ecco il log di Combo Fix:
ComboFix 10-06-21.03 - Franco 22/06/2010 18.01.40.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.959.422 [GMT 2:00]
Eseguito da: c:\documents and settings\Franco\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD0EC-FFA4-00EB-0D24-347CA8A3377C}
* Resident AV is active
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\pswi_preloaded.exe
c:\documents and settings\Franco\Dati applicazioni\.#
c:\programmi\RegistryDoktor 4.1
.
((((((((((((((((((((((((( Files Creati Da 2010-05-22 al 2010-06-22 )))))))))))))))))))))))))))))))))))
.
2010-06-18 21:14 . 2010-06-18 21:14 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-16 07:43 . 2010-06-16 19:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PCPitstop
2010-06-16 07:43 . 2010-06-16 07:50 -------- d-----w- c:\programmi\PCPitstop
2010-06-11 17:15 . 2010-06-16 17:56 400184 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-06-11 09:41 . 2010-05-06 10:32 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-08 19:13 . 2010-06-17 08:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2010-06-07 17:56 . 2010-06-19 14:09 -------- d-----w- C:\unzipped
2010-06-06 08:57 . 2010-06-06 08:57 -------- d-----w- c:\programmi\Garmin GPS Plugin
2010-06-04 08:12 . 2010-06-04 08:12 45056 ----a-r- c:\documents and settings\Franco\Dati applicazioni\Microsoft\Installer\{DDA2B32F-EB16-4C96-A130-4E4A4C1E6B12}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2010-06-04 08:11 . 2010-06-04 08:11 43672 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2010-06-04 07:46 . 2010-06-04 08:16 19876 ------w- c:\windows\HPHins02.dat
2010-06-04 07:46 . 2004-05-24 13:40 4308 ------w- c:\windows\hphmdl02.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-21 06:58 . 2010-01-21 09:42 13568 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-06-20 16:00 . 2009-06-11 13:17 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Azureus
2010-06-19 22:00 . 2007-05-20 16:04 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Skype
2010-06-19 16:04 . 2009-08-27 10:16 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Any Video Converter
2010-06-19 14:56 . 2010-03-17 22:33 -------- d-----w- c:\programmi\Desktop Restore
2010-06-18 07:14 . 2007-05-20 16:03 -------- d-----w- c:\programmi\Google
2010-06-16 19:52 . 2010-05-08 13:45 -------- d-----w- c:\programmi\Messenger_Plus_Live_Italy
2010-06-16 08:19 . 2007-09-27 16:38 -------- d-----w- c:\programmi\Messenger Plus! Live
2010-06-12 08:25 . 2001-08-31 12:00 527092 ----a-w- c:\windows\system32\perfh010.dat
2010-06-12 08:25 . 2001-08-31 12:00 45172 ----a-w- c:\windows\system32\perfc010.dat
2010-06-08 19:34 . 2008-04-24 13:31 -------- d-----r- c:\programmi\Skype
2010-06-08 19:34 . 2007-05-20 16:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2010-06-06 10:03 . 2008-10-19 17:04 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\GARMIN
2010-06-05 21:09 . 2009-10-26 13:54 -------- d-----w- c:\programmi\Glary Utilities
2010-06-04 18:49 . 2008-09-06 13:52 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-06-04 18:45 . 2007-11-16 08:51 -------- d-----w- c:\programmi\Windows Live
2010-06-04 18:44 . 2007-11-16 08:51 -------- dcsh--w- c:\programmi\File comuni\WindowsLiveInstaller
2010-06-04 08:11 . 2007-05-18 15:25 -------- d-----w- c:\programmi\Hewlett-Packard
2010-06-03 21:35 . 2010-03-31 09:12 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-03 09:01 . 2008-12-23 15:39 -------- d-----w- c:\programmi\Microsoft
2010-05-21 12:14 . 2009-10-03 10:39 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 13:20 . 2007-05-23 20:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Motive
2010-05-18 13:17 . 2007-05-23 20:24 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\LimeWire
2010-05-18 13:17 . 2010-04-23 13:00 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Audacity
