Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Aiuto Windows Internet Explorer pagine bianca Opzioni
mediterraneo78
Inviato: Sunday, February 15, 2009 11:18:42 PM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0


----------------- FindyKill V4.707 ------------------

* User : Administrator - SALERNIT-1DCF58
* executed from : C:\Programmi\FindyKill
* Update on 06/12/08 par Chiquitine29
* Start at 23:15:43 the 15/02/2009
* Windows XP - Internet Explorer 8.0.6001.18372


((((((((((((((( *** deleting *** ))))))))))))))))))


--------------- [ Active Processes ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\userinit.exe

--------------- [ Infected files / folders ] ----------------


»»»» Supression files in C:


»»»» Supression files in C:\WINDOWS


»»»» Supression files in C:\WINDOWS\Prefetch

Deleted ! - C:\WINDOWS\prefetch\162265.EXE-2580A165.pf
Deleted ! - C:\WINDOWS\prefetch\175625.EXE-09DE2A49.pf
Deleted ! - C:\WINDOWS\prefetch\6483687.EXE-27C892B8.pf
Deleted ! - C:\WINDOWS\prefetch\6498453.EXE-0B663403.pf
Deleted ! - C:\WINDOWS\prefetch\6726359.EXE-3908E4F4.pf
Deleted ! - C:\WINDOWS\prefetch\6945000.EXE-21DDA7C7.pf
Deleted ! - C:\WINDOWS\prefetch\INSTALL_PATCH.EXE-10FCE5C1.pf

»»»» Supression files in C:\WINDOWS\system32

Deleted ! - C:\WINDOWS\system32\mdelk.exe
Deleted ! - C:\WINDOWS\system32\wintems.exe

»»»» Supression files in C:\WINDOWS\system32\drivers

Deleted ! - C:\WINDOWS\system32\drivers\srosa.sys
Deleted ! - C:\WINDOWS\system32\drivers\srosa2.sys
Deleted ! - C:\WINDOWS\system32\drivers\down\6487890.exe
Deleted ! - C:\WINDOWS\system32\drivers\down\6728515.exe
Deleted ! - "C:\WINDOWS\system32\drivers\down"

»»»» Supression files in C:\Documents and Settings\Administrator\Dati applicazioni

Deleted ! - "C:\Documents and Settings\Administrator\Dati applicazioni\m\flec006.exe"
Deleted ! - "C:\Documents and Settings\Administrator\Dati applicazioni\m"

»»»» Supression files in C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp


»»»» Supression files in C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5

Deleted ! - C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\LBJBUQR2\b64[1].jpg
Deleted ! - C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\LBJBUQR2\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\LN6QCCP4\b64_6[1].jpg
Deleted ! - C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\PB2G7UK7\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\WD34VFG4\b64[1].jpg
Deleted ! - C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\WD34VFG4\b64_1[1].jpg

--------------- [ Registry / Infected keys ] ----------------

Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_USERS\S-1-5-21-484763869-1078145449-725345543-500\Software\Local AppWizard-Generated Applications\install_patch

--------------- [ States / Restarting of services ] ----------------

+- Safe boot mode restored !


+- Services : [ Auto=2 / Request=3 / Disable=4 ]

Ndisuio - Type of startup = 3

EapHost - Type of startup = 2

Ip6Fw - Type of startup = 2

SharedAccess - Type of startup = 2

wuauserv - Type of startup = 2

wscsvc - Type of startup = 2


--------------- [ Cleaning removable drives ] ----------------

+- Informations :

C: - Unit… fissa

F: - Unit… fissa


+- deleting files :


--------------- [ Registry / Mountpoint2 ] ----------------


-> Not found !


--------------- [ Searching Cracks / Keygen ] ----------------



---------------- ! End of report ! ------------------


shapiro
Inviato: Monday, February 16, 2009 8:54:30 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
eravamo arrivati alla fine e hai ripreso il bagle

per fortuna findkill ha tolto molte infezioni

scarica Avenger da qui

http://swandog46.geekstogo.com/avenger.zip

lo installi e lo lanci

Copi e incolli nella finestra: "Input script here" il testo in rosso così come lo vedi scritto:


Files to delete:
%SystemDrive%\WINDOWS\system32\drivers\hidr.exe
%SystemDrive%\WINDOWS\system32\drivers\srosa.sys
%SystemDrive%\WINDOWS\system32\wintems.exe
%SystemDrive%\WINDOWS\system32\hldrrr.exe
%SystemDrive%\WINDOWS\system32\trusted.exe
%SystemDrive%\WINDOWS\system32\drivers\pci32.sys
%UserProfile%\Dati applicazioni\hidires\hidr.exe
%UserProfile%\Dati applicazioni\hidires\rosa.sys
%UserProfile%\Dati applicazioni\m\list.oct
%UserProfile%\Dati applicazioni\m\data.oct
%UserProfile%\Dati applicazioni\m\flec006.exe
%UserProfile%\Dati applicazioni\m\svrlist.oct
%SystemDrive%\system32\re_file.exe
%SystemDrive%\elist.xpt
%UserProfile%\Dati applicazioni\hidires\m_hook.sys
%SystemDrive%\WINDOWS\system32\drivers\hldrrr.exe
%SystemDrive%\WINDOWS\system32\drivers\hldrrr.ex_
%SystemDrive%\WINDOWS\system32\mdelk.exe
%SystemDrive%\WINDOWS\system32\drivers\mdelk.exe
%SystemDrive%\WINDOWS\system32\drivers\pci32.sys
%SystemDrive%\WINDOWS\system32\edlm.exe
%SystemDrive%\WINDOWS\system32\edlm2.exe
%SystemDrive%\Windows\system32\ldR64.dll
%SystemDrive%\WINDOWS\system32\german.exe
%SystemDrive%\WINDOWS\system32\drivers\srosa.sys.XXX
%SystemDrive%\WINDOWS\system32\mdelk.exe.XXX
%SystemDrive%\WINDOWS\system32\wintems.exe.XXX
%SystemDrive%\WINDOWS\system32\1.exe

Folders to delete:
%SystemDrive%\WINDOWS\exefqd
%SystemDrive%\WINDOWS\exefnd
%SystemDrive%\WINDOWS\exefld
%UserProfile%\Dati applicazioni\hidires
%UserProfile%\Dati applicazioni\hidn
%UserProfile%\Dati applicazioni\m\shared
%UserProfile%\Dati applicazioni\m
%SystemDrive%\WINDOWS\System32\drivers\down
%SystemDrive%\WINDOWS\system32\drivers\downld

Registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\CurrentControlSet\Services\pci32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32
HKLM\SYSTEM\CurrentControlSet\Services\rosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_rosa
HKLM\SYSTEM\CurrentControlSet\Services\m_hook
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK
HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ldr64

Registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | hldrrr
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | drvsyskit
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | german.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | drv_st_key

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs

Drivers to disable:
%SystemDrive%\WINDOWS\system32\drivers\hidr.exe
%SystemDrive%\WINDOWS\system32\drivers\srosa.sys
%SystemDrive%\WINDOWS\system32\drivers\pci32.sys
%SystemDrive%\WINDOWS\system32\drivers\hldrrr.exe
%SystemDrive%\WINDOWS\system32\drivers\mdelk.exe








