aiutatemi ve ne prego...non so come liberarmi di loro in modo definitivo...ma senza formattare sono come l'erba cattiva....allego log....
Logfile of HijackThis v1.99.1
Scan saved at 16.44.41, on 18/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\MalwareRemover.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.tim.it/R3 - Default URLSearchHook is missing
O2 - BHO: Class - {0070A397-436C-1BBD-AED0-655794276F6E} - C:\WINDOWS\idftu1.dll (file missing)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O4 - HKLM\..\Run: [MSGlobal] C:\WINDOWS\system32\Idro.exe
O4 - HKLM\..\Run: [MicrosoftFirewall] C:\WINDOWS\system32\MSFirewall.exe
O4 - HKLM\..\Run: [SmilEmail] C:\Programmi\SmilEmail\SmilEmail.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Programmi\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [MSMalwareKit] C:\WINDOWS\system32\MalwareRemover.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ScaricaMP3] C:\Documents and Settings\Administrator\Dati applicazioni\ScaricaMP3[1].exe t
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [lateshow.exe] C:\WINDOWS\system32\lateshow.exe
O4 - HKCU\..\Run: [wke.exe] C:\WINDOWS\system32\wke.exe
O9 - Extra button: ScaricaMP3 - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\Administrator\Dati applicazioni\ScaricaMP3[1].exe
O15 - Trusted Zone:
www.acquadirose.comO15 - Trusted Zone:
www.cisiamodibrutto.comO15 - Trusted Zone:
www.cywanstorage.bizO15 - Trusted Zone:
www.forteforte.comO15 - Trusted Zone:
www.gooogle.bzO15 - Trusted Zone:
www.nanobyte.bizO15 - Trusted Zone:
www.phishingfix.bizO15 - Trusted Zone:
www.playmore.bizO15 - Trusted Zone:
www.preferiti-windows.comO15 - Trusted Zone:
www.ricercadoppia.comO15 - Trusted Zone:
www.scalalap.comO15 - Trusted Zone:
www.smilemail.bizO15 - Trusted Zone:
www.tuttaqualita.comO16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.com/pages/MsnInstC.cabO16 - DPF: {3A4DCD02-A451-4799-9E1C-AC0D4F769A97} -
http://www.cywanstorage.biz/PHFX/MSPhish.exeO16 - DPF: {3F5E67E1-81E6-4487-BF6F-07941A080BAB} -
http://www.cywanstorage.biz/SUPERINSTALLER/messenger.exeO16 - DPF: {5C626A4F-28A7-4A29-9EC8-6BE20FC70424} -
http://www.playmore.biz/pop/amarcord/Amarcord.exeO16 - DPF: {9CAEE012-5DFF-11DB-8373-B622A1EF5492} -
http://www.cywanstorage.biz/SUPERINSTALLER/Amarcord.exeO16 - DPF: {EA5B2F8A-2094-47A1-ADC5-373E93EAF936} -
http://www.cywanstorage.biz/DRT65/IBWire.exeO16 - DPF: {EA8804CE-A2F0-4773-89B8-1E5168A1D8D7} -
http://www.playmore.biz/pop/smile.exeO16 - DPF: {EB5CDBC6-DBA4-48BC-B888-5E2CFF9DF3CD} -
http://www.playmore.biz/pop/MSF.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe