Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Aiuto! Worm Bage1 Opzioni
delgiud
Inviato: Monday, June 22, 2009 9:27:39 AM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Non funziona più la connessione wireless (sono collegato con la linea telefonica) non si avviano più nè spybot, nè hijackthis. Non mi fa accedere nemmeno alla modalità provvisoria. L'unico risultato l'ho avuto con mbam: ecco il log:
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sk9ou0s (Worm.Bagel) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sk9ou0s (Worm.Bagel) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sk9ou0s (Worm.Bagel) -> Quarantined and deleted successfully.

Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Not selected for removal.

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Not selected for removal.

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\11s11ro1s1a2.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP276\A0027987.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP277\A0028009.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP278\A0028046.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP278\A0028068.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP279\A0028088.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP279\A0028122.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP279\A0028142.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP279\A0028335.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP281\A0028433.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP281\A0028443.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP281\A0028453.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP281\A0028463.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP282\A0028482.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP282\A0028468.sys (Worm.Bagel) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP282\A0028492.sys (Worm.Bagel) -> Quarantined and deleted successfully.
Mi date una mano, ragazzi? Grazie.
Sponsor
Inviato: Monday, June 22, 2009 9:27:39 AM

 
shapiro
Inviato: Monday, June 22, 2009 9:39:15 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
come hai notato hai il virus bagle - malwarebytes ha gia' eliminato parecchio

ora disattiva il ripristino e scarica

http://dc108.4shared.com/download/75022994/b07bff/FindyKill.exe?tsid=20090209-102651-de3379fb


Una volta installato chiudi tutte le applicazioni attive e disconnettiti dal internet, poi clicca sull'icona di FindyKill e nella finestra dos che si aprirà scrivi 2 e premi Invio. Attendi il termine della scansione e posta qui il log che trovi in C:\FindyKill.txt


delgiud
Inviato: Monday, June 22, 2009 10:18:12 AM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Ciao Shapiro! Come stai? Contavo proprio su di Te, visto che mi hai già aiutato con successo altre volte. Come vedi....sono recidivo!Brick wall Ecco il log di Findykill:


----------------- FindyKill V4.707 ------------------

* User : Dott.GuidoDelGiudice - DOTT-AE02C74C19
* executed from : C:\Programmi\FindyKill
* Update on 06/12/08 par Chiquitine29
* Start at 9:57:27 the 22/06/2009
* Windows XP - Internet Explorer 6.0.2900.2180


((((((((((((((( *** deleting *** ))))))))))))))))))


--------------- [ Active Processes ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\init32.exe
C:\Programmi\Google\Update\GoogleUpdate.exe

--------------- [ Infected files / folders ] ----------------


»»»» Supression files in C:


»»»» Supression files in C:\WINDOWS


»»»» Supression files in C:\WINDOWS\Prefetch

Deleted ! - C:\WINDOWS\prefetch\1034781.EXE-014E0095.pf
Deleted ! - C:\WINDOWS\prefetch\1115796.EXE-0C97F284.pf
Deleted ! - C:\WINDOWS\prefetch\1151671.EXE-2BE3E876.pf
Deleted ! - C:\WINDOWS\prefetch\1188578.EXE-0F505AFB.pf
Deleted ! - C:\WINDOWS\prefetch\1776359.EXE-2D6782CB.pf
Deleted ! - C:\WINDOWS\prefetch\1784687.EXE-0BD37ADE.pf
Deleted ! - C:\WINDOWS\prefetch\1811046.EXE-0DC1BFCF.pf
Deleted ! - C:\WINDOWS\prefetch\2458500.EXE-1F91ECC6.pf
Deleted ! - C:\WINDOWS\prefetch\432937.EXE-0E295B81.pf
Deleted ! - C:\WINDOWS\prefetch\787218.EXE-348C194E.pf
Deleted ! - C:\WINDOWS\prefetch\977656.EXE-0A17CE8D.pf
Deleted ! - C:\WINDOWS\prefetch\FLEC006.EXE-1E33D9B7.pf
Deleted ! - C:\WINDOWS\prefetch\MDELK.EXE-1D176F91.pf
Deleted ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf

»»»» Supression files in C:\WINDOWS\system32

Not deleted !! - C:\WINDOWS\system32\mdelk.exe
Not deleted !! - C:\WINDOWS\system32\wintems.exe
Deleted ! - C:\WINDOWS\system32\ban_list.txt

»»»» Supression files in C:\WINDOWS\system32\drivers


»»»» Supression files in C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni

Not deleted !! - "C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\flec006.exe"
Deleted ! - "C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\list.oct"
Deleted ! - "C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\data.oct"
Deleted ! - "C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\srvlist.oct"
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\#1_Spyware_Killer_2.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\(Kaspersky.Anti-Virus.Personal.Pro).v5.0.20.Final+reg+license.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\120 Lip Smacking Good Jam Recipes 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\1Z0-007_Oracle_OCP_DBA9i_Introduction_to_Oracle9i_SQL_8.02.05.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Abyss Image Converter 1.00.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\AddLinx_1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\AddThis All-In-One Bookmarking Button 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\ADG_Panorama_Tools_5.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Age_of_Mythology_-_Volcano_Single-player_scenario.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\AgsPro_Dictionary_2.5.2.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\anInvoicer 1.0.0.35.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Arabic_School_Software_(for_beginners)_1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\avg.antispyware.7.5.xx.patch.-.it'ok.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\AVG.Antivirus.v7.0.280.+.SERIAL.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Babya_System_Profiler_2005_11.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Baseball_Card_Collector_Professional_7.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\BGBlitz_1.9.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\BitDefender.Professional.Plus.v8.0.200.WinALL.Incl.Keymaker.And.Patch-CORE.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\BS Icon Maker 1.0.0.4.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Budget Calendar 1.4.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Candle_Prayer_Clock_Demo_Screensaver_1.0_[Patch].zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Catalyst File Transfer Control 6.00.6000.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\ClearCode_1.3.01.396.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Compu-Rx 2.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Content_Scanner_1.0.0.287.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\CrazyContrast 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Create New Folder 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Cute DVD Ripper 1.40.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Delphi_Programmers_tutorial_1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\DisCatalog_2.00.417.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Doe_By_The_Lake_Screensaver_1.0_(KeyGen).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Downloader_Pro_2.0_(Cracked).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\DrWeb.v4.32.key.26-02-2005.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Eastsea_Outlook_Backup_2.00_(With_Crack).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Easy_Web_Gallery_Builder_1.8.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\EZReg_3.12.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\FineBrowser_3.2.33.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Flash DVD Ripper 0.92.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Flash Effect Maker 2.8326 Cracked.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Flash Screensaver 1.0 (Key).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Flash To Video Encoder 4.6.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Flash2Video_4.5.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\foo dsp vlevel 20060324.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\FreeSnap 1.2.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Fuzzy_Sets_for_Ada_4.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Ghost Control Pro 2.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Ghost World Alarm Clock 3.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Halloween_Ghosts_1.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Hang Man 2.1.3.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\HashPuff_1.0.3.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Hatha_Yoga_1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Hit_Inspector_4.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\HP0-390 Practice Exam Testing Engine Software 1.0 (Serial).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Informatik_RawPrint_1.1_(Cracked).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\InstantTxt 0.1.0.15.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Inventory_Director_1.11.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\IPodExtras_1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\KaraFun_1.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Kernel_ReiserFS_4.03_(Serial).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\KeyLaunch 2.1.7.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\KoolKode 2.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Licencia.para.plesk.8.0.1.Linux.-.30.dominios.-.SpamAssassin.-.DrWeb.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\liveDJpro Aqua Edition 1.4.595.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Marker 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Messenger Spam Block 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Mocha Telnet for Vista 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Mondo!_E-Journal_1.1_(Cracked).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Mountain_Skiing_1.1_[Key].zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\MovieFinder_1.240f.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Multi-Browser XP 10.2.8.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\MultiBlog 1.2.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\MySQL-to-MSSQL_3.1_[KeyGen].zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\MyToolkit_2.1.0.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\NCT_Xpress_Download_2.0.2.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\NetLink_3.3.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Ninja_Loves_Pirate_demo.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\NoteScraps 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\nvLeaseCalculator_1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\OffHook 1.0.5 Build 013.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\omega123 toolbar for IE 4.5.131.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Optimal_Inventory_1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\PaintingAll Paul Cezanne Screensaver 1.1.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\PassMark Rebooter 1.3.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Patent Grabber 4.6.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Personalised Letters 2006 1.1.0.3.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Phrogsy 1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Plogue Bidule 0.9687.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Power_CD+G_Filter_1.0.15a.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\PTBSync_4.7b.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Recording to iPod Solution 5.2.11.4.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\RM-X_Photo_Extractor_1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\ROICalculator 1.0.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\RoxBox Karaoke Player 3.1.9.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\RSI_Frontdesk_Manager_1.01d.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Script_Start_1.1.3_[Serial].zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Shortcut Creator 4U3 2.0.20.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Shot_Online_Oceania_AUS_&_NZ.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Simply_CallerID_1.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Sin_City_Trailer.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Smart_Photo_Search_3.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\SpamFilter_for_Eudora_1.5.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\SpamSource_3.16.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Spyware_Medic_1_build_624.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\SQL_Documentor_1.0_Cracked.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Stereographer_1.00_(Key).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Super Yahoo Messenger Archive Decoder 34.06.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Sygate_Personal_Firewall_PRO_5.5.2828_[Cracked].zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Synergy_1.3.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Tardis 2000 1.6 (KeyGen).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\The_Elder_Scrolls_IV_Oblivion_Emperor's_Haven_mod.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Total Power Guitar 1.09.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Travel Dictionary Dutch- PC 5.0.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\urlStart 1.0.2.1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Utility_Ping_2.1.2_[Key+Serial].zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Video Browser 1.1.13.0 Beta 2.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Virtual Serial Port Driver XP 4.5.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\WarHeads_demo.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\WatchDog_8.5.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Weather_Station_1.1.2.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\WebMonitorDummy 1.01.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Windows_History_clean_helper_2.0_[KeyGen].zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\WinLock Remote Administrator 1.45.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\World_Almanac_4.3.0_(KeyGen).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\Wurlitzer_MP3_Jukebox_Player_1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\X-Shrink_1.5.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\X360_Video_Player_ActiveX_Control_1.zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\[APP].Kaspersky.5.0.for.Windows.Workstations.‘-¾‘oªŠ¦z‡%^.2007.3.30‘o%†Sû‘oY‚T?(Crack.Key).zip
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared\[BrasilP2P]Mcafee.Virusscan.Enterprise.8.0i+Desktop.Firewall.8.5.DrMartinez.zip
Deleted ! - "C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m\shared"
Not deleted !! - "C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\m"

»»»» Supression files in C:\DOCUME~1\DOTT~1.GUI\IMPOST~1\Temp


»»»» Supression files in C:\Documents and Settings\Dott.GuidoDelGiudice\Local Settings\Temporary Internet Files\Content.IE5

Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\0JERI5UL\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\0JERI5UL\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\2LAPOJ8X\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\2LAPOJ8X\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\2P8F2TQ5\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\674TM1SV\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\674TM1SV\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\674TM1SV\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\77EHAH6B\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\77EHAH6B\b64[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\77EHAH6B\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\77EHAH6B\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\8HAV8DEN\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\8HAV8DEN\b64[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\9K8B550T\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\9K8B550T\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\A8TPBFF7\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\A8TPBFF7\b64[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\A8TPBFF7\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\APVKP8JM\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\AX47YDA5\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\AX47YDA5\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\CPWNGZ0Z\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\CPWNGZ0Z\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\FCL1NSCK\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\FCL1NSCK\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\FCL1NSCK\b64_3[3].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\FCL1NSCK\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\FCL1NSCK\mxd[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\GHGFSZ47\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\GHGFSZ47\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\GHGFSZ47\b64_3[3].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\KH8TA3S5\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\KH8TA3S5\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\QJ23M56B\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\QJ23M56B\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\SDSFSVKF\b64_6[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\STIBWXYP\b64[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\STIBWXYP\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\STIBWXYP\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\STIBWXYP\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\W9OHQFOT\b64_6[1].jpg
Deleted ! - C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\Y7I36XA7\b64_1[1].jpg

--------------- [ Registry / Infected keys ] ----------------

Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-1202660629-1788223648-839522115-1004\Software\Local AppWizard-Generated Applications\install_crack

--------------- [ States / Restarting of services ] ----------------

+- Safe boot mode restored !


+- Services : [ Auto=2 / Request=3 / Disable=4 ]

Ndisuio - Type of startup = 3

Ip6Fw - Type of startup = 2

SharedAccess - Type of startup = 2

wuauserv - Type of startup = 2

wscsvc - Type of startup = 2


--------------- [ Cleaning removable drives ] ----------------

+- Informations :

C: - Unit… fissa

D: - Unit… CD-ROM


+- deleting files :


--------------- [ Registry / Mountpoint2 ] ----------------


-> Not found !