Spunta "Automatically disable any rootkits found"

clicca sul pulsante "Execute"
Il pc dovrebbe riavviarsi da solo,se così non fosse riavvialo manualmente

posta il log di avenger che trovi in c:\




scaricare Malwarebytes http://www.malwarebytes.org/mbam/program/mbam-setup.exe
1) lo installi
2) lo aggiorni
3) fai una scansione scegliendo la modalità completa
4) NON eliminare per ora le ventuali minacce che rileva
5) finita la scansione seleziona il tabellino log, apri il file di testo e postalo sul forum

http://www.malwarebytes.org/mbam/program/mbam-setup.exe
mediterraneo78
Inviato: Monday, February 16, 2009 11:42:00 AM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
Ecco il log di avenger:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\WINDOWS\system32\drivers\hidr.exe" not found!
Deletion of file "C:\WINDOWS\system32\drivers\hidr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\drivers\srosa.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\srosa.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\wintems.exe" not found!
Deletion of file "C:\WINDOWS\system32\wintems.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\hldrrr.exe" not found!
Deletion of file "C:\WINDOWS\system32\hldrrr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\trusted.exe" not found!
Deletion of file "C:\WINDOWS\system32\trusted.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\drivers\pci32.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\pci32.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open file "C:\Documents and Settings\Administrator\Dati applicazioni\hidires\hidr.exe"
Deletion of file "C:\Documents and Settings\Administrator\Dati applicazioni\hidires\hidr.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: could not open file "C:\Documents and Settings\Administrator\Dati applicazioni\hidires\rosa.sys"
Deletion of file "C:\Documents and Settings\Administrator\Dati applicazioni\hidires\rosa.sys" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: could not open file "C:\Documents and Settings\Administrator\Dati applicazioni\m\list.oct"
Deletion of file "C:\Documents and Settings\Administrator\Dati applicazioni\m\list.oct" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: could not open file "C:\Documents and Settings\Administrator\Dati applicazioni\m\data.oct"
Deletion of file "C:\Documents and Settings\Administrator\Dati applicazioni\m\data.oct" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: could not open file "C:\Documents and Settings\Administrator\Dati applicazioni\m\flec006.exe"
Deletion of file "C:\Documents and Settings\Administrator\Dati applicazioni\m\flec006.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: could not open file "C:\Documents and Settings\Administrator\Dati applicazioni\m\svrlist.oct"
Deletion of file "C:\Documents and Settings\Administrator\Dati applicazioni\m\svrlist.oct" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: could not open file "C:\system32\re_file.exe"
Deletion of file "C:\system32\re_file.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: file "C:\elist.xpt" not found!
Deletion of file "C:\elist.xpt" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open file "C:\Documents and Settings\Administrator\Dati applicazioni\hidires\m_hook.sys"
Deletion of file "C:\Documents and Settings\Administrator\Dati applicazioni\hidires\m_hook.sys" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: file "C:\WINDOWS\system32\drivers\hldrrr.exe" not found!
Deletion of file "C:\WINDOWS\system32\drivers\hldrrr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\drivers\hldrrr.ex_" not found!
Deletion of file "C:\WINDOWS\system32\drivers\hldrrr.ex_" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\mdelk.exe" not found!
Deletion of file "C:\WINDOWS\system32\mdelk.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\drivers\mdelk.exe" not found!
Deletion of file "C:\WINDOWS\system32\drivers\mdelk.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\drivers\pci32.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\pci32.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\edlm.exe" not found!
Deletion of file "C:\WINDOWS\system32\edlm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\edlm2.exe" not found!
Deletion of file "C:\WINDOWS\system32\edlm2.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\Windows\system32\ldR64.dll" not found!
Deletion of file "C:\Windows\system32\ldR64.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\german.exe" not found!
Deletion of file "C:\WINDOWS\system32\german.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\drivers\srosa.sys.XXX" not found!
Deletion of file "C:\WINDOWS\system32\drivers\srosa.sys.XXX" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\mdelk.exe.XXX" not found!
Deletion of file "C:\WINDOWS\system32\mdelk.exe.XXX" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\wintems.exe.XXX" not found!
Deletion of file "C:\WINDOWS\system32\wintems.exe.XXX" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\1.exe" not found!
Deletion of file "C:\WINDOWS\system32\1.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: folder "C:\WINDOWS\exefqd" not found!
Deletion of folder "C:\WINDOWS\exefqd" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: folder "C:\WINDOWS\exefnd" not found!
Deletion of folder "C:\WINDOWS\exefnd" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: folder "C:\WINDOWS\exefld" not found!
Deletion of folder "C:\WINDOWS\exefld" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: folder "C:\Documents and Settings\Administrator\Dati applicazioni\hidires" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dati applicazioni\hidires" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: folder "C:\Documents and Settings\Administrator\Dati applicazioni\hidn" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dati applicazioni\hidn" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open folder "C:\Documents and Settings\Administrator\Dati applicazioni\m\shared"
Deletion of folder "C:\Documents and Settings\Administrator\Dati applicazioni\m\shared" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: folder "C:\Documents and Settings\Administrator\Dati applicazioni\m" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dati applicazioni\m" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: folder "C:\WINDOWS\System32\drivers\down" not found!
Deletion of folder "C:\WINDOWS\System32\drivers\down" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: folder "C:\WINDOWS\system32\drivers\downld" not found!
Deletion of folder "C:\WINDOWS\system32\drivers\downld" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\CurrentControlSet\Services\srosa" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Services\srosa" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\CurrentControlSet\Services\pci32" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Services\pci32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\CurrentControlSet\Services\rosa" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Services\rosa" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_rosa" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_rosa" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\CurrentControlSet\Services\m_hook" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Services\m_hook" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA" not found!
Deletion of registry key "HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA" not found!
Deletion of registry key "HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open driver "%SystemDrive%\WINDOWS\system32\drivers\hidr.exe"
Disablement of driver "%SystemDrive%\WINDOWS\system32\drivers\hidr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open driver "%SystemDrive%\WINDOWS\system32\drivers\srosa.sys"
Disablement of driver "%SystemDrive%\WINDOWS\system32\drivers\srosa.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open driver "%SystemDrive%\WINDOWS\system32\drivers\pci32.sys"
Disablement of driver "%SystemDrive%\WINDOWS\system32\drivers\pci32.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open driver "%SystemDrive%\WINDOWS\system32\drivers\hldrrr.exe"
Disablement of driver "%SystemDrive%\WINDOWS\system32\drivers\hldrrr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open driver "%SystemDrive%\WINDOWS\system32\drivers\mdelk.exe"
Disablement of driver "%SystemDrive%\WINDOWS\system32\drivers\mdelk.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ldr64" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ldr64" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|hldrrr"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|hldrrr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|drvsyskit"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|drvsyskit" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|german.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|german.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|drv_st_key"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|drv_st_key" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist

Registry value "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs" replaced with dummy successfully.

Completed script processing.

*******************

Finished! Terminate.


questo è il log di malwarebytes:

Malwarebytes' Anti-Malware 1.34
Versione del database: 1749
Windows 5.1.2600 Service Pack 3

16/02/2009 11.40.34
mbam-log-2009-02-16 (11-40-34).txt

Tipo di scansione: Scansione completa (C:\|F:\|)
Elementi scansionati: 99734
Tempo trascorso: 20 minute(s), 15 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)
shapiro
Inviato: Monday, February 16, 2009 11:51:02 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
cos'e' successo? hai aperto qualche programma scaricato da emule o cosa?
mediterraneo78
Inviato: Monday, February 16, 2009 11:56:46 AM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
Shapiro non ho aperto niente ...
shapiro
Inviato: Monday, February 16, 2009 12:05:44 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
controlla se ti funziona l'antivirus e riattiva i servizi disabilitati
mediterraneo78
Inviato: Monday, February 16, 2009 12:06:38 PM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
L'antivirus funziona ho riattivato tutti i servizi..
shapiro
Inviato: Monday, February 16, 2009 12:11:18 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
Provia ad aprire il regedit start\esegui\regedit

controlla questa chiave

HKEY_LOCAL_MACHINE / SYSTEM / CurrentControlSet / Services / Ndisuio

quando sei su Ndisuio un solo click e vedi se la voce Start è impostata a "4" mettila a "3"

mediterraneo78
Inviato: Monday, February 16, 2009 12:14:01 PM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
La voce gia' è impostata a "3"
shapiro
Inviato: Monday, February 16, 2009 12:16:41 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
usa questo programmino http://eric.71.mespages.googlepages.com/LopSD.exe
con tutte le applicazioni chiuse e disconnesso
doppio click su LopSD
scegli la lingua E (invio)
1 (ricerca) invio

al termine dello scan riavvia LopSD
questa volta scegli l'opzione 2 (invio)

allega il report C:\LopR.txt insieme ad un nuovo log di hijackthis
mediterraneo78
Inviato: Monday, February 16, 2009 12:30:26 PM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
log 1 opzione:


--------------------\\ Lop S&D 4.2.5-0 XP/Vista


"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 16/02/2009|12.20 )

