Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Un aiuto, grazie ! Opzioni
enzino85
Inviato: Sunday, October 04, 2009 8:51:09 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
UNA SCANSIONE CON UMALWAREBYTES'
***************************************************

UMalwarebytes' Anti-Malware 1.41
Versione del database: 2854
Windows 5.1.2600 Service Pack 3

04/10/2009 18.16.11
mbam-log-2009-10-04 (18-16-11).txt

Tipo di scansione: Scansione rapida
Elementi scansionati: 110319
Tempo trascorso: 9 minute(s), 20 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 1
Valori di registro infetti: 1
Elementi dato del registro infetti: 0
Cartelle infette: 1
File infetti: 23

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\srosa (Worm.Bagle) -> Delete on reboot.

Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\drvsyskit (Worm.Bagle) -> Delete on reboot.

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld (Worm.Bagle) -> Quarantined and deleted successfully.

File infetti:
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\1073843.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\1075843.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\1077218.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\494984.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\496093.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\496531.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\682078.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\683796.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\684453.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\820281.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\822250.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\823750.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\903093.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\904234.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\904781.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\905453.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\906109.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\906343.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\929640.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\930437.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld\930734.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\srosa2.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\desktop\Dati applicazioni\drivers\winupgro.exe (Trojan.Agent) -> Delete on reboot.


UN LOG DI HIJACKTHIS
****************************************************************

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18.28.52, on 04/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
d:\Programmi\Burn\CDBurnerXP\NMSAccessU.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe
C:\PROGRA~1\TVAV~1\TVAV~1\TVTray.exe
C:\Programmi\Lexmark 1200 Series\lxczbmon.exe
C:\WINDOWS\V0350Mon.exe
C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Sidebar\sidebar.exe
C:\Programmi\Windows Live\Messenger\msnmsgr.exe
C:\Programmi\Windows Sidebar\sidebar.exe
C:\Programmi\DesktopEarth\DesktopEarth.exe
D:\Programmi\DiskUtility\totalcmd\TOTALCMD.EXE
D:\My Folder\Antivirus\MegaLab.it_HiJack.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nontipago.it/Servizi/Notizie.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeSearchInstallRTM?clid=1040&ver=12&app=outlook.exe&p1=32&p2=5&p3=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programmi\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmi\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Toolbar &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [TVTray] C:\PROGRA~1\TVAV~1\TVAV~1\TVTray.exe
O4 - HKLM\..\Run: [V0350Mon.exe] C:\WINDOWS\V0350Mon.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Programmi\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PSDrvCheck] D:\Programmi\Foto\programs\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Programmi\DiskUtility\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Programmi\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Programmi\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\Programmi\Windows Sidebar\sidebar.exe /autoRun (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Alice.lnk = ?
O4 - Global Startup: DesktopEarth AutoStart.lnk = ?
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Programmi\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Programmi\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Programmi\Crawler\Toolbar\ctbr.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - D:\Programmi\Foto\MAGIX\Common\Database\bin\fbserver.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - D:\Programmi\Burn\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMSAccessU - Unknown owner - d:\Programmi\Burn\CDBurnerXP\NMSAccessU.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
O23 - Service: UPnPService - Magix AG - C:\Programmi\File comuni\MAGIX Shared\UPnPService\UPnPService.exe

--
End of file - 10354 bytes
Sponsor
Inviato: Sunday, October 04, 2009 8:51:09 PM

 
r16
Inviato: Sunday, October 04, 2009 10:38:38 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Bello scaricare Crack dalla rete vero? (vedi di eliminare i vari crack o Keygen che hai scaricato ultimamente, altrimenti tutto il lavoro che si farà, sarà inutile)

Scarica Findykill:
http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe
installa FindyKill .
chiudi tutte le eventuali applicazioni aperte (antivirus, firewall e programmi "residenti")
disconnettiti da Internet
sconnetti, fisicamente, il modem dal computer.
avvia il tool e digita F per impostare la lingua;
clicca su 2 - Suppression des fichiers infectieux (Eliminazione dei file infetti)
al termine dell'operazione verrà rilasciato un log: salvalo sul Desktop, e postalo qui.
P.S:
Potranno esserci dei riavvii, non preoccuparti, è il programma che stà lavorando.
enzino85
Inviato: Sunday, October 04, 2009 11:18:03 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
QUESTO E' IL LOG RICHIESTO
*************************************************
############################## | FindyKill V5.012 |

# User : desktop (Administrators) # FRANCO
# Update on 20/09/2009 by Chiquitine29
# Start at: 22.54.03 | 04/10/2009
# Website : http://pagesperso-orange.fr/NosTools/index.html

# Intel(R) Pentium(R) 4 CPU 3.00GHz
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : avast! antivirus 4.8.1351 [VPS 091003-0] 4.8.1351 [ (!) Disabled | Updated ]

# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 53,75 Go (28,27 Go free) [WINNEW] # NTFS
# D:\ # Disco rigido locale # 114,49 Go (10,47 Go free) [Work] # NTFS
# E:\ # Disco rigido locale # 20,81 Go (10,53 Go free) [RECOVERY] # NTFS
# G:\ # Disco CD-ROM
# H:\ # Disco CD-ROM
# I:\ # Disco CD-ROM
# J:\ # Disco rimovibile # 7,47 Go (6,22 Go free) [Cruzer] # FAT32

############################## | Processus actifs |

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
d:\Programmi\Burn\CDBurnerXP\NMSAccessU.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## | C: |


################## | C:\WINDOWS |

Supprimé ! C:\WINDOWS\Prefetch\KEY_GEN.EXE-1FDF51C2.pf
Supprimé ! C:\WINDOWS\Prefetch\KEY_GEN.EXE-37DF351C.pf
Supprimé ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-076A42B3.pf

################## | C:\WINDOWS\system32 |


################## | C:\WINDOWS\system32\drivers |


################## | C:\Documents and Settings\desktop\Dati applicazioni |

Supprimé ! C:\Documents and Settings\desktop\Dati applicazioni\drivers\wfsintwq.sys
Supprimé ! C:\Documents and Settings\desktop\Dati applicazioni\drivers

################## | Autres suppression ... |

Supprimé ! "C:\Programmi\ATI Multimedia\main\LaunchPd.exe"
-> Size : 835584 | Crc32 : e41ba87f | Md5 : cccda0e4ae53c153b9b7666659d90674


################## | Temporary Internet Files |


################## | Registre / Clés infectieuses |

Supprimé ! [HKLM\SYSTEM\ControlSet002\Services\srosa]
Supprimé ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]
Supprimé ! [HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S]
Supprimé ! [HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
Supprimé ! [HKCU\Software\bisoft]
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Supprimé ! [HKCU\Software\Local AppWizard-Generated Applications\WINUPGRO]
Supprimé ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
Supprimé ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
Supprimé ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
Supprimé ! [HKLM\software\microsoft\security center] "FirewallOverride"
Supprimé ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"

################## | Etat / Services / Informations |

# Mode sans echec restauré !

# Affichage des fichiers cachés : OK

# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

################## | PEH ... |

Corrupted : C:\Programmi\Alwil Software\Avast4\ashAvast.exe
[Offset = 0000011C - Value = 0x0001]

Corrupted : C:\Programmi\Alwil Software\Avast4\ashDisp.exe
[Offset = 00000124 - Value = 0x0001]

Corrupted : C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
[Offset = 0000010C - Value = 0x0001]

Corrupted : C:\Programmi\Alwil Software\Avast4\ashServ.exe
[Offset = 00000124 - Value = 0x0001]

Corrupted : C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
[Offset = 00000114 - Value = 0x0001]

Corrupted : C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
[Offset = 00000114 - Value = 0x0001]

Corrupted : C:\Programmi\Creative\Shared Files\Software Update\AutoUpdate.exe
[Offset = 0000010C - Value = 0x0001]

Corrupted : C:\Programmi\Lavasoft\Ad-Aware\AAWService.exe
[Offset = 00000114 - Value = 0x0001]

Corrupted : C:\Programmi\Spyware Terminator\SpywareTerminatorShield.Exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : C:\Programmi\Spyware Terminator\sp_rsser.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : C:\Programmi\Spyware Terminator\update\SpywareTerminatorShield.Exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : D:\Mia\Lavoro\Mia\S415520\Mia\Psp\Register.exe
[Offset = 000000D4 - Value = 0x0001]

Corrupted : D:\My Folder\Antivirus\avenger.exe
[Offset = 00000084 - Value = 0x0001]

Corrupted : D:\My Folder\Antivirus\HiJackThis_v2.exe
[Offset = 000000C4 - Value = 0x0001]

Corrupted : D:\My Folder\ComboFix.exe
[Offset = 00000204 - Value = 0x0001]

Corrupted : D:\My Folder\HiJackThis.exe
[Offset = 000000C4 - Value = 0x0001]

Corrupted : D:\Programmi\DiskUtility\BufferZone\ClientGUI.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : D:\Programmi\DiskUtility\PartitionMagic 8.0\DOCS\PM8Flash.exe
[Offset = 000000EC - Value = 0x0001]

Corrupted : D:\Programmi\DiskUtility\PartitionMagic 8.0\DrvMap.exe
[Offset = 00000204 - Value = 0x0001]

Corrupted : D:\Programmi\DiskUtility\PartitionMagic 8.0\pqbw.exe
[Offset = 00000114 - Value = 0x0001]

Corrupted : D:\Programmi\DiskUtility\Spybot - Search & Destroy\blindman.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : D:\Programmi\DiskUtility\Spybot - Search & Destroy\Update.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : D:\Programmi\DiskUtility\XP Manager\LiveUpdate.exe
[Offset = 00000084 - Value = 0x0001]

Corrupted : D:\Programmi\DiskUtility\XP Manager\Uninstaller.exe
[Offset = 00000084 - Value = 0x0001]

Corrupted : D:\Programmi\Foto\Paint Shop Photo Album 5\system\register.exe
[Offset = 000000C4 - Value = 0x0001]

Corrupted : D:\Programmi\Grafica\Paint Shop Pro 9\register.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : D:\Programmi\Internet\Malware Destroyer\Quarantine\FRANCO\NMC.BACKWEB.LITE\Files\Programmi\kodak\kodak software updater\7288971\6.3.2.62-7288971L\Program\register.exe
[Offset = 0000010C - Value = 0x0001]

Corrupted : D:\Programmi\Internet\Net Tools\Uninstaller.exe
[Offset = 000000BC - Value = 0x0001]

Corrupted : D:\Programmi\Internet\Netscape\Navigator 9\uninstall\helper.exe
[Offset = 000000DC - Value = 0x0001]

Corrupted : D:\Programmi\Internet\Recupero Pagina Iniziale\HijackThis.exe
[Offset = 000000BC - Value = 0x0001]

Corrupted : D:\Programmi\Internet\TV\Update.exe
[Offset = 000000F4 - Value = 0x0001]

Corrupted : D:\Programmi\Internet\ZoneAlarm\zauninst.exe
[Offset = 000000CC - Value = 0x0001]

Corrupted : D:\Programmi\Utility\SpeedUpMyPC\helper.exe
[Offset = 00000204 - Value = 0x0001]

Corrupted : D:\Programmi\Utility\Unlocker\UnlockerAssistant.exe
[Offset = 000000E4 - Value = 0x0001]

Corrupted : D:\Programmi\Utility\WinXP Manager\LiveUpdate.exe
[Offset = 00000084 - Value = 0x0001]

Corrupted : D:\Programmi\Utility\WinXP Manager\Uninstaller.exe
[Offset = 00000084 - Value = 0x0001]

Corrupted : D:\Programmi\Video\3ivx\3ivx MPEG-4 5.0.2\uninstaller.exe
[Offset = 000000DC - Value = 0x0001]


################## | Cracks / Keygens / Serials |

"C:\Documents and Settings\All Users\Documenti\Pinnacle\Content\HollywoodFX\"HfxSerial.exe""
15/04/2008 11.20 |Size 79120 |Crc32 5cf1b191 |Md5 4e5ba3b0dce8785928a460b62369a472


