ho fatto come mi hai detto, tranne aggiornamento hijackthis non lo ho trovato (sono novellino......)
comunque ecco il log combofix:
ComboFix 08-11-18.A2 - enrico 2008-11-19 22:02:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.561 [GMT 1:00]
Eseguito da: c:\documents and settings\enrico\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\enrico\Dati applicazioni\inst.exe
C:\setup.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-10-19 al 2008-11-19 )))))))))))))))))))))))))))))))))))
.
2008-11-19 21:01 . 2008-11-19 21:42 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2008-11-19 21:01 . 2008-11-19 21:01 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\SUPERAntiSpyware.com
2008-11-19 21:01 . 2008-11-19 21:01 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-11-19 21:00 . 2008-11-19 21:00 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di stampa
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di rete
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d-------- c:\documents and settings\Administrator\Preferiti
2008-11-18 21:42 . 2007-05-03 16:44 <DIR> d--h----- c:\documents and settings\Administrator\Modelli
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> dr------- c:\documents and settings\Administrator\Menu Avvio
2008-11-18 21:42 . 2008-11-19 22:04 <DIR> d--h----- c:\documents and settings\Administrator\Impostazioni locali
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> d-------- c:\documents and settings\Administrator\Documenti
2008-11-18 21:42 . 2007-05-03 17:37 <DIR> dr-h----- c:\documents and settings\Administrator\Dati applicazioni
2008-11-18 21:42 . 2008-11-18 21:42 <DIR> d-------- c:\documents and settings\Administrator
2008-11-18 21:36 . 2008-11-18 21:36 <DIR> d-------- c:\programmi\Trend Micro
2008-11-18 21:23 . 2008-11-18 21:23 <DIR> d-------- c:\programmi\CCleaner
2008-11-18 17:44 . 2008-11-18 17:45 <DIR> d-------- c:\programmi\ReflexiveArcade
2008-11-18 17:44 . 2008-11-18 17:46 <DIR> d-------- c:\programmi\Aqua Pearls
2008-11-15 22:05 . 2008-11-15 22:05 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-11-15 22:05 . 2008-11-15 22:05 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\Malwarebytes
2008-11-15 22:05 . 2008-11-15 22:05 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-11-15 22:05 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-15 22:05 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-13 16:42 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-13 16:41 . 2008-09-04 18:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 22:18 . 2008-11-12 22:20 <DIR> d-------- c:\programmi\eToro
2008-11-08 22:08 . 2008-11-08 22:08 <DIR> d--h----- c:\windows\PIF
2008-11-01 20:01 . 2008-11-01 20:01 <DIR> d-------- c:\programmi\K-Lite Codec Pack
2008-11-01 19:41 . 2008-07-12 08:18 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2008-11-01 19:41 . 2008-07-12 08:18 1,493,528 --a------ c:\windows\system32\D3DCompiler_39.dll
2008-11-01 19:41 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-11-01 19:41 . 2008-07-31 10:40 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2008-11-01 19:41 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-01 19:41 . 2008-07-12 08:18 467,984 --a------ c:\windows\system32\d3dx10_39.dll
2008-11-01 19:41 . 2008-07-31 10:41 238,088 --a------ c:\windows\system32\xactengine3_2.dll
2008-11-01 19:41 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-01 19:41 . 2008-07-31 10:41 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2008-11-01 19:41 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-01 19:41 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-01 19:38 . 2008-11-01 19:38 <DIR> d-------- c:\windows\Logs