2010-05-18 13:17 . 2009-10-21 16:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2010-05-17 20:27 . 2010-05-17 20:23 -------- d-----w- c:\programmi\iTunes
2010-05-17 20:24 . 2010-05-17 20:24 -------- d-----w- c:\programmi\iPod
2010-05-17 20:24 . 2009-09-18 14:38 -------- d-----w- c:\programmi\File comuni\Apple
2010-05-17 19:58 . 2010-05-17 19:58 -------- d-----w- c:\programmi\Bonjour
2010-05-17 19:55 . 2010-05-17 19:55 73000 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-16 19:05 . 2009-10-23 22:01 -------- d-----w- c:\programmi\NVIDIA Corporation
2010-05-12 20:37 . 2010-05-12 20:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WD_SmartWareCommon
2010-05-12 16:08 . 2007-05-23 19:59 -------- d-----w- c:\programmi\eMule
2010-05-11 12:17 . 2010-05-11 12:17 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Western Digital
2010-05-11 12:17 . 2010-05-11 12:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Western Digital
2010-05-11 12:16 . 2010-05-11 12:16 -------- d-----w- c:\programmi\Western Digital
2010-05-10 20:34 . 2009-06-11 13:16 -------- d-----w- c:\programmi\Vuze
2010-05-08 17:40 . 2009-01-16 21:27 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\uTorrent
2010-05-06 10:32 . 2004-08-19 13:39 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:06 . 2004-08-19 13:31 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 18:09 . 2007-05-21 18:31 -------- d-----w- c:\programmi\Alice ti aiuta
2010-04-28 20:45 . 2010-03-25 18:45 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\U3
2010-04-28 20:04 . 2010-04-28 20:04 -------- d-----w- c:\programmi\File comuni\SWF Studio
2010-04-28 19:41 . 2008-10-05 14:48 -------- d-----w- c:\programmi\Nokia
2010-04-28 19:41 . 2007-05-21 19:32 -------- d-----w- c:\programmi\QuickTime
2010-04-28 19:41 . 2010-04-23 12:31 -------- d-----w- c:\programmi\Audacity 1.3 Beta (Unicode)
2010-04-28 19:41 . 2010-01-09 15:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Suite
2010-04-28 19:41 . 2009-10-26 13:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2010-04-28 09:13 . 2010-03-31 10:25 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-04-27 18:29 . 2010-04-27 18:29 4141117 ----a-w- c:\documents and settings\Franco\Dati applicazioni\Azureus\plugins\vuzexcode\mediainfo.exe
2010-04-27 18:29 . 2010-04-27 18:29 7282688 ----a-w- c:\documents and settings\Franco\Dati applicazioni\Azureus\plugins\vuzexcode\ffmpeg.exe
2010-04-20 05:30 . 2004-08-19 13:37 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-18 19:47 . 2010-04-18 19:47 45648 ----a-w- c:\windows\system32\drivers\rvsystem.sys
2010-04-17 00:24 . 2010-04-17 00:24 306544 ----a-w- c:\windows\WLXPGSS.SCR
2010-04-16 20:12 . 2010-04-16 20:12 48464 ----a-w- c:\windows\system32\sirenacm.dll
2010-04-08 11:20 . 2010-04-08 11:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 11:20 . 2010-04-08 11:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-04-02 17:13 . 2010-04-02 17:13 95232 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-04-02 17:13 . 2010-04-02 17:13 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-02 17:13 . 2010-04-02 17:13 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-02 17:13 . 2010-04-02 17:13 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-03-31 09:12 . 2010-03-31 09:12 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-29 08:29 . 2010-04-02 17:14 34513376 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_ita_web.exe
2008-04-17 12:30 . 2008-01-26 18:15 88 --sh--r- c:\windows\system32\2DE126F1C3.sys
2008-04-17 12:30 . 2007-11-20 23:13 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
Code:<pre>
c:\programmi\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\programmi\Logitech\Desktop Messenger\8876480\Program\backweb-8876480 .exe
c:\programmi\SUPERAntiSpyware\superantispyware .exe
