Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Aiuto da r16 Opzioni
acquaborra
Inviato: Monday, June 01, 2009 9:00:24 AM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
Ciao,
eccomi di nuovo a chiederti il tuo aiuto, sempre se puoi naturalmente.
Come forse ricorderai qualche tempo fa il mio PC, per un maledetto virus mi si era incasinato talmente che tutti gli interventi che mi avevi suggerito di fare
non hanno avuto esito positivo ed alla fine mi avevi giustamente consigliato di fare un bel formattone e reistallare tutto.
Ho seguito il tuo consiglio ed ho reinstallato tutto ed ho caricato SP3, AVG 8.5 e ho anche installato Zone Allarm come da tuo suggerimento.
Tutto OK.
Il problema che ho adesso con il PC è che è diventato di un lento che piu lento non si può. All'avvio rimane svariati minuti sul "caricamento delle impostazioni personali in corso".
Quando lancio Firefox o IE ci vogliono alcuni minuti prima che compaia la schermata iniziale.
Ho fatto varie scanzioni ma risulta tutto regolare.
Noto anche un rallentamento delle prestazioni quando riproduco qualche video dalla rete.
Non so cosa fare.
Comunque ti posto il log di Hijackthis sperando in un tuo aiuto. Grazie
Ecco il log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8.59.40, on 01/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\PDesk\PDesk.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\mgabg.exe
C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Microsoft LifeCam\MSCamS32.exe
C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Programmi\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Programmi\AVG\AVG8\avgcsrvx.exe
C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
O8 - Extra context menu item: Aggiungi a PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapserver3.ldpassociati.it/include/activex/MGViewer/6.0.4.2/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1240123413609
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC0324A8-26D1-467F-BB05-32528C84956F}: NameServer = 151.99.125.1,151.99.250.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Servizio di Google Update (gupdate1c9c0bd9625e4ac) (gupdate1c9c0bd9625e4ac) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\antonio\IMPOST~1\Temp\hpdj.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINDOWS\system32\mgabg.exe
O23 - Service: MySQL - Unknown owner - C:\Programmi\MySQL\MySQL.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8274 bytes
Sponsor
Inviato: Monday, June 01, 2009 9:00:24 AM

 
bazzurlone
Inviato: Monday, June 01, 2009 9:52:53 AM

Rank: AiutAmico

Iscritto dal : 1/20/2005
Posts: 1,537
Per il log,è meglio che ci guardi r16 (mi sembra pulito pero'....non mi pronuncio) per il problema della lentezza puoi fare alcune cosine:dai una bella ripulita con ccleaner ,durante la reinstallazione si possono essere creati file temporanei, esegui uno scandisk,esegui un defrag con smart defrag .
Sia ccleaner che smart defrag li trovi in software nel sito.
raresquare
Inviato: Monday, June 01, 2009 11:05:31 AM

Rank: AiutAmico

Iscritto dal : 5/15/2001
Posts: 320
Aggiungerei ai consigli di bazzurlone di controllare in CCleaner\Strumenti\Avvio, quante voci hai nell'avvio del PC, lasciando tutte quelle relative a Windows ed ai programmi di sicurezza (antivirus, firewall ...) e TOGLIENDO tutte quelle relative a programmi normali.
acquaborra
Inviato: Monday, June 01, 2009 11:10:37 AM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
grazie ad entrambi, ma quello che suggerite l'ho gia fatto senza aver trovato beneficio.
r16
Inviato: Monday, June 01, 2009 5:40:43 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao acquaborra .
Hai provato con una scansione con Malwarebytes?
Scarica ed installa MalwareBytes:
clicca qui per il download : http://www.aiutamici.com/software?id=80346
Prima di fare la scansione AGGIORNALO. (è molto importante)
Esegui una scansione completa del sistema.
Posta il log.
*********************************************************************************
Oppure vediamo come ce la racconta Combofix:
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Salvalo sul desktop.
Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.

Disinstalla combofix in questo modo: (dopo che avrò visto il log)
Start
Esegui
nella finestra di dialogo, copia ed incolla questo comando: Combofix /u e premi Invio poi cancella le cartelle in "C" di Combofix (qoobox)
acquaborra
Inviato: Monday, June 01, 2009 8:04:28 PM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
ecco il log di combofix
ComboFix 09-05-31.06 - antonio 01/06/2009 19.53.49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.510.257 [GMT 2:00]
Eseguito da: c:\documents and settings\antonio\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((( Files Creati Da 2009-05-01 al 2009-06-01 )))))))))))))))))))))))))))))))))))
.

