r16 ha scritto:Ciao.
Disattiva il Tea Timer di SpyBot:
Apri SpyBot in modalità avanzata (menù modalità - avanzata) poi vai in utilità - resident e
togli la spunta a TeaTimer, e
riavvia il pc.
Ci sono ancora delle infezioni.
Scarica Combofix (usa
Internet Explorer)
http://download.bleepingcomputer.com/sUBs/ComboFix.exeSalvalo sul
desktop. (
è obligatorio)
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.
Doppio click su combofix.exe (se usi Vista: tasto destro su Combofix.exe e clicca su: "Esegui come Amministratore" )
E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix)
tu ignorali.
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca
NO.
Durante l'operazione di scansione
è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\
ComboFix.txt.
Postalo qui.
fatto!!
ComboFix 10-10-02.02 - gianni 03/10/2010 17.44.18.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.3063.2410 [GMT 2:00]
Eseguito da: c:\documents and settings\gianni\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\Wyeke
c:\documents and settings\gianni\Dati applicazioni\PriceGong
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\1.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\a.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\b.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\c.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\d.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\e.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\f.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\g.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\h.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\i.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\J.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\k.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\l.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\m.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\mru.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\n.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\o.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\p.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\q.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\r.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\s.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\t.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\u.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\v.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\w.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\x.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\y.xml
c:\documents and settings\gianni\Dati applicazioni\PriceGong\Data\z.xml
c:\documents and settings\gianni\Recent\referto.pdf
c:\programmi\GooglePlusVideos
c:\programmi\GooglePlusVideos\DeploymentHelper.exe
c:\programmi\GooglePlusVideos\FFExt\chrome.manifest
c:\programmi\GooglePlusVideos\FFExt\chrome\content\googleplusvideos.xul
c:\programmi\GooglePlusVideos\FFExt\chrome\content\script-injector.js
c:\programmi\GooglePlusVideos\FFExt\install.rdf
c:\programmi\GooglePlusVideos\GooglePlusVideosLicense.txt
c:\programmi\GooglePlusVideos\GVConfig.ini
c:\programmi\GooglePlusVideos\MFC42U.DLL
c:\programmi\GooglePlusVideos\Uninstall.bat
D:\Autorun.inf
F:\autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WYEKE_SERVICE
((((((((((((((((((((((((( Files Creati Da 2010-09-03 al 2010-10-03 )))))))))))))))))))))))))))))))))))
.
2010-10-02 22:23 . 2010-10-03 07:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-10-02 22:23 . 2010-10-02 22:23 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-10-02 17:07 . 2010-10-02 17:07 63488 ----a-w- c:\documents and settings\gianni\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-10-02 17:07 . 2010-10-02 17:07 52224 ----a-w- c:\documents and settings\gianni\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-10-02 17:07 . 2010-10-02 17:07 117760 ----a-w- c:\documents and settings\gianni\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-10-02 17:06 . 2010-10-02 17:06 -------- d-----w- c:\documents and settings\gianni\Dati applicazioni\SUPERAntiSpyware.com
2010-10-02 17:06 . 2010-10-02 17:06 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2010-10-02 17:05 . 2010-10-02 17:05 -------- d-----w- c:\documents and settings\gianni\Dati applicazioni\Malwarebytes
2010-10-02 17:05 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-02 17:05 . 2010-10-02 17:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-10-02 17:05 . 2010-10-02 17:05 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-10-02 17:05 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-02 17:04 . 2010-10-02 17:06 -------- d-----w- c:\programmi\SUPERAntiSpyware
2010-10-02 16:26 . 2010-10-02 16:26 388096 ----a-r- c:\documents and settings\gianni\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-02 16:26 . 2010-10-02 16:26 -------- d-----w- c:\programmi\Trend Micro
2010-09-30 21:41 . 2010-09-30 21:41 -------- d-----w- C:\$AVG
2010-09-30 21:28 . 2010-09-30 21:28 -------- d-----w- c:\documents and settings\gianni\Dati applicazioni\IObit
2010-09-30 21:28 . 2010-09-30 21:28 -------- d-----w- c:\programmi\IObit
2010-09-30 20:58 . 2010-09-30 20:58 17552011 ----a-w- c:\documents and settings\gianni\Dati applicazioni\Intelli-studio\iUpdate.exe
2010-09-29 22:19 . 2010-09-29 22:19 -------- d-----w- c:\documents and settings\gianni\Dati applicazioni\AVG10
2010-09-29 22:16 . 2010-09-29 22:16 -------- d--h--w- c:\documents and settings\All Users\Dati applicazioni\Common Files
2010-09-29 22:13 . 2010-10-03 15:02 -------- d-----w- c:\windows\system32\drivers\AVG
2010-09-29 22:13 . 2010-09-29 22:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AVG10
2010-09-29 22:07 . 2010-09-29 22:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MFAData
2010-09-25 22:21 . 2009-10-20 16:20 265728 ------w- c:\windows\system32\dllcache\http.sys
2010-09-25 21:24 . 2008-06-14 17:32 272768 ------w- c:\windows\system32\dllcache\bthport.sys
2010-09-25 15:43 . 2010-09-25 15:43 -------- d-----w- c:\windows\ServicePackFiles
2010-09-23 21:08 . 2010-09-25 12:28 -------- d-----w- c:\documents and settings\gianni\Dati applicazioni\Ulead Systems
2010-09-23 21:04 . 2010-09-23 21:04 -------- d-----w- c:\windows\system32\windows media
2010-09-23 21:04 . 2010-09-23 21:04 -------- d--h--w- c:\windows\msdownld.tmp
2010-09-23 21:03 . 2010-09-23 21:03 -------- d-----w- c:\programmi\Windows Media Components
2010-09-23 21:02 . 2010-09-23 21:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Ulead Systems
2010-09-23 21:02 . 2010-09-23 21:02 -------- d-----w- c:\programmi\File comuni\Ulead Systems
2010-09-23 21:02 . 2010-09-23 21:02 -------- d-----w- c:\programmi\Ulead Systems
2010-09-23 20:57 . 2008-04-13 17:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-09-23 20:57 . 2008-04-13 17:45 60032 ----a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-09-23 20:49 . 2007-11-15 18:33 468096 ----a-w- c:\windows\system32\drivers\StkTMini.sys
2010-09-23 20:49 . 2006-12-20 06:38 12351744 ----a-w- c:\windows\system32\drivers\StkCPipe.sys
2010-09-13 14:27 . 2010-09-13 14:27 25680 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2010-09-07 01:49 . 2010-09-07 01:49 298448 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-09-07 01:48 . 2010-09-07 01:48 34384 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-09-07 01:48 . 2010-09-07 01:48 249424 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-09-07 01:48 . 2010-09-07 01:48 26064 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-03 08:53 . 2004-08-30 11:20 85330 ----a-w- c:\windows\system32\perfc010.dat
2010-10-03 08:53 . 2004-08-30 11:20 492504 ----a-w- c:\windows\system32\perfh010.dat
2010-09-30 21:06 . 2010-06-06 10:03 -------- d-----w- c:\documents and settings\gianni\Dati applicazioni\Intelli-studio
2010-09-29 22:12 . 2009-01-27 08:22 -------- d-----w- c:\programmi\AVG
2010-09-29 22:05 . 2009-03-07 22:12 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2010-09-29 22:05 . 2010-02-01 14:54 -------- d-----w- c:\programmi\IKEA HomePlanner
2010-09-29 21:39 . 2009-07-17 23:43 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-09-25 22:27 . 2006-08-23 04:48 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-09-25 15:47 . 2004-08-30 11:19 83535 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-09-25 13:43 . 2009-01-27 08:30 101984 ----a-w- c:\documents and settings\gianni\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-08-19 19:42 . 2010-08-19 19:42 30288 ----a-w- c:\windows\system32\drivers\AVGIDSFilter.sys
2010-08-19 19:42 . 2010-08-19 19:42 123472 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2010-08-19 19:42 . 2010-08-19 19:42 26192 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2010-08-17 13:17 . 2004-08-19 08:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 21:39 . 2010-08-16 21:39 23949040 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Yahoo!\YUpdater\msgup1000_1270_it.exe
2010-08-15 01:25 . 2009-11-23 09:38 -------- d-----w- c:\documents and settings\gianni\Dati applicazioni\TeamViewer
2010-08-12 13:54 . 2010-07-31 14:15 -------- d-----w- c:\programmi\ONDA CONNECTION MANAGER
2010-07-22 15:48 . 2004-08-19 08:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-20 22:41 . 2009-11-07 11:18 256 ----a-w- c:\windows\system32\pool.bin
2009-04-07 18:52 . 2009-04-07 18:52 28672 ----a-w- c:\programmi\mozilla firefox\components\GooglePlusVideosXPCOM.dll
2008-10-19 09:58 . 2008-10-19 09:58 49152 ----a-w- c:\programmi\mozilla firefox\components\SiteVacuumXPCOM.dll
2009-02-01 10:45 . 2009-02-01 10:44 952 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}]
2009-08-10 22:48 288056 ----a-w- c:\programmi\PriceGong\1.5.0\PriceGongIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programmi\File comuni\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Messenger (Yahoo!)"="c:\programmi\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-26 4351216]