2008-11-01 14:33 . 2008-11-01 19:48 <DIR> d-------- c:\documents and settings\enrico\Dati applicazioni\Media Player Classic
2008-10-23 19:29 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-22 19:59 . 2008-10-22 19:59 <DIR> d-------- c:\documents and settings\manuela\Dati applicazioni\DivX
2008-10-21 20:45 . 2008-10-21 20:45 42,771 --a------ c:\windows\CSTBox.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 20:50 --------- d---a-w c:\documents and settings\All Users\Dati applicazioni\TEMP
2008-11-12 20:54 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2008-11-10 20:53 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Motive
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 19:45 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\Canon
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-07 14:09 --------- d-----w c:\programmi\NOS
2008-10-07 14:09 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\NOS
2008-10-06 17:29 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\ArcSoft
2008-10-06 17:28 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\ArcSoft
2008-10-06 17:26 --------- d-----w c:\programmi\File comuni\Adobe
2008-10-06 17:09 --------- d--h--w c:\programmi\InstallShield Installation Information
2008-10-06 17:09 --------- d-----w c:\programmi\File comuni\ArcSoft
2008-10-06 17:09 --------- d-----w c:\programmi\ArcSoft
2008-10-06 17:08 --------- d-----w c:\programmi\Philips
2008-10-06 17:08 --------- d-----w c:\documents and settings\enrico\Dati applicazioni\InstallShield
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-29 19:05 --------- d-----w c:\documents and settings\manuela\Dati applicazioni\Nokia Multimedia Player
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\divx.dll
2008-09-15 15:24 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-26 07:57 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-10 19:17 47,360 ----a-w c:\documents and settings\enrico\Dati applicazioni\pcouffin.sys
2008-04-14 02:14 786,432 --sh--r c:\windows\system32\WindowANTasdIVRI.exe
2008-05-22 17:39 32,768 -csha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008052220080523\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 483,328 2004-12-14 00:12:02 c:\programmi\Adobe\Acrobat 7.0\Distillr\bak\Acrotray.exe
----a-w 483,328 2006-01-12 19:52:32 c:\programmi\Adobe\Acrobat 7.0\Distillr\AcroTray.exe
-c--a-w 155,648 2006-01-12 13:40:44 c:\programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe
-c--a-w 139,264 2006-11-16 17:04:20 c:\programmi\File comuni\Ahead\Lib\bak\NMBgMonitor.exe
-c--a-w 31,016 2006-10-26 22:47:42 c:\programmi\Microsoft Office\Office12\bak\GrooveMonitor.exe
-c--a-w 227,328 2007-03-23 11:20:52 c:\programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe
----a-w 227,328 2007-03-23 11:20:52 c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
-c--a-w 49,152 2003-05-08 10:00:58 c:\programmi\ScanSoft\OmniPageSE2.0\bak\OpwareSE2.exe
-c--a-w 15,360 2004-08-19 13:39:36 c:\windows\system32\bak\ctfmon.exe
----a-w 15,360 2008-04-14 02:14:03 c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"BitTorrent DNA"="c:\programmi\BitTorrent_DNA\dna.exe" [N/A]
"BitComet"="f:\bitcomet\BitComet.exe" [N/A]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2005-10-24 307200]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-29 68856]
"H/PC Connection Agent"="F:\wcescomm.exe" [2005-08-05 1200128]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-11-17 1805552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Acrobat Assistant 7.0"="c:\programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 483328]