c:\windows\system32\ctfmon .exe
c:\windows\system32\hphmon05 .exe
c:\windows\system32\nerocheck .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{08d495ab-a86c-47b0-82ef-da87bf92f730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08d495ab-a86c-47b0-82ef-da87bf92f730}]
2010-04-15 10:33 2515552 ----a-w- c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{08d495ab-a86c-47b0-82ef-da87bf92f730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{08D495AB-A86C-47B0-82EF-DA87BF92F730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\programmi\RocketDock\RocketDock.exe" [2007-09-02 495616]
"RestoreDesktop"="c:\programmi\Restore Desktop\RestoreDesktop.exe" [2003-03-11 45056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2010-02-27 209153]
"HPHUPD05"="c:\programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe" [2004-04-01 49152]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2004-05-05 491520]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
WDDMStatus.lnk - c:\programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoPopUpsOnBoot"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 06:38 241664 ----a-w- c:\programmi\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-12-05 13:41 49152 ----a-w- c:\programmi\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2006-03-21 12:19 69632 ----a-w- c:\programmi\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 08:57 1451520 ----a-w- c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-09-29 23:14 155648 ----a-r- c:\programmi\File comuni\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-02-08 15:58 39408 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"RTHDCPL"=RTHDCPL.EXE
"Alcmtr"=ALCMTR.EXE
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Programmi\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Programmi\\File comuni\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25736:TCP"= 25736:TCP:eMule_TCP
"25745:UDP"= 25745:UDP:eMule_UDP
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/03/2010 11.12.05 64288]
R0 RVSystem;RVSystem;c:\windows\system32\drivers\rvsystem.sys [18/04/2010 21.47.10 45648]
R1 rvsmon;rvsmon;c:\windows\system32\drivers\rvsmon.sys [18/04/2010 21.47.20 264128]
R1 rvsmonn;rvsmonn;c:\windows\system32\drivers\rvsmonn1.sys [18/04/2010 21.47.23 28640]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\programmi\Avira\AntiVir Desktop\avmailc.exe [27/02/2010 20.39.41 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmi\Avira\AntiVir Desktop\sched.exe [27/02/2010 20.39.45 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\programmi\Avira\AntiVir Desktop\avwebgrd.exe [27/02/2010 20.39.43 434945]
R2 ASKService;ASKService;c:\programmi\AskBarDis\bar\bin\AskService.exe [11/06/2009 15.17.58 464264]
R2 ASKUpgrade;ASKUpgrade;c:\programmi\AskBarDis\bar\bin\ASKUpgrade.exe [11/06/2009 15.18.09 234888]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 17.52.57 1352832]
R2 RVSMONBL;Returnil Virtual System Core Service;c:\windows\system32\Returnil\RVS3\rvsmon.exe [06/04/2010 17.13.18 1254800]
R2 rvsmonf;rvsmonf;c:\windows\system32\drivers\rvsmonf.sys [18/04/2010 21.47.22 1035080]
R2 WDDMService;WD SmartWare Drive Manager;c:\programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [13/11/2009 11.28.04 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 8.58.08 20480]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [03/11/2006 18.19.58 13592]
R3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [21/01/2010 11.42.06 13568]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [11/05/2010 14.17.20 11520]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25/03/2008 11.11.27 717296]
S1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\DRIVERS\StarPortLite.sys --> c:\windows\system32\DRIVERS\StarPortLite.sys [?]