"WMPNSCFG"="c:\programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 204288]
"Advanced SystemCare 3"="c:\programmi\IObit\Advanced SystemCare 3\AWC.exe" [2010-08-10 2349776]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-28 2424560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PTHOSTTR"="c:\programmi\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2006-02-14 122880]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-08-31 122940]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1015808]
"hpWirelessAssistant"="c:\programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 454656]
"CognizanceTS"="c:\progra~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 17920]
"QlbCtrl"="c:\programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-05-08 131072]
"Cpqset"="c:\programmi\HPQ\Default Settings\cpqset.exe" [2006-01-26 172094]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-03-09 806912]
"WatchDog"="c:\programmi\InterVideo\DVD Check\DVDCheck.exe" [2005-11-08 184320]
"SynTPStart"="c:\programmi\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2009-01-05 413696]
"RoxWatchTray"="c:\programmi\File comuni\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"IntelliPoint"="c:\programmi\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"HP Software Update"="c:\programmi\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"HPHUPD08"="c:\programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-17 49152]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"UVS10 Preload"="c:\programmi\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe" [2006-08-09 36864]
"AVG_TRAY"="c:\programmi\AVG\AVG10\avgtray.exe" [2010-09-15 2745696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2009-1-30 217088]
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
BlueSoleil.lnk - c:\programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe [2005-11-3 656384]
HP Digital Imaging Monitor.lnk - c:\programmi\Hp\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2005-07-25 18:41 40960 ----a-w- c:\programmi\HPQ\IAM\Bin\AsWlnPkg.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^DVD Check.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\DVD Check.lnk
backup=c:\windows\pss\DVD Check.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2009-05-26 19:06 4351216 ----a-w- c:\programmi\Yahoo!\Messenger\YahooMessenger.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Programmi\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Programmi\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Programmi\\AVG\\AVG10\\avgemcx.exe"=
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13/09/2010 16.27.24 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [07/09/2010 3.48.50 26064]
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [08/01/2009 0.39.36 20744]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [07/09/2010 3.48.54 249424]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [07/09/2010 3.49.00 298448]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 20.25.48 12872]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 20.41.30 67656]
R2 ASChannel;Canale di comunicazione locale;c:\windows\System32\svchost.exe -k Cognizance [19/08/2004 10.00.00 14336]
R2 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\SupportAppXL\cdrom_mon.exe [31/07/2010 14.44.42 81920]
R2 AVGIDSAgent;AVGIDSAgent;c:\programmi\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [03/09/2010 10.35.50 6104144]
R2 avgwd;AVG WatchDog;c:\programmi\AVG\AVG10\avgwdsvc.exe [10/09/2010 1.45.22 265400]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [17/02/2009 1.09.04 8192]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [19/08/2010 21.42.36 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [19/08/2010 21.42.38 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [19/08/2010 21.42.34 26192]
S2 ONDA Autorun CDROM Monitor;ONDA Autorun CDROM Monitor;c:\windows\system32\SupportAppXL\onda_mon.exe --> c:\windows\system32\SupportAppXL\onda_mon.exe [?]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [07/12/2008 13.44.54 30088]
S3 GTIPCI21;GTIPCI21;c:\windows\system32\DRIVERS\gtipci21.sys --> c:\windows\system32\DRIVERS\gtipci21.sys [?]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [02/07/2008 15.58.48 26248]
S3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\drivers\ONDAusbmdm6k.sys [31/07/2010 16.16.08 100480]
S3 ONDAusbnet;ONDA USB-NDIS miniport;c:\windows\system32\drivers\ONDAusbnet.sys [31/07/2010 16.16.08 87552]
S3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\drivers\ONDAusbnmea.sys [31/07/2010 16.16.08 100480]
S3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\drivers\ONDAusbser6k.sys [31/07/2010 16.16.08 100480]
S3 P1001VID;Creative WebCam (WDM);c:\windows\system32\drivers\P1001Vid.sys [03/02/2009 17.23.11 311684]
S3 StkTMini;Syntek AVStream USB2.0 ATV;c:\windows\system32\drivers\StkTMini.sys [23/09/2010 22.49.11 468096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
.
