| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| mr brown Eroe
 
  
 
 Registrato: 25/04/07 10:29
 Messaggi: 42
 Residenza: desktop
 
 | 
			
				|  Inviato: 25 Apr 2007 19:03    Oggetto: svchost??? |   |  
				| 
 |  
				| ciao ragazzi mi sono da poco registrato su questo sito xkè ho notato che c'è gente molto competente. Il mio pc ha dei problemi: il primo è che ogni tanto c'è il file system svchost che mi occupa tutta la cpu per diversi minuti ed è moolto fastidioso oltre che nn so il xkè...e inoltre ogni volta che avvio (windows xp) mi compare questo messaggio: 
 "errore durante il caricamento di c:\WINDOWS\sistem32\pyrcimvq.dll
 impossibile trovare il modulo specificato"
 chi m i sa dire come risolvere questi problemi?please help me!
 |  |  
		| Top |  |  
		|  |  
		| Cybion Dio maturo
 
  
  
 Registrato: 11/03/07 15:27
 Messaggi: 1731
 Residenza: vagabonda senza fissa dimora
 
 | 
			
				|  Inviato: 25 Apr 2007 19:48    Oggetto: |   |  
				| 
 |  
				| Ciao, mr brown, benvenuto!!   
 Innanzitutto posta qui un log di HiJackThis: se non hai già il programma puoi scaricarlo da qui
 
 Estrai il contenuto del file zippato in una cartella permanente, non cartelle temporanee o sul desktop, perchè il programma crea una cartella di backup delle chiavi eliminate e non potrebbe farlo oppure si correrebbe il rischio di cancellazione, se installato in cartelle temporanee!!!
 
 Poi procedi come segue:
 1. Chiudi tutte le applicazioni aperte
 2. Avvia HiJackThis
 3. Clicca su DO A SYSTEM SCAN AND SAVE LOGFILE
 4. Attendi che finisca la scansione e che si apra in automatico un foglio di blocco note (il logfile appunto)
 5. Copia TUTTO il contenuto del logfile.
 6. Incolla qui di seguito il log così ottenuto
 |  |  
		| Top |  |  
		|  |  
		| mr brown Eroe
 
  
 
 Registrato: 25/04/07 10:29
 Messaggi: 42
 Residenza: desktop
 
 | 
			
				|  Inviato: 25 Apr 2007 20:13    Oggetto: ecco hijackthis |   |  
				| 
 |  
				| Logfile of HijackThis v1.99.1 Scan saved at 20.10.35, on 25/04/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Ahead\InCD\InCDsrv.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\cisvc.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Eset\nod32krn.exe
 C:\WINDOWS\system32\slserv.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\QuickTime\bak\qttask.exe
 C:\Programmi\Eset\nod32kui.exe
 C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\WINDOWS\system32\cidaemon.exe
 C:\WINDOWS\system32\cidaemon.exe
 C:\hijackthis_199\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar4.dll
 O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\bak\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\pyrcimvq.dll",setvm
 O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [NBJ] "C:\Programmi\Ahead\Nero BackItUp\NBJ.exe"
 O4 - HKCU\..\Run: [E06IXLRD_211624] "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE" -m
 O4 - HKCU\..\Run: [ssesso] C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe t
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [YAW starten] "c:\programmi\yaw 3.5\fast.exe"
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
 O9 - Extra button: ssesso - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: Yahoo! Poker - http://download2.games.yahoo.com/games/clients/y/pt3_x.cab
 O16 - DPF: Yahoo! Pool 2 - http://download2.games.yahoo.com/games/clients/y/poti_x.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FB5C4B17-710A-4C74-A2AB-EA51DC3213F1}: NameServer = 85.37.17.11 85.38.28.69
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
 O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Programmi\Eset\nod32krn.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
 
 ecco il log...spero riusciate a trovare il problema
 |  |  
		| Top |  |  
		|  |  
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 25 Apr 2007 20:37    Oggetto: |   |  
				| 
 |  
				| ciao. benvenuto anche dalla parte mia!   
 hai qualche problemino... 8)
 
 scarica questo tool di rimozione.
 avvialo
 seleziona Scan for Vundo
 finito lo scan scegli Remove Vundo
 conferma e riavvia.
 
 posta qui il log di VundoFix e uno aggiornato di HiJack
 |  |  
		| Top |  |  
		|  |  
		| mr brown Eroe
 
  
 
 Registrato: 25/04/07 10:29
 Messaggi: 42
 Residenza: desktop
 
 | 
			
				|  Inviato: 25 Apr 2007 21:50    Oggetto: per orange |   |  
				| 
 |  
				| orange ho seguito il tuo consiglio,ho avviato vundofix,ma è normale che da un ora ancora non ha finito?ma a cosa serve effettivamente questo vundo? |  |  
		| Top |  |  
		|  |  
		| holifay Dio maturo
 
  
  
 Registrato: 08/03/05 10:48
 Messaggi: 2912
 Residenza: Milano
 
 | 
			
				|  Inviato: 25 Apr 2007 22:02    Oggetto: Re: per orange |   |  
				| 
 |  
				|  	  | mr brown ha scritto: |  	  | orange ho seguito il tuo consiglio,ho avviato vundofix,ma è normale che da un ora ancora non ha finito?ma a cosa serve effettivamente questo vundo? | 
 
 direi proprio di no
  ma lavora l'hard disk o è impallato? |  |  
		| Top |  |  
		|  |  
		| mr brown Eroe
 
  
 
 Registrato: 25/04/07 10:29
 Messaggi: 42
 Residenza: desktop
 
 | 
			
				|  Inviato: 25 Apr 2007 22:11    Oggetto: per holify |   |  
				| 
 |  
				| si lavora lavora,anche se da un pò di minuti è fermo sullo stesso file... |  |  
		| Top |  |  
		|  |  
		| mr brown Eroe
 
  
 
 Registrato: 25/04/07 10:29
 Messaggi: 42
 Residenza: desktop
 
 | 
			
				|  Inviato: 25 Apr 2007 22:46    Oggetto: ecco i logs |   |  
				| 
 |  
				| Logfile of HijackThis v1.99.1 Scan saved at 22.43.53, on 25/04/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Ahead\InCD\InCDsrv.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\cisvc.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Eset\nod32krn.exe
 C:\WINDOWS\system32\slserv.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\QuickTime\bak\qttask.exe
 C:\Programmi\Eset\nod32kui.exe
 C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\hijackthis_199\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\iccufbux.dll
 O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O2 - BHO: (no name) - {4A445D21-252C-4820-80EB-24B63D964D68} - C:\WINDOWS\system32\monjttsa.dll (file missing)
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar4.dll
 O2 - BHO: (no name) - {B5457B55-99C0-47A1-8DE9-48570007C4FF} - C:\WINDOWS\system32\vtusp.dll (file missing)
 O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar4.dll
 O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\bak\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\pyrcimvq.dll",setvm
 O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [NBJ] "C:\Programmi\Ahead\Nero BackItUp\NBJ.exe"
 O4 - HKCU\..\Run: [E06IXLRD_211624] "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE" -m
 O4 - HKCU\..\Run: [ssesso] C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe t
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [YAW starten] "c:\programmi\yaw 3.5\fast.exe"
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
 O9 - Extra button: ssesso - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: Yahoo! Poker - http://download2.games.yahoo.com/games/clients/y/pt3_x.cab
 O16 - DPF: Yahoo! Pool 2 - http://download2.games.yahoo.com/games/clients/y/poti_x.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FB5C4B17-710A-4C74-A2AB-EA51DC3213F1}: NameServer = 85.37.17.11 85.38.28.69
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
 O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Programmi\Eset\nod32krn.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
 
 
 ecco ora quello di vundo
 VundoFix V6.3.20
 
 Checking Java version...
 
 Sun Java not detected
 Scan started at 20.55.03 25/04/2007
 
 Listing files found while scanning....
 
 C:\WINDOWS\system32\byxwwxv.dll
 C:\WINDOWS\system32\efcaaxu.dll
 C:\WINDOWS\system32\innnaobd.dll
 C:\WINDOWS\system32\mkfcspve.dll
 C:\WINDOWS\system32\psutv.ini
 C:\WINDOWS\system32\psutv.ini2
 C:\WINDOWS\system32\psutv.tmp
 C:\WINDOWS\system32\tuvstsq.dll
 C:\WINDOWS\system32\vtusp.dll
 C:\WINDOWS\system32\wigxskdq.dll
 C:\WINDOWS\system32\xxyvtqp.dll
 
 Beginning removal...
 
 Beginning removal...
 
 Attempting to delete C:\WINDOWS\system32\byxwwxv.dll
 C:\WINDOWS\system32\byxwwxv.dll Could not be deleted.
 
 Attempting to delete C:\WINDOWS\system32\efcaaxu.dll
 C:\WINDOWS\system32\efcaaxu.dll Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\psutv.ini
 C:\WINDOWS\system32\psutv.ini Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\psutv.ini2
 C:\WINDOWS\system32\psutv.ini2 Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\psutv.tmp
 C:\WINDOWS\system32\psutv.tmp Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\tuvstsq.dll
 C:\WINDOWS\system32\tuvstsq.dll Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\vtusp.dll
 C:\WINDOWS\system32\vtusp.dll Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\xxyvtqp.dll
 C:\WINDOWS\system32\xxyvtqp.dll Has been deleted!
 
 Performing Repairs to the registry.
 Done!
 
 e ora ragazzi?che si fa?
 |  |  
		| Top |  |  
		|  |  
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 26 Apr 2007 08:21    Oggetto: Re: per orange |   |  
				| 
 |  
				|  	  | mr brown ha scritto: |  	  | ma a cosa serve effettivamente questo vundo? | 
 dato che  Vundo è un trojan, direi che non ti serve a niente...
     
 VundoFix ha eliminato parecchie cose, tranne quella che speravo che eliminasse...
 prova a fare lo scan con quest'altro di Symantec.
 
 Da Installazione Applicazioni disinstalla MyGlobalSearch
 
 Disattiva il ripristino di configurazione del sistema
 Avvia in modalità provvisoria
 avvia HiJack
 seleziona "Do a system scan only"
 metti la spunta alle voci indicate e premi "Fix checked"
 
 O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\iccufbux.dll
 O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O2 - BHO: (no name) - {4A445D21-252C-4820-80EB-24B63D964D68} - C:\WINDOWS\system32\monjttsa.dll (file missing)
 O2 - BHO: (no name) - {B5457B55-99C0-47A1-8DE9-48570007C4FF} - C:\WINDOWS\system32\vtusp.dll (file missing)
 O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\pyrcimvq.dll",setvm
 O4 - HKCU\..\Run: [ssesso] C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe t
 O9 - Extra button: ssesso - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe (file missing)
 
 scarica CCleaner e dai una ripulita generale (prima vai in Opzioni/Avanzate e togli la spunta da "cancella files temp di windows solo se più vecchi di 48 ore"
 
 posta il log di FixVundo e uno aggiornato di HiJack
 |  |  
		| Top |  |  
		|  |  
		| Blacks84 Dio maturo
 
  
  
 Registrato: 26/04/07 14:50
 Messaggi: 2446
 Residenza: Nelpaese bagnato da tre mari e prosciugato da Tremonti
 
 | 
			
				|  Inviato: 26 Apr 2007 17:32    Oggetto: |   |  
				| 
 |  
				| ciao a tutti....anch'io ho lo stesso problema con svchost per i primi 10minuti all'avvio mi occupa tutto il pc non permettendomi di farli fare nient'altro.....vi posto il risultato di hijackthis 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 15.14.12, on 26/04/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\F-Secure\Anti-Virus\fsgk32st.exe
 C:\Programmi\F-Secure\Anti-Virus\FSGK32.EXE
 C:\Programmi\F-Secure\Common\FSMA32.EXE
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\F-Secure\Common\FSMB32.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\F-Secure\Common\FCH32.EXE
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\Programmi\F-Secure\Common\FAMEH32.EXE
 C:\Programmi\F-Secure\Anti-Virus\fsqh.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\F-Secure\FSAUA\program\fsaua.exe
 C:\Programmi\F-Secure\Anti-Virus\fssm32.exe
 C:\Programmi\F-Secure\FWES\Program\fsdfwd.exe
 C:\Programmi\PCI Audio Applications\Bin\EchoCtrl.exe
 C:\WINDOWS\Mixer.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Java\jre1.5.0_03\bin\jusched.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\F-Secure\Common\FSM32.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\File comuni\Teleca Shared\Generic.exe
 C:\Programmi\F-Secure\Anti-Virus\fsav32.exe
 C:\Programmi\F-Secure\FSGUI\fsguidll.exe
 C:\Programmi\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
 C:\Programmi\Mozilla Firefox\firefox.exe
 C:\hijackthis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.emurayden.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [C-Media Echo Control] C:\Programmi\PCI Audio Applications\Bin\EchoCtrl.exe
 O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
 O4 - HKLM\..\Run: [SpywareBot] C:\Programmi\SpywareBot\SpywareBot.exe -boot
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programmi\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
 O4 - HKLM\..\Run: [Emurayden PSX Emulator] c:\Program Files\Emurayden PSX Emulator v2.1\Emurayden PSX AutoLauncher.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_03\bin\jusched.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
 O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programmi\F-Secure\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programmi\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [SpywareBot] C:\Programmi\SpywareBot\SpywareBot.exe -boot
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart16.exe
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O10 - Unknown file in Winsock LSP: c:\programmi\f-secure\fsps\program\fslsp.dll
 O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5014/mcfscan.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{38D54BC1-02C0-455D-AB52-F221D440F68A}: NameServer = 193.70.152.15 193.70.152.25
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
 O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
 O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Programmi\F-Secure\Anti-Virus\fsgk32st.exe
 O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Programmi\F-Secure\FSAUA\program\fsaua.exe
 O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Programmi\F-Secure\FWES\Program\fsdfwd.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Programmi\F-Secure\Common\FSMA32.EXE
 
 ecco fatto.....
 rimango in attesa di vostra risposta
 |  |  
		| Top |  |  
		|  |  
		| mr brown Eroe
 
  
 
 Registrato: 25/04/07 10:29
 Messaggi: 42
 Residenza: desktop
 
 | 
			
				|  Inviato: 27 Apr 2007 17:55    Oggetto: Re: per orange |   |  
				| 
 |  
				|  	  | Orange ha scritto: |  	  |  	  | mr brown ha scritto: |  	  | ma a cosa serve effettivamente questo vundo? | 
 dato che  Vundo è un trojan, direi che non ti serve a niente...
     
 VundoFix ha eliminato parecchie cose, tranne quella che speravo che eliminasse...
 prova a fare lo scan con quest'altro di Symantec.
 
 Da Installazione Applicazioni disinstalla MyGlobalSearch
 
 Disattiva il ripristino di configurazione del sistema
 Avvia in modalità provvisoria
 avvia HiJack
 seleziona "Do a system scan only"
 metti la spunta alle voci indicate e premi "Fix checked"
 
 O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\iccufbux.dll
 O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O2 - BHO: (no name) - {4A445D21-252C-4820-80EB-24B63D964D68} - C:\WINDOWS\system32\monjttsa.dll (file missing)
 O2 - BHO: (no name) - {B5457B55-99C0-47A1-8DE9-48570007C4FF} - C:\WINDOWS\system32\vtusp.dll (file missing)
 O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\pyrcimvq.dll",setvm
 O4 - HKCU\..\Run: [ssesso] C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe t
 O9 - Extra button: ssesso - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe (file missing)
 
 scarica CCleaner e dai una ripulita generale (prima vai in Opzioni/Avanzate e togli la spunta da "cancella files temp di windows solo se più vecchi di 48 ore"
 
 posta il log di FixVundo e uno aggiornato di HiJack
 | 
 
 
 ok orange,ora faccio quello che mi hai detto,ma che significa:
 
 Disattiva il ripristino di configurazione del sistema. Non so come si fa. Aspetto tue notizie,nel frattempo sto facendo lo scan con il tool symantec
 |  |  
		| Top |  |  
		|  |  
		| aris73 Eroe in grazia degli dei
 
  
  
 Registrato: 26/04/07 22:33
 Messaggi: 102
 
 
 | 
			
				|  Inviato: 27 Apr 2007 17:57    Oggetto: |   |  
				| 
 |  
				| Disattivare ripristino configurazione sistema: Start-->pannello di controllo-->sistema-->ripristino configurazione-->spunta la casella disattiva-->applica--> ok
 |  |  
		| Top |  |  
		|  |  
		| mr brown Eroe
 
  
 
 Registrato: 25/04/07 10:29
 Messaggi: 42
 Residenza: desktop
 
 | 
			
				|  Inviato: 28 Apr 2007 18:46    Oggetto: Re: per orange |   |  
				| 
 |  
				|  	  | Orange ha scritto: |  	  |  	  | mr brown ha scritto: |  	  | ma a cosa serve effettivamente questo vundo? | 
 dato che  Vundo è un trojan, direi che non ti serve a niente...
     
 VundoFix ha eliminato parecchie cose, tranne quella che speravo che eliminasse...
 prova a fare lo scan con quest'altro di Symantec.
 
 Da Installazione Applicazioni disinstalla MyGlobalSearch
 
 Disattiva il ripristino di configurazione del sistema
 Avvia in modalità provvisoria
 avvia HiJack
 seleziona "Do a system scan only"
 metti la spunta alle voci indicate e premi "Fix checked"
 
 O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\iccufbux.dll
 O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O2 - BHO: (no name) - {4A445D21-252C-4820-80EB-24B63D964D68} - C:\WINDOWS\system32\monjttsa.dll (file missing)
 O2 - BHO: (no name) - {B5457B55-99C0-47A1-8DE9-48570007C4FF} - C:\WINDOWS\system32\vtusp.dll (file missing)
 O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Programmi\MyGlobalSearch\bar\8.bin\MGSBAR.DLL
 O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\pyrcimvq.dll",setvm
 O4 - HKCU\..\Run: [ssesso] C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe t
 O9 - Extra button: ssesso - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe (file missing)
 
 scarica CCleaner e dai una ripulita generale (prima vai in Opzioni/Avanzate e togli la spunta da "cancella files temp di windows solo se più vecchi di 48 ore"
 
 posta il log di FixVundo e uno aggiornato di HiJack
 | 
 
 ok orange ho fatto tutto quello che mi hai detto,per ora un problema è risolto,cioè quello del messaggio di errore che mi dava ad ogni avvio,ma resta sempre il problema con svvhost che mi occupa la cpu,ora ti posto quello che mi hai chiesto nel prossimo messaggio
 |  |  
		| Top |  |  
		|  |  
		| mr brown Eroe
 
  
 
 Registrato: 25/04/07 10:29
 Messaggi: 42
 Residenza: desktop
 
 | 
			
				|  Inviato: 28 Apr 2007 18:51    Oggetto: log |   |  
				| 
 |  
				| ecco hijackrthis: Logfile of HijackThis v1.99.1
 Scan saved at 18.33.03, on 28/04/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\hijackthis_199\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar4.dll
 O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar4.dll
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\bak\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [NBJ] "C:\Programmi\Ahead\Nero BackItUp\NBJ.exe"
 O4 - HKCU\..\Run: [E06IXLRD_211624] "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE" -m
 O4 - HKCU\..\Run: [ssesso] C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe t
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: Yahoo! Poker - http://download2.games.yahoo.com/games/clients/y/pt3_x.cab
 O16 - DPF: Yahoo! Pool 2 - http://download2.games.yahoo.com/games/clients/y/poti_x.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
 O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Programmi\Eset\nod32krn.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
 
 
 cmq ho notato che non si riesce ad eliminare questo:
 O4 - HKCU\..\Run: [ssesso] C:\Documents and Settings\pc\Dati applicazioni\ssesso[1].exe t
 
 e infine questo è il log di fixvundo:
 
 Symantec Trojan.Vundo Removal Tool 1.5.0
 
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\baby_martina_kiss@hotmail.it\SharingMetadata\lola82kiss@hotmail.it\DFSR\Staging\CS{D25B4E27-DBA0-E68B-B886-35E8D21F1C6D}\01\10-{D25B4E27-DBA0-E68B-B886-35E8D21F1C6D}-v1-{6B745B16-90EA-43BF-8B3F-B07853F46D9F}-v10-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\baby_martina_kiss@hotmail.it\SharingMetadata\lola82kiss@hotmail.it\DFSR\Staging\CS{D25B4E27-DBA0-E68B-B886-35E8D21F1C6D}\31\11-{8334056F-E5CB-43C0-A840-AE7ADAA0FC73}-v31-{6B745B16-90EA-43BF-8B3F-B07853F46D9F}-v11-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\baby_martina_kiss@hotmail.it\SharingMetadata\lola82kiss@hotmail.it\DFSR\Staging\CS{D25B4E27-DBA0-E68B-B886-35E8D21F1C6D}\33\13-{8334056F-E5CB-43C0-A840-AE7ADAA0FC73}-v33-{6B745B16-90EA-43BF-8B3F-B07853F46D9F}-v13-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\baby_martina_kiss@hotmail.it\SharingMetadata\lola82kiss@hotmail.it\DFSR\Staging\CS{D25B4E27-DBA0-E68B-B886-35E8D21F1C6D}\35\14-{8334056F-E5CB-43C0-A840-AE7ADAA0FC73}-v35-{6B745B16-90EA-43BF-8B3F-B07853F46D9F}-v14-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\angelperry@libero.it\DFSR\Staging\CS{31E38EDE-19E3-0E58-D6FD-85EBDC0AA144}\35\435-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v435-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v435-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\angelperry@libero.it\DFSR\Staging\CS{31E38EDE-19E3-0E58-D6FD-85EBDC0AA144}\90\190-{6C778429-3088-4B0D-AAAC-05CEDBC093B3}-v190-{6C778429-3088-4B0D-AAAC-05CEDBC093B3}-v190-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\angelperry@libero.it\DFSR\Staging\CS{31E38EDE-19E3-0E58-D6FD-85EBDC0AA144}\91\191-{6C778429-3088-4B0D-AAAC-05CEDBC093B3}-v191-{6C778429-3088-4B0D-AAAC-05CEDBC093B3}-v191-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\angelperry@libero.it\DFSR\Staging\CS{31E38EDE-19E3-0E58-D6FD-85EBDC0AA144}\92\192-{6C778429-3088-4B0D-AAAC-05CEDBC093B3}-v192-{6C778429-3088-4B0D-AAAC-05CEDBC093B3}-v192-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\erika-chan@hotmail.it\DFSR\Staging\CS{64CF32F0-45BD-CD13-755B-97514967E618}\01\292-{64CF32F0-45BD-CD13-755B-97514967E618}-v1-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v292-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\erika-chan@hotmail.it\DFSR\Staging\CS{64CF32F0-45BD-CD13-755B-97514967E618}\64\4264-{0C77A43D-E914-4E2F-AB8B-4E6CB5FB3D31}-v4264-{0C77A43D-E914-4E2F-AB8B-4E6CB5FB3D31}-v4264-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\marypet@hotmail.it\DFSR\Staging\CS{131E4667-83E1-BAD6-7235-17E89C3C9DF7}\01\231-{131E4667-83E1-BAD6-7235-17E89C3C9DF7}-v1-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v231-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\pamela12345@tiscali.it\DFSR\Staging\CS{544B836E-B8C9-8F60-90D0-1AF4D9B44C30}\01\437-{544B836E-B8C9-8F60-90D0-1AF4D9B44C30}-v1-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v437-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\spellicchio@hotmail.it\DFSR\Staging\CS{7288701F-7B25-D126-1E75-5E381706FF1D}\01\246-{7288701F-7B25-D126-1E75-5E381706FF1D}-v1-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v246-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\spellicchio@hotmail.it\DFSR\Staging\CS{7288701F-7B25-D126-1E75-5E381706FF1D}\47\248-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v247-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v248-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\01\12-{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}-v1-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v12-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\07\359-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v207-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v359-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\11\40-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v11-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v40-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\13\342-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v13-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v342-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\14\369-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v14-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v369-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\15\339-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v15-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v339-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\15\364-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v15-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v364-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\17\333-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v17-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v333-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\18\372-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v18-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v372-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\19\373-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v19-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v373-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\23\338-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v23-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v338-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\24\344-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v24-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v344-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\24\368-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v224-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v368-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\25\327-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v125-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v327-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\25\352-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v25-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v352-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\26\334-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v26-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v334-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\26\337-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v26-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v337-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\29\365-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v29-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v365-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\30\366-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v130-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v366-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\38\332-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v138-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v332-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\50\355-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v50-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v355-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\53\370-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v53-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v370-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\57\57-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v57-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v57-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\61\336-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v161-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v336-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\64\322-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v164-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v322-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\68\171-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v68-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v171-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\75\348-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v75-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v348-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\79\349-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v79-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v349-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\87\363-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v187-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v363-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\97\347-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v197-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v347-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\dario_volley@hotmail.it\SharingMetadata\star_light92@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\99\230-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v199-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v230-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\ing_raffaele@hotmail.it\SharingMetadata\shoutsrn@inwind.it\DFSR\Staging\CS{561F75FE-9698-3E23-AE3B-954D37008296}\01\10-{561F75FE-9698-3E23-AE3B-954D37008296}-v1-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v10-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\ing_raffaele@hotmail.it\SharingMetadata\skashar@hotmail.it\DFSR\Staging\CS{2CFCB58F-F2C8-7A52-28B8-7312F06054F4}\01\20-{2CFCB58F-F2C8-7A52-28B8-7312F06054F4}-v1-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v20-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\ing_raffaele@hotmail.it\SharingMetadata\skashar@hotmail.it\DFSR\Staging\CS{2CFCB58F-F2C8-7A52-28B8-7312F06054F4}\21\22-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v21-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v22-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\ing_raffaele@hotmail.it\SharingMetadata\skashar@hotmail.it\DFSR\Staging\CS{2CFCB58F-F2C8-7A52-28B8-7312F06054F4}\25\27-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v25-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v27-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\ing_raffaele@hotmail.it\SharingMetadata\tommy_h00@yahoo.it\DFSR\Staging\CS{1B2E5337-BFAC-9ED0-3A3A-CC9BDCBF60EB}\01\11-{1B2E5337-BFAC-9ED0-3A3A-CC9BDCBF60EB}-v1-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v11-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\ing_raffaele@hotmail.it\SharingMetadata\tommy_h00@yahoo.it\DFSR\Staging\CS{1B2E5337-BFAC-9ED0-3A3A-CC9BDCBF60EB}\12\14-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v12-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v14-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\ing_raffaele@hotmail.it\SharingMetadata\tommy_h00@yahoo.it\DFSR\Staging\CS{1B2E5337-BFAC-9ED0-3A3A-CC9BDCBF60EB}\15\18-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v15-{CE4947A2-AFC4-4D3B-8A80-F7DFBFA261B1}-v18-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\skrycci@libero.it\SharingMetadata\angelperry@libero.it\DFSR\Staging\CS{5696E5BC-E9E1-F9DD-581C-96F18CB2CC5B}\01\10-{5696E5BC-E9E1-F9DD-581C-96F18CB2CC5B}-v1-{F26F94E5-5FC7-4A0F-B868-DB74BED3F547}-v10-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\01\43-{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}-v1-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v43-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\07\81-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v207-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v81-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\11\19-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v11-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v19-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\13\71-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v13-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v71-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\14\30-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v14-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v30-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\15\27-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v15-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v27-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\15\29-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v15-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v29-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\17\25-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v17-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v25-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\18\34-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v18-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v34-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\19\26-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v19-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v26-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\23\31-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v23-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v31-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\24\62-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v24-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v62-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\24\79-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v224-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v79-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\25\28-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v25-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v28-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\25\37-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v125-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v37-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\26\27-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v26-{FB04E49B-5574-484D-AD0F-80213FAF4800}-v27-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\26\33-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v26-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v33-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\29\29-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v29-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v29-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\30\38-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v130-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v38-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\38\69-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v138-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v69-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\50\50-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v50-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v50-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\53\56-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v53-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v56-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\57\46-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v57-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v46-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\61\72-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v161-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v72-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\64\73-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v164-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v73-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\68\63-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v68-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v63-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\75\65-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v75-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v65-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\79\66-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v79-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v66-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\87\188-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v187-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v188-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\97\78-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v197-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v78-Downloaded.frx (WARNING: not scanned, path to long)
 C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\star_light92@hotmail.it\SharingMetadata\dario_volley@hotmail.it\DFSR\Staging\CS{25BD4E82-8B22-E0D0-D89B-FAF94BFB4904}\99\80-{1D40C5B5-3D88-43BD-BE7F-BFACFEE2A55E}-v199-{8913CFE5-EDC3-4DAE-A59E-820C47410A02}-v80-Downloaded.frx (WARNING: not scanned, path to long)
 C:\System Volume Information: (not scanned)
 Trojan.Vundo has not been found on your computer.
 
 aspetto tue(vostre in generale) notizie,grazie anticipatamente
 
  |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |