Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
Problema con la connessione
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus
Precedente :: Successivo  
Autore Messaggio
Alvin87
Mortale devoto
Mortale devoto


Registrato: 09/11/08 04:11
Messaggi: 6

MessaggioInviato: 09 Nov 2008 04:16    Oggetto: Problema con la connessione Rispondi citando

Ciao a tutti, sono nuovo del foro ed è un onore per me scrivere qui Laughing
Ma bando alle ciance...Ho un grosso problema con la connessione e perciò mi rivolgo a voi. Da diverso tempo la connessione mi casca spesso e volentieri, lasciandomi però riconnettere tranquillamente dopo 20 o 30 secondi. Il problema è che certi giorni ciò accade anche ogni 5 minuti e non ce la faccio più La cosa curiosa è che, ultimamente, dopo essermi riconnesso si disconnette immediatamente dicen protocollo ppp terminato, cosa che non so cosa vogli dire....

Che ne dite? proviamo a risolvere il problema insieme o mi tocca chiamare quelli di Libero e cazziarli?

Grazie a tutti!
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 09 Nov 2008 19:32    Oggetto: Rispondi citando

Ciao Alvin87 Ciao e benvenuto...
Vediamo se quelli di Libero c'entrano o meno.....ma non credo.

Fai queste operazioni di pulizia:
  • Pulisci i files temporanei con ATF-Cleaner e/o CCleaner
  • Segui le istruzioni di questo topic per usare MBAM.
  • Segui le istruzioni di questo topic per eseguire combofix.
  • Segui le istruzioni di questo topic per postare il log di HiJackThis.
  • Riferisci con un nuovo messaggio in questa discussione dell'esito: se ci sono stati problemi particolari, ecc. ecc. E riporta:
    • Carica il log di MBAM su WikiSend e posta il Forum Link che ti viene assegnato.
    • Carica il log di Combofix su WikiSend e posta il Forum Link che ti viene assegnato.
    • Carica il log di HiJackThis su WikiSend e posta il Forum Link che ti viene assegnato.
Top
Profilo Invia messaggio privato
Alvin87
Mortale devoto
Mortale devoto


Registrato: 09/11/08 04:11
Messaggi: 6

MessaggioInviato: 10 Nov 2008 01:30    Oggetto: Rispondi citando

OK Smile

Grazie mille, faccio tutto o poi rispondo, spero di riuscire entro stasera, al max se ne parla per domani...
Top
Profilo Invia messaggio privato
Alvin87
Mortale devoto
Mortale devoto


Registrato: 09/11/08 04:11
Messaggi: 6

MessaggioInviato: 10 Nov 2008 15:50    Oggetto: Rispondi citando

Allora, tutto fatto. Nessun particolare problema durant il processo, la cosa che mi turba è che nn ho trovato granchè coi 3 programmi, ma giudicate voi Smile
Ah, ho avuto dei problemi con wiki e nn riesco a mettere nulla in linea, posto per ora qui i log completi, poi se magari riesco li uppo sempre su wiki e metto i link, sorry Confused

Log di MBAM
Malwarebytes' Anti-Malware 1.30
Versione del database: 1378
Windows 5.1.2600 Service Pack 2

10/11/2008 14.30.58
mbam-log-2008-11-10 (14-30-58).txt

Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 194076
Tempo trascorso: 54 minute(s), 39 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)



Log di COMBOFIX
ComboFix 08-11-09.01 - Peppalvino 2008-11-10 14:34:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.529 [GMT 1:00]
Eseguito da: d:\documents and settings\Peppalvino\Desktop\ComboFix.exe

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\windows\Downloaded Program Files\setup.inf
d:\windows\IE4 Error Log.txt

.
((((((((((((((((((((((((( Files Creati Da 2008-10-10 al 2008-11-10 )))))))))))))))))))))))))))))))))))
.

2008-11-10 13:30 . 2008-11-10 13:30 142 --a------ d:\windows\system32\spupdsvc.inf
2008-11-10 13:29 . 2008-11-10 13:29 <DIR> d-------- d:\windows\LastGood
2008-11-10 00:26 . 2008-11-10 00:26 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Messenger Plus!
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Windows Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Messenger Plus! Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Circle Developement
2008-11-07 00:24 . 2008-11-10 00:48 <DIR> d-------- d:\programmi\Malwarebytes' Anti-Malware
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-10-22 16:28 38,496 --a------ d:\windows\system32\drivers\mbamswissarmy.sys
2008-11-07 00:24 . 2008-10-22 16:28 15,504 --a------ d:\windows\system32\drivers\mbam.sys
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\programmi\SUPERAntiSpyware
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:27 . 2008-11-06 23:27 <DIR> d-------- d:\programmi\Trend Micro
2008-11-06 23:26 . 2008-11-06 23:26 5,120 --ahs---- d:\windows\system32\Thumbs.db
2008-11-02 15:28 . 2008-11-02 15:30 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SPORE
2008-11-02 13:33 . 2008-11-02 13:33 <DIR> dr-h----- d:\documents and settings\Peppalvino\Dati applicazioni\SecuROM
2008-11-02 13:28 . 2008-11-02 13:28 <DIR> d-------- d:\programmi\Electronic Arts
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\windows\BarTr23
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\programmi\OfficePowerT
2008-10-28 20:48 . 2000-05-22 00:00 647,872 --a------ d:\windows\system32\MSComCt2.ocx
2008-10-28 20:48 . 2000-12-06 00:00 415,176 --a------ d:\windows\system32\Comct332.ocx
2008-10-28 20:48 . 1998-04-25 00:00 368,912 --a------ d:\windows\system32\vbar332.dll
2008-10-28 20:48 . 1998-08-05 00:00 150,528 --a------ d:\windows\system32\MSCmCIT.dll
2008-10-28 20:48 . 2001-03-13 14:49 140,288 --a------ d:\windows\system32\COMDLG32.OCX
2008-10-28 20:48 . 1998-06-24 00:00 137,000 --a------ d:\windows\system32\Msmapi32.ocx
2008-10-28 20:48 . 1998-08-05 00:00 63,488 --a------ d:\windows\system32\MSCc2IT.dll
2008-10-28 20:48 . 1998-08-05 00:00 33,792 --a------ d:\windows\system32\CmDlgIT.dll
2008-10-28 20:48 . 1998-08-05 00:00 28,672 --a------ d:\windows\system32\Cmct3IT.dll
2008-10-22 20:03 . 2008-11-10 13:38 <DIR> d-------- d:\windows\system32\CatRoot_bak
2008-10-22 20:02 . 2008-06-14 18:59 272,768 --------- d:\windows\system32\drivers\bthport.sys
2008-10-22 20:02 . 2008-06-14 18:59 272,768 -----c--- d:\windows\system32\dllcache\bthport.sys
2008-10-22 16:05 . 2008-10-22 16:07 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Spybot - Search & Destroy
2008-10-22 15:12 . 2008-11-09 02:49 <DIR> d-------- D:\VEXPLITE
2008-10-22 15:12 . 2008-11-05 23:02 40,960 --a------ d:\windows\system32\drivers\VIRAGTLT.SYS
2008-10-21 16:40 . 2008-10-21 16:40 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\KONAMI
2008-10-20 00:19 . 2008-10-20 00:19 <DIR> d-------- d:\programmi\Intelore
2008-10-20 00:08 . 2008-10-20 00:08 <DIR> d-------- d:\programmi\ElcomSoft
2008-10-15 23:14 . 2008-10-15 23:14 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SlySoft
2008-10-15 22:42 . 2008-10-17 17:00 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\DivX
2008-10-15 21:59 . 2008-10-15 21:59 <DIR> d-------- d:\programmi\DVDFab 5
2008-10-14 17:30 . 2008-10-14 17:30 <DIR> d-------- d:\programmi\Midway Home Entertainment
2008-10-14 17:18 . 2008-10-14 17:18 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 06:45 --------- d-----w d:\programmi\eMule Applejuice
2008-11-09 16:17 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\uTorrent
2008-11-09 13:32 --------- d-----w d:\programmi\MSN Messenger
2008-11-09 12:27 --------- d---a-w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2008-11-06 22:36 --------- d-----w d:\programmi\File comuni\Wise Installation Wizard
2008-11-02 12:26 --------- d--h--w d:\programmi\InstallShield Installation Information
2008-10-22 15:05 --------- d-----w d:\programmi\DivX
2008-10-22 15:05 --------- d-----w d:\programmi\DAP
2008-10-22 15:05 --------- d-----w d:\programmi\Alcohol Soft
2008-10-21 15:43 107,888 ----a-w d:\windows\system32\CmdLineExt.dll
2008-10-21 15:33 --------- d-----w d:\programmi\KONAMI
2008-10-15 22:24 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\DVD Shrink
2008-10-15 20:59 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Vso
2008-10-15 20:21 --------- d-----w d:\programmi\DVD Shrink
2008-09-30 21:55 --------- d-----w d:\programmi\PokerStars.NET
2008-09-30 21:54 --------- d-----w d:\programmi\Acclaim
2008-09-29 18:45 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Dev-Cpp
2008-09-28 09:06 --------- d-----w d:\programmi\Maxis
2008-09-26 23:05 --------- d-----w d:\programmi\Monte Cristo
2008-09-24 17:50 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\GetRightToGo
2008-09-22 13:14 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\SecondLife
2008-09-20 20:06 --------- d-----w d:\programmi\GiocoDigitale
2008-09-20 20:06 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\GiocoDigitale
2008-09-16 00:14 9,464 ------w d:\windows\system32\drivers\cdralw2k.sys
2008-09-16 00:14 9,336 ------w d:\windows\system32\drivers\cdr4_xp.sys
2008-09-16 00:14 524,288 ----a-w d:\windows\system32\DivXsm.exe
2008-09-16 00:14 43,528 ------w d:\windows\system32\drivers\PxHelp20.sys
2008-09-16 00:14 3,596,288 ----a-w d:\windows\system32\qt-dx331.dll
2008-09-16 00:14 129,784 ------w d:\windows\system32\pxafs.dll
2008-09-16 00:14 120,056 ------w d:\windows\system32\pxcpyi64.exe
2008-09-16 00:14 118,520 ------w d:\windows\system32\pxinsi64.exe
2008-09-16 00:12 81,920 ----a-w d:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w d:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w d:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w d:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w d:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w d:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w d:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w d:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w d:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w d:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w d:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w d:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w d:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w d:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w d:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w d:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w d:\windows\system32\DivXWMPExtType.dll
2008-09-15 15:38 1,846,016 ----a-w d:\windows\system32\win32k.sys
2008-09-11 21:35 --------- d-----w d:\programmi\SpeedSim
2008-09-10 11:34 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft
2008-09-05 22:30 952,360 ------w d:\windows\system32\SETB0.tmp
2008-09-05 22:30 267,304 ------w d:\windows\system32\SETAF.tmp
2008-08-20 05:35 662,016 ----a-w d:\windows\system32\wininet.dll
2008-08-14 13:42 2,139,648 ----a-w d:\windows\system32\ntoskrnl.exe
2008-08-14 13:42 2,019,328 ----a-w d:\windows\system32\ntkrnlpa.exe
2007-12-27 18:56 87,608 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\ezpinst.exe
2007-12-27 18:56 47,360 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\pcouffin.sys
.
Codice:
<pre>
----a-w            79,224 2007-09-06 10:06:09  d:\programmi\Alwil Software\Avast4\ashDisp .exe
----a-r           925,696 2005-05-20 09:11:06  d:\programmi\Analog Devices\Core\smax4pnp .exe
----a-w           153,136 2007-03-01 14:57:24  d:\programmi\File comuni\Nero\Lib\NeroCheck .exe
----a-w           454,144 2007-12-17 14:21:57  d:\programmi\SlySoft\AnyDVD\AnyDVD .exe
----a-w            15,360 2004-08-19 13:39:36  d:\windows\system32\ctfmon .exe
</pre>



((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MsnMsgr"="d:\programmi\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"updateMgr"="d:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Nokia.PCSync"="d:\programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="d:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-06-18 1122816]
"AnyDVD"="d:\programmi\SlySoft\AnyDVD\AnyDVDtray.exe" [N/A]
"SUPERAntiSpyware"="d:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="d:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SunJavaUpdateSched"="d:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NBKeyScan"="d:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"EPSON Stylus Photo R200 Series"="d:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE" [2003-09-11 99840]
"DownloadAccelerator"="d:\programmi\DAP\DAP.EXE" [2007-12-25 4576768]
"SoundMAXPnP"="d:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"QuickTime Task"="d:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"iTunesHelper"="d:\programmi\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"VIRIT LITE MONITOR"="d:\vexplite\MONLITE.EXE" [2008-11-08 249856]
"mirc"="c:\windows\WINCRA\mirc.exe" [N/A]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 d:\windows\system32\HdAShCut.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 d:\windows\system32\stmctrl.dll]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

d:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - d:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
WinZip Quick Pick.lnk - d:\programmi\WinZip\WZQKPICK.EXE [2007-11-09 118784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 d:\programmi\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\uTorrent\\utorrent.exe"=
"d:\\WINDOWS\\system32\\javaw.exe"=
"c:\\File installazione\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\DAP\\DAP.exe"=
"d:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"d:\\Programmi\\MSN Messenger\\livecall.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"d:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"d:\\Programmi\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\iTunes\\iTunes.exe"=
"d:\\Documents and Settings\\Peppalvino\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=

R0 VIRAGTLT;VIRAGTLT;d:\windows\system32\drivers\VIRAGTLT.SYS [2008-11-05 40960]
R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 Stmatm;ATM/ADSL miniport;d:\windows\system32\DRIVERS\stmatm.sys [2002-09-25 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;d:\windows\system32\DRIVERS\torususb.sys [2003-01-09 527980]
S2 viritsvclite;Virit eXplorer Lite;d:\vexplite\viritsvc.exe [2008-11-08 57344]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01933866-a05c-11dd-80e5-a63d096a699a}]
\Shell\Auto\command - H:\UFO.exe
\Shell\AutoRun\command - d:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9910d7b6-9144-11dc-bd7a-fa14b2e46ed4}]
\Shell\Auto\command - H:\UFO.exe
\Shell\AutoRun\command - d:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e24cea-7cee-11dd-8070-a706b2a4527d}]
\Shell\Auto\command - UFO.exe
\Shell\AutoRun\command - d:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe

*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'

2008-10-31 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.
.
------- Supplementare di scansione -------
.
FireFox -: Profile - d:\documents and settings\Peppalvino\Dati applicazioni\Mozilla\Firefox\Profiles\juhf1pjb.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://italian.eazel.com/it/index.php?rvs=hompag&d=79919291
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 14:36:17
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-11-10 14:37:59
ComboFix-quarantined-files.txt 2008-11-10 13:37:04

Pre-Run: 37,076,447,232 byte disponibili
Post-Run: 39,434,362,880 byte disponibili

222 --- E O F --- 2008-11-10 12:31:04




Log di HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14.42.51, on 10/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
D:\Programmi\Alwil Software\Avast4\ashServ.exe
D:\Programmi\Analog Devices\SoundMAX\Smax4.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
D:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
D:\Programmi\Analog Devices\Core\smax4pnp.exe
D:\VEXPLITE\MONLITE.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Programmi\Nokia\Nokia PC Suite 7\PCSync2.exe
D:\Programmi\WinZip\WZQKPICK.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
D:\Programmi\PC Connectivity Solution\ServiceLayer.exe
D:\WINDOWS\system32\WgaTray.exe
D:\Programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
D:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
D:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
D:\Programmi\MSN Messenger\usnsvc.exe
D:\WINDOWS\system32\notepad.exe
D:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\explorer.exe
D:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Programmi\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NBKeyScan] "D:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [DownloadAccelerator] "D:\Programmi\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] D:\VEXPLITE\MONLITE.EXE
O4 - HKLM\..\Run: [mirc] C:\WINDOWS\WINCRA\mirc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] "D:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Nokia.PCSync] "D:\Programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "D:\Programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [AnyDVD] D:\Programmi\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = D:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Clean Traces - D:\Programmi\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - D:\Programmi\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\Programmi\DAP\dapextie2.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: InterCasino Italia - {3543D964-CE64-47E6-B730-152732DAF0E6} - http://italia.intercasino.com/ (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: InterCasino Italia - {3543D964-CE64-47E6-B730-152732DAF0E6} - http://italia.intercasino.com/ (file missing) (HKCU)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: !SASWinLogon - D:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - D:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - D:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - D:\VEXPLITE\viritsvc.exe

--
End of file - 7753 bytes





Ecco qua, che mi dite? Attendo impaziente e intanto inizio a ringraziarvi Very Happy
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 10 Nov 2008 16:08    Oggetto: Rispondi citando

Alvin87 ha scritto:
Allora, tutto fatto. Nessun particolare problema durant il processo, la cosa che mi turba è che nn ho trovato granchè coi 3 programmi, ma giudicate voi Smile

Infatti, non è proprio così;
avete quasi tutti le chiavette/periferiche USB infettate;
I logs, non vanno osservati solo per ciò che eliminano, ma anche su ciò che contengono, in particolare Combofix, se guardi attentamente, c'è il famoso UFO.exe, che non è un oggetto non identificato, ma un virus vero e proprio, che si trasferisce, sui PC, e viceversa, attraverso le chiavette USB.

Dopo queste premessa, iniziamo con la pulizia.
disattiva momentaneamente il riconoscimento automatico delle periferiche USB;
serve il programma TweakUI scaricabile da questa pagina e installalo.
Una volta installato, eseguilo e procedi con questi passaggi:
Citazione:
Espandi la sezione My Computer
Espandi la sottosezione Autoplay
Spostati in Types
Togli il segno di spunta a Enable Autoplay for removable drives
Clicca su Apply
Chiudi TweakUI

PS: Con Espandi intendo: clicca sul simbolo [+] di fianco alle voci che ti ho indicato
Da questo momento tutti gli apparati USB smetteranno di avviarsi automaticamente.
Inserisci le tue chiavette e fai un check delle stesse con il tuo antivirus.
Quando sei sicuro che tutto è a posto, puoi riabilitare l'avvio automatico, rifacendo lo stesso percorso che ti ho indicato.