--------------------\\ Listing folders in DATIAP~1

[25/08/2008|18.19] C:\DOCUME~1\ADMINI~1\DATIAP~1\Adobe
[25/08/2008|16.29] C:\DOCUME~1\ADMINI~1\DATIAP~1\Auslogics
[15/02/2009|23.30] C:\DOCUME~1\ADMINI~1\DATIAP~1\Avira
[18/09/2008|00.52] C:\DOCUME~1\ADMINI~1\DATIAP~1\BSplayer
[18/09/2008|00.50] C:\DOCUME~1\ADMINI~1\DATIAP~1\BSplayer Pro
[26/08/2008|01.14] C:\DOCUME~1\ADMINI~1\DATIAP~1\Comodo
[25/08/2008|00.21] C:\DOCUME~1\ADMINI~1\DATIAP~1\Creative
[10/09/2008|22.07] C:\DOCUME~1\ADMINI~1\DATIAP~1\FMZilla
[10/02/2009|13.28] C:\DOCUME~1\ADMINI~1\DATIAP~1\Foxit
[15/12/2008|02.28] C:\DOCUME~1\ADMINI~1\DATIAP~1\GlarySoft
[01/11/2008|19.41] C:\DOCUME~1\ADMINI~1\DATIAP~1\Google
[10/09/2008|22.10] C:\DOCUME~1\ADMINI~1\DATIAP~1\GrabPro
[26/08/2008|21.32] C:\DOCUME~1\ADMINI~1\DATIAP~1\Help
[24/08/2008|23.28] C:\DOCUME~1\ADMINI~1\DATIAP~1\Identities
[08/09/2008|20.26] C:\DOCUME~1\ADMINI~1\DATIAP~1\InstallShield
[24/08/2008|23.46] C:\DOCUME~1\ADMINI~1\DATIAP~1\Macromedia
[29/10/2008|09.54] C:\DOCUME~1\ADMINI~1\DATIAP~1\Malwarebytes
[22/09/2008|20.03] C:\DOCUME~1\ADMINI~1\DATIAP~1\Media Player Classic
[15/02/2009|19.01] C:\DOCUME~1\ADMINI~1\DATIAP~1\Microsoft
[19/10/2008|20.31] C:\DOCUME~1\ADMINI~1\DATIAP~1\mIRC
[25/08/2008|00.15] C:\DOCUME~1\ADMINI~1\DATIAP~1\Motive
[13/02/2009|17.46] C:\DOCUME~1\ADMINI~1\DATIAP~1\Mozilla
[25/08/2008|15.40] C:\DOCUME~1\ADMINI~1\DATIAP~1\Nero
[30/10/2008|20.27] C:\DOCUME~1\ADMINI~1\DATIAP~1\OpenOffice.org
[03/10/2008|00.09] C:\DOCUME~1\ADMINI~1\DATIAP~1\Orbit
[23/10/2008|22.27] C:\DOCUME~1\ADMINI~1\DATIAP~1\Safer Networking
[26/11/2008|01.31] C:\DOCUME~1\ADMINI~1\DATIAP~1\Softvision
[01/09/2008|17.47] C:\DOCUME~1\ADMINI~1\DATIAP~1\Sun
[25/08/2008|15.06] C:\DOCUME~1\ADMINI~1\DATIAP~1\Thunderbird
[29/08/2008|13.21] C:\DOCUME~1\ADMINI~1\DATIAP~1\TVU Networks
[15/02/2009|23.29] C:\DOCUME~1\ADMINI~1\DATIAP~1\uTorrent
[13/02/2009|18.09] C:\DOCUME~1\ADMINI~1\DATIAP~1\vghd
[01/12/2008|18.53] C:\DOCUME~1\ADMINI~1\DATIAP~1\vlc
[21/10/2008|18.00] C:\DOCUME~1\ADMINI~1\DATIAP~1\Winamp
[12/02/2009|23.27] C:\DOCUME~1\ADMINI~1\DATIAP~1\Windows Live Writer
[25/08/2008|00.33] C:\DOCUME~1\ADMINI~1\DATIAP~1\WinRAR
[0|File] C:\DOCUME~1\ADMINI~1\DATIAP~1\byte
[38|Directory] C:\DOCUME~1\ADMINI~1\DATIAP~1\byte disponibili

[12/02/2009|16.21] C:\DOCUME~1\ALLUSE~1\DATIAP~1\80ckVB
[18/01/2009|12.51] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Adobe
[15/02/2009|23.28] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Avira
[23/09/2008|00.16] C:\DOCUME~1\ALLUSE~1\DATIAP~1\AVS4YOU
[25/08/2008|00.21] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Creative
[21/09/2008|23.41] C:\DOCUME~1\ALLUSE~1\DATIAP~1\GiocoDigitale
[04/11/2008|01.25] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Google
[08/09/2008|20.26] C:\DOCUME~1\ALLUSE~1\DATIAP~1\InstallShield
[29/10/2008|13.01] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Kaspersky Lab Setup Files
[31/10/2008|00.05] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Lavasoft
[29/10/2008|09.54] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Malwarebytes
[13/02/2009|01.40] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Messenger Plus!
[14/02/2009|21.23] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Microsoft
[30/10/2008|17.05] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Microsoft Help
[25/08/2008|15.38] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Nero
[27/08/2008|14.52] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Office Genuine Advantage
[25/08/2008|12.42] C:\DOCUME~1\ALLUSE~1\DATIAP~1\PC Drivers HeadQuarters
[27/08/2008|14.53] C:\DOCUME~1\ALLUSE~1\DATIAP~1\SecTaskMan
[16/02/2009|11.52] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Spybot - Search & Destroy
[29/08/2008|13.21] C:\DOCUME~1\ALLUSE~1\DATIAP~1\TVU Networks
[29/10/2008|14.32] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Windows Genuine Advantage
[25/08/2008|00.31] C:\DOCUME~1\ALLUSE~1\DATIAP~1\WinZip
[25/08/2008|16.51] C:\DOCUME~1\ALLUSE~1\DATIAP~1\WLInstaller
[0|File] C:\DOCUME~1\ALLUSE~1\DATIAP~1\byte
[25|Directory] C:\DOCUME~1\ALLUSE~1\DATIAP~1\byte disponibili

[24/08/2008|23.19] C:\DOCUME~1\DEFAUL~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\DEFAUL~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\DEFAUL~1\DATIAP~1\byte disponibili

[15/02/2009|19.01] C:\DOCUME~1\LOCALS~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\LOCALS~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\LOCALS~1\DATIAP~1\byte disponibili

[15/02/2009|19.01] C:\DOCUME~1\NETWOR~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\NETWOR~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\NETWOR~1\DATIAP~1\byte disponibili

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[16/02/2009 11.19][--a------] C:\WINDOWS\tasks\GlaryInitialize.job
[15/02/2009 15.49][--a------] C:\WINDOWS\tasks\OGADaily.job
[16/02/2009 11.19][--a------] C:\WINDOWS\tasks\OGALogon.job
[16/02/2009 11.19][--ah-----] C:\WINDOWS\tasks\SA.DAT
[31/08/2001 18.00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Programmi

[18/01/2009|12.50] C:\Programmi\Adobe
[29/10/2008|14.36] C:\Programmi\Alice ti aiuta
[25/08/2008|19.16] C:\Programmi\AskSBar
[25/08/2008|00.17] C:\Programmi\ATI Technologies
[25/08/2008|16.29] C:\Programmi\Auslogics
[14/02/2009|21.37] C:\Programmi\AVG
[15/02/2009|23.40] C:\Programmi\Avira
[23/09/2008|00.17] C:\Programmi\AVS4YOU
[18/09/2008|00.50] C:\Programmi\BS.Player ControlBar
[25/08/2008|18.24] C:\Programmi\CCleaner
[03/09/2008|20.16] C:\Programmi\CD_DVD-ROM Generator 1.20
[14/02/2009|16.51] C:\Programmi\Circle Development
[24/08/2008|23.42] C:\Programmi\Common Files
[26/08/2008|01.17] C:\Programmi\COMODO
[24/08/2008|23.15] C:\Programmi\ComPlus Applications
[13/02/2009|00.25] C:\Programmi\Conduit
[26/08/2008|22.17] C:\Programmi\CONEXANT
[26/08/2008|20.16] C:\Programmi\Dell Photo AIO Printer 924
[11/02/2009|16.06] C:\Programmi\DkZ Studio
[04/09/2008|12.05] C:\Programmi\DkZ Update
[25/08/2008|12.59] C:\Programmi\Driver-Soft
[25/08/2008|18.23] C:\Programmi\DustBuster XP
[29/10/2008|14.35] C:\Programmi\EliBagle
[06/10/2008|16.08] C:\Programmi\Everest Poker.net
[12/02/2009|22.01] C:\Programmi\File comuni
[15/02/2009|23.17] C:\Programmi\FindyKill
[10/02/2009|13.31] C:\Programmi\Foxit Software
[10/09/2008|22.08] C:\Programmi\Free Music Zilla
[07/12/2008|18.25] C:\Programmi\Game Graphic Studio
[23/09/2008|12.43] C:\Programmi\GiocoDigitale
[13/12/2008|18.16] C:\Programmi\Glary Utilities
[04/11/2008|01.25] C:\Programmi\Google
[07/01/2009|19.40] C:\Programmi\GRETECH
[26/08/2008|21.01] C:\Programmi\Idf
[17/11/2008|21.31] C:\Programmi\IKEA HomePlanner
[26/11/2008|01.30] C:\Programmi\InstallShield Installation Information
[25/08/2008|13.56] C:\Programmi\Intel
[12/02/2009|19.30] C:\Programmi\Internet Explorer
[21/12/2008|23.27] C:\Programmi\Java
[08/01/2009|13.32] C:\Programmi\JRE
[29/11/2008|12.01] C:\Programmi\Kaspersky Lab
[31/10/2008|00.03] C:\Programmi\Lavasoft
[16/02/2009|11.19] C:\Programmi\Malwarebytes' Anti-Malware
[23/09/2008|20.41] C:\Programmi\Messenger
[13/02/2009|00.05] C:\Programmi\Messenger Plus! Live
[12/02/2009|22.45] C:\Programmi\Microsoft
[23/09/2008|20.46] C:\Programmi\microsoft frontpage
[12/02/2009|22.43] C:\Programmi\Microsoft SQL Server Compact Edition
[12/02/2009|22.44] C:\Programmi\Microsoft Sync Framework
[08/01/2009|13.13] C:\Programmi\Microsoft.NET
[13/02/2009|18.23] C:\Programmi\MouseRunner.com
[23/09/2008|20.38] C:\Programmi\Movie Maker
[16/02/2009|11.53] C:\Programmi\Mozilla Firefox
[16/02/2009|12.09] C:\Programmi\Mozilla Thunderbird
[07/01/2009|19.34] C:\Programmi\Mplayer
[30/10/2008|17.03] C:\Programmi\MSBuild
[24/08/2008|23.15] C:\Programmi\MSN Gaming Zone
[15/11/2008|02.32] C:\Programmi\MSXML 4.0
[24/08/2008|23.22] C:\Programmi\MSXML 6.0
[13/02/2009|20.49] C:\Programmi\Navilog1
[25/08/2008|15.38] C:\Programmi\Nero
[23/09/2008|20.35] C:\Programmi\NetMeeting
[13/02/2009|14.23] C:\Programmi\NoAds
[08/01/2009|13.32] C:\Programmi\OpenOffice.org 3
[08/01/2009|13.32] C:\Programmi\OpenOffice.org 3.0 (it) Installation Files
[23/09/2008|20.35] C:\Programmi\Outlook Express
[31/10/2008|01.03] C:\Programmi\PeerGuardian2
[26/08/2008|21.00] C:\Programmi\Pirelli
[15/02/2009|23.42] C:\Programmi\Poker Club by Lottomatica
[04/02/2009|12.31] C:\Programmi\PokerStars.IT
[06/10/2008|15.25] C:\Programmi\PokerStars.NET
[25/08/2008|14.38] C:\Programmi\PowerQuest
[13/02/2009|15.03] C:\Programmi\QUAD Utilities
[10/02/2009|00.31] C:\Programmi\Recovery Toolbox for RAR
[24/08/2008|23.23] C:\Programmi\Reference Assemblies
[02/11/2008|23.03] C:\Programmi\RegSeeker
[04/11/2008|01.27] C:\Programmi\RegToy
[07/01/2009|22.55] C:\Programmi\Security Task Manager
[24/08/2008|23.17] C:\Programmi\Servizi in linea
[26/08/2008|21.37] C:\Programmi\SigmaTel
[08/09/2008|00.55] C:\Programmi\Smart Projects
[05/02/2009|13.51] C:\Programmi\Softonic_Italia
[29/08/2008|13.26] C:\Programmi\SopCast
[31/10/2008|15.55] C:\Programmi\Spybot - Search & Destroy
[24/08/2008|23.40] C:\Programmi\Telecom Italia
[05/11/2008|20.22] C:\Programmi\The KMPlayer
[23/10/2008|22.05] C:\Programmi\Trend Micro
[03/11/2008|18.38] C:\Programmi\TVAnts
[29/08/2008|13.21] C:\Programmi\TVUPlayer
[13/02/2009|17.25] C:\Programmi\vghd
[22/09/2008|21.51] C:\Programmi\VideoLAN
[20/11/2008|20.53] C:\Programmi\VS Revo Group
[18/09/2008|00.50] C:\Programmi\Webteh
[29/10/2008|14.35] C:\Programmi\Winamp
[12/02/2009|22.45] C:\Programmi\Windows Live
[12/02/2009|22.42] C:\Programmi\Windows Live SkyDrive
[24/08/2008|23.15] C:\Programmi\Windows Media Connect 2
[15/02/2009|23.46] C:\Programmi\Windows Media Player
[23/09/2008|20.35] C:\Programmi\Windows NT
[24/08/2008|23.17] C:\Programmi\WindowsUpdate
[25/08/2008|14.42] C:\Programmi\WinRAR
[21/09/2008|22.23] C:\Programmi\wwSms Client
[23/09/2008|20.46] C:\Programmi\xerox
[07/01/2009|19.47] C:\Programmi\XP Codec Pack
[23/10/2008|22.55] C:\Programmi\Yahoo!
[0|File] C:\Programmi\byte
[107|Directory] C:\Programmi\byte disponibili

--------------------\\ Listing Folders in C:\Programmi\File comuni

[18/01/2009|12.51] C:\Programmi\File comuni\Adobe
[23/09/2008|00.17] C:\Programmi\File comuni\AVSMedia
[26/11/2008|23.10] C:\Programmi\File comuni\DESIGNER
[08/09/2008|20.26] C:\Programmi\File comuni\InstallShield
[25/08/2008|16.44] C:\Programmi\File comuni\Java
[12/02/2009|22.42] C:\Programmi\File comuni\Microsoft Shared
[24/08/2008|23.42] C:\Programmi\File comuni\Motive
[24/08/2008|23.17] C:\Programmi\File comuni\MSSoap
[25/08/2008|15.39] C:\Programmi\File comuni\Nero
[25/08/2008|01.10] C:\Programmi\File comuni\ODBC
[25/08/2008|18.25] C:\Programmi\File comuni\Services
[25/08/2008|01.10] C:\Programmi\File comuni\SpeechEngines
[26/11/2008|23.10] C:\Programmi\File comuni\System
[02/11/2008|14.49] C:\Programmi\File comuni\uusee
[12/02/2009|22.01] C:\Programmi\File comuni\Windows Live
[25/08/2008|16.55] C:\Programmi\File comuni\WindowsLiveInstaller
[07/02/2009|22.20] C:\Programmi\File comuni\Wise Installation Wizard
[0|File] C:\Programmi\File comuni\byte
[19|Directory] C:\Programmi\File comuni\byte disponibili

--------------------\\ Process

( 36 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-16 12:21:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections


No other infections found !