"OpwareSE2"="c:\programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [N/A]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"HP Software Update"="f:\programmi\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-03-28 413696]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"ArcSoft Connection Service"="c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AliceRE_McciTrayApp"="c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe" [2006-11-21 936960]
"Malwarebytes' Anti-Malware"="c:\programmi\Malwarebytes' Anti-Malware\mbamgui.exe" [2008-10-22 399504]
"VTTimer"="VTTimer.exe" [2003-05-07 c:\windows\system32\VTTimer.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"nwiz"="nwiz.exe" [2007-09-17 c:\windows\system32\nwiz.exe]
"Windowfdgfds DasdLL fgfdg Verifier"="WindowANTasdIVRI.exe" [2008-04-14 c:\windows\system32\WindowANTasdIVRI.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Windowfdgfds DasdLL fgfdg Verifier"="WindowANTasdIVRI.exe" [2008-04-14 c:\windows\system32\WindowANTasdIVRI.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"f:\rapimgr.exe"= f:\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"f:\wcescomm.exe"= f:\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"f:\wcesmgr.exe"= f:\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\emule\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"2263:TCP"= 2263:TCP:messenger
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-04 78416]
R2 ACDaemon;ArcSoft Connect Daemon;c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe [2008-10-06 102712]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-04 20560]
R2 MBAMService;MBAMService;"c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe" [2008-11-15 170640]
R3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys [2008-11-15 15504]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe []
S3 MEMSWEEP2;MEMSWEEP2; []
S4 hpt3xx;hpt3xx; []
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
2007-12-14 c:\windows\Tasks\abmjmpu.job
- c:\windows\system32\netqqzwm.exe []
2007-12-05 c:\windows\Tasks\abrplmzg.job
- c:\windows\system32\netqqzwm.exe []
2007-07-06 c:\windows\Tasks\aibhpgy.job
- c:\windows\system32\netqqzwm.exe []
2007-08-31 c:\windows\Tasks\akgblg.job
- c:\windows\system32\netqqzwm.exe []
2008-01-27 c:\windows\Tasks\aleoagwt.job
- c:\windows\system32\netqqzwm.exe []
2007-12-09 c:\windows\Tasks\ank.job
- c:\windows\system32\netqqzwm.exe []
2007-12-03 c:\windows\Tasks\aob.job
- c:\windows\system32\netqqzwm.exe []
2008-01-20 c:\windows\Tasks\aqrgwoxx.job
- c:\windows\system32\netqqzwm.exe []
2007-09-07 c:\windows\Tasks\awhjj.job
- c:\windows\system32\netqqzwm.exe []
2008-02-19 c:\windows\Tasks\aycln.job
- c:\windows\system32\netqqzwm.exe []
2008-01-21 c:\windows\Tasks\bbigva.job
- c:\windows\system32\netqqzwm.exe []
2007-12-16 c:\windows\Tasks\bcpdi.job
- c:\windows\system32\netqqzwm.exe []
2007-10-16 c:\windows\Tasks\bhqzcnda.job
- c:\windows\system32\netqqzwm.exe []
2007-12-11 c:\windows\Tasks\bqtbw.job
- c:\windows\system32\netqqzwm.exe []
2007-07-13 c:\windows\Tasks\bujcnx.job
- c:\windows\system32\netqqzwm.exe []
2007-07-16 c:\windows\Tasks\bwinnt.job
- c:\windows\system32\netqqzwm.exe []
2008-01-23 c:\windows\Tasks\cbffaztp.job
- c:\windows\system32\netqqzwm.exe []
2007-08-30 c:\windows\Tasks\ccmchju.job
- c:\windows\system32\netqqzwm.exe []
2008-01-31 c:\windows\Tasks\cgh.job
- c:\windows\system32\netqqzwm.exe []
2007-11-16 c:\windows\Tasks\cmvcuxx.job
- c:\windows\system32\netqqzwm.exe []
2007-10-10 c:\windows\Tasks\ctid.job
- c:\windows\system32\netqqzwm.exe []
2007-09-10 c:\windows\Tasks\cvmh.job
- c:\windows\system32\netqqzwm.exe []
2008-01-31 c:\windows\Tasks\ddj.job
- c:\windows\system32\netqqzwm.exe []
2008-01-24 c:\windows\Tasks\deadlquf.job
- c:\windows\system32\netqqzwm.exe []
2008-01-25 c:\windows\Tasks\dgncrj.job
- c:\windows\system32\netqqzwm.exe []
2007-12-05 c:\windows\Tasks\dlfpt.job
- c:\windows\system32\netqqzwm.exe []
2007-06-28 c:\windows\Tasks\dlsmca.job
- c:\windows\system32\netqqzwm.exe []
2007-12-07 c:\windows\Tasks\dsnbzvbm.job
- c:\windows\system32\netqqzwm.exe []
2007-12-08 c:\windows\Tasks\dvabcl.job
- c:\windows\system32\netqqzwm.exe []
2007-09-06 c:\windows\Tasks\dxlfteg.job
- c:\windows\system32\netqqzwm.exe []
2007-10-26 c:\windows\Tasks\eakar.job
- c:\windows\system32\netqqzwm.exe []
2008-01-24 c:\windows\Tasks\ejoxnaph.job
- c:\windows\system32\netqqzwm.exe []
2007-07-08 c:\windows\Tasks\elha.job
- c:\windows\system32\netqqzwm.exe []
2007-12-10 c:\windows\Tasks\erep.job
- c:\windows\system32\netqqzwm.exe []
2008-02-15 c:\windows\Tasks\errsj.job
- c:\windows\system32\netqqzwm.exe []
2007-10-14 c:\windows\Tasks\erxk.job
- c:\windows\system32\netqqzwm.exe []
2007-11-09 c:\windows\Tasks\exermd.job
- c:\windows\system32\netqqzwm.exe []
2007-08-28 c:\windows\Tasks\exqy.job
- c:\windows\system32\netqqzwm.exe []
2008-01-29 c:\windows\Tasks\fapgx.job
- c:\windows\system32\netqqzwm.exe []
2007-09-16 c:\windows\Tasks\fla.job
- c:\windows\system32\netqqzwm.exe []
2008-02-12 c:\windows\Tasks\flin.job
- c:\windows\system32\netqqzwm.exe []
2007-12-12 c:\windows\Tasks\fnw.job
- c:\windows\system32\netqqzwm.exe []
2008-01-13 c:\windows\Tasks\ftfwzr.job
- c:\windows\system32\netqqzwm.exe []
2008-02-13 c:\windows\Tasks\fyse.job
- c:\windows\system32\netqqzwm.exe []
2007-10-16 c:\windows\Tasks\fyusrb.job
- c:\windows\system32\netqqzwm.exe []
2007-12-31 c:\windows\Tasks\fztcjz.job
- c:\windows\system32\netqqzwm.exe []
2007-10-18 c:\windows\Tasks\gbgdtjs.job
- c:\windows\system32\netqqzwm.exe []
2007-11-03 c:\windows\Tasks\gckccpbw.job
- c:\windows\system32\netqqzwm.exe []
2008-01-19 c:\windows\Tasks\ggdfi.job
- c:\windows\system32\netqqzwm.exe []
2008-01-08 c:\windows\Tasks\gonkaonz.job
- c:\windows\system32\netqqzwm.exe []
2008-02-17 c:\windows\Tasks\guux.job
- c:\windows\system32\netqqzwm.exe []
2007-12-27 c:\windows\Tasks\hbjef.job
- c:\windows\system32\netqqzwm.exe []
2007-10-04 c:\windows\Tasks\hbptjbc.job
- c:\windows\system32\netqqzwm.exe []
2008-02-05 c:\windows\Tasks\hexu.job
- c:\windows\system32\netqqzwm.exe []
2008-01-04 c:\windows\Tasks\hjqkgfh.job
- c:\windows\system32\netqqzwm.exe []
2008-02-17 c:\windows\Tasks\hkcpddt.job
- c:\windows\system32\netqqzwm.exe []
2007-07-24 c:\windows\Tasks\hkpaqkha.job
- c:\windows\system32\netqqzwm.exe []
2008-02-21 c:\windows\Tasks\hrvbe.job
- c:\windows\system32\netqqzwm.exe []
2007-10-03 c:\windows\Tasks\huo.job
- c:\windows\system32\netqqzwm.exe []
2007-11-17 c:\windows\Tasks\huw.job
- c:\windows\system32\netqqzwm.exe []
2007-09-06 c:\windows\Tasks\hxpy.job
- c:\windows\system32\netqqzwm.exe []
2007-10-14 c:\windows\Tasks\icw.job
- c:\windows\system32\netqqzwm.exe []
2007-10-03 c:\windows\Tasks\ieqxhvyv.job
- c:\windows\system32\netqqzwm.exe []
2007-11-25 c:\windows\Tasks\ijok.job
- c:\windows\system32\netqqzwm.exe []
2007-10-15 c:\windows\Tasks\inoud.job
- c:\windows\system32\netqqzwm.exe []
2007-09-02 c:\windows\Tasks\irvs.job
- c:\windows\system32\netqqzwm.exe []
2008-02-29 c:\windows\Tasks\isvw.job
- c:\windows\system32\netqqzwm.exe []
2007-11-08 c:\windows\Tasks\iuj.job
- c:\windows\system32\netqqzwm.exe []
2007-12-10 c:\windows\Tasks\ixqei.job
- c:\windows\system32\netqqzwm.exe []
2007-07-05 c:\windows\Tasks\javzhet.job
- c:\windows\system32\netqqzwm.exe []
2007-12-23 c:\windows\Tasks\jehqffdt.job
- c:\windows\system32\netqqzwm.exe []
2007-12-06 c:\windows\Tasks\jhu.job
- c:\windows\system32\netqqzwm.exe []
2007-08-08 c:\windows\Tasks\jixkgfwm.job
- c:\windows\system32\netqqzwm.exe []
2007-07-21 c:\windows\Tasks\jkakqk.job
- c:\windows\system32\netqqzwm.exe []
2007-08-30 c:\windows\Tasks\jngogkhd.job
- c:\windows\system32\netqqzwm.exe []
2007-07-20 c:\windows\Tasks\jryy.job
- c:\windows\system32\netqqzwm.exe []
2007-12-27 c:\windows\Tasks\jupzy.job
- c:\windows\system32\netqqzwm.exe []
2008-03-01 c:\windows\Tasks\kct.job
- c:\windows\system32\netqqzwm.exe []
2007-10-30 c:\windows\Tasks\kfvqpuqs.job
- c:\windows\system32\netqqzwm.exe []
2007-11-23 c:\windows\Tasks\kigcb.job
- c:\windows\system32\netqqzwm.exe []
2007-10-17 c:\windows\Tasks\kjjbt.job
- c:\windows\system32\netqqzwm.exe []
2007-10-13 c:\windows\Tasks\kogkvwpc.job
- c:\windows\system32\netqqzwm.exe []
2007-11-27 c:\windows\Tasks\lcrxhgqv.job
- c:\windows\system32\netqqzwm.exe []
2007-08-31 c:\windows\Tasks\lgkmi.job
- c:\windows\system32\netqqzwm.exe []
2007-11-18 c:\windows\Tasks\liajreo.job
- c:\windows\system32\netqqzwm.exe []
2007-09-26 c:\windows\Tasks\lpkiqudp.job
- c:\windows\system32\netqqzwm.exe []
2008-01-11 c:\windows\Tasks\lra.job
- c:\windows\system32\netqqzwm.exe []
2008-01-12 c:\windows\Tasks\lrhvm.job
- c:\windows\system32\netqqzwm.exe []
2007-12-15 c:\windows\Tasks\lrjecna.job
- c:\windows\system32\netqqzwm.exe []
2008-11-16 c:\windows\Tasks\Malwarebytes' Scheduled Scan for enrico.job
- c:\programmi\Malwarebytes' Anti-Malware\mbam.exe [2008-10-22 16:10]
2008-11-16 c:\windows\Tasks\Malwarebytes' Scheduled Update for enrico.job
- c:\programmi\Malwarebytes' Anti-Malware\mbam.exe [2008-10-22 16:10]
2008-02-09 c:\windows\Tasks\mbgid.job
- c:\windows\system32\netqqzwm.exe []
2008-01-03 c:\windows\Tasks\mcrwgmfv.job
- c:\windows\system32\netqqzwm.exe []
2007-11-10 c:\windows\Tasks\mfvo.job
- c:\windows\system32\netqqzwm.exe []
2008-01-10 c:\windows\Tasks\mgyxem.job
- c:\windows\system32\netqqzwm.exe []
2007-10-25 c:\windows\Tasks\mjyrgt.job
- c:\windows\system32\netqqzwm.exe []
2007-12-31 c:\windows\Tasks\mktmwtt.job
- c:\windows\system32\netqqzwm.exe []
2008-02-13 c:\windows\Tasks\mlqx.job
- c:\windows\system32\netqqzwm.exe []
2008-02-17 c:\windows\Tasks\mnudfnxa.job
- c:\windows\system32\netqqzwm.exe []
2007-12-23 c:\windows\Tasks\moivky.job
- c:\windows\system32\netqqzwm.exe []
2008-11-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2007-12-15 c:\windows\Tasks\mrmguo.job
- c:\windows\system32\netqqzwm.exe []
2007-10-01 c:\windows\Tasks\mvtpi.job
- c:\windows\system32\netqqzwm.exe []
2007-12-09 c:\windows\Tasks\mxp.job
- c:\windows\system32\netqqzwm.exe []
2007-07-19 c:\windows\Tasks\mzerwr.job
- c:\windows\system32\netqqzwm.exe []
2007-12-06 c:\windows\Tasks\nfgdcki.job
- c:\windows\system32\netqqzwm.exe []
2007-10-05 c:\windows\Tasks\ngu.job
- c:\windows\system32\netqqzwm.exe []
2007-09-16 c:\windows\Tasks\nocm.job
- c:\windows\system32\netqqzwm.exe []
2007-12-28 c:\windows\Tasks\noiyrh.job
- c:\windows\system32\netqqzwm.exe []
2008-01-22 c:\windows\Tasks\nonxpu.job
- c:\windows\system32\netqqzwm.exe []
2007-12-22 c:\windows\Tasks\oajltytd.job
- c:\windows\system32\netqqzwm.exe []
2008-01-16 c:\windows\Tasks\oaprb.job
- c:\windows\system32\netqqzwm.exe []
2007-10-09 c:\windows\Tasks\oct.job
- c:\windows\system32\netqqzwm.exe []
2007-07-06 c:\windows\Tasks\ogacfmf.job
- c:\windows\system32\netqqzwm.exe []
2007-12-06 c:\windows\Tasks\olbs.job
- c:\windows\system32\netqqzwm.exe []
2008-02-29 c:\windows\Tasks\olkduggz.job
- c:\windows\system32\netqqzwm.exe []
2007-12-14 c:\windows\Tasks\oxhwydh.job
- c:\windows\system32\netqqzwm.exe []
2007-09-16 c:\windows\Tasks\pec.job
- c:\windows\system32\netqqzwm.exe []
2007-08-09 c:\windows\Tasks\pmlxonn.job
- c:\windows\system32\netqqzwm.exe []
2008-01-02 c:\windows\Tasks\pmxkm.job
- c:\windows\system32\netqqzwm.exe []
2007-09-16 c:\windows\Tasks\pnlnld.job
- c:\windows\system32\netqqzwm.exe []
2007-11-10 c:\windows\Tasks\poe.job
- c:\windows\system32\netqqzwm.exe []
2007-12-13 c:\windows\Tasks\pogvr.job
- c:\windows\system32\netqqzwm.exe []
2007-12-01 c:\windows\Tasks\ppbrphmo.job
- c:\windows\system32\netqqzwm.exe []
2007-12-18 c:\windows\Tasks\pqdwhfmx.job
- c:\windows\system32\netqqzwm.exe []
2008-02-20 c:\windows\Tasks\pry.job
- c:\windows\system32\netqqzwm.exe []
2008-01-13 c:\windows\Tasks\puxnnpqr.job
- c:\windows\system32\netqqzwm.exe []
2007-12-03 c:\windows\Tasks\pvsaxg.job
- c:\windows\system32\netqqzwm.exe []
2007-07-07 c:\windows\Tasks\pyyskpuq.job
- c:\windows\system32\netqqzwm.exe []
2007-08-02 c:\windows\Tasks\pzhtm.job
- c:\windows\system32\netqqzwm.exe []
2007-11-10 c:\windows\Tasks\pzsf.job
- c:\windows\system32\netqqzwm.exe []
2007-08-04 c:\windows\Tasks\qbwoorn.job
- c:\windows\system32\netqqzwm.exe []
2007-10-05 c:\windows\Tasks\qdotnai.job
- c:\windows\system32\netqqzwm.exe []
2007-09-24 c:\windows\Tasks\qemk.job
- c:\windows\system32\netqqzwm.exe []
2007-11-29 c:\windows\Tasks\qmsinqbd.job
- c:\windows\system32\netqqzwm.exe []
2007-11-03 c:\windows\Tasks\qny.job
- c:\windows\system32\netqqzwm.exe []
2007-12-09 c:\windows\Tasks\qoe.job
- c:\windows\system32\netqqzwm.exe []
2007-12-25 c:\windows\Tasks\qsqqijcu.job
- c:\windows\system32\netqqzwm.exe []
2007-09-30 c:\windows\Tasks\qtje.job
- c:\windows\system32\netqqzwm.exe []
2007-07-08 c:\windows\Tasks\qxiyhxoe.job
- c:\windows\system32\netqqzwm.exe []
2007-12-15 c:\windows\Tasks\qysvkwpp.job
- c:\windows\system32\netqqzwm.exe []
2008-02-23 c:\windows\Tasks\qzzwal.job
- c:\windows\system32\netqqzwm.exe []
2008-02-17 c:\windows\Tasks\rgojn.job
- c:\windows\system32\netqqzwm.exe []
2008-01-26 c:\windows\Tasks\rltzrmj.job
- c:\windows\system32\netqqzwm.exe []
2007-12-07 c:\windows\Tasks\rlwj.job
- c:\windows\system32\netqqzwm.exe []
2007-09-16 c:\windows\Tasks\rpandv.job
- c:\windows\system32\netqqzwm.exe []
2008-01-05 c:\windows\Tasks\rrboqlw.job
- c:\windows\system32\netqqzwm.exe []
2007-07-22 c:\windows\Tasks\rwqtix.job
- c:\windows\system32\netqqzwm.exe []
2007-12-27 c:\windows\Tasks\saqs.job
- c:\windows\system32\netqqzwm.exe []
2007-12-02 c:\windows\Tasks\sbyupr.job
- c:\windows\system32\netqqzwm.exe []
2008-02-08 c:\windows\Tasks\scqkf.job
- c:\windows\system32\netqqzwm.exe []
2007-07-27 c:\windows\Tasks\sehnbfq.job
- c:\windows\system32\netqqzwm.exe []
2007-09-17 c:\windows\Tasks\ski.job
- c:\windows\system32\netqqzwm.exe []
2007-08-07 c:\windows\Tasks\smjp.job
- c:\windows\system32\netqqzwm.exe []
2008-02-09 c:\windows\Tasks\soxcdlll.job
- c:\windows\system32\netqqzwm.exe []
2007-12-20 c:\windows\Tasks\spkjv.job
- c:\windows\system32\netqqzwm.exe []
2007-07-12 c:\windows\Tasks\spyy.job
- c:\windows\system32\netqqzwm.exe []
2008-01-29 c:\windows\Tasks\ssoaksda.job
- c:\windows\system32\netqqzwm.exe []
2007-11-18 c:\windows\Tasks\syp.job
- c:\windows\system32\netqqzwm.exe []
2007-09-16 c:\windows\Tasks\szao.job
- c:\windows\system32\netqqzwm.exe []
2007-11-13 c:\windows\Tasks\thyqg.job
- c:\windows\system32\netqqzwm.exe []
2007-08-05 c:\windows\Tasks\tinsnj.job
- c:\windows\system32\netqqzwm.exe []
2007-12-04 c:\windows\Tasks\tohj.job
- c:\windows\system32\netqqzwm.exe []
2007-09-20 c:\windows\Tasks\tqfg.job
- c:\windows\system32\netqqzwm.exe []
2007-12-19 c:\windows\Tasks\trxskhag.job
- c:\windows\system32\netqqzwm.exe []
2007-12-08 c:\windows\Tasks\tuqvpsr.job
- c:\windows\system32\netqqzwm.exe []
2007-12-09 c:\windows\Tasks\tvmzoluv.job
- c:\windows\system32\netqqzwm.exe []
2007-09-25 c:\windows\Tasks\twum.job
- c:\windows\system32\netqqzwm.exe []
2008-01-24 c:\windows\Tasks\txic.job
- c:\windows\system32\netqqzwm.exe []
2008-01-31 c:\windows\Tasks\uohyc.job
- c:\windows\system32\netqqzwm.exe []
2007-12-21 c:\windows\Tasks\utq.job
- c:\windows\system32\netqqzwm.exe []
2007-10-16 c:\windows\Tasks\uuuquuao.job
- c:\windows\system32\netqqzwm.exe []
2007-07-23 c:\windows\Tasks\uvvbr.job
- c:\windows\system32\netqqzwm.exe []
2008-01-12 c:\windows\Tasks\vadadc.job
- c:\windows\system32\netqqzwm.exe []
2008-01-07 c:\windows\Tasks\vca.job
- c:\windows\system32\netqqzwm.exe []
2007-08-03 c:\windows\Tasks\vemj.job
- c:\windows\system32\netqqzwm.exe []
2008-01-12 c:\windows\Tasks\vjrssyjc.job
- c:\windows\system32\netqqzwm.exe []
2007-09-10 c:\windows\Tasks\vzdufno.job
- c:\windows\system32\netqqzwm.exe []
2008-02-21 c:\windows\Tasks\vzfx.job
- c:\windows\system32\netqqzwm.exe []
2007-12-09 c:\windows\Tasks\whpd.job
- c:\windows\system32\netqqzwm.exe []
2007-08-01 c:\windows\Tasks\wiw.job
- c:\windows\system32\netqqzwm.exe []
2008-02-07 c:\windows\Tasks\wlr.job
- c:\windows\system32\netqqzwm.exe []
2007-12-01 c:\windows\Tasks\wnjmty.job
- c:\windows\system32\netqqzwm.exe []
2007-08-01 c:\windows\Tasks\wnulaw.job
- c:\windows\system32\netqqzwm.exe []
2007-11-01 c:\windows\Tasks\wophd.job
- c:\windows\system32\netqqzwm.exe []
2007-12-02 c:\windows\Tasks\wpybkn.job
- c:\windows\system32\netqqzwm.exe []
2008-01-13 c:\windows\Tasks\wqnpmgvl.job
- c:\windows\system32\netqqzwm.exe []
2007-12-29 c:\windows\Tasks\wqxbke.job
- c:\windows\system32\netqqzwm.exe []
2008-01-12 c:\windows\Tasks\wtzr.job
- c:\windows\system32\netqqzwm.exe []
2007-11-13 c:\windows\Tasks\wwcodxq.job
- c:\windows\system32\netqqzwm.exe []
2007-11-07 c:\windows\Tasks\wxft.job
- c:\windows\system32\netqqzwm.exe []
2007-11-18 c:\windows\Tasks\wzqxek.job
- c:\windows\system32\netqqzwm.exe []
2008-01-28 c:\windows\Tasks\xaaariut.job
- c:\windows\system32\netqqzwm.exe []
2007-12-26 c:\windows\Tasks\xbychnij.job
- c:\windows\system32\netqqzwm.exe []
2007-12-02 c:\windows\Tasks\xpnbaeg.job
- c:\windows\system32\netqqzwm.exe []
2007-11-08 c:\windows\Tasks\xqusvowh.job
- c:\windows\system32\netqqzwm.exe []
2008-01-31 c:\windows\Tasks\xrhbtvb.job
- c:\windows\system32\netqqzwm.exe []
2008-01-13 c:\windows\Tasks\xtkbb.job
- c:\windows\system32\netqqzwm.exe []
2007-07-20 c:\windows\Tasks\xyrui.job
- c:\windows\system32\netqqzwm.exe []
2007-12-23 c:\windows\Tasks\xzfqsmhx.job
- c:\windows\system32\netqqzwm.exe []
2008-02-07 c:\windows\Tasks\ybxd.job
- c:\windows\system32\netqqzwm.exe []
2007-10-15 c:\windows\Tasks\ydiowwn.job
- c:\windows\system32\netqqzwm.exe []
2008-01-21 c:\windows\Tasks\yipgom.job
- c:\windows\system32\netqqzwm.exe []
2007-09-18 c:\windows\Tasks\ykzwmcx.job
- c:\windows\system32\netqqzwm.exe []
2007-11-15 c:\windows\Tasks\ylfwzilm.job
- c:\windows\system32\netqqzwm.exe []
2008-02-23 c:\windows\Tasks\yvey.job
- c:\windows\system32\netqqzwm.exe []
2007-07-22 c:\windows\Tasks\zbebu.job
- c:\windows\system32\netqqzwm.exe []
2007-07-23 c:\windows\Tasks\zgrbz.job
- c:\windows\system32\netqqzwm.exe []
2007-09-29 c:\windows\Tasks\zis.job
- c:\windows\system32\netqqzwm.exe []
2007-09-09 c:\windows\Tasks\zlpnnta.job
- c:\windows\system32\netqqzwm.exe []
2007-11-15 c:\windows\Tasks\zoxum.job
- c:\windows\system32\netqqzwm.exe []
2007-11-19 c:\windows\Tasks\zrbqka.job
- c:\windows\system32\netqqzwm.exe []
2007-12-02 c:\windows\Tasks\zxhbiskx.job
- c:\windows\system32\netqqzwm.exe []
2008-02-22 c:\windows\Tasks\zym.job
- c:\windows\system32\netqqzwm.exe []
