Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

rimuovere virus "Bagle" Opzioni
giovanni6161
Inviato: Tuesday, January 19, 2010 3:55:21 PM
Rank: AiutAmico

Iscritto dal : 4/1/2008
Posts: 187
ciao mi potreste aiutare a rimuovere questo fastidiosissimo virus? vi ringrazio


PS:non riesco a fare i log di hijackthis
Sponsor
Inviato: Tuesday, January 19, 2010 3:55:21 PM

 
r16
Inviato: Tuesday, January 19, 2010 3:57:13 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Scarica Findykill:
http://pagesperso-orange.fr/NosTools/Chiquitine29/Setup.exe
installa FindyKill .
chiudi tutte le eventuali applicazioni aperte (antivirus, firewall e programmi "residenti")
disconnettiti da Internet
sconnetti, fisicamente, il modem dal computer.
avvia il tool e digita F per impostare la lingua;
clicca su 2 - Suppression des fichiers infectieux (Eliminazione dei file infetti)
al termine dell'operazione verrà rilasciato un log: salvalo sul Desktop, e postalo qui.
P.S:
Potranno esserci dei riavvii, non preoccuparti, è il programma che stà lavorando.
*********************************************************************************
Quando hai finito:

Disattiva il ripristino configurazione di sistema, e tienilo disattivato, fino alla soluzione del problema http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121


Scarica elibagla : http://www.zonavirus.com/datos/descargas/95/elibagla.asp scorri a fondo pagina e clicca su "descargar elibagla".
Salva il file sul desktop
IMPORTANTE: Disconnettiti da internet e disattiva il tuo antivirus.
Doppio click sull'icona Elibagla.exe per avviare il programma.
Assicurati che la casella "Eliminar Ficheros Automaticamente" sia spuntata, e clicca sul pulsante "Explorar".
Al termine della scansione DEVI RIAVVIARE il pc,e postare il log che si trova in: C:\InfoSat.txt
giovanni6161
Inviato: Tuesday, January 19, 2010 5:16:19 PM
Rank: AiutAmico

Iscritto dal : 4/1/2008
Posts: 187
ecco il primo log:


############################## | FindyKill V5.024 |

# User : Stefano (Administrators) # ADMIN
# Update on 09/01/2010 by El Desaparecido
# Start at: 16.46.50 | 19/01/2010
# Website : http://pagesperso-orange.fr/NosTools/index.html
# Contact : FindyKill.Contact@gmail.com

# Intel(R) Pentium(R) 4 CPU 3.00GHz
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : ESET NOD32 Antivirus 4.0 4.0 [ Enabled | Updated ]

# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 152,66 Go (74,65 Go free) # NTFS
# D:\ # Disco CD-ROM
# E:\ # Disco CD-ROM
# F:\ # Disco rigido locale # 185,6 Go (118,45 Go free) [Volume] # NTFS

############################## | Active Processes |

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
C:\Programmi\File comuni\Acronis\CDP\afcdpsrv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Programmi\Hotspot Shield\bin\openvpnas.exe
C:\Programmi\Hotspot Shield\HssWPR\hsssrv.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## | C: |


################## | C:\WINDOWS |

Deleted ! C:\WINDOWS\mdelk.exe
Deleted ! C:\WINDOWS\wintems.exe

################## | C:\WINDOWS\Prefetch |

Deleted ! C:\WINDOWS\Prefetch\115078.EXE-0CF8DC9E.pf
Deleted ! C:\WINDOWS\Prefetch\140046.EXE-222CB67C.pf
Deleted ! C:\WINDOWS\Prefetch\147093.EXE-2A8A4EAD.pf
Deleted ! C:\WINDOWS\Prefetch\149031.EXE-05E2A022.pf
Deleted ! C:\WINDOWS\Prefetch\155625.EXE-06F689FD.pf
Deleted ! C:\WINDOWS\Prefetch\156421.EXE-263DDCF9.pf
Deleted ! C:\WINDOWS\Prefetch\164187.EXE-09A1E4D8.pf
Deleted ! C:\WINDOWS\Prefetch\165437.EXE-1A2726FA.pf
Deleted ! C:\WINDOWS\Prefetch\166796.EXE-331A4718.pf
Deleted ! C:\WINDOWS\Prefetch\170890.EXE-0A9AC7C7.pf
Deleted ! C:\WINDOWS\Prefetch\176421.EXE-255105C7.pf
Deleted ! C:\WINDOWS\Prefetch\211921.EXE-2FFA264E.pf
Deleted ! C:\WINDOWS\Prefetch\220890.EXE-073A58F7.pf
Deleted ! C:\WINDOWS\Prefetch\244015.EXE-1070F005.pf
Deleted ! C:\WINDOWS\Prefetch\247625.EXE-026B39EA.pf
Deleted ! C:\WINDOWS\Prefetch\FLEC006.EXE-0392C2EB.pf
Deleted ! C:\WINDOWS\Prefetch\MDELK.EXE-087EF2B4.pf
Deleted ! C:\WINDOWS\Prefetch\SERIAL.EXE-1B51BE9F.pf
Deleted ! C:\WINDOWS\Prefetch\WINTEMS.EXE-127B61D4.pf
Deleted ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-1C18064C.pf