################## | ! Fin du rapport # FindyKill V5.012 ! |

r16
Inviato: Sunday, October 04, 2009 11:27:42 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Pregasi di eliminare codesto crack:
C:\Documents and Settings\All Users\Documenti\Pinnacle\Content\HollywoodFX\"HfxSerial.exe""
15/04/2008 11.20 |Size 79120 |Crc32 5cf1b191 |Md5 4e5ba3b0dce8785928a460b62369a472

Disistalla in quanto corrotti:
Avast!
Creative
Ad-Aware (questo lo puoi eliminare definitivamente)
Spyware Terminator

Fai questa scansione:
Scarica Elibagla:

http://www.zonavirus.com/datos/descargas/95/elibagla.asp
Clicca in fondo alla pagina "Descargar Elibagla".
clicca sulla icona di Elibagla per avviare il tool
spunta la voce Eliminar ficheros automaticamente
clicca su Explorar
lascia completare la scansione.
al termine dell'operazione verrà rilasciato un log in Disco Locale C: dal nome InfoSat.txt
Postalo qui.
enzino85
Inviato: Sunday, October 04, 2009 11:58:27 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
IL LOG INFOSAT
*************************************
Fri Jan 16 00:21:45 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Acción Directa):

Fri Jan 16 00:22:11 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "C:\"

Nº Total de Directorios: 3449
Nº Total de Ficheros: 29699
Nº de Ficheros Analizados: 7448
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

Fri Jan 16 00:24:45 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "D:\"

Nº Total de Directorios: 3008
Nº Total de Ficheros: 39776
Nº de Ficheros Analizados: 2671
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
Exploración Detenida por el Usuario.

Fri Jan 16 00:27:06 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "D:\"
D:\My Folder\PICTURESTOEXE 5.03 [PATCH](1).ZIP --> Eliminado Bagle.dldr
D:\My Folder\PICTURESTOEXE 5.03 [PATCH].ZIP --> Eliminado Bagle.dldr
D:\My Folder\PICTURESTOEXE 5.03.ZIP --> Eliminado Bagle.dldr
D:\My Folder\SUPER SCREEN CAPTURE 4.0 [KEYGEN].ZIP --> Eliminado Bagle
D:\My Folder\UNLOCKER 1.8.5.ZIP --> Eliminado Bagle.dldr
D:\Programmi\Internet\eMule\Incoming\FILERESCUE PROFESSIONAL 2.7 BUILD 231 (SERIAL).ZIP --> Eliminado Bagle.dldr
D:\RECYCLER\S-1-5-21-1801674531-527237240-725345543-1003\DD27.ZIP --> Eliminado Bagle.dldr
D:\RECYCLER\S-1-5-21-1801674531-527237240-725345543-1003\DD28.ZIP --> Eliminado Bagle.dldr

Nº Total de Directorios: 15540
Nº Total de Ficheros: 245621
Nº de Ficheros Analizados: 17178
Nº de Ficheros Infectados: 8
Nº de Ficheros Limpiados: 8

Fri Jan 16 00:39:26 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "D:\"

Nº Total de Directorios: 15540
Nº Total de Ficheros: 245613
Nº de Ficheros Analizados: 17170
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

Fri Jan 16 00:40:59 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "E:\"

Nº Total de Directorios: 6925
Nº Total de Ficheros: 75538
Nº de Ficheros Analizados: 1300
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

Fri Jan 16 00:42:25 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "F:\"

Nº Total de Directorios: 1
Nº Total de Ficheros: 0
Nº de Ficheros Analizados: 0
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

Fri Jan 16 00:42:27 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "F:\"

Nº Total de Directorios: 1
Nº Total de Ficheros: 0
Nº de Ficheros Analizados: 0
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

Fri Jan 16 00:42:37 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "G:\"
G:\Documents and Settings\desktop\Dati applicazioni\drivers\SROSA2.SYS --> Eliminado Bagle(rootkit)
G:\Documents and Settings\desktop\Dati applicazioni\m\FLEC006.EXE --> Eliminado Bagle.dldr
G:\Qoobox\Quarantine\C\WINDOWS\system32\MDELK.EXE.VIR --> Eliminado Bagle
G:\Qoobox\Quarantine\C\WINDOWS\system32\WINTEMS.EXE.VIR --> Eliminado Bagle
G:\RECYCLER\S-1-5-21-484763869-920026266-725345543-1003\DC10.EXE --> Eliminado Bagle
G:\RECYCLER\S-1-5-21-484763869-920026266-725345543-1003\DC11.EXE --> Eliminado Bagle.dldr
G:\RECYCLER\S-1-5-21-484763869-920026266-725345543-1003\DC28.EXE --> Eliminado Bagle

Nº Total de Directorios: 10560
Nº Total de Ficheros: 86663
Nº de Ficheros Analizados: 14498
Nº de Ficheros Infectados: 7
Nº de Ficheros Limpiados: 7

Fri Jan 16 00:50:00 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "G:\"

Nº Total de Directorios: 10560
Nº Total de Ficheros: 86656
Nº de Ficheros Analizados: 14491
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

Fri Jan 16 00:51:35 2009
EliBagle v12.11b (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 12 de Enero del 2009)

Lista de Acciones (por Exploración):
Explorando "K:\"

Nº Total de Directorios: 2680
Nº Total de Ficheros: 18355
Nº de Ficheros Analizados: 1572
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

(4-10-2009 21:49:41)
EliBagle v12.95 (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 2 de Octubre del 2009)

Lista de Acciones (por Acción Directa):

(4-10-2009 21:49:56)
EliBagle v12.95 (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 2 de Octubre del 2009)

Lista de Acciones (por Exploración):
Explorando "C:\"

Nº Total de Directorios: 8551
Nº Total de Ficheros: 61815
Nº de Ficheros Analizados: 11161
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
r16
Inviato: Monday, October 05, 2009 12:07:42 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ti lascio del lavoro da fare: (e ti prego di eseguire TUTTI i passaggi)

Disattiva il ripristino configurazione di sistema, e tienilo disattivato, fino alla soluzione del problema http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121

Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
Nella schermata iniziale di CCleaner, clicca su Opzioni e poi Avanzate, togli il segno di spunta a: Cancella i file in Windows Temp solo se più vecchi di 48 ore. (poi esegui le pulizie)

Scarica ed installa MalwareBytes:
clicca qui per il download : http://www.aiutamici.com/software?id=80346
Prima di fare la scansione AGGIORNALO. (è molto importante)
Esegui una scansione completa del sistema.
Elimina tutto quello che trova.
Posta il log.

Poi:
Start\Esegui\copia e incolla la stringa %temp% clicca su Ok, svuota la cartella temp. (non eliminare la cartella)
Poi:
Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO
Poi:
Lancia Hijackthis e pulisci gli ADS in questo modo:
clicca sulla voce Open the misc tool section
clicca su Open ads spy
togli la spunta alla voce Quick scan (windows base folder only)
clicca su Scan.
Aspetta pazientemente la fine della scansione.
se venissero rilevati ADS, spunta tutte (senza paura) le caselline e clicca su Remove selected



Scarica Combofix

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


Salvalo sul desktop.

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.

Disinstalla combofix in questo modo: (dopo che avrò visto il log)
Start
Esegui
nella finestra di dialogo, copia ed incolla questo comando: Combofix /u e premi Invio poi cancella le cartelle in "C" di Combofix e (qoobox)

Poi fai :
Start\Esegui\ digita: services.msc, Si apre la pagina dei "Servizi"
Controlla se TUTTI questi "Servizi" siano avviati, e siano in Automatico:
Avvisi, Centro sicurezza PC, Aggiornamenti automatici, Connessioni di rete, Zero Configuration reti senza fili e Windows Firewall/ Condivisione connessione Internet (ICS).
Se ne trovi qualcuno in "Manuale, o Disabilitato, lo riporti in Automatico, ricorda di RIAVVIARE il pc. (RIAVVIALO IN OGNI CASO)
Per avviare un servizio, clicca con il tasto destro sul servizio, Proprietà >Automatico > Ok > Avvia > Ok.


Reistalla i software che hai disistallato. (comunque ce ne sono anche di migliori)
enzino85
Inviato: Monday, October 05, 2009 10:38:00 AM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
SEGUONO I LOG RICHIESTI
QUALI SOFTWARE MI CONSIGLI ?
GRAZIE !

*************************************************

Malwarebytes' Anti-Malware 1.41
Versione del database: 2907
Windows 5.1.2600 Service Pack 3

05/10/2009 10.14.41
mbam-log-2009-10-05 (10-14-41).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 170580
Tempo trascorso: 46 minute(s), 35 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)


************************************************************************

ComboFix 09-10-04.01 - desktop 05/10/2009 10.21.55.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1419 [GMT 2:00]
Eseguito da: c:\documents and settings\desktop\Desktop\ComboFix.exe

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-4116899310-64440567-312699812-1000
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\desktop\Dati applicazioni\Desktopicon
c:\documents and settings\desktop\Dati applicazioni\Microsoft\Clip Organizer\mstore10.mgc
c:\documents and settings\desktop\Dati applicazioni\Microsoft\Clip Organizer\Offic10.MGC
C:\InfoSat.txt
c:\windows\Installer\dc9f10.msi
c:\windows\system32\42KJE738.ocx
c:\windows\system32\ICON.ico
c:\windows\system32\OGACheckControl.dll

----- BITS: Possibili siti infetti -----

hxxp://www.photoshow.com
.
((((((((((((((((((((((((( Files Creati Da 2009-09-05 al 2009-10-05 )))))))))))))))))))))))))))))))))))
.

2009-10-04 20:50 . 2009-10-04 21:11 -------- d-----w- C:\FindyKill
2009-10-04 01:30 . 2009-10-04 01:30 -------- d-----w- c:\temp\twain
2009-10-04 01:27 . 2009-10-04 01:27 -------- d-----w- c:\programmi\File comuni\Fellowes
2009-10-04 01:27 . 2002-02-28 01:27 60416 ------w- c:\windows\system32\miroDV2Bmp.dll
2009-10-04 01:27 . 2002-04-24 02:02 40960 ------w- c:\windows\system32\langserv.dll
2009-10-04 00:10 . 2009-10-04 00:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\QuickTime
2009-10-04 00:08 . 2002-02-28 01:28 81920 ------w- c:\windows\system32\vdrmux.dll
2009-10-04 00:08 . 2002-02-28 01:28 46592 ------w- c:\windows\system32\vdrcodec.dll
2009-10-03 23:19 . 2001-10-31 07:14 77824 ----a-w- c:\windows\system32\mplaw7.dll
2009-10-03 23:19 . 2001-10-31 07:14 77824 ----a-w- c:\windows\system32\mplaa6.dll
2009-10-03 23:19 . 2001-10-31 07:14 65536 ----a-w- c:\windows\system32\mplapx.dll
2009-10-03 23:19 . 2001-10-31 07:14 65536 ----a-w- c:\windows\system32\mplam6.dll
2009-10-03 23:19 . 2001-10-31 07:14 1650688 ----a-w- c:\windows\system32\mplva6.dll
2009-10-03 23:19 . 2001-10-31 07:14 1581056 ----a-w- c:\windows\system32\mplvw7.dll
2009-10-03 23:19 . 2001-10-31 07:14 1552384 ----a-w- c:\windows\system32\mplvm6.dll
2009-10-03 23:19 . 2001-10-31 07:14 1122304 ----a-w- c:\windows\system32\mplvpx.dll
2009-10-03 23:19 . 2001-09-17 10:20 19968 ----a-w- c:\windows\system32\cpuinf32.dll
2009-10-03 23:19 . 2009-10-03 23:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MAGIX
2009-10-03 14:27 . 2009-10-03 14:27 110304 ----a-w- c:\windows\system32\drivers\ACEDRV09.sys
2009-10-03 14:17 . 2009-10-03 14:21 -------- d-----w- c:\programmi\File comuni\MAGIX Shared
2009-10-03 14:09 . 1998-10-15 14:28 85504 ----a-w- c:\windows\system32\HtmlWH.dll
2009-10-03 07:41 . 2001-05-16 15:54 309616 ----a-w- c:\windows\system32\wmv8dmod.dll
2009-10-03 01:28 . 2009-10-03 17:10 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\MAGIX
2009-10-03 01:15 . 2007-04-27 07:43 120200 ----a-w- c:\windows\system32\DLLDEV32i.dll
2009-10-03 01:13 . 2009-10-03 23:22 -------- d-----w- c:\windows\system32\MAGIX
2009-10-03 01:13 . 2007-12-04 12:20 700416 ----a-w- c:\windows\system32\mgxoschk.dll
2009-10-03 00:48 . 2004-04-30 07:37 160640 ----a-w- c:\windows\system32\drivers\a347bus.sys
2009-10-03 00:48 . 2004-04-30 07:33 5248 ----a-w- c:\windows\system32\drivers\a347scsi.sys
2009-10-02 14:02 . 2007-10-23 07:27 110592 ----a-w- c:\documents and settings\desktop\Dati applicazioni\U3\temp\cleanup.exe
2009-10-02 14:02 . 2008-05-02 08:41 3493888 ---ha-w- c:\documents and settings\desktop\Dati applicazioni\U3\temp\Launchpad Removal.exe
2009-09-30 10:57 . 2009-09-30 10:57 -------- d-----w- c:\programmi\File comuni\Yahoo!
2009-09-30 10:57 . 2009-09-30 10:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Studio 12
2009-09-30 10:57 . 2009-09-30 10:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Pinnacle Studio Plus
2009-09-29 21:32 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-09-29 21:32 . 2009-09-29 21:34 -------- d-----w- c:\programmi\K-Lite Codec Pack
2009-09-28 22:56 . 2005-07-12 12:25 401408 ----a-w- c:\windows\system32\pvmjpg30.dll
2009-09-28 22:56 . 2002-09-24 09:12 466624 ----a-w- c:\windows\system32\LTRPR13n.DLL
2009-09-28 22:56 . 2002-09-24 09:12 194248 ----a-w- c:\windows\system32\LTRFD13n.DLL
2009-09-28 22:56 . 2002-09-24 09:12 79360 ----a-w- c:\windows\system32\lfeps13s.dll
2009-09-28 22:56 . 2002-09-24 09:12 74752 ----a-w- c:\windows\system32\lfgif13s.dll
2009-09-28 22:56 . 2002-09-24 09:12 185856 ----a-w- c:\windows\system32\lfpng13s.dll
2009-09-28 22:56 . 2002-08-03 02:34 73728 ------w- c:\windows\system32\MMAviAx.dll
2009-09-28 22:56 . 2002-02-28 01:27 114759 ------w- c:\windows\system32\Aviprax.dll
2009-09-28 22:47 . 2009-09-28 22:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SmartSound Software Inc
2009-09-28 22:47 . 2009-09-28 22:47 -------- d-----w- c:\programmi\SmartSound Software
2009-09-28 22:45 . 2003-11-25 04:02 57856 ----a-w- c:\windows\system32\masd32.dll
2009-09-28 22:45 . 2003-11-25 04:02 138752 ----a-w- c:\windows\system32\mase32.dll
2009-09-28 22:45 . 2003-11-25 04:02 136192 ----a-w- c:\windows\system32\mamc32.dll
2009-09-28 22:45 . 2003-11-25 04:02 196096 ----a-w- c:\windows\system32\macd32.dll
2009-09-28 22:45 . 2003-11-25 04:02 27648 ----a-w- c:\windows\system32\ma32.dll
2009-09-28 22:45 . 2004-02-24 11:04 41219 ----a-w- c:\windows\RSETPATH.exe
2009-09-28 22:44 . 2009-09-28 22:44 25214 ----a-r- c:\documents and settings\desktop\Dati applicazioni\Microsoft\Installer\{EEECE229-49F6-4851-A73A-99B058221F8C}\ARPPRODUCTICON.exe
2009-09-28 22:44 . 2009-09-28 22:44 25214 ----a-r- c:\documents and settings\desktop\Dati applicazioni\Microsoft\Installer\{A77F3C2D-50CC-4A29-A1FB-1E018BE4DCA2}\ARPPRODUCTICON.exe
2009-09-28 22:44 . 2004-01-23 15:44 49152 ----a-w- c:\windows\system32\PCLEGetGuid.dll
2009-09-28 14:24 . 2009-09-28 14:24 -------- d-----w- c:\documents and settings\desktop\Impostazioni locali\Dati applicazioni\Pinnacle
2009-09-28 13:52 . 2009-09-28 13:52 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\DivX
2009-09-28 13:50 . 2009-09-28 13:50 29926 ----a-r- c:\documents and settings\desktop\Dati applicazioni\Microsoft\Installer\{5EB90C06-964F-4195-B83E-BD7E55C88415}\ARPPRODUCTICON.exe
2009-09-28 13:50 . 2009-09-28 13:50 -------- d-----w- c:\programmi\File comuni\Pinnacle
2009-09-28 13:50 . 2009-09-28 13:50 -------- d-----w- c:\documents and settings\desktop\Impostazioni locali\Dati applicazioni\Downloaded Installations
2009-09-28 13:49 . 2009-09-28 13:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Pinnacle Studio Ultimate
2009-09-25 09:16 . 2009-09-25 09:24 17561072 ----a-w- c:\documents and settings\desktop\Dati applicazioni\Real\Update\setup3.08\rp\.exe
2009-09-25 09:15 . 2009-09-25 09:16 8405312 ----a-w- c:\documents and settings\desktop\Dati applicazioni\Real\Update\setup3.08\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2009-09-25 09:11 . 2009-09-25 09:11 10309448 ----a-w- c:\documents and settings\desktop\Dati applicazioni\Real\Update\setup3.08\chr\ChromeInstaller.exe
2009-09-25 09:05 . 2009-09-25 09:05 64000 ----a-w- c:\documents and settings\desktop\Dati applicazioni\Real\Update\setup3.08\RUP\inst_config\gcapi_dll.dll
2009-09-25 09:05 . 2009-09-25 09:05 52288 ----a-w- c:\documents and settings\desktop\Dati applicazioni\Real\Update\setup3.08\RUP\inst_config\gtapi.dll
2009-09-25 09:05 . 2009-09-25 09:05 50688 ----a-w- c:\documents and settings\desktop\Dati applicazioni\Real\Update\setup3.08\RUP\inst_config\fftbapi.dll
2009-09-25 09:05 . 2009-09-25 09:05 114688 ----a-w- c:\documents and settings\desktop\Dati applicazioni\Real\Update\setup3.08\RUP\inst_config\compat.dll
2009-09-24 20:41 . 2009-09-28 22:45 -------- d-----w- c:\programmi\DivX
2009-09-24 19:28 . 2009-09-24 19:28 435720 ----a-w- c:\documents and settings\desktop\Dati applicazioni\Real\Update\setup3.08\setup.exe
2009-09-16 14:38 . 2009-09-16 14:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee
2009-09-14 13:31 . 2009-09-14 13:31 -------- d-----w- c:\programmi\FileHippo.com
2009-09-14 13:18 . 2009-09-14 13:18 -------- d-----w- c:\programmi\QuickTime
2009-09-14 11:17 . 2009-09-04 15:44 515416 ------w- c:\windows\system32\XAudio2_5.dll
2009-09-14 11:17 . 2009-09-04 15:44 238936 ------w- c:\windows\system32\xactengine3_5.dll
2009-09-14 11:17 . 2009-09-04 15:29 1974616 ------w- c:\windows\system32\D3DCompiler_42.dll
2009-09-14 11:17 . 2009-09-04 15:29 5501792 ------w- c:\windows\system32\d3dcsx_42.dll
2009-09-14 11:17 . 2009-09-04 15:29 453456 ------w- c:\windows\system32\d3dx10_42.dll
2009-09-14 11:17 . 2009-09-04 15:29 235344 ------w- c:\windows\system32\d3dx11_42.dll
2009-09-14 11:17 . 2009-09-04 15:29 1892184 ------w- c:\windows\system32\D3DX9_42.dll
2009-09-13 21:29 . 2009-09-13 21:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee Security Scan
2009-09-13 21:29 . 2009-09-13 21:29 -------- d-----w- c:\programmi\McAfee Security Scan
2009-09-13 21:28 . 2009-09-13 21:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-09-13 21:05 . 2009-10-02 13:24 -------- d-----w- c:\windows\Logs
2009-09-13 19:39 . 2009-09-28 19:42 154268 ------w- c:\windows\system32\mlfcache.dat
2009-09-13 19:29 . 2009-09-13 19:29 -------- d-----w- c:\programmi\Bonjour

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-04 22:17 . 2009-01-20 14:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-10-04 21:40 . 2009-01-15 21:43 -------- d-----w- c:\programmi\Creative
2009-10-04 21:39 . 2009-01-15 15:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Creative
2009-10-04 21:32 . 2001-08-31 12:00 90920 ----a-w- c:\windows\system32\perfc010.dat
2009-10-04 21:32 . 2001-08-31 12:00 508470 ----a-w- c:\windows\system32\perfh010.dat
2009-10-04 11:53 . 2009-02-04 18:01 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\Nero
2009-10-04 11:27 . 2009-02-04 18:07 -------- d-----w- c:\programmi\File comuni\Simple Star Shared
2009-10-04 11:27 . 2009-02-04 18:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2009-10-04 09:24 . 2009-01-14 13:52 219272 ----a-w- c:\documents and settings\desktop\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-04 09:23 . 2009-01-14 23:31 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\MailWasherFree
2009-10-04 00:08 . 2009-01-14 19:35 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-10-02 14:02 . 2009-01-30 17:12 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\U3
2009-10-01 10:25 . 2009-01-15 09:55 -------- d-----w- c:\programmi\Lexmark 1200 Series
2009-09-30 18:44 . 2009-01-15 22:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ATI MMC
2009-09-28 14:49 . 2009-02-20 15:51 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-09-28 13:17 . 2009-08-28 19:46 -------- d-----w- c:\programmi\Steinberg
2009-09-28 13:16 . 2009-08-28 19:29 -------- d-----w- c:\programmi\Pinnacle
2009-09-24 21:30 . 2009-01-20 13:01 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-09-24 20:56 . 2009-08-28 19:47 2019 ----a-w- c:\windows\NewRecorder.reg
2009-09-14 14:35 . 2009-01-15 00:11 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\Apple Computer
2009-09-14 13:46 . 2009-06-12 07:54 411368 ------w- c:\windows\system32\deploytk.dll
2009-09-14 13:32 . 2009-02-03 09:32 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\uTorrent
2009-09-14 13:19 . 2009-03-03 20:24 -------- d-----w- c:\programmi\File comuni\Apple
2009-09-14 11:24 . 2009-01-14 22:09 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-09-10 12:54 . 2009-01-16 02:21 38224 ------w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-01-16 02:21 19160 ------w- c:\windows\system32\drivers\mbam.sys
2009-09-04 15:44 . 2009-09-13 21:09 69464 ------w- c:\windows\system32\XAPOFX1_3.dll
2009-08-28 19:53 . 2009-08-28 19:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Pinnacle
2009-08-28 19:46 . 2009-08-28 19:46 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\InstallShield
2009-08-28 19:46 . 2009-01-14 19:35 -------- d-----w- c:\programmi\File comuni\InstallShield
2009-08-28 19:46 . 2009-08-28 19:46 -------- d-----w- c:\programmi\Jasc Software Inc
2009-08-28 19:31 . 2009-08-28 19:31 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Pinnacle Studio
2009-08-28 17:30 . 2009-08-28 17:30 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\avidemux
2009-08-28 15:57 . 2009-08-28 15:57 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\Pegasys Inc
2009-08-27 13:51 . 2009-08-27 13:51 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\Nokia Multimedia Player
2009-08-27 13:29 . 2009-08-27 13:29 -------- d-----w- c:\programmi\DsNET Corp
2009-08-27 13:23 . 2009-08-27 13:07 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\Orbit
2009-08-27 13:07 . 2009-08-27 13:07 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\GrabPro
2009-08-21 08:37 . 2009-01-14 22:14 -------- d-----w- c:\programmi\MSBuild
2009-08-21 08:37 . 2009-08-21 08:37 -------- d-----w- c:\programmi\Reference Assemblies
2009-08-19 12:47 . 2009-08-19 12:47 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\Design-Lib.Com
2009-08-19 12:47 . 2009-08-19 12:47 -------- d-----w- c:\programmi\Design-Lib Creations
2009-08-18 21:34 . 2009-01-15 10:37 -------- d-----w- c:\programmi\File comuni\Adobe
2009-08-18 21:29 . 2009-08-18 21:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Adobe Systems
2009-08-18 21:28 . 2009-08-18 21:28 -------- d-----w- c:\programmi\File comuni\Adobe Systems Shared
2009-08-11 16:05 . 2009-08-11 16:05 -------- d-----w- c:\documents and settings\desktop\Dati applicazioni\FontCreator
2009-08-05 08:59 . 2008-04-13 17:13 205312 ------w- c:\windows\system32\mswebdvd.dll
2009-07-18 08:45 . 2009-08-11 16:05 147608 ------w- c:\windows\system32\FontInstaller.dll
2009-07-17 19:01 . 2008-04-13 17:13 58880 ------w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2008-08-15 08:27 286208 ------w- c:\windows\system32\wmpdxm.dll
.

------- Sigcheck -------

[-] 2008-08-15 . E88631E21A9CACA06104802F9E915115 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

[-] 2008-08-15 . 902E0A75C51196A82BED9CC0E3AC8756 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\programmi\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\programmi\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\programmi\Windows Sidebar\sidebar.exe" [2008-08-15 1274880]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-23 39408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 339968]
"Lexmark 1200 Series"="c:\programmi\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"TVTray"="c:\progra~1\TVAV~1\TVAV~1\TVTray.exe" [2004-09-10 245760]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2009-04-29 198160]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-09-04 417792]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-09-14 149280]
"PCLEPCI"="c:\progra~1\Pinnacle\PPE\PPE.EXE" [2004-02-03 49152]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"PSDrvCheck"="d:\programmi\Foto\programs\PSDrvCheck.exe" [2003-09-12 406016]
"Malwarebytes Anti-Malware (reboot)"="d:\programmi\DiskUtility\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"Sidebar"="c:\programmi\Windows Sidebar\sidebar.exe" [2008-08-15 1274880]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"Nokia.PCSync"="d:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck xmnt2002 /bat=c:\windows\TEMP\PQ_BATCH.PQB /win=c:\windows /dbg=c:\WINDOWS\TEMP\PQ_DEBUG.TXT /ver=262144 /prd=PartitionMagic\0autocheck autochk *\0lsdelete

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Alice ti aiuta.lnk]
backup=c:\windows\pss\Alice ti aiuta.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Avvio rapido di HP Image Zone.lnk]
backup=c:\windows\pss\Avvio rapido di HP Image Zone.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^McAfee Security Scan.lnk]
backup=c:\windows\pss\McAfee Security Scan.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^desktop^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^desktop^Menu Avvio^Programmi^Esecuzione automatica^HDDlife.lnk]
backup=c:\windows\pss\HDDlife.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^desktop^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AAWTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RelevantKnowledge
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Programmi\\Internet\\uTorrent\\uTorrent.exe"=
"d:\\Programmi\\Internet\\eMule\\emule.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"d:\\Programmi\\Internet\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Programmi\\Video\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"d:\\Programmi\\Video\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"d:\\Programmi\\Video\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"d:\\Programmi\\Video\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"d:\\Programmi\\Video\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"d:\\Programmi\\Video\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"d:\\Programmi\\Video\\Pinnacle\\Studio 12\\Programs\\umi.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [20/02/2009 17.43.15 64160]
R2 ACEDRV09;ACEDRV09;c:\windows\system32\drivers\ACEDRV09.sys [03/10/2009 16.27.35 110304]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\programmi\Lavasoft\Ad-Aware\AAWService.exe" --> c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;d:\programmi\Foto\MAGIX\Common\Database\bin\fbserver.exe --> d:\programmi\Foto\MAGIX\Common\Database\bin\fbserver.exe [?]
S3 TTDec;ATI WDM Teletext Decoder;c:\windows\system32\drivers\atinttxx.sys [14/01/2009 16.35.01 13824]
S3 UPnPService;UPnPService;c:\programmi\File comuni\MAGIX Shared\UPnPService\UPnPService.exe [03/10/2009 16.21.59 544768]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S3 VF0350Vfx;VF0350 Video FX;c:\windows\system32\drivers\V0350Vfx.sys [15/01/2009 23.10.28 7424]
S3 VF0350Vid;Live! Cam Video IM (VF0350);c:\windows\system32\drivers\V0350Vid.sys [15/01/2009 23.10.25 170368]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection WSidebar.inf,Registrazione_SideBar
.
Contenuto della cartella 'Scheduled Tasks'

2009-08-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-10-05 c:\windows\Tasks\RegCure Program Check.job
- d:\programmi\DiskUtility\RegCure\RegCure.exe [2007-08-02 07:20]

2009-01-20 c:\windows\Tasks\RegCure.job
- d:\programmi\DiskUtility\RegCure\RegCure.exe [2007-08-02 07:20]

2009-10-05 c:\windows\Tasks\User_Feed_Synchronization-{BAA84876-83C2-408E-B173-4487A0AA420E}.job
- c:\windows\system32\msfeedssync.exe [2001-08-31 03:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.nontipago.it/Servizi/Notizie.htm
IE: E&sporta in Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\desktop\Dati applicazioni\Mozilla\Firefox\Profiles\vtjs5iq8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.nontipago.it/Servizi/Notizie.htm
FF - prefs.js: keyword.URL - about:neterror?e=query&u=
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: yahoo.homepage.dontask - true.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-fsm - (no file)
AddRemove-HijackThis - c:\docume~1\desktop\IMPOST~1\Temp\_tc\HijackThis.exe
AddRemove-Karaoke 5_is1 - n:\portableapps\Karaoke5\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-05 10:26
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,4f,a4,fb,bb,cd,
ac,25,f2,2e,e8,e1,00,eb,16,2b,de,eb,f6,34,06,17,ab,f7,7c,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,93,a0,b4,32,50,
c3,3f,25,46,47,15,b0,92,4b,c7,ef,ac,7c,c4,26,f8,87,65,a7,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,82,02,96,f3,70,
9e,4d,0f,7a,45,05,fd,91,e8,6f,31,f3,34,9f,0e,ad,ff,89,d7,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,2d,fd,45,1e,e0,
24,5d,72,6b,65,49,6a,7e,99,74,f7,4d,99,5a,ec,bc,22,6f,b9,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,bc,e0,15,5d,b7,
7d,6a,a0,e9,02,6c,fa,fb,1d,47,57,af,47,82,cd,8e,77,12,c2,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,81,2b,75,b0,5e,
12,51,35,50,93,e5,ab,ec,6a,4e,ab,e0,ac,cb,56,9c,6d,89,c6,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,e2,10,c3,7e,26,
28,d0,ac,97,20,4e,9a,c7,f1,35,ee,cf,1d,d3,4c,9f,bc,56,6b,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,93,e1,cb,67,94,
32,96,d2,aa,52,c6,00,84,3c,26,64,50,32,93,6e,92,d6,d3,b1,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,fa,81,bc,82,cf,
30,33,76,b2,46,9a,e2,1b,fe,1b,94,bd,08,03,bf,03,c3,5b,c4,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,47,58,75,a6,fc,
c5,73,1b,37,a4,aa,c3,a6,15,56,0a,ce,40,14,89,34,b8,b9,69,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,66,8b,96,1e,c2,
b0,25,e5,f8,31,0f,a9,5f,a0,ec,fb,54,17,24,b2,6e,3b,2e,7b,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,57,3a,21,97,e9,
25,b7,35,05,73,21,dd,54,d8,4a,c5,9a,09,dd,e4,97,51,db,44,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(520)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-10-05 10.28.53
ComboFix-quarantined-files.txt 2009-10-05 08:28

Pre-Run: 30.843.293.696 byte disponibili
Post-Run: 30.801.977.344 byte disponibili

397 --- E O F --- 2009-09-14 11:28
r16
Inviato: Monday, October 05, 2009 1:34:09 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ok.
Dimmi come funziona il pc, e se riscontri dei problemi.
Posta un log di HJT.
enzino85
Inviato: Monday, October 05, 2009 4:41:57 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
Il computer sembra funzionare correttamente.
Un consiglio per il software da installare ?
Segue il log di HJT.


*********************************************Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16.35.07, on 05/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Java\jre6\bin\jqs.exe
d:\Programmi\Burn\CDBurnerXP\NMSAccessU.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe
C:\PROGRA~1\TVAV~1\TVAV~1\TVTray.exe
C:\Programmi\Lexmark 1200 Series\lxczbmon.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\Programmi\Windows Sidebar\sidebar.exe
C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
C:\Programmi\Windows Live\Messenger\msnmsgr.exe
C:\Programmi\Windows Sidebar\sidebar.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\DesktopEarth\DesktopEarth.exe
D:\Programmi\DiskUtility\totalcmd\TOTALCMD.EXE
d:\Programmi\Diskutility\ClamWin\bin\ClamTray.exe
D:\Programmi\DiskUtility\ClamWin\bin\ClamWin.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nontipago.it/Servizi/Notizie.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeSearchInstallRTM?clid=1040&ver=12&app=outlook.exe&p1=32&p2=5&p3=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programmi\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmi\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [TVTray] C:\PROGRA~1\TVAV~1\TVAV~1\TVTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PSDrvCheck] D:\Programmi\Foto\programs\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Programmi\DiskUtility\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [ClamWin] "d:\Programmi\Diskutility\ClamWin\bin\ClamTray.exe" --logon
O4 - HKCU\..\Run: [Sidebar] C:\Programmi\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Programmi\Windows Sidebar\sidebar.exe /autoRun (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "D:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Alice.lnk = ?
O4 - Global Startup: DesktopEarth AutoStart.lnk = ?
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Programmi\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0BA66152-A1CC-4104-9874-570B63BEEA3F}: NameServer = 85.37.17.5 85.38.28.77
O17 - HKLM\System\CS1\Services\Tcpip\..\{0BA66152-A1CC-4104-9874-570B63BEEA3F}: NameServer = 85.37.17.5 85.38.28.77
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Programmi\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - D:\Programmi\Foto\MAGIX\Common\Database\bin\fbserver.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Programmi\Lavasoft\Ad-Aware\AAWService.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - D:\Programmi\Burn\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMSAccessU - Unknown owner - d:\Programmi\Burn\CDBurnerXP\NMSAccessU.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: UPnPService - Magix AG - C:\Programmi\File comuni\MAGIX Shared\UPnPService\UPnPService.exe

--
End of file - 9601 bytes
r16
Inviato: Monday, October 05, 2009 5:34:19 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Disattiva il ripristino configurazione di sistema, e tienilo disattivato, fino alla soluzione del problema http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121

Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked

O2 - BHO: (no name) - AutorunsDisabled - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [TVTray] C:\PROGRA~1\TVAV~1\TVAV~1\TVTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PSDrvCheck] D:\Programmi\Foto\programs\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Programmi\DiskUtility\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Programmi\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "D:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - Global Startup: DesktopEarth AutoStart.lnk = ?
O23 - Service: Ad-Aware 2007 Service (aawservice) - - (no file)
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Programmi\Lavasoft\Ad-Aware\AAWService.exe (file missing)

Fai una pulizia con CCleaner.

Riavvia il pc.

Se le voci 023 non si eliminano, prova a eliminarle in Modalità provvisoria.

Come antivirus ti consiglio questo:
Avira: (però non sono sicuro che vada daccordo con ClamWin, eventualmente lo disistalli)
http://www.aiutamici.com/software?ID=10908

Lo configuri esattamente come in questa guida, in formato PDF:

http://www.zeusnews.it/zz_upload/PSV/Guida%20completa%20di%20%20AVIRA%20Antivir%209.pdf

Le voci indicate nella prima immagine a pagina 11 della Guida, spuntale tutte (nell'immagine non lo sono).
enzino85
Inviato: Monday, October 05, 2009 10:13:24 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
Tutto a posto !

G R A Z I E !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
r16
Inviato: Monday, October 05, 2009 10:20:47 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Figurati.....di niente.
Occhio a cosa scarichi.....Drool
Ciao!
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.