi\Trojan Remover
2009-03-15 03:21 . 2009-03-15 03:21 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Simply Super Software
2009-03-15 03:21 . 2009-03-15 03:21 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Simply Super Software
2009-03-15 03:21 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-03-15 03:21 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-03-15 03:21 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-03-15 03:21 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-03-15 03:21 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-03-15 03:13 . 2009-03-15 03:22 344 --a------ C:\autorun.inf.vir
2009-03-14 13:33 . 2009-03-14 13:33 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\ChessBase
2009-03-13 23:23 . 2009-03-15 19:46 10,709,024 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-03-13 23:23 . 2009-03-15 17:22 124,724 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-03-13 23:20 . 2008-07-09 09:05 75,248 --a------ c:\windows\zllsputility.exe
2009-03-13 23:20 . 2008-07-09 09:05 54,672 --a------ c:\windows\system32\vsutil_loc0410.dll
2009-03-13 23:20 . 2008-07-09 09:05 42,384 --a------ c:\windows\zllsputility_loc0410.dll
2009-03-13 23:20 . 2008-07-09 09:05 21,904 --a------ c:\windows\system32\imsinstall_loc0410.dll
2009-03-13 23:20 . 2008-07-09 09:05 17,808 --a------ c:\windows\system32\imslsp_install_loc0410.dll
2009-03-13 23:19 . 2009-03-13 23:20 <DIR> d-------- c:\windows\system32\ZoneLabs
2009-03-13 23:19 . 2009-03-13 23:19 <DIR> d-------- c:\programmi\Zone Labs
2009-03-13 23:19 . 2008-07-09 09:05 1,086,952 --a------ c:\windows\system32\zpeng24.dll
2009-03-13 23:19 . 2009-03-15 17:23 358,382 --a------ c:\windows\system32\vsconfig.xml
2009-03-13 23:16 . 2009-03-15 03:15 <DIR> d-------- c:\programmi\Spyware Terminator
2009-03-13 23:16 . 2009-03-13 23:20 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Spyware Terminator
2009-03-13 23:16 . 2009-03-15 09:22 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spyware Terminator
2009-03-13 23:16 . 2009-03-13 23:16 142,592 --a------ c:\windows\system32\drivers\sp_rsdrv2.sys
2009-03-12 03:32 . 2009-03-12 03:32 <DIR> d-------- c:\programmi\MyFree Codec
2009-03-08 17:58 . 2009-03-08 17:59 <DIR> d-------- c:\programmi\Windows Live Safety Center
2009-03-08 10:29 . 2009-03-13 21:51 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\Orbit
2009-03-07 20:06 . 2009-03-14 09:28 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\Spyware Terminator
2009-03-07 17:58 . 2009-03-15 03:15 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Spyware Terminator
2009-03-07 15:05 . 2009-03-10 17:30 <DIR> d-------- c:\documents and settings\Orietta\Dati applicazioni\Spyware Terminator
2009-03-07 14:08 . 2009-03-07 14:08 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\MailFrontier
2009-03-07 14:08 . 2004-04-27 04:40 11,264 --a------ c:\windows\system32\SpOrder.dll
2009-03-07 14:08 . 2009-03-13 23:21 4,212 ---h----- c:\windows\system32\zllictbl.dat
2009-03-07 14:07 . 2009-03-15 18:51 <DIR> d-------- c:\windows\Internet Logs
2009-03-07 14:07 . 2009-03-15 17:27 312 --a------ c:\windows\system32\BIN_STRSBW.SPT
2009-03-07 14:06 . 2009-03-07 14:06 <DIR> d-------- c:\programmi\Trend Micro
2009-03-07 14:05 . 2009-03-07 14:05 <DIR> d-------- c:\programmi\SpywareBlaster
2009-03-07 14:05 . 2009-03-15 14:09 <DIR> d-a------ c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-03-07 14:05 . 2005-08-25 19:18 118,784 --a------ c:\windows\system32\MSSTDFMT.DLL
2009-03-07 14:01 . 2009-03-07 14:01 <DIR> d-------- c:\programmi\Crawler
2009-03-07 03:36 . 2009-03-07 03:36 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\EstSoft
2009-03-05 07:41 . 2009-03-05 07:41 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Creative
2009-03-04 21:04 . 2009-03-04 21:04 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\.clamwin
2009-03-04 15:31 . 2009-03-04 15:31 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\.clamwin
2009-03-04 14:31 . 2009-03-04 14:31 <DIR> d-------- c:\documents and settings\Orietta\Dati applicazioni\.clamwin
2009-03-04 01:19 . 2009-03-04 01:19 <DIR> d-------- c:\programmi\ESTsoft
2009-03-04 01:19 . 2009-03-04 01:19 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\ESTsoft
2009-03-04 00:57 . 2009-03-04 00:57 <DIR> d-------- c:\programmi\ClamWin
2009-03-04 00:57 . 2009-03-04 00:57 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\.clamwin
2009-03-04 00:57 . 2009-03-04 00:57 <DIR> d-------- c:\documents and settings\All Users\.clamwin
2009-03-03 23:53 . 2009-03-03 23:53 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Auslogics
2009-03-02 15:32 . 2009-03-10 17:34 127 --a------ c:\windows\system32\~.inf
2009-03-01 16:35 . 2009-03-01 16:35 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\Ahead
2009-03-01 16:27 . 2009-03-01 16:27 <DIR> d-------- c:\documents and settings\Ivano\Dati applicazioni\DivX
2009-03-01 16:20 . 2009-03-01 16:20 <DIR> d-------- c:\documents and settings\Ivano\Bluetooth Software
2009-03-01 13:58 . 2009-03-01 16:17 <DIR> d-------- c:\programmi\Orbitdownloader
2009-03-01 13:58 . 2009-03-01 13:59 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\Orbit
2009-03-01 13:58 . 2009-03-01 13:58 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\GrabPro
2009-03-01 13:55 . 2009-03-01 13:55 <DIR> d-------- c:\programmi\File comuni\xing shared
2009-03-01 13:55 . 2009-03-01 13:55 <DIR> d-------- c:\programmi\File comuni\Real
2009-03-01 13:55 . 2009-03-01 13:55 <DIR> d-------- C:\Program Files
2009-03-01 09:04 . 2009-03-13 08:57 <DIR> d-------- c:\programmi\Unlocker
2009-03-01 09:03 . 2009-03-01 09:03 <DIR> d-------- c:\documents and settings\Vittorio\Dati applicazioni\GlarySoft
2009-03-01 08:54 . 2009-03-01 08:54 <DIR> d-------- c:\programmi\Glary Utilities
2009-03-01 08:54 . 2009-03-01 08:54 <DIR> d-------- c:\programmi\CCleaner
2009-02-28 13:35 . 2009-03-12 00:15 <DIR> d-------- c:\programmi\TubeSucker
2009-02-28 10:49 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-28 10:49 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-02-28 10:49 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-28 07:13 . 2009-02-28 07:13 <DIR> d-------- c:\documents and settings\Orietta\Bluetooth Software
2009-02-27 21:37 . 2009-02-27 21:37 <DIR> d-------- c:\documents and settings\Pablo\Bluetooth Software
2009-02-27 19:07 . 2009-02-27 19:07 <DIR> d-------- c:\documents and settings\Vittorio\Bluetooth Software
2009-02-27 19:07 . 2008-04-13 19:13 21,504 --a------ c:\windows\system32\hidserv.dll
2009-02-27 19:07 . 2008-04-13 19:13 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll
2009-02-27 19:06 . 2008-04-13 18:53 14,720 --a------ c:\windows\system32\drivers\kbdhid.sys
2009-02-27 19:06 . 2008-04-13 18:53 14,720 --a--c--- c:\windows\system32\dllcache\kbdhid.sys
2009-02-27 19:05 . 2009-02-27 19:05 <DIR> d-------- c:\programmi\WIDCOMM
2009-02-27 19:05 . 2007-08-14 02:38 862,922 --a------ c:\windows\system32\drivers\btkrnl.sys
2009-02-27 19:05 . 2007-08-14 02:38 329,901 --a------ c:\windows\system32\drivers\btaudio.sys
2009-02-27 19:05 . 2007-08-14 02:38 149,123 --a------ c:\windows\system32\drivers\btwdndis.sys
2009-02-27 19:05 . 2007-08-14 02:38 106,557 --a------ c:\windows\system32\btw_ci.dll
2009-02-27 19:05 . 2007-08-14 02:38 67,672 --a------ c:\windows\system32\drivers\btwusb.sys
2009-02-27 19:05 . 2007-08-14 02:38 47,875 --a------ c:\windows\system32\drivers\btwhid.sys
2009-02-27 19:05 . 2007-08-14 02:38 30,459 --a------ c:\windows\system32\drivers\btport.sys
2009-02-27 19:05 . 2007-08-14 02:38 30,285 --a------ c:\windows\system32\drivers\btwmodem.sys
2009-02-27 16:58 . 2009-02-27 17:11 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\GetRightToGo
2009-02-27 16:03 . 2009-03-15 14:14 <DIR> d-------- c:\documents and settings\Pablo\Tracing
2009-02-27 16:00 . 2009-02-27 16:00 <DIR> d-------- c:\programmi\Windows Live SkyDrive
2009-02-27 16:00 . 2009-02-27 16:00 <DIR> d-------- c:\programmi\Windows Live
2009-02-27 16:00 . 2009-02-27 16:00 <DIR> d-------- c:\programmi\Microsoft
2009-02-27 15:55 . 2009-02-27 15:55 <DIR> d-------- c:\programmi\File comuni\Windows Live
2009-02-27 01:19 . 2009-03-13 21:36 <DIR> d-------- C:\downloads
2009-02-27 01:19 . 2009-03-13 21:58 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Orbit
2009-02-27 01:19 . 2009-03-01 14:19 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\GrabPro
2009-02-25 21:31 . 2009-03-07 17:12 16 --a------ c:\windows\popcinfo.dat
2009-02-25 17:46 . 2008-04-13 11:46 37,888 --a------ c:\windows\system32\drivers\bthmodem.sys
2009-02-25 17:46 . 2008-04-13 11:46 37,888 --a--c--- c:\windows\system32\dllcache\bthmodem.sys
2009-02-25 00:33 . 2009-02-25 00:33 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Ahead
2009-02-24 17:49 . 2009-02-24 17:49 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\OpenOffice.org
2009-02-23 22:18 . 2008-04-13 19:14 152,576 --a------ c:\windows\system32\irftp.exe
2009-02-23 01:27 . 2009-03-15 15:48 <DIR> d-------- c:\programmi\eMule
2009-02-21 02:12 . 2009-02-21 02:12 <DIR> d-------- c:\documents and settings\Pablo\Dati applicazioni\Creative
2009-02-21 02:09 . 2006-10-05 23:17 53,248 --------- c:\windows\Ctregrun.exe
2009-02-21 02:09 . 2003-06-12 23:25 7,062 --a------ c:\windows\system32\audiopid.vxd
2009-02-21 02:08 . 2009-02-21 02:08 <DIR> d-------- c:\programmi\File comuni\Creative
2009-02-21 02:08 . 2009-02-21 02:08 <DIR> d--h----- c:\programmi\Creative Installation Information
2009-02-21 02:08 . 2009-02-21 02:12 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Creative
2009-02-21 02:08 . 1999-12-12 18:01 44,032 --------- c:\windows\system32\CTSVCCDA.EXE
2009-02-21 02:08 . 1999-11-17 18:00 25,088 --------- c:\windows\system32\CTSVCCTL.EXE
2009-02-21 02:07 . 2009-02-21 02:07 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-21 02:07 . 2009-02-21 02:12 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-02-21 02:07 . 2009-02-21 02:09 <DIR> d-------- c:\programmi\Creative
2009-02-20 21:43 . 2009-03-12 10:40 65 --a------ c:\windows\FISHUI.INI
2009-02-20 21:03 . 2009-02-20 21:03 <DIR> d-------- c:\documents and settings\Orietta\Dati applicazioni\OpenOffice.org
2009-02-20 20:01 . 2009-02-20 20:01 <DIR> d-------- C:\My Video
2009-02-20 20:00 . 2009-02-20 20:00 <DIR> d-------- c:\programmi\Samsung

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-14 07:36 1,373,696 ----a-w c:\windows\Internet Logs\xDB1.tmp
2009-03-13 21:11 --------- d-----w c:\programmi\Java
2009-03-01 12:55 --------- d-----w c:\programmi\Google
2009-02-21 04:04 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-20 15:24 --------- d-----w c:\documents and settings\Vittorio\Dati applicazioni\Ahead
2009-02-19 16:54 --------- d-----w c:\programmi\Alwil Software
2009-02-19 16:52 --------- d-----w c:\programmi\OpenOffice.org 3
2009-02-19 16:52 --------- d-----w c:\programmi\JRE
2009-02-19 16:52 --------- d-----w c:\programmi\File comuni\Java
2009-02-19 16:48 --------- d-----w c:\programmi\PDFCreator
2009-02-19 16:48 --------- d-----w c:\programmi\DivX
2009-02-19 16:47 --------- d-----w c:\programmi\File comuni\Adobe
2009-02-19 16:47 --------- d-----w c:\programmi\AusLogics Disk Defrag
2009-02-19 16:38 --------- d-----w c:\programmi\File comuni\LightScribe
2009-02-19 16:37 --------- d-----w c:\programmi\File comuni\Ahead
2009-02-19 16:37 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Ahead
2009-02-19 16:35 --------- d-----w c:\programmi\Nero
2009-02-19 16:35 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Nero
2009-02-19 16:01 --------- d-----w c:\documents and settings\Vittorio\Dati applicazioni\ATI
2009-02-19 16:01 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\ATI
2009-02-19 16:00 --------- d-----w c:\programmi\ATI Technologies
2009-02-19 15:56 --------- d-----w c:\programmi\File comuni\InstallShield
2009-02-19 15:51 --------- d-----w c:\programmi\microsoft frontpage
2009-02-19 15:50 --------- d-----w c:\programmi\Servizi in linea
2009-02-09 14:04 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 17:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LightScribe Control Panel"="c:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe" [2007-07-18 451872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"UnlockerAssistant"="c:\programmi\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"ClamWin"="c:\programmi\ClamWin\bin\ClamTray.exe" [2008-11-09 86016]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-13 148888]
"SpywareTerminator"="c:\progra~1\SPYWAR~1\SpywareTerminatorShield.exe" [2009-03-13 2233856]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"TrojanScanner"="c:\programmi\Trojan Remover\Trjscan.exe" [2009-03-15 1303432]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 c:\windows\SkyTel.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 c:\windows\system32\bthprops.cpl]

