Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Files infetti Opzioni
panchoz
Inviato: Friday, January 08, 2010 8:51:09 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
giancarlo52 ha scritto:
Grazie dei preziosi consigli
Domani farò tutto e poi vi farò sapere



Ok.

Shhh Nessuno ti ha chiesto, nemmeno io, se fai un pò di manutenzione come deframmentazione e scandisk approfondito, soprattutto quest'ultimo.

Ti è piaciuto Ccleaner?

giancarlo52
Inviato: Friday, January 08, 2010 8:54:00 PM
Rank: AiutAmico

Iscritto dal : 1/4/2010
Posts: 118
Si, la faccio periodicamente.
Periodicamente lancio anche MBM e Norman
CCleaner lo usavo già, ma forse non era settato nel modo migliore, ora l'ho settato seguendo i tuoi consigli
panchoz
Inviato: Friday, January 08, 2010 9:03:28 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Ok, se lo 'scandisk approfondito' non da problemi è un buon segno!

Speak to the hand
giancarlo52
Inviato: Saturday, January 09, 2010 6:20:13 PM
Rank: AiutAmico

Iscritto dal : 1/4/2010
Posts: 118
Ho fatto la verifica con Combo fix, ecco il report:

ComboFix 10-01-04.01 - GianCarlo 09/01/2010 18.06.31.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.768.489 [GMT 1:00]
Eseguito da: c:\documents and settings\GianCarlo\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-6C25-9E7C08000A00}
AV: AVG *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Doctor Web Anti-Virus *On-access scanning enabled* (Updated) {3454C8F1-ECBC-4180-A6F4-04632FBA762B}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programmi\CyberDefender
c:\windows\system32\2.tmp

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MEMSWEEP2
-------\Service_MEMSWEEP2


((((((((((((((((((((((((( Files Creati Da 2009-12-09 al 2010-01-09 )))))))))))))))))))))))))))))))))))
.

2010-01-07 20:21 . 2010-01-07 20:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\clp
2010-01-07 20:20 . 2010-01-08 20:36 -------- d-----w- c:\documents and settings\GianCarlo\Dati applicazioni\Common Toolkit Suite
2010-01-07 20:18 . 2010-01-08 20:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Common Toolkit Suite
2010-01-07 20:05 . 2010-01-08 20:46 -------- d-----w- c:\documents and settings\GianCarlo\Dati applicazioni\Fighters
2010-01-05 22:29 . 2009-11-25 10:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-05 22:29 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-05 22:29 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-05 22:29 . 2010-01-05 22:29 -------- d-----w- c:\programmi\Avira
2010-01-05 22:29 . 2010-01-05 22:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-01-05 20:00 . 2010-01-05 20:00 -------- d-----w- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\PackageAware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-09 17:13 . 2007-09-07 20:49 -------- d-----w- c:\programmi\Mozilla Thunderbird
2010-01-09 17:05 . 2008-05-28 15:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2010-01-06 20:53 . 2006-11-27 19:05 -------- d-----w- c:\programmi\Sony Ericsson
2010-01-05 22:23 . 2010-01-05 22:23 32532 ----a-w- c:\windows\SCHEDLGU.TXT.TMP
2010-01-04 19:52 . 2008-06-21 09:05 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-04 19:51 . 2008-07-13 16:39 5061520 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-03 08:12 . 2008-08-20 05:59 91638753 ----a-w- c:\windows\Internet Logs\tvDebug.zip
2009-12-30 13:55 . 2008-08-02 14:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 13:54 . 2008-06-21 09:05 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 10:05 . 2008-01-09 08:11 -------- d-----w- c:\programmi\Google
2009-12-08 15:00 . 2008-06-08 16:35 -------- d-----w- c:\programmi\AVS4YOU
2009-12-08 15:00 . 2008-06-08 16:35 -------- d-----w- c:\programmi\File comuni\AVSMedia
2009-12-08 14:51 . 2009-12-08 14:51 -------- d-----w- c:\documents and settings\GianCarlo\Dati applicazioni\AVS4YOU
2009-11-15 16:20 . 2009-11-14 12:27 -------- d-----w- c:\programmi\QuickTime
2009-11-15 16:20 . 2006-11-27 21:43 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2009-11-14 13:49 . 2009-11-14 12:39 -------- d-----w- c:\programmi\iPod
2009-11-14 13:06 . 2009-11-14 12:27 -------- d-----w- c:\programmi\File comuni\Apple
2009-11-14 12:41 . 2009-11-14 12:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-12 21:42 . 2008-05-11 04:22 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-11-12 21:31 . 2009-10-29 19:34 38976 ----a-w- c:\windows\system32\drivers\pssdk42.sys
2009-10-27 22:58 . 2001-08-31 10:00 74210 ----a-w- c:\windows\system32\perfc010.dat
2009-10-27 22:58 . 2001-08-31 10:00 447502 ----a-w- c:\windows\system32\perfh010.dat
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-03 39408]
"Google Update"="c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-06-10 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\programmi\Analog Devices\SoundMAX\SMTray.exe" [2002-11-08 98304]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-04-28 323584]
"zBrowser Launcher"="c:\programmi\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 919016]
"SystemProtect"="c:\programmi\System Protect\SysProtect_Tray.exe" [2009-01-21 1223680]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"IObit Security 360"="c:\programmi\IObit\IObit Security 360\IS360tray.exe" [2009-11-14 1278736]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]

