Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

VIRUS E QUANT'ALTRO Opzioni
renzozilio
Inviato: Thursday, January 21, 2010 5:17:09 PM
Rank: Member

Iscritto dal : 1/21/2010
Posts: 12
Buongiorno a voi, sono un nuovo amico che cerca aiuto.
Il computer è diventato lento e mi introduce schermate di disturbo.
Ho attivato i programmi CCleaner, ClamWin e Spybot; un pò di "porcheria" è stata debellata ma mi resta sempre una bella lista fornita da Hijack che allego.
Come dite voi, per i non esperti è pericoloso cancellare i files descritti in tale lista ed è per questo che chiedo il vostro aiuto. Cordiali saluti Renzo Zilio

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.17.49, on 21/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\RegCure\RegCure.exe
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Programmi\ClamWin\bin\ClamTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
C:\Programmi\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Programmi\AVG\AVG8\avgcsrvx.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\Skype\Plugin Manager\skypePM.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://italian.ircfast.com/it/index.php?rvs=hompag
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {b5146c40-189a-4311-bda9-fbae3e023187} - (no file)
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,,,,"c:\windows\canontool.exe","c:\windows\nortonpad.exe",
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Virgilio Toolbar - {D3403F28-7D39-435F-A8CB-45016C29E48E} - C:\Programmi\Virgilio Toolbar\VirgilioBand.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Programmi\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programmi\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmi\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programmi\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Programmi\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PSDrvCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Programmi\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Programmi\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\RunOnce: [SpybotDeletingA3009] command.com /c del "C:\Programmi\RegistrySmart\Errors.stg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8246] cmd.exe /c del "C:\Programmi\RegistrySmart\Errors.stg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA396] command.com /c del "C:\Programmi\RegistrySmart\Results.stg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3299] cmd.exe /c del "C:\Programmi\RegistrySmart\Results.stg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5487] command.com /c del "C:\Programmi\RelevantKnowledge\rlls.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5067] cmd.exe /c del "C:\Programmi\RelevantKnowledge\rlls.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmi\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [NBJ] "C:\Programmi\Ahead\nero\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Programmi\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB4418] command.com /c del "C:\Programmi\RegistrySmart\Errors.stg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4868] cmd.exe /c del "C:\Programmi\RegistrySmart\Errors.stg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4507] command.com /c del "C:\Programmi\RegistrySmart\Results.stg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4842] cmd.exe /c del "C:\Programmi\RegistrySmart\Results.stg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8902] command.com /c del "C:\Programmi\RelevantKnowledge\rlls.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5721] cmd.exe /c del "C:\Programmi\RelevantKnowledge\rlls.dll"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Programmi\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Programmi\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: Crea preferiti portatile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Crea preferiti portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137779450562
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5920058-11F0-4267-A733-8F61BFC40EF5}: NameServer = 193.70.152.15 193.70.152.25
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: \\?\C:\WINDOWS\system32\lpt2.lge
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Servizio di Google Update (gupdate1c9ad7450a18406) (gupdate1c9ad7450a18406) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe

--
End of file - 11585 bytes
Sponsor
Inviato: Thursday, January 21, 2010 5:17:09 PM

 
panchoz
Inviato: Thursday, January 21, 2010 5:27:00 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Welcome.

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Questa sera riceverai una patch per la sicurezza di IE6. Tuttavia la Microsoft stessa invita gli utenti ad aggiornare a IE8..

AVG e' arrivato alla vers 9.
panchoz
Inviato: Thursday, January 21, 2010 5:31:24 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Mentri aspetti, e per accelerare i tempi, fai una scansione con Malwarebytes

scheda Aiutamici> http://software.aiutamici.com/software?ID=80346


Aggiornalo, e' importante, ed esegui una scansione COMPLETA. Poi posta il LOG.
renzozilio
Inviato: Friday, January 22, 2010 7:41:16 AM
Rank: Member

Iscritto dal : 1/21/2010
Posts: 12
alla c.a. di panchoz.
grazie per le tue immediate risposte.


Ho eseguito aggiornamento di AVG in versione 9
Ho eseguito una scansione e sono statiriscontrati 7 errori, 2 rimossi dal programma ma 5 no



Ho attivato MALWAREBYTES
Eseguita una 1° scansione con risultato di 24 errori e ti allego il LOG

Malwarebytes' Anti-Malware 1.44
Versione del database: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

21/01/2010 18.07.39
mbam-log-2010-01-21 (18-07-33).txt

Tipo di scansione: Scansione rapida
Elementi scansionati: 131152
Tempo trascorso: 8 minute(s), 45 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 9
Valori di registro infetti: 3
Elementi dato del registro infetti: 0
Cartelle infette: 5
File infetti: 13

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0140df95-9128-4053-ae72-f43f0cfca062} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Rogue.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Rogue.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Rogue.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Rogue.Ascentive) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.

Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\SysRestore.dll (Rogue.Ascentive) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\adsltaskbar (Trojan.Agent) -> No action taken.

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
C:\Programmi\RegistrySmart (Rogue.RegistrySmart) -> No action taken.
C:\Programmi\RegistrySmart\Log (Rogue.RegistrySmart) -> No action taken.
C:\Programmi\RegistrySmart\Registry Backups (Rogue.RegistrySmart) -> No action taken.
C:\Programmi\RelevantKnowledge (Spyware.MarketScore) -> No action taken.
C:\Programmi\RelevantKnowledge\components (Spyware.MarketScore) -> No action taken.

File infetti:
C:\RECYCLER\S-1-5-21-776561741-706699826-839522115-1004\Dc259.dll (Adware.MyWebSearch) -> No action taken.
C:\RECYCLER\S-1-5-21-776561741-706699826-839522115-1004\Dc277.dll (Adware.MyWebSearch) -> No action taken.
C:\WINDOWS\system32\SysRestore.dll (Rogue.Ascentive) -> No action taken.
C:\Programmi\RegistrySmart\Log\log_2006_11_03_14_56_49.eklog (Rogue.RegistrySmart) -> No action taken.
C:\Programmi\RegistrySmart\Log\log_2006_11_03_14_56_51.eklog (Rogue.RegistrySmart) -> No action taken.
C:\Programmi\RegistrySmart\Log\log_2006_11_03_14_56_53.eklog (Rogue.RegistrySmart) -> No action taken.
C:\Programmi\RegistrySmart\Registry Backups\2006-11-03_15-02-28.reg (Rogue.RegistrySmart) -> No action taken.
C:\Programmi\RelevantKnowledge\chrome.manifest (Spyware.MarketScore) -> No action taken.
C:\Programmi\RelevantKnowledge\install.rdf (Spyware.MarketScore) -> No action taken.
C:\Programmi\RelevantKnowledge\rloci.bin (Spyware.MarketScore) -> No action taken.
C:\Programmi\RelevantKnowledge\rlph.dll (Spyware.MarketScore) -> No action taken.
C:\Programmi\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) -> No action taken.
C:\Programmi\RelevantKnowledge\rlxf.dll (Spyware.MarketScore) -> No action taken.


Eliminati gli errori, eseguita 2° scansione con risultato 0 errori

Ho attivato Hijack this
Eseguita una 1° scansione con HIJACK THIS il cui log ti ho inviato a metà pomeriggio.
Eseguita una 2° scansione con il nuovo risultato che puoi vedere nel log allegato.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23.04.11, on 21/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Ahead\InCD\InCDsrv.exe
C:\Programmi\AVG\AVG9\avgchsvx.exe
C:\Programmi\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
C:\Programmi\RegCure\RegCure.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\AVG\AVG9\avgwdsvc.exe
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Programmi\ClamWin\bin\ClamTray.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Programmi\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
C:\Programmi\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Programmi\AVG\AVG9\avgemc.exe
C:\Programmi\AVG\AVG9\avgam.exe
C:\Programmi\AVG\AVG9\avgnsx.exe
C:\Programmi\AVG\AVG9\avgcsrvx.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\AVG\AVG9\avgcsrvx.exe
C:\Programmi\Skype\Plugin Manager\skypePM.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\AVG\AVG9\avgui.exe
C:\Programmi\AVG\AVG9\avgscanx.exe
C:\Programmi\AVG\AVG9\avgcsrvx.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://italian.ircfast.com/it/index.php?rvs=hompag
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {b5146c40-189a-4311-bda9-fbae3e023187} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programmi\AVG\AVG9\Toolbar\IEToolbar.dll
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,"c:\windows\canontool.exe","c:\windows\nortonpad.exe",
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Virgilio Toolbar - {D3403F28-7D39-435F-A8CB-45016C29E48E} - C:\Programmi\Virgilio Toolbar\VirgilioBand.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Programmi\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programmi\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmi\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programmi\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Programmi\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PSDrvCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Programmi\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Programmi\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmi\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [NBJ] "C:\Programmi\Ahead\nero\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Programmi\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Programmi\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Programmi\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: Crea preferiti portatile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Crea preferiti portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137779450562
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264108325250
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5920058-11F0-4267-A733-8F61BFC40EF5}: NameServer = 193.70.152.15 193.70.152.25
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: \\?\C:\WINDOWS\system32\lpt2.lge
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG9\avgwdsvc.exe
O23 - Service: Servizio di Google Update (gupdate1c9ad7450a18406) (gupdate1c9ad7450a18406) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe

--
End of file - 10859 bytes

Ho attivato Spybot, ho fatto una 1° scansione senza riscontare errori




Ti informo che per l'accesso a Internet non sto utilizzando Explorer, bensì Mozilla, perchè, mi hanno a suo tempo detto che è più affidabile.

Grazie della tua cortese disponibilità e competenza.
Un saluto da Renzo
panchoz
Inviato: Friday, January 22, 2010 9:37:29 AM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Renzo, per il Log aspetta il parere di Rosselli, Pidue o R16.



O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe

r16
Inviato: Friday, January 22, 2010 2:40:44 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Scarica Avenger, e scompattalo in una sua cartella non temporanea e non sul desktop:
http://swandog46.geekstogo.com/avenger.zip

Avvia AVENGER
Clicca Ok
Inserisci queste righe (fai copia-incolla) nel riquadro bianco:

Code:
Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs


Togli la spunta da Scan for Rootkit
Clicca su Execute e aspetta...
Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
Al termine dell'operazione, posta qui il risultato di Avenger .

*********************************************************************************
Scarica Combofix

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


Salvalo sul desktop.

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.
renzozilio
Inviato: Friday, January 22, 2010 7:13:25 PM
Rank: Member

Iscritto dal : 1/21/2010
Posts: 12

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Registry value "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs" replaced with dummy successfully.

Completed script processing.

*******************

Finished! Terminate.






























Purtroppo non sono riuscito a bloccare AVG e nemmeno a sconfigurarlo.
Grazie dell'aiuto. Un saluto . Renzo


LOGFILE COMBOFIX

ComboFix 10-01-21.08 - admin 22/01/2010 18.50.02.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1535.1044 [GMT 1:00]
Eseguito da: c:\documents and settings\admin\Documenti\Download\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
I seguenti file sono stati disabilitati durante la scansione:
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll


((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\admin\Dati applicazioni\inst.exe
c:\documents and settings\admin\Preferiti\Download programs.url
c:\documents and settings\admin\Preferiti\Games.url
c:\documents and settings\admin\Preferiti\Translator.url
c:\documents and settings\admin\Preferiti\Videos.url
C:\LOG.TXT
c:\programmi\AskSearch\bin\DefaultSearch.dll
c:\windows\A.tmp
c:\windows\AUTOLNCH.REG
c:\windows\B.tmp
c:\windows\C.tmp
c:\windows\E.tmp
c:\windows\system32\regsvr32.dll

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_OREANS32
-------\Service_oreans32


((((((((((((((((((((((((( Files Creati Da 2009-12-22 al 2010-01-22 )))))))))))))))))))))))))))))))))))
.

2010-01-22 02:09 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-01-21 21:27 . 2010-01-21 21:27 -------- d-----w- c:\programmi\Microsoft CAPICOM 2.1.0.2
2010-01-21 18:52 . 2010-01-21 19:23 -------- dc----w- C:\$AVG
2010-01-21 18:51 . 2010-01-21 18:51 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-01-21 18:50 . 2010-01-22 17:46 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-01-21 16:52 . 2010-01-21 16:52 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\Malwarebytes
2010-01-21 16:52 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-21 16:52 . 2010-01-21 16:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-01-21 16:52 . 2010-01-21 17:07 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-21 16:52 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-21 12:46 . 2010-01-22 06:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-01-21 12:46 . 2010-01-21 12:48 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-01-20 21:47 . 2010-01-20 21:47 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-20 17:23 . 2010-01-20 17:23 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\.clamwin
2010-01-20 17:23 . 2010-01-20 17:23 -------- d-----w- c:\programmi\ClamWin
2010-01-20 17:23 . 2010-01-20 17:23 -------- d-----w- c:\documents and settings\All Users\.clamwin
2010-01-20 15:38 . 2010-01-20 15:38 -------- d-----w- c:\programmi\Trend Micro
2010-01-19 11:37 . 2010-01-19 11:37 417792 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\dbsqgfet.exe
2010-01-15 11:36 . 2010-01-15 11:36 364544 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\sfbnjv.exe
2010-01-13 06:54 . 2009-11-21 15:54 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 07:15 . 2010-01-12 07:15 -------- d-----w- c:\programmi\Uniblue
2009-12-27 07:48 . 2009-12-27 07:48 -------- d-----w- c:\programmi\Enigma Software Group
2009-12-27 07:22 . 2009-12-27 07:22 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\Uniblue

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-22 17:28 . 2005-09-13 17:06 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\Skype
2010-01-22 16:35 . 2007-12-24 21:55 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\skypePM
2010-01-22 14:29 . 2005-03-11 22:16 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\AdobeUM
2010-01-22 06:51 . 2008-09-14 12:23 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-01-21 21:30 . 2007-03-10 20:47 -------- d-----w- c:\programmi\Microsoft ActiveSync
2010-01-21 18:52 . 2008-08-06 13:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-21 18:52 . 2008-08-06 13:39 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-21 18:52 . 2008-08-06 13:39 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-21 18:51 . 2008-08-06 13:39 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-21 18:50 . 2008-06-07 07:51 -------- d-----w- c:\programmi\AVG
2010-01-21 13:20 . 2006-04-29 07:11 -------- d-----w- c:\programmi\RegistryFix
2010-01-20 22:40 . 2007-05-15 05:54 -------- d-----w- c:\programmi\eMule
2010-01-12 19:23 . 2009-12-11 20:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Ascentive
2009-12-29 10:49 . 2005-03-07 00:51 -------- d-----w- c:\programmi\EPSON Print CD
2009-12-23 07:13 . 2009-12-14 10:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\RegCure
2009-12-23 06:58 . 2009-12-14 10:12 -------- d-----w- c:\programmi\RegCure
2009-12-22 05:08 . 2004-08-19 12:00 669696 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:08 . 2004-08-19 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-14 11:11 . 2009-12-14 11:11 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\Ascentive
2009-12-11 21:01 . 2009-11-02 16:31 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-12-11 07:27 . 2009-12-11 07:27 -------- d-----w- c:\programmi\Eazel-IT
2009-12-09 11:07 . 2004-08-19 12:00 48308 ----a-w- c:\windows\system32\perfc010.dat
2009-12-09 11:07 . 2004-08-19 12:00 346260 ----a-w- c:\windows\system32\perfh010.dat
2009-12-08 18:28 . 2009-12-08 18:28 351744 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\thgaanti.exe
2009-12-08 14:22 . 2009-12-08 14:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\GoldWaveCDDB
2009-11-30 18:27 . 2009-11-30 18:27 293376 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\fmuldl.exe
2009-11-28 18:27 . 2009-11-28 18:27 434176 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\czwlaxmd.exe
2009-11-26 18:26 . 2009-11-26 18:26 319488 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\tiere.exe
2009-11-21 15:54 . 2004-08-19 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-12 18:22 . 2009-11-12 18:22 327680 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\amyeqeh.exe
2009-11-10 18:21 . 2009-11-10 18:21 434176 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\kwtyvamj.exe
2009-11-04 09:29 . 2009-11-04 09:29 152576 -c--a-w- c:\documents and settings\admin\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-02 16:31 . 2009-11-02 16:31 74 ---ha-w- c:\windows\UBURN.DAT
2009-11-01 22:45 . 2009-11-01 22:45 330240 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\vwmmve.exe
2009-10-27 09:32 . 2009-10-27 09:32 405504 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\ukkahw.exe
2006-11-30 17:51 . 2006-11-30 17:48 14879120 -c--a-w- c:\programmi\GoogleEarthWin.exe
2006-10-23 08:08 . 2006-10-23 08:08 17207032 -c--a-w- c:\programmi\avg75free_428a818.exe
2006-09-25 21:12 . 2006-09-25 21:12 7908566 -c--a-w- c:\programmi\nero66012_ita.exe
2006-09-25 13:19 . 2006-09-25 13:18 2405604 -c--a-w- c:\programmi\123dvdclone.exe
2006-09-18 17:08 . 2006-09-18 17:08 2072690 -c--a-w- c:\programmi\wfaxaut.exe
2006-09-15 13:42 . 2006-09-15 13:42 1159680 -c--a-w- c:\programmi\USR2884C-Win2000-XP-V177.exe
2006-09-15 13:34 . 2006-09-15 13:35 1225728 -c--a-w- c:\programmi\2884_XP_199_v92upgrade.exe
2006-09-01 12:37 . 2006-09-01 12:37 806483 ----a-w- c:\programmi\dvddecripter.zip
2006-02-21 14:32 . 2005-11-04 10:08 2020491 -c--a-w- c:\programmi\privacy-eraser-pro-setup.exe
2006-01-17 08:53 . 2006-01-17 08:47 24436627 -c--a-w- c:\programmi\pex85trial_eng.exe
2005-11-04 17:46 . 2005-11-04 17:46 522682 -c--a-w- c:\programmi\aspi_471a2.exe
2005-11-04 14:56 . 2005-11-04 14:56 11284970 ----a-w- c:\programmi\cdbxp_setup_3.0.116.zip
2005-11-04 14:55 . 2005-11-04 14:52 4826302 -c--a-w- c:\programmi\cdbxp_runtimes.exe
2005-11-04 14:20 . 2005-11-04 14:20 987213 -c--a-w- c:\programmi\BurnXFree.dmg
2005-11-01 14:31 . 2005-11-01 14:15 21647192 -c--a-w- c:\programmi\NVIDIA_PureVideo_Decoder_Trial_1.02-177.exe
2005-10-19 16:09 . 2005-10-19 16:09 1310720 -c--a-w- c:\programmi\isfw.exe
2005-09-29 18:51 . 2005-09-29 18:51 700416 -c--a-w- c:\programmi\StubInstaller.exe
2005-08-07 09:02 . 2005-08-07 09:01 7741336 ----a-w- c:\programmi\DivX521XP2K.exe
2005-08-07 08:52 . 2005-08-07 08:52 899414 -c--a-w- c:\programmi\SetupDVDDecrypter_3.5.4.0.exe
2005-06-08 20:56 . 2005-06-08 20:56 2000324 -c--a-w- c:\programmi\cdex_151.exe
2005-05-11 22:17 . 2005-06-11 12:40 5100032 -c--a-w- c:\programmi\Firefox Setup 1.0.4.exe
2005-03-31 20:17 . 2006-09-26 14:07 40960 ----a-w- c:\programmi\Uninstall_CDS.exe
2005-02-26 15:20 . 2005-03-19 09:19 5086216 -c--a-w- c:\programmi\Firefox Setup 1.0.1.exe
2009-02-02 20:09 . 2009-02-02 20:08 24 --sh--w- c:\windows\SCA3C8896.tmp
2005-08-07 09:04 . 2005-08-07 09:04 56 -csha-r- c:\windows\system32\D1DEACDDC9.sys
2006-06-17 07:42 . 2006-06-17 07:42 848 -csha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-21 18:51 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^PHOTOfunSTUDIO -viewer-.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\PHOTOfunSTUDIO -viewer-.lnk
backup=c:\windows\pss\PHOTOfunSTUDIO -viewer-.lnkCommon Startup
backupExtension=Common Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2007-10-11 06:45 31232 ----a-w- c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-01-21 18:50 2033432 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
2009-11-03 20:49 86016 ----a-w- c:\programmi\ClamWin\bin\ClamTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
2006-09-28 19:21 57344 ----a-w- c:\programmi\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 02:14 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo R300 Series]
2003-09-11 03:00 99840 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_S4I0F2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2005-01-19 13:22 405583 ----a-w- c:\programmi\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 12:11 267048 ----a-w- c:\programmi\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
2005-12-07 08:26 489472 ----a-w- c:\programmi\Logitech\Video\CameraAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraService(E)]
2004-11-01 15:22 262144 ----a-w- c:\windows\system32\ElkCtrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
2005-12-07 08:33 73728 ----a-w- c:\programmi\Logitech\Video\InstallHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2005-12-09 13:32 225280 ----a-w- c:\windows\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2006-09-15 12:27 2048000 -c----w- c:\programmi\ahead\nero\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2007-02-08 19:43 95800 ----a-w- c:\programmi\Olympus\OLYMPUS Master 2\MMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSDrvCheck]
2003-11-10 15:06 406016 ------w- c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-11-14 22:43 286720 ----a-w- c:\programmi\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-12-08 15:35 32768 ----a-w- c:\programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-01-29 13:01 23975720 ----a-r- c:\programmi\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 --sha-r- c:\programmi\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\programmi\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-10-08 06:58 198160 ----a-w- c:\programmi\File comuni\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
2004-02-04 21:04 45056 ----a-w- c:\programmi\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\ahead\\Nero ShowTime\\ShowTime.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\WCESMgr.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\StubInstaller.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\Programmi\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Programmi\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Programmi\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Programmi\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Programmi\\WinMX\\WinMX.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgam.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [21/01/2010 19.51.36 161800]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [06/08/2008 14.39.21 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [06/08/2008 14.39.26 360584]
R2 avg9emc;AVG E-mail Scanner;c:\programmi\AVG\AVG9\avgemc.exe [21/01/2010 19.50.51 906520]
R2 avg9wd;AVG WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [21/01/2010 19.50.48 285392]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [07/11/2005 17.27.41 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;c:\windows\system32\drivers\torususb.sys [07/11/2005 17.27.41 527980]
S2 gupdate1c9ad7450a18406;Servizio di Google Update (gupdate1c9ad7450a18406);c:\programmi\Google\Update\GoogleUpdate.exe [25/03/2009 19.05.37 133104]
S2 USBBC;USB Bridge Cable (Windows 2000);c:\windows\system32\USBBC20.sys [14/03/2005 10.02.23 14228]
S3 SER120;OTI Serial port driver;c:\windows\system32\drivers\ser120.sys [09/05/2006 16.02.05 32910]
.
Contenuto della cartella 'Scheduled Tasks'

2010-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-25 18:05]

2010-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-25 18:05]

2010-01-22 c:\windows\Tasks\RegCure Program Check.job
- c:\programmi\RegCure\RegCure.exe [2009-12-11 19:00]

2010-01-22 c:\windows\Tasks\RegCure Startup.job
- c:\programmi\RegCure\RegCure.exe [2009-12-11 19:00]

2010-01-22 c:\windows\Tasks\RegCure.job
- c:\programmi\RegCure\RegCure.exe [2009-12-11 19:00]
.
.
------- Scansione supplementare -------
.
mStart Page = hxxp://italian.ircfast.com/it/index.php?rvs=hompag
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Open using &Advanced JPEG Compressor - c:\programmi\Advanced JPEG Compressor\ajcieex.htm
TCP: {A5920058-11F0-4267-A733-8F61BFC40EF5} = 193.70.152.15 193.70.152.25
FF - ProfilePath - c:\documents and settings\admin\Dati applicazioni\Mozilla\Firefox\Profiles\7e8j4dsh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.virgilio.it/|http://www.virgilio.it/|http://www.virgilio.it/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\documents and settings\admin\Dati applicazioni\Mozilla\Firefox\Profiles\7e8j4dsh.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programmi\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\programmi\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\programmi\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\programmi\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\programmi\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\admin\Dati applicazioni\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\programmi\Viewpoint\Viewpoint Media Player\npViewpoint.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: browser.sessionstore.resume_from_crash - false
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-PowerBar - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-22 18:58
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ????????????l?@?l?@?D??????w???????????????wl?@?l?@????? ???????????g??w???w???????w???wx??????????w???????? ??????????????|x???0???????????? lt???w?????????????????N|?B???t???????l?@?l?@????????w????t?@?????l?@?8?@?l?@?3??s????????????????????8?@?_??s8?@?8?@

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1B19715B-5638-8401-1C19-FE3D8F14AFD3}]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) ) (Everyone)
@="Class"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2BE06C05-FF40-08E1-B3D2-C3A1E47712C9}]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) ) (Everyone)
@="Class"

[HKEY_LOCAL_MACHINE\software\Microsoft\hrvki]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) (5) (Everyone)

[HKEY_LOCAL_MACHINE\software\Microsoft\negyf]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) ) (Everyone)
"{1B19715B-5638-8401-1C19-FE3D8F14AFD3}"=""
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'Explorer.EXE'(1608)
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-01-22 19:05:02 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-22 18:04

Pre-Run: 7.508.426.752 byte disponibili
Post-Run: 7.630.487.552 byte disponibili

- - End Of File - - A775AFA0EF7CAF992C3C3EA39AB91648
r16
Inviato: Saturday, January 23, 2010 3:11:32 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Hai il pc molto infetto.
Devi disistallare SpyBot, compreso il Tea Timer. (da "Installazione Applicazioni")
A mio avviso, anche AVG è danneggiato.
Per cui, ti consiglio di disistallarlo.
Prima di disistallarlo, cessane l'esecuzione dalla Tray bar. (vicino all'orologio di Windows)
Poi lo disistalli da "Installazione Applicazioni".
Infine fai girare questo tool, che toglie eventuali residui rimasti.:
http://www.grisoft.cz/filedir/util/avg_arm_sup_____.dir/avgremover.exe

Finite le disistallazioni, fai una pulizia con CCleaner.(registro compreso)
Per il momento, NON reistallare AVG.
Esegui prima queste indicazioni:

Apri un file di testo sul Desktop (start\esegui\digita: notepad.exe\ Ok
Ci incolli il codice che vedi qui sotto, e salvi il file di testo obbligatoriamente con il nome CFScript.txt

Code:
Folder::
c:\programmi\Eazel-IT

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
PowerBar =-
[-HKEY_LOCAL_MACHINE\software\Microsoft\hrvki]
[-HKEY_LOCAL_MACHINE\software\Microsoft\negyf]

RegNull::
[HKEY_LOCAL_MACHINE\software\Microsoft\hrvki]
[HKEY_LOCAL_MACHINE\software\Microsoft\negyf]

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1B19715B-5638-8401-1C19-FE3D8F14AFD3}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2BE06C05-FF40-08E1-B3D2-C3A1E47712C9}]
[HKEY_LOCAL_MACHINE\software\Microsoft\hrvki]
[HKEY_LOCAL_MACHINE\software\Microsoft\negyf]


e trascinalo sull'icona di ComboFix.
Attendi la fine dei lavori, senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix.

Poi:
Scarica Avira:
http://www.aiutamici.com/software?ID=10908
Lo configuri esattamente come in questa guida, in formato PDF:
http://www.zeusnews.it/zz_upload/PSV/Guida%20completa%20di%20%20AVIRA%20Antivir%209.pdf

Le voci indicate nella prima immagine a pagina 11 della Guida, spuntale tutte (nell'immagine non lo sono).
Fai una scansione completa, e posta il log.
Mi raccomando, esegui le indicazioni cronologicamente. (
panchoz
Inviato: Saturday, January 23, 2010 3:33:29 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Ciao R16,

anche volendo fortissimamente ...non potevo dir nulla a favore di Avira!!


All'inizio ho fatto notare che quella installata era una versione superata di AVG.


paolopa
Inviato: Saturday, January 23, 2010 5:00:13 PM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
r16,mi levi una curiosita' se non disturbo?c è(credo)di nuovo l userinit inquinato,potrebbe essere il gromozon?ciao e grazie.
renzozilio
Inviato: Saturday, January 23, 2010 5:59:49 PM
Rank: Member

Iscritto dal : 1/21/2010
Posts: 12
all'attenzione di r16:
ho eseguito tutta la procedura che mi hai inviato e come da te richiesto ti allego il LOG di AVIRA.
Grazie dell'aiuto. Renzo


Avira AntiVir Personal - Free Antivirus Updater

Ora di creazione: Sat Jan 23 17:39:31 2010


Sistema operativo:
Windows XP (Service Pack 3) [5.1.2600]

Informazioni sul prodotto:
Versione del prodotto: 9.0.0.21
Updater: C:\Programmi\Avira\AntiVir Desktop\update.exe 9.0.0.52
Plugin: C:\Programmi\Avira\AntiVir Desktop\updext.dll 9.0.0.6

Directory temporanea: C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\
Cartella di backup: C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\BACKUP\
Directory dapos;installazione: C:\Programmi\Avira\AntiVir Desktop\
Cartella Updater: C:\Programmi\Avira\AntiVir Desktop\
Cartella AppData: C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\


[UPD] [INFO] Verifica della disponibilità di file più recenti.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://62.146.66.189/update'.
[UPD] [INFO] Download di 'http://62.146.66.189/update/idx/master.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://62.146.66.189/update/idx/master.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
[UPDLIB] [ERROR] Download del file 'http://62.146.66.189/update/idx/master.idx'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://62.146.66.189/update/idx/master.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://80.190.143.226/update'.
[UPD] [INFO] Download di 'http://80.190.143.226/update/idx/master.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.226/update/idx/master.idx'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.226/update/idx/master.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
[UPD] [INFO] Download di 'http://80.190.143.226/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.226/update/idx/wks_avira-win32-it-pecl.idx'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.226/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.226/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://80.190.143.227/update'.
[UPD] [INFO] Download di 'http://80.190.143.227/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.227/update/idx/wks_avira-win32-it-pecl.idx'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.227/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.227/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://80.190.143.228/update'.
[UPD] [INFO] Download di 'http://80.190.143.228/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.228/update/idx/wks_avira-win32-it-pecl.idx'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.228/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.228/update/idx/wks_avira-win32-it-pecl.idx'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.228/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://80.190.143.229/update'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.229/update/idx/wks_avira-win32-it-pecl.idx'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.229/update/idx/wks_avira-win32-it-pecl.idx' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.idx'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/idx/wks_avira-win32-it-pecl.info.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl.info.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/idx/vdf.info.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\vdf.info.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/idx/ave2-win32-int.info.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\ave2-win32-int.info.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/idx/specvir-win32-int.info.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\specvir-win32-int.info.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/idx/wks_avira-win32-it-pecl-info.info.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-it-pecl-info.info.gz'.
[UPD] [INFO] Confronto dei file locali con lo stato sul server per l'aggiornamento.
[UPD] [INFO] Controllo del modulo SELFUPDATE:
[UPD] [INFO] Controllo del modulo VDF:
[UPD] [INFO] File 'n_vdf/vbase001.vdf' (locale, server): 7.10.0.1 < 7.10.1.0
[UPD] [INFO] File 'n_vdf/vbase002.vdf' (locale, server): 7.10.0.2 < 7.10.3.1
[UPD] [INFO] File 'n_vdf/vbase003.vdf' (locale, server): 7.10.0.3 < 7.10.3.2
[UPD] [INFO] File 'n_vdf/vbase004.vdf' (locale, server): 7.10.0.4 < 7.10.3.3
[UPD] [INFO] File 'n_vdf/vbase005.vdf' (locale, server): 7.10.0.5 < 7.10.3.4
[UPD] [INFO] File 'n_vdf/vbase006.vdf' (locale, server): 7.10.0.6 < 7.10.3.5
[UPD] [INFO] File 'n_vdf/vbase007.vdf' (locale, server): 7.10.0.7 < 7.10.3.6
[UPD] [INFO] File 'n_vdf/vbase008.vdf' (locale, server): 7.10.0.8 < 7.10.3.7
[UPD] [INFO] File 'n_vdf/vbase009.vdf' (locale, server): 7.10.0.9 < 7.10.3.8
[UPD] [INFO] File 'n_vdf/vbase010.vdf' (locale, server): 7.10.0.10 < 7.10.3.9
[UPD] [INFO] File 'n_vdf/vbase011.vdf' (locale, server): 7.10.0.11 < 7.10.3.10
[UPD] [INFO] File 'n_vdf/vbase012.vdf' (locale, server): 7.10.0.12 < 7.10.3.11
[UPD] [INFO] File 'n_vdf/vbase013.vdf' (locale, server): 7.10.0.13 < 7.10.3.12
[UPD] [INFO] File 'n_vdf/vbase014.vdf' (locale, server): 7.10.0.14 < 7.10.3.45
[UPD] [INFO] File 'n_vdf/vbase015.vdf' (locale, server): 7.10.0.15 < 7.10.3.46
[UPD] [INFO] File 'n_vdf/vbase016.vdf' (locale, server): 7.10.0.16 < 7.10.3.47
[UPD] [INFO] File 'n_vdf/vbase017.vdf' (locale, server): 7.10.0.17 < 7.10.3.48
[UPD] [INFO] File 'n_vdf/vbase018.vdf' (locale, server): 7.10.0.18 < 7.10.3.49
[UPD] [INFO] File 'n_vdf/vbase019.vdf' (locale, server): 7.10.0.19 < 7.10.3.50
[UPD] [INFO] File 'n_vdf/vbase020.vdf' (locale, server): 7.10.0.20 < 7.10.3.51
[UPD] [INFO] File 'n_vdf/vbase021.vdf' (locale, server): 7.10.0.21 < 7.10.3.52
[UPD] [INFO] File 'n_vdf/vbase022.vdf' (locale, server): 7.10.0.22 < 7.10.3.53
[UPD] [INFO] File 'n_vdf/vbase023.vdf' (locale, server): 7.10.0.23 < 7.10.3.54
[UPD] [INFO] File 'n_vdf/vbase024.vdf' (locale, server): 7.10.0.24 < 7.10.3.55
[UPD] [INFO] File 'n_vdf/vbase025.vdf' (locale, server): 7.10.0.25 < 7.10.3.56
[UPD] [INFO] File 'n_vdf/vbase026.vdf' (locale, server): 7.10.0.26 < 7.10.3.57
[UPD] [INFO] File 'n_vdf/vbase027.vdf' (locale, server): 7.10.0.27 < 7.10.3.58
[UPD] [INFO] File 'n_vdf/vbase028.vdf' (locale, server): 7.10.0.28 < 7.10.3.59
[UPD] [INFO] File 'n_vdf/vbase029.vdf' (locale, server): 7.10.0.29 < 7.10.3.60
[UPD] [INFO] File 'n_vdf/vbase030.vdf' (locale, server): 7.10.0.30 < 7.10.3.61
[UPD] [INFO] File 'n_vdf/vbase031.vdf' (locale, server): 7.10.0.33 < 7.10.3.62
[UPD] [INFO] File 'n_vdf/aevdf.dat' (locale, server): 7.10.0.33 < 7.10.3.62
[UPD] [INFO] Controllo del modulo AVE2:
[UPD] [INFO] File 'ave2/win32/int/aecore.dll' (locale, server): 8.1.8.2 < 8.1.9.5
[UPD] [INFO] File 'ave2/win32/int/aegen.dll' (locale, server): 8.1.1.71 < 8.1.1.83
[UPD] [INFO] File 'ave2/win32/int/aehelp.dll' (locale, server): 8.1.7.0 < 8.1.10.0
[UPD] [INFO] File 'ave2/win32/int/aeheur.dll' (locale, server): 8.1.0.178 < 8.1.0.195
[UPD] [INFO] File 'ave2/win32/int/aepack.dll' (locale, server): 8.2.0.3 < 8.2.0.5
[UPD] [INFO] File 'ave2/win32/int/aerdl.dll' (locale, server): 8.1.3.2 < 8.1.3.4
[UPD] [INFO] File 'ave2/win32/int/aescn.dll' (locale, server): 8.1.2.5 < 8.1.3.1
[UPD] [INFO] File 'ave2/win32/int/aescript.dll' (locale, server): 8.1.2.43 < 8.1.3.12
[UPD] [INFO] File 'ave2/win32/int/aevdf.dll' (locale, server): 8.1.1.2 < 8.1.1.3
[UPD] [INFO] File 'ave2/win32/int/aeset.dat' (locale, server): 8.2.1.59 < 8.2.1.150
[UPD] [INFO] Controllo del modulo MAIN:
[UPD] [INFO] Il file 'wks_avira/win32/it/basic-nt/xp/avgntflt.inf' è contrassegnato con il flag IGNORE e pertanto non viene incluso.
[UPD] [INFO] Il file 'wks_avira/win32/it/basic-nt/avupgsvc.exe' è contrassegnato con il flag IGNORE e pertanto non viene incluso.
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/filelist.ini' è contrassegnato con il flag IGNORE e pertanto non viene incluso.
[UPD] [INFO] Il file 'wks_avira/win32/it/basic-nt/presetup.exe' è contrassegnato con il flag IGNORE e pertanto non viene incluso.
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/product.ini' è contrassegnato con il flag IGNORE e pertanto non viene incluso.
[UPD] [INFO] Il file 'wks_avira/win32/it/basic-nt/vcredist_x86.exe' è contrassegnato con il flag IGNORE e pertanto non viene incluso.
[UPD] [INFO] Controllo del modulo AVREP_NT:
[UPD] [INFO] Controllo del modulo COMMAPPDATA_AV:
[UPD] [INFO] Il file 'wks_avira/win32/it/basic-nt/addr_file.html' è già installato e non verrà aggiornato.
[UPD] [INFO] Controllo del modulo COMMAPP:
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/produpd.avj' è già installato e non verrà aggiornato.
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/scanjob.avj' è già installato e non verrà aggiornato.
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/startupd.avj' è già installato e non verrà aggiornato.
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/updjob.avj' è già installato e non verrà aggiornato.
[UPD] [INFO] Controllo del modulo COMMAPDATA_AV_PROFILES:
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/folder.avp' è già installato e non verrà aggiornato.
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/rootkit.avp' è già installato e non verrà aggiornato.
[UPD] [INFO] Controllo del modulo TEXT:
[UPD] [INFO] Il file 'wks_avira/win32/it/classic-nt/eula.txt' è già installato e non verrà aggiornato.
[UPD] [INFO] Controllo del modulo DRV:
[UPD] [INFO] Controllo del modulo PRODINFO:
[UPD] [INFO] Controllo delle dipendenze della modalità di aggiornamento del prodotto.
[UPD] [INFO] Le dipendenze sono state eseguite.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\BACKUP\' necessita di 4612781 byte di spazio libero su disco.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\' necessita di 19600764 byte di spazio libero su disco.
[UPD] [INFO] 'C:\Programmi\Avira\AntiVir Desktop\' necessita di 9800382 byte di spazio libero su disco.
[UPD] [INFO] Spazio su disco OK.
[UPD] [INFO] Drive: C:\, capacità libera: 2122473472 byte.
[UPD] [INFO] Download di nuovi file in corso...
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase001.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase001.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase002.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase002.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase003.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase003.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase004.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase004.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase005.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase005.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase006.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase006.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase007.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase007.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase008.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase008.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase009.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase009.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase010.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase010.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase011.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase011.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase012.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase012.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase013.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase013.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase014.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase014.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase015.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase015.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase016.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase016.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase017.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase017.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase018.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase018.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase019.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase019.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase020.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase020.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase021.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase021.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase022.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase022.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase023.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase023.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase024.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase024.vdf.gz'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.229/update/n_vdf/vbase024.vdf.gz'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase024.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase024.vdf.gz'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.229/update/n_vdf/vbase024.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase024.vdf.gz'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://80.190.143.230/update'.
[UPD] [INFO] Download di 'http://80.190.143.230/update/n_vdf/vbase024.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase024.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.230/update/n_vdf/vbase025.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase025.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.230/update/n_vdf/vbase026.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase026.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.230/update/n_vdf/vbase027.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase027.vdf.gz'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.230/update/n_vdf/vbase027.vdf.gz'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.230/update/n_vdf/vbase027.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase027.vdf.gz'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.230/update/n_vdf/vbase027.vdf.gz'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.230/update/n_vdf/vbase027.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase027.vdf.gz'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://80.190.143.231/update'.
[UPD] [INFO] Download di 'http://80.190.143.231/update/n_vdf/vbase027.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase027.vdf.gz'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.231/update/n_vdf/vbase027.vdf.gz'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.231/update/n_vdf/vbase027.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase027.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.231/update/n_vdf/vbase028.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase028.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.231/update/n_vdf/vbase029.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase029.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.231/update/n_vdf/vbase030.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase030.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.231/update/n_vdf/vbase031.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase031.vdf.gz'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.231/update/n_vdf/vbase031.vdf.gz'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.231/update/n_vdf/vbase031.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase031.vdf.gz'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.231/update/n_vdf/vbase031.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase031.vdf.gz'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://80.190.143.232/update'.
[UPD] [INFO] Download di 'http://80.190.143.232/update/n_vdf/vbase031.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase031.vdf.gz'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.232/update/n_vdf/vbase031.vdf.gz'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.232/update/n_vdf/vbase031.vdf.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase031.vdf.gz'.
[UPD] [INFO] Download di 'http://80.190.143.232/update/n_vdf/aevdf.dat.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\aevdf.dat.gz'.
[UPD] [INFO] Download di 'http://80.190.143.232/update/ave2/win32/int/aecore.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aecore.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.232/update/ave2/win32/int/aegen.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aegen.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.232/update/ave2/win32/int/aehelp.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aehelp.dll.gz'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.232/update/ave2/win32/int/aehelp.dll.gz'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.232/update/ave2/win32/int/aehelp.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aehelp.dll.gz'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.232/update/ave2/win32/int/aehelp.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aehelp.dll.gz'.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Selezione del server per l'aggiornamento 'http://80.190.143.233/update'.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aehelp.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aehelp.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aeheur.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aeheur.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aepack.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aepack.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aerdl.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aerdl.dll.gz'.
[UPDLIB] [ERROR] Download del file 'http://80.190.143.233/update/ave2/win32/int/aerdl.dll.gz'. Servizio non disponibile.
[UPDLIB] [ERROR] Gestore download: errore nella libreria WinINet.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aerdl.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aerdl.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aescn.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aescn.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aescript.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aescript.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aevdf.dll.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aevdf.dll.gz'.
[UPD] [INFO] Download di 'http://80.190.143.233/update/ave2/win32/int/aeset.dat.gz' in 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aeset.dat.gz'.
[UPD] [INFO] File di licenza: versione completa
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase001.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase001.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase002.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase002.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase003.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase003.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase004.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase004.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase005.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase005.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase006.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase006.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase007.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase007.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase008.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase008.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase009.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase009.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase010.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase010.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase011.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase011.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase012.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase012.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase013.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase013.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase014.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase014.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase015.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase015.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase016.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase016.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase017.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase017.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase018.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase018.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase019.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase019.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase020.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase020.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase021.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase021.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase022.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase022.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase023.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase023.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase024.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase024.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase025.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase025.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase026.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase026.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase027.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase027.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase028.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase028.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase029.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase029.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase030.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase030.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase031.vdf' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\vbase031.vdf'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\aevdf.dat' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aevdf.dat'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aecore.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aecore.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aegen.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aegen.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aehelp.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aehelp.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aeheur.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aeheur.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aepack.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aepack.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aerdl.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aerdl.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aescn.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aescn.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aescript.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aescript.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aevdf.dll' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aevdf.dll'.
[UPD] [INFO] 'C:\Documents and Settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aeset.dat' è stato copiato in 'C:\Programmi\Avira\AntiVir Desktop\aeset.dat'.
[UPD] [INFO] Reinizializzazione di Avira AntiVir Guard riuscita.

Riepilogo:
**********
42 file scaricati
42 file installati
File scaricato(i): vbase001.vdf 7.10.1.0; vbase002.vdf 7.10.3.1; vbase003.vdf 7.10.3.2; vbase004.vdf 7.10.3.3; vbase005.vdf 7.10.3.4; vbase006.vdf 7.10.3.5; vbase007.vdf 7.10.3.6;
vbase008.vdf 7.10.3.7; vbase009.vdf 7.10.3.8; vbase010.vdf 7.10.3.9; vbase011.vdf 7.10.3.10; vbase012.vdf 7.10.3.11; vbase013.vdf 7.10.3.12; vbase014.vdf 7.10.3.45;
vbase015.vdf 7.10.3.46; vbase016.vdf 7.10.3.47; vbase017.vdf 7.10.3.48; vbase018.vdf 7.10.3.49; vbase019.vdf 7.10.3.50; vbase020.vdf 7.10.3.51; vbase021.vdf 7.10.3.52;
vbase022.vdf 7.10.3.53; vbase023.vdf 7.10.3.54; vbase024.vdf 7.10.3.55; vbase025.vdf 7.10.3.56; vbase026.vdf 7.10.3.57; vbase027.vdf 7.10.3.58; vbase028.vdf 7.10.3.59;
vbase029.vdf 7.10.3.60; vbase030.vdf 7.10.3.61; vbase031.vdf 7.10.3.62; aevdf.dat 7.10.3.62; aecore.dll 8.1.9.5; aegen.dll 8.1.1.83; aehelp.dll 8.1.10.0;
aeheur.dll 8.1.0.195; aepack.dll 8.2.0.5; aerdl.dll 8.1.3.4; aescn.dll 8.1.3.1; aescript.dll 8.1.3.12; aevdf.dll 8.1.1.3; aeset.dat 8.2.1.150;


17:56:16 L'aggiornamento è stato eseguito con successo!
r16
Inviato: Saturday, January 23, 2010 8:44:45 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
No, non ci siamo capiti.
Prima della scansione con Avira (che quella non è una scansione) dovevi fare della altre importanti operazioni.
La scansione con Combofix, per esempio.
E postare il relativo log che ne usciva.
Oltre al log di Combofix, posta anche un log aggiornato di HijackThis.
renzozilio
Inviato: Saturday, January 23, 2010 10:03:52 PM
Rank: Member

Iscritto dal : 1/21/2010
Posts: 12
ciaor16 scusami se non ho osservato la sequenza delle tue informazioni descritte nella mail precedente, ma il PC a volte non collabora.
Asd ogni buon conto, questo è il LOG di COMBOFIX



ComboFix 10-01-21.08 - admin 23/01/2010 21.44.45.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1535.1101 [GMT 1:00]
Eseguito da: c:\documents and settings\admin\Documenti\Download\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
I seguenti file sono stati disabilitati durante la scansione:
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll


((((((((((((((((((((((((( Files Creati Da 2009-12-23 al 2010-01-23 )))))))))))))))))))))))))))))))))))
.

2010-01-23 16:34 . 2009-11-25 10:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-23 16:34 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-23 16:34 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-23 16:34 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-23 16:34 . 2010-01-23 16:34 -------- d-----w- c:\programmi\Avira
2010-01-23 16:34 . 2010-01-23 16:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-01-22 02:09 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-01-21 21:27 . 2010-01-21 21:27 -------- d-----w- c:\programmi\Microsoft CAPICOM 2.1.0.2
2010-01-21 18:52 . 2010-01-21 19:23 -------- dc----w- C:\$AVG
2010-01-21 18:50 . 2010-01-23 15:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-01-21 16:52 . 2010-01-21 16:52 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\Malwarebytes
2010-01-21 16:52 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-21 16:52 . 2010-01-21 16:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-01-21 16:52 . 2010-01-21 17:07 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-21 16:52 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-21 12:46 . 2010-01-23 15:26 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-01-21 12:46 . 2010-01-23 15:26 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-01-20 21:47 . 2010-01-20 21:47 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-20 17:23 . 2010-01-20 17:23 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\.clamwin
2010-01-20 17:23 . 2010-01-20 17:23 -------- d-----w- c:\programmi\ClamWin
2010-01-20 17:23 . 2010-01-20 17:23 -------- d-----w- c:\documents and settings\All Users\.clamwin
2010-01-20 15:38 . 2010-01-20 15:38 -------- d-----w- c:\programmi\Trend Micro
2010-01-19 11:37 . 2010-01-19 11:37 417792 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\dbsqgfet.exe
2010-01-13 06:54 . 2009-11-21 15:54 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 07:15 . 2010-01-12 07:15 -------- d-----w- c:\programmi\Uniblue
2009-12-27 07:48 . 2009-12-27 07:48 -------- d-----w- c:\programmi\Enigma Software Group
2009-12-27 07:22 . 2009-12-27 07:22 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\Uniblue

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-23 19:17 . 2005-09-06 06:14 -------- d-----w- c:\programmi\TopText
2010-01-22 17:28 . 2005-09-13 17:06 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\Skype
2010-01-22 16:35 . 2007-12-24 21:55 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\skypePM
2010-01-22 14:29 . 2005-03-11 22:16 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\AdobeUM
2010-01-22 06:51 . 2008-09-14 12:23 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-01-21 21:30 . 2007-03-10 20:47 -------- d-----w- c:\programmi\Microsoft ActiveSync
2010-01-21 18:50 . 2008-06-07 07:51 -------- d-----w- c:\programmi\AVG
2010-01-21 13:20 . 2006-04-29 07:11 -------- d-----w- c:\programmi\RegistryFix
2010-01-20 22:40 . 2007-05-15 05:54 -------- d-----w- c:\programmi\eMule
2010-01-12 19:23 . 2009-12-11 20:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Ascentive
2009-12-29 10:49 . 2005-03-07 00:51 -------- d-----w- c:\programmi\EPSON Print CD
2009-12-23 07:13 . 2009-12-14 10:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\RegCure
2009-12-23 06:58 . 2009-12-14 10:12 -------- d-----w- c:\programmi\RegCure
2009-12-22 05:08 . 2004-08-19 12:00 669696 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:08 . 2004-08-19 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-14 11:11 . 2009-12-14 11:11 -------- dc----w- c:\documents and settings\admin\Dati applicazioni\Ascentive
2009-12-11 21:01 . 2009-11-02 16:31 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-12-09 11:07 . 2004-08-19 12:00 48308 ----a-w- c:\windows\system32\perfc010.dat
2009-12-09 11:07 . 2004-08-19 12:00 346260 ----a-w- c:\windows\system32\perfh010.dat
2009-12-08 18:28 . 2009-12-08 18:28 351744 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\thgaanti.exe
2009-12-08 14:22 . 2009-12-08 14:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\GoldWaveCDDB
2009-11-30 18:27 . 2009-11-30 18:27 293376 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\fmuldl.exe
2009-11-28 18:27 . 2009-11-28 18:27 434176 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\czwlaxmd.exe
2009-11-26 18:26 . 2009-11-26 18:26 319488 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\tiere.exe
2009-11-21 15:54 . 2004-08-19 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-12 18:22 . 2009-11-12 18:22 327680 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\amyeqeh.exe
2009-11-10 18:21 . 2009-11-10 18:21 434176 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\kwtyvamj.exe
2009-11-04 09:29 . 2009-11-04 09:29 152576 -c--a-w- c:\documents and settings\admin\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-02 16:31 . 2009-11-02 16:31 74 ---ha-w- c:\windows\UBURN.DAT
2009-10-27 09:32 . 2009-10-27 09:32 405504 ----a-w- c:\documents and settings\admin\Impostazioni locali\Dati applicazioni\ukkahw.exe
2006-11-30 17:51 . 2006-11-30 17:48 14879120 -c--a-w- c:\programmi\GoogleEarthWin.exe
2006-10-23 08:08 . 2006-10-23 08:08 17207032 -c--a-w- c:\programmi\avg75free_428a818.exe
2006-09-25 21:12 . 2006-09-25 21:12 7908566 -c--a-w- c:\programmi\nero66012_ita.exe
2006-09-25 13:19 . 2006-09-25 13:18 2405604 -c--a-w- c:\programmi\123dvdclone.exe
2006-09-18 17:08 . 2006-09-18 17:08 2072690 -c--a-w- c:\programmi\wfaxaut.exe
2006-09-15 13:42 . 2006-09-15 13:42 1159680 -c--a-w- c:\programmi\USR2884C-Win2000-XP-V177.exe
2006-09-15 13:34 . 2006-09-15 13:35 1225728 -c--a-w- c:\programmi\2884_XP_199_v92upgrade.exe
2006-09-01 12:37 . 2006-09-01 12:37 806483 ----a-w- c:\programmi\dvddecripter.zip
2006-02-21 14:32 . 2005-11-04 10:08 2020491 -c--a-w- c:\programmi\privacy-eraser-pro-setup.exe
2006-01-17 08:53 . 2006-01-17 08:47 24436627 -c--a-w- c:\programmi\pex85trial_eng.exe
2005-11-04 17:46 . 2005-11-04 17:46 522682 -c--a-w- c:\programmi\aspi_471a2.exe
2005-11-04 14:56 . 2005-11-04 14:56 11284970 ----a-w- c:\programmi\cdbxp_setup_3.0.116.zip
2005-11-04 14:55 . 2005-11-04 14:52 4826302 -c--a-w- c:\programmi\cdbxp_runtimes.exe
2005-11-04 14:20 . 2005-11-04 14:20 987213 -c--a-w- c:\programmi\BurnXFree.dmg
2005-11-01 14:31 . 2005-11-01 14:15 21647192 -c--a-w- c:\programmi\NVIDIA_PureVideo_Decoder_Trial_1.02-177.exe
2005-10-19 16:09 . 2005-10-19 16:09 1310720 -c--a-w- c:\programmi\isfw.exe
2005-09-29 18:51 . 2005-09-29 18:51 700416 -c--a-w- c:\programmi\StubInstaller.exe
2005-08-07 09:02 . 2005-08-07 09:01 7741336 ----a-w- c:\programmi\DivX521XP2K.exe
2005-08-07 08:52 . 2005-08-07 08:52 899414 -c--a-w- c:\programmi\SetupDVDDecrypter_3.5.4.0.exe
2005-06-08 20:56 . 2005-06-08 20:56 2000324 -c--a-w- c:\programmi\cdex_151.exe
2005-05-11 22:17 . 2005-06-11 12:40 5100032 -c--a-w- c:\programmi\Firefox Setup 1.0.4.exe
2005-03-31 20:17 . 2006-09-26 14:07 40960 ----a-w- c:\programmi\Uninstall_CDS.exe
2005-02-26 15:20 . 2005-03-19 09:19 5086216 -c--a-w- c:\programmi\Firefox Setup 1.0.1.exe
2009-02-02 20:09 . 2009-02-02 20:08 24 --sh--w- c:\windows\SCA3C8896.tmp
2005-08-07 09:04 . 2005-08-07 09:04 56 -csha-r- c:\windows\system32\D1DEACDDC9.sys
2006-06-17 07:42 . 2006-06-17 07:42 848 -csha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-01-23_16.14.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 01:19 . 2007-11-07 01:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 05:07 . 2008-07-29 05:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 05:07 . 2008-07-29 05:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2010-01-23 19:23 . 2010-01-23 19:23 16384 c:\windows\Temp\Perflib_Perfdata_7fc.dat
+ 2010-01-23 16:34 . 2009-05-11 08:12 28520 c:\windows\system32\drivers\ssmdrv.sys
+ 2008-07-29 07:05 . 2008-07-29 07:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 02:54 . 2008-07-29 02:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2010-01-23 16:32 . 2010-01-23 16:32 228352 c:\windows\Installer\35fdec.msi
+ 2008-07-29 07:05 . 2008-07-29 07:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 07:05 . 2008-07-29 07:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
- 2005-03-07 01:26 . 2010-01-23 12:19 3817984 c:\windows\Installer\13890c.msi
+ 2005-03-07 01:26 . 2010-01-23 16:30 3817984 c:\windows\Installer\13890c.msi
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^PHOTOfunSTUDIO -viewer-.lnk]
backup=c:\windows\pss\PHOTOfunSTUDIO -viewer-.lnkCommon Startup
backupExtension=Common Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2007-10-11 06:45 31232 ----a-w- c:\programmi\File comuni\ArcSoft\Connection Service\Bin\ACDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
2009-11-03 20:49 86016 ----a-w- c:\programmi\ClamWin\bin\ClamTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
2006-09-28 19:21 57344 ----a-w- c:\programmi\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 02:14 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo R300 Series]
2003-09-11 03:00 99840 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_S4I0F2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2005-01-19 13:22 405583 ----a-w- c:\programmi\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 12:11 267048 ----a-w- c:\programmi\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
2005-12-07 08:26 489472 ----a-w- c:\programmi\Logitech\Video\CameraAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraService(E)]
2004-11-01 15:22 262144 ----a-w- c:\windows\system32\ElkCtrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
2005-12-07 08:33 73728 ----a-w- c:\programmi\Logitech\Video\InstallHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2005-12-09 13:32 225280 ----a-w- c:\windows\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2006-09-15 12:27 2048000 -c----w- c:\programmi\ahead\nero\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2007-02-08 19:43 95800 ----a-w- c:\programmi\Olympus\OLYMPUS Master 2\MMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSDrvCheck]
2003-11-10 15:06 406016 ------w- c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-11-14 22:43 286720 ----a-w- c:\programmi\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-12-08 15:35 32768 ----a-w- c:\programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-01-29 13:01 23975720 ----a-r- c:\programmi\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\programmi\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-10-08 06:58 198160 ----a-w- c:\programmi\File comuni\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
2004-02-04 21:04 45056 ----a-w- c:\programmi\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\ahead\\Nero ShowTime\\ShowTime.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\WCESMgr.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\StubInstaller.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\Programmi\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Programmi\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Programmi\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Programmi\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Programmi\\WinMX\\WinMX.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [07/11/2005 17.27.41 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;c:\windows\system32\drivers\torususb.sys [07/11/2005 17.27.41 527980]
S2 gupdate1c9ad7450a18406;Servizio di Google Update (gupdate1c9ad7450a18406);c:\programmi\Google\Update\GoogleUpdate.exe [25/03/2009 19.05.37 133104]
S2 USBBC;USB Bridge Cable (Windows 2000);c:\windows\system32\USBBC20.sys [14/03/2005 10.02.23 14228]
S3 SER120;OTI Serial port driver;c:\windows\system32\drivers\ser120.sys [09/05/2006 16.02.05 32910]
.
Contenuto della cartella 'Scheduled Tasks'