2007-10-23 c:\windows\Tasks\zzbv.job
- c:\windows\system32\netqqzwm.exe []
.
.
------- Supplementare di scansione -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to AMV Converter... - c:\programmi\MP3 Player Utilities 4.15\AMVConverter\grab.html
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti nel file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\programmi\MP3 Player Utilities 4.15\MediaManager\grab.html
TCP: {B1A92480-049C-48EC-A329-D43338B1B63C} = 192.168.1.1
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\Account.dll - O16 -: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4}
hxxp://www.tele2mail.com/static/apps/utils/AccountHelper.cab
c:\windows\Downloaded Program Files\Account.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-19 22:04:43
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-11-19 22:07:59
ComboFix-quarantined-files.txt 2008-11-19 21:07:55
Pre-Run: 16,783,593,472 byte disponibili
Post-Run: 17,077,219,328 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
656 --- E O F --- 2008-11-13 16:08:09
questo invece è il log hijack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.12.59, on 19/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmi\Windows Defender\MSASCui.exe
F:\Programmi\HP\HP Software Update\HPWuSchd.exe
C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\wcescomm.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
F:\rapimgr.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
F:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [OpwareSE2] "C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] "F:\Programmi\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\Run: [AliceRE_McciTrayApp] C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunServices: [Windowfdgfds DasdLL fgfdg Verifier] WindowANTasdIVRI.exe
O4 - HKLM\..\RunOnce: [InstallHelper C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer] "C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer\InstallHelper.exe" "/DIR=C:\Programmi\Alice ti aiuta\vendors\AliceRE\content\template\driven_dev\syncer"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmi\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BitComet] "F:\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_7 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\wcescomm.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
O4 - Global Startup: Digisoft AntiDialer.lnk = F:\Digisoft AntiDialer\AntiDialer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = F:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\Programmi\MP3 Player Utilities 4.15\AMVConverter\grab.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Programmi\MP3 Player Utilities 4.15\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra 'Tools' menuitem: Crea preferito portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\INetRepl.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: Alice - {AD01FB3B-8AD7-4994-82BE-3B7E6F4E14C1} -
http://gw.aliceadsl.it/alice (file missing) (HKCU)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197568262529O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) -
http://www.tele2mail.com/static/apps/utils/AccountHelper.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{6449E0AC-867A-4BD8-9DC5-B2AA42499B9D}: NameServer = 85.37.17.44 85.38.28.90
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A92480-049C-48EC-A329-D43338B1B63C}: NameServer = 192.168.1.1
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Network WanMiniport First Position - Unknown owner - C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 12850 bytes
attendo disposizioni !!!!!!!!!!!!!!!!
ciao e grazie