Adesso crea col blocco note un file di testo mettendoci queste scritte:
Citazione:
RenV::
d:\programmi\Alwil Software\Avast4\ashDisp .exe
d:\programmi\Analog Devices\Core\smax4pnp .exe
d:\programmi\File comuni\Nero\Lib\NeroCheck .exe
d:\programmi\SlySoft\AnyDVD\AnyDVD .exe
d:\windows\system32\ctfmon .exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01933866-a05c-11dd-80e5-a63d096a699a}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9910d7b6-9144-11dc-bd7a-fa14b2e46ed4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e24cea-7cee-11dd-8070-a706b2a4527d}]

Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:

Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro. Wink
Posta il log aggiornato di combofix.
Prova poi a pulire le periferiche USB usando il tool Perlovga Removal Tool
Top
Profilo Invia messaggio privato
Alvin87
Mortale devoto
Mortale devoto


Registrato: 09/11/08 04:11
Messaggi: 6

MessaggioInviato: 10 Nov 2008 16:33    Oggetto: Rispondi citando

Ecco il log, preciso che nn sapevo che riavviasse il pc e purtroppo avevo in esecuzione automatica messenger e antivir che però ho chiuso immediatamente, nn credo abbiano dato problemi....




ComboFix 08-11-09.04 - Peppalvino 2008-11-10 15.20.35.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.517 [GMT 1:00]
Eseguito da: d:\documents and settings\Peppalvino\Desktop\ComboFix.exe
Interruttori di comando utilizzati :: d:\documents and settings\Peppalvino\Desktop\CFScript.txt.txt
* Creato nuovo punto di ripristino

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((( Files Creati Da 2008-10-10 al 2008-11-10 )))))))))))))))))))))))))))))))))))
.

2008-11-10 15:14 . 2003-06-25 16:05 266,360 --a------ d:\windows\system32\TweakUI.exe
2008-11-10 15:14 . 2002-06-21 15:09 160,217 --a------ d:\windows\system32\PowerToysLicense.rtf
2008-11-10 00:26 . 2008-11-10 00:26 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Messenger Plus!
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Windows Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Messenger Plus! Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Circle Developement
2008-11-07 00:24 . 2008-11-10 00:48 <DIR> d-------- d:\programmi\Malwarebytes' Anti-Malware
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-10-22 16:28 38,496 --a------ d:\windows\system32\drivers\mbamswissarmy.sys
2008-11-07 00:24 . 2008-10-22 16:28 15,504 --a------ d:\windows\system32\drivers\mbam.sys
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\programmi\SUPERAntiSpyware
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:27 . 2008-11-06 23:27 <DIR> d-------- d:\programmi\Trend Micro
2008-11-06 23:26 . 2008-11-06 23:26 5,120 --ahs---- d:\windows\system32\Thumbs.db
2008-11-02 15:28 . 2008-11-02 15:30 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SPORE
2008-11-02 13:33 . 2008-11-02 13:33 <DIR> dr-h----- d:\documents and settings\Peppalvino\Dati applicazioni\SecuROM
2008-11-02 13:28 . 2008-11-02 13:28 <DIR> d-------- d:\programmi\Electronic Arts
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\windows\BarTr23
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\programmi\OfficePowerT
2008-10-28 20:48 . 2000-05-22 00:00 647,872 --a------ d:\windows\system32\MSComCt2.ocx
2008-10-28 20:48 . 2000-12-06 00:00 415,176 --a------ d:\windows\system32\Comct332.ocx
2008-10-28 20:48 . 1998-04-25 00:00 368,912 --a------ d:\windows\system32\vbar332.dll
2008-10-28 20:48 . 1998-08-05 00:00 150,528 --a------ d:\windows\system32\MSCmCIT.dll
2008-10-28 20:48 . 2001-03-13 14:49 140,288 --a------ d:\windows\system32\COMDLG32.OCX
2008-10-28 20:48 . 1998-06-24 00:00 137,000 --a------ d:\windows\system32\Msmapi32.ocx
2008-10-28 20:48 . 1998-08-05 00:00 63,488 --a------ d:\windows\system32\MSCc2IT.dll
2008-10-28 20:48 . 1998-08-05 00:00 33,792 --a------ d:\windows\system32\CmDlgIT.dll
2008-10-28 20:48 . 1998-08-05 00:00 28,672 --a------ d:\windows\system32\Cmct3IT.dll
2008-10-22 20:03 . 2008-11-10 15:04 <DIR> d-------- d:\windows\system32\CatRoot_bak
2008-10-22 20:02 . 2008-06-14 18:59 272,768 --------- d:\windows\system32\drivers\bthport.sys
2008-10-22 20:02 . 2008-06-14 18:59 272,768 -----c--- d:\windows\system32\dllcache\bthport.sys
2008-10-22 16:05 . 2008-10-22 16:07 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Spybot - Search & Destroy
2008-10-22 15:12 . 2008-11-09 02:49 <DIR> d-------- D:\VEXPLITE
2008-10-22 15:12 . 2008-11-05 23:02 40,960 --a------ d:\windows\system32\drivers\VIRAGTLT.SYS
2008-10-21 16:40 . 2008-10-21 16:40 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\KONAMI
2008-10-20 00:19 . 2008-10-20 00:19 <DIR> d-------- d:\programmi\Intelore
2008-10-20 00:08 . 2008-10-20 00:08 <DIR> d-------- d:\programmi\ElcomSoft
2008-10-15 23:14 . 2008-10-15 23:14 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SlySoft
2008-10-15 22:42 . 2008-10-17 17:00 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\DivX
2008-10-15 21:59 . 2008-10-15 21:59 <DIR> d-------- d:\programmi\DVDFab 5
2008-10-14 17:30 . 2008-10-14 17:30 <DIR> d-------- d:\programmi\Midway Home Entertainment
2008-10-14 17:18 . 2008-10-14 17:18 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 06:45 --------- d-----w d:\programmi\eMule Applejuice
2008-11-09 16:17 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\uTorrent
2008-11-09 13:32 --------- d-----w d:\programmi\MSN Messenger
2008-11-09 12:27 --------- d---a-w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2008-11-06 22:36 --------- d-----w d:\programmi\File comuni\Wise Installation Wizard
2008-11-02 12:26 --------- d--h--w d:\programmi\InstallShield Installation Information
2008-10-22 15:05 --------- d-----w d:\programmi\DivX
2008-10-22 15:05 --------- d-----w d:\programmi\DAP
2008-10-22 15:05 --------- d-----w d:\programmi\Alcohol Soft
2008-10-21 15:33 --------- d-----w d:\programmi\KONAMI
2008-10-15 22:24 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\DVD Shrink
2008-10-15 20:59 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Vso
2008-10-15 20:21 --------- d-----w d:\programmi\DVD Shrink
2008-09-30 21:55 --------- d-----w d:\programmi\PokerStars.NET
2008-09-30 21:54 --------- d-----w d:\programmi\Acclaim
2008-09-29 18:45 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Dev-Cpp
2008-09-28 09:06 --------- d-----w d:\programmi\Maxis
2008-09-26 23:05 --------- d-----w d:\programmi\Monte Cristo
2008-09-24 17:50 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\GetRightToGo
2008-09-22 13:14 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\SecondLife
2008-09-20 20:06 --------- d-----w d:\programmi\GiocoDigitale
2008-09-20 20:06 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\GiocoDigitale
2008-09-16 00:14 9,464 ------w d:\windows\system32\drivers\cdralw2k.sys
2008-09-16 00:14 9,336 ------w d:\windows\system32\drivers\cdr4_xp.sys
2008-09-16 00:14 43,528 ------w d:\windows\system32\drivers\PxHelp20.sys
2008-09-11 21:35 --------- d-----w d:\programmi\SpeedSim
2008-09-10 11:34 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft
2007-12-27 18:56 87,608 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\ezpinst.exe
2007-12-27 18:56 47,360 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\pcouffin.sys
.
Codice:
<pre>
----a-w            79,224 2007-09-06 10:06:09  d:\programmi\Alwil Software\Avast4\ashDisp .exe
----a-r           925,696 2005-05-20 09:11:06  d:\programmi\Analog Devices\Core\smax4pnp .exe
</pre>



((((((((((((((((((((((((((((( snapshot@2008-11-10_14.36.47.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-03 20:32:22 231,552 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ac97ali.sys
- 2004-08-03 20:32:32 84,480 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ac97via.sys
- 2004-08-03 20:32:24 10,880 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\admjoy.sys
- 2004-08-03 20:31:20 36,224 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\an983.sys
- 2004-08-03 20:29:30 56,623 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1btxx.sys
- 2004-08-03 20:29:30 11,615 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1mdxx.sys
- 2004-08-03 20:29:30 12,047 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1pdxx.sys
- 2004-08-03 20:29:32 30,671 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1raxx.sys
- 2004-08-03 20:29:32 63,663 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1rvxx.sys
- 2004-08-03 20:29:32 26,367 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1snxx.sys
- 2004-08-03 20:29:32 21,343 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1ttxx.sys
- 2004-08-03 20:29:32 36,463 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1tuxx.sys
- 2004-08-03 20:29:32 29,455 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1xbxx.sys
- 2004-08-03 20:29:32 34,735 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1xsxx.sys
- 2004-08-19 13:23:38 327,168 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati2mtaa.sys
- 2004-08-19 13:23:40 701,440 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati2mtag.sys
- 2004-08-03 20:29:28 57,856 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinbtxx.sys
- 2004-08-03 20:29:30 13,824 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinmdxx.sys
- 2004-08-03 20:29:30 14,336 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinpdxx.sys
- 2004-08-03 20:29:30 52,224 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinraxx.sys
- 2004-08-03 20:29:32 104,960 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinrvxx.sys
- 2004-08-03 20:29:32 28,672 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinsnxx.sys
- 2004-08-03 20:29:32 13,824 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinttxx.sys
- 2004-08-03 20:29:32 73,216 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atintuxx.sys
- 2004-08-03 20:29:32 31,744 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinxbxx.sys
- 2004-08-03 20:29:32 63,488 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinxsxx.sys
- 2004-08-03 20:32:26 48,640 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\cwrwdm.sys
- 2004-08-19 13:22:30 121,344 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\epcl5res.dll
- 2004-08-03 20:32:28 137,088 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\essm2e.sys
- 2004-08-03 20:31:24 34,173 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\forehe.sys
- 2004-08-03 20:41:48 220,032 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\hsfbs2s2.sys
- 2004-08-03 20:41:50 685,056 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\hsfcxts2.sys
- 2004-08-03 20:41:56 1,041,536 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\hsfdpsp2.sys
- 2004-08-03 20:29:38 161,020 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\i81xnt5.sys
- 2008-04-13 17:13:42 424,448 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\licdll.dll
- 2004-08-19 13:31:46 607,292 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ltmdmnt.sys
- 2004-08-19 13:31:48 422,272 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ltmdmntt.sys
- 2004-08-03 20:39:32 20,864 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\lwadihid.sys
- 2004-08-03 20:41:56 11,868 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\mdmxsdk.sys
- 2004-08-03 20:41:40 126,686 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\mtlmnt5.sys
- 2004-08-03 20:41:38 1,309,184 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\mtlstrm.sys
- 2004-08-03 20:29:38 452,736 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\mtxparhm.sys
- 2004-08-19 13:33:24 132,695 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\netwlan5.sys
- 2006-12-30 17:27:08 4,569 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\new\secupd.dat
- 2004-08-03 20:41:40 180,360 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ntmtlfax.sys
- 2004-08-03 20:29:56 1,897,408 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\nv4_mini.sys
- 2004-08-03 20:31:24 29,502 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\pca200e.sys
- 2004-08-03 20:06:18 169,984 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\pcx500.sys
- 2004-08-03 20:41:40 13,776 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\recagent.sys
- 2004-08-03 20:31:34 20,992 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\rtl8139.sys
- 2004-08-03 20:29:52 166,912 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\s3gnbm.sys
- 2008-04-13 17:13:50 1,001,472 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\setupapi.dll
- 2004-08-03 20:31:36 32,768 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\sisnic.sys
- 2004-08-03 20:31:42 63,547 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\sla30nd5.sys
- 2004-08-03 20:41:42 129,535 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\slnt7554.sys
- 2004-08-03 20:41:44 404,990 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\slntamr.sys
- 2004-08-03 20:41:46 95,424 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\slnthal.sys
- 2004-08-03 20:41:46 13,240 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\slwdmsup.sys
- 2008-04-13 17:13:52 438,272 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spcompat.dll
- 2007-08-10 06:20:24 18,808 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spmsg.dll
- 2008-04-13 17:14:22 11,264 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spnpinst.exe
- 2007-08-10 06:20:24 33,656 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\sprecovr.exe
- 2007-08-10 06:20:24 233,848 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spuninst.exe
- 2007-08-10 06:20:26 26,488 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spupdsvc.exe
- 2008-04-13 17:14:08 8,192 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\fixccs.exe
- 2008-04-13 17:14:16 6,656 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\nv4prep.exe
- 2008-04-13 17:13:50 1,001,472 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\setupapi.dll
- 2008-04-13 17:13:52 438,272 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\spcompat.dll
- 2007-08-10 06:20:24 26,488 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\spcustom.dll
- 2008-04-13 17:14:22 11,264 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\spnpinst.exe
- 2007-08-10 06:20:26 763,768 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\update.exe
- 2007-08-10 06:20:34 402,296 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\updspapi.dll
- 2004-08-19 13:28:22 32,384 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\usb101et.sys
- 2004-08-03 20:29:38 12,415 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv01nt.sys
- 2004-08-03 20:29:38 12,127 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv02nt.sys
- 2004-08-03 20:29:38 11,775 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv05nt.sys
- 2004-08-03 20:29:40 11,807 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv07nt.sys
- 2004-08-03 20:29:40 11,295 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv08nt.sys
- 2004-08-03 20:29:42 11,871 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv09nt.sys
- 2004-08-03 20:29:42 11,935 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv11nt.sys
- 2004-08-03 20:29:42 29,311 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv01nt.sys
- 2004-08-03 20:29:44 19,551 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv02nt.sys
- 2004-08-03 20:29:44 33,599 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv04nt.sys
- 2004-08-03 20:29:46 22,271 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv06nt.sys
- 2004-08-03 20:29:46 25,471 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv10nt.sys
- 2004-08-03 20:29:46 23,615 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wch7xxnt.sys
- 2004-08-03 20:31:28 154,624 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wlluc48.sys
- 2004-08-03 20:29:48 12,063 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wsiintxx.sys
- 2004-08-03 20:29:50 19,455 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wvchntxx.sys
- 2007-04-10 13:00:54 236,928 ------w d:\windows\system32\WgaLogon.dll
+ 2008-09-05 22:30:52 267,304 ----a-w d:\windows\system32\WgaLogon.dll
- 2007-04-10 13:01:38 337,280 ------w d:\windows\system32\WgaTray.exe
+ 2008-09-05 22:30:06 952,360 ----a-w d:\windows\system32\WgaTray.exe
+ 2008-11-10 14:23:54 16,384 ----atw d:\windows\Temp\Perflib_Perfdata_4e4.dat
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MsnMsgr"="d:\programmi\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"updateMgr"="d:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Nokia.PCSync"="d:\programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="d:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-06-18 1122816]
"AnyDVD"="d:\programmi\SlySoft\AnyDVD\AnyDVDtray.exe" [N/A]
"SUPERAntiSpyware"="d:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="d:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NBKeyScan"="d:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"EPSON Stylus Photo R200 Series"="d:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE" [2003-09-11 99840]
"DownloadAccelerator"="d:\programmi\DAP\DAP.EXE" [2007-12-25 4576768]
"SoundMAXPnP"="d:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"QuickTime Task"="d:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"iTunesHelper"="d:\programmi\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"VIRIT LITE MONITOR"="d:\vexplite\MONLITE.EXE" [2008-11-08 249856]
"mirc"="c:\windows\WINCRA\mirc.exe" [N/A]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 d:\windows\system32\HdAShCut.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 d:\windows\system32\stmctrl.dll]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

d:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - d:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
WinZip Quick Pick.lnk - d:\programmi\WinZip\WZQKPICK.EXE [2007-11-09 118784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 d:\programmi\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\uTorrent\\utorrent.exe"=
"d:\\WINDOWS\\system32\\javaw.exe"=
"c:\\File installazione\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\DAP\\DAP.exe"=
"d:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"d:\\Programmi\\MSN Messenger\\livecall.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"d:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"d:\\Programmi\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\iTunes\\iTunes.exe"=
"d:\\Documents and Settings\\Peppalvino\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=

R0 VIRAGTLT;VIRAGTLT;d:\windows\system32\drivers\VIRAGTLT.SYS [2008-11-05 40960]
R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 viritsvclite;Virit eXplorer Lite;d:\vexplite\viritsvc.exe [2008-11-08 57344]
R3 Stmatm;ATM/ADSL miniport;d:\windows\system32\DRIVERS\stmatm.sys [2002-09-25 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;d:\windows\system32\DRIVERS\torususb.sys [2003-01-09 527980]
.
Contenuto della cartella 'Scheduled Tasks'

2008-10-31 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 15:24:37
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
d:\windows\system32\ati2evxx.exe
d:\windows\system32\ati2evxx.exe
d:\programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
d:\programmi\Alwil Software\Avast4\aswUpdSv.exe
d:\programmi\Alwil Software\Avast4\ashServ.exe
d:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\programmi\Nero\Nero8\Nero BackItUp\NBService.exe
d:\windows\system32\wdfmgr.exe
d:\programmi\Alwil Software\Avast4\ashMaiSv.exe
d:\programmi\Alwil Software\Avast4\ashWebSv.exe
d:\windows\system32\WgaTray.exe
d:\windows\system32\rundll32.exe
d:\programmi\iPod\bin\iPodService.exe
d:\programmi\PC Connectivity Solution\ServiceLayer.exe
d:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
d:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
d:\programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
.
**************************************************************************
.
Ora fine scansione: 2008-11-10 15:30:32 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-11-10 14:30:28
ComboFix2.txt 2008-11-10 13:38:00

Pre-Run: 39.596.707.840 byte disponibili
Post-Run: 39,595,253,760 byte disponibili

292 --- E O F --- 2008-11-10 12:31:04
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 10 Nov 2008 16:44    Oggetto: Rispondi citando

Gran parte dell'operazione è riuscita;

devi rifare l'operazione con questi file, e tieni l'antivirus disattivato:
Citazione:
RenV::
d:\programmi\Alwil Software\Avast4\ashDisp .exe
d:\programmi\Analog Devices\Core\smax4pnp .exe

Inoltre, ho visto che hai due antivirus, così non ha protezione perchè vanno in conflitto; ho visto che possiedi Virit, quindi disinstalla Avast;
quì la discussione su come procedere; oppure installa Avira Antivir, se decidi di non tenere VirIT.
Top
Profilo Invia messaggio privato
Alvin87
Mortale devoto
Mortale devoto


Registrato: 09/11/08 04:11
Messaggi: 6

MessaggioInviato: 10 Nov 2008 17:03    Oggetto: Rispondi citando

Ennesimo log, grazie per la pazienza e per la disponibilità...

ComboFix 08-11-09.04 - Peppalvino 2008-11-10 15:52:15.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.645 [GMT 1:00]
Eseguito da: d:\documents and settings\Peppalvino\Desktop\ComboFix.exe
Interruttori di comando utilizzati :: d:\documents and settings\Peppalvino\Desktop\CFScript.txt
* Creato nuovo punto di ripristino

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((( Files Creati Da 2008-10-10 al 2008-11-10 )))))))))))))))))))))))))))))))))))
.

2008-11-10 15:14 . 2003-06-25 16:05 266,360 --a------ d:\windows\system32\TweakUI.exe
2008-11-10 15:14 . 2002-06-21 15:09 160,217 --a------ d:\windows\system32\PowerToysLicense.rtf
2008-11-10 00:26 . 2008-11-10 00:26 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Messenger Plus!
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Windows Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Messenger Plus! Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Circle Developement
2008-11-07 00:24 . 2008-11-10 00:48 <DIR> d-------- d:\programmi\Malwarebytes' Anti-Malware
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-10-22 16:28 38,496 --a------ d:\windows\system32\drivers\mbamswissarmy.sys
2008-11-07 00:24 . 2008-10-22 16:28 15,504 --a------ d:\windows\system32\drivers\mbam.sys
2008-11-06 23:36 . 2008-11-10 15:47 <DIR> d-------- d:\programmi\SUPERAntiSpyware
2008-11-06 23:36 . 2008-11-10 15:47 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:27 . 2008-11-06 23:27 <DIR> d-------- d:\programmi\Trend Micro
2008-11-06 23:26 . 2008-11-06 23:26 5,120 --ahs---- d:\windows\system32\Thumbs.db
2008-11-02 15:28 . 2008-11-02 15:30 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SPORE
2008-11-02 13:33 . 2008-11-02 13:33 <DIR> dr-h----- d:\documents and settings\Peppalvino\Dati applicazioni\SecuROM
2008-11-02 13:28 . 2008-11-02 13:28 <DIR> d-------- d:\programmi\Electronic Arts
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\windows\BarTr23
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\programmi\OfficePowerT
2008-10-28 20:48 . 2000-05-22 00:00 647,872 --a------ d:\windows\system32\MSComCt2.ocx
2008-10-28 20:48 . 2000-12-06 00:00 415,176 --a------ d:\windows\system32\Comct332.ocx
2008-10-28 20:48 . 1998-04-25 00:00 368,912 --a------ d:\windows\system32\vbar332.dll
2008-10-28 20:48 . 1998-08-05 00:00 150,528 --a------ d:\windows\system32\MSCmCIT.dll
2008-10-28 20:48 . 2001-03-13 14:49 140,288 --a------ d:\windows\system32\COMDLG32.OCX
2008-10-28 20:48 . 1998-06-24 00:00 137,000 --a------ d:\windows\system32\Msmapi32.ocx
2008-10-28 20:48 . 1998-08-05 00:00 63,488 --a------ d:\windows\system32\MSCc2IT.dll
2008-10-28 20:48 . 1998-08-05 00:00 33,792 --a------ d:\windows\system32\CmDlgIT.dll
2008-10-28 20:48 . 1998-08-05 00:00 28,672 --a------ d:\windows\system32\Cmct3IT.dll
2008-10-22 20:03 . 2008-11-10 15:04 <DIR> d-------- d:\windows\system32\CatRoot_bak
2008-10-22 20:02 . 2008-06-14 18:59 272,768 --------- d:\windows\system32\drivers\bthport.sys
2008-10-22 20:02 . 2008-06-14 18:59 272,768 -----c--- d:\windows\system32\dllcache\bthport.sys
2008-10-22 16:05 . 2008-10-22 16:07 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Spybot - Search & Destroy
2008-10-22 15:12 . 2008-11-10 15:55 <DIR> d-------- D:\VEXPLITE
2008-10-22 15:12 . 2008-11-05 23:02 40,960 --a------ d:\windows\system32\drivers\VIRAGTLT.SYS
2008-10-21 16:40 . 2008-10-21 16:40 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\KONAMI
2008-10-20 00:19 . 2008-10-20 00:19 <DIR> d-------- d:\programmi\Intelore
2008-10-20 00:08 . 2008-10-20 00:08 <DIR> d-------- d:\programmi\ElcomSoft
2008-10-15 23:14 . 2008-10-15 23:14 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SlySoft
2008-10-15 22:42 . 2008-10-17 17:00 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\DivX
2008-10-15 21:59 . 2008-10-15 21:59 <DIR> d-------- d:\programmi\DVDFab 5
2008-10-14 17:30 . 2008-10-14 17:30 <DIR> d-------- d:\programmi\Midway Home Entertainment
2008-10-14 17:18 . 2008-10-14 17:18 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 14:51 --------- d-----w d:\programmi\eMule Applejuice
2008-11-10 14:47 --------- d-----w d:\programmi\File comuni\Wise Installation Wizard
2008-11-10 14:26 --------- d---a-w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2008-11-09 16:17 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\uTorrent
2008-11-09 13:32 --------- d-----w d:\programmi\MSN Messenger
2008-11-02 12:26 --------- d--h--w d:\programmi\InstallShield Installation Information
2008-10-22 15:05 --------- d-----w d:\programmi\DivX
2008-10-22 15:05 --------- d-----w d:\programmi\DAP
2008-10-22 15:05 --------- d-----w d:\programmi\Alcohol Soft
2008-10-21 15:33 --------- d-----w d:\programmi\KONAMI
2008-10-15 22:24 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\DVD Shrink
2008-10-15 20:59 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Vso
2008-10-15 20:21 --------- d-----w d:\programmi\DVD Shrink
2008-09-30 21:55 --------- d-----w d:\programmi\PokerStars.NET
2008-09-30 21:54 --------- d-----w d:\programmi\Acclaim
2008-09-29 18:45 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Dev-Cpp
2008-09-28 09:06 --------- d-----w d:\programmi\Maxis
2008-09-26 23:05 --------- d-----w d:\programmi\Monte Cristo
2008-09-24 17:50 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\GetRightToGo
2008-09-22 13:14 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\SecondLife
2008-09-20 20:06 --------- d-----w d:\programmi\GiocoDigitale
2008-09-20 20:06 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\GiocoDigitale
2008-09-16 00:14 9,464 ------w d:\windows\system32\drivers\cdralw2k.sys
2008-09-16 00:14 9,336 ------w d:\windows\system32\drivers\cdr4_xp.sys
2008-09-16 00:14 43,528 ------w d:\windows\system32\drivers\PxHelp20.sys
2008-09-11 21:35 --------- d-----w d:\programmi\SpeedSim
2008-09-10 11:34 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft
2007-12-27 18:56 87,608 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\ezpinst.exe
2007-12-27 18:56 47,360 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\pcouffin.sys
.
Codice:
<pre>
----a-w            79,224 2007-09-06 10:06:09  d:\programmi\Alwil Software\Avast4\ashDisp .exe
----a-r           925,696 2005-05-20 09:11:06  d:\programmi\Analog Devices\Core\smax4pnp .exe
</pre>



((((((((((((((((((((((((((((( snapshot_2008-11-10_15.30.10.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-10 14:55:21 16,384 ----atw d:\windows\Temp\Perflib_Perfdata_4ec.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MsnMsgr"="d:\programmi\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"updateMgr"="d:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Nokia.PCSync"="d:\programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="d:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-06-18 1122816]
"AnyDVD"="d:\programmi\SlySoft\AnyDVD\AnyDVDtray.exe" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="d:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NBKeyScan"="d:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"EPSON Stylus Photo R200 Series"="d:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE" [2003-09-11 99840]
"DownloadAccelerator"="d:\programmi\DAP\DAP.EXE" [2007-12-25 4576768]
"SoundMAXPnP"="d:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"QuickTime Task"="d:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"iTunesHelper"="d:\programmi\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"mirc"="c:\windows\WINCRA\mirc.exe" [N/A]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 d:\windows\system32\HdAShCut.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 d:\windows\system32\stmctrl.dll]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

d:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - d:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
WinZip Quick Pick.lnk - d:\programmi\WinZip\WZQKPICK.EXE [2007-11-09 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\uTorrent\\utorrent.exe"=
"d:\\WINDOWS\\system32\\javaw.exe"=
"c:\\File installazione\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\DAP\\DAP.exe"=
"d:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"d:\\Programmi\\MSN Messenger\\livecall.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"d:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"d:\\Programmi\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\iTunes\\iTunes.exe"=
"d:\\Documents and Settings\\Peppalvino\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=

R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 Stmatm;ATM/ADSL miniport;d:\windows\system32\DRIVERS\stmatm.sys [2002-09-25 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;d:\windows\system32\DRIVERS\torususb.sys [2003-01-09 527980]
.
Contenuto della cartella 'Scheduled Tasks'

2008-10-31 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 15:56:55
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
d:\windows\system32\ati2evxx.exe
d:\windows\system32\ati2evxx.exe
d:\programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
d:\programmi\Alwil Software\Avast4\aswUpdSv.exe
d:\programmi\Alwil Software\Avast4\ashServ.exe
d:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\programmi\Nero\Nero8\Nero BackItUp\NBService.exe
d:\windows\system32\wdfmgr.exe
d:\programmi\Alwil Software\Avast4\ashMaiSv.exe
d:\programmi\Alwil Software\Avast4\ashWebSv.exe
d:\windows\system32\WgaTray.exe
d:\windows\system32\rundll32.exe
d:\programmi\iPod\bin\iPodService.exe
d:\programmi\PC Connectivity Solution\ServiceLayer.exe
d:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
d:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
d:\programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
.
**************************************************************************
.
Ora fine scansione: 2008-11-10 16:02:03 - macchina è stato riavviato [Peppalvino]
ComboFix-quarantined-files.txt 2008-11-10 15:01:59
ComboFix2.txt 2008-11-10 14:30:33
ComboFix3.txt 2008-11-10 13:38:00

Pre-Run: 39,534,006,272 byte disponibili
Post-Run: 39,536,656,384 byte disponibili

190 --- E O F --- 2008-11-10 12:31:04
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 10 Nov 2008 23:37    Oggetto: Rispondi citando

Fai la Scansione con FindAWF e posta poi il log generato.
Top
Profilo Invia messaggio privato
Alvin87
Mortale devoto
Mortale devoto


Registrato: 09/11/08 04:11
Messaggi: 6

MessaggioInviato: 12 Nov 2008 02:17    Oggetto: Rispondi citando

Sante62 ha scritto:
Fai la Scansione con FindAWF e posta poi il log generato.


Ehm...Mi dice che il topic cercato nn esiste Sad

Cmq se può interessare il problema è scomparso e lo posso confermare, ho avuto il PC connesso per 26 ore Laughing

Sante sei il mio nuovo Dio 8)
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 12 Nov 2008 10:39    Oggetto: Rispondi

OK, però ti consiglio di scaricare e fare la scasnione con KASPERSKY VIRUS REMOVAL TOOL: clicca qui per il download
Compatibilita: Windows XP

scarica la versione del tool più aggiornata rispetto alla data ed ora di pubblicazione

Installa KASPERSKY VIRUS REMOVAL TOOL:
verrà creata una apposta cartella sul Desktop
all?interno della cartella è presente la classica icona (una K) di Kaspersky
clicca sull?icona per lanciare il tool
imposta le aree che intendi scansionare (Startup Objects e Disk boot sector sono impostate di default)
al termine della scansione sarà possibile rimuovere e/o mettere in quarantena i file infetti rilevati
salva il log che verrà rilasciato

Nota 1: Il tool è incompatibile se si hanno già prodotti Kaspersky installati
Nota 2: non possiede una funzione di aggiornamento automatico delle firme.
Perchè ancora c'è qualcosa che non è stata sistemata...e cioè Avast "corrotto".
Top
Profilo Invia messaggio privato
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus Tutti i fusi orari sono GMT + 2 ore
Pagina 1 di 1

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi