Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Virus o similare che non riesco ad eliminare!!!! Opzioni
unodeisenatori
Inviato: Tuesday, March 17, 2009 5:45:27 PM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
eseguo!
unodeisenatori
Inviato: Tuesday, March 17, 2009 6:27:22 PM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47


Avira AntiVir Personal
Report file date: martedì 17 marzo 2009 17:42

Scanning for 1305356 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: MICHELE

Version information:
BUILD.DAT : 8.2.0.347 16934 Bytes 16/03/2009 14:45:00
AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 08:21:26
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 16:39:36
ANTIVIR2.VDF : 7.1.2.152 749568 Bytes 11/03/2009 16:39:38
ANTIVIR3.VDF : 7.1.2.183 189952 Bytes 17/03/2009 16:39:39
Engineversion : 8.2.0.116
AEVDF.DLL : 8.1.1.0 106868 Bytes 17/03/2009 16:39:50
AESCRIPT.DLL : 8.1.1.63 364923 Bytes 17/03/2009 16:39:49
AESCN.DLL : 8.1.1.8 127346 Bytes 17/03/2009 16:39:48
AERDL.DLL : 8.1.1.3 438645 Bytes 04/11/2008 13:58:38
AEPACK.DLL : 8.1.3.10 397686 Bytes 17/03/2009 16:39:47
AEOFFICE.DLL : 8.1.0.36 196987 Bytes 17/03/2009 16:39:46
AEHEUR.DLL : 8.1.0.104 1634679 Bytes 17/03/2009 16:39:45
AEHELP.DLL : 8.1.2.2 119158 Bytes 17/03/2009 16:39:42
AEGEN.DLL : 8.1.1.29 336245 Bytes 17/03/2009 16:39:41
AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 10:05:56
AECORE.DLL : 8.1.6.6 176501 Bytes 17/03/2009 16:39:40
AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 10:05:56
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 12:02:15
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\programmi\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: martedì 17 marzo 2009 17:42

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'GiocoDigitalePoker.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
Scan process 'ImApp.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'UStorSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'PSIService.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
31 processes with 31 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '54' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\responsabile\Desktop\Dow\FindyKill.exe
[DETECTION] Contains recognition pattern of the DR/Tool.PsKill.K.39 dropper
[NOTE] The file was moved to '4a2dd485.qua'!
C:\System Volume Information\_restore{FD94A837-E8C9-4AAE-8F6F-6EA6E3898508}\RP3\A0000251.exe
[DETECTION] Contains recognition pattern of the DR/Tool.PsKill.K.39 dropper
[NOTE] The file was moved to '49efdb30.qua'!
C:\{80016EEE-0000-0000-BEDD-B2AC1A83D4DF}\DATA.CAB
[0] Archive type: CAB (Microsoft)
--> RESOURCE1
[1] Archive type: HIDDEN
--> MEM\AV0008e543.AV$
[DETECTION] Contains recognition pattern of the DR/Click.Agent.IP.5 dropper
[NOTE] The file was moved to '4a13dcf9.qua'!


End of the scan: martedì 17 marzo 2009 18:24
Used time: 41:22 Minute(s)

The scan has been done completely.

7609 Scanning directories
663816 Files were scanned
4 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
3 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
663811 Files not concerned
3733 Archives were scanned
1 Warnings
3 Notes

shapiro
Inviato: Tuesday, March 17, 2009 10:10:43 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
spero che questa sia la fase conclusiva - sei riuscito a reinstallare l'antivirus che ti ha trovato altre 3 infezioni

altra cosa importante : aggiorna il service pack 3

http://www.microsoft.com/downloads/details.aspx?FamilyID=5b33b5a8-5e76-401f-be08-1e1555d4f3d4&DisplayLang=it
unodeisenatori
Inviato: Wednesday, March 18, 2009 8:11:07 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
questo l'ho lanciato ieri sera prima di andare a casa



Avira AntiVir Personal
Report file date: martedì 17 marzo 2009 18:30

Scanning for 1305356 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: MICHELE

Version information:
BUILD.DAT : 8.2.0.347 16934 Bytes 16/03/2009 14:45:00
AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 08:21:26
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 16:39:36
ANTIVIR2.VDF : 7.1.2.152 749568 Bytes 11/03/2009 16:39:38
ANTIVIR3.VDF : 7.1.2.183 189952 Bytes 17/03/2009 16:39:39
Engineversion : 8.2.0.116
AEVDF.DLL : 8.1.1.0 106868 Bytes 17/03/2009 16:39:50
AESCRIPT.DLL : 8.1.1.63 364923 Bytes 17/03/2009 16:39:49
AESCN.DLL : 8.1.1.8 127346 Bytes 17/03/2009 16:39:48
AERDL.DLL : 8.1.1.3 438645 Bytes 04/11/2008 13:58:38
AEPACK.DLL : 8.1.3.10 397686 Bytes 17/03/2009 16:39:47
AEOFFICE.DLL : 8.1.0.36 196987 Bytes 17/03/2009 16:39:46
AEHEUR.DLL : 8.1.0.104 1634679 Bytes 17/03/2009 16:39:45
AEHELP.DLL : 8.1.2.2 119158 Bytes 17/03/2009 16:39:42
AEGEN.DLL : 8.1.1.29 336245 Bytes 17/03/2009 16:39:41
AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 10:05:56
AECORE.DLL : 8.1.6.6 176501 Bytes 17/03/2009 16:39:40
AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 10:05:56
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 12:02:15
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\programmi\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: martedì 17 marzo 2009 18:30

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'userinit.exe' - '1' Module(s) have been scanned
Scan process 'ImApp.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
Scan process 'UStorSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'PSIService.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
34 processes with 34 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '54' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!


End of the scan: martedì 17 marzo 2009 19:09
Used time: 38:30 Minute(s)

The scan has been done completely.

7608 Scanning directories
663813 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
663812 Files not concerned
3731 Archives were scanned
1 Warnings
0 Notes

unodeisenatori
Inviato: Wednesday, March 18, 2009 8:47:25 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
continuo a non poter lanciare hjt e shopos antirootkit
shapiro
Inviato: Wednesday, March 18, 2009 8:54:11 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
disinstalla sophos e hijackthis e reinstallali puliti

unodeisenatori
Inviato: Wednesday, March 18, 2009 9:39:20 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
evvaiiiiiiiiiiiiii

log hjt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:36, on 2009-03-18
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\IncrediMail\bin\IMApp.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file)
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Programmi\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [JobHisInit] C:\Programmi\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Programmi\Intel Audio Studio\IntelAudioStudio.exe" BOOT
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [IncrediMail] C:\Programmi\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ricerca - res://C:\Programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) -
O16 - DPF: {4C833081-D026-4FF8-968F-7EAB660D2FBA} (TVAnts ActiveX Control) -
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} -
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = umbriaservizi.locale
O17 - HKLM\Software\..\Telephony: DomainName = umbriaservizi.locale
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = umbriaservizi.locale
O20 - Winlogon Notify: nnnkijj - C:\WINDOWS\
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe

--
End of file - 8249 bytes
unodeisenatori
Inviato: Wednesday, March 18, 2009 9:49:20 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
shopos anti rootkit partito e non ha rilevato nessuna infezione...

shap sei mitico...Applause Applause Applause

non ho altre parole...

4 giorni di dura battaglia ma il capitano e il fido scudiero hanno eliminato il male!Dancing

ultima rottura di balle e poi vado a pubblicizzarti anche sul forum di ebay....te lo meriti

E' vero che avira non scansiona le e-mail?
shapiro
Inviato: Wednesday, March 18, 2009 9:52:54 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ciao Drool sei troppo forte

si e' vero, avira free non scansiona le mail, ma puoi scaricarle sul desktop e scansionarle, oppure con meno di 20 euro l'anno hai avira che ti scansiona anche la posta

fai un'altro sforzo

Scarica Lop S&D | http://eric.71.mespages.googlepages.com/LopSD.exe
con tutte le applicazioni chiuse e disconnesso
doppio click su LopSD
scegli la lingua E (invio)


scegli solo l'opzione 2 (invio)

allega il report C:\LopR.txt insieme ad un nuovo log di hijackthis
unodeisenatori
Inviato: Wednesday, March 18, 2009 10:12:20 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
log lop s&d