################## | C:\WINDOWS\system32 |

Deleted ! C:\WINDOWS\system32\wfsintwq.sys

################## | C:\WINDOWS\system32\drivers |


################## | C:\Documents and Settings\Stefano\Dati applicazioni |

Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\drivers\downld
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\drivers\winupgro.exe
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\drivers
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\flec006.exe
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\#1 Smart PopUp Stopper Pro 4.4 CrAcKed.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\3D Box Maker Professional v1.2 Build 12200512 WinALL Incl Keygen by ARN.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Adaptec Easy CD Creator v4.0 Deluxe Full.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Address 2000.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Adobe After Effects 4.0 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Adobe Photoshop CS3 v10.0.1.0 by CiM.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\AdventNet ManageEngine OpManager Professional v5.5 Keymaker Only by AGAiN.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\AirStrike 2 v2.12.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\AK Research Labs CHM2Web Pro v2.80.212 by DJiNN.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Akram Audio Converter v2.5 WinALL Incl Keygen by ViRiLiTY.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\ALAP ImagePort for QuarkXPress 1.0.1 for Mac.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Alarm Clock Pro 9.2.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Alarm Master Plus v4.11 Win98MeNT2k by EiTHeL.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Alive Address Book v1.5.2.312 by HERETiC.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Alive MP3 WAV Converter Standard 2.2.1.5.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Alloy Executable Compiler 1.05.13.2000.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Altova MapForce Enterprise v2007.3.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Amethyst CADwizz 1.25c (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Amethyst CADwizz 1.27h.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Ancestral Author v2.3i.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Animate Nature Screensaver v1.01.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\AOL Instant Messenger (AIM) Ads Removal By ReaLIsTy.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Aone Ultra RM Converter v2.4.0 by AT4RE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Apimac Slide Show for Windows v8.0.0 Incl Keymaker by EMBRACE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Ashampoo BurnYa! DataCD v1.3 by SSG.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\AssetManage 99.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Aston 1.2.4.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\AT Screen Thief 3.2.3 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Atomic-FTP 1.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Attractive Clock 2.0.2-key.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\AVISplitter 1.1 (crack).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\AVM Alice 3.00.00 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Baldur's Gate 2 SoA & ToB ITEMS LISTING v2.01.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Baldurs Gate 2.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Battlefield 1942 Secret Weapons of WWII 1 x (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Beta Program Bug & Feature Database 1.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Bid-n-Invoice Home Cleaning 2.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\BitTorrent Acceleration Tool 2.3.8.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Black Widow 4.14 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\BlotterGeist 1.3.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Borland JDataStore v7.05 by SHOCK.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Borland StarTeam Stardisk v6.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Bowling Assistant 1 A4 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\BPS CD Ripper Grabber v3.6.0.2 by ECLiPSE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\BPS SpyWare Adware Remover 8.2.0 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Brickles 3000.1.0 for Mac.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\BriefAudit v1.0a by DBC.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Budget Advisor 1.19.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Cafe Cop 3.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Camtasia Studio 2.0.2.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\CaptureIt v1.2.1 by FFF.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\CBL Web Application Builder v8.01.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\CD Label Designer 2.0 Build 116 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\CDmax 1.8.4.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Ceramic Wares 1.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Charlie and Arnaud 1.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\CheckDialer v1.4 by PC.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\ChrisTWEAK v1.20 Multilanguage by TBE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Contraption Zack (1992) (Presage) FULL!.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Cooking Aficionado v3.0.1 WinALL MULTiLANGUAGE ReggedFAiTH.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\CoolRead v1.7 by DVT.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\CreateInstall Pro v2003.3.0 by SnD.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Crossword Forge v4.0.2 by Core.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Dark Castle 3D Screensaver 1.1 crack.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\DeltaGIS v4.05.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Digigenius DVD to iPhone Converter 3.6.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\DigitByte Ofilter Player v1.1 by RED.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\DlgXRSizer 4.1.6.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\DLSoft dBarcode Java PDF417 v1.00 by Lz0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Domeru DVD to iPod Converter v3.6.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Dungeon Siege 2 NORTHERN & WESTERN GREILYN JUNGLE MAP.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\DVD Cover Searcher v1.1 Cracked by NiTROUS.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Easy File Sharing Web Server v1.23 Keygen by SND.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\EasyQuizz Pro v2.3.2.19 by FRENCH-BS.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Echo Fire 2.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Elektro Puzzle 1.33.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Empire Earth 2 v1.10 [ENGLISH] No-CD Fixed EXE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Enfish Personal 5.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Eurobuchfuehrung v1.6 DateCode 12102004 German by ViRiLiTY.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\EZB Systems UltraISO Media Edition v7.6.6.1308 WinAll Cracked by CRD.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Feurio v1.67 Professional BiLiNGUAL by HARPOON.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Fifa 2005.1.0 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Fighters Clock 1.5.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FinePrint v5.44 Incl Keymaker by ACME.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FineWare Space Hound v4.0.0.1744 by DVT.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Firehand Lightning 2.3.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Flaming Pear LunarCell v1.4.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FlashGet v1.1 Fixed.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FlexHex v2.46 by SND.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FolderView 1.85 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FolderView v1.0 Serial by AmoK.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FSecure AntiVirus Workstation 5.22 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FTP ServU 2.2 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\FWB CDROM Toolkit 2.0.1 for Mac.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Gameloft Battle for The White House v111 Retail JAVA by RLYEH.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\GS Advanced GIF Optimizer 4.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\HalWorks v2.0 by PC.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Hotel Gigant +2 Trainer 2.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\HTML to Image v2.0.2007.708 by CiM.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Icon Extractor 3.3 by Drone.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\IdeaStorm 2.0J for Mac (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\IDentify! 2.5.1 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\II Workproject v4.41 WinALL Regged by ViRiLiTY.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Illumination 110 Lighting Console 1.02.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\imPRESSion Lite 1.01d (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Incredible Hulk Retail JAVA 3220 by RLYEH.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\IOXperts - for Mac (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Iparmor v5.45.0127.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\iSITE 1.0 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\JPG to PDF Creator 4.3.2.1 crack.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Just Buttons v1.6 by Eminence.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Keep Out Halloween Edition 3D Screen Saver 1.5.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\KFSensor v1.5.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Liberty 1.2.5 for PalmOS.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Logger Pro 3.8.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Mahjongg Valentines 1.0 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\MarketSMS 2.3.3595.20567.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Medical Toolbar Icons 2009.2 crack.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\MENTOR GRAPHICS PRECISION RTL SYNTHESIS V2005c 99UDING UPDATE1 LiNUX by NiTROUS.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\MessengerLog v3.07.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Microsoft Windows 98 OEM.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Microstation 3D (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\MindControl 1.1 for Mac (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Moyea DVD to iPhone Converter by RESURRECTiON.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\MP3 Spliter and Joiner v3.32 build 2 by AT4RE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\MultiDB Querier v1.1.1.43 by DiGERATi.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Nalsoft Subtitle Player v1.0.2.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Nero 6.6.0.12 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Nero Burning ROM v5.5.2.4 Regmaker.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\NetBarrier 1.5 for Mac.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\NETSCAN PRO 3.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\NetShade 3.0.2 for Mac (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\NFL 2009 Retail JAVA Motorola K1 by RLYEH.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\NiceTracker 1.01b (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Nord And Bert Couldnt Make Head Or Tail Of It (1987) (Infocom) FULL!.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Office Financials 2000.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\OfficeIRC Server 2.3.287.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Offline Explorer v3.3 build 1788 Standard.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\opera bowser 6.20.0 for Symbian OS (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Overlord [MULTI5] No-DVD - Fixed Image.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Panda Platinum Internet Security v8.03.00.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Patriots Retail JAVA 176x220 by RLYEH.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\PDF Stamp Command Line v1.1 (05-03-2004).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Pdf995 Printer Driver v7.2s WinALL Incl Keymaker by Core.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Pennocks Email Notifier 1.1.10.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\PercussionStudio v3.0f by TMG.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Periscope Image Browser 1.0 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Personal Diary 1.0.0 CrAcKed.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\photoshop 9.0cs2 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\PhotoTools 3.01.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Pocket Relaxer Desktop 1.0 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Power Video Converter v2.2.12 by Under SEH T3am.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Primal Code 3.0.425 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Pristine Sounds 98 SR2.2 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Quick Access Folders and Files v2.0 WinALL Cracked by BRD.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Quota Manager 2.6.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\RandGreg Radio Pro 2.2.2.57.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Real Spy Monitor v2.11 by HERETiC.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Recovery for Access 2.3 Build 11116.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Recovery for Backup 1.8 Build 11052.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Registry Clean Expert v4.52.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Regit Point of Sale v3.50 by Jest Newbee.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\RemodelCOST Estimator for Excel v2.3 DateCode 08182004 WinALL Regged by CHiCNCREAM.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\RemoteExec v3.07 by BLiZZARD.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Replica Single Server 3.05 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Resizer XT 1.2.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\RhythmTutor 1.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\River Past Talkative 2.0.4.40205.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\RoN Thrones and Patriots v3.2.3.2901 & v3.2.3.2905 +3 TRAINER.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\RStudio Agent Emergency v2.0.819 by SCRiPTMAFiA.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\S.T.A.L.K.E.R. Call of Pripyat v1.6.01 SP WEIGHT FIX.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Safe Melt 2.74E.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\SafeHouse 2.00.062 448 Bits (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\SciTech Display Doctor 6.5 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Screen Record 1.3 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\ShuCASH 3000 v3.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Soft PC Big Ben Chimes 1.0.0.6.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Softboy net Exe Icons Changer v4.8c WinALL Incl Keygen by BLiZZARD.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Solas Data Heidenhain CNC Tutor 3.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Sonalksis All Plugins Bundle VST DX RTAS v2.02 Incl KeygenAiR.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Sonic Foundry Video Factory 1.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\SourcePublisher for C Plus Plus v1.4.352b.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\South River Titan FTP Server v4.02.248 Enterprise Edition by ZWT.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\SpyBouncer v1.28 WinALL by TBE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Stars Nues ScreenSaver.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Student Diary 1.61 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Super Ad Blocker v4.2.0.1012 by HERiTAGE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Super Charge 4.5.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Taxi Tycoon v1.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\TeamTrax Lite 1.1 CrAcKed.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Teleport Pro v1.47.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\TFTP Server 2000 v3.6.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\The All Seeing Eye v2.3.3.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\The Bat! v2.01 by Core.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\The Da Vinci Code [MULTI] No-DVD Fixed Image.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Titanium AntiVirus 2006 titanium 2006 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Tom Clancys Rainbow Six 3 Raven Shield v1.41 NoCD Patch by DRUNK.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Tony Hawk's Underground 2 1.00 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Total Recorder v3.0.1 Patch by Lockless2k.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\TrialAction Xmas Volley v1.0 for Pocket PC 2002.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Turbo Connect v2.0.0.2.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Twistingo Deluxe v1.0 GERMAN Cracked WORKING by TNT.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\TypeInIt Professional v2.5.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\UEFA Euro 2004.1.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\UsenetGrab 2.0.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\VisioForge Video Edit SDK (ActiveX Version) 3.71.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\VNI IMSL C Numerical Library v6.0 for VC 6.0 by TBE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\voice changer 4.1 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Vortiball 1.1.3.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\VSE Web Site Turbo 3.0.1 for Mac.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\WAPman 1.5.2 for PalmOS.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Wichio Browser v3.5 WinALL by TBE.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Windows Wallpaper v1.7.4 German WinAll by LAXiTY.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Windows XP Titanium Edition (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\WinRescue ME 1.08.16 (Serial).zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\WinSuperKit 4.2.545.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\WizFlow Flowcharter Professional v5.09.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Word Perfect Works for Mac.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Wordsheets 5.1.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\WorldShift v1.0.21 +11 TRAINER.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Xilisoft DVD Ripper Standard v5.0.27.0131 by CiM.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Xilisoft DVD Ripper Ultimate v5.0.24 build 0111.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Xilisoft DVD Ripper Ultimate v5.0.32 build 0314 by PSC.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Xlinksoft Youtube to MP4 Converter 2009.05.22-key.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Xtreme PhotoStory on CD & DVD 8.0.3.2.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared\Zealot All Video Converter v1.0.5.zip
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m\shared
Deleted ! C:\Documents and Settings\Stefano\Dati applicazioni\m

################## | Reference of comparaison Bagle MD5 : |

File : C:\Documents and Settings\Stefano\Dati applicazioni\drivers\winupgro.exe
-> Crc32 : 5557b760 | Md5 : b23a7d01c4480742d988a71c94d6148f


################## | Other deleting ... |

Deleted ! "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
-> Size : 839168 | Crc32 : 5557b760 | Md5 : b23a7d01c4480742d988a71c94d6148f

