

Comincia a pulire l'interno del pc dalla polvere, provare a staccare le ram magari provandone una alla volta se ne hai due, vedi se poi cambia qualcosa
ComboFix 10-07-09.02 - nomeutente 10/07/2010 17.94.02.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.512.283 [GMT 2:00]
Eseguito da: c:\documents and settings\nomeutente\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\WinPCap
c:\programmi\WinPCap\daemon_mgm.exe
c:\programmi\WinPCap\INSTALL.LOG
c:\programmi\WinPCap\NetMonInstaller.exe
c:\programmi\WinPCap\npf_mgm.exe
c:\programmi\WinPCap\rpcapd.exe
c:\programmi\WinPCap\Uninstall.exe
c:\windows\start.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Creati Da 2010-06-10 al 2010-07-10 )))))))))))))))))))))))))))))))))))
.
2010-07-10 14:48 . 2010-07-10 14:47 398336 ----a-w- c:\windows\system32\CF14214.exe
2010-06-19 17:04 . 2010-05-06 10:32 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-10 15:07 . 2008-10-03 13:46 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-07-10 15:04 . 2009-05-23 11:08 -------- d-----w- c:\documents and settings\JESSICA\Dati applicazioni\WTablet
2010-07-10 14:38 . 2010-03-14 23:04 -------- d-----w- c:\programmi\Crawler
2010-07-04 11:57 . 2008-11-17 16:06 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Bluetooth
2010-06-30 16:45 . 2003-04-08 12:00 79292 ----a-w- c:\windows\system32\perfc010.dat
2010-06-30 16:45 . 2003-04-08 12:00 478808 ----a-w- c:\windows\system32\perfh010.dat
2010-06-06 14:00 . 2009-02-20 12:23 -------- d-----w- c:\programmi\PokerStars.IT
2010-05-30 17:16 . 2009-02-09 09:58 -------- d-----w- c:\programmi\Full Tilt Poker
2010-05-25 17:09 . 2010-05-25 17:09 503808 ----a-w- c:\documents and settings\JESSICA\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-65ca6979-n\msvcp71.dll
2010-05-25 17:09 . 2010-05-25 17:09 499712 ----a-w- c:\documents and settings\JESSICA\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-65ca6979-n\jmc.dll
2010-05-25 17:09 . 2010-05-25 17:09 61440 ----a-w- c:\documents and settings\JESSICA\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6ed7bce7-n\decora-sse.dll
2010-05-25 17:09 . 2010-05-25 17:09 348160 ----a-w- c:\documents and settings\JESSICA\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-65ca6979-n\msvcr71.dll
2010-05-25 17:09 . 2010-05-25 17:09 12800 ----a-w- c:\documents and settings\JESSICA\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6ed7bce7-n\decora-d3d.dll
2010-05-20 14:56 . 2009-03-06 09:37 -------- d-----w- c:\programmi\Google
2010-05-20 14:44 . 2004-11-07 22:40 -------- d-----w- c:\programmi\File comuni\Adobe
2010-05-20 14:13 . 2009-03-08 10:16 -------- d-----w- c:\programmi\CCleaner
2010-05-17 22:35 . 2010-05-17 22:35 -------- d-----w- c:\programmi\Veoh Networks
2010-05-17 17:35 . 2010-05-17 17:35 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\WTablet
2010-05-17 14:07 . 2005-01-02 13:42 26000 ----a-w- c:\documents and settings\JESSICA\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-05-17 14:06 . 2010-05-17 14:06 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\FLEXnet
2010-05-17 13:40 . 2010-05-17 13:40 -------- d-----w- c:\programmi\Adobe Media Player
2010-05-12 17:04 . 2009-01-09 15:40 -------- d-----w- c:\programmi\Java
2010-05-06 10:32 . 2006-06-23 11:28 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:06 . 2003-04-08 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2003-04-08 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-12 15:29 . 2010-05-12 17:04 411368 ----a-w- c:\windows\system32\deployJava1.dll
2009-03-02 21:48 . 2009-03-02 21:48 311287 ----a-w- c:\programmi\uploader.zip
2009-03-02 21:47 . 2009-03-02 21:47 870066 ----a-w- c:\programmi\SoftickPPP234-en.zip
2005-01-02 13:19 . 2005-01-02 13:19 261 ---ha-w- c:\programmi\hpothb07.tif
2005-01-02 13:19 . 2005-01-02 13:19 148 ---ha-w- c:\programmi\hpothb07.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2008-10-01 07:40 192960 ------w- c:\programmi\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^hp psc 1000 series.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\hp psc 1000 series.lnk
backup=c:\windows\pss\hp psc 1000 series.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^hpoddt01.exe.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^JESSICA^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma.lnk]
path=c:\documents and settings\JESSICA\Menu Avvio\Programmi\Esecuzione automatica\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-15 17:07 141608 ----a-w- c:\programmi\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [10/03/2009 13.04.28 159600]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmi\Avira\AntiVir Desktop\sched.exe [24/02/2010 15.42.31 108289]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [10/03/2009 13.04.29 73840]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [23/05/2009 13.07.16 1373480]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [10/03/2009 13.03.37 95640]
R3 Tunx00;FunTV Video Capture;c:\windows\system32\drivers\Tunx00.sys [08/11/2004 0.35.30 302720]
R3 TxTuner;FunTV TV Tuner;c:\windows\system32\drivers\TxTuner.sys [13/11/2004 12.48.09 26880]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [25/02/2010 3.04.01 135664]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\programmi\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 14.49.20 227232]
.
Contenuto della cartella 'Scheduled Tasks'
2006-04-03 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1100 series5E771253C1676EBED677BF361FDFC537825E15B8100293262.job
- c:\programmi\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
2010-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-25 01:03]
2010-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-02-25 01:03]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://it.msn.com
uInternet Settings,ProxyServer = <local>
uInternet Settings,ProxyOverride = <local>;*.local
IE: Blocca informazioni personali da questo sito - file://c:\programmi\GhostSurf\info.block.html
IE: Blocca popups in questo sito - file://c:\programmi\GhostSurf\popup.block.html
IE: Blocca questa pubblicità - file://c:\programmi\GhostSurf\menu.blockimg.html
IE: Crawler Search - tbr:iemenu
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Permetti alle informazioni personali di raggiungere questo sito - file://c:\programmi\GhostSurf\info.allow.html
IE: Permetti popups in questo sito - file://c:\programmi\GhostSurf\popup.allow.html
IE: Permetti questa pubblicità - file://c:\programmi\GhostSurf\menu.allowimg.html
IE: {{4B21E152-BA59-4ebf-B522-8C55B265EE1A} - c:\programmi\PartyItalia\PartyPokerIt\RunApp.exe
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\programmi\PokerStars.IT\PokerStarsUpdate.exe
TCP: {15176DD8-9E80-459C-9F94-7CE3C257A2D5} = 192.168.1.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\programmi\Crawler\ctbr.dll
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\JESSICA\Dati applicazioni\Mozilla\Firefox\Profiles\1jkgijvz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=it-IT&FORM=MICIW1&q=
FF - component: c:\programmi\Crawler\firefox\components\xcomm.dll
FF - component: c:\programmi\Crawler\firefox\components\xshared.dll
FF - component: c:\programmi\Crawler\firefox\components\xsupport.dll
FF - component: c:\programmi\Crawler\firefox\components\xwsg.dll
FF - plugin: c:\programmi\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
MSConfigStartUp-SoftickPPP - c:\programmi\Softick\PPP\Bin\PPPGate.exe
AddRemove-Virgin Poker - c:\poker\Virgin Poker\_SetupPoker.exe_a12148.exe
AddRemove-WinPcapInst - c:\programmi\WinPcap\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-10 17:06
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2656)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\PC Tools Firewall Plus\FWService.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2010-07-10 17:17:25 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-07-10 15:17
Pre-Run: 45.102.333.952 byte disponibili
Post-Run: 45.285.527.552 byte disponibili
- - End Of File - - C15BDE0B51A1168E5B545CECBF79A0E9


) mettiamo un po' d'ordine a questo argomento?
Regolamento
, ok? ![Smile [:)]](http://www.megalab.it/forum/images/smilies/smile.gif)
), ma fin d'ora posso suggerirti di disattivare la creazione dei punti di ripristino sul tuo elaboratore, riavviare tutto, ripetere la scansione, dire ad Avira di rimuovere quello che ha trovato, fare una ulteriore scansione e postare nuovamente il log.



onekef ha scritto:ho disattivato il ripristino di configurazione di sistema e gia penso di aver sbagliato,è la stessa cosa? mi avete detto di disattivare la creazione dei punti di ripristino.

onekef ha scritto:scusate ancora



Visitano il forum: Nessuno e 5 ospiti
megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising