Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
neofita di vista mi puzza sembra esserci qualcosa che non va
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus
Precedente :: Successivo  
Autore Messaggio
bemaffei
Mortale pio
Mortale pio


Registrato: 11/10/07 16:36
Messaggi: 24

MessaggioInviato: 31 Dic 2007 00:07    Oggetto: neofita di vista mi puzza sembra esserci qualcosa che non va Rispondi citando

Ciao a tutti

dopo due giorni che mi sto vedendo questo SO a naso mi sembra di avere già qualcosa che non va!!

mi si aprono ogni tanto finestre vuote di iexporer!!!

usati Serch and destroy spyware doctor e ripulito di qualcosa ma il problema persiste...

ho trovato lqvcpuafka.exe in esecuzione !!!!

ecco il mi log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.56.59, on 30/12/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\System32\msconfig.exe
C:\Windows\system32\mmc.exe
C:\Windows\system32\conime.exe
C:\Windows\System32\msinfo32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=IT_IT&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=IT_IT&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=IT_IT&c=73&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: APSHook.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

--
End of file - 12767 bytes

Ciao
e grazie per qualche dritta di FINE ANNO!!!!
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 31 Dic 2007 10:57    Oggetto: Rispondi citando

Ciao bemaffei Smile
Non mi pare ci siano anomalie nel log.
Non so se Combofix è compatibile con Vista, ma guarda questa discussione relativa a Combofix, scaricalo e fai la scansione del PC, postando il risultato come indicato. Fai la scansione anche con Virit
Aggiornalo mediante l'icona della parabola posta nella barra in alto e fagli fare la scansione completa del PC.
Fai in modo che rimuova automaticamente i file infetti trovati.
Non dimenticare di disattivare momentaneamente il tuo antivirus.
Incolla poi quì il risultato, insiema ad un nuovo log di HJT.
Top
Profilo Invia messaggio privato
bemaffei
Mortale pio
Mortale pio


Registrato: 11/10/07 16:36
Messaggi: 24

MessaggioInviato: 31 Dic 2007 21:16    Oggetto: ecco il rapporto di combofix Rispondi citando

ComboFix 07-12-30.3 - benny 2007-12-31 19.53.38.1 - NTFSx86
Microsoft® Windows Vista? Home Premium 6.0.6000.0.1252.1.1040.18.2047 [GMT 1:00]
Eseguito da: C:\Users\benny\Desktop\Sicurezza\ComboFix.exe
* Creato nuovo punto di ripristino
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\internetgamebox
C:\Program Files\internetgamebox\InternetGameBox.exe
C:\Program Files\internetgamebox\language
C:\Program Files\internetgamebox\Privacy Policy.url
C:\Program Files\internetgamebox\ressources\AttenteOff.html
C:\Program Files\internetgamebox\ressources\AttenteOn.html
C:\Program Files\internetgamebox\ressources\configv2_en.xml
C:\Program Files\internetgamebox\ressources\configv2_es.xml
C:\Program Files\internetgamebox\ressources\configv2_fr.xml
C:\Program Files\internetgamebox\ressources\favoris\defaultv2.swf
C:\Program Files\internetgamebox\skins\skinv2.skn
C:\Program Files\internetgamebox\Terms and conditions.url
C:\Program Files\internetgamebox\uninst.exe
C:\Program Files\internetgamebox\Website.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InternetGameBox
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InternetGameBox\InternetGameBox.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InternetGameBox\Privacy Policy.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InternetGameBox\Terms and conditions.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InternetGameBox\Website.lnk
c:\Users\benny\AppData\Local\lqvcpuafka.dat
c:\users\benny\appdata\local\lqvcpuafka.exe
c:\Users\benny\AppData\Local\lqvcpuafka_nav.dat
c:\Users\benny\AppData\Local\lqvcpuafka_navps.dat
C:\Users\benny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InternetGameBox
C:\Users\benny\AppData\Roaming\setup_it[1].exe

.
((((((((((((((((((((((((( Files Creati Da 2007-11-28 al 2007-12-31 )))))))))))))))))))))))))))))))))))
.

2007-12-31 19:48 . 2005-09-23 08:29 626,688 --a------ C:\Windows\System32\msvcr80.dll
2007-12-31 19:20 . 2007-12-21 21:17 219 --a------ C:\Windows\win.tmp
2007-12-31 19:20 . 2006-09-18 22:46 219 --a------ C:\Windows\system.tmp
2007-12-31 15:32 . 2007-12-31 15:32 <DIR> d-------- C:\Program Files\Realtek
2007-12-30 23:44 . 2007-12-30 23:44 1,890 --a------ C:\Windows\System32\tmp.reg
2007-12-30 23:41 . 2007-12-30 23:41 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-12-29 19:06 . 2007-12-29 19:06 0 --a------ C:\Windows\nsreg.dat
2007-12-29 19:04 . 2007-12-29 19:04 <DIR> d-------- C:\Program Files\Common Files\xing shared
2007-12-29 19:04 . 2007-12-29 19:14 4,059 --a------ C:\Windows\mozver.dat
2007-12-29 19:03 . 2007-12-29 19:03 <DIR> d-------- C:\Program Files\Common Files\Real
2007-12-29 19:02 . 2007-12-29 19:02 <DIR> d-------- C:\Program Files\Real
2007-12-29 16:06 . 2007-12-29 21:01 <DIR> d-------- C:\Users\benny\.housecall6.6
2007-12-29 16:05 . 2007-12-29 16:05 <DIR> d-------- C:\Windows\Sun
2007-12-29 12:04 . 2007-12-30 13:45 <DIR> d-------- C:\filmini
2007-12-29 11:08 . 2007-12-29 11:08 22,528 --a------ C:\Windows\System32\Partizan.exe
2007-12-29 11:02 . C:\Windows\(2) C:\ComboFix\winstart.bat
2007-12-29 10:38 . 2007-12-29 11:53 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2007-12-29 10:38 . 2007-12-29 11:53 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2007-12-29 09:58 . 2007-12-29 09:58 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-29 09:55 . 2007-12-29 09:55 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2007-12-29 09:55 . 2007-12-29 09:55 <DIR> d-------- C:\Users\All Users\Kaspersky Lab
2007-12-29 09:55 . 2007-12-29 09:55 <DIR> d-------- C:\ProgramData\Kaspersky Lab
2007-12-29 09:36 . 2007-12-31 19:59 <DIR> d-a------ C:\Users\All Users\TEMP
2007-12-29 09:36 . 2007-12-31 19:59 <DIR> d-a------ C:\ProgramData\TEMP
2007-12-29 09:28 . 2006-08-24 11:40 51,072 --a------ C:\Windows\System32\drivers\ikhlayer.sys
2007-12-29 09:28 . 2006-07-10 16:38 30,592 --a------ C:\Windows\System32\drivers\ikhfile.sys
2007-12-29 09:27 . 2007-12-29 09:27 <DIR> d-------- C:\Users\benny\AppData\Roaming\PC Tools
2007-12-29 09:27 . 2007-12-29 10:54 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-12-29 09:18 . 2007-12-29 09:18 <DIR> d-------- C:\Windows\Repair
2007-12-29 09:17 . 2007-12-29 09:17 <DIR> d-------- C:\Users\benny\AppData\Roaming\Systweak
2007-12-29 09:17 . 2007-12-29 09:21 <DIR> d-------- C:\Program Files\Advanced System Optimizer
2007-12-29 01:00 . 2007-12-29 01:00 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2007-12-29 00:05 . 2007-12-30 10:12 <DIR> d-------- C:\Program Files\Linksys
2007-12-27 22:28 . 2007-12-31 00:55 547,064 --ah----- C:\Windows\System32\mlfcache.dat
2007-12-27 20:58 . 2007-12-27 20:58 <DIR> d-------- C:\Program Files\TomTom DesktopSuite
2007-12-27 20:29 . 2007-12-27 20:59 <DIR> d-------- C:\Program Files\Picasa2
2007-12-27 00:14 . 2007-12-29 09:34 336,066,613 --a------ C:\Windows\MEMORY.DMP
2007-12-26 23:18 . 2007-12-26 23:18 <DIR> d-------- C:\perflogs
2007-12-26 19:05 . 2007-12-26 19:05 <DIR> d-------- C:\Users\benny\AppData\Roaming\Sony
2007-12-26 19:05 . 2007-12-26 19:05 <DIR> d-------- C:\Users\benny\AppData\Roaming\Publish Providers
2007-12-26 19:05 . 2007-12-26 19:05 <DIR> d-------- C:\Users\benny\AppData\Roaming\NetMedia Providers
2007-12-26 19:04 . 2007-12-26 19:04 <DIR> d-------- C:\Program Files\Sony
2007-12-26 19:02 . 2007-12-26 19:08 <DIR> d-------- C:\Program Files\Sony Setup
2007-12-26 17:01 . 2007-12-26 17:01 <DIR> d-------- C:\Program Files\vanBasco's Karaoke Player
2007-12-26 11:11 . 2007-12-26 11:37 <DIR> d-------- C:\Audio
2007-12-25 21:34 . 2007-12-28 19:45 <DIR> d-------- C:\Users\benny\AppData\Roaming\ZoomBrowser EX
2007-12-25 21:33 . 2007-12-25 21:33 <DIR> d-------- C:\Users\benny\AppData\Roaming\Canon
2007-12-25 21:26 . 2007-12-28 19:44 <DIR> d-------- C:\Users\All Users\ZoomBrowser
2007-12-25 21:26 . 2007-12-28 19:44 <DIR> d-------- C:\ProgramData\ZoomBrowser
2007-12-24 21:19 . 2007-12-25 21:23 <DIR> d-------- C:\Program Files\Common Files\Canon
2007-12-23 18:37 . 2007-12-23 18:48 <DIR> d-------- C:\Driver Computer
2007-12-23 17:58 . 2004-06-02 10:27 163,840 --a------ C:\Windows\System32\CNDUK175.dll
2007-12-23 17:58 . 2004-05-31 18:04 118,867 --a------ C:\Windows\System32\DSLLK175.dll
2007-12-23 17:58 . 2004-06-02 10:26 94,208 --a------ C:\Windows\System32\CNDCK175.dll
2007-12-23 17:58 . 2004-06-08 18:46 40,960 --a------ C:\Windows\System32\CNDNDlg.exe
2007-12-23 17:30 . 2001-08-08 11:45 2,641,973 --a------ C:\Windows\System32\opapi11.dll
2007-12-23 17:30 . 2001-08-07 13:54 74,665 --a------ C:\Windows\System32\openpage.msg
2007-12-23 17:30 . 2007-12-23 17:30 0 --a------ C:\Windows\OPPRIN~1.INI
2007-12-23 17:29 . 1999-12-07 11:00 565,760 --a------ C:\Windows\System32\MSVCP50.DLL
2007-12-23 17:28 . 2007-12-25 21:27 <DIR> d-------- C:\Program Files\Canon
2007-12-23 17:27 . 1998-11-13 14:07 307,712 --a------ C:\Windows\IsUn0410.exe
2007-12-23 15:11 . 2007-12-23 15:11 <DIR> d-------- C:\Users\All Users\Yahoo! Companion
2007-12-23 15:11 . 2007-12-23 15:11 <DIR> d-------- C:\ProgramData\Yahoo! Companion
2007-12-23 15:11 . 2000-05-24 15:02 299,520 --a------ C:\Windows\uninst.exe
2007-12-23 14:56 . 2006-09-29 06:56 28,248 -ra------ C:\Windows\System32\AdobePDF.dll
2007-12-23 14:41 . 2007-12-23 14:41 <DIR> d-------- C:\Users\benny\AppData\Roaming\ACD Systems
2007-12-23 14:41 . 2007-12-23 14:41 <DIR> d-------- C:\Program Files\Yahoo!
2007-12-23 14:40 . 2007-12-23 14:40 <DIR> d-------- C:\Users\All Users\ACD Systems
2007-12-23 14:40 . 2007-12-23 14:40 <DIR> d-------- C:\ProgramData\ACD Systems
2007-12-23 14:40 . 2007-12-23 14:40 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2007-12-23 14:40 . 2007-12-23 14:40 <DIR> d-------- C:\Program Files\ACD Systems
2007-12-23 14:39 . 2007-12-23 14:39 10,368 --a------ C:\Windows\System32\drivers\pfc.sys
2007-12-23 00:32 . 2007-12-23 00:32 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-23 00:32 . 2007-12-04 14:04 837,496 --a------ C:\Windows\System32\aswBoot.exe
2007-12-23 00:32 . 2004-01-09 10:13 380,928 --a------ C:\Windows\System32\actskin4.ocx
2007-12-23 00:32 . 2007-12-04 13:54 95,608 --a------ C:\Windows\System32\AvastSS.scr
2007-12-23 00:32 . 2007-12-04 15:52 45,648 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2007-12-23 00:32 . 2007-12-04 15:51 42,912 --a------ C:\Windows\System32\drivers\aswTdi.sys
2007-12-23 00:32 . 2007-12-04 15:53 23,152 --a------ C:\Windows\System32\drivers\aswRdr.sys
2007-12-23 00:24 . 2007-12-23 14:59 <DIR> d-------- C:\Users\All Users\FLEXnet
2007-12-23 00:24 . 2007-12-23 14:59 <DIR> d-------- C:\ProgramData\FLEXnet
2007-12-23 00:17 . 2007-12-23 00:17 <DIR> d-------- C:\Program Files\Bonjour
2007-12-23 00:09 . 2007-12-23 00:09 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-12-22 23:53 . 2007-12-22 23:53 <DIR> d-------- C:\Program Files\WinZip Self-Extractor
2007-12-22 23:51 . 2007-12-22 23:51 <DIR> d-------- C:\Users\benny\AppData\Roaming\PeerNetworking
2007-12-22 23:48 . 2007-12-22 23:50 575 --a------ C:\Windows\System32\Ahmbed.gz
2007-12-22 23:24 . 2007-12-22 23:24 <DIR> d-------- C:\Users\benny\AppData\Roaming\Corel
2007-12-22 23:23 . 2007-12-22 23:23 <DIR> d-------- C:\Users\All Users\InstallShield
2007-12-22 23:23 . 2007-12-22 23:23 <DIR> d-------- C:\ProgramData\InstallShield
2007-12-22 23:17 . 2007-12-30 15:10 2,828 --ahs---- C:\Windows\System32\KGyGaAvL.sys
2007-12-22 23:10 . 2007-12-23 14:29 <DIR> d-------- C:\Users\benny\AppData\Roaming\Roxio
2007-12-22 16:05 . 2007-12-22 16:05 <DIR> d-------- C:\Program Files\Microsoft IntelliPoint
2007-12-22 02:02 . 2007-12-22 02:02 <DIR> d-------- C:\Users\benny\AppData\Roaming\HP
2007-12-22 02:02 . 2007-12-22 02:02 <DIR> d-------- C:\Users\benny\AppData\Roaming\CyberLink
2007-12-22 01:54 . 2007-12-29 12:57 274,963 --a------ C:\Users\benny\AppData\Roaming\nvModes.dat
2007-12-22 00:49 . 2007-12-30 17:03 <DIR> d-------- C:\Users\benny\AppData\Roaming\skypePM
2007-12-22 00:49 . 2007-12-22 00:49 <DIR> d-------- C:\Program Files\Skype
2007-12-22 00:49 . 2007-12-22 00:49 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-12-22 00:49 . 2007-12-22 00:49 32 --a------ C:\Users\All Users\ezsid.dat
2007-12-22 00:49 . 2007-12-22 00:49 32 --a------ C:\ProgramData\ezsid.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 14:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-30 14:38 319,456 ----a-w C:\Windows\DIFxAPI.dll
2007-12-29 18:04 --------- d-----w C:\Program Files\Google
2007-12-23 19:30 --------- d-----w C:\ProgramData\CyberLink
2007-12-22 23:17 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-22 22:54 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-22 22:23 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-22 22:10 --------- d-----w C:\ProgramData\Sonic
2007-12-22 20:02 --------- d-----w C:\ProgramData\Symantec
2007-12-22 01:08 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-22 01:02 --------- d-----w C:\ProgramData\HP
2007-12-21 20:32 --------- d-----w C:\ProgramData\Roxio
2007-12-21 18:07 --------- d-sh--w C:\ProgramData\Preferiti
2007-12-21 18:07 --------- d-sh--w C:\ProgramData\Modelli
2007-12-21 18:07 --------- d-sh--w C:\ProgramData\Menu Avvio
2007-12-21 18:07 --------- d-sh--w C:\ProgramData\Documenti
2007-12-21 18:07 --------- d-sh--w C:\ProgramData\Desktop
2007-12-21 18:07 --------- d-sh--w C:\ProgramData\Dati applicazioni
2007-12-21 18:07 --------- d-sh--w C:\Program Files\File comuni
2007-12-21 06:20 174 --sha-w C:\Program Files\desktop.ini
2007-12-21 06:15 --------- d-----w C:\Program Files\Windows Mail
2007-12-21 06:15 --------- d-----w C:\Program Files\Windows Defender
2007-12-21 06:15 --------- d-----w C:\Program Files\Windows Calendar
2007-12-21 06:03 87,040 ----a-w C:\Windows\System32\msoert2.dll
2007-12-21 06:03 8,192 ----a-w C:\Windows\System32\riched32.dll
2007-12-21 06:03 77,824 ----a-w C:\Windows\System32\rascfg.dll
2007-12-21 06:03 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2007-12-21 06:03 694,784 ----a-w C:\Windows\System32\localspl.dll
2007-12-21 06:03 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2007-12-21 06:03 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2007-12-21 06:03 52,736 ----a-w C:\Windows\System32\rasdiag.dll
2007-12-21 06:03 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2007-12-21 06:03 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2007-12-21 06:03 384,000 ----a-w C:\Windows\System32\netcfgx.dll
2007-12-21 06:03 36,864 ----a-w C:\Windows\System32\cdd.dll
2007-12-21 06:03 33,280 ----a-w C:\Windows\System32\traffic.dll
2007-12-21 06:03 32,768 ----a-w C:\Windows\System32\rasmxs.dll
2007-12-21 06:03 286,208 ----a-w C:\Windows\System32\ipnathlp.dll
2007-12-21 06:03 22,016 ----a-w C:\Windows\System32\rasser.dll
2007-12-21 06:03 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2007-12-21 06:03 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2007-12-21 06:03 15,360 ----a-w C:\Windows\System32\pacerprf.dll
2007-12-21 06:03 134,656 ----a-w C:\Windows\System32\dps.dll
2007-12-21 06:03 13,824 ----a-w C:\Windows\System32\wshqos.dll
2007-12-21 06:03 13,824 ----a-w C:\Windows\System32\icsunattend.exe
2007-12-21 06:02 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-12-21 06:02 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-12-21 06:02 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-12-21 06:02 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-12-21 06:02 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-12-21 06:02 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-12-21 06:02 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-12-21 06:02 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-12-21 06:02 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-12-21 06:02 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-12-21 06:02 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-12-21 06:02 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-12-21 06:02 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-12-21 06:02 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys
2007-12-21 05:56 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2007-12-21 05:56 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-12-21 05:56 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-12-21 05:56 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2007-12-21 05:56 61,952 ----a-w C:\Windows\System32\cmifw.dll
2007-12-21 05:56 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-12-21 05:56 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2007-12-21 05:56 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2007-12-21 05:56 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-12-21 05:56 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2007-12-21 05:56 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2007-12-21 05:56 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2007-12-21 05:56 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2007-12-21 05:54 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2007-12-21 05:54 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2007-12-21 05:54 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2007-12-21 05:54 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2007-12-21 05:44 88,576 ----a-w C:\Windows\System32\avifil32.dll
2007-12-21 05:44 82,944 ----a-w C:\Windows\System32\mciavi32.dll
2007-12-21 05:44 8,138,240 ----a-w C:\Windows\System32\ssBranded.scr
2007-12-21 05:44 712,192 ----a-w C:\Windows\System32\WindowsCodecs.dll
2007-12-21 05:44 69,632 ----a-w C:\Windows\System32\sendmail.dll
2007-12-21 05:44 65,024 ----a-w C:\Windows\System32\avicap32.dll
2007-12-21 05:44 61,440 ----a-w C:\Windows\System32\ntprint.exe
2007-12-21 05:44 31,232 ----a-w C:\Windows\System32\msvidc32.dll
2007-12-21 05:44 269,824 ----a-w C:\Windows\System32\schannel.dll
2007-12-21 05:44 220,160 ----a-w C:\Windows\System32\ntprint.dll
2007-12-21 05:44 123,904 ----a-w C:\Windows\System32\msvfw32.dll
2007-12-21 05:44 120,320 ----a-w C:\Windows\System32\dhcpcsvc6.dll
2007-12-21 05:44 12,800 ----a-w C:\Windows\System32\msrle32.dll
2007-12-21 05:44 10,240 ----a-w C:\Windows\System32\dhcpcmonitor.dll
2007-12-21 05:44 1,984,512 ----a-w C:\Windows\System32\authui.dll
2007-12-21 05:40 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-21 05:40 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-21 05:40 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
.
Codice:

----a-w            64,000 2005-06-10 16:09:34  C:\Audio\Discografia\mp3-old\altro\Pinnacle Steinberg.myMP3 PRO v5.0 Keygen .exe



((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-12-29 09:32 2115728]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
"Sidebar"="C:\Program Files\Windows Sidebar\Sidebar.exe" [2006-11-02 13:35 1196032]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-29 19:03 185896]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 12:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 15:12 317128]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 04:36 827392]
"CognizanceTS"="c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll" [2003-12-22 19:12 17920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-12-29 09:32 2115728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=APSHook.dll

R2 ASBroker;Operatore della sessione di accesso;C:\Windows\System32\svchost.exe [2006-11-02 10:45]
R2 ASChannel;Canale di comunicazione locale;C:\Windows\System32\svchost.exe [2006-11-02 10:45]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-12-04 15:52]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot []
R3 btwaudio;Periferica audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-01-02 11:45]
R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-01-02 11:45]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-01-02 11:45]
R3 NETw4v32;Driver scheda Intel(R) Wireless WiFi Link per Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-03-01 13:49]
R3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-03-05 22:28]
S3 BCM43XV;Driver della scheda di rete Broadcom Extensible 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 08:30]
S3 WRVS4400N_Sp50;WRVS4400N_Sp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\WRVS4400N_Sp50.sys [2006-11-28 21:46]
S4 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-12-22 00:27]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
bthsvcs REG_MULTI_SZ BthServ
Cognizance REG_MULTI_SZ ASBroker ASChannel
GPSvcGroup REG_MULTI_SZ GPSvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{434231b7-b00e-11dc-a58f-806e6f6e6963}]
\shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6870e9d0-b4b1-11dc-9103-001e375c0df9}]
\shell\AutoRun\command - I:\InstallTomTomHOME.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69a2e1d6-aff5-11dc-a44d-001e375c0df9}]
\shell\AutoRun\command - G:\setupSNK.exe

.
Contenuto della cartella 'Scheduled Tasks'
"2007-12-31 13:07:02 C:\Windows\Tasks\User_Feed_Synchronization-{61E0BAF2-9B91-4E86-B181-FBDB42739FE2}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-31 19:59:46
Windows 6.0.6000 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2007-12-31 20:04:55
C:\qoobox\ComboFix-quarantined-files.txt 2007-12-31 19:04:38
.
2007-12-29 00:00:23 --- E O F ---

poi faccio il virit


MI sembra che abbia trovato dei file ?????

ciao

benny
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 01 Gen 2008 18:46    Oggetto: Rispondi

Si ha eliminato dei file....Aspetto il log di Virit...
Top
Profilo Invia messaggio privato
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus Tutti i fusi orari sono GMT + 2 ore
Pagina 1 di 1

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi