Pagina 1 di 1

Potete controllarmi il Log?

MessaggioInviato: sab apr 24, 2010 6:49 pm
da pirataunico

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18.44.01, on 24/04/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
C:\Programmi\File comuni\Mcafee\McSvcHost\McSvHost.exe
C:\Programmi\File comuni\McAfee\SystemCore\mfevtps.exe
C:\Programmi\McAfee Online Backup\MOBKbackup.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programmi\CyberLink\Shared files\RichVideo.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\Programmi\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\TomTom HOME 2\TomTomHOMEService.exe
C:\Programmi\UPHClean\uphclean.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Programmi\File comuni\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\File comuni\McAfee\SystemCore\mcshield.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\mshta.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fastweb.it/portale/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: Softonic Italia FF Toolbar - {55f58bee-3fad-46fe-bf11-887e3bb32a43} - C:\Programmi\Softonic_Italia_FF\tbSof0.dll
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Softonic Italia FF Toolbar - {55f58bee-3fad-46fe-bf11-887e3bb32a43} - C:\Programmi\Softonic_Italia_FF\tbSof0.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmi\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programmi\File comuni\McAfee\SystemCore\ScriptSn.20100422192559.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Programmi\Power Translator\Applications\LEC IE Translation Extension.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmi\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O3 - Toolbar: Softonic Italia FF Toolbar - {55f58bee-3fad-46fe-bf11-887e3bb32a43} - C:\Programmi\Softonic_Italia_FF\tbSof0.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Programmi\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [BrowserChoice] "C:\WINDOWS\system32\browserchoice.exe" /run
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/56.25/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmi\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Servizio di Google Update (gupdate1c9f105e6f75df7) (gupdate1c9f105e6f75df7) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Programmi\File comuni\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Programmi\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: McAfee Personal Firewall (McMPFSvc) - McAfee, Inc. - C:\Programmi\File comuni\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Programmi\File comuni\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Programmi\File comuni\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Programmi\File comuni\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Programmi\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Programmi\File comuni\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Programmi\File comuni\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Programmi\File comuni\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Programmi\File comuni\McAfee\SystemCore\mfevtps.exe
O23 - Service: 1% (MOBKbackup) - McAfee, Inc. - C:\Programmi\McAfee Online Backup\MOBKbackup.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Programmi\File comuni\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Programmi\TomTom HOME 2\TomTomHOMEService.exe

--
End of file - 12814 bytes

Re: Potete controllarmi il Log?

MessaggioInviato: dom apr 25, 2010 7:24 am
da crazy.cat
Che problemi hai oltre a due o trecento toolbar e programmi inutili attivi?

Re: Potete controllarmi il Log?

MessaggioInviato: dom apr 25, 2010 9:25 am
da farbix89
posso buttarla li,in attesa di smentita o conferma dell'utente

"Internet Explorer si Apre dopo 10 anni,e il PC si avvia come una lumaca,con tutte quelle toolbar e programmi inutili"

Re: Potete controllarmi il Log?

MessaggioInviato: dom apr 25, 2010 10:09 pm
da RedRob
Platform: Windows XP SP2, il SP3?? [uhm] Importantissimo per la sicurezza complessiva.

comunque sistema prima tutto il resto.

Re: Potete controllarmi il Log?

MessaggioInviato: lun apr 26, 2010 2:08 pm
da Berga95
@ RedRob: Si vede dal log, alla 3a riga: SP2...
Comunque mi sto sbagliando o c'è McAfee e spyware terminator con la protezione in tempo reale di tutti e 2?
[ciao]

Re: Potete controllarmi il Log?

MessaggioInviato: lun apr 26, 2010 4:38 pm
da pirataunico
fabrix 89 ha pienamente ragione , si apre dopo 10 anni e il pc si avvia come una lumaca, questo e' il problema; adesso pero' ho tolto spyware terminator in tempo reale perche' la nuova versione di mc afee non lo accettava e le cose sono andate meglio....come faccio a togliere tutte quello tool bar?e cosa devo togliere dal log che vi ho mandato?
grazie x il vs tempo vi auguro una bellissima serata

Re: Potete controllarmi il Log?

MessaggioInviato: lun apr 26, 2010 5:53 pm
da crazy.cat
Per le toolbar controlla nelle applicazioni installate.

Rifai la scansione con hijackthis, selezioni le caselle di queste righe e premi fix checked per eliminarle.
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [BrowserChoice] "C:\WINDOWS\system32\browserchoice.exe" /run

Re: Potete controllarmi il Log?

MessaggioInviato: lun mag 03, 2010 3:17 pm
da naploli
mi kontrollate anche il mio
ComboFix 10-04-30.03 - Tommy 02/05/2010 13.08.32.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.510.217 [GMT 2:00]
Eseguito da: c:\documents and settings\Tommy\Desktop\ComboFix.exe
AV: AVG Internet Security 3-pack *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programmi\WindowsUpdate
c:\windows\system32\Ijl11.dll

.
((((((((((((((((((((((((( Files Creati Da 2010-04-02 al 2010-05-02 )))))))))))))))))))))))))))))))))))
.

2010-05-01 16:55 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-05-01 16:55 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-01 14:44 . 2010-05-01 14:44 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\WMTools Downloaded Files
2010-05-01 14:22 . 2010-05-01 15:38 -------- d-----w- c:\documents and settings\Tommy\Tracing
2010-05-01 14:21 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Microsoft
2010-05-01 14:21 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Windows Live SkyDrive
2010-05-01 14:20 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Windows Live
2010-05-01 14:11 . 2010-05-01 14:11 -------- d-----w- c:\programmi\File comuni\Windows Live
2010-05-01 14:11 . 2010-05-01 14:22 14248 ----a-w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-04-29 21:57 . 2010-05-01 23:32 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\vlc
2010-04-29 21:55 . 2010-04-29 21:55 -------- d-----w- c:\programmi\VideoLAN
2010-04-25 20:18 . 2010-04-25 20:18 -------- d-----w- c:\windows\Sun
2010-04-25 20:17 . 2010-04-25 20:17 -------- d-----w- c:\programmi\File comuni\Java
2010-04-25 20:17 . 2010-04-25 20:17 503808 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\msvcp71.dll
2010-04-25 20:17 . 2010-04-25 20:17 499712 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\jmc.dll
2010-04-25 20:17 . 2010-04-25 20:17 348160 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\msvcr71.dll
2010-04-25 20:17 . 2010-04-25 20:17 61440 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6238d18e-n\decora-sse.dll
2010-04-25 20:17 . 2010-04-25 20:17 12800 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6238d18e-n\decora-d3d.dll
2010-04-25 20:16 . 2010-04-25 20:16 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-25 20:16 . 2010-04-25 20:16 -------- d-----w- c:\programmi\Java
2010-04-22 19:26 . 2010-04-22 19:26 -------- d-sh--w- c:\documents and settings\Tommy\PrivacIE
2010-04-22 19:21 . 2010-04-22 19:21 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-04-22 19:21 . 2010-04-22 19:21 -------- d-sh--w- c:\documents and settings\Tommy\IETldCache
2010-04-22 19:18 . 2010-02-25 06:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-04-22 19:18 . 2010-02-25 06:16 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-04-22 19:18 . 2010-02-25 06:16 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-04-22 19:18 . 2010-02-25 06:16 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-04-22 19:18 . 2010-02-25 06:16 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-22 19:18 . 2010-02-25 09:46 11070976 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-04-22 19:18 . 2010-04-24 16:17 -------- d-----w- c:\windows\ie8updates
2010-04-22 19:17 . 2010-02-16 04:50 64000 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-04-22 19:13 . 2010-04-22 19:16 -------- dc-h--w- c:\windows\ie8
2010-04-22 18:39 . 2010-04-22 18:39 360584 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgtdix.sys
2010-04-22 18:39 . 2010-04-22 18:39 28424 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgmfx86.sys
2010-04-22 18:39 . 2010-04-22 18:39 74760 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\UniversalDD.sys
2010-04-22 18:39 . 2010-04-22 18:39 30216 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSFilter.sys
2010-04-22 18:39 . 2010-04-22 18:39 25736 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSShim.sys
2010-04-22 18:39 . 2010-04-22 18:39 25608 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSxx.sys
2010-04-22 18:39 . 2010-04-22 18:39 122376 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSDriver.sys
2010-04-22 18:39 . 2010-04-22 18:39 333192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgldx86.sys
2010-04-22 18:39 . 2010-04-22 18:39 161800 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgrkx86.sys
2010-04-22 18:38 . 2010-04-22 18:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-22 18:25 . 2010-04-22 18:14 1007896 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.exe
2010-04-22 18:25 . 2010-04-22 18:14 1658136 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.dll
2010-04-22 18:25 . 2010-04-22 18:14 613656 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgiproxy.exe
2010-04-22 18:25 . 2010-04-22 18:14 800536 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avginet.dll
2010-04-22 18:15 . 2010-04-22 18:42 -------- d-----w- C:\$AVG
2010-04-22 18:14 . 2010-04-22 18:38 25096 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-04-22 18:14 . 2010-04-22 18:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-04-22 18:13 . 2010-04-22 18:13 -------- d-----w- c:\windows\SxsCaPendDel
2010-04-22 18:07 . 2010-01-25 13:28 3777816 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Temp\AVG\setup.exe
2010-04-22 18:07 . 2010-04-22 18:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Temp
2010-04-22 10:10 . 2008-03-28 08:07 20992 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\languages\compare.exe
2010-04-22 10:10 . 2010-04-22 10:10 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\Convivea
2010-04-22 10:10 . 2009-04-10 16:40 118784 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\x.exe
2010-04-22 10:10 . 2008-03-28 08:02 60928 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\update.exe
2010-04-22 10:10 . 2007-07-11 17:43 24557 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\special.exe
2010-04-22 10:10 . 2003-08-19 03:06 80896 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\x.dll
2010-04-22 10:10 . 2010-04-22 10:10 -------- d-----w- c:\programmi\Bit Che
2010-04-22 09:54 . 2010-05-01 21:36 -------- d-----w- c:\programmi\uTorrent
2010-04-22 09:54 . 2010-04-22 09:54 -------- d-----w- c:\programmi\Conduit
2010-04-22 09:54 . 2010-04-22 09:54 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Conduit
2010-04-22 09:54 . 2010-04-26 18:49 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Softonic-IT
2010-04-22 09:54 . 2010-04-22 10:02 -------- d-----w- c:\programmi\Softonic-IT
2010-04-22 09:53 . 2010-05-02 11:10 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\uTorrent
2010-04-22 09:50 . 2010-04-22 09:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DivX
2010-04-22 08:03 . 2010-04-28 18:14 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Temp
2010-04-22 08:03 . 2010-04-22 08:05 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google
2010-04-22 08:00 . 2010-02-17 12:05 2193664 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-04-22 08:00 . 2010-02-16 19:05 2149888 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-04-22 08:00 . 2010-02-16 19:05 2028032 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-04-22 07:57 . 2008-06-14 17:32 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-04-22 07:57 . 2008-06-14 17:32 272768 ------w- c:\windows\system32\drivers\bthport.sys
2010-04-21 17:57 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-21 15:20 . 2010-04-21 15:20 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Ahead
2010-04-21 15:18 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-04-21 15:17 . 2010-04-21 15:17 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\Ahead
2010-04-21 15:15 . 2010-04-21 15:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2010-04-21 15:15 . 2010-04-21 15:17 -------- d-----w- c:\programmi\File comuni\Ahead
2010-04-21 15:15 . 2010-04-21 15:15 -------- d-----w- c:\programmi\Nero
2010-04-21 15:06 . 2010-04-22 18:38 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-04-21 14:56 . 2010-04-22 18:38 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-21 14:55 . 2010-04-22 18:38 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-21 14:55 . 2010-04-22 18:38 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-21 14:55 . 2010-05-02 10:49 -------- d-----w- c:\windows\system32\drivers\Avg
2010-04-21 14:55 . 2010-04-22 18:14 -------- d-----w- c:\programmi\AVG
2010-04-21 07:55 . 2009-01-07 16:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-04-21 07:55 . 2010-05-01 17:02 -------- d--h--w- c:\windows\$hf_mig$
2010-04-20 18:22 . 2010-04-20 18:22 -------- d-sh--w- c:\documents and settings\Tommy\UserData
2010-04-20 18:08 . 2008-10-21 03:16 465152 ----a-r- c:\windows\system32\drivers\rt73.sys
2010-04-20 18:06 . 2006-05-24 11:36 110592 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\U3\temp\cleanup.exe
2010-04-20 18:05 . 2010-04-20 18:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2010-04-20 17:58 . 2010-04-20 17:58 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Help
2010-04-20 17:52 . 2002-09-12 15:29 6016 ----a-w- c:\windows\system32\ntsim.sys
2010-04-20 17:52 . 2008-04-13 09:45 6272 -c--a-w- c:\windows\system32\dllcache\splitter.sys
2010-04-20 17:52 . 2008-04-13 09:45 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-04-20 17:52 . 2008-04-13 10:17 83072 -c--a-w- c:\windows\system32\dllcache\wdmaud.sys
2010-04-20 17:52 . 2008-04-13 10:17 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2010-04-20 17:49 . 2010-04-20 17:49 -------- d-----w- c:\windows\Drivers
2010-04-20 17:49 . 2010-04-20 17:49 -------- d-----w- c:\programmi\WLAN a+b+g mini-PCI module
2010-04-20 17:47 . 2003-03-26 05:27 59392 ------w- c:\windows\system32\agrsmdel.exe
2010-04-20 17:46 . 2010-04-20 17:46 -------- d-----w- c:\windows\Options
2010-04-20 17:45 . 2010-04-20 17:46 -------- d-----w- c:\programmi\ATI Technologies
2010-04-20 17:45 . 2010-04-20 17:55 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-04-20 17:45 . 2010-04-20 17:49 -------- d-----w- c:\programmi\File comuni\InstallShield
2010-04-20 17:44 . 2010-04-20 17:44 -------- d-----w- c:\documents and settings\Tommy\Bluetooth Software
2010-04-20 17:40 . 2010-04-20 17:40 -------- d-----w- c:\programmi\VIA
2010-04-20 17:40 . 2002-12-27 02:41 26880 ----a-w- c:\windows\system32\drivers\VIAAGP1.SYS
2010-04-20 17:40 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-04-20 17:23 . 2001-08-30 18:41 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-04-20 17:23 . 2001-08-30 18:41 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-04-20 17:23 . 2008-04-13 09:45 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-04-20 17:23 . 2008-04-13 09:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-04-20 17:21 . 2010-04-21 15:09 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\U3
2010-04-20 17:21 . 2008-04-13 09:45 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-24 17:40 . 2004-08-30 20:00 48012 ----a-w- c:\windows\system32\perfc010.dat
2010-04-24 17:40 . 2004-08-30 20:00 345620 ----a-w- c:\windows\system32\perfh010.dat
2010-04-21 19:25 . 2010-04-19 17:35 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-04-20 17:51 . 2010-04-20 17:51 -------- d-----w- c:\programmi\Realtek Sound Manager
2010-04-20 17:51 . 2010-04-20 17:51 -------- d-----w- c:\programmi\AvRack
2010-04-19 17:36 . 2010-04-19 17:36 -------- d-----w- c:\programmi\microsoft frontpage
2010-04-19 17:34 . 2010-04-19 17:34 -------- d-----w- c:\programmi\Servizi in linea
2010-04-19 17:31 . 2010-04-19 17:31 21840 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-10 06:15 . 2008-04-13 17:13 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:16 . 2008-04-13 17:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2008-04-13 10:17 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:05 . 2008-04-13 16:55 2193664 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2008-04-13 18:55 2070528 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-13 17:13 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-13 10:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.

------- Sigcheck -------

[-] 2008-06-20 . 3316C8A8EC07A9D4C0BE10310809A9E5 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e3393495-8103-46a0-8181-270273eddd60}]
2010-03-17 13:45 2355224 ----a-w- c:\programmi\Softonic-IT\tbSoft.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E3393495-8103-46A0-8181-270273EDDD60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"Google Update"="c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2010-04-22 136176]
"uTorrent"="c:\programmi\uTorrent\uTorrent.exe" [2010-05-01 321328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"AGRSMMSG"="AGRSMMSG.exe" [2003-04-01 88267]
"SoundMan"="SOUNDMAN.EXE" [2003-05-14 55296]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-22 18:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [22/04/2010 20.14.47 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [21/04/2010 17.06.43 52872]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [21/04/2010 16.55.59 216200]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [21/04/2010 16.56.04 242896]
R2 avg9emc;AVG E-mail Scanner;c:\programmi\AVG\AVG9\avgemc.exe [22/04/2010 20.38.25 916760]
R2 avg9wd;AVG WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [22/04/2010 20.38.43 308064]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [22/04/2010 20.14.28 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [22/04/2010 20.14.27 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [22/04/2010 20.14.26 26120]
S3 AVGIDSAgent;AVG9IDSAgent;c:\programmi\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [22/04/2010 20.38.30 5888008]
.
Contenuto della cartella 'Scheduled Tasks'

2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-789336058-1202660629-1003Core.job
- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-22 08:03]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-789336058-1202660629-1003UA.job
- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-22 08:03]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://search.conduit.com?SearchSource= ... =CT2530241
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-WGA Agent - c:\windows\system32\mga.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-02 13:11
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2010-05-02 13:13:23
ComboFix-quarantined-files.txt 2010-05-02 11:13

Pre-Run: 72.687.509.504 byte disponibili
Post-Run: 73.504.567.296 byte disponibili

WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 87989AB626458C3BC4F565449B79B2E9