S2 gupdate1c98a061b8f7796;Google Update Service (gupdate1c98a061b8f7796);c:\programmi\Google\Update\GoogleUpdate.exe [08/02/2009 17.58.37 133104]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [13/07/2008 11.51.57 8192]
S3 MA8630C;MA8630C;c:\windows\system32\drivers\MA8630C.sys [07/10/2008 22.38.45 23248]
S3 MA8630M;MA8630M;c:\windows\system32\drivers\MA8630M.sys [07/10/2008 22.38.46 25428]
S3 MA8630U;MA8630U;c:\windows\system32\drivers\MA8630U.sys [07/10/2008 22.38.47 51154]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenuto della cartella 'Scheduled Tasks'
2010-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 20:59]
2010-06-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-06-16 c:\windows\Tasks\CanoScan Toolbox 5.job
- c:\progra~1\Canon\CANOSC~1.0\CSTBox.exe [2009-10-16 16:54]
2010-06-22 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2010-02-07 08:01]
2010-06-22 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-05-20 19:13]
2010-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-08 15:58]
2010-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-08 15:58]
2010-06-22 c:\windows\Tasks\HP Usg Daily.job
- c:\programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe [2004-04-01 10:33]
2010-06-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 16:20]
2010-06-22 c:\windows\Tasks\Pulitura disco.job
- c:\windows\system32\cleanmgr.exe [2004-08-19 02:14]
2010-06-21 c:\windows\Tasks\WebReg 20091021182202.job
- c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe [2002-10-16 13:39]
2010-06-17 c:\windows\Tasks\Windows Update.job
- c:\windows\system32\wupdmgr.exe [2001-08-31 12:00]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.com/ig?hl=it
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://www.mirarsearch.com/?useie5=1&q=
IE: &ieSpell Options - c:\programmi\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\programmi\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\programmi\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\programmi\ieSpell\wikipedia.HTM
LSP: c:\programmi\Avira\AntiVir Desktop\avsda.dll
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {4EC99A0B-E57C-4FBE-B9C4-8428424FBF88} - hxxp://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
DPF: {528BF874-2681-4CE3-8C62-AA0D3BC0A719} - hxxp://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
DPF: {5AF01DCD-8539-4814-9693-ADF47058F075} - hxxp://aiuto.alice.it/ata/static/installers/WebflowActiveXInstaller_4-1-5.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
Toolbar-{701436C2-A36F-40FF-8009-866EB98ABB85} - (no file)
WebBrowser-{F4035115-6152-4901-A81D-F4E0A0479615} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{701436C2-A36F-40FF-8009-866EB98ABB85} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-22 18:11
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"659BD8E725A05FDCC64118EA787EAA2B534A94FABE"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8b,4e,a9,aa,a0,bb,b4,43,bb,86,30,\
"3A77B377802A4B6183DDE08FDE4AD9AF647A702826"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8b,4e,a9,aa,a0,bb,b4,43,bb,86,30,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'lsass.exe'(768)
c:\programmi\Avira\AntiVir Desktop\avsda.dll
.
Ora fine scansione: 2010-06-22 18:17:26
ComboFix-quarantined-files.txt 2010-06-22 16:17
ComboFix2.txt 2009-05-05 15:53
Pre-Run: 21.420.539.904 byte disponibili
Post-Run: 21.751.861.248 byte disponibili
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - F8E3D2EB5C1CD2848064BA1A1E91A37A
Per quanto riguarda il Fax ho eseguito quanto suggeritomi sia per l'impostazione che per il cavo di collegamento ma i fax non partono:vorrei rinunciare ma piuttosto mi pare sia possibile spedire i Fax anche attraverso il modem ADSL alice gate voip 2 plus....se si cosa devo fare?
Grazie cbbusto,fdaccc,paolopa per l'aiuto!
PS.ho annullato diversi programmi in apertura ed ora mi pare sia tornato tutto normale circa la lentezza.
Mi resta ancora il problema della finestra di WORD che ogni tanto compare la scritta"Il file normale esiste già.Sostituirlo?" io dico SI per eliminare questa finestra ,però mi dà fastidio....!!!Ciao ragazzi e grazie sarò noioso!