2010-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-25 18:05]

2010-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-25 18:05]

2010-01-23 c:\windows\Tasks\RegCure Program Check.job
- c:\programmi\RegCure\RegCure.exe [2009-12-11 19:00]

2010-01-23 c:\windows\Tasks\RegCure Startup.job
- c:\programmi\RegCure\RegCure.exe [2009-12-11 19:00]

2010-01-23 c:\windows\Tasks\RegCure.job
- c:\programmi\RegCure\RegCure.exe [2009-12-11 19:00]
.
.
------- Scansione supplementare -------
.
mStart Page = hxxp://italian.ircfast.com/it/index.php?rvs=hompag
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Open using &Advanced JPEG Compressor - c:\programmi\Advanced JPEG Compressor\ajcieex.htm
TCP: {A5920058-11F0-4267-A733-8F61BFC40EF5} = 193.70.152.15 193.70.152.25
FF - ProfilePath - c:\documents and settings\admin\Dati applicazioni\Mozilla\Firefox\Profiles\7e8j4dsh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.virgilio.it/|http://www.virgilio.it/|http://www.virgilio.it/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\documents and settings\admin\Dati applicazioni\Mozilla\Firefox\Profiles\7e8j4dsh.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\admin\Dati applicazioni\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\programmi\Viewpoint\Viewpoint Media Player\npViewpoint.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: browser.sessionstore.resume_from_crash - false
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-23 21:58
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(5876)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-01-23 22:00:28
ComboFix-quarantined-files.txt 2010-01-23 21:00
ComboFix2.txt 2010-01-23 16:16
ComboFix3.txt 2010-01-22 18:05

Pre-Run: 3.662.110.720 byte disponibili
Post-Run: 3.639.857.152 byte disponibili

- - End Of File - - 125FC50B73C56E79C6F855EDB78D4AFD



e questo è quello di Hijack This

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.05.31, on 23/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
C:\Programmi\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://italian.ircfast.com/it/index.php?rvs=hompag
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {b5146c40-189a-4311-bda9-fbae3e023187} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Virgilio Toolbar - {D3403F28-7D39-435F-A8CB-45016C29E48E} - C:\Programmi\Virgilio Toolbar\VirgilioBand.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programmi\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmi\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Programmi\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: Crea preferiti portatile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Crea preferiti portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137779450562
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264108325250
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5920058-11F0-4267-A733-8F61BFC40EF5}: NameServer = 193.70.152.15 193.70.152.25
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Programmi\File comuni\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Servizio di Google Update (gupdate1c9ad7450a18406) (gupdate1c9ad7450a18406) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe

--
End of file - 6706 bytes


Ti saluto e ringrazio. Renzo


r16
Inviato: Saturday, January 23, 2010 11:08:24 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
renzozilio
Inviato: Sunday, January 24, 2010 11:32:27 AM
Rank: Member

Iscritto dal : 1/21/2010
Posts: 12
alla c.a. di r16.
Ciao sono ancora Renzo, ho fatto come mi hai scritto: ho installato Explorer 8, poi ho aggiornato anche Windows al SP3.
Ora nel mio PC sono presenti 2 browser; Explorer e Mozilla: devo eliminare Mozilla?
Avira lo faccio girare ogni giorno sul PC??.
Grazie e buona domenica. Renzo
panchoz
Inviato: Sunday, January 24, 2010 11:46:06 AM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Explorer e FF possono convivere tranquillamente.


Con Avira non occorre fare la scansione tutti i giorni, pure troppo settimanale.

Una volta alla settimana con MBAM ci può stare.


Shhh Salvo disposizioni diverse per un periodo di monitoraggio post-operatorio!!Drool

panchoz
Inviato: Sunday, January 24, 2010 11:50:56 AM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Considerato che il Sistema ha subito vari cambiamenti sarebbe d'uopo eseguire Cleanup and Repair:
http://software.aiutamici.com/software?s=y


Mi raccomando Ccleaner "pulizia" Registro e file inutilizzati, alcune impostazioni:
- file delle precedenti 48 ore
- vecchi dati Prefetch
- Log IIS

si possono NON cancellare..

- collegamenti Menu Star e Desktop
- dati recenti
- cronologia (se non espressamente desiderato)
renzozilio
Inviato: Sunday, January 24, 2010 2:11:36 PM
Rank: Member

Iscritto dal : 1/21/2010
Posts: 12
Ho fatto girare CCleaner. e lo farò girare ogni giorno; prima lo facevo saltuariamente ma comunque entro i 10-15 gg.

Mi dici poi che conviene eseguire; "Una volta alla........... con MBAM ci può stare"
ma MBAN non so che programma sia e la frequenza qual'è?
.
Ho fatto girare "Cleanup and Repair" ora lo devo fare anche in seguito ma con quale frequenza?

Forse avrai bisogno di controllare qualche altro log dopo esecuzione di Hijack e Avira?

Come si fa a sapere se ora il PC si trova in uno stato buono ed è protetto?

Potresti dirmi se per la sicurezza del PC sono sufficienti CCleaner e Avira o serve anche AVG?

Grazie del tuo aiuto. Un saluto da Renzo
panchoz
Inviato: Sunday, January 24, 2010 2:34:32 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
renzozilio ha scritto:
Ho fatto girare CCleaner. e lo farò girare ogni giorno; prima lo facevo saltuariamente ma comunque entro i 10-15 gg.

Mi dici poi che conviene eseguire; "Una volta alla........... con MBAM ci può stare"
ma MBAN non so che programma sia e la frequenza qual'è? MalwareBytes AntiMalware
.
Ho fatto girare "Cleanup and Repair" ora lo devo fare anche in seguito ma con quale frequenza? Non esiste un periodo prefissato, di solito quando si apportano dei cambiamenti o 2/3 mesi.


Forse avrai bisogno di controllare qualche altro log dopo esecuzione di Hijack e Avira?
Te lo dirà R16.


Come si fa a sapere se ora il PC si trova in uno stato buono ed è protetto?
Vedi sopra.


Potresti dirmi se per la sicurezza del PC sono sufficienti CCleaner e Avira o serve anche AVG?
Ccleaner serve per la "pulizia" come ho scritto sopra. In ambito Sicurezza è molto utile perchè cancella i file temporanei che sono il terreno dove si annidano le minacce in ingresso.
Shhh Shhh Shhh Avira e AVG sono 2 antivirus residenti che entrerebbero in conflitto fra di loro se utilizzati contemporaneamente, o anche solo presenti insieme.

Grazie del tuo aiuto. Un saluto da Renzo
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.