[F:13][D:3]-> C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp
[F:16][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
[F:72][D:4]-> C:\DOCUME~1\ADMINI~1\IMPOST~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 13/02/2009|21.37 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 13/02/2009|21.41 - Option : [2]
3 - "C:\Lop SD\LopR_3.txt" - 16/02/2009|12.21 - Option : [1]

--------------------\\ Scan completed at 12.21.57

log 2 opzione :


--------------------\\ Lop S&D 4.2.5-0 XP/Vista


"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 16/02/2009|12.22 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in DATIAP~1

[25/08/2008|18.19] C:\DOCUME~1\ADMINI~1\DATIAP~1\Adobe
[25/08/2008|16.29] C:\DOCUME~1\ADMINI~1\DATIAP~1\Auslogics
[15/02/2009|23.30] C:\DOCUME~1\ADMINI~1\DATIAP~1\Avira
[18/09/2008|00.52] C:\DOCUME~1\ADMINI~1\DATIAP~1\BSplayer
[18/09/2008|00.50] C:\DOCUME~1\ADMINI~1\DATIAP~1\BSplayer Pro
[26/08/2008|01.14] C:\DOCUME~1\ADMINI~1\DATIAP~1\Comodo
[25/08/2008|00.21] C:\DOCUME~1\ADMINI~1\DATIAP~1\Creative
[10/09/2008|22.07] C:\DOCUME~1\ADMINI~1\DATIAP~1\FMZilla
[10/02/2009|13.28] C:\DOCUME~1\ADMINI~1\DATIAP~1\Foxit
[15/12/2008|02.28] C:\DOCUME~1\ADMINI~1\DATIAP~1\GlarySoft
[01/11/2008|19.41] C:\DOCUME~1\ADMINI~1\DATIAP~1\Google
[10/09/2008|22.10] C:\DOCUME~1\ADMINI~1\DATIAP~1\GrabPro
[26/08/2008|21.32] C:\DOCUME~1\ADMINI~1\DATIAP~1\Help
[24/08/2008|23.28] C:\DOCUME~1\ADMINI~1\DATIAP~1\Identities
[08/09/2008|20.26] C:\DOCUME~1\ADMINI~1\DATIAP~1\InstallShield
[24/08/2008|23.46] C:\DOCUME~1\ADMINI~1\DATIAP~1\Macromedia
[29/10/2008|09.54] C:\DOCUME~1\ADMINI~1\DATIAP~1\Malwarebytes
[22/09/2008|20.03] C:\DOCUME~1\ADMINI~1\DATIAP~1\Media Player Classic
[15/02/2009|19.01] C:\DOCUME~1\ADMINI~1\DATIAP~1\Microsoft
[19/10/2008|20.31] C:\DOCUME~1\ADMINI~1\DATIAP~1\mIRC
[25/08/2008|00.15] C:\DOCUME~1\ADMINI~1\DATIAP~1\Motive
[13/02/2009|17.46] C:\DOCUME~1\ADMINI~1\DATIAP~1\Mozilla
[25/08/2008|15.40] C:\DOCUME~1\ADMINI~1\DATIAP~1\Nero
[30/10/2008|20.27] C:\DOCUME~1\ADMINI~1\DATIAP~1\OpenOffice.org
[03/10/2008|00.09] C:\DOCUME~1\ADMINI~1\DATIAP~1\Orbit
[23/10/2008|22.27] C:\DOCUME~1\ADMINI~1\DATIAP~1\Safer Networking
[26/11/2008|01.31] C:\DOCUME~1\ADMINI~1\DATIAP~1\Softvision
[01/09/2008|17.47] C:\DOCUME~1\ADMINI~1\DATIAP~1\Sun
[25/08/2008|15.06] C:\DOCUME~1\ADMINI~1\DATIAP~1\Thunderbird
[29/08/2008|13.21] C:\DOCUME~1\ADMINI~1\DATIAP~1\TVU Networks
[15/02/2009|23.29] C:\DOCUME~1\ADMINI~1\DATIAP~1\uTorrent
[13/02/2009|18.09] C:\DOCUME~1\ADMINI~1\DATIAP~1\vghd
[01/12/2008|18.53] C:\DOCUME~1\ADMINI~1\DATIAP~1\vlc
[21/10/2008|18.00] C:\DOCUME~1\ADMINI~1\DATIAP~1\Winamp
[12/02/2009|23.27] C:\DOCUME~1\ADMINI~1\DATIAP~1\Windows Live Writer
[25/08/2008|00.33] C:\DOCUME~1\ADMINI~1\DATIAP~1\WinRAR
[0|File] C:\DOCUME~1\ADMINI~1\DATIAP~1\byte
[38|Directory] C:\DOCUME~1\ADMINI~1\DATIAP~1\byte disponibili

[12/02/2009|16.21] C:\DOCUME~1\ALLUSE~1\DATIAP~1\80ckVB
[18/01/2009|12.51] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Adobe
[15/02/2009|23.28] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Avira
[23/09/2008|00.16] C:\DOCUME~1\ALLUSE~1\DATIAP~1\AVS4YOU
[25/08/2008|00.21] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Creative
[21/09/2008|23.41] C:\DOCUME~1\ALLUSE~1\DATIAP~1\GiocoDigitale
[04/11/2008|01.25] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Google
[08/09/2008|20.26] C:\DOCUME~1\ALLUSE~1\DATIAP~1\InstallShield
[29/10/2008|13.01] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Kaspersky Lab Setup Files
[31/10/2008|00.05] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Lavasoft
[29/10/2008|09.54] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Malwarebytes
[13/02/2009|01.40] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Messenger Plus!
[14/02/2009|21.23] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Microsoft
[30/10/2008|17.05] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Microsoft Help
[25/08/2008|15.38] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Nero
[27/08/2008|14.52] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Office Genuine Advantage
[25/08/2008|12.42] C:\DOCUME~1\ALLUSE~1\DATIAP~1\PC Drivers HeadQuarters
[27/08/2008|14.53] C:\DOCUME~1\ALLUSE~1\DATIAP~1\SecTaskMan
[16/02/2009|11.52] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Spybot - Search & Destroy
[29/08/2008|13.21] C:\DOCUME~1\ALLUSE~1\DATIAP~1\TVU Networks
[29/10/2008|14.32] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Windows Genuine Advantage
[25/08/2008|00.31] C:\DOCUME~1\ALLUSE~1\DATIAP~1\WinZip
[25/08/2008|16.51] C:\DOCUME~1\ALLUSE~1\DATIAP~1\WLInstaller
[0|File] C:\DOCUME~1\ALLUSE~1\DATIAP~1\byte
[25|Directory] C:\DOCUME~1\ALLUSE~1\DATIAP~1\byte disponibili

[24/08/2008|23.19] C:\DOCUME~1\DEFAUL~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\DEFAUL~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\DEFAUL~1\DATIAP~1\byte disponibili

[15/02/2009|19.01] C:\DOCUME~1\LOCALS~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\LOCALS~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\LOCALS~1\DATIAP~1\byte disponibili

[15/02/2009|19.01] C:\DOCUME~1\NETWOR~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\NETWOR~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\NETWOR~1\DATIAP~1\byte disponibili

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[16/02/2009 11.19][--a------] C:\WINDOWS\tasks\GlaryInitialize.job
[15/02/2009 15.49][--a------] C:\WINDOWS\tasks\OGADaily.job
[16/02/2009 11.19][--a------] C:\WINDOWS\tasks\OGALogon.job
[16/02/2009 11.19][--ah-----] C:\WINDOWS\tasks\SA.DAT
[31/08/2001 18.00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Programmi