################## | Temporary Internet Files |


################## | Registry |

Deleted ! [HKLM\SYSTEM\ControlSet002\Services\sK9Ou0s]
Deleted ! [HKLM\SYSTEM\ControlSet002\Services\srosa]
Deleted ! [HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S]
Deleted ! [HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
Deleted ! [HKCU\Software\bisoft]
Deleted ! [HKCU\Software\DateTime4]
Deleted ! [HKCU\Software\MuleAppData]
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
Deleted ! [HKCU\Software\Local AppWizard-Generated Applications\serial]
Deleted ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]

################## | State |

# Safe boot mode : OK


# Showing of hidden files : OK

# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

################## | PEH |

Corrupted : C:\Documents and Settings\Stefano\Desktop\Cose varie\rimuovere virus\ComboFix.exe
[Offset = 00000204 - Value = 0x0001]

Corrupted : C:\Documents and Settings\Stefano\Desktop\Cose varie\rimuovere virus\HijackThis.exe
[Offset = 000000C4 - Value = 0x0001]

Corrupted : C:\Programmi\ESET\ESET NOD32 Antivirus\egui.exe
[Offset = 000000FC - Value = 0x0001]

Corrupted : C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe
[Offset = 000000F4 - Value = 0x0001]

Corrupted : C:\Programmi\Red Kawa\Video Converter\uninstaller.exe
[Offset = 000000DC - Value = 0x0001]

Corrupted : C:\Programmi\Symantec\Norton PartitionMagic 8.0\DOCS\PM8Flash.exe
[Offset = 0000010C - Value = 0x0001]

Corrupted : C:\Programmi\Symantec\Norton PartitionMagic 8.0\DrvMap.exe
[Offset = 00000204 - Value = 0x0001]

Corrupted : C:\Programmi\Symantec\Norton PartitionMagic 8.0\pqbw.exe
[Offset = 00000114 - Value = 0x0001]

Corrupted : C:\Programmi\Unlocker\UnlockerAssistant.exe
[Offset = 000000E4 - Value = 0x0001]

Corrupted : C:\WINDOWS\$NtServicePackUninstall$\sysinfo.exe
[Offset = 000000E4 - Value = 0x0001]

Attempt of repair...
Backup : sysinfo.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$NtUninstallKB898461$\update.exe
[Offset = 000000E4 - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.



################## | Cracks > Keygens > Serials |

"C:\Documents and Settings\Stefano\Impostazioni locali\Dati applicazioni\tt7_keygen.exe"
27/07/2008 11.00 |Size 49664 |Crc32 25301ecd |Md5 743050c26f8803d4485d3eecc19c038e


################## | End of Report # FindyKill V5.024 ! |


ecco il secondo:


(19-1-2010 15:40:6)
EliBagle v13.43 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 18 de Enero del 2010)

Lista de Acciones (por Acción Directa):
C:\WINDOWS\WINTEMS.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\MDELK.EXE --> Bagle Acceso Denegado.
Por favor, envienos una muestra del fichero
C:\Muestras\WINUPGRO.EXE.Muestra EliBagle v13.43
a "virus@satinfo.es". Gracias.
C:\DOCUMENTS AND SETTINGS\STEFANO\DATI APPLICAZIONI\DRIVERS\WINUPGRO.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\WFSINTWQ.SYS --> Bagle(rootkit) Acceso Denegado.
C:\DOCUMENTS AND SETTINGS\STEFANO\DATI APPLICAZIONI\M\FLEC006.EXE --> Bagle.dldr Acceso Denegado.
Reinicie para Completar la Limpieza.

(19-1-2010 15:40:17)
EliBagle v13.43 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 18 de Enero del 2010)

Lista de Acciones (por Exploración):
Explorando "C:\"

(19-1-2010 16:0:12)
EliBagle v13.43 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 18 de Enero del 2010)

Lista de Acciones (por Acción Directa):

(19-1-2010 16:0:13)
EliBagle v13.43 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 18 de Enero del 2010)

Lista de Acciones (por Exploración):
Explorando "C:\"

Nº Total de Directorios: 9110
Nº Total de Ficheros: 77746
Nº de Ficheros Analizados: 16696
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0


cmq l'antivirus non si avvia ancora
giovanni6161
Inviato: Tuesday, January 19, 2010 7:40:09 PM
Rank: AiutAmico

Iscritto dal : 4/1/2008
Posts: 187
ho disinstallato l'antivirus perchè ormai era inutilizzabile adesso posso comunque completare la procedura di pulizia del pc?
r16
Inviato: Tuesday, January 19, 2010 8:30:00 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Disistalla questi software, in quanto danneggiati:
Combofix.
HijackThis
NOD32 (già fatto mi sembra, poi, ne installeremo un'altro, se il Nod non è a pagamento.)
Norton PartitionMagic 8.0
Unlocker

Scarica ed installa MalwareBytes:
clicca qui per il download : http://www.aiutamici.com/software?id=80346
Prima di fare la scansione AGGIORNALO. (è molto importante)
Esegui una scansione completa del sistema.
Elimina gli eventuali file infetti che trova.
Posta il log.
giovanni6161
Inviato: Tuesday, January 19, 2010 9:58:39 PM
Rank: AiutAmico

Iscritto dal : 4/1/2008
Posts: 187
ecco il log,devo eliminare i file infetti?

Malwarebytes' Anti-Malware 1.44
Versione del database: 3599
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

19/01/2010 21.56.46
mbam-log-2010-01-19 (21-56-36).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 198617
Tempo trascorso: 48 minute(s), 18 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 9
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 5
File infetti: 2

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
C:\Programmi\MyWebSearch (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> No action taken.

File infetti:

C:\Programmi\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> No action taken.
r16
Inviato: Tuesday, January 19, 2010 10:16:51 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
giovanni6161 ha scritto:
ecco il log,devo eliminare i file infetti?

E di corsa anche..... (mi sembra di avertelo scritto)

Scarica Combofix (spero che la versione precedente, l'hai disistallata)

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


Salvalo sul desktop.

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.

giovanni6161
Inviato: Tuesday, January 19, 2010 11:55:08 PM
Rank: AiutAmico

Iscritto dal : 4/1/2008
Posts: 187
ecco il log di combofix:

ComboFix 10-01-19.02 - Stefano 19/01/2010 23.44.07.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.958.571 [GMT 1:00]
Eseguito da: c:\documents and settings\Stefano\Desktop\ComboFix.exe

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\documents and settings\All Users\Dati applicazioni\vlc-1.0.3-win32.exe
c:\documents and settings\Stefano\Dati applicazioni\Desktopicon
c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\pyjscmvf.dat
c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\pyjscmvf.exe
c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\pyjscmvf_nav.dat
c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\pyjscmvf_navps.dat
C:\InfoSat.txt
C:\LOG.TXT
C:\Muestras
c:\muestras\WINUPGRO.EXE.Muestra EliBagle v13.43
c:\windows\struct~.ini
c:\windows\system32\OGACheckControl.dll
c:\windows\system32\twain_32.dll
c:\windows\Tasks\ckfnriwv.job

.
((((((((((((((((((((((((( Files Creati Da 2009-12-19 al 2010-01-19 )))))))))))))))))))))))))))))))))))
.