2009-06-01 07:24 . 2002-10-29 06:20 40960 ----a-r- c:\windows\system32\drivers\fetnd5b.sys
2009-05-31 10:22 . 2008-04-14 02:13 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2009-05-31 10:22 . 2001-08-30 21:08 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-05-31 10:22 . 2008-04-14 02:13 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2009-05-31 10:22 . 2001-08-30 21:08 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2009-05-31 10:22 . 2001-08-30 21:08 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2009-05-31 10:22 . 2001-08-30 21:08 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2009-05-31 10:22 . 2001-08-17 18:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2009-05-31 10:22 . 2004-08-03 20:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys
2009-05-31 10:22 . 2004-08-03 20:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys
2009-05-31 10:22 . 2008-04-14 02:13 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2009-05-31 10:21 . 2008-04-13 18:36 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys
2009-05-31 10:21 . 2004-08-03 20:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys
2009-05-31 10:21 . 2001-08-30 18:46 35402 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys
2009-05-31 10:21 . 2001-08-17 19:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys
2009-05-31 10:21 . 2001-08-30 21:08 54272 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll
2009-05-31 10:21 . 2001-08-30 21:08 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2009-05-31 10:21 . 2001-08-17 19:28 701386 -c--a-w- c:\windows\system32\dllcache\wdhaalba.sys
2009-05-31 10:19 . 2001-08-17 18:14 249402 -c--a-w- c:\windows\system32\dllcache\vinwm.sys
2009-05-31 10:19 . 2001-08-17 19:49 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys
2009-05-31 10:19 . 2001-08-17 19:28 687999 -c--a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2009-05-31 10:19 . 2001-08-17 19:28 765884 -c--a-w- c:\windows\system32\dllcache\usrti.sys
2009-05-31 10:19 . 2001-08-17 19:28 113762 -c--a-w- c:\windows\system32\dllcache\usrpda.sys
2009-05-31 10:19 . 2001-08-17 19:28 7556 -c--a-w- c:\windows\system32\dllcache\usroslba.sys
2009-05-31 10:19 . 2001-08-17 19:28 224802 -c--a-w- c:\windows\system32\dllcache\usr1807a.sys
2009-05-31 10:19 . 2001-08-17 19:28 794399 -c--a-w- c:\windows\system32\dllcache\usr1806v.sys
2009-05-31 10:19 . 2001-08-17 19:28 793598 -c--a-w- c:\windows\system32\dllcache\usr1806.sys
2009-05-31 10:19 . 2001-08-17 19:28 794654 -c--a-w- c:\windows\system32\dllcache\usr1801.sys
2009-05-31 10:19 . 2008-04-13 18:45 26112 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2009-05-31 10:19 . 2008-04-13 18:45 17152 -c--a-w- c:\windows\system32\dllcache\usbohci.sys
2009-05-31 10:19 . 2004-08-19 13:28 32384 -c--a-w- c:\windows\system32\dllcache\usb101et.sys
2009-05-31 10:18 . 2001-08-30 21:08 94720 -c--a-w- c:\windows\system32\dllcache\umaxud32.dll
2009-05-31 10:18 . 2001-08-30 21:08 28672 -c--a-w- c:\windows\system32\dllcache\umaxu40.dll
2009-05-31 10:18 . 2001-08-30 21:08 27136 -c--a-w- c:\windows\system32\dllcache\umaxu22.dll
2009-05-31 10:18 . 2001-08-30 21:08 69632 -c--a-w- c:\windows\system32\dllcache\umaxu12.dll
2009-05-31 10:18 . 2001-08-30 21:08 50688 -c--a-w- c:\windows\system32\dllcache\umaxscan.dll
2009-05-31 10:18 . 2001-08-17 19:58 22912 -c--a-w- c:\windows\system32\dllcache\umaxpcls.sys
2009-05-31 10:18 . 2001-08-30 21:08 50176 -c--a-w- c:\windows\system32\dllcache\umaxp60.dll
2009-05-31 10:18 . 2001-08-30 21:08 47616 -c--a-w- c:\windows\system32\dllcache\umaxcam.dll
2009-05-31 10:18 . 2001-08-30 21:08 212480 -c--a-w- c:\windows\system32\dllcache\um54scan.dll
2009-05-31 10:18 . 2001-08-30 21:08 216576 -c--a-w- c:\windows\system32\dllcache\um34scan.dll
2009-05-31 10:18 . 2001-08-17 19:52 36736 -c--a-w- c:\windows\system32\dllcache\ultra.sys
2009-05-31 10:18 . 2001-08-17 19:48 11520 -c--a-w- c:\windows\system32\dllcache\twotrack.sys
2009-05-31 10:16 . 2001-08-17 18:10 28232 -c--a-w- c:\windows\system32\dllcache\tos4mo.sys
2009-05-31 10:16 . 2001-08-17 18:14 123995 -c--a-w- c:\windows\system32\dllcache\tjisdn.sys
2009-05-31 10:16 . 2001-08-17 18:51 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2009-05-31 10:16 . 2001-08-30 21:07 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll
2009-05-31 10:16 . 2008-04-13 18:40 149376 -c--a-w- c:\windows\system32\dllcache\tffsport.sys
2009-05-31 10:16 . 2001-08-17 18:13 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys
2009-05-31 10:16 . 2001-08-17 18:13 37961 -c--a-w- c:\windows\system32\dllcache\tdk100b.sys
2009-05-31 10:16 . 2001-08-17 19:49 30464 -c--a-w- c:\windows\system32\dllcache\tbatm155.sys
2009-05-31 10:16 . 2001-08-17 19:52 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys
2009-05-31 10:16 . 2001-08-17 18:50 36640 -c--a-w- c:\windows\system32\dllcache\t2r4mini.sys
2009-05-31 10:16 . 2001-08-30 21:07 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll
2009-05-31 10:14 . 2001-08-17 18:11 48736 -c--a-w- c:\windows\system32\dllcache\srwlnd5.sys
2009-05-31 10:14 . 2001-08-30 21:08 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll
2009-05-31 10:14 . 2001-08-30 21:08 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll
2009-05-31 10:14 . 2001-08-17 19:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys
2009-05-31 10:14 . 2001-08-30 21:08 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll
2009-05-31 10:14 . 2001-08-17 20:07 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys
2009-05-31 10:14 . 2001-08-17 19:56 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys
2009-05-31 10:14 . 2001-08-17 18:51 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys
2009-05-31 10:14 . 2001-08-30 21:08 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll
2009-05-31 10:14 . 2001-08-17 18:51 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys
2009-05-31 10:14 . 2001-08-17 19:53 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys
2009-05-31 10:14 . 2008-04-13 18:40 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys
2009-05-31 10:14 . 2001-08-17 19:53 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys
2009-05-31 10:13 . 2001-08-17 18:51 58368 -c--a-w- c:\windows\system32\dllcache\smiminib.sys
2009-05-31 10:13 . 2001-08-30 21:07 147200 -c--a-w- c:\windows\system32\dllcache\smidispb.dll
2009-05-31 10:13 . 2001-08-17 18:12 25034 -c--a-w- c:\windows\system32\dllcache\smcpwr2n.sys
2009-05-31 10:13 . 2001-08-30 20:37 36937 -c--a-w- c:\windows\system32\dllcache\smcirda.sys
2009-05-31 10:13 . 2001-08-17 18:12 24576 -c--a-w- c:\windows\system32\dllcache\smc8000n.sys
2009-05-31 10:13 . 2001-08-17 19:57 6784 -c--a-w- c:\windows\system32\dllcache\smbhc.sys
2009-05-31 10:13 . 2008-04-13 18:36 6912 -c--a-w- c:\windows\system32\dllcache\smbclass.sys
2009-05-31 10:13 . 2008-04-13 18:36 16000 -c--a-w- c:\windows\system32\dllcache\smbbatt.sys
2009-05-31 10:13 . 2001-08-30 21:08 45568 -c--a-w- c:\windows\system32\dllcache\smb3w.dll
2009-05-31 10:13 . 2001-08-30 21:08 33792 -c--a-w- c:\windows\system32\dllcache\smb0w.dll
2009-05-31 10:11 . 2001-08-30 20:30 161792 -c--a-w- c:\windows\system32\dllcache\sgsmusb.sys
2009-05-31 10:11 . 2001-07-21 20:29 18400 -c--a-w- c:\windows\system32\dllcache\sgsmld.sys
2009-05-31 10:11 . 2001-08-17 18:51 98080 -c--a-w- c:\windows\system32\dllcache\sgiulnt5.sys
2009-05-31 10:11 . 2001-08-30 21:07 386560 -c--a-w- c:\windows\system32\dllcache\sgiul50.dll
2009-05-31 10:11 . 2001-08-17 18:19 36480 -c--a-w- c:\windows\system32\dllcache\sfmanm.sys
2009-05-31 10:11 . 2001-08-30 20:28 6912 -c--a-w- c:\windows\system32\dllcache\serscan.sys
2009-05-31 10:11 . 2001-08-30 20:28 18176 -c--a-w- c:\windows\system32\dllcache\sermouse.sys
2009-05-31 10:11 . 2001-08-17 19:53 6912 -c--a-w- c:\windows\system32\dllcache\seaddsmc.sys
2009-05-31 10:11 . 2008-04-13 18:45 11520 -c--a-w- c:\windows\system32\dllcache\scsiscan.sys
2009-05-31 10:11 . 2001-08-17 19:52 11648 -c--a-w- c:\windows\system32\dllcache\scsiprnt.sys
2009-05-31 10:09 . 2001-08-30 21:07 182272 -c--a-w- c:\windows\system32\dllcache\s3mt3d.dll
2009-05-31 10:07 . 2001-08-17 19:51 19584 -c--a-w- c:\windows\system32\dllcache\rasirda.sys
2009-05-31 10:06 . 2001-08-30 21:07 5632 -c--a-w- c:\windows\system32\dllcache\ptpusb.dll
2009-05-31 10:05 . 2008-04-14 02:12 259328 -c--a-w- c:\windows\system32\dllcache\perm3dd.dll
2009-05-31 10:04 . 2001-08-30 21:08 39424 -c--a-w- c:\windows\system32\dllcache\ovcoms.exe
2009-05-31 10:03 . 2001-08-30 21:07 123776 -c--a-w- c:\windows\system32\dllcache\nv3.dll
2009-05-31 10:03 . 2001-08-17 18:49 51552 -c--a-w- c:\windows\system32\dllcache\ntgrip.sys
2009-05-31 10:03 . 2001-08-30 19:30 9472 -c--a-w- c:\windows\system32\dllcache\ntapm.sys
2009-05-31 10:03 . 2001-08-17 19:53 7552 -c--a-w- c:\windows\system32\dllcache\nsmmc.sys
2009-05-31 10:03 . 2008-04-13 18:54 28672 -c--a-w- c:\windows\system32\dllcache\nscirda.sys
2009-05-31 10:03 . 2001-08-17 18:20 87040 -c--a-w- c:\windows\system32\dllcache\nm6wdm.sys
2009-05-31 10:03 . 2001-08-17 18:20 126080 -c--a-w- c:\windows\system32\dllcache\nm5a2wdm.sys
2009-05-31 10:03 . 2001-08-17 18:12 32840 -c--a-w- c:\windows\system32\dllcache\ngrpci.sys
2009-05-31 10:03 . 2004-08-19 13:33 132695 -c--a-w- c:\windows\system32\dllcache\netwlan5.sys
2009-05-31 10:03 . 2001-08-30 19:20 66174 -c--a-w- c:\windows\system32\dllcache\netflx3.sys
2009-05-31 10:03 . 2001-08-17 18:50 39264 -c--a-w- c:\windows\system32\dllcache\neo20xx.sys
2009-05-31 10:01 . 2008-04-13 18:46 49024 -c--a-w- c:\windows\system32\dllcache\mstape.sys
2009-05-31 10:01 . 2001-08-17 19:48 12416 -c--a-w- c:\windows\system32\dllcache\msriffwv.sys
2009-05-31 10:01 . 2001-08-17 20:00 2944 -c--a-w- c:\windows\system32\dllcache\msmpu401.sys
2009-05-31 10:01 . 2008-04-13 18:54 22016 -c--a-w- c:\windows\system32\dllcache\msircomm.sys
2009-05-31 10:01 . 2001-08-17 20:02 35200 -c--a-w- c:\windows\system32\dllcache\msgame.sys
2009-05-31 10:01 . 2001-08-17 19:48 6016 -c--a-w- c:\windows\system32\dllcache\msfsio.sys
2009-05-31 10:01 . 2008-04-13 18:46 51200 -c--a-w- c:\windows\system32\dllcache\msdv.sys
2009-05-31 10:01 . 2001-08-17 19:52 17280 -c--a-w- c:\windows\system32\dllcache\mraid35x.sys
2009-05-31 10:00 . 2008-04-13 18:46 15232 -c--a-w- c:\windows\system32\dllcache\mpe.sys
2009-05-31 10:00 . 2001-08-30 18:41 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-05-31 10:00 . 2001-08-17 19:52 6528 -c--a-w- c:\windows\system32\dllcache\miniqic.sys
2009-05-31 10:00 . 2001-08-30 18:34 320384 -c--a-w- c:\windows\system32\dllcache\mgaum.sys
2009-05-31 10:00 . 2001-08-30 21:07 235648 -c--a-w- c:\windows\system32\dllcache\mgaud.dll
2009-05-31 10:00 . 2008-04-13 18:41 26112 -c--a-w- c:\windows\system32\dllcache\memstpci.sys
2009-05-31 10:00 . 2001-08-30 21:07 47616 -c--a-w- c:\windows\system32\dllcache\memgrp.dll
2009-05-31 10:00 . 2001-08-17 19:58 8320 -c--a-w- c:\windows\system32\dllcache\memcard.sys
2009-05-31 10:00 . 2001-08-30 18:21 165034 -c--a-w- c:\windows\system32\dllcache\mdgndis5.sys
2009-05-31 10:00 . 2001-08-17 19:52 7424 -c--a-w- c:\windows\system32\dllcache\mammoth.sys
2009-05-31 09:20 . 2008-04-13 18:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2009-05-31 09:20 . 2001-08-30 18:03 26986 -c--a-w- c:\windows\system32\dllcache\lanepic5.sys
2009-05-31 09:20 . 2001-08-17 18:12 19016 -c--a-w- c:\windows\system32\dllcache\ktc111.sys
2009-05-31 09:20 . 2001-08-30 21:07 37376 -c--a-w- c:\windows\system32\dllcache\kousd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 17:47 . 2009-04-19 05:19 -------- d-----w- c:\programmi\Mozilla Thunderbird
2009-06-01 17:43 . 2009-04-19 07:14 2608 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-01 17:34 . 2009-04-19 06:59 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\Skype
2009-05-31 18:09 . 2009-04-19 07:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-05-31 14:43 . 2009-05-31 14:44 1594880 ----a-w- c:\windows\Internet Logs\xDBF.tmp
2009-05-31 10:38 . 2009-04-22 05:30 5842976 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-31 08:44 . 2009-04-19 07:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-05-31 08:32 . 2009-04-22 05:30 66008 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-05-30 22:23 . 2009-05-31 08:26 1593344 ----a-w- c:\windows\Internet Logs\xDBE.tmp
2009-05-30 21:49 . 2006-03-02 12:00 81380 ----a-w- c:\windows\system32\perfc010.dat
2009-05-30 21:49 . 2006-03-02 12:00 483474 ----a-w- c:\windows\system32\perfh010.dat
2009-05-27 15:35 . 2009-05-27 15:43 1586688 ----a-w- c:\windows\Internet Logs\xDBD.tmp
2009-05-22 15:06 . 2009-04-19 07:04 -------- d-----w- c:\programmi\Google
2009-05-21 15:24 . 2009-05-21 15:25 1576448 ----a-w- c:\windows\Internet Logs\xDBC.tmp
2009-05-20 13:50 . 2009-04-19 21:09 43792 ----a-w- c:\documents and settings\antonio\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-05-12 18:00 . 2009-05-13 10:25 1560064 ----a-w- c:\windows\Internet Logs\xDBB.tmp
2009-05-09 15:32 . 2009-05-09 17:37 1556480 ----a-w- c:\windows\Internet Logs\xDBA.tmp
2009-05-03 18:49 . 2009-04-19 09:37 -------- d-----w- c:\programmi\File comuni\Adobe
2009-05-02 11:59 . 2009-05-02 12:00 3486720 ----a-w- c:\windows\Internet Logs\xDB8.tmp
2009-05-02 11:59 . 2009-05-02 12:00 1534976 ----a-w- c:\windows\Internet Logs\xDB9.tmp
2009-05-02 11:07 . 2009-04-18 17:10 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-02 11:07 . 2009-04-18 17:10 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-02 11:07 . 2009-04-18 17:10 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-02 11:07 . 2009-04-18 17:10 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-02 11:05 . 2009-05-02 11:05 1437464 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgupd.dll
2009-05-02 11:05 . 2009-05-02 11:05 755992 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avginet.dll
2009-04-30 07:25 . 2009-04-30 07:26 1527296 ----a-w- c:\windows\Internet Logs\xDB7.tmp
2009-04-29 04:59 . 2009-04-29 04:59 -------- d-----w- c:\programmi\Trend Micro
2009-04-28 12:27 . 2009-04-28 13:48 1512448 ----a-w- c:\windows\Internet Logs\xDB6.tmp
2009-04-27 17:25 . 2009-04-27 17:25 2496 ----a-w- c:\windows\system32\d3d8caps.dat
2009-04-27 14:38 . 2009-04-27 14:40 1501696 ----a-w- c:\windows\Internet Logs\xDB1A.tmp
2009-04-27 09:26 . 2009-04-27 09:26 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\Ahead
2009-04-27 09:21 . 2009-04-27 09:21 -------- d-----w- c:\programmi\File comuni\Ahead
2009-04-27 09:21 . 2009-04-27 09:21 -------- d-----w- c:\programmi\Nero
2009-04-27 05:49 . 2009-04-27 05:49 -------- d-----w- c:\programmi\File comuni\Adobe Systems Shared
2009-04-27 05:20 . 2009-04-27 05:20 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\FLEXnet
2009-04-26 07:00 . 2009-04-26 07:00 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-26 07:00 . 2009-04-26 07:00 -------- d-----w- c:\programmi\Java
2009-04-26 06:59 . 2009-04-26 06:59 152576 ----a-w- c:\documents and settings\antonio\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-26 05:29 . 2009-04-26 05:29 34816 ----a-w- c:\windows\system32\BGData.bin
2009-04-25 15:20 . 2009-04-26 05:28 2670592 ----a-w- c:\windows\Internet Logs\xDB4.tmp
2009-04-25 15:20 . 2009-04-26 05:28 1464320 ----a-w- c:\windows\Internet Logs\xDB5.tmp
2009-04-25 12:18 . 2009-04-25 13:47 1460736 ----a-w- c:\windows\Internet Logs\xDB3.tmp
2009-04-25 12:18 . 2009-04-25 13:47 2978816 ----a-w- c:\windows\Internet Logs\xDB2.tmp
2009-04-25 06:38 . 2009-04-25 06:38 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\AdobeUM
2009-04-25 06:35 . 2009-04-25 06:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Adobe Systems
2009-04-25 05:56 . 2009-04-25 05:56 -------- d-----w- c:\programmi\Diskeeper Corporation
2009-04-25 05:01 . 2009-04-25 05:01 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WinZip
2009-04-24 18:13 . 2009-04-24 18:13 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\ACD Systems
2009-04-24 18:09 . 2009-04-24 18:09 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ACD Systems
2009-04-24 18:09 . 2009-04-24 18:09 -------- d-----w- c:\programmi\File comuni\ACD Systems
2009-04-24 18:09 . 2009-04-24 18:09 -------- d-----w- c:\programmi\ACD Systems
2009-04-24 15:10 . 2009-04-24 15:08 -------- d-----w- c:\programmi\Macromedia
2009-04-24 15:10 . 2009-04-24 14:30 -------- d-----w- c:\programmi\File comuni\Macromedia
2009-04-24 15:10 . 2009-04-19 09:28 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-04-24 12:24 . 2009-04-24 13:59 1263616 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2009-04-24 12:18 . 2009-04-24 12:18 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\GlobalSCAPE
2009-04-24 12:18 . 2009-04-24 12:18 -------- d-----w- c:\programmi\GlobalSCAPE
2009-04-24 07:43 . 2009-04-24 07:43 -------- d-----w- c:\programmi\Microsoft.NET
2009-04-24 06:49 . 2009-04-24 06:49 -------- d-----w- c:\programmi\Panda Security
2009-04-23 18:10 . 2009-04-23 18:10 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\vlc
2009-04-23 18:09 . 2009-04-23 18:09 -------- d-----w- c:\programmi\VideoLAN
2009-04-23 11:00 . 2009-04-23 11:00 -------- d-----w- c:\programmi\MySQL
2009-04-23 06:19 . 2009-04-23 06:19 -------- d-----w- c:\programmi\Apache Software Foundation
2009-04-22 11:46 . 2009-04-22 11:46 -------- d-----w- c:\programmi\IZArc
2009-04-22 10:11 . 2009-04-22 10:10 -------- d-----w- c:\programmi\Microsoft LifeCam
2009-04-22 05:28 . 2009-04-18 17:23 4212 ---h--w- c:\windows\system32\zllictbl.dat
2009-04-22 05:08 . 2009-04-22 05:08 -------- d-----w- c:\programmi\Zone Labs
2009-04-22 04:58 . 2009-04-22 04:58 -------- d-----w- c:\programmi\VIA
2009-04-22 04:57 . 2009-04-19 09:28 -------- d-----w- c:\programmi\File comuni\InstallShield
2009-04-22 04:53 . 2009-04-22 04:53 -------- d-----w- c:\programmi\Fastrate USB 100
2009-04-22 04:52 . 2009-04-22 04:52 -------- d-----w- c:\programmi\Telecom Italia
2009-04-21 17:58 . 2009-04-21 08:04 137152 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2009-04-21 17:57 . 2009-04-21 17:57 -------- d-----w- c:\programmi\ADSL MODEM UTILITY
2009-04-21 11:04 . 2009-04-21 11:04 -------- d-----w- c:\programmi\CCleaner
2009-04-21 07:38 . 2009-04-21 07:38 -------- d-----w- c:\programmi\MSBuild
2009-04-21 07:33 . 2009-04-21 07:33 -------- d-----w- c:\programmi\Reference Assemblies
2009-04-20 17:56 . 2009-04-20 05:43 -------- d-----w- c:\programmi\eMule
2009-04-19 15:07 . 2009-04-19 15:07 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\EPSON
2009-04-19 15:07 . 2009-04-19 15:06 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\Smart Panel
2009-04-19 10:38 . 2009-04-18 16:55 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-19 09:44 . 2009-04-19 09:41 -------- d-----w- c:\programmi\Hewlett-Packard
2009-04-19 09:44 . 2009-04-19 09:44 82380 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2009-04-19 09:37 . 2009-04-19 09:37 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\InterTrust
2009-04-19 09:31 . 2009-04-19 09:31 -------- d-----w- c:\programmi\ArcSoft
2009-04-19 09:31 . 2009-04-19 09:28 -------- d-----w- c:\programmi\Smart Panel
2009-04-19 09:31 . 2009-04-19 09:31 -------- d-----w- c:\programmi\File comuni\Python
2009-04-19 09:30 . 2009-04-19 09:28 -------- d-----w- c:\programmi\EPSON
2009-04-19 09:09 . 2009-04-19 09:09 -------- d-----w- c:\programmi\VIA Technologies, Inc
2009-04-19 08:06 . 2009-04-19 08:06 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\Malwarebytes
2009-04-19 08:06 . 2009-04-19 08:06 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-04-19 08:06 . 2009-04-19 08:06 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-04-19 08:03 . 2009-04-19 07:57 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-04-19 06:59 . 2009-04-19 06:59 -------- d-----r- c:\programmi\Skype
2009-04-19 06:59 . 2009-04-19 06:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2009-04-19 05:19 . 2009-04-19 05:19 -------- d-----w- c:\documents and settings\antonio\Dati applicazioni\Thunderbird
2009-04-19 04:46 . 2009-04-19 04:46 0 ----a-w- c:\windows\nsreg.dat
2009-04-18 17:24 . 2009-04-18 17:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MailFrontier
2009-04-18 17:10 . 2009-04-18 17:10 -------- d-----w- c:\programmi\AVG
2009-04-18 17:10 . 2009-04-18 17:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-02 1947928]
"Matrox Powerdesk"="c:\windows\system32\PDesk\PDesk.exe" [2003-08-11 667648]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Monitor Apache Servers.lnk - c:\programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe [2008-12-10 41042]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-02 11:07 11952 ----a-w- c:\windows\system32\avgrsstx.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Avvio veloce di Adobe Acrobat.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Avvio veloce di Adobe Acrobat.lnk
backup=c:\windows\pss\Avvio veloce di Adobe Acrobat.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^raid_tool.exe.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\raid_tool.exe.lnk
backup=c:\windows\pss\raid_tool.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^antonio^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma.lnk]
path=c:\documents and settings\antonio\Menu Avvio\Programmi\Esecuzione automatica\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"BITS"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:eMule_TCP
"4672:UDP"= 4672:UDP:eMule_UPD

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [24/04/2009 8.50.35 28544]
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [22/04/2009 6.58.30 75904]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18/04/2009 19.10.41 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18/04/2009 19.10.47 108552]
R2 Apache2.2;Apache2.2;c:\programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe [10/12/2008 0.10.14 24636]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [18/04/2009 19.10.34 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [18/04/2009 19.10.33 298776]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [22/04/2009 6.53.23 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;c:\windows\system32\drivers\torususb.sys [22/04/2009 6.53.23 527980]
S2 gupdate1c9c0bd9625e4ac;Servizio di Google Update (gupdate1c9c0bd9625e4ac);c:\programmi\Google\Update\GoogleUpdate.exe [19/04/2009 9.06.31 133104]
S3 UtilNT;UtilNT;c:\windows\system32\drivers\UtilNt.sys [19/04/2009 10.37.56 5533]
.
Contenuto della cartella 'Scheduled Tasks'

2009-05-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2009-06-01 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-19 07:04]

2009-06-01 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-04-19 07:05]

2009-04-22 c:\windows\Tasks\Microsoft_Hardware_Launch_vVX3000_exe.job
- c:\windows\vVX3000.exe [2009-04-19 14:22]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

SafeBoot-procexp90.Sys


.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: Aggiungi a PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {EC0324A8-26D1-467F-BB05-32528C84956F} = 151.99.125.1,151.99.250.2
FF - ProfilePath - c:\documents and settings\antonio\Dati applicazioni\Mozilla\Firefox\Profiles\gku9z3e5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.it
FF - component: c:\programmi\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-01 19:57
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\programmi\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\programmi\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(3884)
c:\windows\system32\PDesk\PDKERNEL.DLL
c:\windows\system32\PDesk\PDTOOLS.DLL
c:\windows\system32\PDesk\PDRESITA.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2009-06-01 19.59.48
ComboFix-quarantined-files.txt 2009-06-01 17:59

Pre-Run: 29.088.890.880 byte disponibili
Post-Run: 29.089.525.760 byte disponibili

365 --- E O F --- 2009-05-13 18:07vv
r16
Inviato: Monday, June 01, 2009 11:17:17 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Combofix, non ha rilevato niente di anomalo.
Aspetto il log di MBAM.
Poi fai queste pulizie:
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
Poi:
Start\Esegui\copia e incolla la stringa %temp% clicca su Ok, svuota la cartella temp. (non eliminare la cartella)
Poi:
Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO
Poi:
Lancia Hijackthis e pulisci gli ADS in questo modo:
clicca sulla voce Open the misc tool section
clicca su Open ads spy
togli la spunta alla voce Quick scan (windows base folder only)
clicca su Scan
se venissero rilevati ADS, spunta tutte le caselline e clicca su Remove selected
acquaborra
Inviato: Tuesday, June 02, 2009 11:49:55 AM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
questo è il log di mbam
Malwarebytes' Anti-Malware 1.37
Versione del database: 2212
Windows 5.1.2600 Service Pack 3

02/06/2009 11.36.18
mbam-log-2009-06-02 (11-36-18).txt

Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 228198
Tempo trascorso: 1 hour(s), 39 minute(s), 39 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)
adesso procedo a fare quello che mi hai suggerito
acquaborra
Inviato: Wednesday, June 03, 2009 8:15:52 AM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
Fatto tutto quello che mi hai suggerito ma non ho rilevato miglioramenti riguardo alla lentezza nell'avvio di XP.
Ripeto ho installato SP3, AVG 8.5 e Zone Alarm.
r16
Inviato: Wednesday, June 03, 2009 11:47:51 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao acquaborra .
Le scansioni non hanno rilevato infezioni.
Prova disistallare il firewall, e vedi se ci sono notevoli miglioramenti.
Poi fai questa scansione:
SYSTEM SCAN

scaricalo sul desktop:
http://www.suspectfile.com/systemscan
Aprilo ed assicurati che tutte le opzioni siano spuntate, clicca su "Scan Now"
Finita la scansione verranno rilasciati (sempre sul desktop all'interno della cartella suspectfile) due file.
Collegati ad internet e vai alla pagina WikiSend: http://www.wikisend.com/
Clicca sul bottone "Sfoglia"
Seleziona il file appena salvato
Clicca su Upload file
Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati:
Download Link / Forum Link
Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum.
Ricordati d'effettuare la scansione senza connessione attiva e con l'antivirus disabilitato salvo poi riattivarlo a scansione terminata.

NB:
la durata della scansione può risultare lunga, potrebbe addirittura sembrare che il programma non stia lavorando, non preoccuparti non è così.
SystemScan viene riconosciuto, erroneamente, da alcuni antivirus come infetto.
giza
Inviato: Thursday, June 04, 2009 10:58:59 AM

Rank: AiutAmico

Iscritto dal : 10/27/2006
Posts: 9,589
"Lancia Hijackthis e pulisci gli ADS in questo modo:
clicca sulla voce Open the misc tool section
clicca su Open ads spy
togli la spunta alla voce Quick scan (windows base folder only)
clicca su Scan
se venissero rilevati ADS, spunta tutte le caselline e clicca su Remove selected ""


ma gli ads sono questi? e cosa sono?

C:\Documents and Settings\All Users\Dati applicazioni\TEMP : 5C321E34 (125 bytes)
C:\Documents and Settings\All Users\Dati applicazioni\TEMP : 5C321E34 (125 bytes)
C:\WINDOWS\Cursors\arrow_n.cur : NEDTA.DAT (6144 bytes)
paolopa
Inviato: Thursday, June 04, 2009 11:14:37 AM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
dico una banalita',non è che per caso stai viaggiando con due firewall?windows firewall e zone allarm,che magari possono creare conflitto?se è una sciocchezza scusate l' intrusione.
acquaborra
Inviato: Thursday, June 04, 2009 12:17:55 PM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
Caro r16 rieccomi
Allora, disattivando ZA non ho trovato miglioramenti. Ho fatto quindi il resto.
report.txt
r16
Inviato: Thursday, June 04, 2009 2:46:49 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao acquaborra
Ricapitoliamo:
Nessuna scansione che è stata effettuata, ha rilevato infezioni.
Il log di Systemscan, non presenta problemi.
Fai questa scansione con il Tool di Kaspersky, se non trova nulla, non è un problema di virus.
Installa KASPERSKY VIRUS REMOVAL TOOL sul Desktop:
http://downloads5.kaspersky-labs.com/devbuilds/AVPTool/
Doppio click sul Setup.exe.
verrà creata una apposta cartella sul Desktop e comparirà la schermata iniziale del Tool.
imposta le aree che intendi scansionare (Startup Objects e Disk boot sector sono impostate di default) e clicca "SCAN"
al termine della scansione sarà possibile rimuovere e/o mettere in quarantena i file infetti rilevati
salva il log che verrà rilasciato.

Clicca "Reports" poi - "Save to file" e per comodità salvalo sul Desktop.(poi lo posti qui)

Per eliminare Kaspersky Virus Removal Tool ,devi chiudere il programma cliccando X in alto alla finestra, ti comparirà una finestra, che ti chiederà se vuoi rimuovere completamente il programma dal tuo computer.
Clicca SI.
Dopo la disistallazione ti chiederà di riavviare il pc.
Clicca SI di nuovo.
Posta il log nelle stesse modalità di Systemscan.
acquaborra
Inviato: Thursday, June 04, 2009 9:18:49 PM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
Questo è il report di Kaspersky:
report.txt
r16
Inviato: Thursday, June 04, 2009 11:16:40 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao
Nessun miglioramento?

Installa Internet Explorer 7 :

http://www.microsoft.com/downloads/details.aspx?FamilyID=9ae91ebe-3385-447c-8a30-081805b2f90b&DisplayLang=it

Da Installazione Applicazioni, disinstalla tutte le versioni installate di Abobe Reader, Adobe Flash Player (comprese quelle marcate Macromedia) e Javasun ( (tutte le versioni eventuamente presenti) .

Dopo la disinstallazione, installa le versioni aggiornate di:
Adobe Reader:
http://www.adobe.com/it/products/acrobat/readstep2.html

Adobe Flash Player:
http://www.adobe.com/it/products/flashplayer/


JAVASun:
http://www.aiutamici.com/software?ID=11134

Se in fase di installazione, ti venisse rchiesta l'installazione di qualche Toolbar, non la installare.
Posta un log aggiornato di HJT.
acquaborra
Inviato: Friday, June 05, 2009 1:15:41 PM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
Ciao,
ti aggiorno.
Ho disistallato e reinstallato i programmi che mi hai indicato. Ho dovuto però disistallare IE7 e tornare a IE6 perché non riuscivo con IE7 a connettermi ad internet sebbene avessi provato di tutto. Firefox si connetteva IE7 no. Tornando ad IE6 tutto OK.
Non capisco.
Comunque ecco il log di HjT aggiornato:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13.10.32, on 05/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\mgabg.exe
C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\Programmi\Microsoft LifeCam\MSCamS32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Programmi\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmi\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\PDesk\PDesk.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
O8 - Extra context menu item: Aggiungi a PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapserver3.ldpassociati.it/include/activex/MGViewer/6.0.4.2/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1240123413609
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC0324A8-26D1-467F-BB05-32528C84956F}: NameServer = 151.99.125.1,151.99.250.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Servizio di Google Update (gupdate1c9c0bd9625e4ac) (gupdate1c9c0bd9625e4ac) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\antonio\IMPOST~1\Temp\hpdj.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINDOWS\system32\mgabg.exe
O23 - Service: MySQL - Unknown owner - C:\Programmi\MySQL\MySQL.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7717 bytes
r16
Inviato: Friday, June 05, 2009 1:29:15 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao acquaborra .
Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
O8 - Extra context menu item: Aggiungi a PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapserver3.ldpassociati.it/include/activex/MGViewer/6.0.4.2/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site .cab?1240123413609
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Servizio di Google Update (gupdate1c9c0bd9625e4ac) (gupdate1c9c0bd9625e4ac) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\antonio\IMPOST~1\Temp\hpdj.exe (file missing)

Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223

Riavvia il computer.
Posta un nuovo log di HJT.
acquaborra
Inviato: Friday, June 05, 2009 4:45:03 PM

Rank: Member

Iscritto dal : 8/15/2008
Posts: 15
Eccomi,
dunque al riavvio le cose sembrano migliorate infatti XP è rimasto solo qualche istante su "caricamento delle impostazioni personali...." contro i vari minuti di prima. A questo punto vorrei sapere se ZA lo posso rimettere all'avvio di Windows. Anche il servizio di Apache non è partito lo faccio manualmente alla bisogna?
Ecco comunque il nuovo log HJT;
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16.38.05, on 05/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\mgabg.exe
C:\Programmi\Microsoft LifeCam\MSCamS32.exe
C:\Programmi\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Programmi\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC0324A8-26D1-467F-BB05-32528C84956F}: NameServer = 151.99.125.1,151.99.250.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apache2.2 - Apache Software Foundation - C:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Servizio di Google Update (gupdate1c9c0bd9625e4ac) (gupdate1c9c0bd9625e4ac) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINDOWS\system32\mgabg.exe
O23 - Service: MySQL - Unknown owner - C:\Programmi\MySQL\MySQL.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5461 bytes
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.