Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Problemi con invio fax e apertura lenta Opzioni
fmancini
Inviato: Saturday, June 19, 2010 6:55:43 PM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
eccomi con 2 nuovi problemi:
FAX-Ho il modem PCI Soft V 92 vers.2.0.19.0 Speakerphone della Conexant ed inviavo fax.Ho nel frattempo inserito il modem Alice gate voip 2 plus wi-fi con ADSL e non riesco più da inviare i fax nè con Fax talk Communicator nè con la console di Windows:viene effettuata la composizione del numero ma dopo alcuni squilli e i tre tentativi da me impostati il fax diventa inattivo( e cade la linea?)e il fax non parte.

APERTURA LENTA-Forse ho troppi programmi in apertura??

Penso sia utile per gli esperti che mi vorranno aiutare l'invio del log di HijackThis e l'elenco dei programmi in apertura.

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 18.17.33, on 19/06/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\nvsvc32.exe
C:\windows\system32\svchost.exe
C:\Programmi\Windows Defender\MsMpEng.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programmi\AskBarDis\bar\bin\AskService.exe
C:\Programmi\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Common Files\Motive\McciCMService.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
C:\WINDOWS\system32\PSIService.exe
C:\windows\system32\Returnil\RVS3\rvsmon.exe
C:\Programmi\Photodex\ProShowGold\ScsiAccess.exe
C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\system32\svchost.exe
C:\Programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\Programmi\Avira\AntiVir Desktop\avmailc.exe
C:\Programmi\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\windows\system32\fxssvc.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\Lavasoft\Ad-Aware\AAWService.exe
C:\Programmi\Lavasoft\Ad-Aware\AAWTray.exe
C:\windows\Dit.exe
C:\windows\system32\RUNDLL32.EXE
C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~3.EXE
C:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
C:\Programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\windows\system32\hphmon05.exe
C:\Programmi\RocketDock\RocketDock.exe
C:\Programmi\Restore Desktop\RestoreDesktop.exe
C:\windows\system32\ctfmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programmi\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
C:\Programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
C:\Programmi\Windows Live\Messenger\msnmsgr.exe
C:\Programmi\Windows Live\Contacts\wlcomm.exe
C:\Programmi\FaxTalk Communicator\FTCtrl32.exe
C:\Programmi\FaxTalk Communicator\FAPIEXE.EXE
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\IObit\Advanced SystemCare 3\AWC.exe
C:\Programmi\HP\hpcoretech\comp\hpdarc.exe
C:\windows\explorer.exe
C:\Programmi\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mirarsearch.com/?useie5=1&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66008
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66008
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mirarsearch.com/?useie5=1&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Messenger Plus Live Italy Toolbar - {08d495ab-a86c-47b0-82ef-da87bf92f730} - C:\Programmi\Messenger_Plus_Live_Italy\tbMes0.dll
O2 - BHO: Messenger Plus Live Italy Toolbar - {08d495ab-a86c-47b0-82ef-da87bf92f730} - C:\Programmi\Messenger_Plus_Live_Italy\tbMes0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Programmi\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programmi\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Programmi\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O3 - Toolbar: Mirar - {701436C2-A36F-40FF-8009-866EB98ABB85} - (no file)
O3 - Toolbar: Messenger Plus Live Italy Toolbar - {08d495ab-a86c-47b0-82ef-da87bf92f730} - C:\Programmi\Messenger_Plus_Live_Italy\tbMes0.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CICache] CICache.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [AliceRE_McciTrayApp] C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~3.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\windows\system32\hphmon05.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [RocketDock] "C:\Programmi\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [RestoreDesktop] C:\Programmi\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
O4 - HKCU\..\Run: [SmartRAM] "C:\Programmi\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Policies\Explorer\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - Global Startup: WDDMStatus.lnk = C:\Programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O4 - Global Startup: WDSmartWare.lnk = C:\Programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Programmi\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Check &Spelling - res://C:\Programmi\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Programmi\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Programmi\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Programmi\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Programmi\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Programmi\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Programmi\ieSpell\iespell.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
O16 - DPF: {4EC99A0B-E57C-4FBE-B9C4-8428424FBF88} (McciUtilsSpecialFolder Class) - http://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {528BF874-2681-4CE3-8C62-AA0D3BC0A719} (McciSysSCM Class) - http://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
O16 - DPF: {5AF01DCD-8539-4814-9693-ADF47058F075} (ReportReader Class) - http://aiuto.alice.it/ata/static/installers/WebflowActiveXInstaller_4-1-5.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) - http://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{154CF1E7-118E-4EE7-BFF7-6DC81998C56B}: NameServer = 85.37.17.8 85.38.28.73
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\windows\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Programmi\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Programmi\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Google Update Service (gupdate1c98a061b8f7796) (gupdate1c98a061b8f7796) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Programmi\Common Files\Motive\McciCMService.exe
O23 - Service: Network WanMiniport First Position - Unknown owner - C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Returnil Virtual System Core Service (RVSMONBL) - CJSC Returnil Software - C:\windows\system32\Returnil\RVS3\rvsmon.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Programmi\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: ServiceLayer - Nokia - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe

--
End of file - 14915 bytes


Programma File Posizione fisica Valore Dati
Adobe Acrobat C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run Adobe Reader Speed Launcher "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe Reader and Acrobat Manager C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run Adobe ARM "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
AliceRE_McciTrayApp C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~3.EXE HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run AliceRE_McciTrayApp C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~3.EXE
AntiVir Desktop C:\Programmi\Avira\AntiVir Desktop\avgnt.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run avgnt "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
CICache C:\windows\CICache.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run CICache CICache.exe
Customized Icon and Label C:\windows\Dit.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run Dit Dit.exe
GoogleToolbarNotifier C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe HKEY_CURRENT_USER\Software\MicroSoft\Windows\CurrentVersion\Run swg "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
Hewlett-Packard hpwuSchd C:\Programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run HP Software Update "C:\Programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
hp coretech (COmponent REuse TECHnology) C:\Programmi\HP\hpcoretech\hpcmpmgr.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run HP Component Manager "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
HP DeskJet C:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run HPDJ Taskbar Utility C:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
HP Photosmart C:\Programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run HPHUPD05 C:\Programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
HP Photosmart C:\windows\system32\hphmon05.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run HPHmon05 C:\windows\system32\hphmon05.exe
Kanex RestoreDesktop C:\Programmi\Restore Desktop\RestoreDesktop.exe HKEY_CURRENT_USER\Software\MicroSoft\Windows\CurrentVersion\Run RestoreDesktop C:\Programmi\Restore Desktop\RestoreDesktop.exe
Microsoft® Windows® Operating System C:\windows\system32\ctfmon.exe HKEY_CURRENT_USER\Software\MicroSoft\Windows\CurrentVersion\Run ctfmon.exe C:\windows\system32\ctfmon.exe
Nero BackItUp Scheduler C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe HKEY_CURRENT_USER\Software\MicroSoft\Windows\CurrentVersion\Run NBJ "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
NVIDIA Compatible Windows 2000 Display driver, Version 197.45 C:\windows\system32\NvCpl.dll HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run NvCplDaemon RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
NVIDIA Media Center Library C:\windows\system32\NvMcTray.dll HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run NvMediaCenter RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit
nwiz nwiz.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run nwiz nwiz.exe /installquiet
QuickTime C:\Programmi\QuickTime\qttask.exe HKEY_LOCAL_MACHINE\Software\MicroSoft\Windows\CurrentVersion\Run QuickTime Task "C:\Programmi\QuickTime\qttask.exe" -atboottime
RocketDock C:\Programmi\RocketDock\RocketDock.exe HKEY_CURRENT_USER\Software\MicroSoft\Windows\CurrentVersion\Run RocketDock "C:\Programmi\RocketDock\RocketDock.exe"
SmartRAM C:\Programmi\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe HKEY_CURRENT_USER\Software\MicroSoft\Windows\CurrentVersion\Run SmartRAM "C:\Programmi\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m
WD Drive Manager C:\Programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\WDDMStatus.lnk N/D N/D
WD SmartWare C:\Programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\WDSmartWare.lnk N/D N/D
Vi ringrazio molto se vi spiegherete in termini adatti a me..poco esperto!!!
ciao
Sponsor
Inviato: Saturday, June 19, 2010 6:55:43 PM