2010-01-19 22:21 . 2010-01-19 22:21 0 ----a-w- c:\windows\system32\cd.dat
2010-01-19 19:58 . 2010-01-19 19:58 5115823 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-19 17:39 . 2010-01-19 17:39 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Windows Search
2010-01-19 15:04 . 2010-01-19 15:58 -------- d-----w- C:\FindyKill
2010-01-19 14:39 . 2006-01-19 12:15 92672 ----a-r- c:\windows\system32\drivers\viamraid.sys
2010-01-19 14:19 . 2006-02-23 03:39 11264 ----a-r- c:\windows\system32\drivers\xfilt.sys
2010-01-19 14:19 . 2006-02-23 03:38 9728 ----a-r- c:\windows\system32\drivers\videX32.sys
2010-01-19 14:16 . 2010-01-19 14:16 -------- d-----w- c:\programmi\Realtek AC97
2010-01-19 14:06 . 2001-08-30 20:54 3328 -c--a-w- c:\windows\system32\dllcache\pciide.sys
2010-01-19 14:06 . 2001-08-30 20:54 3328 ----a-w- c:\windows\system32\drivers\pciide.sys
2010-01-19 13:43 . 1997-11-19 14:49 303616 ----a-w- c:\windows\IsUninst.exe
2010-01-19 13:43 . 2010-01-19 13:43 -------- d-----w- c:\documents and settings\Stefano\WINDOWS
2010-01-16 20:01 . 2010-01-16 20:28 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Adobe
2010-01-16 20:01 . 2010-01-16 20:01 -------- d-----w- c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\Identities
2010-01-16 20:01 . 2010-01-16 20:01 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Windows Desktop Search
2010-01-16 19:59 . 2010-01-17 07:49 -------- d-----w- c:\programmi\Windows Desktop Search
2010-01-16 19:59 . 2010-01-16 19:59 -------- d-----w- c:\windows\system32\GroupPolicy
2010-01-16 19:57 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-01-16 19:57 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-01-16 19:57 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-01-15 14:05 . 2010-01-15 14:05 -------- d-----w- c:\programmi\File comuni\eSellerate
2010-01-15 14:04 . 2010-01-16 12:45 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\vlc
2010-01-13 09:49 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-13 09:49 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-13 09:49 . 2009-07-14 00:15 90112 ----a-w- c:\windows\system32\dpl100.dll
2010-01-13 09:49 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2010-01-13 09:49 . 2009-07-14 00:15 685056 ----a-w- c:\windows\system32\divx.dll
2010-01-13 09:49 . 2010-01-05 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-13 09:49 . 2010-01-13 09:52 -------- d-----w- c:\programmi\K-Lite Codec Pack
2010-01-12 21:19 . 2009-11-21 15:54 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 18:26 . 2010-01-11 18:26 -------- d-----w- c:\programmi\FreeTime
2010-01-11 18:02 . 2010-01-11 18:02 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NCH Software
2010-01-11 18:02 . 2010-01-11 18:10 -------- d-----w- c:\programmi\NCH Software
2010-01-07 17:25 . 2010-01-07 17:25 -------- d-----w- C:\Hotspot Shield
2010-01-07 17:24 . 2010-01-07 17:25 -------- d-----w- c:\programmi\Hotspot Shield
2010-01-05 20:19 . 2010-01-05 20:19 -------- d-----w- c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\TVLC
2010-01-04 20:24 . 2010-01-04 20:24 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\OpenDNS Updater
2010-01-01 11:45 . 2010-01-01 11:45 -------- d-----w- c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\MetaGeek,_LLC
2010-01-01 11:37 . 2010-01-01 11:37 -------- d-----w- c:\programmi\MetaGeek
2009-12-27 17:02 . 2007-08-22 18:53 -------- d-----w- C:\msinst
2009-12-27 17:02 . 2007-08-22 18:53 -------- d-----w- C:\installer
2009-12-27 17:02 . 2007-08-22 18:53 -------- d-----w- C:\battery
2009-12-21 18:16 . 2009-12-21 18:16 152576 ----a-w- c:\documents and settings\Stefano\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-21 18:15 . 2009-12-21 18:15 79488 ----a-w- c:\documents and settings\Stefano\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-21 11:38 . 2009-12-21 11:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-19 19:58 . 2009-01-07 22:11 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-19 19:54 . 2008-07-16 09:05 -------- d-----w- c:\programmi\Unlocker
2010-01-19 19:46 . 2008-04-16 17:50 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\uTorrent
2010-01-19 16:43 . 2004-08-30 20:00 88772 ----a-w- c:\windows\system32\perfc010.dat
2010-01-19 16:43 . 2004-08-30 20:00 504918 ----a-w- c:\windows\system32\perfh010.dat
2010-01-19 14:20 . 2009-12-08 20:26 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-19 13:50 . 2008-09-09 20:49 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\MegauploadToolbar
2010-01-16 21:35 . 2008-04-16 15:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-01-16 18:01 . 2008-04-16 17:58 -------- d-----w- c:\programmi\File comuni\Adobe
2010-01-16 17:44 . 2008-06-22 16:57 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Canon
2010-01-13 10:42 . 2008-04-16 15:06 70992 ----a-w- c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-01-13 09:45 . 2008-04-16 15:38 -------- d-----w- c:\programmi\DivX
2010-01-12 16:51 . 2009-12-12 13:20 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\LimeWire
2010-01-07 15:07 . 2009-01-07 22:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-01-07 22:27 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-28 10:52 . 2008-04-16 17:39 -------- d-----w- c:\programmi\Messenger Plus! Live
2009-12-26 11:38 . 2008-04-18 12:33 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Skype
2009-12-26 11:24 . 2008-04-18 12:34 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\skypePM
2009-12-21 20:32 . 2008-04-16 14:15 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-12-21 18:18 . 2008-04-16 17:38 -------- d-----w- c:\programmi\Java
2009-12-19 17:48 . 2009-12-19 17:48 -------- d-----w- c:\programmi\Sagasoft
2009-12-18 19:01 . 2009-12-18 18:59 -------- d-----w- c:\programmi\UltraMixer
2009-12-15 19:24 . 2009-12-15 19:24 -------- d-----w- c:\programmi\ConvertHelper
2009-12-12 14:15 . 2002-10-15 22:54 178176 ----a-w- c:\windows\system32\unrar.dll
2009-12-12 13:08 . 2009-12-12 13:08 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-12-10 15:27 . 2009-12-10 15:27 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\VoipCheapCom
2009-12-09 20:59 . 2009-02-16 13:13 -------- d-----w- c:\programmi\Samsung
2009-12-09 17:31 . 2009-12-09 17:31 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Thunderbird
2009-12-08 18:31 . 2009-12-08 18:04 -------- d--h--w- c:\programmi\FX Uninstall Information
2009-12-08 17:39 . 2009-12-08 17:39 -------- d-----w- c:\programmi\Megaupload
2009-12-08 16:46 . 2008-04-16 16:01 -------- d-----w- c:\programmi\Microsoft Works
2009-12-08 15:26 . 2009-12-08 15:25 -------- d-----w- c:\programmi\LimeWire
2009-12-08 15:19 . 2008-07-19 20:57 -------- d-----w- c:\programmi\ZAR
2009-12-08 15:11 . 2008-06-02 18:36 -------- d-----w- c:\programmi\Google
2009-12-08 15:07 . 2008-04-23 18:31 -------- d-----w- c:\programmi\BearShare Test
2009-12-08 14:42 . 2009-12-08 14:42 159168 ----a-w- c:\windows\system32\drivers\afcdp.sys
2009-12-08 14:42 . 2009-01-27 17:42 -------- d-----w- c:\programmi\File comuni\Acronis
2009-12-08 14:42 . 2009-12-08 14:42 911552 ----a-w- c:\windows\system32\drivers\tdrpm255.sys
2009-12-08 14:42 . 2008-07-24 12:29 570016 ----a-w- c:\windows\system32\drivers\timntr.sys
2009-12-08 14:42 . 2008-07-24 12:29 157248 ----a-w- c:\windows\system32\drivers\snapman.sys
2009-12-08 14:35 . 2009-01-27 17:42 -------- d-----w- c:\programmi\Acronis
2009-12-08 14:14 . 2008-04-16 15:22 75776 ----a-w- c:\windows\system32\storprop.dll
2009-12-08 14:14 . 2004-08-30 20:00 40448 ----a-w- c:\windows\system32\drivers\intelppm.sys
2009-12-08 14:14 . 2004-08-30 20:00 188416 ----a-w- c:\windows\system32\drivers\acpi.sys
2009-12-08 14:14 . 2004-08-30 20:00 68736 ----a-w- c:\windows\system32\drivers\pci.sys
2009-11-21 15:54 . 2004-08-30 20:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-12 21:42 . 2009-11-12 21:42 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2009-11-12 21:42 . 2009-11-12 21:42 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2009-10-29 07:40 . 2004-08-30 20:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
2008-11-24 19:48 . 2008-11-24 19:38 24 --sh--w- c:\windows\SF2224595.tmp
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2010-01-07 17:24 218160 ----a-w- c:\programmi\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-29 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-09-21 53248]
"VTTrayp"="VTtrayp.exe" [2007-08-27 200704]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-05-26 413696]
"AppleSyncNotifier"="c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-20 177472]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"TrueImageMonitor.exe"="c:\programmi\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-10-06 5076088]
"Servizio Acronis Scheduler2"="c:\programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2009-10-06 357688]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\Orbitdownloader\\orbitdm.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitnet.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Motorola\\Software Update\\msu.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\WCESMgr.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Stefano\\Desktop\\Programmi vari\\My Mobile\\MyMobiler\\MyMobiler.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [23/06/2008 18.44.20 5248]
R0 tdrpman255;Acronis Try&Decide and Restore Points filter (build 255);c:\windows\system32\drivers\tdrpm255.sys [08/12/2009 15.42.47 911552]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [19/01/2010 15.19.41 11264]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [16/04/2008 15.07.47 13696]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\programmi\File comuni\Acronis\CDP\afcdpsrv.exe [08/12/2009 15.42.54 2326920]
R2 LF30FS;LF30FS;c:\programmi\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [19/11/2004 17.07.00 101488]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [08/12/2009 15.42.59 159168]
R3 portio32;portio32;c:\windows\system32\drivers\portio32.sys [29/05/2009 17.22.58 2048]
S0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [23/06/2008 18.44.20 160640]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys --> c:\windows\system32\DRIVERS\ehdrv.sys [?]
S2 ekrn;ESET Service;"c:\programmi\ESET\ESET NOD32 Antivirus\ekrn.exe" --> c:\programmi\ESET\ESET NOD32 Antivirus\ekrn.exe [?]
S2 gupdate1c9f8bbd63beb96;Servizio di Google Update (gupdate1c9f8bbd63beb96);c:\programmi\Google\Update\GoogleUpdate.exe [29/06/2009 14.16.37 133104]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [30/08/2004 21.00.00 3584]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [30/04/2009 14.24.54 12672]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [06/09/2009 17.21.33 17149]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [02/02/2009 11.44.26 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [02/02/2009 11.44.27 7680]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [07/11/2008 20.13.02 42112]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [06/09/2009 17.21.28 362944]
.
Contenuto della cartella 'Scheduled Tasks'