c:\documents and settings\GianCarlo\Menu Avvio\Programmi\Esecuzione automatica\
Mozilla Firefox (2).lnk - c:\programmi\Mozilla Firefox\firefox.exe [2008-5-31 908248]
Mozilla Thunderbird (2).lnk - c:\programmi\Mozilla Thunderbird\thunderbird.exe [2008-6-10 8318056]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Logitech Desktop Messenger.lnk - c:\programmi\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2003-10-20 169472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoPopUpsOnBoot"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 22:46 57344 ----a-w- c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 ----a-w- c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-06-10 19:33 133104 ----atw- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\GianCarlo\\Dati applicazioni\\SopCast\\adv\\SopAdver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17/09/2009 18.33.02 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [30/09/2009 17.57.52 206256]
R2 IS360service;IS360service;c:\programmi\IObit\IObit Security 360\is360srv.exe [15/11/2009 17.26.22 312592]
R2 SP_Service;System Protect Deletion Prevention Service;c:\programmi\System Protect\SysProtect_srv.exe [21/01/2009 21.47.57 598528]
R3 sp_prot;System Protect Filter Driver;c:\windows\system32\drivers\sp_prot.sys [21/01/2009 21.47.57 12288]
S2 gupdate1c9a4c8197b2e8c;Google Update Service (gupdate1c9a4c8197b2e8c);c:\programmi\Google\Update\GoogleUpdate.exe [14/03/2009 18.12.41 133104]
S2 PTK License-FIGHTERS-18665827;PTK License-FIGHTERS-18665827;c:\programmi\Fighters\licenseservice.exe --> c:\programmi\Fighters\licenseservice.exe [?]
S2 PTK Live Update-FIGHTERS-18665827;PTK Live Update-FIGHTERS-18665827;c:\programmi\Fighters\updateservice.exe --> c:\programmi\Fighters\updateservice.exe [?]
S2 PTK Scanner-FIGHTERS-18665827;PTK Scanner-FIGHTERS-18665827;c:\programmi\Fighters\ScannerService.exe --> c:\programmi\Fighters\ScannerService.exe [?]
S2 PTK SharedAccess-FIGHTERS-18665827;PTK SharedAccess-FIGHTERS-18665827;c:\programmi\Fighters\configservice.exe --> c:\programmi\Fighters\configservice.exe [?]
S3 AVFSFilter;AVFSFilter;c:\windows\system32\DRIVERS\avfsfilter.sys --> c:\windows\system32\DRIVERS\avfsfilter.sys [?]
S3 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [29/10/2009 20.34.46 38976]
S3 sdAuxService;PC Tools Auxiliary Service; [x]
S3 Vfscan;Vfscan;c:\windows\system32\drivers\vffilter.sys [18/11/2008 10.01.46 15496]
S4 JJMS;JJMS; [x]
S4 KUJYMATDEMV;KUJYMATDEMV; [x]
S4 RWSHJBWXB;RWSHJBWXB; [x]
S4 XCBQIHHHAOPO;XCBQIHHHAOPO; [x]
.
Contenuto della cartella 'Scheduled Tasks'

2010-01-09 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-04 18:58]

2010-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-14 17:12]

2010-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-14 17:12]

2010-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-630328440-682003330-1003Core.job
- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-10 19:33]

2010-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-630328440-682003330-1003UA.job
- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-10 19:33]

2010-01-03 c:\windows\Tasks\SmartDefrag.job
- c:\programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-12-20 15:22]
.
.
------- Scansione supplementare -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: eBay Search
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\GianCarlo\Dati applicazioni\Mozilla\Firefox\Profiles\vadju7mi.default\
FF - prefs.js: browser.startup.homepage - hxxp://tin.alice.it/indexbb.html
FF - component: c:\documents and settings\GianCarlo\Dati applicazioni\Mozilla\Firefox\Profiles\vadju7mi.default\extensions\{4b897551-0a2b-4159-99e7-3cd721caec78}\components\FFExternalAlert.dll
FF - plugin: c:\documents and settings\GianCarlo\Dati applicazioni\Mozilla\Firefox\Profiles\vadju7mi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll

---- FIREFOX POLICIES ----





pref(dom.disable_open_during_load, true);
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

WebBrowser-{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-09 18:12
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(5964)
c:\progra~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\programmi\File comuni\Microsoft Shared\Web Components\10\1040\OWCI10.DLL
c:\programmi\Logitech\iTouch\iTchHk.dll
c:\programmi\File comuni\Logitech\Scrolling\LgMsgHk.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\windows\System32\Ati2evxx.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
c:\programmi\Analog Devices\SoundMAX\SMAgent.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-09 18:17:59 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-09 17:17
ComboFix2.txt 2009-09-16 17:53
ComboFix3.txt 2009-08-22 14:27
ComboFix4.txt 2008-06-19 07:15

Pre-Run: 23.460.716.544 byte disponibili
Post-Run: 23.436.685.312 byte disponibili

Current=5 Default=5 Failed=4 LastKnownGood=1 Sets=1,4,5,6
- - End Of File - - D51D6237CBC96A113D47C6433A9A8FBD



Ho poi lanciato Norman che continua a segnalare questo file infetto:

C:\WINDOWS\Driver Cache\i386\driver.cab/wdmaud.drv (Infected with W32/Suspicious_Gen.CMJV)


r16
Inviato: Saturday, January 09, 2010 11:19:21 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Lascia perdere quello che dice Norman.
Anzi, se lo disistalli, è meglio.