 
cbbusto
Inviato: Saturday, June 19, 2010 10:05:14 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Per i fax hai controllato nelle proprietà del modem che sia deselezionata la casella...Attendi il segnale prima
di comporre il numero ?


Nel log di HJ ci sono diversi file sospetti, comunque attendi l'esperto che ti spiega cosa fare.
Nel frattempo scarica Malwarebytes, da aiutamici, lo installi, aggiornalo e fai una scansione completa, posta il log.
Di programmi in avvio ne hai una montagna, lascia solo l'antivirus e quelli di Nvidia, gli altri li puoi eliminare.
fmancini
Inviato: Sunday, June 20, 2010 8:41:54 AM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
grazie e resto in attesa di ulteriori istruzioni:intanto allego il log di Malwarebytes
ciao
Malwarebytes' Anti-Malware 1.43
Versione del database: 3482
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

20/06/2010 0.03.15
mbam-log-2010-06-20 (00-03-15).txt

Tipo di scansione: Scansione rapida
Elementi scansionati: 114662
Tempo trascorso: 26 minute(s), 31 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)
fmancini
Inviato: Sunday, June 20, 2010 9:14:26 AM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
La casella Attendi il segnale....era selezionata ed ora l'ho disattivata e intanto allego il log del modem:
06-20-2010 08:28:05.546 - File: C:\windows\system32\drivers\modem.sys, Versione 5.1.2600
06-20-2010 08:28:05.593 - File: C:\windows\system32\modemui.dll, Versione 5.1.2600
06-20-2010 08:28:06.093 - File: C:\windows\system32\mdminst.dll, Versione 5.1.2600
06-20-2010 08:28:06.093 - Tipo di modem: PCI SoftV92 Speakerphone Modem
06-20-2010 08:28:06.093 - Percorso informazioni sul modem: oem66.inf
06-20-2010 08:28:06.093 - Sezione informazioni sul modem: Modem1
06-20-2010 08:28:06.093 - Corrispondenza ID hardware: pci\ven_14f1&dev_2f00&subsys_200414f1
06-20-2010 08:28:06.437 - 115200,8,N,1, ctsfl=1, rtsctl=2
06-20-2010 08:28:06.437 - Inizializzazione modem in corso.
06-20-2010 08:28:06.437 - Il livello del segnale DSR è basso durante l'inizializzazione del modem. Verificare che il modem sia acceso.
06-20-2010 08:28:06.437 - Invio: AT<cr>
06-20-2010 08:28:06.437 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.437 - risposta interpretata: OK
06-20-2010 08:28:06.453 - Invio: AT&FE0V1S0=0&C1&D2+MR=2;+DR=1;+ER=1;W2<cr>
06-20-2010 08:28:06.593 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.593 - risposta interpretata: OK
06-20-2010 08:28:06.609 - Invio: ATS7=60S30=26L1M1+ES=3,0,2;+DS=3;+DS44=3;+IFC=2,2;X4<cr>
06-20-2010 08:28:06.609 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.609 - risposta interpretata: OK
06-20-2010 08:28:06.609 - Invio comandi di inizializzazione utente in corso.
06-20-2010 08:28:06.625 - Invio: atx&f1x3<cr>
06-20-2010 08:28:06.765 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.765 - risposta interpretata: OK
06-20-2010 08:28:06.765 - In attesa di una chiamata.
06-20-2010 08:28:06.781 - Invio: ATS0=0<cr>
06-20-2010 08:28:06.781 - Ricezione: ATS0=0<cr>
06-20-2010 08:28:06.781 - Echo comandi
06-20-2010 08:28:06.781 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.781 - risposta interpretata: OK
06-20-2010 08:56:40.500 - Passthrough attivo
06-20-2010 08:56:42.906 - Passthrough inattivo
06-20-2010 08:56:42.906 - 115200,8,N,1, ctsfl=1, rtsctl=2
06-20-2010 08:56:42.906 - Inizializzazione modem in corso.
06-20-2010 08:56:42.906 - Il livello del segnale DSR è basso durante l'inizializzazione del modem. Verificare che il modem sia acceso.
06-20-2010 08:56:42.906 - Invio: AT<cr>
06-20-2010 08:56:42.906 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:42.906 - risposta interpretata: OK
06-20-2010 08:56:42.921 - Invio: AT&FE0V1S0=0&C1&D2+MR=2;+DR=1;+ER=1;W2<cr>
06-20-2010 08:56:43.062 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:43.062 - risposta interpretata: OK
06-20-2010 08:56:43.078 - Invio: ATS7=60S30=26L1M1+ES=3,0,2;+DS=3;+DS44=3;+IFC=2,2;X4<cr>
06-20-2010 08:56:43.078 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:43.078 - risposta interpretata: OK
06-20-2010 08:56:43.078 - Invio comandi di inizializzazione utente in corso.
06-20-2010 08:56:43.093 - Invio: atx&f1x3<cr>
06-20-2010 08:56:43.234 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:43.234 - risposta interpretata: OK
06-20-2010 08:56:43.234 - In attesa di una chiamata.
06-20-2010 08:56:43.250 - Invio: ATS0=0<cr>
06-20-2010 08:56:43.250 - Ricezione: ATS0=0<cr>
06-20-2010 08:56:43.250 - Echo comandi
06-20-2010 08:56:43.250 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:43.250 - risposta interpretata: OK
Inoltre l'opzione Modem e telefono dice che il modem PC software V92 ecc... è collegato alla porta COM 3 ma nella gestione periferiche,porte COM e LPT mi compare solo la porta COM 1 e LPT Stampante ECP.Cosa succede?Grazie infinite
fmancini
Inviato: Monday, June 21, 2010 9:47:46 AM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
allego il log del modem PC Soft V92..col quale non riesco ad inviare fax
06-20-2010 08:28:05.250 - File: C:\windows\system32\tapisrv.dll, Versione 5.1.2600
06-20-2010 08:28:05.250 - File: C:\windows\system32\unimdm.tsp, Versione 5.1.2600
06-20-2010 08:28:05.250 - File: C:\windows\system32\unimdmat.dll, Versione 5.1.2600
06-20-2010 08:28:05.250 - File: C:\windows\system32\uniplat.dll, Versione 5.1.2600
06-20-2010 08:28:05.546 - File: C:\windows\system32\drivers\modem.sys, Versione 5.1.2600
06-20-2010 08:28:05.593 - File: C:\windows\system32\modemui.dll, Versione 5.1.2600
06-20-2010 08:28:06.093 - File: C:\windows\system32\mdminst.dll, Versione 5.1.2600
06-20-2010 08:28:06.093 - Tipo di modem: PCI SoftV92 Speakerphone Modem
06-20-2010 08:28:06.093 - Percorso informazioni sul modem: oem66.inf
06-20-2010 08:28:06.093 - Sezione informazioni sul modem: Modem1
06-20-2010 08:28:06.093 - Corrispondenza ID hardware: pci\ven_14f1&dev_2f00&subsys_200414f1
06-20-2010 08:28:06.437 - 115200,8,N,1, ctsfl=1, rtsctl=2
06-20-2010 08:28:06.437 - Inizializzazione modem in corso.
06-20-2010 08:28:06.437 - Il livello del segnale DSR è basso durante l'inizializzazione del modem. Verificare che il modem sia acceso.
06-20-2010 08:28:06.437 - Invio: AT<cr>
06-20-2010 08:28:06.437 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.437 - risposta interpretata: OK
06-20-2010 08:28:06.453 - Invio: AT&FE0V1S0=0&C1&D2+MR=2;+DR=1;+ER=1;W2<cr>
06-20-2010 08:28:06.593 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.593 - risposta interpretata: OK
06-20-2010 08:28:06.609 - Invio: ATS7=60S30=26L1M1+ES=3,0,2;+DS=3;+DS44=3;+IFC=2,2;X4<cr>
06-20-2010 08:28:06.609 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.609 - risposta interpretata: OK
06-20-2010 08:28:06.609 - Invio comandi di inizializzazione utente in corso.
06-20-2010 08:28:06.625 - Invio: atx&f1x3<cr>
06-20-2010 08:28:06.765 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.765 - risposta interpretata: OK
06-20-2010 08:28:06.765 - In attesa di una chiamata.
06-20-2010 08:28:06.781 - Invio: ATS0=0<cr>
06-20-2010 08:28:06.781 - Ricezione: ATS0=0<cr>
06-20-2010 08:28:06.781 - Echo comandi
06-20-2010 08:28:06.781 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:28:06.781 - risposta interpretata: OK
06-20-2010 08:56:40.500 - Passthrough attivo
06-20-2010 08:56:42.906 - Passthrough inattivo
06-20-2010 08:56:42.906 - 115200,8,N,1, ctsfl=1, rtsctl=2
06-20-2010 08:56:42.906 - Inizializzazione modem in corso.
06-20-2010 08:56:42.906 - Il livello del segnale DSR è basso durante l'inizializzazione del modem. Verificare che il modem sia acceso.
06-20-2010 08:56:42.906 - Invio: AT<cr>
06-20-2010 08:56:42.906 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:42.906 - risposta interpretata: OK
06-20-2010 08:56:42.921 - Invio: AT&FE0V1S0=0&C1&D2+MR=2;+DR=1;+ER=1;W2<cr>
06-20-2010 08:56:43.062 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:43.062 - risposta interpretata: OK
06-20-2010 08:56:43.078 - Invio: ATS7=60S30=26L1M1+ES=3,0,2;+DS=3;+DS44=3;+IFC=2,2;X4<cr>
06-20-2010 08:56:43.078 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:43.078 - risposta interpretata: OK
06-20-2010 08:56:43.078 - Invio comandi di inizializzazione utente in corso.
06-20-2010 08:56:43.093 - Invio: atx&f1x3<cr>
06-20-2010 08:56:43.234 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:43.234 - risposta interpretata: OK
06-20-2010 08:56:43.234 - In attesa di una chiamata.
06-20-2010 08:56:43.250 - Invio: ATS0=0<cr>
06-20-2010 08:56:43.250 - Ricezione: ATS0=0<cr>
06-20-2010 08:56:43.250 - Echo comandi
06-20-2010 08:56:43.250 - Ricezione: <cr><lf>OK<cr><lf>
06-20-2010 08:56:43.250 - risposta interpretata: OK
paolopa
Inviato: Monday, June 21, 2010 9:59:09 AM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
di fax non capisco nulla,ma vediamo se combofix ti elimina quelle voci che sono sospette...
Scarica Combofix

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Salvalo sul desktop.

Importante: dopo aver scaricato COMBOFIX chiudi la connessione disabilita il tuo antivirus e
chiudi TUTTI i programmi aperti,(Firewall compreso) e


Doppio click su combofix.exe (comparirà una videata.)

E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix)
tu ignorali.

Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.

Durante l'operazione di scansione è importante non usare il PC (neanche il mouse)
e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.
fdaccc
Inviato: Monday, June 21, 2010 8:01:27 PM

Rank: AiutAmico

Iscritto dal : 12/12/2009
Posts: 2,114
Magari prima di fargli usare combofix era meglio eseguire una scansione COMPLETA, non RAPIDA con MBAM..
cbbusto
Inviato: Monday, June 21, 2010 10:16:41 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
I dati del modem che hai postato sono a posto il modem funziona, fai questo controllo, in gestione periferiche>modem>proprietà>scheda avanzate, clic su impostazioni avanzate della porta e spunta:
Usa buffer FIFO poi sotto sposta le leve di Buffer di ricezione e buffer di trasmissione, tutte a destra su Alta,
per quanto riguarda la porta COM 3 ti viene segnalata perchè le prime due sono occupate, verifica cliccando sulla freccetta nera e vedi nella finestra a discesa che compare.
Hai detto di aver aggiunto il modem Alice per ADSL, hai inserito le due prese telefoniche, una per il modem Alice e una per il modem analogico ? entrambe vanno inserite nel filtro tripolare ADSL che sicuramente hai, come
L'immagine sotto, altrimenti i fax non puoi inviarli.
fmancini
Inviato: Tuesday, June 22, 2010 7:04:36 PM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
ecco il log di Combo Fix:
ComboFix 10-06-21.03 - Franco 22/06/2010 18.01.40.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.959.422 [GMT 2:00]
Eseguito da: c:\documents and settings\Franco\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD0EC-FFA4-00EB-0D24-347CA8A3377C}
* Resident AV is active


ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Dati applicazioni\pswi_preloaded.exe
c:\documents and settings\Franco\Dati applicazioni\.#
c:\programmi\RegistryDoktor 4.1

.
((((((((((((((((((((((((( Files Creati Da 2010-05-22 al 2010-06-22 )))))))))))))))))))))))))))))))))))
.

2010-06-18 21:14 . 2010-06-18 21:14 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-16 07:43 . 2010-06-16 19:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PCPitstop
2010-06-16 07:43 . 2010-06-16 07:50 -------- d-----w- c:\programmi\PCPitstop
2010-06-11 17:15 . 2010-06-16 17:56 400184 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-06-11 09:41 . 2010-05-06 10:32 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-08 19:13 . 2010-06-17 08:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2010-06-07 17:56 . 2010-06-19 14:09 -------- d-----w- C:\unzipped
2010-06-06 08:57 . 2010-06-06 08:57 -------- d-----w- c:\programmi\Garmin GPS Plugin
2010-06-04 08:12 . 2010-06-04 08:12 45056 ----a-r- c:\documents and settings\Franco\Dati applicazioni\Microsoft\Installer\{DDA2B32F-EB16-4C96-A130-4E4A4C1E6B12}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2010-06-04 08:11 . 2010-06-04 08:11 43672 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2010-06-04 07:46 . 2010-06-04 08:16 19876 ------w- c:\windows\HPHins02.dat
2010-06-04 07:46 . 2004-05-24 13:40 4308 ------w- c:\windows\hphmdl02.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-21 06:58 . 2010-01-21 09:42 13568 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-06-20 16:00 . 2009-06-11 13:17 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Azureus
2010-06-19 22:00 . 2007-05-20 16:04 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Skype
2010-06-19 16:04 . 2009-08-27 10:16 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Any Video Converter
2010-06-19 14:56 . 2010-03-17 22:33 -------- d-----w- c:\programmi\Desktop Restore
2010-06-18 07:14 . 2007-05-20 16:03 -------- d-----w- c:\programmi\Google
2010-06-16 19:52 . 2010-05-08 13:45 -------- d-----w- c:\programmi\Messenger_Plus_Live_Italy
2010-06-16 08:19 . 2007-09-27 16:38 -------- d-----w- c:\programmi\Messenger Plus! Live
2010-06-12 08:25 . 2001-08-31 12:00 527092 ----a-w- c:\windows\system32\perfh010.dat
2010-06-12 08:25 . 2001-08-31 12:00 45172 ----a-w- c:\windows\system32\perfc010.dat
2010-06-08 19:34 . 2008-04-24 13:31 -------- d-----r- c:\programmi\Skype
2010-06-08 19:34 . 2007-05-20 16:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2010-06-06 10:03 . 2008-10-19 17:04 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\GARMIN
2010-06-05 21:09 . 2009-10-26 13:54 -------- d-----w- c:\programmi\Glary Utilities
2010-06-04 18:49 . 2008-09-06 13:52 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-06-04 18:45 . 2007-11-16 08:51 -------- d-----w- c:\programmi\Windows Live
2010-06-04 18:44 . 2007-11-16 08:51 -------- dcsh--w- c:\programmi\File comuni\WindowsLiveInstaller
2010-06-04 08:11 . 2007-05-18 15:25 -------- d-----w- c:\programmi\Hewlett-Packard
2010-06-03 21:35 . 2010-03-31 09:12 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-03 09:01 . 2008-12-23 15:39 -------- d-----w- c:\programmi\Microsoft
2010-05-21 12:14 . 2009-10-03 10:39 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 13:20 . 2007-05-23 20:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Motive
2010-05-18 13:17 . 2007-05-23 20:24 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\LimeWire
2010-05-18 13:17 . 2010-04-23 13:00 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Audacity
2010-05-18 13:17 . 2009-10-21 16:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2010-05-17 20:27 . 2010-05-17 20:23 -------- d-----w- c:\programmi\iTunes
2010-05-17 20:24 . 2010-05-17 20:24 -------- d-----w- c:\programmi\iPod
2010-05-17 20:24 . 2009-09-18 14:38 -------- d-----w- c:\programmi\File comuni\Apple
2010-05-17 19:58 . 2010-05-17 19:58 -------- d-----w- c:\programmi\Bonjour
2010-05-17 19:55 . 2010-05-17 19:55 73000 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-16 19:05 . 2009-10-23 22:01 -------- d-----w- c:\programmi\NVIDIA Corporation
2010-05-12 20:37 . 2010-05-12 20:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WD_SmartWareCommon
2010-05-12 16:08 . 2007-05-23 19:59 -------- d-----w- c:\programmi\eMule
2010-05-11 12:17 . 2010-05-11 12:17 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Western Digital
2010-05-11 12:17 . 2010-05-11 12:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Western Digital
2010-05-11 12:16 . 2010-05-11 12:16 -------- d-----w- c:\programmi\Western Digital
2010-05-10 20:34 . 2009-06-11 13:16 -------- d-----w- c:\programmi\Vuze
2010-05-08 17:40 . 2009-01-16 21:27 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\uTorrent
2010-05-06 10:32 . 2004-08-19 13:39 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:06 . 2004-08-19 13:31 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 18:09 . 2007-05-21 18:31 -------- d-----w- c:\programmi\Alice ti aiuta
2010-04-28 20:45 . 2010-03-25 18:45 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\U3
2010-04-28 20:04 . 2010-04-28 20:04 -------- d-----w- c:\programmi\File comuni\SWF Studio
2010-04-28 19:41 . 2008-10-05 14:48 -------- d-----w- c:\programmi\Nokia
2010-04-28 19:41 . 2007-05-21 19:32 -------- d-----w- c:\programmi\QuickTime
2010-04-28 19:41 . 2010-04-23 12:31 -------- d-----w- c:\programmi\Audacity 1.3 Beta (Unicode)
2010-04-28 19:41 . 2010-01-09 15:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Suite
2010-04-28 19:41 . 2009-10-26 13:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2010-04-28 09:13 . 2010-03-31 10:25 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-04-27 18:29 . 2010-04-27 18:29 4141117 ----a-w- c:\documents and settings\Franco\Dati applicazioni\Azureus\plugins\vuzexcode\mediainfo.exe
2010-04-27 18:29 . 2010-04-27 18:29 7282688 ----a-w- c:\documents and settings\Franco\Dati applicazioni\Azureus\plugins\vuzexcode\ffmpeg.exe
2010-04-20 05:30 . 2004-08-19 13:37 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-18 19:47 . 2010-04-18 19:47 45648 ----a-w- c:\windows\system32\drivers\rvsystem.sys
2010-04-17 00:24 . 2010-04-17 00:24 306544 ----a-w- c:\windows\WLXPGSS.SCR
2010-04-16 20:12 . 2010-04-16 20:12 48464 ----a-w- c:\windows\system32\sirenacm.dll
2010-04-08 11:20 . 2010-04-08 11:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 11:20 . 2010-04-08 11:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-04-02 17:13 . 2010-04-02 17:13 95232 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-04-02 17:13 . 2010-04-02 17:13 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-02 17:13 . 2010-04-02 17:13 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-02 17:13 . 2010-04-02 17:13 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-03-31 09:12 . 2010-03-31 09:12 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-29 08:29 . 2010-04-02 17:14 34513376 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_ita_web.exe
2008-04-17 12:30 . 2008-01-26 18:15 88 --sh--r- c:\windows\system32\2DE126F1C3.sys
2008-04-17 12:30 . 2007-11-20 23:13 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
Code:
<pre>
c:\programmi\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\programmi\Logitech\Desktop Messenger\8876480\Program\backweb-8876480 .exe
c:\programmi\SUPERAntiSpyware\superantispyware .exe
c:\windows\system32\ctfmon .exe
c:\windows\system32\hphmon05 .exe
c:\windows\system32\nerocheck .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>


((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{08d495ab-a86c-47b0-82ef-da87bf92f730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]

[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08d495ab-a86c-47b0-82ef-da87bf92f730}]
2010-04-15 10:33 2515552 ----a-w- c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{08d495ab-a86c-47b0-82ef-da87bf92f730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]

[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{08D495AB-A86C-47B0-82EF-DA87BF92F730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]

[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\programmi\RocketDock\RocketDock.exe" [2007-09-02 495616]
"RestoreDesktop"="c:\programmi\Restore Desktop\RestoreDesktop.exe" [2003-03-11 45056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2010-02-27 209153]
"HPHUPD05"="c:\programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe" [2004-04-01 49152]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2004-05-05 491520]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
WDDMStatus.lnk - c:\programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoPopUpsOnBoot"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 06:38 241664 ----a-w- c:\programmi\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-12-05 13:41 49152 ----a-w- c:\programmi\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2006-03-21 12:19 69632 ----a-w- c:\programmi\ScanSoft\OmniPageSE4.0\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 08:57 1451520 ----a-w- c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-09-29 23:14 155648 ----a-r- c:\programmi\File comuni\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-02-08 15:58 39408 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"RTHDCPL"=RTHDCPL.EXE
"Alcmtr"=ALCMTR.EXE
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Programmi\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Programmi\\File comuni\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25736:TCP"= 25736:TCP:eMule_TCP
"25745:UDP"= 25745:UDP:eMule_UDP

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/03/2010 11.12.05 64288]
R0 RVSystem;RVSystem;c:\windows\system32\drivers\rvsystem.sys [18/04/2010 21.47.10 45648]
R1 rvsmon;rvsmon;c:\windows\system32\drivers\rvsmon.sys [18/04/2010 21.47.20 264128]
R1 rvsmonn;rvsmonn;c:\windows\system32\drivers\rvsmonn1.sys [18/04/2010 21.47.23 28640]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\programmi\Avira\AntiVir Desktop\avmailc.exe [27/02/2010 20.39.41 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmi\Avira\AntiVir Desktop\sched.exe [27/02/2010 20.39.45 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\programmi\Avira\AntiVir Desktop\avwebgrd.exe [27/02/2010 20.39.43 434945]
R2 ASKService;ASKService;c:\programmi\AskBarDis\bar\bin\AskService.exe [11/06/2009 15.17.58 464264]
R2 ASKUpgrade;ASKUpgrade;c:\programmi\AskBarDis\bar\bin\ASKUpgrade.exe [11/06/2009 15.18.09 234888]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 17.52.57 1352832]
R2 RVSMONBL;Returnil Virtual System Core Service;c:\windows\system32\Returnil\RVS3\rvsmon.exe [06/04/2010 17.13.18 1254800]
R2 rvsmonf;rvsmonf;c:\windows\system32\drivers\rvsmonf.sys [18/04/2010 21.47.22 1035080]
R2 WDDMService;WD SmartWare Drive Manager;c:\programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [13/11/2009 11.28.04 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 8.58.08 20480]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [03/11/2006 18.19.58 13592]
R3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [21/01/2010 11.42.06 13568]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [11/05/2010 14.17.20 11520]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25/03/2008 11.11.27 717296]
S1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\DRIVERS\StarPortLite.sys --> c:\windows\system32\DRIVERS\StarPortLite.sys [?]
S2 gupdate1c98a061b8f7796;Google Update Service (gupdate1c98a061b8f7796);c:\programmi\Google\Update\GoogleUpdate.exe [08/02/2009 17.58.37 133104]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [13/07/2008 11.51.57 8192]
S3 MA8630C;MA8630C;c:\windows\system32\drivers\MA8630C.sys [07/10/2008 22.38.45 23248]
S3 MA8630M;MA8630M;c:\windows\system32\drivers\MA8630M.sys [07/10/2008 22.38.46 25428]
S3 MA8630U;MA8630U;c:\windows\system32\drivers\MA8630U.sys [07/10/2008 22.38.47 51154]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenuto della cartella 'Scheduled Tasks'

2010-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 20:59]

2010-06-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-06-16 c:\windows\Tasks\CanoScan Toolbox 5.job
- c:\progra~1\Canon\CANOSC~1.0\CSTBox.exe [2009-10-16 16:54]

2010-06-22 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2010-02-07 08:01]

2010-06-22 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-05-20 19:13]

2010-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-08 15:58]

2010-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-08 15:58]

2010-06-22 c:\windows\Tasks\HP Usg Daily.job
- c:\programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe [2004-04-01 10:33]

2010-06-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 16:20]

2010-06-22 c:\windows\Tasks\Pulitura disco.job
- c:\windows\system32\cleanmgr.exe [2004-08-19 02:14]

2010-06-21 c:\windows\Tasks\WebReg 20091021182202.job
- c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe [2002-10-16 13:39]

2010-06-17 c:\windows\Tasks\Windows Update.job
- c:\windows\system32\wupdmgr.exe [2001-08-31 12:00]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.com/ig?hl=it
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://www.mirarsearch.com/?useie5=1&q=
IE: &ieSpell Options - c:\programmi\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\programmi\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\programmi\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\programmi\ieSpell\wikipedia.HTM
LSP: c:\programmi\Avira\AntiVir Desktop\avsda.dll
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {4EC99A0B-E57C-4FBE-B9C4-8428424FBF88} - hxxp://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
DPF: {528BF874-2681-4CE3-8C62-AA0D3BC0A719} - hxxp://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
DPF: {5AF01DCD-8539-4814-9693-ADF47058F075} - hxxp://aiuto.alice.it/ata/static/installers/WebflowActiveXInstaller_4-1-5.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

Toolbar-{701436C2-A36F-40FF-8009-866EB98ABB85} - (no file)
WebBrowser-{F4035115-6152-4901-A81D-F4E0A0479615} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{701436C2-A36F-40FF-8009-866EB98ABB85} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-22 18:11
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"659BD8E725A05FDCC64118EA787EAA2B534A94FABE"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8b,4e,a9,aa,a0,bb,b4,43,bb,86,30,\
"3A77B377802A4B6183DDE08FDE4AD9AF647A702826"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8b,4e,a9,aa,a0,bb,b4,43,bb,86,30,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'lsass.exe'(768)
c:\programmi\Avira\AntiVir Desktop\avsda.dll
.
Ora fine scansione: 2010-06-22 18:17:26
ComboFix-quarantined-files.txt 2010-06-22 16:17
ComboFix2.txt 2009-05-05 15:53

Pre-Run: 21.420.539.904 byte disponibili
Post-Run: 21.751.861.248 byte disponibili

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - F8E3D2EB5C1CD2848064BA1A1E91A37A
Per quanto riguarda il Fax ho eseguito quanto suggeritomi sia per l'impostazione che per il cavo di collegamento ma i fax non partono:vorrei rinunciare ma piuttosto mi pare sia possibile spedire i Fax anche attraverso il modem ADSL alice gate voip 2 plus....se si cosa devo fare?
Grazie cbbusto,fdaccc,paolopa per l'aiuto!
PS.ho annullato diversi programmi in apertura ed ora mi pare sia tornato tutto normale circa la lentezza.
Mi resta ancora il problema della finestra di WORD che ogni tanto compare la scritta"Il file normale esiste già.Sostituirlo?" io dico SI per eliminare questa finestra ,però mi dà fastidio....!!!Ciao ragazzi e grazie sarò noioso!
paolopa
Inviato: Tuesday, June 22, 2010 7:36:46 PM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
combofix ti ha levato alcune infezioni,pero' temo propio che vada eseguito uno script,ed io non sono in grado di fartelo fare,speriamo che r16 dia un occhiata a questo post,altrimenti glielo segnaliamo...
r16
Inviato: Tuesday, June 22, 2010 10:49:16 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Apri un file di testo con il Block Note sul Desktop
Ci incolli il codice che vedi qui sotto, e salvi il file di testo obbligatoriamente con il nome CFScript.txt

Code:
KillAll::
File::
c:\programmi\Lavasoft\Ad-Aware\AAWService.exe
c:\windows\system32\drivers\Lbd.sys
c:\windows\system32\lsdelete.exe
Renv::
c:\programmi\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\programmi\Logitech\Desktop Messenger\8876480\Program\backweb-8876480 .exe
c:\programmi\SUPERAntiSpyware\superantispyware .exe
c:\windows\system32\ctfmon .exe
c:\windows\system32\hphmon05 .exe
c:\windows\system32\nerocheck .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
Driver::
ASKService
ASKUpgrade
Lbd
Lavasoft Ad-Aware Service
Folder::
c:\windows\Tasks


e trascinalo sull'icona di ComboFix.
Attendi la fine dei lavori, senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix
fmancini
Inviato: Wednesday, June 23, 2010 3:04:41 PM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
scusa ma non so come aprire un file con block note...
maopapof
Inviato: Wednesday, June 23, 2010 3:17:48 PM

Rank: AiutAmico

Iscritto dal : 10/31/2004
Posts: 7,179
start .... accessori .....blocco note ========= > fai il copia ed incolla di quello che ha scritto r ... sedici e mezzo e salvi con nome mettendolo sul desktop .... con questo nome .... CFScript.txt .... e poi prosegui :O)





fmancini
Inviato: Wednesday, June 23, 2010 4:10:28 PM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
ho salvato il log col nome suggerito e ho trascinato sull'icona su ComboFix.exe....ho cliccato su esegui...
fmancini
Inviato: Wednesday, June 23, 2010 4:12:41 PM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
ho salvato il log col nome suggerito e ho trascinato sull'icona su ComboFix.exe....ho cliccato su esegui...e ora penso vada
fmancini
Inviato: Wednesday, June 23, 2010 5:19:07 PM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
ecco il logo aggiornato di ComboFix
fmancini
Inviato: Wednesday, June 23, 2010 5:19:53 PM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
ComboFix 10-06-22.03 - Franco 23/06/2010 16.43.13.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.959.127 [GMT 2:00]
Eseguito da: c:\documents and settings\Franco\Desktop\Antivirus.Spyw.Pulizia.Defr\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD0EC-FFA4-00EB-0D24-347CA8A3377C}
* Resident AV is active


ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((( Files Creati Da 2010-05-23 al 2010-06-23 )))))))))))))))))))))))))))))))))))
.

2010-06-18 21:14 . 2010-06-18 21:14 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-16 07:43 . 2010-06-16 19:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PCPitstop
2010-06-16 07:43 . 2010-06-16 07:50 -------- d-----w- c:\programmi\PCPitstop
2010-06-11 17:15 . 2010-06-16 17:56 400184 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-06-11 09:41 . 2010-05-06 10:32 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-08 19:13 . 2010-06-17 08:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2010-06-07 17:56 . 2010-06-19 14:09 -------- d-----w- C:\unzipped
2010-06-06 08:57 . 2010-06-06 08:57 -------- d-----w- c:\programmi\Garmin GPS Plugin
2010-06-04 08:11 . 2010-06-04 08:11 43672 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2010-06-04 07:46 . 2010-06-04 08:16 19876 ------w- c:\windows\HPHins02.dat
2010-06-04 07:46 . 2004-05-24 13:40 4308 ------w- c:\windows\hphmdl02.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-21 06:58 . 2010-01-21 09:42 13568 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-06-20 16:00 . 2009-06-11 13:17 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Azureus
2010-06-19 22:00 . 2007-05-20 16:04 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Skype
2010-06-19 16:04 . 2009-08-27 10:16 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Any Video Converter
2010-06-19 14:56 . 2010-03-17 22:33 -------- d-----w- c:\programmi\Desktop Restore
2010-06-18 07:14 . 2007-05-20 16:03 -------- d-----w- c:\programmi\Google
2010-06-16 19:52 . 2010-05-08 13:45 -------- d-----w- c:\programmi\Messenger_Plus_Live_Italy
2010-06-16 08:19 . 2007-09-27 16:38 -------- d-----w- c:\programmi\Messenger Plus! Live
2010-06-12 08:25 . 2001-08-31 12:00 527092 ----a-w- c:\windows\system32\perfh010.dat
2010-06-12 08:25 . 2001-08-31 12:00 45172 ----a-w- c:\windows\system32\perfc010.dat
2010-06-08 19:34 . 2008-04-24 13:31 -------- d-----r- c:\programmi\Skype
2010-06-08 19:34 . 2007-05-20 16:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2010-06-06 10:03 . 2008-10-19 17:04 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\GARMIN
2010-06-05 21:09 . 2009-10-26 13:54 -------- d-----w- c:\programmi\Glary Utilities
2010-06-04 18:49 . 2008-09-06 13:52 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-06-04 18:45 . 2007-11-16 08:51 -------- d-----w- c:\programmi\Windows Live
2010-06-04 18:44 . 2007-11-16 08:51 -------- dcsh--w- c:\programmi\File comuni\WindowsLiveInstaller
2010-06-04 08:12 . 2010-06-04 08:12 45056 ----a-r- c:\documents and settings\Franco\Dati applicazioni\Microsoft\Installer\{DDA2B32F-EB16-4C96-A130-4E4A4C1E6B12}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2010-06-04 08:11 . 2007-05-18 15:25 -------- d-----w- c:\programmi\Hewlett-Packard
2010-06-03 21:35 . 2010-03-31 09:12 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-03 09:01 . 2008-12-23 15:39 -------- d-----w- c:\programmi\Microsoft
2010-05-21 12:14 . 2009-10-03 10:39 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 13:20 . 2007-05-23 20:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Motive
2010-05-18 13:17 . 2007-05-23 20:24 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\LimeWire
2010-05-18 13:17 . 2010-04-23 13:00 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Audacity
2010-05-18 13:17 . 2009-10-21 16:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2010-05-17 20:27 . 2010-05-17 20:23 -------- d-----w- c:\programmi\iTunes
2010-05-17 20:24 . 2010-05-17 20:24 -------- d-----w- c:\programmi\iPod
2010-05-17 20:24 . 2009-09-18 14:38 -------- d-----w- c:\programmi\File comuni\Apple
2010-05-17 19:58 . 2010-05-17 19:58 -------- d-----w- c:\programmi\Bonjour
2010-05-17 19:55 . 2010-05-17 19:55 73000 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-16 19:05 . 2009-10-23 22:01 -------- d-----w- c:\programmi\NVIDIA Corporation
2010-05-12 20:37 . 2010-05-12 20:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WD_SmartWareCommon
2010-05-12 16:08 . 2007-05-23 19:59 -------- d-----w- c:\programmi\eMule
2010-05-11 12:17 . 2010-05-11 12:17 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\Western Digital
2010-05-11 12:17 . 2010-05-11 12:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Western Digital
2010-05-11 12:16 . 2010-05-11 12:16 -------- d-----w- c:\programmi\Western Digital
2010-05-10 20:34 . 2009-06-11 13:16 -------- d-----w- c:\programmi\Vuze
2010-05-08 17:40 . 2009-01-16 21:27 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\uTorrent
2010-05-06 10:32 . 2004-08-19 13:39 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:06 . 2004-08-19 13:31 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 18:09 . 2007-05-21 18:31 -------- d-----w- c:\programmi\Alice ti aiuta
2010-04-28 20:45 . 2010-03-25 18:45 -------- d-----w- c:\documents and settings\Franco\Dati applicazioni\U3
2010-04-28 20:04 . 2010-04-28 20:04 -------- d-----w- c:\programmi\File comuni\SWF Studio
2010-04-28 19:41 . 2008-10-05 14:48 -------- d-----w- c:\programmi\Nokia
2010-04-28 19:41 . 2007-05-21 19:32 -------- d-----w- c:\programmi\QuickTime
2010-04-28 19:41 . 2010-04-23 12:31 -------- d-----w- c:\programmi\Audacity 1.3 Beta (Unicode)
2010-04-28 19:41 . 2010-01-09 15:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Suite
2010-04-28 19:41 . 2009-10-26 13:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Yahoo! Companion
2010-04-28 09:13 . 2010-03-31 10:25 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-04-27 18:29 . 2010-04-27 18:29 4141117 ----a-w- c:\documents and settings\Franco\Dati applicazioni\Azureus\plugins\vuzexcode\mediainfo.exe
2010-04-27 18:29 . 2010-04-27 18:29 7282688 ----a-w- c:\documents and settings\Franco\Dati applicazioni\Azureus\plugins\vuzexcode\ffmpeg.exe
2010-04-20 05:30 . 2004-08-19 13:37 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-18 19:47 . 2010-04-18 19:47 45648 ----a-w- c:\windows\system32\drivers\rvsystem.sys
2010-04-17 00:24 . 2010-04-17 00:24 306544 ----a-w- c:\windows\WLXPGSS.SCR
2010-04-16 20:12 . 2010-04-16 20:12 48464 ----a-w- c:\windows\system32\sirenacm.dll
2010-04-08 11:20 . 2010-04-08 11:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 11:20 . 2010-04-08 11:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-04-02 17:13 . 2010-04-02 17:13 95232 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-04-02 17:13 . 2010-04-02 17:13 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-02 17:13 . 2010-04-02 17:13 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-02 17:13 . 2010-04-02 17:13 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-03-31 09:12 . 2010-03-31 09:12 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-29 08:29 . 2010-04-02 17:14 34513376 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_ita_web.exe
2008-04-17 12:30 . 2008-01-26 18:15 88 --sh--r- c:\windows\system32\2DE126F1C3.sys
2008-04-17 12:30 . 2007-11-20 23:13 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
Code:
<pre>
c:\programmi\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\programmi\Logitech\Desktop Messenger\8876480\Program\backweb-8876480 .exe
c:\programmi\SUPERAntiSpyware\superantispyware .exe
c:\windows\system32\ctfmon .exe
c:\windows\system32\hphmon05 .exe
c:\windows\system32\nerocheck .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>


((((((((((((((((((((((((((((( SnapShot@2010-06-22_16.11.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-23 14:17 . 2010-06-23 14:17 16384 c:\windows\Temp\usgthrsvc\Perflib_Perfdata_930.dat
+ 2010-06-23 14:16 . 2010-06-23 14:16 16384 c:\windows\Temp\Perflib_Perfdata_158.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{08d495ab-a86c-47b0-82ef-da87bf92f730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]

[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08d495ab-a86c-47b0-82ef-da87bf92f730}]
2010-04-15 10:33 2515552 ----a-w- c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{08d495ab-a86c-47b0-82ef-da87bf92f730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]

[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{08D495AB-A86C-47B0-82EF-DA87BF92F730}"= "c:\programmi\Messenger_Plus_Live_Italy\tbMes0.dll" [2010-04-15 2515552]

[HKEY_CLASSES_ROOT\clsid\{08d495ab-a86c-47b0-82ef-da87bf92f730}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\programmi\RocketDock\RocketDock.exe" [2007-09-02 495616]
"RestoreDesktop"="c:\programmi\Restore Desktop\RestoreDesktop.exe" [2003-03-11 45056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2010-02-27 209153]
"HPHUPD05"="c:\programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe" [2004-04-01 49152]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2004-05-05 491520]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
WDDMStatus.lnk - c:\programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoPopUpsOnBoot"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 06:38 241664 ----a-w- c:\programmi\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-12-05 13:41 49152 ----a-w- c:\programmi\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2006-03-21 12:19 69632 ----a-w- c:\programmi\ScanSoft\OmniPageSE4.0\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 08:57 1451520 ----a-w- c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-09-29 23:14 155648 ----a-r- c:\programmi\File comuni\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-02-08 15:58 39408 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"RTHDCPL"=RTHDCPL.EXE
"Alcmtr"=ALCMTR.EXE
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Programmi\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Programmi\\File comuni\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25736:TCP"= 25736:TCP:eMule_TCP
"25745:UDP"= 25745:UDP:eMule_UDP

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/03/2010 11.12.05 64288]
R0 RVSystem;RVSystem;c:\windows\system32\drivers\rvsystem.sys [18/04/2010 21.47.10 45648]
R1 rvsmon;rvsmon;c:\windows\system32\drivers\rvsmon.sys [18/04/2010 21.47.20 264128]
R1 rvsmonn;rvsmonn;c:\windows\system32\drivers\rvsmonn1.sys [18/04/2010 21.47.23 28640]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\programmi\Avira\AntiVir Desktop\avmailc.exe [27/02/2010 20.39.41 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmi\Avira\AntiVir Desktop\sched.exe [27/02/2010 20.39.45 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\programmi\Avira\AntiVir Desktop\avwebgrd.exe [27/02/2010 20.39.43 434945]
R2 ASKService;ASKService;c:\programmi\AskBarDis\bar\bin\AskService.exe [11/06/2009 15.17.58 464264]
R2 ASKUpgrade;ASKUpgrade;c:\programmi\AskBarDis\bar\bin\ASKUpgrade.exe [11/06/2009 15.18.09 234888]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 17.52.57 1352832]
R2 RVSMONBL;Returnil Virtual System Core Service;c:\windows\system32\Returnil\RVS3\rvsmon.exe [06/04/2010 17.13.18 1254800]
R2 rvsmonf;rvsmonf;c:\windows\system32\drivers\rvsmonf.sys [18/04/2010 21.47.22 1035080]
R2 WDDMService;WD SmartWare Drive Manager;c:\programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [13/11/2009 11.28.04 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 8.58.08 20480]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [03/11/2006 18.19.58 13592]
R3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [21/01/2010 11.42.06 13568]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [11/05/2010 14.17.20 11520]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25/03/2008 11.11.27 717296]
S1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\DRIVERS\StarPortLite.sys --> c:\windows\system32\DRIVERS\StarPortLite.sys [?]
S2 gupdate1c98a061b8f7796;Google Update Service (gupdate1c98a061b8f7796);c:\programmi\Google\Update\GoogleUpdate.exe [08/02/2009 17.58.37 133104]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [13/07/2008 11.51.57 8192]
S3 MA8630C;MA8630C;c:\windows\system32\drivers\MA8630C.sys [07/10/2008 22.38.45 23248]
S3 MA8630M;MA8630M;c:\windows\system32\drivers\MA8630M.sys [07/10/2008 22.38.46 25428]
S3 MA8630U;MA8630U;c:\windows\system32\drivers\MA8630U.sys [07/10/2008 22.38.47 51154]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenuto della cartella 'Scheduled Tasks'

2010-06-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 20:59]

2010-06-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-06-23 c:\windows\Tasks\CanoScan Toolbox 5.job
- c:\progra~1\Canon\CANOSC~1.0\CSTBox.exe [2009-10-16 16:54]

2010-06-23 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2010-02-07 08:01]

2010-06-23 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-05-20 19:13]

2010-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-08 15:58]

2010-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-08 15:58]

2010-06-23 c:\windows\Tasks\HP Usg Daily.job
- c:\programmi\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe [2004-04-01 10:33]

2010-06-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 16:20]

2010-06-23 c:\windows\Tasks\Pulitura disco.job
- c:\windows\system32\cleanmgr.exe [2004-08-19 02:14]

2010-06-22 c:\windows\Tasks\WebReg 20091021182202.job
- c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe [2002-10-16 13:39]

2010-06-17 c:\windows\Tasks\Windows Update.job
- c:\windows\system32\wupdmgr.exe [2001-08-31 12:00]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.com/ig?hl=it
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://www.mirarsearch.com/?useie5=1&q=
IE: &ieSpell Options - c:\programmi\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\programmi\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\programmi\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\programmi\ieSpell\wikipedia.HTM
LSP: c:\programmi\Avira\AntiVir Desktop\avsda.dll
TCP: {154CF1E7-118E-4EE7-BFF7-6DC81998C56B} = 85.37.17.8 85.38.28.73
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {4EC99A0B-E57C-4FBE-B9C4-8428424FBF88} - hxxp://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
DPF: {528BF874-2681-4CE3-8C62-AA0D3BC0A719} - hxxp://aiuto.alice.it/ata/static/installers/McciControlInstaller_6.6.cab
DPF: {5AF01DCD-8539-4814-9693-ADF47058F075} - hxxp://aiuto.alice.it/ata/static/installers/WebflowActiveXInstaller_4-1-5.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-23 16:55
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"659BD8E725A05FDCC64118EA787EAA2B534A94FABE"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8b,4e,a9,aa,a0,bb,b4,43,bb,86,30,\
"3A77B377802A4B6183DDE08FDE4AD9AF647A702826"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8b,4e,a9,aa,a0,bb,b4,43,bb,86,30,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'lsass.exe'(768)
c:\programmi\Avira\AntiVir Desktop\avsda.dll

- - - - - - - > 'explorer.exe'(2128)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-06-23 17:03:35
ComboFix-quarantined-files.txt 2010-06-23 15:03
ComboFix2.txt 2010-06-22 16:17
ComboFix3.txt 2009-05-05 15:53

Pre-Run: 21.686.087.680 byte disponibili
Post-Run: 21.674.475.520 byte disponibili

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 59D6628FDDFA4EE526D1DE050493E654
fmancini
Inviato: Wednesday, June 23, 2010 5:24:20 PM

Rank: AiutAmico

Iscritto dal : 12/16/2006
Posts: 105
ancora un grazie a maopapof-r16-paolopa-cbbusto-fdacc per la sollecitudine...avrete capito che ne mastico poco di pc...abbiate pazienza..grazie
cbbusto
Inviato: Wednesday, June 23, 2010 5:26:22 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Per quanto riguarda il fax, è strano che non riesci a inviarli, probabilmente non hai configurato bene il
programma di windows, devi impostarlo per invio e ricezione.
I fax viaggiano solo in analogico e non si possono inviare con l'ADSL, però ci sono programmi che puoi usare in rete,
guarda su aiuitamici QUI
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.