2010-01-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34]

2010-01-19 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-02 13:13]

2010-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-29 13:16]

2010-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-29 13:16]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://google.it/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Do&wnload selected by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/202
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {17FF1734-F917-4576-A0D5-7D3AE7A389A0} = 212.216.172.62,194.243.154.62
FF - ProfilePath - c:\documents and settings\Stefano\Dati applicazioni\Mozilla\Firefox\Profiles\fakteoqj.default\
FF - prefs.js: browser.startup.homepage - hxxp://it.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:it:official
FF - plugin: c:\programmi\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\programmi\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\programmi\File comuni\Nero\Lib\NMBgMonitor.exe
HKCU-Run-VoipCheapCom - c:\programmi\VoipCheapCom.com\VoipCheapCom\VoipCheapCom.exe
HKLM-Run-LFAgent - (no file)
HKLM-Run-UUSeeMediaCenter - c:\programmi\File comuni\uusee\UUSeeMediaCenter.exe
AddRemove-EADM - c:\programmi\Electronic Arts\EADM\Uninstall.exe
AddRemove-eMule - c:\programmi\eMule\Uninstall.exe
AddRemove-HijackThis - c:\docume~1\Stefano\IMPOST~1\Temp\Rar$EX00.359\HijackThis.exe
AddRemove-kikin plugin (JDownloader Edition) - c:\programmi\kikin\uninst.exe
AddRemove-pyjscmvf - c:\documents and settings\stefano\impostazioni locali\dati applicazioni\pyjscmvf.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-19 23:49
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\S-1-5-21-1202660629-179605362-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FA5C0FCD-D2AA-C76B-0638-671A85EB2C11}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oaknbpomopoonhffbeaimkghjddcme"=hex:6a,61,6f,6d,6b,69,61,65,6e,69,68,63,6c,6e,
68,65,6f,65,65,65,00,21
"naindnkgjebddfddopngddeepklc"=hex:6a,61,6f,6d,6b,69,61,65,6e,69,68,63,6c,6e,
68,65,6f,65,65,65,00,21
.
Ora fine scansione: 2010-01-19 23:52:25
ComboFix-quarantined-files.txt 2010-01-19 22:52

Pre-Run: 80.335.831.040 byte disponibili
Post-Run: 80.286.031.872 byte disponibili

- - End Of File - - C3D3D1F46B052726DA1C88FD789C5A72
r16
Inviato: Wednesday, January 20, 2010 12:17:57 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Non mi sembra che hai disistallato il Nod.
Esegui questo tooll che elimina gli eventuali "rimasugli":
http://www.nod32.nl/download/tool/nod32removal.exe

Poi:
Apri un file di testo sul Desktop (start\esegui\digita: notepad.exe\ Ok
Ci incolli il codice che vedi qui sotto, e salvi il file di testo obbligatoriamente con il nome CFScript.txt

Code:
Folder::
c:\programmi\Unlocker

RegNull::
[HKEY_USERS\S-1-5-21-1202660629-179605362-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FA5C0FCD-D2AA-C76B-0638-671A85EB2C11}*]

e trascinalo sull'icona di ComboFix.
Attendi la fine dei lavori, senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix

Quando hai finito installa questo antivirus:
Scarica Avira:
http://www.aiutamici.com/software?ID=10908

Lo configuri esattamente come in questa guida, in formato PDF:

http://www.zeusnews.it/zz_upload/PSV/Guida%20completa%20di%20%20AVIRA%20Antivir%209.pdf
Inizia pure dal punto 3.
Le voci indicate nella prima immagine a pagina 11 della Guida, spuntale tutte (nell'immagine non lo sono).
Fai una scansione completa, e posta il log.
amexis
Inviato: Wednesday, January 20, 2010 2:54:45 PM
Rank: AiutAmico

Iscritto dal : 1/20/2010
Posts: 31
d'oh! ciao ci sono cascato anche io

vorrei ringraziarvi dell'aiuto che mi darete :-D

per ora ho fatto solo il log di elibal, anche perchè non va nessun programma antivirus, non me li fa scaricare, mi blocca il link e mi chiude il browser

(20-1-2010 0:19:47)
EliBagle v13.44 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 19 de Enero del 2010)

Lista de Acciones (por Acción Directa):
Por favor, envienos una muestra del fichero
C:\Muestras\WINUPGRO.EXE.Muestra EliBagle v13.44
a "virus@satinfo.es". Gracias.
C:\DOCUMENTS AND SETTINGS\AMEXIS\DATI APPLICAZIONI\DRIVERS\WINUPGRO.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\SROSA2.SYS --> Eliminado Bagle(rootkit)
C:\WINDOWS\SYSTEM32\WFSINTWQ.SYS --> Bagle(rootkit) Acceso Denegado.

(20-1-2010 0:22:10)
EliBagle v13.44 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 19 de Enero del 2010)

Lista de Acciones (por Acción Directa):
Por favor, envienos una muestra del fichero
C:\Muestras\WINUPGRO.EXE.Muestra EliBagle v13.44
a "virus@satinfo.es". Gracias.
C:\DOCUMENTS AND SETTINGS\AMEXIS\DATI APPLICAZIONI\DRIVERS\WINUPGRO.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\WFSINTWQ.SYS --> Bagle(rootkit) Acceso Denegado.
Restaurada Clave: "SafeBoot\Minimal y Network"
Reinicie para Completar la Limpieza.
Restaurada Clave: "SafeBoot\Minimal y Network"
Reinicie para Completar la Limpieza.

(20-1-2010 0:32:45)
EliBagle v13.44 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 19 de Enero del 2010)

Lista de Acciones (por Exploración):
Explorando "C:\"

Nº Total de Directorios: 15941
Nº Total de Ficheros: 179189
Nº de Ficheros Analizados: 15762
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

(20-1-2010 0:47:47)
EliBagle v13.44 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 19 de Enero del 2010)

Lista de Acciones (por Exploración):
Explorando "D:\"

Nº Total de Directorios: 13054
Nº Total de Ficheros: 184046
Nº de Ficheros Analizados: 6981
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

(20-1-2010 13:8:51)
EliBagle v13.44 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 19 de Enero del 2010)

Lista de Acciones (por Acción Directa):
Por favor, envienos una muestra del fichero
C:\Muestras\WINUPGRO.EXE.Muestra EliBagle v13.44
a "virus@satinfo.es". Gracias.
C:\DOCUMENTS AND SETTINGS\AMEXIS\DATI APPLICAZIONI\DRIVERS\WINUPGRO.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\WFSINTWQ.SYS --> Bagle(rootkit) Acceso Denegado.
Restaurada Clave: "SafeBoot\Minimal y Network"
Reinicie para Completar la Limpieza.

(20-1-2010 13:8:57)
EliBagle v13.44 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 19 de Enero del 2010)

Lista de Acciones (por Exploración):
Explorando "C:\"

Nº Total de Directorios: 15945
Nº Total de Ficheros: 179189
Nº de Ficheros Analizados: 15762
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0

(20-1-2010 13:25:28)
EliBagle v13.44 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 19 de Enero del 2010)

Lista de Acciones (por Exploración):
Explorando "D:\"

Nº Total de Directorios: 13054
Nº Total de Ficheros: 184016
Nº de Ficheros Analizados: 6954
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
paolopa
Inviato: Wednesday, January 20, 2010 3:06:19 PM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
@amexis sarebbe meglio se aprissi un topic tutto tuo,altrimenti credo che si generera' confusione.
entri nella sezione e clicchi newtopic,dai un titolo possibilmente esplicativo,spieghi il problema e vedrai che qualcunoti aiutera'.e in bocca al lupo!
amexis
Inviato: Wednesday, January 20, 2010 3:09:56 PM
Rank: AiutAmico

Iscritto dal : 1/20/2010
Posts: 31
Think pensavo che mettendo questo messaggio qui non avrei creato due discussioni identiche...

ok se devo sposto Angel
r16
Inviato: Wednesday, January 20, 2010 3:11:04 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
@amexis .
Segui il consiglio di Paolopa, fai una scansione con FindKill e posta il log.
giovanni6161
Inviato: Wednesday, January 20, 2010 3:12:39 PM
Rank: AiutAmico

Iscritto dal : 4/1/2008
Posts: 187
ecco il log di combofix ho dovuto farlo due volte perchè la prima volta mi è apparsa una schermata blu di errore,per l'antivirus invece di avira posso reinstallare nod32?

ComboFix 10-01-19.08 - Stefano 20/01/2010 15.01.47.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.958.573 [GMT 1:00]
Eseguito da: c:\documents and settings\Stefano\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Stefano\Desktop\CFScript.txt

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\programmi\Unlocker
c:\programmi\Unlocker\README.TXT
c:\programmi\Unlocker\uninst.exe
c:\programmi\Unlocker\Unlocker-List.txt
c:\programmi\Unlocker\Unlocker.exe
c:\programmi\Unlocker\Unlocker.url
c:\programmi\Unlocker\UnlockerAssistant.exe
c:\programmi\Unlocker\UnlockerDriver5.sys
c:\programmi\Unlocker\UnlockerHook.dll

.
((((((((((((((((((((((((( Files Creati Da 2009-12-20 al 2010-01-20 )))))))))))))))))))))))))))))))))))
.

2010-01-19 22:21 . 2010-01-19 22:21 0 ----a-w- c:\windows\system32\cd.dat
2010-01-19 19:58 . 2010-01-19 19:58 5115823 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-19 17:39 . 2010-01-19 17:39 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Windows Search
2010-01-19 15:04 . 2010-01-19 15:58 -------- d-----w- C:\FindyKill
2010-01-19 14:39 . 2006-01-19 12:15 92672 ----a-r- c:\windows\system32\drivers\viamraid.sys
2010-01-19 14:19 . 2006-02-23 03:39 11264 ----a-r- c:\windows\system32\drivers\xfilt.sys
2010-01-19 14:19 . 2006-02-23 03:38 9728 ----a-r- c:\windows\system32\drivers\videX32.sys
2010-01-19 14:16 . 2010-01-19 14:16 -------- d-----w- c:\programmi\Realtek AC97
2010-01-19 14:06 . 2001-08-30 20:54 3328 -c--a-w- c:\windows\system32\dllcache\pciide.sys
2010-01-19 14:06 . 2001-08-30 20:54 3328 ----a-w- c:\windows\system32\drivers\pciide.sys
2010-01-19 13:43 . 1997-11-19 14:49 303616 ----a-w- c:\windows\IsUninst.exe
2010-01-19 13:43 . 2010-01-19 13:43 -------- d-----w- c:\documents and settings\Stefano\WINDOWS
2010-01-16 20:01 . 2010-01-16 20:28 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Adobe
2010-01-16 20:01 . 2010-01-16 20:01 -------- d-----w- c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\Identities
2010-01-16 20:01 . 2010-01-16 20:01 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Windows Desktop Search
2010-01-16 19:59 . 2010-01-17 07:49 -------- d-----w- c:\programmi\Windows Desktop Search
2010-01-16 19:59 . 2010-01-16 19:59 -------- d-----w- c:\windows\system32\GroupPolicy
2010-01-16 19:57 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-01-16 19:57 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-01-16 19:57 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-01-15 14:05 . 2010-01-15 14:05 -------- d-----w- c:\programmi\File comuni\eSellerate
2010-01-15 14:04 . 2010-01-16 12:45 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\vlc
2010-01-13 09:49 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-13 09:49 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-13 09:49 . 2009-07-14 00:15 90112 ----a-w- c:\windows\system32\dpl100.dll
2010-01-13 09:49 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2010-01-13 09:49 . 2009-07-14 00:15 685056 ----a-w- c:\windows\system32\divx.dll
2010-01-13 09:49 . 2010-01-05 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-13 09:49 . 2010-01-13 09:52 -------- d-----w- c:\programmi\K-Lite Codec Pack
2010-01-12 21:19 . 2009-11-21 15:54 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 18:26 . 2010-01-11 18:26 -------- d-----w- c:\programmi\FreeTime
2010-01-11 18:02 . 2010-01-11 18:02 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NCH Software
2010-01-11 18:02 . 2010-01-11 18:10 -------- d-----w- c:\programmi\NCH Software
2010-01-07 17:25 . 2010-01-07 17:25 -------- d-----w- C:\Hotspot Shield
2010-01-07 17:24 . 2010-01-07 17:25 -------- d-----w- c:\programmi\Hotspot Shield
2010-01-05 20:19 . 2010-01-05 20:19 -------- d-----w- c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\TVLC
2010-01-04 20:24 . 2010-01-04 20:24 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\OpenDNS Updater
2010-01-01 11:45 . 2010-01-01 11:45 -------- d-----w- c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\MetaGeek,_LLC
2010-01-01 11:37 . 2010-01-01 11:37 -------- d-----w- c:\programmi\MetaGeek
2009-12-27 17:02 . 2007-08-22 18:53 -------- d-----w- C:\msinst
2009-12-27 17:02 . 2007-08-22 18:53 -------- d-----w- C:\installer
2009-12-27 17:02 . 2007-08-22 18:53 -------- d-----w- C:\battery
2009-12-21 18:16 . 2009-12-21 18:16 152576 ----a-w- c:\documents and settings\Stefano\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-21 18:15 . 2009-12-21 18:15 79488 ----a-w- c:\documents and settings\Stefano\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-19 19:58 . 2009-01-07 22:11 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-19 19:46 . 2008-04-16 17:50 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\uTorrent
2010-01-19 16:43 . 2004-08-30 20:00 88772 ----a-w- c:\windows\system32\perfc010.dat
2010-01-19 16:43 . 2004-08-30 20:00 504918 ----a-w- c:\windows\system32\perfh010.dat
2010-01-19 14:20 . 2009-12-08 20:26 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-19 13:50 . 2008-09-09 20:49 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\MegauploadToolbar
2010-01-16 21:35 . 2008-04-16 15:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-01-16 18:01 . 2008-04-16 17:58 -------- d-----w- c:\programmi\File comuni\Adobe
2010-01-16 17:44 . 2008-06-22 16:57 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Canon
2010-01-13 10:42 . 2008-04-16 15:06 70992 ----a-w- c:\documents and settings\Stefano\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-01-13 09:45 . 2008-04-16 15:38 -------- d-----w- c:\programmi\DivX
2010-01-12 16:51 . 2009-12-12 13:20 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\LimeWire
2010-01-07 15:07 . 2009-01-07 22:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-01-07 22:27 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-28 10:52 . 2008-04-16 17:39 -------- d-----w- c:\programmi\Messenger Plus! Live
2009-12-26 11:38 . 2008-04-18 12:33 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Skype
2009-12-26 11:24 . 2008-04-18 12:34 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\skypePM
2009-12-21 20:32 . 2008-04-16 14:15 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-12-21 18:18 . 2008-04-16 17:38 -------- d-----w- c:\programmi\Java
2009-12-21 11:38 . 2009-12-21 11:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2009-12-19 17:48 . 2009-12-19 17:48 -------- d-----w- c:\programmi\Sagasoft
2009-12-18 19:01 . 2009-12-18 18:59 -------- d-----w- c:\programmi\UltraMixer
2009-12-15 19:24 . 2009-12-15 19:24 -------- d-----w- c:\programmi\ConvertHelper
2009-12-12 14:15 . 2002-10-15 22:54 178176 ----a-w- c:\windows\system32\unrar.dll
2009-12-12 13:08 . 2009-12-12 13:08 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-12-10 15:27 . 2009-12-10 15:27 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\VoipCheapCom
2009-12-09 20:59 . 2009-02-16 13:13 -------- d-----w- c:\programmi\Samsung
2009-12-09 17:31 . 2009-12-09 17:31 -------- d-----w- c:\documents and settings\Stefano\Dati applicazioni\Thunderbird
2009-12-08 18:31 . 2009-12-08 18:04 -------- d--h--w- c:\programmi\FX Uninstall Information
2009-12-08 17:39 . 2009-12-08 17:39 -------- d-----w- c:\programmi\Megaupload
2009-12-08 16:46 . 2008-04-16 16:01 -------- d-----w- c:\programmi\Microsoft Works
2009-12-08 15:26 . 2009-12-08 15:25 -------- d-----w- c:\programmi\LimeWire
2009-12-08 15:19 . 2008-07-19 20:57 -------- d-----w- c:\programmi\ZAR
2009-12-08 15:11 . 2008-06-02 18:36 -------- d-----w- c:\programmi\Google
2009-12-08 15:07 . 2008-04-23 18:31 -------- d-----w- c:\programmi\BearShare Test
2009-12-08 14:42 . 2009-12-08 14:42 159168 ----a-w- c:\windows\system32\drivers\afcdp.sys
2009-12-08 14:42 . 2009-01-27 17:42 -------- d-----w- c:\programmi\File comuni\Acronis
2009-12-08 14:42 . 2009-12-08 14:42 911552 ----a-w- c:\windows\system32\drivers\tdrpm255.sys
2009-12-08 14:42 . 2008-07-24 12:29 570016 ----a-w- c:\windows\system32\drivers\timntr.sys
2009-12-08 14:42 . 2008-07-24 12:29 157248 ----a-w- c:\windows\system32\drivers\snapman.sys
2009-12-08 14:35 . 2009-01-27 17:42 -------- d-----w- c:\programmi\Acronis
2009-12-08 14:14 . 2008-04-16 15:22 75776 ----a-w- c:\windows\system32\storprop.dll
2009-12-08 14:14 . 2004-08-30 20:00 40448 ----a-w- c:\windows\system32\drivers\intelppm.sys
2009-12-08 14:14 . 2004-08-30 20:00 188416 ----a-w- c:\windows\system32\drivers\acpi.sys
2009-12-08 14:14 . 2004-08-30 20:00 68736 ----a-w- c:\windows\system32\drivers\pci.sys
2009-11-21 15:54 . 2004-08-30 20:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-12 21:42 . 2009-11-12 21:42 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2009-11-12 21:42 . 2009-11-12 21:42 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2009-10-29 07:40 . 2004-08-30 20:00 916480 ------w- c:\windows\system32\wininet.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
2008-11-24 19:48 . 2008-11-24 19:38 24 --sh--w- c:\windows\SF2224595.tmp
.

((((((((((((((((((((((((((((( SnapShot@2010-01-19_22.49.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-20 13:58 . 2010-01-20 13:58 16384 c:\windows\Temp\Perflib_Perfdata_5e0.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2010-01-07 17:24 218160 ----a-w- c:\programmi\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-29 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-09-21 53248]
"VTTrayp"="VTtrayp.exe" [2007-08-27 200704]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-05-26 413696]
"AppleSyncNotifier"="c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-20 177472]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"TrueImageMonitor.exe"="c:\programmi\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-10-06 5076088]
"Servizio Acronis Scheduler2"="c:\programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2009-10-06 357688]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\Orbitdownloader\\orbitdm.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitnet.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Motorola\\Software Update\\msu.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\WCESMgr.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Stefano\\Desktop\\Programmi vari\\My Mobile\\MyMobiler\\MyMobiler.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [23/06/2008 18.44.20 5248]
R0 tdrpman255;Acronis Try&Decide and Restore Points filter (build 255);c:\windows\system32\drivers\tdrpm255.sys [08/12/2009 15.42.47 911552]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [19/01/2010 15.19.41 11264]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [16/04/2008 15.07.47 13696]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\programmi\File comuni\Acronis\CDP\afcdpsrv.exe [08/12/2009 15.42.54 2326920]
R2 LF30FS;LF30FS;c:\programmi\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [19/11/2004 17.07.00 101488]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [08/12/2009 15.42.59 159168]
R3 portio32;portio32;c:\windows\system32\drivers\portio32.sys [29/05/2009 17.22.58 2048]
S0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [23/06/2008 18.44.20 160640]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys --> c:\windows\system32\DRIVERS\ehdrv.sys [?]
S2 ekrn;ESET Service;"c:\programmi\ESET\ESET NOD32 Antivirus\ekrn.exe" --> c:\programmi\ESET\ESET NOD32 Antivirus\ekrn.exe [?]
S2 gupdate1c9f8bbd63beb96;Servizio di Google Update (gupdate1c9f8bbd63beb96);c:\programmi\Google\Update\GoogleUpdate.exe [29/06/2009 14.16.37 133104]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [30/08/2004 21.00.00 3584]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [30/04/2009 14.24.54 12672]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [06/09/2009 17.21.33 17149]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [02/02/2009 11.44.26 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [02/02/2009 11.44.27 7680]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [07/11/2008 20.13.02 42112]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [06/09/2009 17.21.28 362944]
.
Contenuto della cartella 'Scheduled Tasks'

2010-01-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34]

2010-01-20 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-02 13:13]

2010-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-29 13:16]

2010-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-29 13:16]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://google.it/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Do&wnload selected by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/202
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {17FF1734-F917-4576-A0D5-7D3AE7A389A0} = 212.216.172.62,194.243.154.62
FF - ProfilePath - c:\documents and settings\Stefano\Dati applicazioni\Mozilla\Firefox\Profiles\fakteoqj.default\
FF - prefs.js: browser.startup.homepage - hxxp://it.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:it:official
FF - plugin: c:\programmi\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\programmi\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

AddRemove-Unlocker - c:\programmi\Unlocker\uninst.exe



**************************************************************************
scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti:

**************************************************************************
.
Ora fine scansione: 2010-01-20 15:09:46
ComboFix-quarantined-files.txt 2010-01-20 14:09

Pre-Run: 80.292.331.520 byte disponibili
Post-Run: 80.242.987.008 byte disponibili

- - End Of File - - 6A0884049616A87D7C27656DEE4FB626
r16
Inviato: Wednesday, January 20, 2010 3:14:04 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ok.
Dimmi i problemi che riscontri.
giovanni6161
Inviato: Wednesday, January 20, 2010 8:16:38 PM
Rank: AiutAmico

Iscritto dal : 4/1/2008
Posts: 187
adesso non ho problemi installo avira e faccio uno scan (con nod32 ho dei problemi)
r16
Inviato: Wednesday, January 20, 2010 8:20:52 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Commenta:
adesso non ho problemi installo avira e faccio uno scan (con nod32 ho dei problemi)

Perchè lo hai disistallato male. (infatti, ci sono ancora delle chiavi di registro sul log di Combofix.
Comunque, Avira è migliore del Nod.
Fai una scansione completa, e posta il log.
Scarica Avira:
http://www.aiutamici.com/software?ID=10908

Lo configuri esattamente come in questa guida, in formato PDF:

http://www.zeusnews.it/zz_upload/PSV/Guida%20completa%20di%20%20AVIRA%20Antivir%209.pdf

Le voci indicate nella prima immagine a pagina 11 della Guida, spuntale tutte (nell'immagine non lo sono).
giovanni6161
Inviato: Wednesday, January 20, 2010 10:12:14 PM
Rank: AiutAmico

Iscritto dal : 4/1/2008
Posts: 187
i programmi keyfinder e unlocker sono sicuro che non sono dannosi per il pc cmq ecco il log di avira:

Avira AntiVir Personal
Data del file di report: mercoledì 20 gennaio 2010 21:21

Ricerca di 1572646 virus e programmi indesiderati.

Concesso in licenza a : Avira AntiVir Personal - FREE Antivirus
Numero di serie : 0000149996-ADJIE-0000001
Piattaforma : Windows XP
Versione di Windows : (Service Pack 3) [5.1.2600]
Modalità di avvio : Booting eseguito regolarmente
Nome utente : SYSTEM
Nome computer : ADMIN

Informazioni sulla versione:
BUILD.DAT : 9.0.0.21 21699 Bytes 04/12/2009 14:20:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 13/10/2009 10:26:40
AVSCAN.DLL : 9.0.3.0 47873 Bytes 03/03/2009 10:14:29
LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:56
LUKERES.DLL : 9.0.2.0 12545 Bytes 03/03/2009 10:15:14
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 06:35:52
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 14:52:15
VBASE002.VDF : 7.10.1.1 2048 Bytes 19/11/2009 14:52:15
VBASE003.VDF : 7.10.1.2 2048 Bytes 19/11/2009 14:52:16
VBASE004.VDF : 7.10.1.3 2048 Bytes 19/11/2009 14:52:16
VBASE005.VDF : 7.10.1.4 2048 Bytes 19/11/2009 14:52:16
VBASE006.VDF : 7.10.1.5 2048 Bytes 19/11/2009 14:52:16
VBASE007.VDF : 7.10.1.6 2048 Bytes 19/11/2009 14:52:16
VBASE008.VDF : 7.10.1.7 2048 Bytes 19/11/2009 14:52:16
VBASE009.VDF : 7.10.1.8 2048 Bytes 19/11/2009 14:52:16
VBASE010.VDF : 7.10.1.9 2048 Bytes 19/11/2009 14:52:16
VBASE011.VDF : 7.10.1.10 2048 Bytes 19/11/2009 14:52:16
VBASE012.VDF : 7.10.1.11 2048 Bytes 19/11/2009 14:52:16
VBASE013.VDF : 7.10.1.79 209920 Bytes 25/11/2009 14:52:17
VBASE014.VDF : 7.10.1.128 197632 Bytes 30/11/2009 14:52:18
VBASE015.VDF : 7.10.1.178 195584 Bytes 07/12/2009 14:52:18
VBASE016.VDF : 7.10.1.224 183296 Bytes 14/12/2009 14:52:19
VBASE017.VDF : 7.10.1.247 182272 Bytes 15/12/2009 14:52:19
VBASE018.VDF : 7.10.2.30 198144 Bytes 21/12/2009 14:52:20
VBASE019.VDF : 7.10.2.63 187392 Bytes 24/12/2009 14:52:20
VBASE020.VDF : 7.10.2.93 195072 Bytes 29/12/2009 14:52:21
VBASE021.VDF : 7.10.2.131 201216 Bytes 07/01/2010 14:52:21
VBASE022.VDF : 7.10.2.158 192000 Bytes 11/01/2010 14:52:22
VBASE023.VDF : 7.10.2.186 200704 Bytes 14/01/2010 14:52:22
VBASE024.VDF : 7.10.2.205 201728 Bytes 15/01/2010 14:52:23
VBASE025.VDF : 7.10.2.219 158720 Bytes 18/01/2010 14:52:23
VBASE026.VDF : 7.10.2.230 173056 Bytes 19/01/2010 14:52:24
VBASE027.VDF : 7.10.2.231 2048 Bytes 19/01/2010 14:52:24
VBASE028.VDF : 7.10.2.232 2048 Bytes 19/01/2010 14:52:24
VBASE029.VDF : 7.10.2.233 2048 Bytes 19/01/2010 14:52:24
VBASE030.VDF : 7.10.2.234 2048 Bytes 19/01/2010 14:52:24
VBASE031.VDF : 7.10.2.242 102400 Bytes 20/01/2010 14:52:25
Motore : 8.2.1.142
AEVDF.DLL : 8.1.1.2 106867 Bytes 08/11/2009 06:38:52
AESCRIPT.DLL : 8.1.3.7 594296 Bytes 20/01/2010 14:52:44
AESCN.DLL : 8.1.3.1 127348 Bytes 20/01/2010 14:52:44
AESBX.DLL : 8.1.1.1 246132 Bytes 08/11/2009 06:38:44
AERDL.DLL : 8.1.3.4 479605 Bytes 20/01/2010 14:52:43
AEPACK.DLL : 8.2.0.5 422262 Bytes 20/01/2010 14:52:43
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 08/11/2009 06:38:38
AEHEUR.DLL : 8.1.0.195 2232695 Bytes 20/01/2010 14:52:42
AEHELP.DLL : 8.1.10.0 237942 Bytes 20/01/2010 14:52:39
AEGEN.DLL : 8.1.1.83 369014 Bytes 20/01/2010 14:52:38
AEEMU.DLL : 8.1.1.0 393587 Bytes 08/11/2009 06:38:26
AECORE.DLL : 8.1.9.5 184693 Bytes 20/01/2010 14:52:25
AEBB.DLL : 8.1.0.3 53618 Bytes 08/11/2009 06:38:20
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:48:02
AVPREF.DLL : 9.0.3.0 44289 Bytes 26/08/2009 14:14:06
AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:25:10
AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:45
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:12
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:38
NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:41:28
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 17/06/2009 13:11:50
RCTEXT.DLL : 9.0.73.0 87809 Bytes 03/11/2009 07:16:42