Apri un file di testo sul Desktop (start\esegui\digita: notepad.exe\ Ok
Ci incolli il codice che vedi qui sotto, e salvi il file di testo obbligatoriamente con il nome CFScript.txt

Code:
File::
c:\windows\system32\drivers\PCTCore.sys
c:\windows\system32\drivers\Lbd.sys
c:\programmi\IObit\IObit Security 360\IS360tray.exe
c:\programmi\Fighters\ScannerService.exe

Folder::
c:\programmi\Fighters
c:\programmi\IObit
c:\documents and settings\GianCarlo\Dati applicazioni\Fighters

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IObit Security 360"=-

Driver::
Lbd
PCTCore
JJMS
KUJYMATDEMV
RWSHJBWXB;RWSHJBWXB
XCBQIHHHAOPO
sdAuxService
PTK License-FIGHTERS-18665827



e trascinalo sull'icona di ComboFix.
Attendi la fine dei lavori, senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix
giancarlo52
Inviato: Sunday, January 10, 2010 10:08:09 AM
Rank: AiutAmico

Iscritto dal : 1/4/2010
Posts: 118
Ho fatto come mi hai detto, ecco il log:

ComboFix 10-01-04.01 - GianCarlo 10/01/2010 9.48.42.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.768.501 [GMT 1:00]
Eseguito da: d:\desktop\PROGRAMMI SICUREZZA\ComboFix.exe
Opzioni usate :: d:\desktop\PROGRAMMI SICUREZZA\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-6C25-9E7C08000A00}
AV: AVG *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Doctor Web Anti-Virus *On-access scanning enabled* (Updated) {3454C8F1-ECBC-4180-A6F4-04632FBA762B}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!

FILE ::
"c:\programmi\Fighters\ScannerService.exe"
"c:\programmi\IObit\IObit Security 360\IS360tray.exe"
"c:\windows\system32\drivers\Lbd.sys"
"c:\windows\system32\drivers\PCTCore.sys"
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\GianCarlo\Dati applicazioni\Fighters
c:\programmi\IObit
c:\programmi\IObit\Advanced SystemCare 3\AutoCare.exe
c:\programmi\IObit\Advanced SystemCare 3\AutoSweep.exe
c:\programmi\IObit\Advanced SystemCare 3\AWC.exe
c:\programmi\IObit\Advanced SystemCare 3\AWCInit.exe
c:\programmi\IObit\Advanced SystemCare 3\AwcSchedule.dll
c:\programmi\IObit\Advanced SystemCare 3\Backup\RegistryBackup.cab
c:\programmi\IObit\Advanced SystemCare 3\ContextMenu.exe
c:\programmi\IObit\Advanced SystemCare 3\CookiesBK.pln
c:\programmi\IObit\Advanced SystemCare 3\CoolTrayIcon_D6plus.bpl
c:\programmi\IObit\Advanced SystemCare 3\Def.dbd
c:\programmi\IObit\Advanced SystemCare 3\ESR.exe
c:\programmi\IObit\Advanced SystemCare 3\EULA.rtf
c:\programmi\IObit\Advanced SystemCare 3\FFSweep.dll
c:\programmi\IObit\Advanced SystemCare 3\FileSweep.dll
c:\programmi\IObit\Advanced SystemCare 3\Help.html
c:\programmi\IObit\Advanced SystemCare 3\IEFavBK.pln
c:\programmi\IObit\Advanced SystemCare 3\Images\care.png
c:\programmi\IObit\Advanced SystemCare 3\Images\ds.png
c:\programmi\IObit\Advanced SystemCare 3\Images\home.png
c:\programmi\IObit\Advanced SystemCare 3\Images\mw.png
c:\programmi\IObit\Advanced SystemCare 3\Images\tips.jpg
c:\programmi\IObit\Advanced SystemCare 3\Images\tips2.jpg
c:\programmi\IObit\Advanced SystemCare 3\Images\ut.png
c:\programmi\IObit\Advanced SystemCare 3\IObitUpdate.exe
c:\programmi\IObit\Advanced SystemCare 3\Language\Albanian.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Brasil.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\ChineseSimp.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\ChineseTrad.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Czech.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Dansk.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Dutch.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\English.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Finnish.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\French.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\German.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Hebrew.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Hungarian.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Italiano.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Japanese.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Korean.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Persian.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Polish.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Romanian.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Russian.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Spanish.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Srpski.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Svenska.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Swedish.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Turkish.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Ukrainian.lng
c:\programmi\IObit\Advanced SystemCare 3\Language\Valencian.lng
c:\programmi\IObit\Advanced SystemCare 3\License.dat
c:\programmi\IObit\Advanced SystemCare 3\News\bnews.html
c:\programmi\IObit\Advanced SystemCare 3\News\Css\bstyle.css
c:\programmi\IObit\Advanced SystemCare 3\News\Css\wstyle.css
c:\programmi\IObit\Advanced SystemCare 3\News\wnews.html
c:\programmi\IObit\Advanced SystemCare 3\NtfsData.dll
c:\programmi\IObit\Advanced SystemCare 3\RegeditBK.pln
c:\programmi\IObit\Advanced SystemCare 3\Registration.exe
c:\programmi\IObit\Advanced SystemCare 3\Routine.dll
c:\programmi\IObit\Advanced SystemCare 3\rtl70.bpl
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_01.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_01_mouseover.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_02.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_02_mouseover.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_03.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_03_mouseover.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_04.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_04_mouseover.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Button_bg_down.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Button_bg_left.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Button_bg_right.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\4C_Button_bg_up.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Bg_Content.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\BG_Main.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_en_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_en_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_en_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Check.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Checked.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Close1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Close2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Content_bg_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Content_bg_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Content_bg_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Flag.ico
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Layout.ini
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Min1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Min2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\scan.avi
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Shadow.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Tab_Bottom.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Tab_Selected_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Tab_Selected_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Tab_Selected_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Tab_UnSelected_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Tab_UnSelected_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Tab_UnSelected_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Title.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\UnCheck.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Unchecked.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Upgrade1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\Black\Upgrade2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_01.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_01_mouseover.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_02.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_02_mouseover.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_03.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_03_mouseover.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_04.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_04_mouseover.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Button_bg_down.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Button_bg_left.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Button_bg_right.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\4C_Button_bg_up.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Bg_Content.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\BG_Main.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Care_Button_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Care_Button_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Care_Button_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Care_Button_en_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Care_Button_en_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Care_Button_en_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Check.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Checked.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Close1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Close2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Content_bg_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Content_bg_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Content_bg_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Flag.ico
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Layout.ini
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Min1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Min2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\scan.avi
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Shadow.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Tab_Bottom.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Tab_BottomLine.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Tab_Selected_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Tab_Selected_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Tab_Selected_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Tab_UnSelected_1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Tab_UnSelected_2.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Tab_UnSelected_3.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Title.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\UnCheck.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Unchecked.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Upgrade1.png
c:\programmi\IObit\Advanced SystemCare 3\Skin\White\Upgrade2.png
c:\programmi\IObit\Advanced SystemCare 3\sqlite3.dll
c:\programmi\IObit\Advanced SystemCare 3\STFix.dll
c:\programmi\IObit\Advanced SystemCare 3\Sup_DiskChk.exe
c:\programmi\IObit\Advanced SystemCare 3\Sup_DiskCleaner.exe
c:\programmi\IObit\Advanced SystemCare 3\Sup_GameBooster.exe
c:\programmi\IObit\Advanced SystemCare 3\Sup_InternetBooster.exe
c:\programmi\IObit\Advanced SystemCare 3\Sup_IS360.exe
c:\programmi\IObit\Advanced SystemCare 3\Sup_ISD.exe
c:\programmi\IObit\Advanced SystemCare 3\Sup_RegistryDefrag.exe
c:\programmi\IObit\Advanced SystemCare 3\Sup_ShortcutsFixer.exe
c:\programmi\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
c:\programmi\IObit\Advanced SystemCare 3\Sus_DriverBackUp.exe
c:\programmi\IObit\Advanced SystemCare 3\Sus_PIeHelp.exe
c:\programmi\IObit\Advanced SystemCare 3\Sus_SystemBackup.exe
c:\programmi\IObit\Advanced SystemCare 3\Sus_SystemFileScan.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_AutoShutDown.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_ClonedFilesFinder.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_ContextManager.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_DiskExplorer.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_RestoreCenter.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_SoftUninstaller.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_StartUpManager.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_SysInfo.exe
c:\programmi\IObit\Advanced SystemCare 3\Sut_WinManager.exe
c:\programmi\IObit\Advanced SystemCare 3\unins000.dat
c:\programmi\IObit\Advanced SystemCare 3\unins000.exe
c:\programmi\IObit\Advanced SystemCare 3\unins000.msg
c:\programmi\IObit\Advanced SystemCare 3\Update History.txt
c:\programmi\IObit\Advanced SystemCare 3\Update\awc3check.upt
c:\programmi\IObit\Advanced SystemCare 3\UpdateLog.txt
c:\programmi\IObit\Advanced SystemCare 3\vcl70.bpl
c:\programmi\IObit\Advanced SystemCare 3\vclx70.bpl
c:\programmi\IObit\Advanced SystemCare 3\winSkinD7R.bpl
c:\programmi\IObit\Advanced SystemCare 3\Wizard.exe
c:\programmi\IObit\Advanced WindowsCare V2\Backup\Backup.ini
c:\programmi\IObit\Advanced WindowsCare V2\Backup\bekksc.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\cpakef.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\fvfjuo.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\hqutts.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\IgnoreList.ini
c:\programmi\IObit\Advanced WindowsCare V2\Backup\jxcigb.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\kbwefq.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\lvhmjf.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\osokvu.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\rfmklo.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\wkewjp.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\wvgxkn.reg
c:\programmi\IObit\Advanced WindowsCare V2\Backup\yfujyp.reg
c:\programmi\IObit\Advanced WindowsCare V2\Fav.ico
c:\programmi\IObit\Advanced WindowsCare V2\Main.ini
c:\programmi\IObit\IObit Security 360\a_hijackscan.exe
c:\programmi\IObit\IObit Security 360\Addition.def
c:\programmi\IObit\IObit Security 360\b_securityholes.exe
c:\programmi\IObit\IObit Security 360\c_passivedefense.exe
c:\programmi\IObit\IObit Security 360\core.def
c:\programmi\IObit\IObit Security 360\d_powerfuldelete.exe
c:\programmi\IObit\IObit Security 360\data.dat
c:\programmi\IObit\IObit Security 360\e_privacysweeper.exe
c:\programmi\IObit\IObit Security 360\EULA.rtf
c:\programmi\IObit\IObit Security 360\f_pctuneup.exe
c:\programmi\IObit\IObit Security 360\ffsweep.dll
c:\programmi\IObit\IObit Security 360\filesweep.dll
c:\programmi\IObit\IObit Security 360\g_portable.exe
c:\programmi\IObit\IObit Security 360\help.html
c:\programmi\IObit\IObit Security 360\holesscan.bpl
c:\programmi\IObit\IObit Security 360\Images\main_pro.jpg
c:\programmi\IObit\IObit Security 360\Images\main_upgrade.jpg
c:\programmi\IObit\IObit Security 360\Images\overview.jpg
c:\programmi\IObit\IObit Security 360\Images\protection.jpg
c:\programmi\IObit\IObit Security 360\Images\scan.jpg
c:\programmi\IObit\IObit Security 360\Images\scan_main.jpg
c:\programmi\IObit\IObit Security 360\Images\tools.jpg
c:\programmi\IObit\IObit Security 360\information.ini
c:\programmi\IObit\IObit Security 360\is360.exe
c:\programmi\IObit\IObit Security 360\IS360DataBase.db
c:\programmi\IObit\IObit Security 360\is360ext.dll
c:\programmi\IObit\IObit Security 360\IS360Init.exe
c:\programmi\IObit\IObit Security 360\is360mon.dll
c:\programmi\IObit\IObit Security 360\is360srv.exe
c:\programmi\IObit\IObit Security 360\is360tray.exe
c:\programmi\IObit\IObit Security 360\is360updater.exe
c:\programmi\IObit\IObit Security 360\IWsIS360.exe
c:\programmi\IObit\IObit Security 360\language\Arabic.lng
c:\programmi\IObit\IObit Security 360\language\ChineseSimp.lng
c:\programmi\IObit\IObit Security 360\language\ChineseTrad.lng
c:\programmi\IObit\IObit Security 360\language\Czech.lng
c:\programmi\IObit\IObit Security 360\language\Danish.lng
c:\programmi\IObit\IObit Security 360\language\Dutch.lng
c:\programmi\IObit\IObit Security 360\language\English.lng
c:\programmi\IObit\IObit Security 360\language\Estonian.lng
c:\programmi\IObit\IObit Security 360\language\French.lng
c:\programmi\IObit\IObit Security 360\language\German.lng
c:\programmi\IObit\IObit Security 360\language\Hungarian.lng
c:\programmi\IObit\IObit Security 360\language\Italian.lng
c:\programmi\IObit\IObit Security 360\language\Japanese.lng
c:\programmi\IObit\IObit Security 360\language\Korean.lng
c:\programmi\IObit\IObit Security 360\language\Portuguese(PT-BR).lng
c:\programmi\IObit\IObit Security 360\language\Portuguese.lng
c:\programmi\IObit\IObit Security 360\language\Russian.lng
c:\programmi\IObit\IObit Security 360\language\Slovak.lng
c:\programmi\IObit\IObit Security 360\language\Spanish.lng
c:\programmi\IObit\IObit Security 360\language\Swedish.lng
c:\programmi\IObit\IObit Security 360\language\Turkish.lng
c:\programmi\IObit\IObit Security 360\language\Vietnamese.lng
c:\programmi\IObit\IObit Security 360\license.dat
c:\programmi\IObit\IObit Security 360\madbasic_.bpl
c:\programmi\IObit\IObit Security 360\maddisAsm_.bpl
c:\programmi\IObit\IObit Security 360\madexcept_.bpl
c:\programmi\IObit\IObit Security 360\Quarantine Zone\info.db
c:\programmi\IObit\IObit Security 360\Quarantine Zone\xyponcmr
c:\programmi\IObit\IObit Security 360\readme.txt
c:\programmi\IObit\IObit Security 360\rtl120.bpl
c:\programmi\IObit\IObit Security 360\shellextdll.dll
c:\programmi\IObit\IObit Security 360\sqlite3.dll
c:\programmi\IObit\IObit Security 360\taskdll.dll
c:\programmi\IObit\IObit Security 360\unins000.dat
c:\programmi\IObit\IObit Security 360\unins000.exe
c:\programmi\IObit\IObit Security 360\unins000.msg
c:\programmi\IObit\IObit Security 360\update.dat
c:\programmi\IObit\IObit Security 360\UpdateLog.txt
c:\programmi\IObit\IObit Security 360\vcl120.bpl
c:\programmi\IObit\IObit Security 360\vclx120.bpl
c:\programmi\IObit\IObit SmartDefrag\config.ini
c:\programmi\IObit\IObit SmartDefrag\EULA.rtf
c:\programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
c:\programmi\IObit\IObit SmartDefrag\language\???.lng
c:\programmi\IObit\IObit SmartDefrag\language\????.lng
c:\programmi\IObit\IObit SmartDefrag\language\?????.lng
c:\programmi\IObit\IObit SmartDefrag\language\??????.lng
c:\programmi\IObit\IObit SmartDefrag\language\???????.lng
c:\programmi\IObit\IObit SmartDefrag\language\?????????.lng
c:\programmi\IObit\IObit SmartDefrag\language\Arabic.lng
c:\programmi\IObit\IObit SmartDefrag\language\Bahasa Indonesia.lng
c:\programmi\IObit\IObit SmartDefrag\language\Czech.lng
c:\programmi\IObit\IObit SmartDefrag\language\Danish.lng
c:\programmi\IObit\IObit SmartDefrag\language\Deutsch.lng
c:\programmi\IObit\IObit SmartDefrag\language\Eesti.lng
c:\programmi\IObit\IObit SmartDefrag\language\English.lng
c:\programmi\IObit\IObit SmartDefrag\language\Español.lng
c:\programmi\IObit\IObit SmartDefrag\language\Finnish.lng
c:\programmi\IObit\IObit SmartDefrag\language\Français.lng
c:\programmi\IObit\IObit SmartDefrag\language\Hrvatski.lng
c:\programmi\IObit\IObit SmartDefrag\language\Italiano.lng
c:\programmi\IObit\IObit SmartDefrag\language\Korean.lng
c:\programmi\IObit\IObit SmartDefrag\language\Lietuvi?.lng
c:\programmi\IObit\IObit SmartDefrag\language\Magyar.lng
c:\programmi\IObit\IObit SmartDefrag\language\Nederlands.lng
c:\programmi\IObit\IObit SmartDefrag\language\Norwegian.lng
c:\programmi\IObit\IObit SmartDefrag\language\Polish.lng
c:\programmi\IObit\IObit SmartDefrag\language\Portuguese(PT-BR).lng
c:\programmi\IObit\IObit SmartDefrag\language\Portuguese(PT-PT).lng
c:\programmi\IObit\IObit SmartDefrag\language\Portuguese.lng
c:\programmi\IObit\IObit SmartDefrag\language\Român.lng
c:\programmi\IObit\IObit SmartDefrag\language\Slovenski.lng
c:\programmi\IObit\IObit SmartDefrag\language\Svenska.lng
c:\programmi\IObit\IObit SmartDefrag\language\Turkish.lng
c:\programmi\IObit\IObit SmartDefrag\language\Ukrainian.lng
c:\programmi\IObit\IObit SmartDefrag\language\Valencian.lng
c:\programmi\IObit\IObit SmartDefrag\language\Vietnamese.lng
c:\programmi\IObit\IObit SmartDefrag\NtfsData.dll
c:\programmi\IObit\IObit SmartDefrag\SDInit.exe
c:\programmi\IObit\IObit SmartDefrag\taskdll.dll
c:\programmi\IObit\IObit SmartDefrag\unins000.dat
c:\programmi\IObit\IObit SmartDefrag\unins000.exe
c:\programmi\IObit\IObit SmartDefrag\unins000.msg
c:\programmi\IObit\IObit SmartDefrag\What's new.txt
c:\windows\system32\drivers\Lbd.sys
c:\windows\system32\drivers\PCTCore.sys

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_JJMS
-------\Legacy_KUJYMATDEMV
-------\Legacy_LBD
-------\Legacy_PTK_LICENSE-FIGHTERS-18665827
-------\Legacy_SDAUXSERVICE
-------\Legacy_XCBQIHHHAOPO
-------\Service_JJMS
-------\Service_KUJYMATDEMV
-------\Service_Lbd
-------\Service_PCTCore
-------\Service_PTK License-FIGHTERS-18665827
-------\Service_sdAuxService
-------\Service_XCBQIHHHAOPO
-------\Legacy_IS360service
-------\Service_IS360service


((((((((((((((((((((((((( Files Creati Da 2009-12-10 al 2010-01-10 )))))))))))))))))))))))))))))))))))
.

2010-01-09 18:18 . 2010-01-09 18:21 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-01-07 20:21 . 2010-01-07 20:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\clp
2010-01-07 20:20 . 2010-01-08 20:36 -------- d-----w- c:\documents and settings\GianCarlo\Dati applicazioni\Common Toolkit Suite
2010-01-07 20:18 . 2010-01-08 20:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Common Toolkit Suite
2010-01-05 22:29 . 2009-11-25 10:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-05 22:29 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-05 22:29 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-05 22:29 . 2010-01-05 22:29 -------- d-----w- c:\programmi\Avira
2010-01-05 22:29 . 2010-01-05 22:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-01-05 20:00 . 2010-01-05 20:00 -------- d-----w- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\PackageAware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-10 08:57 . 2007-09-07 20:49 -------- d-----w- c:\programmi\Mozilla Thunderbird
2010-01-10 08:32 . 2006-11-28 12:25 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-01-09 19:14 . 2006-10-17 14:23 22288 ----a-w- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-01-09 17:05 . 2008-05-28 15:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2010-01-06 20:53 . 2006-11-27 19:05 -------- d-----w- c:\programmi\Sony Ericsson
2010-01-05 22:23 . 2010-01-05 22:23 32532 ----a-w- c:\windows\SCHEDLGU.TXT.TMP
2010-01-04 19:52 . 2008-06-21 09:05 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-04 19:51 . 2008-07-13 16:39 5061520 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-03 08:12 . 2008-08-20 05:59 91638753 ----a-w- c:\windows\Internet Logs\tvDebug.zip
2009-12-30 13:55 . 2008-08-02 14:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 13:54 . 2008-06-21 09:05 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 10:05 . 2008-01-09 08:11 -------- d-----w- c:\programmi\Google
2009-12-08 15:00 . 2008-06-08 16:35 -------- d-----w- c:\programmi\AVS4YOU
2009-12-08 15:00 . 2008-06-08 16:35 -------- d-----w- c:\programmi\File comuni\AVSMedia
2009-12-08 14:51 . 2009-12-08 14:51 -------- d-----w- c:\documents and settings\GianCarlo\Dati applicazioni\AVS4YOU
2009-11-15 16:20 . 2009-11-14 12:27 -------- d-----w- c:\programmi\QuickTime
2009-11-15 16:20 . 2006-11-27 21:43 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2009-11-14 13:49 . 2009-11-14 12:39 -------- d-----w- c:\programmi\iPod
2009-11-14 13:06 . 2009-11-14 12:27 -------- d-----w- c:\programmi\File comuni\Apple
2009-11-14 12:41 . 2009-11-14 12:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-12 21:42 . 2008-05-11 04:22 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-11-12 21:31 . 2009-10-29 19:34 38976 ----a-w- c:\windows\system32\drivers\pssdk42.sys
2009-10-27 22:58 . 2001-08-31 10:00 74210 ----a-w- c:\windows\system32\perfc010.dat
2009-10-27 22:58 . 2001-08-31 10:00 447502 ----a-w- c:\windows\system32\perfh010.dat
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-03 39408]
"Google Update"="c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-06-10 133104]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\programmi\Analog Devices\SoundMAX\SMTray.exe" [2002-11-08 98304]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-04-28 323584]
"zBrowser Launcher"="c:\programmi\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 919016]
"SystemProtect"="c:\programmi\System Protect\SysProtect_Tray.exe" [2009-01-21 1223680]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]

c:\documents and settings\GianCarlo\Menu Avvio\Programmi\Esecuzione automatica\
Mozilla Firefox (2).lnk - c:\programmi\Mozilla Firefox\firefox.exe [2008-5-31 908248]
Mozilla Thunderbird (2).lnk - c:\programmi\Mozilla Thunderbird\thunderbird.exe [2008-6-10 8318056]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Logitech Desktop Messenger.lnk - c:\programmi\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2003-10-20 169472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoPopUpsOnBoot"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 22:46 57344 ----a-w- c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 ----a-w- c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-06-10 19:33 133104 ----atw- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\GianCarlo\\Dati applicazioni\\SopCast\\adv\\SopAdver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=

R2 SP_Service;System Protect Deletion Prevention Service;c:\programmi\System Protect\SysProtect_srv.exe [21/01/2009 21.47.57 598528]
R3 sp_prot;System Protect Filter Driver;c:\windows\system32\drivers\sp_prot.sys [21/01/2009 21.47.57 12288]
S2 gupdate1c9a4c8197b2e8c;Google Update Service (gupdate1c9a4c8197b2e8c);c:\programmi\Google\Update\GoogleUpdate.exe [14/03/2009 18.12.41 133104]
S2 PTK Live Update-FIGHTERS-18665827;PTK Live Update-FIGHTERS-18665827;c:\programmi\Fighters\updateservice.exe --> c:\programmi\Fighters\updateservice.exe [?]
S2 PTK Scanner-FIGHTERS-18665827;PTK Scanner-FIGHTERS-18665827;c:\programmi\Fighters\ScannerService.exe --> c:\programmi\Fighters\ScannerService.exe [?]
S2 PTK SharedAccess-FIGHTERS-18665827;PTK SharedAccess-FIGHTERS-18665827;c:\programmi\Fighters\configservice.exe --> c:\programmi\Fighters\configservice.exe [?]
S3 AVFSFilter;AVFSFilter;c:\windows\system32\DRIVERS\avfsfilter.sys --> c:\windows\system32\DRIVERS\avfsfilter.sys [?]
S3 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [29/10/2009 20.34.46 38976]
S3 Vfscan;Vfscan;c:\windows\system32\drivers\vffilter.sys [18/11/2008 10.01.46 15496]
S4 RWSHJBWXB;RWSHJBWXB; [x]
.
Contenuto della cartella 'Scheduled Tasks'

2010-01-10 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-04 18:58]

2010-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-14 17:12]

2010-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-14 17:12]

2010-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-630328440-682003330-1003Core.job
- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-10 19:33]

2010-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-630328440-682003330-1003UA.job
- c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-10 19:33]
.
.
------- Scansione supplementare -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: eBay Search
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\GianCarlo\Dati applicazioni\Mozilla\Firefox\Profiles\vadju7mi.default\
FF - prefs.js: browser.startup.homepage - hxxp://tin.alice.it/indexbb.html
FF - component: c:\documents and settings\GianCarlo\Dati applicazioni\Mozilla\Firefox\Profiles\vadju7mi.default\extensions\{4b897551-0a2b-4159-99e7-3cd721caec78}\components\FFExternalAlert.dll
FF - plugin: c:\documents and settings\GianCarlo\Dati applicazioni\Mozilla\Firefox\Profiles\vadju7mi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll

---- FIREFOX POLICIES ----





pref(dom.disable_open_during_load, true);
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

AddRemove-Advanced SystemCare 3_is1 - c:\programmi\IObit\Advanced SystemCare 3\unins000.exe
AddRemove-IObit Security 360_is1 - c:\programmi\IObit\IObit Security 360\unins000.exe
AddRemove-Smart Defrag_is1 - c:\programmi\IObit\IObit SmartDefrag\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-10 09:57
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(3212)
c:\progra~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\programmi\File comuni\Microsoft Shared\Web Components\10\1040\OWCI10.DLL
c:\programmi\Logitech\iTouch\iTchHk.dll
c:\programmi\File comuni\Logitech\Scrolling\LgMsgHk.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\windows\System32\Ati2evxx.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
c:\programmi\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-10 10:00:37 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-10 09:00
ComboFix2.txt 2010-01-09 17:18
ComboFix3.txt 2009-09-16 17:53
ComboFix4.txt 2009-08-22 14:27
ComboFix5.txt 2010-01-10 08:47

Pre-Run: 23.329.447.936 byte disponibili
Post-Run: 23.234.424.832 byte disponibili

Current=5 Default=5 Failed=4 LastKnownGood=1 Sets=1,4,5,6
- - End Of File - - E05E71A92DC58BDC885B18744EC14D03


r16
Inviato: Sunday, January 10, 2010 1:51:52 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ok.
Riscontri problemi?
Posta un log di HJT.
giancarlo52
Inviato: Sunday, January 10, 2010 1:54:21 PM
Rank: AiutAmico

Iscritto dal : 1/4/2010
Posts: 118
Nessun problema al momento, ecco il log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13.55.16, on 10/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\Programmi\System Protect\SysProtect_srv.exe
C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\Logitech\iTouch\iTouch.exe
C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmi\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmi\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SystemProtect] C:\Programmi\System Protect\SysProtect_Tray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Mozilla Firefox (2).lnk = C:\Programmi\Mozilla Firefox\firefox.exe
O4 - Startup: Mozilla Thunderbird (2).lnk = C:\Programmi\Mozilla Thunderbird\thunderbird.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmi\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O23 - Service: Avira AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c9a4c8197b2e8c) (gupdate1c9a4c8197b2e8c) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: PTK Live Update-FIGHTERS-18665827 - Unknown owner - C:\Programmi\Fighters\updateservice.exe (file missing)
O23 - Service: PTK Scanner-FIGHTERS-18665827 - Unknown owner - C:\Programmi\Fighters\ScannerService.exe (file missing)
O23 - Service: PTK SharedAccess-FIGHTERS-18665827 - Unknown owner - C:\Programmi\Fighters\configservice.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Protect Deletion Prevention Service (SP_Service) - Xacti Corporation - C:\Programmi\System Protect\SysProtect_srv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7482 bytes

fdaccc
Inviato: Sunday, January 10, 2010 2:05:25 PM

Rank: AiutAmico

Iscritto dal : 12/12/2009
Posts: 2,114
Un consiglio da amico ?
disinstalla spybot
reinstallalo e nel setup fai attenzione a NON spuntare la voce relativa al Tea Timer

r16
Inviato: Sunday, January 10, 2010 2:11:02 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Disattiva il ripristino configurazione di sistema, e tienilo disattivato, fino alla soluzione del problema http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121

Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\GianCarlo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmi\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O23 - Service: PTK Live Update-FIGHTERS-18665827 - Unknown owner - C:\Programmi\Fighters\updateservice.exe (file missing)
O23 - Service: PTK Scanner-FIGHTERS-18665827 - Unknown owner - C:\Programmi\Fighters\ScannerService.exe (file missing)
O23 - Service: PTK SharedAccess-FIGHTERS-18665827 - Unknown owner - C:\Programmi\Fighters\configservice.exe (file missing)

N.B:
Se le voci 023 non si eliminano, prova in Modalità provvisoria.

Fai una pulizia con CCleaner. (registro compreso.

Poi:
Start\Esegui\copia e incolla la stringa %temp% clicca su Ok, svuota la cartella temp. (non eliminare la cartella)
Poi:
Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO
Poi:
Lancia Hijackthis e pulisci gli ADS in questo modo:
clicca sulla voce Open the misc tool section
clicca su Open ads spy
togli la spunta alla voce Quick scan (windows base folder only)
clicca su Scan.
Aspetta pazientemente la fine della scansione.
se venissero rilevati ADS, spunta tutte (senza paura) le caselline e clicca su Remove selected

Riattiva il ripristino configurazione di sistema e, se tutto è a posto, creane uno nuovo.
giancarlo52
Inviato: Sunday, January 10, 2010 2:55:40 PM
Rank: AiutAmico

Iscritto dal : 1/4/2010
Posts: 118
Ho seguito esattamente le tue istruzioni, ora posso dire di essere a posto?
panchoz
Inviato: Sunday, January 10, 2010 3:02:16 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Solo x R16,

a proposito di Spybot.

Il programma non è presente nel 1° log HiJackThis.

Poi durante l'excursus del topic ho ipotizzato l'uso di Spybot senza però prescriverlo, infatti non ho allegato il link di Aiutamici che conosco alla perfezione come sai.

Mi dispiace per Giancarlo se non volendo l'ho confuso. E pensare che questa è stata la discussione più tranquilla...degli ultimi tempi!


Buona Domenica.
panchoz
Inviato: Sunday, January 10, 2010 10:04:07 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Giancarlo52,

oggi pensavo e ripensavo a questa discussione che abbiamo vissuto, almeno in parte, insieme.

Mi son fatto l'idea che sei un ... (non ridere Drool ) un ipocondriaco informatico.

Non è con tanti, tantissimi anti-virus-malware-spyware-ecc che ci sente sicuri e protetti, ma con quelli appropriati e nel giusto dosaggio!

Resta con noi, faremo molta strada e fra qualche mesetto aiuterai tu stesso.


Shhh Prossima tappa, sarai introdotto in Linux ...assai meno sensibile ai virus!
r16
Inviato: Sunday, January 10, 2010 10:41:05 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
giancarlo52 ha scritto:
Ho seguito esattamente le tue istruzioni, ora posso dire di essere a posto?

Si, sei a posto.
Ma dovresti essertene accorto anche tu, che il pc funziona, (o almeno dovrebbe) meglio.
Ciao!
giancarlo52
Inviato: Sunday, January 10, 2010 11:06:58 PM
Rank: AiutAmico

Iscritto dal : 1/4/2010
Posts: 118
Ringrazio te e tutti gli altri che sono intervenuti, senza il vostro aiuto, in particolare il tuo, non avrei saputo fare nulla
r16
Inviato: Sunday, January 10, 2010 11:12:22 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Di niente.
Ciao!Drool
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.