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz )
BIOS : Default System BIOS
USER : responsabile ( Not Administrator ! )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:233 Go (Free:195 Go)
D:\ (CD or DVD)
X:\ (Network Disk)
Y:\ (Network Disk)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 2009-03-18|10:03 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

Deleted! - C:\DOCUME~1\RESPON~1\Cookies\responsabile@banner.32vegas[2].txt

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in DATIAP~1

[2009-03-11|11:55] C:\DOCUME~1\ADMINI~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\ADMINI~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\ADMINI~1\DATIAP~1\byte disponibili

[2009-03-13|11:22] C:\DOCUME~1\ALLUSE~1\DATIAP~1\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
[2008-11-14|14:36] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Adobe
[2008-11-07|09:52] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Apple
[2008-11-07|09:54] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Apple Computer
[2008-07-16|07:41] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Autodesk
[2009-03-17|17:37] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Avira
[2008-12-10|15:05] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Corel
[2007-11-29|14:55] C:\DOCUME~1\ALLUSE~1\DATIAP~1\eBay
[2008-09-08|17:20] C:\DOCUME~1\ALLUSE~1\DATIAP~1\GiocoDigitale
[2008-08-07|08:43] C:\DOCUME~1\ALLUSE~1\DATIAP~1\IM
[2008-08-07|08:42] C:\DOCUME~1\ALLUSE~1\DATIAP~1\IncrediMail
[2009-02-06|15:47] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Installations
[2009-01-12|14:56] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Malwarebytes
[2009-02-02|11:40] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Microsoft
[2008-01-16|12:05] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Nokia
[2008-10-17|11:53] C:\DOCUME~1\ALLUSE~1\DATIAP~1\NVIDIA
[2008-07-18|08:09] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Office Genuine Advantage
[2007-05-21|16:37] C:\DOCUME~1\ALLUSE~1\DATIAP~1\PC Suite
[2008-09-03|07:38] C:\DOCUME~1\ALLUSE~1\DATIAP~1\RoboForm
[2009-03-16|11:27] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Spybot - Search & Destroy
[2009-02-02|17:41] C:\DOCUME~1\ALLUSE~1\DATIAP~1\SweetIM
[2009-03-11|12:20] C:\DOCUME~1\ALLUSE~1\DATIAP~1\TEMP
[2008-01-16|10:06] C:\DOCUME~1\ALLUSE~1\DATIAP~1\TVU networks
[2008-01-18|15:18] C:\DOCUME~1\ALLUSE~1\DATIAP~1\WholeSecurity
[2007-05-11|11:16] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Windows Genuine Advantage
[2008-03-11|17:43] C:\DOCUME~1\ALLUSE~1\DATIAP~1\WLInstaller
[0|File] C:\DOCUME~1\ALLUSE~1\DATIAP~1\byte
[28|Directory] C:\DOCUME~1\ALLUSE~1\DATIAP~1\byte disponibili

[2007-05-11|10:44] C:\DOCUME~1\DEFAUL~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\DEFAUL~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\DEFAUL~1\DATIAP~1\byte disponibili

[2009-03-11|11:55] C:\DOCUME~1\LOCALS~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\LOCALS~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\LOCALS~1\DATIAP~1\byte disponibili

[2009-03-11|11:55] C:\DOCUME~1\NETWOR~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\NETWOR~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\NETWOR~1\DATIAP~1\byte disponibili

[2008-01-29|16:37] C:\DOCUME~1\RESPON~1\DATIAP~1\Acreon
[2008-03-11|10:48] C:\DOCUME~1\RESPON~1\DATIAP~1\AD ON Multimedia
[2008-11-05|18:43] C:\DOCUME~1\RESPON~1\DATIAP~1\Adobe
[2008-11-05|18:43] C:\DOCUME~1\RESPON~1\DATIAP~1\AdobeAUM
[2008-11-05|18:43] C:\DOCUME~1\RESPON~1\DATIAP~1\AdobeUM
[2007-05-31|08:33] C:\DOCUME~1\RESPON~1\DATIAP~1\Ahead
[2008-11-10|12:24] C:\DOCUME~1\RESPON~1\DATIAP~1\Apple Computer
[2008-07-16|07:41] C:\DOCUME~1\RESPON~1\DATIAP~1\Autodesk
[2007-06-05|09:53] C:\DOCUME~1\RESPON~1\DATIAP~1\CasaPortale.de
[2008-12-10|15:06] C:\DOCUME~1\RESPON~1\DATIAP~1\Corel
[2008-01-14|18:40] C:\DOCUME~1\RESPON~1\DATIAP~1\DeepBurner
[2007-11-29|14:55] C:\DOCUME~1\RESPON~1\DATIAP~1\eBay
[2008-09-05|11:43] C:\DOCUME~1\RESPON~1\DATIAP~1\GanymedeNet
[2008-05-29|13:44] C:\DOCUME~1\RESPON~1\DATIAP~1\GeoVid
[2007-06-11|09:08] C:\DOCUME~1\RESPON~1\DATIAP~1\Graphisoft
[2007-10-29|17:05] C:\DOCUME~1\RESPON~1\DATIAP~1\gtk-2.0
[2007-05-31|14:32] C:\DOCUME~1\RESPON~1\DATIAP~1\Help
[2007-05-11|15:42] C:\DOCUME~1\RESPON~1\DATIAP~1\Identities
[2007-10-29|15:52] C:\DOCUME~1\RESPON~1\DATIAP~1\Inkscape
[2008-11-04|16:38] C:\DOCUME~1\RESPON~1\DATIAP~1\InstallShield
[2008-05-07|14:16] C:\DOCUME~1\RESPON~1\DATIAP~1\InterTrust
[2007-11-05|09:55] C:\DOCUME~1\RESPON~1\DATIAP~1\Joost
[2007-05-25|17:02] C:\DOCUME~1\RESPON~1\DATIAP~1\Lavasoft
[2007-11-19|08:37] C:\DOCUME~1\RESPON~1\DATIAP~1\Leadertech
[2007-12-18|12:14] C:\DOCUME~1\RESPON~1\DATIAP~1\Macromedia
[2009-01-12|14:56] C:\DOCUME~1\RESPON~1\DATIAP~1\Malwarebytes
[2009-03-11|11:55] C:\DOCUME~1\RESPON~1\DATIAP~1\Microsoft
[2008-02-19|10:14] C:\DOCUME~1\RESPON~1\DATIAP~1\Mozilla
[2009-02-05|18:00] C:\DOCUME~1\RESPON~1\DATIAP~1\Nokia
[2009-02-06|15:42] C:\DOCUME~1\RESPON~1\DATIAP~1\Nokia Multimedia Player
[2009-02-06|15:53] C:\DOCUME~1\RESPON~1\DATIAP~1\NSeries
[2007-05-17|16:10] C:\DOCUME~1\RESPON~1\DATIAP~1\Nvu
[2008-04-07|17:32] C:\DOCUME~1\RESPON~1\DATIAP~1\PC Suite
[2008-03-31|10:03] C:\DOCUME~1\RESPON~1\DATIAP~1\Ready
[2008-01-16|16:00] C:\DOCUME~1\RESPON~1\DATIAP~1\Real
[2009-01-27|17:27] C:\DOCUME~1\RESPON~1\DATIAP~1\Search Settings
[2007-11-05|08:11] C:\DOCUME~1\RESPON~1\DATIAP~1\stickies
[2007-05-31|10:33] C:\DOCUME~1\RESPON~1\DATIAP~1\Sun
[2008-01-16|10:06] C:\DOCUME~1\RESPON~1\DATIAP~1\TVU networks
[2009-01-27|11:11] C:\DOCUME~1\RESPON~1\DATIAP~1\Video DVD Maker FREE
[2007-08-06|14:29] C:\DOCUME~1\RESPON~1\DATIAP~1\vlc
[2008-07-14|17:17] C:\DOCUME~1\RESPON~1\DATIAP~1\WeatherWatcher
[0|File] C:\DOCUME~1\RESPON~1\DATIAP~1\byte
[44|Directory] C:\DOCUME~1\RESPON~1\DATIAP~1\byte disponibili

[2007-05-11|10:49] C:\DOCUME~1\utente\DATIAP~1\Identities
[2009-03-11|11:55] C:\DOCUME~1\utente\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\utente\DATIAP~1\byte
[4|Directory] C:\DOCUME~1\utente\DATIAP~1\byte disponibili

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[2009-03-04 18:38][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009-03-18 09:06][--a------] C:\WINDOWS\tasks\OGADaily.job
[2009-03-18 09:32][--a------] C:\WINDOWS\tasks\OGALogon.job
[2009-03-18 09:31][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2006-03-02 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Programmi

[2009-03-06|09:56] C:\Programmi\1618-Roulette
[2009-02-11|12:28] C:\Programmi\Adobe
[2008-02-26|15:27] C:\Programmi\Ahead
[2007-05-11|14:17] C:\Programmi\Alwil Software
[2007-05-11|16:42] C:\Programmi\AnswerWorks 4.0
[2008-11-07|09:52] C:\Programmi\Apple Software Update
[2009-03-11|12:31] C:\Programmi\Ashampoo
[2007-10-26|08:45] C:\Programmi\Astonsoft
[2007-11-19|08:38] C:\Programmi\Audio Edit
[2008-07-16|07:34] C:\Programmi\AutoCAD 2008
[2007-05-11|16:42] C:\Programmi\AutoCAD LT 2006
[2008-07-16|07:31] C:\Programmi\Autodesk
[2008-05-28|08:55] C:\Programmi\Autodesk Revit Building 8.1
[2009-03-17|17:37] C:\Programmi\Avira
[2008-10-20|07:30] C:\Programmi\B2BPOKER
[2008-11-03|15:49] C:\Programmi\Biglietti da Visita Pro 2.0 Demo
[2008-11-07|09:54] C:\Programmi\Bonjour
[2007-05-15|10:15] C:\Programmi\Business Objects
[2009-01-12|15:14] C:\Programmi\CCleaner
[2007-05-11|10:41] C:\Programmi\ComPlus Applications
[2008-12-10|15:06] C:\Programmi\Corel
[2007-05-21|16:35] C:\Programmi\DIFX
[2007-11-06|12:45] C:\Programmi\Drive Rescue
[2008-07-11|09:53] C:\Programmi\Easy CD-DA Extractor 11
[2008-01-21|08:41] C:\Programmi\eBay
[2009-02-24|16:17] C:\Programmi\eMule
[2008-08-01|10:51] C:\Programmi\Enigma Software Group
[2009-01-27|11:25] C:\Programmi\eRightSoft
[2009-03-16|16:55] C:\Programmi\File comuni
[2009-03-17|11:25] C:\Programmi\FindyKill
[2008-12-18|08:34] C:\Programmi\Foxit Software
[2008-11-04|16:29] C:\Programmi\Free Internet Window Washer
[2009-02-27|15:02] C:\Programmi\Free Video Converter
[2008-01-21|08:47] C:\Programmi\FreeRIP3
[2009-03-16|19:03] C:\Programmi\FreeUndelete
[2009-01-27|17:26] C:\Programmi\GiocoDigitale
[2007-06-11|14:53] C:\Programmi\Graphisoft1
[2008-11-04|16:28] C:\Programmi\Hewlett-Packard
[2008-11-04|16:33] C:\Programmi\HP
[2008-02-22|09:23] C:\Programmi\iColorFolder
[2008-07-02|11:29] C:\Programmi\IDoser v4
[2009-02-09|08:20] C:\Programmi\IncrediMail
[2008-09-04|07:17] C:\Programmi\inKline Global
[2007-12-13|10:43] C:\Programmi\Innovative Solutions
[2008-12-18|08:33] C:\Programmi\InstallShield Installation Information
[2007-05-11|11:02] C:\Programmi\Intel
[2007-05-11|11:01] C:\Programmi\Intel Audio Studio
[2009-02-13|09:09] C:\Programmi\Internet Explorer
[2009-03-13|15:43] C:\Programmi\Java
[2008-10-20|11:06] C:\Programmi\Join ME
[2009-01-27|11:07] C:\Programmi\Konvertor
[2007-05-25|17:02] C:\Programmi\Lavasoft
[2008-01-16|09:13] C:\Programmi\Mediacenter 1.0a
[2009-03-18|09:25] C:\Programmi\Messenger
[2009-02-02|11:41] C:\Programmi\Microsoft
[2007-05-11|10:44] C:\Programmi\microsoft frontpage
[2008-07-16|07:30] C:\Programmi\Microsoft Office
[2009-02-27|18:42] C:\Programmi\Microsoft Silverlight
[2007-05-11|16:25] C:\Programmi\Microsoft.NET
[2007-10-29|15:33] C:\Programmi\Millegiochi Rosso Alice
[2008-12-15|16:56] C:\Programmi\Mio Technology
[2008-10-13|10:13] C:\Programmi\Montini
[2009-03-18|09:25] C:\Programmi\Movie Maker
[2009-03-18|09:36] C:\Programmi\Mozilla Firefox
[2008-02-21|08:25] C:\Programmi\Mozilla Firefox 3 Beta 3
[2007-07-27|11:11] C:\Programmi\mp3DirectCut
[2007-05-11|12:48] C:\Programmi\MSBuild
[2007-05-11|10:40] C:\Programmi\MSN Gaming Zone
[2007-05-11|10:53] C:\Programmi\MSXML 4.0
[2007-05-11|13:52] C:\Programmi\MSXML 6.0
[2008-10-24|11:30] C:\Programmi\NASA
[2009-03-18|09:22] C:\Programmi\NetMeeting
[2009-02-06|15:46] C:\Programmi\Nokia
[2009-03-13|08:28] C:\Programmi\Nufsoft
[2008-10-21|09:15] C:\Programmi\OpenAL
[2009-03-18|09:22] C:\Programmi\Outlook Express
[2009-03-18|09:13] C:\Programmi\Panda Security
[2007-05-21|16:35] C:\Programmi\PC Connectivity Solution
[2008-07-15|09:43] C:\Programmi\PC Wizard 2008
[2009-02-26|09:54] C:\Programmi\PhotoFiltre
[2009-01-16|08:20] C:\Programmi\PokerStars.IT
[2008-11-07|09:53] C:\Programmi\QuickTime
[2008-01-16|18:13] C:\Programmi\RadioXpi
[2008-04-09|07:15] C:\Programmi\ReadyFree
[2008-01-16|15:59] C:\Programmi\Real
[2007-05-11|12:45] C:\Programmi\Reference Assemblies
[2008-12-12|12:17] C:\Programmi\Resource Kit
[2007-05-15|08:59] C:\Programmi\RMAdmin
[2007-06-08|15:24] C:\Programmi\RMClient
[2009-01-27|11:30] C:\Programmi\Search Settings
[2008-03-13|12:54] C:\Programmi\Serif
[2007-05-11|10:43] C:\Programmi\Servizi in linea
[2007-05-11|11:00] C:\Programmi\SigmaTel
[2007-11-05|12:13] C:\Programmi\Sophos
[2009-03-16|11:30] C:\Programmi\Spybot - Search & Destroy
[2007-05-15|14:06] C:\Programmi\STR
[2007-05-15|14:06] C:\Programmi\STRWIN32
[2009-02-02|17:41] C:\Programmi\SweetIM
[2009-01-27|11:18] C:\Programmi\Total Video Converter
[2008-04-01|15:32] C:\Programmi\Trend Micro
[2008-01-16|16:18] C:\Programmi\TVAntsX
[2008-07-16|07:32] C:\Programmi\Uninstall Information
[2007-08-06|14:28] C:\Programmi\VideoLAN
[2008-01-16|10:34] C:\Programmi\Vlc-vcr
[2008-07-14|17:19] C:\Programmi\Weather Watcher
[2007-06-11|14:54] C:\Programmi\WIBUKEY
[2007-06-11|08:54] C:\Programmi\WIBU-SYSTEMS
[2009-02-02|11:40] C:\Programmi\Windows Live
[2009-03-13|10:26] C:\Programmi\Windows Live Safety Center
[2009-02-02|11:40] C:\Programmi\Windows Live SkyDrive
[2007-05-11|12:44] C:\Programmi\Windows Media Connect 2
[2009-03-18|09:22] C:\Programmi\Windows Media Player
[2009-03-18|09:22] C:\Programmi\Windows NT
[2007-05-11|10:43] C:\Programmi\WindowsUpdate
[2007-05-11|16:56] C:\Programmi\WinRAR
[2009-01-27|10:58] C:\Programmi\Wondershare
[2007-05-11|10:44] C:\Programmi\xerox
[2008-02-05|09:05] C:\Programmi\Yahoo!
[2008-02-05|09:01] C:\Programmi\YouTube Downloader
[2007-11-06|18:23] C:\Programmi\Zeallsoft
[0|File] C:\Programmi\byte
[122|Directory] C:\Programmi\byte disponibili

--------------------\\ Listing Folders in C:\Programmi\File comuni

[2008-12-10|11:28] C:\Programmi\File comuni\Adobe
[2008-02-26|15:26] C:\Programmi\File comuni\Ahead
[2009-01-16|08:23] C:\Programmi\File comuni\Apple
[2008-07-16|07:34] C:\Programmi\File comuni\Autodesk Shared
[2007-05-15|10:15] C:\Programmi\File comuni\Business Objects
[2008-07-16|07:31] C:\Programmi\File comuni\DESIGNER
[2008-05-29|13:43] C:\Programmi\File comuni\GeoVid
[2008-05-07|14:15] C:\Programmi\File comuni\InstallShield
[2007-05-31|10:21] C:\Programmi\File comuni\Java
[2009-02-23|08:28] C:\Programmi\File comuni\Microsoft Shared
[2007-05-11|10:42] C:\Programmi\File comuni\MSSoap
[2009-02-06|15:46] C:\Programmi\File comuni\Nokia
[2007-05-11|12:33] C:\Programmi\File comuni\ODBC
[2007-10-29|15:32] C:\Programmi\File comuni\ParallelGraphics
[2009-02-05|17:54] C:\Programmi\File comuni\PCSuite
[2008-01-16|16:00] C:\Programmi\File comuni\Real
[2007-05-11|10:42] C:\Programmi\File comuni\Services
[2007-05-11|12:33] C:\Programmi\File comuni\SpeechEngines
[2007-05-15|14:08] C:\Programmi\File comuni\STR
[2009-03-18|09:22] C:\Programmi\File comuni\System
[2009-02-02|11:37] C:\Programmi\File comuni\Windows Live
[2008-03-11|17:45] C:\Programmi\File comuni\WindowsLiveInstaller
[2008-01-16|16:00] C:\Programmi\File comuni\xing shared
[0|File] C:\Programmi\File comuni\byte
[25|Directory] C:\Programmi\File comuni\byte disponibili

--------------------\\ Process

( 32 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-18 10:05:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 82

--------------------\\ Searching for other infections


No other infections found !

[F:20][D:6]-> c:\temp
[F:11][D:0]-> C:\DOCUME~1\RESPON~1\Cookies
[F:175][D:4]-> C:\DOCUME~1\RESPON~1\IMPOST~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 2009-03-18|10:05 - Option : [2]

--------------------\\ Scan completed at 10:05:46
unodeisenatori
Inviato: Wednesday, March 18, 2009 10:12:56 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
log hjt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:08, on 2009-03-18
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\IncrediMail\bin\IMApp.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file)
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Programmi\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [JobHisInit] C:\Programmi\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Programmi\Intel Audio Studio\IntelAudioStudio.exe" BOOT
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [IncrediMail] C:\Programmi\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ricerca - res://C:\Programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) -
O16 - DPF: {4C833081-D026-4FF8-968F-7EAB660D2FBA} (TVAnts ActiveX Control) -
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} -
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = umbriaservizi.locale
O17 - HKLM\Software\..\Telephony: DomainName = umbriaservizi.locale
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = umbriaservizi.locale
O20 - Winlogon Notify: nnnkijj - C:\WINDOWS\
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe

--
End of file - 8164 bytes
unodeisenatori
Inviato: Wednesday, March 18, 2009 10:30:20 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
shapiro
Inviato: Wednesday, March 18, 2009 10:41:53 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ahahah Drool Drool sei il piu' forte del forum, un personaggio davvero simpaticissimi....pensa mi metto ancora a ridere quando ti ho fatto usare combofix e ti ho detto di non toccare niente durante la scansione e tu hai risposto:'' MI SONO ALZATO PURE IN PIEDI''Drool

grazie unodeisenatori, sono felice davvero di averti risolto questo problema- purtroppo il bagle entra soprattutto con i programmi come emule, quindi attento a cosa scarichi

usa avira, fai due o tre scansioni settimanali e aggiornalo sempre, e' un ottimo antivirus


per finire, Avvia Hijackthis e clicca su "do a system scan only"
Metti la spunta a queste voci e clicca su "fix checked


R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgHelper.dll


O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)

O2 - BHO: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file)

O3 - Toolbar: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file)

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)

O20 - Winlogon Notify: nnnkijj - C:\WINDOWS\





scarica Ccleaner

http://www.filehippo.com/download_ccleaner/

1) per il download dell'ultima versione clicca a destra in alto sotto la freccia verde
2) installalo
3) clicca su "avvia pulizia", ripeti il procedimento 2 volte

poi

scarica Atfcleaner

http://www.atribune.org/ccount/click.php?id=1

Avvia ATFCleaner.exe con un doppio click

1) seleziona la casella Select All
2) clicca sul pulsante Empty selected
3) aspetta l'avviso Done Cleaning.
maopapof
Inviato: Wednesday, March 18, 2009 11:30:50 AM

Rank: AiutAmico

Iscritto dal : 10/31/2004
Posts: 7,179
scusate ...ma come avete scoperto che è bugle e non otorun2 ? ... senza polemica alcuna :O)

unodeisenatori
Inviato: Wednesday, March 18, 2009 11:33:51 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
GRAZIE A TE SHAPIRO...

cmq ho tolto avira perchè ricevo una marea di email e mi rimane piu' facile utilizzare un antivirus che me le controlli...ho rimesso avast

penso che avast mi avesse anche avvertito del virus ma io preso dal lavoro ( e da qualche partita a poker Drool ) l'ho sottovalutato!!!!

procedo con l'iter e ci riaggiorniamo
unodeisenatori
Inviato: Wednesday, March 18, 2009 11:34:50 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
scusate ...ma come avete scoperto che è bugle e non otorun2

per me poteva essere qualsiasi cosa...
unodeisenatori
Inviato: Wednesday, March 18, 2009 11:42:03 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
shap ho finito di fare i compiti....

posso andare in giardino ora??????
shapiro
Inviato: Wednesday, March 18, 2009 11:51:25 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ciao maopapof, guarda i report che cosa hanno trovato

@ unodeisenatori si si ora puoi andare anche in giardino

buon lavoro e se hai bisogno torna

ciao
unodeisenatori
Inviato: Wednesday, March 18, 2009 11:56:03 AM
Rank: AiutAmico

Iscritto dal : 3/13/2009
Posts: 47
Dancing Dancing Dancing Dancing

grande shap grazie mille di tutto...

veramente sei stato di una gentilezza unica!!!
shapiro
Inviato: Wednesday, March 18, 2009 11:58:52 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
non preoccuparti, controlla bene tutti i passaggi che ti ho suggerito e quando hai bisogno torna senza problemi

Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.