Impostazioni di configurazione per la scansione attuale:
Nome del job................................: Scansione completa del sistema
File di configurazione......................: c:\programmi\avira\antivir desktop\sysscan.avp
Report......................................: basso
Azione primaria.............................: interattivo
Azione secondaria...........................: ignora
Scansione dei record master di avvio........: Attivo
Scansiona record di avvio...................: Attivo
Record di avvio.............................: C:, F:,
Scansione dei programmi attivi..............: Attivo
Scansiona la registrazione..................: Attivo
Cerca Rootkits..............................: Attivo
Controllo di integrità dei file di sistema..: Non attivo
Modalità di scansione file..................: Tutti i file
Scansione degli archivi.....................: Attivo
Limita la profondità di ricorsione..........: 20
Archivio estensioni Smart...................: Attivo
Macro euristico.............................: Attivo
File euristico..............................: medio
Categorie irregolari delle minacce..........: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR,

Avvio della scansione: mercoledì 20 gennaio 2010 21:21

È stata avviata la scansione per accertare la presenza di oggetti nascosti.
Sono stati esaminati '59249' oggetti, sono stati rilevati '0' oggetti nascosti.

La scansione dei processi in esecuzione verrà avviata:
Scansione processo 'avscan.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'avcenter.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'UnlockerAssistant.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'firefox.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'alg.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'iPodService.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'CALMAIN.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'searchindexer.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'PnkBstrA.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'NBService.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'jqs.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'hsssrv.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'openvpnas.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'rapimgr.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'ctfmon.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'wcescomm.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'Crypserv.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'mDNSResponder.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'AppleMobileDeviceService.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'avgnt.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'avguard.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'soundman.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'jusched.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'TrueImageMonitor.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'iTunesHelper.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'GrooveMonitor.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'VTTrayp.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'VTTimer.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'afcdpsrv.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'schedhlp.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'schedul2.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'explorer.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'sched.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'spoolsv.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'svchost.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'lsass.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'services.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'winlogon.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'csrss.exe' - '1' modulo(i) scansionato(i)
Scansione processo 'smss.exe' - '1' modulo(i) scansionato(i)
48 processi scansionati con '48' Moduli

Avvio della scansione dei record master di avvio:
Record master di avvio dell'Hard Disk 0
[INFO] Nessun virus è stato trovato!
Record master di avvio dell'Hard Disk 1
[INFO] Nessun virus è stato trovato!

Avvio della scansione dei record di avvio:
Record di avvio 'C:\'
[INFO] Nessun virus è stato trovato!
Record di avvio 'F:\'
[INFO] Nessun virus è stato trovato!

Avvio della scansione dei file eseguibili (registro):
Il registro è stato scansionato ( 60 file ).


Avvio della scansione del file selezionati:

Inizia con la scansione di 'C:\'
C:\pagefile.sys
[AVVISO] Impossibile aprire il file!
[NOTA] Questo è un file di sistema di Windows.
[NOTA] Impossibile aprire questo file per la scansione.
C:\Documents and Settings\Stefano\Desktop\Cose varie\rendere windows autentico\wp\keyfinder.exe
[0] Tipo di archivio: RAR SFX (self extracting)
[RILEVAMENTO] Contiene il modello di rilevamento del programma SPR/Tool.Agent
--> findkey.exe
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Agent.542720.C
--> xpkey.exe
[RILEVAMENTO] Contiene il modello di rilevamento del programma SPR/Tool.XPKey
--> officekey.exe
[RILEVAMENTO] Contiene il modello di rilevamento del programma SPR/PSW.RAS.A.3
C:\System Volume Information\_restore{F772933C-6EBA-4645-97E6-9C1374DBB3E1}\RP3\A0006633.exe
[0] Tipo di archivio: RAR SFX (self extracting)
[RILEVAMENTO] Contiene il modello di rilevamento del programma SPR/Tool.Agent
--> findkey.exe
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Agent.542720.C
--> xpkey.exe
[RILEVAMENTO] Contiene il modello di rilevamento del programma SPR/Tool.XPKey
--> officekey.exe
[RILEVAMENTO] Contiene il modello di rilevamento del programma SPR/PSW.RAS.A.3
C:\System Volume Information\_restore{F772933C-6EBA-4645-97E6-9C1374DBB3E1}\RP3\A0006634.exe
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Patched.Gen2
C:\System Volume Information\_restore{F772933C-6EBA-4645-97E6-9C1374DBB3E1}\RP3\A0006635.exe
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Patched.Gen2
C:\System Volume Information\_restore{F772933C-6EBA-4645-97E6-9C1374DBB3E1}\RP3\A0006636.EXE
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Crypt.XPACK.Gen
Inizia con la scansione di 'F:\' <Volume>

Avvio della disinfezione:
C:\Documents and Settings\Stefano\Desktop\Cose varie\rendere windows autentico\wp\keyfinder.exe
[RILEVAMENTO] Contiene il modello di rilevamento del programma SPR/Tool.Agent
[NOTA] Il file è stato spostato in quarantena con il nome '4bd071e6.qua'!
C:\System Volume Information\_restore{F772933C-6EBA-4645-97E6-9C1374DBB3E1}\RP3\A0006633.exe
[RILEVAMENTO] Contiene il modello di rilevamento del programma SPR/Tool.Agent
[NOTA] Il file è stato spostato in quarantena con il nome '4b8771b2.qua'!
C:\System Volume Information\_restore{F772933C-6EBA-4645-97E6-9C1374DBB3E1}\RP3\A0006634.exe
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Patched.Gen2
[NOTA] Il file è stato spostato in quarantena con il nome '4af2a74b.qua'!
C:\System Volume Information\_restore{F772933C-6EBA-4645-97E6-9C1374DBB3E1}\RP3\A0006635.exe
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Patched.Gen2
[NOTA] Il file è stato spostato in quarantena con il nome '484c275b.qua'!
C:\System Volume Information\_restore{F772933C-6EBA-4645-97E6-9C1374DBB3E1}\RP3\A0006636.EXE
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Crypt.XPACK.Gen
[NOTA] Il file è stato spostato in quarantena con il nome '4eeb8393.qua'!


Fine della scansione: mercoledì 20 gennaio 2010 22:11
Tempo impiegato: 45:39 Minuto(i)

La scansione è stata completamente eseguita.

9105 Directory scansionate
309893 I file sono stati scansionati
11 Rilevati virus e/o programmi indesiderati
0 I file sono stati classificati come sospetti
0 I file sono stati eliminati
0 I virus o i programmi indesiderati sono stati riparati
5 File spostati in quarantena
0 File rinominati
1 Impossibile scansionare i file
309881 File non infetti
2626 Archivi scansionati
1 Avvisi
6 Note
59249 Oggetti scansionati durante la scansione dei rootkit
0 Sono stati rilevati oggetti nascosti

r16
Inviato: Wednesday, January 20, 2010 10:29:19 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Commenta:
programmi keyfinder e unlocker sono sicuro che non sono dannosi per il pc

Avira ha eliminato quello che contevano i file infetti nella loro "quarantina". (e altro)
Siamo al finale:
Posta un log di HJT .
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.