Contenuto della cartella 'Scheduled Tasks'
2009-02-02 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\programmi\Microsoft IntelliPoint\ipoint.exe [2008-06-10 11:56]
2010-10-03 c:\windows\Tasks\User_Feed_Synchronization-{3C673716-9310-4749-85AB-F934D9B6F1C2}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: &Cerca con Google - c:\programmi\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Traduci parola in italiano - c:\programmi\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Link a ritroso - c:\programmi\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Pagine simili - c:\programmi\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Versione cache della pagina - c:\programmi\Google\GoogleToolbar1.dll/cmcache.html
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\gianni\Dati applicazioni\Mozilla\Firefox\Profiles\hp0x0gyv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it
FF - prefs.js: keyword.URL - hxxp://it.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_it&p=
FF - component: c:\programmi\AVG\AVG10\Firefox\components\avgssff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D0523BB4-21E7-11DD-9AB7-415B56D89593} - (no file)
HKLM-Run-Recguard - c:\windows\Sminst\Recguard.exe
AddRemove-Creative WebCam - c:\windows\CtDrvIns.exe -uninstall USB\VID_041E&PID_400D -plugin P1001Pin.dll
AddRemove-recfree - c:\programmi\RecFree.com\recfree\1.3.60.6\uninstall.exe
AddRemove-RecFreeToolbar - c:\programmi\RecFree.com\RecFreeToolbar\1.3.11.0\uninstall.exe
**************************************************************************
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\HPQ\Default Settings\cpqset.exe????????pS??7?4?7?3??????? ??4B??????????????hB?????pS?
Scansione files nascosti ...
Scansione completata con successo
Files nascosti:
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"0140111900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1084)
c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\programmi\HPQ\IAM\Bin\AsWlnPkg.dll
- - - - - - - > 'explorer.exe'(1612)
c:\windows\system32\WININET.dll
c:\progra~1\ALICET~1\SMARTB~1\SBHook.dll
c:\programmi\HPQ\IAM\Bin\SFSShell.dll
c:\programmi\HPQ\IAM\bin\ItMsg.dll
c:\programmi\HPQ\IAM\bin\1040\SFSShell.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\progra~1\AVG\AVG10\avgchsvx.exe
c:\progra~1\AVG\AVG10\avgrsx.exe
c:\windows\system32\DllHost.exe
c:\windows\System32\SCardSvr.exe
c:\programmi\HPQ\IAM\bin\asghost.exe
c:\windows\system32\agrsmsvc.exe
c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\MCCITR~1.EXE
c:\windows\system32\igfxsrvc.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\IVT Corporation\BlueSoleil\BTNtService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\programmi\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
c:\programmi\AVG\AVG10\avgnsx.exe
c:\programmi\AVG\AVG10\avgemcx.exe
c:\programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
c:\programmi\Hewlett-Packard\Shared\hpqwmiex.exe
c:\programmi\Windows Media Player\WMPNetwk.exe
c:\programmi\HP\Digital Imaging\bin\hpqSTE08.exe
c:\programmi\iPod\bin\iPodService.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\programmi\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\programmi\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Ora fine scansione: 2010-10-03 17:56:52 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-10-03 15:56
Pre-Run: 128.895.201.280 byte disponibili
Post-Run: 129.452.834.816 byte disponibili
- - End Of File - - FE37630A99823660E182D0AB2437799E
adesso provo a riavviare e ti dico