Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

HijackThis controllo log per apertura di pagine diverse da quelle cliccate Opzioni
integra
Inviato: Thursday, March 12, 2009 7:33:23 PM
Rank: Member

Iscritto dal : 3/12/2009
Posts: 23
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:12:12, on 12/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\File comuni\BitDefender\BitDefender Update Service\livesrv.exe
C:\Programmi\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\Spybot - Search & Destroy\SpybotSD.exe
C:\Programmi\SpywareBlaster\spywareblaster.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\SpywareBlaster\spywareblaster.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\CDBurnerXP\NMSAccessU.exe
C:\Programmi\BitDefender\BitDefender 2009\seccenter.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\BitDefender\BitDefender 2009\bdagent.exe
C:\Programmi\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.it
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Programmi\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BDAgent] "C:\Programmi\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Programmi\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Spybot - Search & Destroy.lnk = C:\Programmi\Spybot - Search & Destroy\SpybotSD.exe
O4 - Startup: SpywareBlaster.lnk = C:\Programmi\SpywareBlaster\spywareblaster.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: !saswinlogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: BitDefender Arrakis Server (arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Programmi\File comuni\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: Servizio trasferimento intelligente in background (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Google Update Service (gupdate1c99126c1e940e6) (gupdate1c99126c1e940e6) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (livesrv) - BitDefender SRL - C:\Programmi\File comuni\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NMSAccessU (nmsaccessu) - Unknown owner - C:\Programmi\CDBurnerXP\NMSAccessU.exe
O23 - Service: BitDefender Virus Shield (vsserv) - BitDefender S. R. L. - C:\Programmi\BitDefender\BitDefender 2009\vsserv.exe
O23 - Service: Aggiornamenti automatici (wuauserv) - Unknown owner - C:\WINDOWS\

--
End of file - 5017 bytes
Sponsor
Inviato: Thursday, March 12, 2009 7:33:23 PM

 
r16
Inviato: Thursday, March 12, 2009 7:51:29 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao
Il log non presenta anomalie.
Fai queste 2 scansioni seguendo bene le indicazioni:
Scarica ed installa MalwareBytes:
clicca qui per il download : http://www.aiutamici.com/software?id=80346
Prima di fare la scansione AGGIORNALO.
Esegui una scansione completa del sistema
Posta il log.
Poi:
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,e dopo aver scaricato COMBOFIX, chiudi la connessione.

Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Salvalo sul desktop.
Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
Digita 1 premi Invio e segui le indicazioni.
Al termine, verrà creato un file log chiamato C:\ComboFix.txt. Postalo qui.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.

integra
Inviato: Thursday, March 12, 2009 9:39:37 PM
Rank: Member

Iscritto dal : 3/12/2009
Posts: 23
Ok Provo a fare tutto come scritto .
integra
Inviato: Thursday, March 12, 2009 11:45:49 PM
Rank: Member

Iscritto dal : 3/12/2009
Posts: 23
Malwarebytes' Anti-Malware 1.34
Versione del database: 1841
Windows 5.1.2600 Service Pack 3

12/03/2009 22.32.38
mbam-log-2009-03-12 (22-32-38).txt

Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 111024
Tempo trascorso: 27 minute(s), 33 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)
integra
Inviato: Friday, March 13, 2009 12:46:24 AM
Rank: Member

Iscritto dal : 3/12/2009
Posts: 23
ComboFix 09-03-10.03 - utente 2009-03-12 23.58.43.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.511.295 [GMT 1:00]
Eseguito da: c:\documents and settings\utente\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning enabled* (Updated)
FW: BitDefender Firewall *enabled*
* Creato nuovo punto di ripristino
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\mpg4c32.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Creati Da 2009-02-12 al 2009-03-12 )))))))))))))))))))))))))))))))))))
.

2009-03-12 07:31 . 2009-03-12 07:31 850 --a------ c:\windows\system32\ProductTweaks.xml
2009-03-12 07:31 . 2009-03-12 07:31 385 --a------ c:\windows\system32\user_gensett.xml
2009-03-11 23:54 . 2009-03-11 23:54 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\BitDefender
2009-03-11 22:41 . 2009-03-11 22:41 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\SUPERAntiSpyware.com
2009-03-11 22:37 . 2009-03-12 23:52 121 --a------ c:\windows\bdagent.INI
2009-03-11 21:48 . 2009-03-12 23:58 81,984 --a------ c:\windows\system32\bdod.bin
2009-03-11 21:35 . 2009-03-11 21:35 <DIR> d-------- c:\windows\system32\logs
2009-03-11 21:35 . 2009-03-11 21:35 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\BitDefender
2009-03-11 21:34 . 2009-03-11 21:35 <DIR> d-------- c:\programmi\BitDefender
2009-03-11 21:34 . 2009-03-11 21:38 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\BitDefender
2009-03-11 21:29 . 2009-03-11 21:35 <DIR> d-------- c:\programmi\File comuni\BitDefender
2009-03-11 21:16 . 2009-03-11 21:16 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-03-11 21:16 . 2009-03-11 21:16 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\Malwarebytes
2009-03-11 21:16 . 2009-03-11 21:16 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-03-11 21:16 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-11 21:16 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-11 21:10 . 2009-03-11 21:10 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2009-03-11 21:10 . 2009-03-11 21:10 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\SUPERAntiSpyware.com
2009-03-11 21:10 . 2009-03-11 21:10 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2009-03-11 21:09 . 2009-03-11 21:09 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2009-03-10 13:46 . 2009-03-10 13:46 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\DivX
2009-03-10 13:45 . 2009-03-10 13:45 <DIR> d---s---- c:\documents and settings\utente\UserData
2009-03-10 13:42 . 2009-03-10 13:42 <DIR> d-------- c:\programmi\Pinnacle
2009-03-10 13:42 . 2009-03-10 13:42 <DIR> d-------- c:\programmi\File comuni\Yahoo!
2009-03-10 13:42 . 2009-03-10 13:46 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Pinnacle VideoSpin
2009-03-10 13:41 . 2009-03-10 13:41 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Pinnacle
2009-03-09 19:55 . 2009-03-10 00:52 <DIR> d-------- C:\Lop SD
2009-03-09 18:45 . 2009-03-09 18:50 <DIR> d-------- c:\programmi\CDBurnerXP
2009-03-09 18:45 . 2009-03-09 18:45 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\Canneverbe_Limited
2009-03-08 02:07 . 2009-03-08 02:07 <DIR> d-------- c:\windows\Options
2009-03-06 21:38 . 2009-03-06 21:38 <DIR> d-------- c:\programmi\AVSMedia
2009-03-06 13:47 . 2009-03-12 23:48 <DIR> d-a------ c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-03-05 19:27 . 2009-02-01 07:06 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di stampa
2009-03-05 19:27 . 2009-02-01 07:06 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di rete
2009-03-05 19:27 . 2009-03-12 18:38 <DIR> d-------- c:\documents and settings\Administrator\Preferiti
2009-03-05 19:27 . 2009-02-01 06:16 <DIR> d--h----- c:\documents and settings\Administrator\Modelli
2009-03-05 19:27 . 2009-02-01 07:06 <DIR> dr------- c:\documents and settings\Administrator\Menu Avvio
2009-03-05 19:27 . 2009-03-13 00:00 <DIR> d--h----- c:\documents and settings\Administrator\Impostazioni locali
2009-03-05 19:27 . 2009-02-01 07:06 <DIR> d-------- c:\documents and settings\Administrator\Documenti
2009-03-05 19:27 . 2009-03-11 23:54 <DIR> dr-h----- c:\documents and settings\Administrator\Dati applicazioni
2009-03-05 19:27 . 2009-03-05 19:28 <DIR> d-------- c:\documents and settings\Administrator