--------------- [ Searching Cracks / Keygen ] ----------------

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Backup pendrive1-3-07\Keygen.exe
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\0Dayz Motorola Gamez Appz Torrentboyz.com Pack 5\ALON.Software.Contact.Guide.v1.02.UIQ.Motorola.AXXX.A1000.SymbianOS.Cracked-SyMPDA.rar
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\Access.NetFront.v3.2.S60.SymbianOS7.Cracked-PWNPDA.SIS
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\ALON_ContactGuide-Pro_v1.02_Cracked_SMPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\AppLauncher.v1.003.S60.SymbianOS.Cracked-EViLPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\DVDPlayer_1_24_Symbian_S60_Cracked_By_Bryan.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\Flash_Lite_1.10_Cracked_By_Zibri.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\Killer.Mobile.BlackBaller.v1.12.S60.SymbianOS7.Cracked-BiNPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\XCaller.v1.07.S60.SymbianOS.Incl.Keygen.Patch-BiNPDA
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\XCaller.v1.07.S60.SymbianOS.Incl.Keygen.Patch-BiNPDA\Mobystar.XCaller.v1.07.S60.SymbianOS.Incl.Keygen.Patch-BiNPDA
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\ZenoMorphS60_103F_nopdf\keygen.exe
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\APPLICATIONS\Symbian\Zipman 2.31\wildpalm.zipman.v2.31se.s60.symbianos.cracked-binpda.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Absolutist[1][1].Block.Buster.v1.0.S60.SymbianOS6.SymbianOS7.Cracked-HeXPDA
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\bitrabbit.atomanic.v1.00.s60.symbianos.cracked-binpda.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata.Backgammon.Professional.v1.00.S60.SymbianOS.Cracked-HeXPDA
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata.Checkers.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata[1].Hearts.v1.11.S60.SymbianOS.Cracked-HeXPDA
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata[2].Reversi.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cellcheckers.v1.10.s60.symbianos.cracked-binpda.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Infinite.Dreams.SuperMiners.v1.02.S60.SymbianOS.Cracked-HeXPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\KillerMaze.v0.81.S60.SymbianOS.Cracked-SymBoSS.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Absolutist[1][1].Block.Buster.v1.0.S60.SymbianOS6.SymbianOS7.Cracked-HeXPDA\Block.Buster.v1.0.S60.SymbianOS6.SymbianOS7.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Absolutist[1][1].Block.Buster.v1.0.S60.SymbianOS6.SymbianOS7.Cracked-HeXPDA\HeXPDA.nfo
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata.Backgammon.Professional.v1.00.S60.SymbianOS.Cracked-HeXPDA\Backgammon Professional.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata.Backgammon.Professional.v1.00.S60.SymbianOS.Cracked-HeXPDA\GsBackgammon.app
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata.Backgammon.Professional.v1.00.S60.SymbianOS.Cracked-HeXPDA\HeXPDA.nfo
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata.Checkers.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA\Checkers Professional.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata.Checkers.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA\GsCheckers.app
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata.Checkers.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA\HeXPDA.nfo
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata[1].Hearts.v1.11.S60.SymbianOS.Cracked-HeXPDA\Cascata.Hearts.v1.11.S60.SymbianOS.Cracked-HeXPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata[1].Hearts.v1.11.S60.SymbianOS.Cracked-HeXPDA\Hearts.app
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata[1].Hearts.v1.11.S60.SymbianOS.Cracked-HeXPDA\HeXPDA.nfo
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata[2].Reversi.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA\Cascata.Reversi.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata[2].Reversi.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA\GsReversi.app
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\Cascata[2].Reversi.Professional.v1.01.S60.SymbianOS.Cracked-HeXPDA\HeXPDA.nfo
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\maumau_s60_2_35\Keygen.exe
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads torrent\WR Nokia N70 & N90 Pack\GAMES\Symbian\MGS\MVRPOOL2\MVRPOOL2\keygen.exe
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\giochinokia\ALON.Software.Contact.Guide.v1.02.UIQ.Motorola.AXXX.A1000.SymbianOS.Cracked-SyMPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\giochinokia\aplicaciones\Mp3Player.v1.22\VikingGames.Mp3Player.v1.22.S60.SymbianOS6.Cracked-18plus2.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Vecchia memory nokia\System\install\callcheater60.100.cracked-d3sign.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Vecchia memory nokia\System\install\Killer.Mobile.BlackBaller.v1.12.S60.SymbianOS7.Cracked-BiNPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Vecchia memory nokia\System\install\Plenware.Gina.v1.53.S60.SymbianOS.Cracked-HeXPDA.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Vecchia memory nokia\System\install\sbsh.papyrus.v1.00.9.s60.symbianos7.cracked-binpda.sis
C:\Documents and Settings\Dott.GuidoDelGiudice\Preferiti\Web Fantasy v2 [Download Roms GBA NDS Music Mp3 Crack Final Fantasy Pokemon Yu Gi Oh One Piece Kingdom Hearts Emulatori].url
C:\Documents and Settings\Dott.GuidoDelGiudice\Recent\crack serial number macromedia flash mx 2004 7.2.txt.lnk
C:\Documents and Settings\Dott.GuidoDelGiudice\Recent\[Adobe] - Macromedia Flash 8 Professional(Full) Keygen.rar.lnk
C:\Documents and Settings\Dott.GuidoDelGiudice\Recent\[APP ITA] Macromedia Flash Pro 8 + keygen.rar.lnk


---------------- ! End of report ! ------------------


La connessione wireless continua a darmi: "Impossibile configurare la connessione senza fili"
Attendo istruzioni sul da farsi.
shapiro
Inviato: Monday, June 22, 2009 10:39:28 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ciao delgiud

findykill ha eliminato tantissime infezioni

continuiamo con le eliminazioni

scarica http://downloads1.kaspersky-labs.com/devbuilds/AVPTool/

seleziona la partizione da scansionare e clicca su Scan per avviare la scansione
terminata la scansione, in caso di rilevazione di infezioni, clicca su Neutralize all
si apriranno dei popup dove potrai scegliere se cancellare o disinfettare l'oggetto: metti la spunta su Apply to all e clicca su Quarantine

per salvare il Report che verrà rilasciato, clicca sul tasto Reports - salvalo ed allegalo- fai copia-incolla delle infezioni trovate

Per la wireless vediamo appena finito kaspersky
delgiud
Inviato: Monday, June 22, 2009 11:27:28 AM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Ho bisogno di un pò di tempo perchè Kaspersky è di 40 Mega per cui con la connessione analogica mi ci vorrebbero 4 ore. Devo farmelo scaricare e poi trasferire sul mio pc. Quale partizione devo selezionare? Grazie Shapiro, ci sentiamo appena eseguito il tutto.
shapiro
Inviato: Monday, June 22, 2009 11:36:16 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
seleziona la partizione C:\
delgiud
Inviato: Monday, June 22, 2009 10:33:55 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Niente da fare! Ho scaricato il programma ma quando cerco di farlo partire mi dà "errore di inizializzazione 00000etc.." Ho provato a reinstallarlo ma...niente! Che faccio?
delgiud
Inviato: Tuesday, June 23, 2009 8:01:15 AM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Shapiro, ce l'ho fatta! Ho rifatto la scansione con Findykill e mi ha ripristinato la modalità provvisoria. Da lì sono riuscito ad avviare Kaspersky Virus Removal e ad effettuare la scansione: 160 treath rimossi!
Questo è il report delle infezioni trovate da kaspersky:
Statistics

Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------


Settings

Parameter Value
--------- -----
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes


Quarantine

Status Object Size Added
------ ------ ---- -----


Backup

Status Object Size
------ ------ ----
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1188578.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\bv_image_converter_1.0.zip 862,4 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\ss_britney_spears_screensaver_1.0.zip 911,2 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1315437.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\balinese_souvenirs_1.0.zip 947,8 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1105578.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\zaep 4.1.zip 813,6 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\airxonix_1.35.zip 855,2 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\usingit web content management 1.0.zip 885,7 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\spreadsheetgear_for_.net_2006_2.0.0.49_(crack).zip 845,2 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\650312.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\mcafee.desktop.firewall.v8.5.0.591-dvt==.zip 845 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\mos-exp_-_microsoft_excel_2002_core_practice_test_questions_1.0.zip 991,2 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1258906.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\dscrypt_1.10.zip 877,2 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\monet_morning_1.0_(with_crack).zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\firefly internet phone 3.0.2 build 4776.zip 831,8 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3370796.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\htmlstatictext 1.3.0.0.zip 874,7 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\notepad_mobile_with_notesync_3.1.zip 915,6 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1381812.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\advanced_random_number_and_permutation_generator_1.0_(with_crack).zip 913,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\symantec.pcanywhere.v12.0.german-core.zip 813 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\803531.exe 70 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1151671.exe 70 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3057109.exe 596,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\ghost_hunter_3.0_(patch).zip 986 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\disklogon lite 2.3.zip 964,9 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\nshred 2.2.1027.zip 816,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\csimagefile_6.2.zip 816,2 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\glooton 1.5.1.zip 806,2 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\485078.exe 596,5 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\windows\system32\mdelk.exe 70 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1160062.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\iwrite_1.0.zip 853,5 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3347875.exe 70 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3520171.exe 97 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\windows\system32\wintems.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\da_vinci_encoded_3d_slideshow_screensaver_1.0.zip 838,8 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1811046.exe 596,5 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\2458500.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\patch_creator_2.8_(crack).zip 917,2 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\recentrun_1.5.zip 910,4 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\protalentperformer_deluxe_1.95_[with_crack].zip 828,4 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\swf to gif converter 1.2.zip 817,5 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1185656.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\essential_mortgage_secrets_e-book_1.0_serial.zip 929,9 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\the shortcut - my documents 2.01.zip 867,8 KB
Infected: Trojan program Trojan.Win32.Hrup.a c:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\jozfzg.exe 264,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\password protected lock 2.9.zip 870,3 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\championship_manager_4_retail_patch_1.zip 869,6 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\medjugorje messages 2006.8.zip 892,0 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\787218.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\sfilecopy_0.2.zip 877,0 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\domain finder tools 2.07626.zip 914,9 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1866000.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\command_&_conquer_renegade_-_final_conflict_map.zip 867,9 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\serials.kaspersky.mobile.anti.virus.infos.2006.all.versions.zip 917,1 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\openbook_2.1.zip 981,8 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\qmailfilter_1.2.zip 937,8 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3787296.exe 596,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\armadillo photo media 5.zip 807,3 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\greatnews 1.0 beta build 384.czip 836 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3748265.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\eastsea_html_to_image_converter_2.00_(key).zip 841,6 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3469875.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\raging sky 1.0.zip 888,0 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\mergic_vpn_1.1.zip 987,4 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\loggui_1.0.zip 1010,4 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\826750.exe 596,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\jkfragmenter 1.2.zip 966,9 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\tabview_organizer_1.02.0130.zip 889,9 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\874187.exe 98 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\nature watch screensaver 2.4.zip 890,9 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\898828.exe 596,5 KB
Infected: Trojan program Trojan-Spy.Win32.Agent.akib c:\windows\system32\dllcache\userinit.exe 102,5 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1233437.exe 596,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\dll killer 5.0.1.5.zip 893,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\fontlook 3.7.zip 889,7 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\dsplayer_0.888.zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\cutetype 1.0.0.1.zip 874,9 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\4121125.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\salesmate_+_1.0_(key+serial).zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\anetto_html_candy_2.0_[serial].zip 861,7 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1133687.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\imtoo mpeg to dvd converter 3.0.45.0515.zip 873,3 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\ubiworks sdk 1.1.zip 894,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\kr_web_audio_1.0.zip 887,8 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\4353296.exe 70 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3450906.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\precious_puppies_screensaver_1.0_(crack).zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\iceprojector_1.5.zip 833,0 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\ilovevideoz 4.5.117.zip 852,9 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\4105984.exe 596,5 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1562171.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\gravity lesson screensaver.zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\templab_1.0.0.zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\windows certificate enrollment control vulnerability patch (windows me) 5.131.3659.0.zip 959,8 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\snipergame 1.0.0.0.zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\viscom video edit pro activex control 2.62.zip 878,1 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\file creator 1.02.zip 879,7 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.avs c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\111wfs1intwq.sys 122,5 KB
Infected: Trojan program Trojan-Spy.Win32.Agent.akib c:\windows\system32\config\systemprofile\impostazioni locali\temporary internet files\content.ie5\yw910gpk\lsp[1].exe 102,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\schonbrunn gardens screensaver 3.0.zip 835,7 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\712609.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\greatnews 1.0 beta build 384.zip 800,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\toolbar_button_builder_1.0.zip 903 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1115796.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\office image exporter 1.3.zip 943,0 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1590234.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\dbxpert for oracle 8.0.1.5.zip 1013 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\783156.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\jtg web browser 1.0.0.1.zip 847,0 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\977656.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\hoster 3.321.zip 884 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\687593.exe 66 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\bekey_virtual_(on-screen)_keyboard_1.3.2.11.zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\jpeg_quality_estimator_1.0.zip 826,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\color_planner_2.zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\delphi_form_editor_5.3.zip 878,9 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\432937.exe 596,5 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\4143015.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\winlife 1.0.zip 958,7 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\visnetic antivirus plug-in for visnetic mailserver 4.6.1.3.zip 937,6 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\amphisoft photo detailer 1.1 [key+serial].zip 806,4 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\venice screensaver ev.zip 971,4 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\windows_password_expert_1.2.zip 899,3 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\nitro downloader 3.0.zip 865,7 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\itransfer_2.1.zip 899,4 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\avenger\wintems.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\volumelock 2.1.zip 919,7 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\bg_cd_manager_1.42.zip 843,2 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\kernel_palm_pdb_4.03_[crack].zip 979,6 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\blue_ice_demo.zip 818,1 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\ignition_2.10.0.52.zip 879,3 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\programmi\toshiba\toscdspd\toscdspd.exe 836 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\vibrations 1.1.zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\vnportal toolbar for ie 4.5.131.0.zip 805,2 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\unreal_tournament_2004_blade_skin.zip 1 MB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\searchsites_3.5.zip 833,1 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1084578.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\nevercenter silo 2.0.02.zip 882,7 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\spoofstick for ie and firefox 1.05.zip 958,3 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\m\flec006.exe 97 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\alphabutton_2.2.1.zip 931 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\gigaom_rss_reader_1.0.zip 964,2 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\3272921.exe 97 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1034781.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\exentryc's_junior_3.6.zip 853,5 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\amazon search 1.3.zip 960,6 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\everydaysms_1.1.zip 837,1 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\explore++_1.0.zip 995,1 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\gahnomen 1.5.zip 1003,2 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1003953.exe 97 KB
Infected: virus Email-Worm.Win32.Bagle.of c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\downld\1784687.exe 70 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\documents and settings\dott.guidodelgiudice\dati applicazioni\drivers\winupgro.exe 836 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\free file encryptor 1.0.zip 911,1 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\epractize test lab - free scea practize test 1.0.zip 819,0 KB
Infected: Trojan program Trojan-Downloader.Win32.Bagle.axw c:\avenger\m\shared\medreader_physician_edition_4.zip 1 MB

Ho potuto anche eseguire il log hijack, eccolo:
Logfile of HijackThis v1.99.1
Scan saved at 7.25.52, on 23/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\DOTT~1.GUI\IMPOST~1\Temp\Rar$EX00.954\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB002" /M "Stylus C46"
O4 - HKLM\..\Run: [DataLayer] C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ocgoi] "c:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\ocgoi.exe" ocgoi
O4 - HKCU\..\Run: [iioma] "c:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\iioma.exe" iioma
O4 - HKCU\..\Run: [ANT Agent] C:\Garmin\ANT Agent\ANT Agent.exe
O4 - HKCU\..\Run: [akioy] "c:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\akioy.exe" akioy
O4 - HKCU\..\Run: [kgskksy] "c:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\kgskksy.exe" kgskksy
O4 - HKCU\..\Run: [wmsae] "c:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\wmsae.exe" wmsae
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: is-5O00F.lnk = C:\Documents and Settings\Dott.GuidoDelGiudice\Desktop\Virus Removal Tool\is-5O00F\startup.exe
O4 - Startup: _uninst_.bat
O4 - Startup: _uninst_is-S771U.exe.bat
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download &Flash Movies - C:\Programmi\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2424145-6457-4791-8900-4B70DA9EA85B}: NameServer = 151.99.125.2
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Servizio di Google Update (gupdate1c9e237b8b5021e) (gupdate1c9e237b8b5021e) - Unknown owner - C:\Programmi\Google\Update\GoogleUpdate.exe" /svc (file missing)
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Programmi\Java\jre6\bin\jqs.exe" -service -config "C:\Programmi\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

Ora la connessione wireless funziona. Che ne pensi?
shapiro
Inviato: Tuesday, June 23, 2009 9:52:12 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
hai cliccato su Neutralize durante la ricerca delle infezioni?


SCARICA http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe


Riavvia il computer in modalità provvisoria: all'avvio del pc, prima che inizi a caricare Windows, premi ripetutamente F8. Uscirà la finestra del menu Opzioni avanzate di Windows => scegli modalità provvisoria (usa il tasto freccia ^).

Esegui Navilog1 e scegli l'opzione 2 (Automatic Cleaning) e dai l'ok

Quando finisce posta il log che trovi in C:\ come cleannavi.txt
delgiud
Inviato: Tuesday, June 23, 2009 4:30:46 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
No, temo di non aver cliccato su neutralize. Finita la scansione ho fatto Delete x tutti i file infetti trovati, tranne userinit.exe, perchè ricordavo che, in un'altra occasione, cancellandolo, non mi partiva più windows.
Ecco il log di Navilog:
Navipromo Removal version 3.7.0 started on 23/06/2009 at 16.19.29,00

Fix running from C:\Programmi\navilog1

Updated on 10.12.2008 at 21h00 by IL-MAFIOSO

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) M processor 1.40GHz )
BIOS : Ver 1.00PARTTBL
USER : Dott.GuidoDelGiudice ( Administrator )
BOOT : Fail-safe boot




C:\ (Local Disk) - NTFS - Total:37 Go (Free:10 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)


Automatic removal
with Catchme and GNS results


Cleanning stage done in safe mode


*** fsbl1.txt not found ***
(Check that Catchme found nothing in Search Mode)


*** Deleting with Backups GenericNaviSearch results ***

* Deletion in "C:\WINDOWS\System32" *


* Deletion in "C:\Documents and Settings\Dott.GuidoDelGiudice\impost~1\datiap~1" *


* Deletion in "C:\DOCUME~1\ADMINI~1\impost~1\datiap~1" *


*** Deleting folders in "C:\WINDOWS" ***


*** Deleting folders in "C:\Programmi" ***


*** Deleting folders in "C:\Documents and Settings\All Users\menuav~1\progra~1" ***


*** Deleting folders in "C:\Documents and Settings\All Users\menuav~1" ***


*** Deleting folders in "c:\docume~1\alluse~1\datiap~1" ***


*** Deleting folders in "C:\Documents and Settings\Dott.GuidoDelGiudice\datiap~1" ***


*** Deleting folders in "C:\DOCUME~1\ADMINI~1\datiap~1" ***


*** Deleting folders in "C:\Documents and Settings\Dott.GuidoDelGiudice\impost~1\datiap~1" ***


*** Deleting folders in "C:\DOCUME~1\ADMINI~1\impost~1\datiap~1" ***


*** Deleting folders in "C:\Documents and Settings\Dott.GuidoDelGiudice\menuav~1\progra~1" ***


*** Deleting folders in "C:\DOCUME~1\ADMINI~1\menuav~1\progra~1" ***



*** Deleting files ***


*** Deleting temporary files ***

Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Dott.GuidoDelGiudice\impost~1\Temp done !

*** Complementary Search ***
(Search specific files)

1)Deletion with backups new Instant Access files:

2)Heuristic search and deletion with backups :


* In "C:\WINDOWS\system32" *



* In "C:\Documents and Settings\Dott.GuidoDelGiudice\impost~1\datiap~1" *


jozfzg.dat found !
Copy jozfzg.dat done !
jozfzg.dat deleted !

jozfzg_nav.dat found !
Copy jozfzg_nav.dat done !
jozfzg_nav.dat deleted !

jozfzg_navps.dat found !
Copy jozfzg_navps.dat done !
jozfzg_navps.dat deleted !


* In "C:\DOCUME~1\ADMINI~1\impost~1\datiap~1" *



*** Copy Registry to Safebackup folder ***

Backing up Registry done !

*** Cleaning Registry ***

Registry cleaned


*** Certificates ***

Egroup Certificate not found !
Electronic-Group Certificate deleted !
Montorgueil Certificate not found !
OOO-Favorit Certificate deleted !
Sunny-Day-Design-Ltd Certificate not found !

*** Search others known folders and files ***

C:\WINDOWS\system32\twxyxyxx.ini2 found ! Possible Vundo infection, not cleaned with this tool !
C:\WINDOWS\system32\uDefNUtv.ini2 found ! Possible Vundo infection, not cleaned with this tool !


*** Cleaning stage complete on 23/06/2009 at 16.20.13,71 ***

shapiro
Inviato: Tuesday, June 23, 2009 5:33:10 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ci sono dei file che navilog non ha eliminato o non sono piu' nel tuo pc

per maggior sicurezza fai una scansione con Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
(non installare la recovery console)
Lascia lavorare il programma senza interferire
Allega il rapporto C:\ComboFix.txt nella tua risposta

hai notato se si aprono pagine pubblicitarie?


delgiud
Inviato: Tuesday, June 23, 2009 6:15:11 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
No, non si apre nessuna pagina pubblicitaria.
Ecco il Combofix:
ComboFix 09-06-22.0D - Dott.GuidoDelGiudice 23/06/2009 17.45.44.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.502.205 [GMT 2:00]
Eseguito da: c:\programmi\ComboFix.exe

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\m
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\11s11ro1s1a2.sys
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1055500.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1062171.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1064375.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1066703.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1068312.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1070906.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1071125.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1076312.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1077937.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1078187.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1079953.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1085140.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1087125.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1087296.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1090171.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1108312.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1120421.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1130203.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1131625.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1276359.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1285515.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1288921.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1298140.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1300781.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1301640.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1356156.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1358875.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1359593.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1425171.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1465390.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1474453.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1484578.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1513656.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1530437.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1550062.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1551984.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1552062.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1569343.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1571078.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1571203.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1736046.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1745078.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1745171.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1755203.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1755500.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1756796.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1757078.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1765828.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1766718.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1773484.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1776390.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1777734.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1779000.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1782156.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1783203.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1786812.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1787750.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1787859.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1806609.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1810031.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1810312.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1874468.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1878781.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1879140.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1880406.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1882593.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\1882875.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2060203.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2061390.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2061500.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2070984.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2073562.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2073593.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2312140.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2313687.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2313781.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2441968.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2479890.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2482093.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2482406.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2483328.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2484843.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\2485125.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3390265.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3407000.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3412687.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3416625.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3427421.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3433750.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3440484.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3442062.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3442203.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3500796.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3502546.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3516859.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3696437.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3699015.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3699046.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3704250.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3705765.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3706015.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3712859.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3714828.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3714953.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3736187.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3740265.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3744687.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3746171.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3762109.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3763859.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\3764437.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4018312.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4019625.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4019687.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4027843.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4029187.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4029265.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4153500.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4156203.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4160859.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4161968.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4165109.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4166671.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4236390.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4240812.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4241000.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4371281.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4374765.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4375593.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4376875.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4379640.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\4379843.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\728656.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\737312.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\740437.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\744328.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\755218.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\761625.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\768140.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\769953.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers\downld\770406.exe
c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\AntivirusXP.lnk
c:\windows\system32\senekacrhnrvam.dat
c:\windows\system32\senekampucblxs.dat
c:\windows\system32\test.ttt
c:\windows\system32\twxyxyxx.ini
c:\windows\system32\twxyxyxx.ini2
c:\windows\system32\uDefNUtv.ini
c:\windows\system32\uDefNUtv.ini2
c:\windows\system32\win32hlp.cnf
c:\windows\Tasks\pzznanbs.job
c:\windows\ufdata2000.log

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_111111S1RO1S1A
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
-------\Service_seneka


((((((((((((((((((((((((( Files Creati Da 2009-05-23 al 2009-06-23 )))))))))))))))))))))))))))))))))))
.

2009-06-23 15:43 . 2009-06-23 15:42 3039024 ----a-r- c:\programmi\ComboFix.exe
2009-06-22 21:57 . 2008-07-08 12:54 148496 ----a-w- c:\windows\system32\drivers\79993412.sys
2009-06-22 19:58 . 2009-06-22 19:59 42315312 ----a-w- c:\programmi\setup_7.0.0.290_22.06.2009_22-58.exe
2009-06-22 07:51 . 2009-06-22 20:56 -------- d-----w- c:\programmi\FindyKill
2009-06-22 07:51 . 2009-06-22 07:51 517009 ----a-w- c:\programmi\FindyKill.exe
2009-06-21 22:14 . 2009-06-21 22:14 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-06-21 22:11 . 2009-06-21 22:11 -------- d-----w- c:\programmi\spybotsd152
2009-06-21 20:24 . 2009-06-21 20:24 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
2009-06-21 17:50 . 2009-06-23 15:51 -------- d--h--w- c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\drivers
2009-06-21 07:37 . 2009-06-21 07:37 -------- d-----w- c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\dvdcss
2009-06-21 07:35 . 2009-06-21 07:37 -------- d-----w- c:\programmi\DVDSmith Movie Backup
2009-06-21 07:34 . 2009-06-21 07:34 2034448 ----a-w- c:\programmi\dvdsmith-movie-backup.exe
2009-06-17 17:36 . 2009-06-17 17:36 1915520 ----a-w- c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-06-05 22:12 . 2009-06-05 22:12 -------- d-----w- c:\programmi\Garmin GPS Plugin
2009-06-05 19:47 . 2009-06-05 19:47 -------- d-----w- c:\programmi\DIFX
2009-06-05 19:47 . 2009-06-05 19:48 -------- d-----w- c:\programmi\Garmin
2009-05-31 21:35 . 2009-05-31 21:35 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Google
2009-05-30 22:26 . 2009-05-30 22:27 -------- d-----w- c:\programmi\eMule AdunanzA
2009-05-30 08:24 . 2009-05-30 08:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\GARMIN
2009-05-29 12:21 . 2009-05-30 08:24 -------- d-----w- c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\GARMIN
2009-05-29 12:19 . 2007-09-06 13:53 18944 ----a-w- c:\windows\system32\drivers\SiLib.sys
2009-05-29 12:19 . 2007-09-06 13:53 14848 ----a-w- c:\windows\system32\drivers\DSI_SiUSBXp_3_1.sys
2009-05-29 12:19 . 2009-05-29 12:19 -------- dc----w- C:\Garmin
2009-05-27 21:15 . 2009-05-27 21:15 -------- d-----w- c:\programmi\NCH Swift Sound

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-23 16:06 . 2009-02-26 21:15 17248288 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-23 16:02 . 2009-02-26 21:15 201644 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-23 14:20 . 2008-12-12 21:26 -------- d-----w- c:\programmi\Navilog1
2009-06-23 05:31 . 2006-03-02 12:00 48766 ----a-w- c:\windows\system32\perfc010.dat
2009-06-23 05:31 . 2006-03-02 12:00 348104 ----a-w- c:\windows\system32\perfh010.dat
2009-06-23 02:14 . 2009-02-17 09:43 104960 ----a-w- c:\windows\system32\userinit.exe
2009-06-22 05:26 . 2008-07-14 10:28 1234712 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgtray.exe
2009-06-22 05:26 . 2008-07-14 10:28 231192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgwdsvc.exe
2009-06-22 05:26 . 2008-07-14 10:28 873752 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgemc.exe
2009-06-22 05:26 . 2008-07-14 10:28 311576 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgrsx.exe
2009-06-21 23:41 . 2008-05-19 15:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-06-21 22:14 . 2009-02-18 23:02 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-06-21 18:18 . 2009-06-21 18:40 172182 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1040.dat
2009-06-21 08:36 . 2008-05-22 09:03 -------- d-----w- c:\programmi\eMule
2009-06-15 16:41 . 2008-05-20 21:33 -------- d-----w- c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\CoreFTP
2009-05-31 21:37 . 2008-12-20 18:45 -------- d-----w- c:\programmi\Google
2009-05-30 22:30 . 2008-05-20 21:39 -------- d-----w- c:\programmi\AdunanzA
2009-05-15 19:13 . 2009-05-15 14:21 -------- d-----w- c:\programmi\NCH Software
2009-05-15 14:22 . 2009-05-15 14:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NCH Software
2009-05-15 14:21 . 2009-05-15 14:21 -------- d-----w- c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\NCH Software
2009-05-15 14:21 . 2009-05-15 14:20 453264 ----a-w- c:\programmi\debutsetup.exe
2009-05-15 13:24 . 2009-05-15 13:24 -------- d-----w- c:\programmi\Trust
2009-05-15 13:24 . 2008-05-19 14:19 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-03-31 19:15 . 2009-03-31 19:15 152576 ----a-w- c:\documents and settings\Dott.GuidoDelGiudice\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-02-18 22:41 . 2009-02-18 22:41 9694356 ----a-w- c:\programmi\spybotsd152.zip
2008-12-13 14:24 . 2008-12-13 14:23 724952 ----a-w- c:\programmi\avenger.zip
2008-12-12 22:06 . 2008-12-12 22:06 2539400 ----a-w- c:\programmi\mbam-setup.exe
2008-12-12 21:25 . 2008-12-12 21:25 576862 ----a-w- c:\programmi\Navilog1.exe
2008-12-11 09:40 . 2008-12-11 09:40 4530016 ----a-w- c:\programmi\isobuster_all_lang.exe
2008-09-15 08:26 . 2008-09-15 08:26 2801569 ----a-w- c:\programmi\DeepBurner1.exe
2008-09-11 12:59 . 2008-09-11 12:59 29962241 ----a-w- c:\programmi\SUPERsetup.exe
2008-09-10 09:01 . 2008-09-10 09:00 4960294 ----a-w- c:\programmi\RivaEncoderSetup.exe
2008-06-23 19:40 . 2008-06-23 19:40 59839784 ----a-w- c:\programmi\iTunesSetup.exe
2008-06-12 10:03 . 2008-06-12 10:03 15951256 ----a-w- c:\programmi\java.exe
2008-06-04 11:07 . 2008-06-04 11:06 28979464 ----a-w- c:\programmi\FileFormatConverters.exe
2008-05-12 10:14 . 2008-06-04 22:15 1175282 ----a-w- c:\programmi\fhsetup.exe
2008-05-12 09:57 . 2008-06-04 22:16 1244944 ----a-w- c:\programmi\FlashCatcher.exe
2008-04-14 10:32 . 2008-05-20 22:09 984832 ----a-w- c:\programmi\Pdf Password Remover 2.5 Crack.rar
2008-04-10 13:57 . 2008-05-20 22:15 3558791 ----a-w- c:\programmi\youtubedownloader.exe
2007-12-06 08:45 . 2008-05-20 22:07 1232943 ----a-w- c:\programmi\install_textsoap.exe
2006-06-20 10:07 . 2008-08-01 14:53 13999801 ----a-w- c:\programmi\movieconverter.exe
2005-11-04 09:59 . 2008-05-20 22:08 1382485 ----a-w- c:\programmi\jpegoptimizer.exe
2004-11-10 08:32 . 2008-05-20 22:15 2421920 ----a-w- c:\programmi\winzip90.exe
2004-03-30 23:32 . 2008-05-20 22:14 86016 ----a-w- c:\programmi\txtclean.exe
.

------- Sigcheck -------

[-] 2008-04-14 02:14 26624 DF69726907357C3ADD243F48902B0331 c:\windows\SoftwareDistribution\Download\8dab4f2c899f11c2863dff51dfb836e7\userinit.exe
[-] 2009-06-23 02:14 104960 13A3D30F7E9FAC9B41D0F930B5A185D9 c:\windows\system32\userinit.exe

.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
"ANT Agent"="c:\garmin\ANT Agent\ANT Agent.exe" [2009-05-21 11026008]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-06-21 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="c:\programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-12-23 28672]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-28 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-28 126976]
"Acrobat Assistant 7.0"="c:\programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2007-04-27 282624]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2007-06-28 270648]
"ISUSPM Startup"="c:\progra~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"EPSON Stylus C46 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE" [2004-01-13 99840]
"DataLayer"="c:\programmi\File comuni\PCSuite\DataLayer\DataLayer.exe" [2005-09-06 820736]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 176128]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"TFncKy"="TFncKy.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-04-28 88363]
"NDSTray.exe"="NDSTray.exe" [BU]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-19 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Acrobat.lnk - c:\windows\Installer\{AC76BA86-1034-4700-7760-000000000002}\SC_Acrobat.exe [2008-5-20 25214]
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
BTTray.lnk - c:\programmi\WIDCOMM\Software Bluetooth\BTTray.exe [2005-9-16 610365]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2008-5-19 155648]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=

R1 is-5O00Fdrv;is-5O00Fdrv;c:\windows\system32\drivers\79993412.sys [22/06/2009 23.57.34 148496]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [19/05/2008 16.22.27 57408]
S2 gupdate1c9e237b8b5021e;Servizio di Google Update (gupdate1c9e237b8b5021e);c:\programmi\Google\Update\GoogleUpdate.exe [31/05/2009 23.35.28 133104]
S2 osrtvsmr;osrtvsmr;\??\c:\windows\system32\drivers\osrtvsmr.sys --> c:\windows\system32\drivers\osrtvsmr.sys [?]
S3 SDVC05;USB SDVC05;c:\windows\system32\drivers\SDVC05.sys [09/09/2008 16.35.26 18088]
.
Contenuto della cartella 'Scheduled Tasks'

2009-06-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-05-31 21:35]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe
HKLM-Run-NBKeyScan - c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe


.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti nel file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download &Flash Movies - c:\programmi\Flash2X\Flash Hunter\save.htm
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {E2424145-6457-4791-8900-4B70DA9EA85B} = 151.99.125.2
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\programmi\CoreFTP\pftpns.dll
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-23 18:04
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(1996)
c:\programmi\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
c:\programmi\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\system32\rundll32.exe
c:\programmi\WIDCOMM\Software Bluetooth\BTStackServer.exe
c:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2009-06-23 18.11.23 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-06-23 16:11

Pre-Run: 11.137.646.592 byte disponibili
Post-Run: 11.109.302.272 byte disponibili

364 --- E O F --- 2009-06-23 05:33
shapiro
Inviato: Tuesday, June 23, 2009 6:31:08 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
Scarica Avenger

http://swandog46.geekstogo.com/avenger.zip

Estrailo in una cartella a tua scelta
Esegui il file avenger.exe
Ora incolla queste righe nella box bianca che si è aperta:


files to delete:
c:\windows\system32\drivers\79993412.sys
c:\windows\system32\drivers\osrtvsmr.sys




Togli il segno di spunta dalla voce Scan for Rootkits
Premi il pulsante Execute
Rispondi di Si alle due richieste di Avenger
Adesso il tuo computer dovrebbe riavviarsi, nel caso non succedesse, riavvialo tu manualmente
Al riavvio del computer, copia e incolla qui il contenuto del blocco note che apparirà.
delgiud
Inviato: Tuesday, June 23, 2009 6:43:40 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File "c:\windows\system32\drivers\79993412.sys" deleted successfully.

Error: file "c:\windows\system32\drivers\osrtvsmr.sys" not found!
Deletion of file "c:\windows\system32\drivers\osrtvsmr.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.
shapiro
Inviato: Tuesday, June 23, 2009 8:51:28 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
prova a reinstallare il tuo antivirus

disinstalla ComboFix in questa maniera:

Start\esegui

nella casella di dlialogo copia ed incolla questo comando: combofix /u


2) vai in Disco Locale C: ed elimina la cartella QooBox

3) elimina l'eventuale cartella che avevi creato sul Desktop in cui avevi posizionato Combofix.


Apri la lista dei Servizi
Start > Esegui >digitate SERVICES.MSC >Ok ed abilita, dove è necessario, questi servizi disabilitati: Avvisi, Centro sicurezza PC, Aggiornamenti automatici, Connessioni di rete, Zero Configuration reti senza fili e Windows Firewall/ Condivisione connessione Internet (ICS). (Per avviare un servizio, clic con il tasto destro su Proprietà >Automatico > Ok > Avvia > Ok).


scarica http://www.filehippo.com/download_ccleaner/

1) per il download dell'ultima versione clicca a destra in alto sotto la freccia verde
2) installalo (senza la toolbar aggiuntiva)
3) clicca su "avvia pulizia", ripeti il procedimento 2 volte

poi


scarica http://www.atribune.org/ccount/click.php?id=1


Avvia ATFCleaner.exe con un doppio click

1.1) seleziona la casella Select All
2.1) clicca sul pulsante Empty selected
3.1) aspetta l'avviso Done Cleaning
(se usi opera o firefox,spunta anche le loro sezioni)



Fai una nuova scansione con Malwarebytes http://www.malwarebytes.org/mbam/program/mbam-setup.exe
1) lo installi
2) lo aggiorni
3) fai una scansione scegliendo la modalità completa
4) NON eliminare per ora le ventuali minacce che rileva
5) finita la scansione seleziona il tabellino log, apri il file di testo e postalo sul forum


Finite queste operazioni, posta un log di hjt




delgiud
Inviato: Wednesday, June 24, 2009 12:47:52 AM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Tutto fatto! Ecco il log di mbam:
Malwarebytes' Anti-Malware 1.38
Versione del database: 2325
Windows 5.1.2600 Service Pack 2

24/06/2009 0.41.41
mbam-log-2009-06-24 (00-41-32).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 151285
Tempo trascorso: 59 minute(s), 20 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 1
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> No action taken.

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)

Ed ecco il log Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 0.47.30, on 24/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Garmin\ANT Agent\ANT Agent.exe
C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\WIDCOMM\SOFTWA~1\BTSTAC~1.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\internet explorer\iexplore.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\DOTT~1.GUI\IMPOST~1\Temp\Rar$EX00.562\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB002" /M "Stylus C46"
O4 - HKLM\..\Run: [DataLayer] C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ANT Agent] C:\Garmin\ANT Agent\ANT Agent.exe
O4 - Startup: is-5O00F.lnk = C:\Documents and Settings\Dott.GuidoDelGiudice\Desktop\Virus Removal Tool\is-5O00F\startup.exe
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download &Flash Movies - C:\Programmi\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2424145-6457-4791-8900-4B70DA9EA85B}: NameServer = 151.99.125.2
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Servizio di Google Update (gupdate1c9e237b8b5021e) (gupdate1c9e237b8b5021e) - Unknown owner - C:\Programmi\Google\Update\GoogleUpdate.exe" /svc (file missing)
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Programmi\Java\jre6\bin\jqs.exe" -service -config "C:\Programmi\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

shapiro
Inviato: Wednesday, June 24, 2009 10:34:30 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
riavvia malwarebytes e togli quell'infezione

apri hjt ed elimina

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

sai dirmi ora il pc come va'?
delgiud
Inviato: Wednesday, June 24, 2009 11:37:57 AM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Fatto! Il pc ora funziona bene. Per la verità, nonostante l'infezione, a parte la wireless bloccata, ha sempre continuato a funzionare.
Devo fare altro? Posso riattivare il ripristino? Mi conviene riattivare spybot?
shapiro
Inviato: Wednesday, June 24, 2009 11:39:55 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ti consiglio di fare una nuova installazione di spybot, tenuto conto dell'infezione che hai avuto

riattiva il ripristino e installa il tuo antivirus(se non lo hai gia' fatto)
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.