[18/01/2009|12.50] C:\Programmi\Adobe
[29/10/2008|14.36] C:\Programmi\Alice ti aiuta
[25/08/2008|19.16] C:\Programmi\AskSBar
[25/08/2008|00.17] C:\Programmi\ATI Technologies
[25/08/2008|16.29] C:\Programmi\Auslogics
[14/02/2009|21.37] C:\Programmi\AVG
[15/02/2009|23.40] C:\Programmi\Avira
[23/09/2008|00.17] C:\Programmi\AVS4YOU
[18/09/2008|00.50] C:\Programmi\BS.Player ControlBar
[25/08/2008|18.24] C:\Programmi\CCleaner
[03/09/2008|20.16] C:\Programmi\CD_DVD-ROM Generator 1.20
[14/02/2009|16.51] C:\Programmi\Circle Development
[24/08/2008|23.42] C:\Programmi\Common Files
[26/08/2008|01.17] C:\Programmi\COMODO
[24/08/2008|23.15] C:\Programmi\ComPlus Applications
[13/02/2009|00.25] C:\Programmi\Conduit
[26/08/2008|22.17] C:\Programmi\CONEXANT
[26/08/2008|20.16] C:\Programmi\Dell Photo AIO Printer 924
[11/02/2009|16.06] C:\Programmi\DkZ Studio
[04/09/2008|12.05] C:\Programmi\DkZ Update
[25/08/2008|12.59] C:\Programmi\Driver-Soft
[25/08/2008|18.23] C:\Programmi\DustBuster XP
[29/10/2008|14.35] C:\Programmi\EliBagle
[06/10/2008|16.08] C:\Programmi\Everest Poker.net
[12/02/2009|22.01] C:\Programmi\File comuni
[15/02/2009|23.17] C:\Programmi\FindyKill
[10/02/2009|13.31] C:\Programmi\Foxit Software
[10/09/2008|22.08] C:\Programmi\Free Music Zilla
[07/12/2008|18.25] C:\Programmi\Game Graphic Studio
[23/09/2008|12.43] C:\Programmi\GiocoDigitale
[13/12/2008|18.16] C:\Programmi\Glary Utilities
[04/11/2008|01.25] C:\Programmi\Google
[07/01/2009|19.40] C:\Programmi\GRETECH
[26/08/2008|21.01] C:\Programmi\Idf
[17/11/2008|21.31] C:\Programmi\IKEA HomePlanner
[26/11/2008|01.30] C:\Programmi\InstallShield Installation Information
[25/08/2008|13.56] C:\Programmi\Intel
[12/02/2009|19.30] C:\Programmi\Internet Explorer
[21/12/2008|23.27] C:\Programmi\Java
[08/01/2009|13.32] C:\Programmi\JRE
[29/11/2008|12.01] C:\Programmi\Kaspersky Lab
[31/10/2008|00.03] C:\Programmi\Lavasoft
[16/02/2009|11.19] C:\Programmi\Malwarebytes' Anti-Malware
[23/09/2008|20.41] C:\Programmi\Messenger
[13/02/2009|00.05] C:\Programmi\Messenger Plus! Live
[12/02/2009|22.45] C:\Programmi\Microsoft
[23/09/2008|20.46] C:\Programmi\microsoft frontpage
[12/02/2009|22.43] C:\Programmi\Microsoft SQL Server Compact Edition
[12/02/2009|22.44] C:\Programmi\Microsoft Sync Framework
[08/01/2009|13.13] C:\Programmi\Microsoft.NET
[13/02/2009|18.23] C:\Programmi\MouseRunner.com
[23/09/2008|20.38] C:\Programmi\Movie Maker
[16/02/2009|11.53] C:\Programmi\Mozilla Firefox
[16/02/2009|12.09] C:\Programmi\Mozilla Thunderbird
[07/01/2009|19.34] C:\Programmi\Mplayer
[30/10/2008|17.03] C:\Programmi\MSBuild
[24/08/2008|23.15] C:\Programmi\MSN Gaming Zone
[15/11/2008|02.32] C:\Programmi\MSXML 4.0
[24/08/2008|23.22] C:\Programmi\MSXML 6.0
[13/02/2009|20.49] C:\Programmi\Navilog1
[25/08/2008|15.38] C:\Programmi\Nero
[23/09/2008|20.35] C:\Programmi\NetMeeting
[13/02/2009|14.23] C:\Programmi\NoAds
[08/01/2009|13.32] C:\Programmi\OpenOffice.org 3
[08/01/2009|13.32] C:\Programmi\OpenOffice.org 3.0 (it) Installation Files
[23/09/2008|20.35] C:\Programmi\Outlook Express
[31/10/2008|01.03] C:\Programmi\PeerGuardian2
[26/08/2008|21.00] C:\Programmi\Pirelli
[15/02/2009|23.42] C:\Programmi\Poker Club by Lottomatica
[04/02/2009|12.31] C:\Programmi\PokerStars.IT
[06/10/2008|15.25] C:\Programmi\PokerStars.NET
[25/08/2008|14.38] C:\Programmi\PowerQuest
[13/02/2009|15.03] C:\Programmi\QUAD Utilities
[10/02/2009|00.31] C:\Programmi\Recovery Toolbox for RAR
[24/08/2008|23.23] C:\Programmi\Reference Assemblies
[02/11/2008|23.03] C:\Programmi\RegSeeker
[04/11/2008|01.27] C:\Programmi\RegToy
[07/01/2009|22.55] C:\Programmi\Security Task Manager
[24/08/2008|23.17] C:\Programmi\Servizi in linea
[26/08/2008|21.37] C:\Programmi\SigmaTel
[08/09/2008|00.55] C:\Programmi\Smart Projects
[05/02/2009|13.51] C:\Programmi\Softonic_Italia
[29/08/2008|13.26] C:\Programmi\SopCast
[31/10/2008|15.55] C:\Programmi\Spybot - Search & Destroy
[24/08/2008|23.40] C:\Programmi\Telecom Italia
[05/11/2008|20.22] C:\Programmi\The KMPlayer
[23/10/2008|22.05] C:\Programmi\Trend Micro
[03/11/2008|18.38] C:\Programmi\TVAnts
[29/08/2008|13.21] C:\Programmi\TVUPlayer
[13/02/2009|17.25] C:\Programmi\vghd
[22/09/2008|21.51] C:\Programmi\VideoLAN
[20/11/2008|20.53] C:\Programmi\VS Revo Group
[18/09/2008|00.50] C:\Programmi\Webteh
[29/10/2008|14.35] C:\Programmi\Winamp
[12/02/2009|22.45] C:\Programmi\Windows Live
[12/02/2009|22.42] C:\Programmi\Windows Live SkyDrive
[24/08/2008|23.15] C:\Programmi\Windows Media Connect 2
[15/02/2009|23.46] C:\Programmi\Windows Media Player
[23/09/2008|20.35] C:\Programmi\Windows NT
[24/08/2008|23.17] C:\Programmi\WindowsUpdate
[25/08/2008|14.42] C:\Programmi\WinRAR
[21/09/2008|22.23] C:\Programmi\wwSms Client
[23/09/2008|20.46] C:\Programmi\xerox
[07/01/2009|19.47] C:\Programmi\XP Codec Pack
[23/10/2008|22.55] C:\Programmi\Yahoo!
[0|File] C:\Programmi\byte
[107|Directory] C:\Programmi\byte disponibili

--------------------\\ Listing Folders in C:\Programmi\File comuni

[18/01/2009|12.51] C:\Programmi\File comuni\Adobe
[23/09/2008|00.17] C:\Programmi\File comuni\AVSMedia
[26/11/2008|23.10] C:\Programmi\File comuni\DESIGNER
[08/09/2008|20.26] C:\Programmi\File comuni\InstallShield
[25/08/2008|16.44] C:\Programmi\File comuni\Java
[12/02/2009|22.42] C:\Programmi\File comuni\Microsoft Shared
[24/08/2008|23.42] C:\Programmi\File comuni\Motive
[24/08/2008|23.17] C:\Programmi\File comuni\MSSoap
[25/08/2008|15.39] C:\Programmi\File comuni\Nero
[25/08/2008|01.10] C:\Programmi\File comuni\ODBC
[25/08/2008|18.25] C:\Programmi\File comuni\Services
[25/08/2008|01.10] C:\Programmi\File comuni\SpeechEngines
[26/11/2008|23.10] C:\Programmi\File comuni\System
[02/11/2008|14.49] C:\Programmi\File comuni\uusee
[12/02/2009|22.01] C:\Programmi\File comuni\Windows Live
[25/08/2008|16.55] C:\Programmi\File comuni\WindowsLiveInstaller
[07/02/2009|22.20] C:\Programmi\File comuni\Wise Installation Wizard
[0|File] C:\Programmi\File comuni\byte
[19|Directory] C:\Programmi\File comuni\byte disponibili

--------------------\\ Process

( 36 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-16 12:24:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections


No other infections found !

[F:15][D:3]-> C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp
[F:16][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
[F:72][D:4]-> C:\DOCUME~1\ADMINI~1\IMPOST~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 13/02/2009|21.37 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 13/02/2009|21.41 - Option : [2]
3 - "C:\Lop SD\LopR_3.txt" - 16/02/2009|12.21 - Option : [1]
4 - "C:\Lop SD\LopR_4.txt" - 16/02/2009|12.25 - Option : [2]

--------------------\\ Scan completed at 12.25.09

Infine log di hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12.28.22, on 16/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avguard.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avesvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Windows Live\Family Safety\fsssvc.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avmailc.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\Programmi\Windows Live\Family Safety\fsui.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\GiocoDigitale\Poker\GiocoDigitalePoker.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yoby.net/sb/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/webhp?hl=it
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Softonic Italia Toolbar - {4edd5c14-2d22-4d7a-9748-c975a7fd933b} - C:\Programmi\Softonic_Italia\tbSof1.dll
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Programmi\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Programmi\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Softonic Italia Toolbar - {4edd5c14-2d22-4d7a-9748-c975a7fd933b} - C:\Programmi\Softonic_Italia\tbSof1.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Programmi\Windows Live\Family Safety\fssbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: BS.Player ControlBar - {2C688203-7EB3-4327-9995-1CB417BA23F9} - C:\Programmi\BS.Player ControlBar\BSToolbar.dll
O3 - Toolbar: Softonic Italia Toolbar - {4edd5c14-2d22-4d7a-9748-c975a7fd933b} - C:\Programmi\Softonic_Italia\tbSof1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [fssui] "C:\Programmi\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programmi\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Premium\avmailc.exe
O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Premium\sched.exe
O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Premium\avguard.exe
O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Servizio assistenza di Avira AntiVir Premium MailGuard (AVEService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Premium\avesvc.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Programmi\Windows Live\installer\WLSetupSvc.exe (file missing)

--
End of file - 9819 bytes
shapiro
Inviato: Monday, February 16, 2009 12:44:34 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
Avvia Hijackthis e clicca su "do a system scan only"
Metti la spunta a queste voci e clicca su "fix checked



R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Programmi\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)


controlla questo in rosso C:\Programmi\Softonic_Italia\tbSof1.dll


fallo da qui ► http://www.virustotal.com/it/


ma quante toolbar hai installate??

l'hai installata tu questa ControlBar toolbar?
mediterraneo78
Inviato: Monday, February 16, 2009 12:55:22 PM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
ne avevo installate un bel po' che poi ho eliminato cmq questo è il rapporto di C:\Programmi\Softonic_Italia\tbSof1.dll:


File tbfre1.dll ricevuto il 2009.02.16 10:30:53 (CET)
Antivirus Versione Ultimo aggiornamento Risultato
a-squared 4.0.0.93 2009.02.16 -
AhnLab-V3 5.0.0.2 2009.02.16 -
AntiVir 7.9.0.79 2009.02.15 -
Authentium 5.1.0.4 2009.02.15 W32/OnlineGames.A.gen!Eldorado
Avast 4.8.1335.0 2009.02.15 -
AVG 8.0.0.237 2009.02.15 -
BitDefender 7.2 2009.02.16 -
CAT-QuickHeal 10.00 2009.02.16 -
ClamAV 0.94.1 2009.02.16 -
Comodo 978 2009.02.15 -
DrWeb 4.44.0.09170 2009.02.16 -
eSafe 7.0.17.0 2009.02.15 -
eTrust-Vet 31.6.6358 2009.02.16 -
F-Prot 4.4.4.56 2009.02.15 W32/OnlineGames.A.gen!Eldorado
F-Secure 8.0.14470.0 2009.02.16 -
Fortinet 3.117.0.0 2009.02.15 -
GData 19 2009.02.16 -
Ikarus T3.1.1.45.0 2009.02.16 -
K7AntiVirus 7.10.630 2009.02.14 -
Kaspersky 7.0.0.125 2009.02.16 -
McAfee 5527 2009.02.15 -
McAfee+Artemis 5527 2009.02.15 -
Microsoft 1.4306 2009.02.16 -
NOD32 3855 2009.02.16 -
Norman 6.00.02 2009.02.13 -
nProtect 2009.1.8.0 2009.02.16 -
Panda 10.0.0.10 2009.02.15 -
PCTools 4.4.2.0 2009.02.15 -
Prevx1 V2 2009.02.16 -
Rising 21.17.01.00 2009.02.16 -
SecureWeb-Gateway 6.7.6 2009.02.16 -
Sophos 4.38.0 2009.02.16 -
Sunbelt 3.2.1851.2 2009.02.12 -
Symantec 10 2009.02.16 -
TheHacker 6.3.2.1.258 2009.02.16 -
TrendMicro 8.700.0.1004 2009.02.16 -
VBA32 3.12.8.12 2009.02.16 -
ViRobot 2009.2.16.1608 2009.02.16 -
VirusBuster 4.5.11.0 2009.02.15 -
Informazioni addizionali
File size: 1881112 bytes
MD5...: f9b508bc69d1ee43a09dfbcae6c42e04
SHA1..: f31b07e34538a43fef46847cd29a001069780d19
SHA256: b755356503232df79de9b08c116e870ef03ac1f6b1b3bdb77b7afbe06c12cfcf
SHA512: d9b9b4b111db21fc0989576d22756a406634722abaae044677615684925521a1<br>c89d5e7c099c97723b9cd88cd0996ca1a3ebf20730157c5c69fef6e034535dee<br>
ssdeep: 24576:tS7xQcB+fGWuUNWUEkw4Xs+a7W/4dI6U2prKGa40BcVg9SSXJ6gelveCFi<br>B65df9:tOOGWDUhibTpW463fHzVQ6tLT<br>
PEiD..: -
TrID..: File type identification<br>Windows OCX File (71.0%)<br>Win32 Executable MS Visual C++ (generic) (21.6%)<br>Win32 Executable Generic (4.9%)<br>Generic Win/DOS Executable (1.1%)<br>DOS Executable Generic (1.1%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0xde15a<br>timedatestamp.....: 0x4975cd8f (Tue Jan 20 13:11:43 2009)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x10da12 0x10dc00 6.56 7c135281188d610ed638c7234c241966<br>.rdata 0x10f000 0x55d7f 0x55e00 4.51 7c6252c1f58f4dc55afde9bb9efae496<br>.data 0x165000 0x6260 0x4200 4.84 17d3e694c044f25072850637c050a8e0<br>.rsrc 0x16c000 0x4c170 0x4c200 5.65 488b4a71ffb64bf677b82c6e58d78564<br>.reloc 0x1b9000 0x16442 0x16600 5.90 e4eb470fb6941fbbb82b6942efa51b1b<br><br>( 19 imports ) <br>&gt; COMCTL32.dll: ImageList_ReplaceIcon, CreatePropertySheetPageW, PropertySheetW, CreateToolbarEx, InitCommonControlsEx, _TrackMouseEvent, ImageList_Create<br>&gt; WININET.dll: DeleteUrlCacheEntry, FindNextUrlCacheEntryA, FindFirstUrlCacheEntryA, InternetCanonicalizeUrlW, InternetCrackUrlW, InternetCloseHandle, InternetSetOptionA, InternetCanonicalizeUrlA, FindCloseUrlCache, InternetSetOptionExA, InternetConnectA, InternetGetLastResponseInfoA, HttpSendRequestA, HttpQueryInfoA, InternetOpenA, InternetCrackUrlA, InternetOpenW, InternetSetOptionW, InternetOpenUrlW, InternetReadFile, InternetGetConnectedState, HttpOpenRequestA, GetUrlCacheEntryInfoW, InternetQueryOptionA<br>&gt; SHLWAPI.dll: PathFileExistsW<br>&gt; WSOCK32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -<br>&gt; VERSION.dll: GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW<br>&gt; MSIMG32.dll: GradientFill<br>&gt; urlmon.dll: ObtainUserAgentString, URLDownloadToFileW<br>&gt; CRYPT32.dll: CryptMsgClose, CryptProtectData, CryptUnprotectData, CryptQueryObject, CryptMsgGetParam, CertFindCertificateInStore, CertGetNameStringW, CertFreeCertificateContext, CertCloseStore, CertGetNameStringA<br>&gt; WINMM.dll: PlaySoundW, sndPlaySoundW, PlaySoundA, timeGetTime<br>&gt; KERNEL32.dll: GetVersionExA, GetLocalTime, GetModuleHandleW, GetLongPathNameW, GetModuleFileNameA, GetCurrentThreadId, lstrcpyA, GetTickCount, GetThreadLocale, SetEndOfFile, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, CreateFileA, SetStdHandle, GetLocaleInfoA, FlushFileBuffers, SetFilePointer, GetConsoleMode, GetConsoleCP, GetStringTypeW, GetStringTypeA, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetFileType, SetHandleCount, HeapSize, LCMapStringW, LCMapStringA, GetOEMCP, GetACP, GetCPInfo, GetStdHandle, WriteFile, ExitProcess, VirtualFree, HeapCreate, HeapDestroy, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, InterlockedIncrement, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, VirtualAlloc, MoveFileW, GetProcessHeap, GetCommandLineA, ResumeThread, ExitThread, RaiseException, GetSystemTimeAsFileTime, HeapReAlloc, HeapAlloc, HeapFree, RtlUnwind, ReleaseSemaphore, CreateSemaphoreW, InterlockedExchange, GetCurrentThread, SetThreadPriority, GetComputerNameW, MoveFileExW, RemoveDirectoryW, TerminateProcess, CreateToolhelp32Snapshot, Thread32First, Thread32Next, OpenProcess, LocalAlloc, InterlockedDecrement, OutputDebugStringW, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, MulDiv, LoadLibraryA, CreateFileW, GetFileSize, ReadFile, SizeofResource, GlobalAlloc, GlobalLock, GlobalUnlock, GlobalFree, WideCharToMultiByte, GetModuleHandleA, GetLastError, GetModuleFileNameW, CloseHandle, ReleaseMutex, CreateMutexW, GetCurrentProcess, FlushInstructionCache, VirtualProtect, Sleep, ExpandEnvironmentStringsW, CreateProcessW, GetLocaleInfoW, LoadLibraryW, GetProcAddress, FreeLibrary, CreateDirectoryW, Beep, GetDateFormatW, GetTimeFormatW, FindResourceW, LoadResource, LockResource, FreeResource, GetFileAttributesW, WaitForSingleObject, SetLastError, CreateThread, GetExitCodeThread, TerminateThread, FindFirstFileW, DeleteFileW, FindNextFileW, FindClose, MultiByteToWideChar, CopyFileW, GetCurrentProcessId, lstrlenW, lstrcpyW, LocalFree<br>&gt; USER32.dll: GetDlgCtrlID, GetClientRect, SetWindowTextW, SetWindowTextA, wsprintfW, CallWindowProcA, InvalidateRect, GetWindow, GetClassInfoExW, RegisterClassExW, CopyRect, UpdateWindow, GetLastInputInfo, MonitorFromRect, LoadImageW, IsWindow, GetDlgItem, SendMessageA, ClientToScreen, GetParent, GetWindowLongW, SetCursor, LoadCursorA, PostMessageA, ShowWindow, SetWindowLongW, DialogBoxParamW, DialogBoxParamA, CreateDialogParamA, CreateDialogParamW, ReleaseDC, IsWindowEnabled, GetDlgItemTextA, FrameRect, DrawFrameControl, MessageBoxA, GetWindowThreadProcessId, AllowSetForegroundWindow, IsWindowUnicode, GetDesktopWindow, MsgWaitForMultipleObjects, EndDialog, GetDlgItemTextW, GetScrollInfo, IsMenu, GetMenuInfo, SetMenuInfo, GetMenuItemID, GetMenuState, CheckMenuItem, TrackPopupMenu, GetMonitorInfoW, CreatePopupMenu, DestroyMenu, SetClassLongA, SetLayeredWindowAttributes, IsIconic, SetForegroundWindow, PostThreadMessageA, SetWindowRgn, SetWindowPos, EnableWindow, IsDlgButtonChecked, CallWindowProcW, GetMenuItemCount, InsertMenuItemW, SetMenuItemInfoW, GetMenuItemInfoW, DeleteMenu, EnableMenuItem, EndMenu, CheckDlgButton, GetAsyncKeyState, SetActiveWindow, TranslateMessage, GetMessageA, ReleaseCapture, GetCapture, DispatchMessageA, SetCapture, GetCursorPos, BeginPaint, EndPaint, GetUpdateRect, ScreenToClient, SetDlgItemTextW, GetMonitorInfoA, DrawIconEx, GetIconInfo, DestroyIcon, FillRect, GetSysColor, PeekMessageA, MessageBoxW, DefWindowProcW, GetWindowTextW, SendMessageW, GetWindowTextLengthW, SystemParametersInfoW, FindWindowW, IsWindowVisible, SetWindowsHookExA, UnhookWindowsHookEx, GetMenuItemInfoA, CallNextHookEx, GetClassInfoW, RegisterClassW, CreateWindowExW, GetSystemMetrics, KillTimer, GetWindowLongA, SetTimer, UnregisterClassA, GetClassNameW, SetWindowLongA, DefWindowProcA, DestroyWindow, GetFocus, IsChild, SetFocus, PostMessageW, PtInRect, FindWindowExW, RegisterWindowMessageW, GetWindowRect, GetDC, DrawTextW, MoveWindow<br>&gt; GDI32.dll: GetDeviceCaps, GetTextColor, GetBkColor, GetBkMode, SetTextAlign, TextOutW, ExcludeClipRect, RoundRect, CreateRectRgn, CombineRgn, GetPixel, BitBlt, Polygon, GdiFlush, SetPixel, GetObjectA, GetTextAlign, GetTextExtentPoint32W, Rectangle, SetBkColor, CreateSolidBrush, CreateFontIndirectW, GetLayout, CreateCompatibleDC, CreateCompatibleBitmap, PlgBlt, DeleteDC, CreatePen, SelectObject, MoveToEx, LineTo, DeleteObject, GetWindowOrgEx, SetWindowOrgEx, SetBkMode, SetTextColor, GetStockObject<br>&gt; comdlg32.dll: GetOpenFileNameW<br>&gt; ADVAPI32.dll: RegOpenKeyExW, RegSetValueExW, RegCreateKeyExW, RegDeleteKeyW, RegQueryValueExW, CryptAcquireContextA, CryptReleaseContext, OpenProcessToken, GetTokenInformation, GetSidSubAuthorityCount, GetSidSubAuthority, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, RegEnumValueW, RegEnumKeyExW, RegDeleteValueW, RegOpenKeyW, RegEnumKeyW, RegCreateKeyW, RegQueryInfoKeyW, RegCloseKey<br>&gt; SHELL32.dll: ShellExecuteW, SHGetFolderPathW, SHCreateDirectoryExW, ShellExecuteExW<br>&gt; ole32.dll: CoGetMalloc, StringFromIID, CoCreateInstance, IIDFromString, CreateStreamOnHGlobal, CLSIDFromString, CoUninitialize, CoInitialize<br>&gt; OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<br>&gt; PSAPI.DLL: GetModuleFileNameExW, EnumProcessModules, GetProcessMemoryInfo<br>&gt; DNSAPI.dll: DnsQuery_A<br><br>( 11 exports ) <br>DllCanUnloadNow, DllGetClassObject, DllOnUninstall, DllOnUpdateFinish, DllOpenUninstallPage, DllRegisterServer, DllShowTB, DllShowToolbar, DllShowToolbarWithIE, DllUnregisterServer, DllUpdate<br>

shapiro
Inviato: Monday, February 16, 2009 1:24:46 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
e' tutto un ammasso di parole intrecciate Drool non si capisce niente

se non ti servono disinstalla le toolbar e fixa questa voce con hjt

O3 - Toolbar: BS.Player ControlBar - {2C688203-7EB3-4327-9995-1CB417BA23F9} - C:\Programmi\BS.Player ControlBar\BSToolbar.dll

sai dirmi come va' ora il pc?
mediterraneo78
Inviato: Monday, February 16, 2009 1:31:30 PM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
Shapiro il pc va sicuramente meglio solo quando lo chiudo o lo riavvio mi escono quelle finestre seccanti di qualche applicazione che non termina per il resto è ok .

Ho fixato il file che hai detto e ho disinstallato i toobar che non mi servono
shapiro
Inviato: Monday, February 16, 2009 1:33:11 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
spiegati meglio.....quale applicazione?
mediterraneo78
Inviato: Monday, February 16, 2009 1:44:19 PM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
Shapiro il problema che non riesco a capire l'applicazione in pratica mi econo finestre con sopra scritto internet explorer
shapiro
Inviato: Monday, February 16, 2009 1:47:26 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
sopra la finestra ci sara' il nome dell'applicazione....no? hai disinstallato qualche programma ultimamente? dovresti pulire il registro con ccleaner (se lo sai fare) altrimenti ti spiego come fare
mediterraneo78
Inviato: Monday, February 16, 2009 1:48:58 PM
Rank: Newbie

Iscritto dal : 2/13/2009
Posts: 0
se me l'ho spieghi è meglio
shapiro
Inviato: Monday, February 16, 2009 3:32:43 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
di solito io le chiavi che tolgo le controllo da me - se vuoi toglierle senza pericoli, puoi usare reg seeker dove potrai scegliere quali togliere senza usare programmi che tolgono ( a volte) anche quelle che non dovrebbero - fammi sapere se vuoi il ''fai da te'' oppure l'eliminazione automatica con ccleaner
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.