2009-03-05 19:25 . 2009-03-05 22:35 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-03-05 19:23 . 2009-03-05 22:35 <DIR> d-------- c:\programmi\Lavasoft
2009-03-05 19:23 . 2009-03-05 22:35 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2009-03-05 19:23 . 2009-03-05 22:35 <DIR> d--h-c--- c:\documents and settings\All Users\Dati applicazioni\~0
2009-03-05 13:48 . 2009-03-12 21:23 <DIR> d-------- c:\programmi\SpywareBlaster
2009-03-05 13:48 . 2005-08-25 18:19 115,920 --a------ c:\windows\system32\MSINET.OCX
2009-03-05 13:46 . 2009-03-06 07:38 372 --a------ c:\windows\wininit.ini
2009-03-05 07:46 . 2009-03-05 22:27 <DIR> d-------- c:\programmi\Spybot - Search & Destroy
2009-03-05 07:46 . 2009-03-08 02:17 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-03-05 01:22 . 2009-03-05 01:22 2 --a------ C:\-1670713505
2009-03-05 01:22 . 2009-03-05 01:22 0 --a------ C:\hglf.exe
2009-03-05 01:21 . 2009-03-05 01:22 68,608 --a------ C:\hblyl.exe
2009-03-05 00:28 . 2009-03-05 00:28 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\AVS4YOU
2009-03-05 00:28 . 2009-03-05 00:28 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\AVS4YOU
2009-03-03 07:43 . 2009-03-04 13:57 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\dvdcss
2009-02-28 15:51 . 2009-02-28 15:51 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\vlc
2009-02-27 13:37 . 2009-02-27 13:37 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\Ahead
2009-02-26 07:44 . 2009-03-08 02:10 <DIR> d-------- c:\programmi\Easy Schedule Maker
2009-02-23 22:02 . 2009-02-23 22:04 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\AVS Video Converter
2009-02-23 21:45 . 2009-02-23 21:45 <DIR> d-------- c:\programmi\GSpot
2009-02-23 21:18 . 2009-03-06 21:42 <DIR> d-------- c:\programmi\File comuni\AVSMedia
2009-02-23 21:18 . 2003-05-21 23:50 1,700,352 --a------ c:\windows\system32\GdiPlus.dll
2009-02-23 21:18 . 2003-05-22 12:26 638,976 --a------ c:\windows\system32\divx.dll
2009-02-23 21:18 . 2004-07-03 20:59 524,288 --a------ c:\windows\system32\xvidcore.dll
2009-02-23 21:18 . 2003-05-21 23:50 261,632 --a------ c:\windows\system32\mcdvd_32.dll
2009-02-23 21:18 . 2003-05-22 12:26 221,215 --a------ c:\windows\system32\divxdec.ax
2009-02-23 21:18 . 2003-05-21 23:50 156,910 --a------ c:\windows\WMSysPr8.prx
2009-02-23 21:18 . 2004-07-03 21:08 139,264 --a------ c:\windows\system32\xvidvfw.dll
2009-02-23 21:18 . 2003-05-21 23:50 82,944 --a------ c:\windows\system32\vct3216.acm
2009-02-23 21:18 . 2004-02-04 21:11 81,920 --a------ c:\windows\system32\AC3ACM.acm
2009-02-23 21:18 . 2004-09-06 16:06 53,248 --a------ c:\windows\system32\xvid.ax
2009-02-23 21:18 . 2003-05-21 23:50 38,912 --a------ c:\windows\system32\alf2cd.acm
2009-02-23 21:18 . 2000-03-14 20:55 13,239 --a------ c:\windows\system32\Scg726.acm
2009-02-23 13:33 . 2008-04-14 03:14 152,576 --a------ c:\windows\system32\irftp.exe
2009-02-23 13:33 . 2008-04-14 03:14 152,576 --a--c--- c:\windows\system32\dllcache\irftp.exe
2009-02-23 13:33 . 2008-04-14 03:13 29,696 --a------ c:\windows\system32\irmon.dll
2009-02-23 13:33 . 2008-04-14 03:13 29,696 --a--c--- c:\windows\system32\dllcache\irmon.dll
2009-02-23 13:33 . 2008-04-14 03:13 8,192 --a------ c:\windows\system32\wshirda.dll
2009-02-23 13:33 . 2008-04-14 03:13 8,192 --a--c--- c:\windows\system32\dllcache\wshirda.dll
2009-02-21 16:31 . 2009-03-06 13:20 <DIR> d-------- c:\programmi\DNA
2009-02-21 16:31 . 2009-02-21 16:34 <DIR> d-------- c:\programmi\BitTorrent
2009-02-21 16:31 . 2009-03-06 13:24 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\DNA
2009-02-21 16:31 . 2009-03-08 02:13 <DIR> d-------- c:\documents and settings\utente\Dati applicazioni\BitTorrent
2009-02-20 19:23 . 2009-02-20 19:23 <DIR> d-------- c:\windows\Downloaded Installations
2009-02-20 19:22 . 2009-02-20 19:22 <DIR> d-------- C:\Temp
2009-02-19 22:41 . 2009-02-19 22:41 <DIR> d-------- c:\windows\Sun
2009-02-18 21:12 . 2009-02-18 21:12 <DIR> d-------- c:\programmi\Java
2009-02-18 21:12 . 2009-02-18 21:12 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-18 21:12 . 2009-02-18 21:12 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-18 13:15 . 2009-03-12 13:45 202 --a------ c:\windows\NeroDigital.ini
2009-02-17 23:40 . 2008-04-13 19:45 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2009-02-17 23:40 . 2008-04-13 19:45 32,128 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2009-02-17 23:40 . 2008-04-14 03:13 21,504 --a------ c:\windows\system32\hidserv.dll
2009-02-17 23:40 . 2008-04-14 03:13 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll
2009-02-17 23:40 . 2008-04-14 02:53 14,720 --a------ c:\windows\system32\drivers\kbdhid.sys
2009-02-17 23:40 . 2008-04-14 02:53 14,720 --a--c--- c:\windows\system32\dllcache\kbdhid.sys
2009-02-17 23:40 . 2001-08-30 20:41 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-02-17 23:40 . 2001-08-30 20:41 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-02-17 23:40 . 2008-04-13 19:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-02-17 23:40 . 2008-04-13 19:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-02-17 21:15 . 2009-02-17 21:15 <DIR> d-------- C:\Archivos de programa
2009-02-17 21:14 . 2009-03-05 00:09 <DIR> d-------- c:\programmi\eMule
2009-02-17 20:43 . 2009-02-17 20:43 <DIR> d-------- c:\windows\system32\it-it
2009-02-17 20:43 . 2009-02-17 20:43 <DIR> d-------- c:\windows\system32\it
2009-02-17 20:43 . 2009-02-17 20:43 <DIR> d-------- c:\windows\system32\bits
2009-02-17 20:43 . 2009-02-17 20:43 <DIR> d-------- c:\windows\l2schemas
2009-02-17 20:40 . 2009-02-17 20:40 <DIR> d-------- c:\windows\ServicePackFiles
2009-02-17 19:24 . 2009-02-17 19:24 <DIR> d-------- c:\programmi\MSXML 4.0
2009-02-17 19:21 . 2009-02-17 19:21 <DIR> d-------- c:\programmi\EPSON
2009-02-17 19:21 . 2002-10-08 03:34 73,676 --a------ c:\windows\system32\EBPMON2.DLL
2009-02-17 19:21 . 2002-07-31 03:25 61,440 --a------ c:\windows\system32\ECBTEG.DLL
2009-02-17 19:21 . 2000-06-07 02:01 34,304 --a------ c:\windows\system32\EBPCHP.DLL
2009-02-17 19:21 . 2008-04-13 19:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-02-17 19:21 . 2001-09-04 03:04 182 --a------ c:\windows\system32\EBPPORT.DAT
2009-02-17 19:13 . 2009-02-17 19:14 <DIR> d-------- c:\programmi\File comuni\Adobe
2009-02-17 19:08 . 2004-08-19 15:23 327,168 --------- c:\windows\system32\drivers\ati2mtaa.sys
2009-02-17 18:57 . 2008-12-12 18:01 3,088,896 -----c--- c:\windows\system32\dllcache\mshtml.dll
2009-02-17 18:57 . 2008-08-14 14:22 2,192,896 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-17 18:57 . 2008-08-14 14:22 2,148,864 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-17 18:57 . 2008-08-14 14:22 2,069,760 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-17 18:57 . 2008-08-14 14:22 2,027,520 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-17 18:57 . 2008-09-15 16:24 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2009-02-17 18:57 . 2008-10-16 02:00 1,499,648 -----c--- c:\windows\system32\dllcache\shdocvw.dll
2009-02-17 18:57 . 2008-10-16 02:00 668,672 -----c--- c:\windows\system32\dllcache\wininet.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-12 20:26 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-03-11 20:38 --------- d-----w c:\programmi\ESET
2009-02-26 22:16 --------- d-----w c:\programmi\File comuni\Ahead
2009-02-26 06:31 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Babylon
2009-02-26 06:30 --------- d-----w c:\documents and settings\utente\Dati applicazioni\Babylon
2009-02-17 20:09 --------- d-----w c:\programmi\CCleaner
2009-02-17 17:39 --------- d-----w c:\programmi\Google
2009-02-05 23:35 38,160 ----a-w c:\windows\system32\MLPagAx.dll
2009-02-05 23:35 189,712 ----a-w c:\windows\system32\RALMain.dll
2009-02-05 23:33 54,544 ----a-w c:\windows\system32\PCLEGetGuid.dll
2009-02-03 16:03 104,328 ----a-w c:\windows\system32\drivers\bdfndisf.sys
2009-02-02 11:20 --------- d-----w c:\programmi\Ahead
2009-02-01 08:31 --------- d-----w c:\programmi\Babylon
2009-02-01 05:57 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Ahead
2009-02-01 05:50 --------- d-----w c:\programmi\VideoLAN
2009-02-01 05:49 --------- d-----w c:\programmi\ScanSoft
2009-02-01 05:48 --------- d-----w c:\programmi\File comuni\InstallShield
2009-02-01 05:45 --------- d-----w c:\programmi\Microsoft AutoRoute
2009-02-01 05:40 --------- d-----w c:\programmi\DAEMON Tools Toolbar
2009-02-01 05:40 --------- d-----w c:\programmi\DAEMON Tools Lite
2009-02-01 05:39 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-02-01 05:39 --------- d-----w c:\documents and settings\utente\Dati applicazioni\DAEMON Tools
2009-02-01 05:38 --------- d-----w c:\programmi\IZArc
2009-02-01 05:36 --------- d-----w c:\programmi\Microsoft.NET
2009-02-01 05:35 --------- d-----w c:\programmi\Microsoft Works
2009-02-01 05:19 --------- d-----w c:\programmi\microsoft frontpage
2009-02-01 05:18 --------- d-----w c:\programmi\Servizi in linea
2008-12-16 16:52 61,440 ----a-w c:\programmi\mozilla firefox\components\FFComm.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon]
2008-12-22 11:05 356352 c:\programmi\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.mjpg"= pvmjpg30.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^ USRobotics Wireless USB Adapter.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^Spybot - Search & Destroy.lnk]
path=c:\documents and settings\utente\Menu Avvio\Programmi\Esecuzione automatica\Spybot - Search & Destroy.lnk
backup=c:\windows\pss\Spybot - Search & Destroy.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^SpywareBlaster.lnk]
path=c:\documents and settings\utente\Menu Avvio\Programmi\Esecuzione automatica\SpywareBlaster.lnk
backup=c:\windows\pss\SpywareBlaster.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobe reader speed launcher]
--a------ 2008-06-12 02:38 34672 c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
--a------ 2006-05-24 17:39 2655272 c:\programmi\Babylon\Babylon-Pro\Babylon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]
--a------ 2009-01-09 12:51 741376 c:\programmi\BitDefender\BitDefender 2009\bdagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDefender Antiphishing Helper]
--a------ 2008-10-17 17:02 69632 c:\programmi\BitDefender\BitDefender 2009\IEShow.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bittorrent dna]
--a------ 2009-02-21 16:31 321344 c:\programmi\DNA\btdna.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-07-24 16:02 490952 c:\programmi\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sunjavaupdatesched]
--a------ 2009-02-18 21:12 148888 c:\programmi\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2009-02-17 11:43 1830128 c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\alcxmonitor]
--a------ 2004-09-07 13:47 57344 c:\windows\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bluetoothauthenticationagent]
--a------ 2008-04-14 03:14 110592 c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\eMule\\eMule.exe"=
"c:\\Programmi\\DNA\\btdna.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
"c:\\Programmi\\Spybot - Search & Destroy\\SpybotSD.exe"=
"c:\\Programmi\\Pinnacle\\VideoSpin\\Programs\\RM.exe"=
"c:\\Programmi\\Pinnacle\\VideoSpin\\Programs\\umi.exe"=
"c:\\Programmi\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe"=

R1 sasdifsv;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
R1 saskutil;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 bdvedisk;BDVEDISK;c:\programmi\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-10-06 82696]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
R3 bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2009-02-03 104328]
S2 gupdate1c99126c1e940e6;Google Update Service (gupdate1c99126c1e940e6);c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-17 133104]
S3 arrakis3;BitDefender Arrakis Server;c:\programmi\File comuni\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
S3 sasenum;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
S3 USRWGU(USR);USRobotics Wireless USB Adapter(USR);c:\windows\system32\DRIVERS\USRWGU.sys --> c:\windows\system32\DRIVERS\USRWGU.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c9503482-fc58-11dd-9361-00112fa3d8cc}]
\Shell\AutoRun\command - G:\EmDesk.exe
\Shell\EmDesk\command - G:\EmDesk.exe
.
Contenuto della cartella 'Scheduled Tasks'

2009-03-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []

2009-03-12 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-17 18:39]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

MSConfigStartUp-agrsmmsg - AGRSMMSG.exe


.
------- Scansione supplementare -------
.
uStart Page = hxxp://google.it
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\utente\Dati applicazioni\Mozilla\Firefox\Profiles\6hvaeamj.default\
FF - prefs.js: browser.startup.homepage - www.google.it
FF - component: c:\programmi\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\programmi\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npbittorrent.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-13 00:01:01
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629d4b-2ad3-4e50-b716-a66c15c63153}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,89,08,81,d9,5e,
96,e1,c7,e2,63,26,f1,3f,c8,ff,68,f4,93,52,e5,71,65,65,9d,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604bb98a-a94f-4a5c-a67c-d8d3582c741c}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:46,47,15,b0,92,4b,c7,ef,c7,34,f0,77,ae,
e4,16,ff,6a,9c,d6,61,af,45,84,18,57,d1,f6,f4,e0,d8,98,fa,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373fb-9cd8-4e47-b990-5a4466c16034}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,89,7c,88,e4,9f,
7c,8f,78,ff,7c,85,e0,43,d4,0e,fe,84,7c,10,bd,39,c5,13,1f,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554ccd-f60f-4708-ad98-d0152d08c8b9}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,1f,7a,a2,bd,d8,
bf,d9,64,86,8c,21,01,be,91,eb,e7,38,c7,5d,da,aa,40,8b,d5,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7eb537f9-a916-4339-b91b-ded8e83632c0}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,e8,3d,33,60,e6,
81,65,eb,f5,1d,4d,73,a8,13,5c,05,64,9d,2c,66,24,f5,de,d5,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395e8-7a56-4fb1-843b-3e52d94db145}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,ba,f8,66,b3,45,
9d,8e,cd,df,20,58,62,78,6b,cf,c8,b3,5f,cf,d6,57,ab,2b,15,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ac3ed30b-6f1a-4bfc-a4f6-2ebdccd34c19}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,0b,91,78,2b,fc,
7b,f6,8e,fb,a7,78,e6,12,2f,9a,ea,7e,d6,f9,34,04,32,33,b8,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{de5654ca-eb84-4df9-915b-37e957082d6d}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,3d,a1,7e,f9,72,
07,4c,40,01,3a,48,fc,e8,04,4a,f1,ae,09,f0,55,09,ce,5f,6d,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e39c35e8-7488-4926-92b2-2f94619ac1a5}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,58,d2,89,c8,1d,
73,bc,09,f6,0f,4e,58,98,5b,89,c9,cf,e3,67,b2,2a,cf,5b,07,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{eacafce5-b0e2-4288-8073-c02ff9619b6f}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,90,b5,1f,4d,c4,
1e,24,ac,3d,ce,ea,26,2d,45,aa,78,82,70,c8,c9,ac,57,f0,e2,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f8f02add-7366-4186-9488-c21cb8b3dcec}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,40,ef,b2,27,e7,
bd,5e,82,2a,b7,cc,b5,b9,7f,41,e7,be,f6,e0,99,59,34,8b,ff,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{fee45de2-a467-4bf9-bf2d-1411304bcd84}\inprocserver32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:05,73,21,dd,54,d8,4a,c5,c2,70,57,ac,16,
82,c6,49,6c,43,2d,1e,aa,22,2f,9c,2b,2e,03,b6,bb,03,8c,14,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Objects\Effects\Alchemy]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\ShimInclusionList\FIREFOX.EXE]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\UIPlugins\{292AE934-4F49-40bb-9E7E-6F6398ED9C31}]
@DACL=(02 0000)
"FriendlyName"="Nero Fast CD-Burning Plug-in"
"Description"="Scrivere CD"
"Capabilities"=dword:40000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows Media Player\SP0\KB952069_WM9\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB938464\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB946648\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB950760\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB950762\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB950974\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB951066\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB951376-v2\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB951698\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB951748\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB951978\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB952287\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB952954\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB954211\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB954459\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB954600\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB955069\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB955839\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB956802\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB956803\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB956841\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB957097\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB958215\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB958644\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB958687\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB960714\Filelist]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP4\KB960715\Filelist]
@DACL=(02 0000)
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(808)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
.
Ora fine scansione: 2009-03-13 0.02.56
ComboFix-quarantined-files.txt 2009-03-12 23:02:53
ComboFix2.txt 2009-03-06 12:33:25
ComboFix3.txt 2009-03-06 12:21:51

Pre-Run: 44.337.729.536 byte disponibili
Post-Run: 44,326,379,520 byte disponibili

423 --- E O F --- 2009-02-25 02:00:28
r16
Inviato: Friday, March 13, 2009 12:18:04 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Esegui queste operazioni di pulizia:
Disattiva il ripristino configurazione di sistema: http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
Poi:
Start\Esegui\copia e incolla la stringa %temp% clicca su Ok, svuota la cartella temp. (non eliminare la cartella)
Poi:
Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO
Poi:
Lancia Hijackthis e pulisci gli ADS in questo modo:
clicca sulla voce Open the misc tool section
clicca su Open ads spy
togli la spunta alla voce Quick scan (windows base folder only)
clicca su Scan
se venissero rilevati ADS, spunta tutte le caselline e clicca su Remove selected
Riavvia il pc.
Riattiva il ripristino configurazione di sistema e, se tutto è a posto, creane uno nuovo.
Riferisci se il problema è risolto, oppure no.
integra
Inviato: Saturday, March 14, 2009 9:38:27 PM
Rank: Member

Iscritto dal : 3/12/2009
Posts: 23
Ciao, sembrava tutto apposto ma dopo una giornata mi ha rifatto il problema d'oh!. Con esattezza "clicco su una rierca di google e mi apre una pagina diversa ( porno )di un determinato sito che non ricordo, torno indietro riclicco e mi da' pagina non disponibile, ritorno indietro e riclicco sullo stesso link e finalmente apre la pagina cercata. Questo tipo di problema si presenta in maniera discontinua. Sto pensando di formattare, dato che ho il disco ripartito elimino solo xp e installazioniThink
r16
Inviato: Saturday, March 14, 2009 11:32:56 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Prova a rifare le scansione con Combofix, e Malwarebytes.
E' possibile che il pc dopo una giornata,(la sfortuna ci vede benissimo) si sia infettato ancora. (posta i relativi log)
Cambia l'antivirus, non mi sembra un granchè BitDefender.
Prova questo:
http://www.aiutamici.com/software?ID=11537
Prima di formattare elimina questi file in rosso:
C:\-1670713505
C:\hglf.exe
C:\hblyl.exe
Se non li vedi subito, "Visualizza i file e le cartelle nascoste".
integra
Inviato: Sunday, April 26, 2009 6:06:12 PM
Rank: Member

Iscritto dal : 3/12/2009
Posts: 23
Ciao , scusami se non mi sono fatto sentire, non ho "navigato" molto in questo periodo e quel poco ero di fretta......Cmq bando alle scuse il Pc è ok e effettivamente ho trovato alcuni dei file in rosso che mi hai elencato. GRAZIE MILLE SALUTONI
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.