allora ho eseguito tutte le tue istruzioni.
Ecco il log fatto con combofix:
ComboFix 08-07-11.1 - Principale 2008-07-12 15.47.52.1 -x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.173 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Principale\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\Documents and Settings\Principale\Impostazioni locali\Dati applicazioni\ntcigf.dat
C:\Documents and Settings\Principale\Impostazioni locali\Dati applicazioni\ntcigf.exe
C:\Documents and Settings\Principale\Impostazioni locali\Dati applicazioni\ntcigf_nav.dat
C:\Documents and Settings\Principale\Impostazioni locali\Dati applicazioni\ntcigf_navps.dat
C:\Programmi\instant access
C:\Programmi\instant access\Center\Fun-Games.lnk
C:\Programmi\instant access\Multi\20080706150703\Common\module.php
C:\Programmi\instant access\Multi\20080706150703\js\js_api_dialer.php
C:\Programmi\instant access\Multi\20080706150703\medias\button1.gif
C:\Programmi\instant access\Multi\20080706150703\medias\button2.gif
C:\Programmi\instant access\Multi\20080706150703\medias\button3.gif
C:\Programmi\instant access\Multi\20080706150703\medias\button4.gif
C:\Programmi\instant access\Multi\20080706150703\medias\dialer.ico
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\drivers\csrss.exe
C:\WINDOWS\system32\drivers\reg.exe
C:\WINDOWS\system32\drivers\smss.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\oeminfo.ini
C:\WINDOWS\system32\uninstall.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-06-12 al 2008-07-12 )))))))))))))))))))))))))))))))))))
.
2008-07-12 14:09 . 2005-12-10 06:55 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-07-12 14:09 . 2005-12-10 06:36 <DIR> d--h----- C:\Documents and Settings\Administrator\Risorse di stampa
2008-07-12 14:09 . 2005-12-10 06:36 <DIR> d--h----- C:\Documents and Settings\Administrator\Risorse di rete
2008-07-12 14:09 . 2005-12-10 07:03 <DIR> dr------- C:\Documents and Settings\Administrator\Preferiti
2008-07-12 14:09 . 2005-12-10 06:36 <DIR> d--h----- C:\Documents and Settings\Administrator\Modelli
2008-07-12 14:09 . 2005-12-10 06:36 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Avvio
2008-07-12 14:09 . 2005-12-10 06:36 <DIR> d--h----- C:\Documents and Settings\Administrator\Impostazioni locali
2008-07-12 14:09 . 2005-12-10 07:03 <DIR> dr------- C:\Documents and Settings\Administrator\Documenti
2008-07-12 14:09 . 2005-12-10 07:05 <DIR> d-------- C:\Documents and Settings\Administrator\Dati applicazioni\Symantec
2008-07-12 14:09 . 2005-12-10 07:13 <DIR> d-------- C:\Documents and Settings\Administrator\Dati applicazioni\Intel
2008-07-12 14:09 . 2005-12-10 06:36 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dati applicazioni
2008-07-12 14:09 . 2008-07-12 14:09 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-12 13:59 . 2008-07-12 13:59 <DIR> d-------- C:\VEXPLITE
2008-07-12 13:59 . 2008-03-17 19:23 39,808 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-07-12 12:03 . 2008-07-12 12:03 <DIR> d-------- C:\Programmi\Trend Micro
2008-07-11 22:33 . 2008-07-11 22:33 <DIR> d-------- C:\Programmi\PopUp Killer
2008-07-11 22:33 . 2008-07-11 22:32 720,896 --a------ C:\WINDOWS\iun6002.exe
2008-07-11 21:23 . 2008-07-11 21:23 284 --a------ C:\WINDOWS\wininit.ini
2008-07-11 20:42 . 2008-07-11 20:42 <DIR> d-------- C:\Programmi\Spybot - Search & Destroy
2008-07-11 20:42 . 2008-07-11 20:42 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-07-11 12:34 . 2008-07-11 12:34 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\SITEguard
2008-07-11 12:30 . 2008-07-11 12:30 <DIR> d-------- C:\Programmi\File comuni\iS3
2008-07-11 12:30 . 2008-07-11 12:30 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\STOPzilla!
2008-07-09 12:39 . 2008-07-09 12:39 <DIR> d-------- C:\Programmi\Tacmi
2008-06-20 19:39 . 2008-06-20 19:39 247,296 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 12:44 . 2008-06-20 12:44 138,368 --------- C:\WINDOWS\system32\dllcache\afd.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-20 17:39 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:39 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 08:30 --------- d-----w C:\Programmi\Macromedia
2008-06-03 08:30 --------- d-----w C:\Programmi\File comuni\Macromedia
2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:14 1,292,800 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:14 1,292,800 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-23 20:16 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:42 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:42 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-20 19:00 702,644 ----a-w C:\Programmi\JUN2007_d3dx10_34_x64.cab
2007-06-20 19:00 702,072 ----a-w C:\Programmi\JUN2007_d3dx10_34_x86.cab
2007-06-20 19:00 45,302 ----a-w C:\Programmi\dxdllreg_x86.cab
2007-06-20 19:00 200,722 ----a-w C:\Programmi\JUN2007_XACT_x64.cab
2007-06-20 19:00 156,509 ----a-w C:\Programmi\JUN2007_XACT_x86.cab
2007-06-20 19:00 1,611,374 ----a-w C:\Programmi\JUN2007_d3dx9_34_x64.cab
2007-06-20 19:00 1,610,886 ----a-w C:\Programmi\JUN2007_d3dx9_34_x86.cab
2006-01-24 15:08 0 ----a-w C:\Documents and Settings\Principale\Dati applicazioni\wklnhst.dat
1999-03-10 11:53 99,840 ----a-w C:\Programmi\File comuni\IRAABOUT.DLL
1998-12-08 22:53 70,144 ----a-w C:\Programmi\File comuni\IRAMDMTR.DLL
1998-12-08 22:53 48,640 ----a-w C:\Programmi\File comuni\IRALPTTR.DLL
1998-12-08 22:53 31,744 ----a-w C:\Programmi\File comuni\IRAWEBTR.DLL
1998-12-08 22:53 186,368 ----a-w C:\Programmi\File comuni\IRAREG.DLL
1998-12-08 22:53 17,920 ----a-w C:\Programmi\File comuni\IRASRIAL.DLL
.
------- Sigcheck -------
2004-08-19 14:00 544256 e6f62282ebaa63ba07fa2dc7198b8d0d C:\WINDOWS\system32\winlogon.exe
2004-08-19 14:00 504832 4166454e2bcfcc20d1b8a5ac9feab243 C:\WINDOWS\VistaMizer\old\winlogon.exe
2007-02-28 18:02 2224384 1c7e8c998dc5ceefabe13654283fe8bd C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 18:02 2224384 1c7e8c998dc5ceefabe13654283fe8bd C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2007-02-28 18:02 2061312 49baea1d9379df8cd897aff9f49bc9de C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2005-03-02 19:06 2060544 8f485cf9683f1220ba27d10281052fce C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2005-03-02 19:12 2060672 de16030e8209fd96eeb06d9e3d8c84a8 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 19:44 2063104 0943f29440085d86a1b9b9c2356b45b4 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 18:06 2063104 f89d8e24fbe047506d60b850d00bdee3 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2004-08-19 14:00 2060544 4dc3a3626b02c39aa69aae6f64bfbc2d C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2007-02-28 18:02 2061312 49baea1d9379df8cd897aff9f49bc9de C:\WINDOWS\VistaMizer\old\ntkrnlpa.exe
2006-12-19 19:22 2061312 7373bd87175412862cf9e534c6aa5ec9 C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 18:02 2347136 df615fac8a0b7a29533d8bbfb240c5f2 C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 18:02 2347136 df615fac8a0b7a29533d8bbfb240c5f2 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-02-28 18:02 2184064 5ec517cc0865808df80d2184b0131d27 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2005-03-02 19:07 2183040 84e6643db22c06128576afbf89dfee70 C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2005-03-02 19:12 2183296 c120a33c71e706545cf26d6276bc0344 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 19:44 2185728 ecb771f4cc4b5cd2b19b294fbd56f75d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 18:06 2185856 763ea08993b467a3af048ef185b1f805 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2004-08-19 14:00 2184704 4591cf1f202181113de2996e79a2905a C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2007-02-28 18:02 2184064 5ec517cc0865808df80d2184b0131d27 C:\WINDOWS\VistaMizer\old\ntoskrnl.exe
2006-12-19 19:22 2184064 b33a2a0e76d3a2faa044b197e345458c C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2004-08-19 14:00 25088 40de117b6ccfc031d2dc8b73d82020cf C:\WINDOWS\system32\ctfmon.exe
2004-08-19 14:00 15360 5b33b4265966ee063c7fbea28958d9c2 C:\WINDOWS\VistaMizer\old\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 14:00 25088]
"Yodm3D"="C:\Documents and Settings\Principale\Desktop\Film\Yodm3D.exe" [2007-04-04 22:11 2339840]
"EPSON Stylus DX4400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 07:01 180736]
"SpybotSD TeaTimer"="C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-18 23:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-18 23:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-18 23:10 114688]
"SynTPEnh"="C:\Programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-08-18 22:07 737369]
"Power_Gear"="C:\Programmi\ASUS\Power4 Gear\BatteryLife.exe" [2005-06-16 15:48 86016]
"IntelZeroConfig"="C:\Programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2005-07-22 22:46 401408]
"IntelWireless"="C:\Programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2005-07-22 22:47 385024]
"EOUApp"="C:\Programmi\Intel\Wireless\Bin\EOUWiz.exe" [2005-07-22 22:51 356352]
"RemoteControl"="C:\Programmi\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"DSLSTATEXE"="C:\Program Files\D-Link\DSL-200\dslstat.exe" [2004-11-26 05:05 356352]
"DSLAGENTEXE"="C:\Program Files\D-Link\DSL-200\dslagent.exe" [2004-11-26 05:05 16384]
"Hcontrol"="C:\WINDOWS\Hcontrol.exe" [2002-01-08 15:22 53248]
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2006-07-30 22:07 180269]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40 155648]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"PopUpKiller"="C:\Programmi\PopUp Killer\popupkiller.EXE" [2002-03-23 19:09 108032]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-07-12 14:02 245760]
"Collegamento alla pagina delle proprietà di High Definition Audio"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-08-18 02:38 86016 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2005-07-26 04:54 2806784 C:\WINDOWS\ALCWZRD.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 14:00 25088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2005-07-22 22:46 110592 C:\Programmi\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\LimeWire\\LimeWire.exe"=
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 19:23]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 NwSapAgent;Agente SAP;C:\WINDOWS\system32\svchost.exe [2004-08-19 14:00]
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-07-12 14:02]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D.sys [2004-07-06 19:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53cf13fc-8f5b-11db-b816-001346300101}]
\Shell\AutoRun\command - oufddh.exe
\Shell\explore\Command - oufddh.exe
\Shell\open\Command - oufddh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bb8f767a-2fc9-11dd-bd8a-001346300101}]
\Shell\Auto\command - UFO.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
*Newly Created Service* - CATCHME
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-12 15:51:33
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-07-12 15:52:46
ComboFix-quarantined-files.txt 2008-07-12 13:52:40
18 Directory 20,996,882,432 byte disponibili
20 Directory 21,208,170,496 byte disponibili
195 --- E O F --- 2008-07-11 10:15:41
Ecco l'ultimo log fatto con hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15.59.16, on 12/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmi\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programmi\Intel\Wireless\Bin\OProtSvc.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\VEXPLITE\viritsvc.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\ASUS\Power4 Gear\BatteryLife.exe
C:\Programmi\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmi\Intel\Wireless\Bin\EOUWiz.exe
C:\Programmi\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\WINDOWS\Hcontrol.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\PopUp Killer\popupkiller.EXE
C:\VEXPLITE\MONLITE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ATKOSD.exe
C:\Documents and Settings\Principale\Desktop\Film\Yodm3D.exe
C:\Programmi\ASUS\Asus ChkMail\ChkMail.exe
C:\Programmi\Microsoft Office\Office\1040\OLFSNT40.EXE
C:\Programmi\Java\jre1.6.0_03\bin\jucheck.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmi\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Collegamento alla pagina delle proprietà di High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Programmi\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Programmi\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmi\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Programmi\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\ASUSTeK\ASUSDVD\PDVDServ.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\Hcontrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PopUpKiller] C:\Programmi\PopUp Killer\popupkiller.EXE
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yodm3D] C:\Documents and Settings\Principale\Desktop\Film\Yodm3D.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\WINDOWS\TEMP\E_SB0.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://messenger.zone.msn.com/binary/ZIntro.cab55579.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{221BB18A-23EA-41E1-9226-76AEAB9D4D16}: NameServer = 85.37.17.58 85.38.28.94
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas
www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
--
End of file - 9405 bytes
Per ora nn stanno apparendo le finestre...speriamo in bene...grazie del tuo aiuto e scusa se ti ho fatto perdere del tempo,grazie ankora