c:\documents and settings\Orietta\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\Pablo\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\Vittorio\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.0.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-13 561213]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"IncrediMail"=c:\programmi\IncrediMail\bin\IncMail.exe /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MP10_EnsureFileVer"=c:\windows\inf\unregmp2.exe /EnsureFileVersions
"Alcmtr"=ALCMTR.EXE
"SMSTray"=c:\programmi\Samsung\EmoDio\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitdm.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitnet.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-19 114768]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2009-02-19 13696]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2009-03-13 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-19 20560]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [2009-02-20 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;c:\windows\system32\drivers\torususb.sys [2009-02-20 527980]
S2 gupdate1c99a6cf39b029c;Servizio di Google Update (gupdate1c99a6cf39b029c);c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-01 133104]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-02-23 37296]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'

2009-03-15 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2009-02-12 17:10]

2009-03-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-01 13:55]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://mystart.incredimail.com/italian
IE: &Download by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search - tbr:iemenu
IE: Do&wnload selected by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/202
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\programmi\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Vittorio\Dati applicazioni\Mozilla\Firefox\Profiles\52m0hmc0.default\
FF - component: c:\programmi\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\programmi\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\programmi\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\programmi\Crawler\Toolbar\firefox\components\xwsg.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmi\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 19:45:59
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(792)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-03-15 19.46.57
ComboFix-quarantined-files.txt 2009-03-15 18:46:54
ComboFix2.txt 2009-03-15 18:00:52

Pre-Run: 437.815.242.752 byte disponibili
Post-Run: 437,802,352,640 byte disponibili

279 --- E O F --- 2009-03-11 16:21:09

Ora conbofx va disinstallato?
Fammi sapere se ti sembra tutto ok.
Grazie
Vittorio
r16
Inviato: Sunday, March 15, 2009 9:18:46 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Posta un ultimo log di HJT.
Ma è tutto a posto.
Disattiva il ripristino configurazione di sistema.
Disinstalla combofix in questo modo:
Start
Esegui
nella finestra di dialogo, copia ed incolla questo comando: Combofix /u e premi Invio poi cancella le cartelle in "C" di combofix (qoobox)

Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
Poi:
Start\Esegui\copia e incolla la stringa %temp% clicca su Ok, svuota la cartella temp. (non eliminare la cartella)
Poi:
Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO
Poi:
Lancia Hijackthis e pulisci gli ADS in questo modo:
clicca sulla voce Open the misc tool section
clicca su Open ads spy
togli la spunta alla voce Quick scan (windows base folder only)
clicca su Scan
se venissero rilevati ADS, spunta tutte le caselline e clicca su Remove selected

Riavvia il pc.
Riattiva il ripristino configurazione di sistema e, se tutto è a posto, creane uno nuovo.
vittorio.sc
Inviato: Sunday, March 15, 2009 11:22:29 PM
Rank: Member

Iscritto dal : 11/11/2006
Posts: 21
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23.04.13, on 15/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Unlocker\UnlockerAssistant.exe
C:\Programmi\ClamWin\bin\ClamTray.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\OpenOffice.org 3\program\soffice.exe
C:\Programmi\OpenOffice.org 3\program\soffice.bin
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/italian
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Programmi\Orbitdownloader\orbitcth.dll
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Programmi\Orbitdownloader\GrabPro.dll
O3 - Toolbar: Toolbar &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programmi\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ClamWin] "C:\Programmi\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TrojanScanner] C:\Programmi\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Programmi\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Download by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{823ADB4E-0F3E-4CEB-9C49-B66540EA2AB2}: NameServer = 193.70.152.15 193.70.152.25
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Servizio di Google Update (gupdate1c99a6cf39b029c) (gupdate1c99a6cf39b029c) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 9674 bytes
Ti ho inviato il log.
Ora faccio quello che hai detto.
Grazie.
Vittorio
r16
Inviato: Sunday, March 15, 2009 11:28:11 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao Vittorio.
Il log è bello pulito.
Si, fai quelle operazioni di pulizia, il pc ti ringrazierà.Drool
Ciao!
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.