| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 03 Set 2007 13:35    Oggetto: PC lento e spegnimenti improvvisi |   |  
				| 
 |  
				| Ciao ragazzi, vorrei che mi aiutaste, il pc, mi si spegne senza preavviso ed il sistema e molto lento...ho controllato negli errori di sistema e sono davvero molti..ora li riporto qui....ps: tutto è successo da quando mio fratello minore tocca il pc. Vi prego aiutatemi!!! 
 log6.txt
 
 edit by bdoriano
 I logs caricali su http://www.freefilehosting.net come indicato qui.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 03 Set 2007 14:39    Oggetto: |   |  
				| 
 |  
				| Ciao, benvenuto/a   
 con l'elenco che hai postato si riesce a capire solo che hai una marea di errori...
  Se sospetti la presenza di un virus nel tuo PC, segui le indicazione di questo topic e posta un log di HiJackThis. |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 03 Set 2007 15:52    Oggetto: fatto |   |  
				| 
 |  
				| Fatto ed ecco il risultato: 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Belkin\Software Bluetooth\bin\btwdins.exe
 C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
 C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Belkin\Software Bluetooth\BTTray.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Programmi\Spyware Doctor\svcntaux.exe
 C:\Programmi\Spyware Doctor\swdsvc.exe
 C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\Programmi\Spyware Doctor\SDTrayApp.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\WINDOWS\system32\WgaTray.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Hbtools\HBTV\HBTV.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\HbTools\Bin\4.8.4.0\HbtSrv.exe
 C:\Programmi\Windows Live Toolbar\msn_sl.exe
 C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?product=ssearch&src_id=395&client_id=A21C5C4001C7EE150025339E&version=4.5.4.0&it=1188815508&loc=&qry=&url=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome (obfuscated)
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programmi\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL
 O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programmi\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programmi\MyWebSearch\bar\7.bin\MWSBAR.DLL
 O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll
 O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Programmi\NewDotNet\newdotnet7_48.dll
 O2 - BHO: TVEngine Helper /fleok=1D8A83A5C2E6107C91A475760EA83FA5EF80752B94E2DD775D784E293EC1 - {4B18DD50-C996-44fc-AC52-0FECFF82ED58} - c:\programmi\hbtools\hbtv\hbtvhelper.dll
 O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
 O2 - BHO: (no name) - {5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e} - C:\Programmi\Horoscopes IT\bin\Horoscopes_IT.dll
 O2 - BHO: HbTools - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Programmi\HbTools\Bin\4.8.4.0\HbtHostIE.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
 O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
 O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
 O3 - Toolbar: Virgilio Toolbar - {D3403F28-7D39-435F-A8CB-45016C29E48E} - C:\Programmi\Virgilio Toolbar\VirgilioBand.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: H&otbar - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Programmi\HbTools\Bin\4.8.4.0\HbtHostIE.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 O3 - Toolbar: Starware Oroscopi - {1962c5bc-e475-465b-823b-133e711bceb9} - C:\Programmi\Horoscopes IT\bin\Horoscopes_IT.dll
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SDTray] "C:\Programmi\Spyware Doctor\SDTrayApp.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe" /WinStart
 O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [AWMON] "C:\Programmi\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: C6 Messenger.lnk = C:\Programmi\C6 Messenger\c6Messenger.exe
 O4 - Startup: IMVU.lnk = C:\Programmi\IMVU\IMVUClient.exe
 O4 - Startup: Utilità controllo supporti di Picture Motion Browser.lnk = C:\Programmi\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
 O4 - Global Startup: Album Fast Start.lnk = C:\Programmi\ABMTSR.EXE
 O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: Google Updater.lnk = C:\Programmi\Google\Google Updater\GoogleUpdater.exe
 O8 - Extra context menu item: &MSN Search - res://C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll/search.htm
 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm762YYIT
 O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?6c03903813c3453da27821d1284155a
 O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?6c03903813c3453da27821d1284155a
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie_ctx.htm
 O8 - Extra context menu item: Translate with &Babylon - res://C:\Programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll
 O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll
 O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie.htm
 O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie.htm
 O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Utente\Menu Avvio\Programmi\IMVU\Run IMVU.lnk
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra button: Alice - {F77CF537-2D54-4054-AB13-6C46B96D5E36} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
 O15 - Trusted Zone: *.cercoporno.com
 O15 - Trusted Zone: *.eros-porno.com
 O15 - Trusted Zone: *.videopornazzi.com
 O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
 O16 - DPF: {00000000-0023-0000-5400-320020040070} - http://www.manga4you.it/adult/adult.exe
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/WebfettiInitialSetup1.0.0.15-3.cab
 O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://beautifulspaceitaly.spaces.msn.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137177993844
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184166701640
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
 O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
 O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\d4j0le1m1h.dll (file missing)
 O23 - Service: Boonty Games - BOONTY - C:\Programmi\File comuni\BOONTY Shared\Service\Boonty.exe
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\Belkin\Software Bluetooth\bin\btwdins.exe
 O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
 O23 - Service: GoogleDesktopManager - Google - C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
 O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 O23 - Service: StyleXPService - Unknown owner - C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe
 
 --
 End of file - 14259 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 03 Set 2007 18:06    Oggetto: |   |  
				| 
 |  
				| Ciao miaka8620   Il tuo PC è altamente infetto.
 
 Direi di lasciare stare per ora HJT.-
 Scarica Virit da qui: http://www.tgsoft.it/italy/download.htm
 
 Aggiornalo e fagli fare la scansione completa del PC.
 Fai in modo che rimuova automaticamente i file infetti trovati.
 Incolla poi quì il risultato. Riavvia il PC e rifai un log aggiornato di HJT.
 Installati urgentemente un antivirus, un firewall e un paio di Antyspyware.
 Sul primo link della pagina principale del forum trovi la discussione al riguardo.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 04 Set 2007 01:14    Oggetto: |   |  
				| 
 |  
				| ho fatto tutto quello che mi hai detto e dopo ho fatto il log con HJT ed ecco il risultto: Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
 C:\Programmi\Belkin\Software Bluetooth\bin\btwdins.exe
 C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
 C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Programmi\Spyware Doctor\svcntaux.exe
 C:\VEXPLITE\MONLITE.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 C:\Programmi\Belkin\Software Bluetooth\BTTray.exe
 C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\Programmi\Spyware Doctor\SDTrayApp.exe
 C:\WINDOWS\system32\svchost.exe
 C:\VEXPLITE\viritsvc.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\WgaTray.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Spyware Doctor\swdsvc.exe
 C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programmi\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL (file missing)
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Programmi\NewDotNet\newdotnet7_48.dll
 O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
 O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
 O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
 O3 - Toolbar: Virgilio Toolbar - {D3403F28-7D39-435F-A8CB-45016C29E48E} - C:\Programmi\Virgilio Toolbar\VirgilioBand.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SDTray] "C:\Programmi\Spyware Doctor\SDTrayApp.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe" /WinStart
 O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [AWMON] "C:\Programmi\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: C6 Messenger.lnk = C:\Programmi\C6 Messenger\c6Messenger.exe
 O4 - Startup: IMVU.lnk = C:\Programmi\IMVU\IMVUClient.exe
 O4 - Startup: Utilità controllo supporti di Picture Motion Browser.lnk = C:\Programmi\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
 O4 - Global Startup: Album Fast Start.lnk = C:\Programmi\ABMTSR.EXE
 O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: Google Updater.lnk = C:\Programmi\Google\Google Updater\GoogleUpdater.exe
 O8 - Extra context menu item: &MSN Search - res://C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll/search.htm
 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm762YYIT
 O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?6c03903813c3453da27821d1284155a
 O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?6c03903813c3453da27821d1284155a
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie_ctx.htm
 O8 - Extra context menu item: Translate with &Babylon - res://C:\Programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
 O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
 O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie.htm
 O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie.htm
 O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Utente\Menu Avvio\Programmi\IMVU\Run IMVU.lnk
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra button: Alice - {F77CF537-2D54-4054-AB13-6C46B96D5E36} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
 O15 - Trusted Zone: *.cercoporno.com
 O15 - Trusted Zone: *.eros-porno.com
 O15 - Trusted Zone: *.videopornazzi.com
 O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://beautifulspaceitaly.spaces.msn.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137177993844
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184166701640
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
 O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
 O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\d4j0le1m1h.dll (file missing)
 O23 - Service: Boonty Games - BOONTY - C:\Programmi\File comuni\BOONTY Shared\Service\Boonty.exe
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\Belkin\Software Bluetooth\bin\btwdins.exe
 O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
 O23 - Service: GoogleDesktopManager - Google - C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
 O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 O23 - Service: StyleXPService - Unknown owner - C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe
 O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas   www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
 
 --
 End of file - 12872 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 04 Set 2007 08:37    Oggetto: |   |  
				| 
 |  
				| Sarebbe utile anche il log di VirIT.  |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 04 Set 2007 17:53    Oggetto: |   |  
				| 
 |  
				| il problema e che appena ha finito ho riavviato e nn ha salvato il risultato di Virit..cmq ricordo che ha cancellato 27 virus..(nn sò sè ti può essere utile!! |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 04 Set 2007 18:02    Oggetto: |   |  
				| 
 |  
				| il log viene salvato comunque. lo trovi in C:\VIRITLITE\VIRITEXP.log 	  | miaka8620 ha scritto: |  	  | il problema e che appena ha finito ho riavviato e nn ha salvato il risultato di Virit.. | 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 06 Set 2007 18:34    Oggetto: |   |  
				| 
 |  
				| Trovato, grazie mille Orange! SCANSIONE DEL REGISTRO]
 {00A6FAF1-072E-44cf-8957-5838F569A31D}  Infetto da BHO.MyWebSearch.B
 * * *  RIMOSSO  * * *
 {07B18EA1-A523-4961-B6BB-170DE4475CCA}  Infetto da BHO.MyWebSearch.B
 * * *  RIMOSSO  * * *
 {1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}  Infetto da BHO.MyWebSearch.B
 * * *  RIMOSSO  * * *
 {07B18EA9-A523-4961-B6BB-170DE4475CCA}  Infetto da BHO.MyWebSearch.B
 * * *  RIMOSSO  * * *
 {07B18EAB-A523-4961-B6BB-170DE4475CCA}  Infetto da BHO.MyWebSearch.B
 * * *  RIMOSSO  * * *
 {00000000-0023-0000-5400-320020040070}  Infetto da Trojan.Win32.Dialer.AV
 * * *  RIMOSSO  * * *
 {74CC49F7-EB32-4A08-B204-948962A6E3DB}  Infetto da Trojan.Win32.Hotbar.I
 * * *  RIMOSSO  * * *
 {8C875948-9C60-4381-9248-0DF180542D53}  Infetto da Trojan.Win32.Hotbar.L
 * * *  RIMOSSO  * * *
 {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}  Infetto da Adware.FunWeb.C
 * * *  RIMOSSO  * * *
 {4B18DD50-C996-44fc-AC52-0FECFF82ED58}  Infetto da BHO.Hotbar.F
 * * *  RIMOSSO  * * *
 {100EB1FD-D03E-47FD-81F3-EE91287F9465}  Infetto da BHO.Shopper.D
 * * *  RIMOSSO  * * *
 {5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e}  Infetto da Adware.Starware.J
 * * *  RIMOSSO  * * *
 {1962c5bc-e475-465b-823b-133e711bceb9}  Infetto da Adware.Starware.J
 * * *  RIMOSSO  * * *
 
 [A:]
 BOOT SECTOR: OK
 
 
 [C:]
 MASTER BOOT RECORD: OK
 BOOT SECTOR: OK
 
 C:\Documents and Settings\Utente\Menu Avvio\Programmi\Esecuzione automatica\ctfmon.exe Infetto da Trojan.Win32.VB.CS
 * * *  RIMOSSO  * * *
 C:\Program Files\Windows TaskAd\WinSched.exe Infetto da Trojan.Win32.Syncro.B
 * * *  RIMOSSO  * * *
 C:\Programmi\HbTools\Bin\4.8.4.0\HbtGuard.exe Infetto da Trojan.Win32.Hotbar.AB
 * * *  RIMOSSO  * * *
 C:\Programmi\HbTools\Bin\4.8.4.0\HbtHostIE.dll Infetto da Trojan.Win32.Hotbar.I
 Il file sarà spostato nella cartella di quarantena.
 C:\Programmi\HbTools\Bin\4.8.4.0\HbtInstIE.dll Infetto da Trojan.Win32.Hotbar.Y
 * * *  RIMOSSO  * * *
 C:\Programmi\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe Infetto da Trojan.Win32.Hotbar.N
 * * *  RIMOSSO  * * *
 C:\Programmi\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe Infetto da Trojan.Win32.Hotbar.V
 * * *  RIMOSSO  * * *
 C:\Programmi\HbTools\HBTV\HBTV.exe Infetto da Adware.HotBar.C
 Il file sarà spostato nella cartella di quarantena.
 C:\Programmi\HbTools\HBTV\HBTVHelper.dll Infetto da BHO.Hotbar.F
 Il file sarà spostato nella cartella di quarantena.
 C:\Programmi\Horoscopes IT\bin\Horoscopes_IT.dll Infetto da Adware.Starware.J
 Il file sarà spostato nella cartella di quarantena.
 C:\Programmi\MyWebSearch\bar\6.bin\MWSBAR.DLL Infetto da BHO.MyWebSearch.N
 * * *  RIMOSSO  * * *
 C:\Programmi\MyWebSearch\bar\7.bin\F3HISTSW.DLL Infetto da Adware.FunWeb.B
 * * *  RIMOSSO  * * *
 C:\Programmi\MyWebSearch\bar\7.bin\F3SCHMON.EXE Infetto da AdWare.FunWeb.A
 * * *  RIMOSSO  * * *
 C:\Programmi\MyWebSearch\bar\7.bin\M3SLSRCH.EXE Infetto da Trojan.Win32.MyWebSearch.J
 * * *  RIMOSSO  * * *
 C:\Programmi\MyWebSearch\bar\7.bin\M3SRCHMN.EXE Infetto da Trojan.Win32.MyWebSearch.I
 * * *  RIMOSSO  * * *
 C:\Programmi\MyWebSearch\bar\7.bin\MWSBAR.DLL Infetto da BHO.MyWebSearch.N
 Il file sarà spostato nella cartella di quarantena.
 C:\Programmi\MyWebSearch\bar\7.bin\MWSOEMON.EXE Infetto da Trojan.Win32.MyWebSearch.H
 * * *  RIMOSSO  * * *
 C:\Programmi\MyWebSearch\SrchAstt\6.bin\MWSSRCAS.DLL Infetto da BHO.MyWebSearch.P
 * * *  RIMOSSO  * * *
 C:\Programmi\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL Infetto da BHO.MyWebSearch.P
 Il file sarà spostato nella cartella di quarantena.
 C:\Programmi\NewDotNet\newdotnet7_48.dll Infetto da LSP.NewDotNet.G
 Contattare il Supporto Tecnico TG Soft
 C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll Infetto da BHO.Shopper.D
 Il file sarà spostato nella cartella di quarantena.
 C:\Programmi\Starware371\bin\Starware371.dll Infetto da Adware.Starware.J
 * * *  RIMOSSO  * * *
 C:\WINDOWS\Downloaded Program Files\gsa_00673.exe Infetto da Trojan.Win32.Dialer.Gen
 * * *  RIMOSSO  * * *
 C:\WINDOWS\system\smss.exe Infetto da Backdoor.SdBot.KR
 * * *  RIMOSSO  * * *
 C:\WINDOWS\system32\jmgnsjzi.exe Infetto da Trojan.Win32.Hotbar.AB
 * * *  RIMOSSO  * * *
 
 [D:]
 
 
 [E:]
 
 
 [F:]
 MASTER BOOT RECORD: OK
 BOOT SECTOR: OK
 
 F:\Documents and Settings\Utente\Documenti\My Music\music_it.exe Infetto da Adware.Starware.E
 * * *  RIMOSSO  * * *
 F:\Recycled\ctfmon.exe Infetto da Trojan.Win32.VB.CS
 * * *  RIMOSSO  * * *
 
 [G:]
 
 
 [H:]
 
 
 [I:]
 
 
 [J:]
 
 
 Chiavi Registro infette: 13.
 Files Infetti: 27.
 Files Sospetti: 0.
 Files Analizzati: 131331.
 Files Totali: 131331.
 Chiavi Registro rimosse: 13.
 Virus Rimossi: 19.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 06 Set 2007 21:09    Oggetto: |   |  
				| 
 |  
				| ECCO FATTO  : 
 
 
 kk.log
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 06 Set 2007 23:09    Oggetto: |   |  
				| 
 |  
				| Manca il log Autostart di GMER. Comunue, dal log Rootkit che hai inviato non si vede nulla di strano.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 06 Set 2007 23:15    Oggetto: |   |  
				| 
 |  
				| Ah, dimenticavo, hai installato Daemon Tools per caso?. |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 07 Set 2007 17:35    Oggetto: |   |  
				| 
 |  
				| si me l'ha inviato un amico! |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 07 Set 2007 17:38    Oggetto: |   |  
				| 
 |  
				| il log autostar è quello che mi appare appena apro la pagina del programma? in ogni caso sè è quello eccolo qui: ùù.log
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 07 Set 2007 18:08    Oggetto: |   |  
				| 
 |  
				|  	  | miaka8620 ha scritto: |  	  | il log autostar è quello che mi appare appena apro la pagina del programma? | 
 No, quello è il log rootkit.
 
 Vaaaaa bene, repetita iuvant:
 
  	  | Citazione: |  	  | Avvia GMER clicca su > > >
 Clicca su Autostart
 metti il segno di spunta a Show All
 clicca su Scan
 al termine della scansione, clicca su Copy
 Apri il blocco note e premi CTRL+V (oppure clicca su Modifica e poi su Incolla).
 Salva il file e caricalo su http://www.freefilehosting.net
 Posta qui il link che ti viene assegnato.
 | 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 07 Set 2007 18:31    Oggetto: |   |  
				| 
 |  
				|  	  | miaka8620 ha scritto: |  	  | si me l'ha inviato un amico! | 
 
 Quale versione hai?
 Daemon tools usa una tecnica simile ai rootkit per nascondere alcuni files e chiavi di registro perfino agli utenti amministratori di windows.
 Questo file C:\WINDOWS\System32\Drivers\sptd.sys appartiene a Daemon tools. Se non si elimina con ile varie scansioni dovresti disinstallare Daemon tools e togliere tutti i riferimenti.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 07 Set 2007 20:43    Oggetto: |   |  
				| 
 |  
				| bdoriano grazie mille.. ecco l'indirizzo òòò.txt..
 grazie anche a te,sante,lo disinstallo subito, così sono più sicura!!!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 08 Set 2007 10:07    Oggetto: |   |  
				| 
 |  
				| Ciao. Neanche il log autostart presenta cose strane.
 
 Avvia Hijackthis e metti la spunta a sinistra di queste righe:
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programmi\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL (file missing)
 O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Programmi\NewDotNet\newdotnet7_48.dll
 O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm762YYIT
 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
 O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
 O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
 O15 - Trusted Zone: *.cercoporno.com
 O15 - Trusted Zone: *.eros-porno.com
 O15 - Trusted Zone: *.videopornazzi.com
 O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll questa se la conosci non eliminarla (016)
 O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\d4j0le1m1h.dll (file missing)
 O23 - Service: Boonty Games - BOONTY - C:\Programmi\File comuni\BOONTY Shared\Service\Boonty.exe
 Clicca Fix Checked
 Riavvia il PC e posta un log di HJT aggiornato.
 
 Collegati poi a Kaspersky e fai una scansione online:
 http://forum.zeusnews.com/viewtopic.php?t=21705
 Quando sta scaricando i file necessari, disattiva momentaneamente l'antivirus ed eventualmente anche il firewall. Non appena inizia la scansione del PC disconnettiti da internet.
 Alla fine carica il risultato su www.freefilehosting.net, riportando quì il link che ti viene assegnato.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| miaka8620 Mortale pio
 
  
 
 Registrato: 03/09/07 13:15
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 08 Set 2007 15:23    Oggetto: |   |  
				| 
 |  
				| questo è il log agiornato di HJT: C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
 C:\Programmi\Belkin\Software Bluetooth\bin\btwdins.exe
 C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
 C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Programmi\Spyware Doctor\svcntaux.exe
 C:\Programmi\Spyware Doctor\swdsvc.exe
 C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\VEXPLITE\viritsvc.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\WgaTray.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Spyware Doctor\SDTrayApp.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 C:\Programmi\Belkin\Software Bluetooth\BTTray.exe
 C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\Windows Live Toolbar\msn_sl.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
 O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
 O3 - Toolbar: Virgilio Toolbar - {D3403F28-7D39-435F-A8CB-45016C29E48E} - C:\Programmi\Virgilio Toolbar\VirgilioBand.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe" /WinStart
 O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [AWMON] "C:\Programmi\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: C6 Messenger.lnk = C:\Programmi\C6 Messenger\c6Messenger.exe
 O4 - Startup: IMVU.lnk = C:\Programmi\IMVU\IMVUClient.exe
 O4 - Startup: PopTray.lnk = C:\Programmi\PopTray\PopTray.exe
 O4 - Startup: Utilità controllo supporti di Picture Motion Browser.lnk = C:\Programmi\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
 O4 - Global Startup: Album Fast Start.lnk = C:\Programmi\ABMTSR.EXE
 O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: Google Updater.lnk = C:\Programmi\Google\Google Updater\GoogleUpdater.exe
 O8 - Extra context menu item: &MSN Search - res://C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll/search.htm
 O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?6c03903813c3453da27821d1284155a
 O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?6c03903813c3453da27821d1284155a
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie_ctx.htm
 O8 - Extra context menu item: Translate with &Babylon - res://C:\Programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
 O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Programmi\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
 O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie.htm
 O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie.htm
 O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Utente\Menu Avvio\Programmi\IMVU\Run IMVU.lnk
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra button: Alice - {F77CF537-2D54-4054-AB13-6C46B96D5E36} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
 O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://beautifulspaceitaly.spaces.msn.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137177993844
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184166701640
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
 O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\Belkin\Software Bluetooth\bin\btwdins.exe
 O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
 O23 - Service: GoogleDesktopManager - Google - C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
 O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 O23 - Service: StyleXPService - Unknown owner - C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe
 O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas   www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
 
 Ora faccio l'altra scansione online
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |