Jump to content

Welcome to Geeks to Go - Register now for FREE
Geeks To Go is a helpful hub, where thousands of friendly volunteers serve up answers and support. Get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute.
Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more. This message and all ads will be removed once you have signed in.
Create an Account Login to Account

to delete on not to delete? [Solved]


  • This topic is locked This topic is locked

#1
Gianfry

Gianfry

    New Member

  • Member
  • Pip
  • 9 posts
I scanned my pc by runscanner and found many item present in the registry but not in windows file. Can i delete these items? I attache the .log file.
Many thanks for your help.
Gianfry

Attached Files


  • 0

Advertisement


#2
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,266 posts
Greetings and Welcome to The Forums!!

My name is Gringo and I'll be glad to help you with your malware problems.

I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of us

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.




I need to get some reports to get a base to start from so I need you to run these programs first.


-DeFogger-

  • Please download DeFogger to your desktop.

    Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger may ask you to reboot the machine, if it does - click OK
Do not re-enable these drivers until otherwise instructed.


-Security Check-

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


-Download DDS-

  • Please download DDS from one of the links below and save it to your desktop:

    Posted Image
    Download DDS and save it to your desktop

    Link1
    Link2
    Link3


    • Double-Click on dds.scr and a command window will appear. This is normal.
    • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply

information and logs

  • In your next post I need the following

  • both reports from DDS
  • report from security check
  • let me know of any problems you may have had

Gringo

  • 0

#3
Gianfry

Gianfry

    New Member

  • Member
  • Pip
  • 9 posts
I post the file requested:
- Checkup.txt
Results of screen317's Security Check version 0.99.53
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Norman Security Suite
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Ad-Aware
Out of date HijackThis installed!
SpywareBlaster 4.4
Spybot - Search & Destroy
Malwarebytes Anti-Malware versione 1.65.0.1400
HijackThis 1.99.1
Hijackthis 1.99.1
CCleaner
Wise Registry Cleaner 5.9.1
Java version out of Date!
Adobe Flash Player 11.4.402.287
Mozilla Firefox (3.6.13) Firefox out of Date!
Mozilla Thunderbird (2.0.0 Thunderbird out of Date!
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Ad-Aware AAWService.exe is disabled!
Ad-Aware AAWTray.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 3%
````````````````````End of Log``````````````````````
- Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-10-19.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 18-06-2006 21:56:33
System Uptime: 27-10-2012 8:38:29 (1 hours ago)
.
Motherboard: MICRO-STAR INTERNATIONAL CO., LTD | | MS-7125
Processor: AMD Athlon™ 64 X2 Dual Core Processor 4200+ | Socket 939 | 2211/201mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 233 GiB total, 34,433 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\CB9E8E10DC00
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\CB9E8E10DC00
Service: NIC1394
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_058C1462&REV_15\4&14AECDB0&0&0060
Manufacturer: Marvell
Name: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
PNP Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_058C1462&REV_15\4&14AECDB0&0&0060
Service: yukonwxp
.
==== System Restore Points ===================
.
RP1580: 29-07-2012 9:05:16 - Software Distribution Service 3.0
RP1581: 30-07-2012 9:17:55 - Punto di arresto del sistema
RP1582: 31-07-2012 11:06:22 - Software Distribution Service 3.0
RP1583: 01-08-2012 11:52:36 - Punto di arresto del sistema
RP1584: 02-08-2012 10:34:29 - Software Distribution Service 3.0
RP1585: 03-08-2012 11:10:05 - Software Distribution Service 3.0
RP1586: 04-08-2012 13:16:02 - Punto di arresto del sistema
RP1587: 06-08-2012 11:01:23 - Software Distribution Service 3.0
RP1588: 07-08-2012 11:01:43 - Punto di arresto del sistema
RP1589: 07-08-2012 16:20:16 - Software Distribution Service 3.0
RP1590: 07-08-2012 18:58:04 - RegCure Pro Backup
RP1591: 08-08-2012 10:33:52 - RegCure Pro Backup
RP1592: 09-08-2012 10:50:18 - Software Distribution Service 3.0
RP1593: 10-08-2012 11:11:25 - Punto di arresto del sistema
RP1594: 12-08-2012 12:11:10 - Software Distribution Service 3.0
RP1595: 13-08-2012 12:14:39 - Punto di arresto del sistema
RP1596: 14-08-2012 9:18:08 - Software Distribution Service 3.0
RP1597: 14-08-2012 12:52:28 - Software Distribution Service 3.0
RP1598: 14-08-2012 12:59:54 - Software Distribution Service 3.0
RP1599: 14-08-2012 14:02:20 - Software Distribution Service 3.0
RP1600: 14-08-2012 14:17:49 - Software Distribution Service 3.0
RP1601: 16-08-2012 10:02:07 - Software Distribution Service 3.0
RP1602: 16-08-2012 10:46:02 - Software Distribution Service 3.0
RP1603: 17-08-2012 11:04:47 - Punto di arresto del sistema
RP1604: 21-08-2012 10:29:48 - Software Distribution Service 3.0
RP1605: 27-08-2012 8:48:13 - Software Distribution Service 3.0
RP1606: 28-08-2012 9:32:49 - Software Distribution Service 3.0
RP1607: 29-08-2012 13:25:55 - Punto di arresto del sistema
RP1608: 30-08-2012 8:50:37 - Software Distribution Service 3.0
RP1609: 31-08-2012 8:56:17 - Punto di arresto del sistema
RP1610: 01-09-2012 10:14:21 - Software Distribution Service 3.0
RP1611: 02-09-2012 2:21:19 - Software Distribution Service 3.0
RP1612: 02-09-2012 8:58:08 - Installed Java™ 6 Update 35
RP1613: 03-09-2012 9:43:30 - Software Distribution Service 3.0
RP1614: 03-09-2012 10:41:23 - RegCure Pro Backup
RP1615: 03-09-2012 11:26:29 - RegCure Pro Backup
RP1616: 03-09-2012 12:56:38 - Criteri di protezione dall'accesso di codice macchina di .NET Framework installato
RP1617: 03-09-2012 15:13:07 - Installato Punto di ripristino InstallShield
RP1618: 03-09-2012 15:15:42 - Installed ABBYY FineReader 6.0 Sprint
RP1619: 03-09-2012 15:16:48 - Installato EPSON Web-To-Page
RP1620: 03-09-2012 16:33:19 - DirectX installato
RP1621: 03-09-2012 16:55:15 - Software Distribution Service 3.0
RP1622: 03-09-2012 17:36:53 - Configurato Edilclima Programmi
RP1623: 04-09-2012 9:26:16 - Software Distribution Service 3.0
RP1624: 04-09-2012 16:18:57 - Software Distribution Service 3.0
RP1625: 04-09-2012 16:49:02 - Installato Edilclima Programmi
RP1626: 04-09-2012 18:49:31 - Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - ITA rimosso
RP1627: 05-09-2012 7:53:28 - Installed Microsoft .NET Compact Framework 2.0
RP1628: 05-09-2012 10:20:05 - Reimage Repair Restore Point
RP1629: 05-09-2012 15:09:23 - Software Distribution Service 3.0
RP1630: 05-09-2012 15:18:55 - Software Distribution Service 3.0
RP1631: 05-09-2012 16:02:04 - Software Distribution Service 3.0
RP1632: 05-09-2012 20:00:08 - Software Distribution Service 3.0
RP1633: 06-09-2012 9:30:00 - Software Distribution Service 3.0
RP1634: 06-09-2012 9:32:00 - Software Distribution Service 3.0
RP1635: 06-09-2012 10:24:50 - Installed Microsoft Fix it 50123
RP1636: 06-09-2012 10:27:05 - Software Distribution Service 3.0
RP1637: 06-09-2012 10:43:06 - Software Distribution Service 3.0
RP1638: 06-09-2012 11:04:12 - Software Distribution Service 3.0
RP1639: 06-09-2012 13:00:28 - Installed Windows KB954550-v5.
RP1640: 06-09-2012 13:00:38 - Driver della stampante Microsoft XPS Document Writer installato
RP1641: 06-09-2012 13:00:51 - Driver della stampante Microsoft XPS Document Writer installato
RP1642: 06-09-2012 13:03:04 - Installed %1 %2.
RP1643: 06-09-2012 13:07:42 - Software Distribution Service 3.0
RP1644: 06-09-2012 15:31:10 - Configurato Edilclima Programmi
RP1645: 07-09-2012 10:08:36 - Software Distribution Service 3.0
RP1646: 07-09-2012 16:41:34 - HP Deskjet 1280 installato
RP1647: 08-09-2012 10:26:30 - Software Distribution Service 3.0
RP1648: 08-09-2012 11:47:21 - Software Distribution Service 3.0
RP1649: 08-09-2012 12:06:01 - Installed Microsoft Fix it 50468
RP1650: 08-09-2012 13:00:46 - DirectX installato
RP1651: 09-09-2012 13:30:33 - Punto di arresto del sistema
RP1652: 10-09-2012 7:09:47 - Software Distribution Service 3.0
RP1653: 11-09-2012 9:38:46 - Software Distribution Service 3.0
RP1654: 11-09-2012 9:43:38 - Software Distribution Service 3.0
RP1655: 12-09-2012 13:24:10 - Punto di arresto del sistema
RP1656: 12-09-2012 17:39:01 - Software Distribution Service 3.0
RP1657: 12-09-2012 20:08:16 - Software Distribution Service 3.0
RP1658: 13-09-2012 11:24:21 - Software Distribution Service 3.0
RP1659: 14-09-2012 12:39:30 - Punto di arresto del sistema
RP1660: 14-09-2012 19:32:38 - Software Distribution Service 3.0
RP1661: 14-09-2012 20:16:19 - RegCure Pro Backup
RP1662: 16-09-2012 10:45:05 - Software Distribution Service 3.0
RP1663: 16-09-2012 16:11:37 - Software Distribution Service 3.0
RP1664: 17-09-2012 16:28:00 - Punto di arresto del sistema
RP1665: 18-09-2012 8:54:02 - Software Distribution Service 3.0
RP1666: 19-09-2012 13:30:19 - Punto di arresto del sistema
RP1667: 20-09-2012 8:20:55 - Software Distribution Service 3.0
RP1668: 21-09-2012 11:02:59 - Software Distribution Service 3.0
RP1669: 22-09-2012 9:21:32 - Software Distribution Service 3.0
RP1670: 22-09-2012 16:44:56 - Software Distribution Service 3.0
RP1671: 22-09-2012 19:10:16 - Installazione di Nitro Reader 2 completata
RP1672: 24-09-2012 8:38:11 - Software Distribution Service 3.0
RP1673: 25-09-2012 11:11:05 - Punto di arresto del sistema
RP1674: 26-09-2012 8:51:24 - Software Distribution Service 3.0
RP1675: 27-09-2012 11:27:01 - Punto di arresto del sistema
RP1676: 28-09-2012 8:55:52 - Software Distribution Service 3.0
RP1677: 29-09-2012 16:44:58 - Software Distribution Service 3.0
RP1678: 29-09-2012 18:02:15 - Removed PerfectDisk 11 Professional.
RP1679: 30-09-2012 2:18:49 - Software Distribution Service 3.0
RP1680: 30-09-2012 16:43:10 - Software Distribution Service 3.0
RP1681: 30-09-2012 17:51:32 - RegCure Pro Backup
RP1682: 01-10-2012 9:33:25 - Software Distribution Service 3.0
RP1683: 01-10-2012 20:18:09 - Software Distribution Service 3.0
RP1684: 02-10-2012 9:04:33 - Software Distribution Service 3.0
RP1685: 03-10-2012 8:26:51 - Software Distribution Service 3.0
RP1686: 04-10-2012 8:49:24 - Punto di arresto del sistema
RP1687: 05-10-2012 15:46:45 - Software Distribution Service 3.0
RP1688: 06-10-2012 16:20:07 - Punto di arresto del sistema
RP1689: 07-10-2012 2:25:59 - Software Distribution Service 3.0
RP1690: 07-10-2012 9:27:27 - Software Distribution Service 3.0
RP1691: 08-10-2012 9:26:29 - Software Distribution Service 3.0
RP1692: 08-10-2012 19:19:01 - RegCure Pro Backup
RP1693: 10-10-2012 9:42:28 - Software Distribution Service 3.0
RP1694: 10-10-2012 17:08:41 - Software Distribution Service 3.0
RP1695: 11-10-2012 17:51:38 - Punto di arresto del sistema
RP1696: 12-10-2012 10:12:22 - Software Distribution Service 3.0
RP1697: 13-10-2012 11:07:23 - Punto di arresto del sistema
RP1698: 15-10-2012 8:52:24 - Software Distribution Service 3.0
RP1699: 15-10-2012 11:56:59 - Driver della stampante PDF24 PDF installato
RP1700: 16-10-2012 9:17:19 - Software Distribution Service 3.0
RP1701: 17-10-2012 8:31:35 - Software Distribution Service 3.0
RP1702: 18-10-2012 9:56:07 - Punto di arresto del sistema
RP1703: 19-10-2012 10:16:00 - Software Distribution Service 3.0
RP1704: 20-10-2012 8:36:53 - Installed Java™ 6 Update 37
RP1705: 20-10-2012 20:17:32 - Installed PerfectDisk 12.5 Professional.
RP1706: 21-10-2012 2:20:51 - Software Distribution Service 3.0
RP1707: 21-10-2012 8:39:18 - Software Distribution Service 3.0
RP1708: 22-10-2012 8:39:12 - Software Distribution Service 3.0
RP1709: 22-10-2012 8:39:57 - RegCure Pro Backup
RP1710: 23-10-2012 8:48:55 - Software Distribution Service 3.0
RP1711: 24-10-2012 11:05:12 - Software Distribution Service 3.0
RP1712: 24-10-2012 12:58:08 - Installazione di Nitro Reader 2 completata
RP1713: 25-10-2012 14:32:59 - Punto di arresto del sistema
RP1714: 26-10-2012 14:53:50 - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
3F Filippi catalogue 03 / 2011
ABB DOC2
ABB Software Desktop 2
ABB Sophie 1.1.0.0
ABBIQ 3.0
Able2Doc v5.0
Ad-Aware
Adenix S.M.A.R.T. Explorer 1.0
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Shockwave Player 11.5
Aggiornamento critico per Windows Media Player 11 (KB959772)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB931768)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB933566)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB937143)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB938127)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB939653)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB942615)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB944533)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB950759)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB953838)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB956390)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB958215)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB960714)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB961260)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB963027)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB969897)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB972260)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB974455)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB976325)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2183461)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2360131)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2416400)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2482017)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2497640)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2510531)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2530548)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2544521)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2559049)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2586448)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2618444)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2647516)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2675157)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2699988)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2722913)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2744842)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB971961)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB976325)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB978207)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB981332)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB982381)
Aggiornamento della protezione per Windows Media Player (KB2378111)
Aggiornamento della protezione per Windows Media Player (KB952069)
Aggiornamento della protezione per Windows Media Player (KB954155)
Aggiornamento della protezione per Windows Media Player (KB968816)
Aggiornamento della protezione per Windows Media Player (KB973540)
Aggiornamento della protezione per Windows Media Player (KB975558)
Aggiornamento della protezione per Windows Media Player (KB978695)
Aggiornamento della protezione per Windows Media Player 10 (KB936782)
Aggiornamento della protezione per Windows Media Player 11 (KB954154)
Aggiornamento della protezione per Windows XP (KB2079403)
Aggiornamento della protezione per Windows XP (KB2115168)
Aggiornamento della protezione per Windows XP (KB2121546)
Aggiornamento della protezione per Windows XP (KB2124261)
Aggiornamento della protezione per Windows XP (KB2160329)
Aggiornamento della protezione per Windows XP (KB2229593)
Aggiornamento della protezione per Windows XP (KB2259922)
Aggiornamento della protezione per Windows XP (KB2279986)
Aggiornamento della protezione per Windows XP (KB2286198)
Aggiornamento della protezione per Windows XP (KB2290570)
Aggiornamento della protezione per Windows XP (KB2296011)
Aggiornamento della protezione per Windows XP (KB2296199)
Aggiornamento della protezione per Windows XP (KB2347290)
Aggiornamento della protezione per Windows XP (KB2360937)
Aggiornamento della protezione per Windows XP (KB2387149)
Aggiornamento della protezione per Windows XP (KB2393802)
Aggiornamento della protezione per Windows XP (KB2412687)
Aggiornamento della protezione per Windows XP (KB2419632)
Aggiornamento della protezione per Windows XP (KB2423089)
Aggiornamento della protezione per Windows XP (KB2436673)
Aggiornamento della protezione per Windows XP (KB2440591)
Aggiornamento della protezione per Windows XP (KB2443105)
Aggiornamento della protezione per Windows XP (KB2476490)
Aggiornamento della protezione per Windows XP (KB2476687)
Aggiornamento della protezione per Windows XP (KB2478960)
Aggiornamento della protezione per Windows XP (KB2478971)
Aggiornamento della protezione per Windows XP (KB2479628)
Aggiornamento della protezione per Windows XP (KB2479943)
Aggiornamento della protezione per Windows XP (KB2481109)
Aggiornamento della protezione per Windows XP (KB2483185)
Aggiornamento della protezione per Windows XP (KB2485376)
Aggiornamento della protezione per Windows XP (KB2485663)
Aggiornamento della protezione per Windows XP (KB2503658)
Aggiornamento della protezione per Windows XP (KB2503665)
Aggiornamento della protezione per Windows XP (KB2506212)
Aggiornamento della protezione per Windows XP (KB2506223)
Aggiornamento della protezione per Windows XP (KB2507618)
Aggiornamento della protezione per Windows XP (KB2507938)
Aggiornamento della protezione per Windows XP (KB2508272)
Aggiornamento della protezione per Windows XP (KB2508429)
Aggiornamento della protezione per Windows XP (KB2509553)
Aggiornamento della protezione per Windows XP (KB2511455)
Aggiornamento della protezione per Windows XP (KB2524375)
Aggiornamento della protezione per Windows XP (KB2535512)
Aggiornamento della protezione per Windows XP (KB2536276-v2)
Aggiornamento della protezione per Windows XP (KB2536276)
Aggiornamento della protezione per Windows XP (KB2544893-v2)
Aggiornamento della protezione per Windows XP (KB2544893)
Aggiornamento della protezione per Windows XP (KB2555917)
Aggiornamento della protezione per Windows XP (KB2562937)
Aggiornamento della protezione per Windows XP (KB2566454)
Aggiornamento della protezione per Windows XP (KB2567053)
Aggiornamento della protezione per Windows XP (KB2567680)
Aggiornamento della protezione per Windows XP (KB2570222)
Aggiornamento della protezione per Windows XP (KB2570947)
Aggiornamento della protezione per Windows XP (KB2584146)
Aggiornamento della protezione per Windows XP (KB2585542)
Aggiornamento della protezione per Windows XP (KB2592799)
Aggiornamento della protezione per Windows XP (KB2598479)
Aggiornamento della protezione per Windows XP (KB2603381)
Aggiornamento della protezione per Windows XP (KB2618451)
Aggiornamento della protezione per Windows XP (KB2619339)
Aggiornamento della protezione per Windows XP (KB2620712)
Aggiornamento della protezione per Windows XP (KB2621440)
Aggiornamento della protezione per Windows XP (KB2624667)
Aggiornamento della protezione per Windows XP (KB2631813)
Aggiornamento della protezione per Windows XP (KB2633171)
Aggiornamento della protezione per Windows XP (KB2639417)
Aggiornamento della protezione per Windows XP (KB2641653)
Aggiornamento della protezione per Windows XP (KB2646524)
Aggiornamento della protezione per Windows XP (KB2647518)
Aggiornamento della protezione per Windows XP (KB2653956)
Aggiornamento della protezione per Windows XP (KB2655992)
Aggiornamento della protezione per Windows XP (KB2659262)
Aggiornamento della protezione per Windows XP (KB2660465)
Aggiornamento della protezione per Windows XP (KB2661637)
Aggiornamento della protezione per Windows XP (KB2676562)
Aggiornamento della protezione per Windows XP (KB2685939)
Aggiornamento della protezione per Windows XP (KB2686509)
Aggiornamento della protezione per Windows XP (KB2691442)
Aggiornamento della protezione per Windows XP (KB2695962)
Aggiornamento della protezione per Windows XP (KB2698365)
Aggiornamento della protezione per Windows XP (KB2705219)
Aggiornamento della protezione per Windows XP (KB2707511)
Aggiornamento della protezione per Windows XP (KB2709162)
Aggiornamento della protezione per Windows XP (KB2712808)
Aggiornamento della protezione per Windows XP (KB2718523)
Aggiornamento della protezione per Windows XP (KB2719985)
Aggiornamento della protezione per Windows XP (KB2723135)
Aggiornamento della protezione per Windows XP (KB2724197)
Aggiornamento della protezione per Windows XP (KB2731847)
Aggiornamento della protezione per Windows XP (KB923561)
Aggiornamento della protezione per Windows XP (KB938464)
Aggiornamento della protezione per Windows XP (KB946648)
Aggiornamento della protezione per Windows XP (KB950762)
Aggiornamento della protezione per Windows XP (KB950974)
Aggiornamento della protezione per Windows XP (KB951066)
Aggiornamento della protezione per Windows XP (KB951376-v2)
Aggiornamento della protezione per Windows XP (KB951748)
Aggiornamento della protezione per Windows XP (KB952004)
Aggiornamento della protezione per Windows XP (KB952954)
Aggiornamento della protezione per Windows XP (KB953155)
Aggiornamento della protezione per Windows XP (KB953839)
Aggiornamento della protezione per Windows XP (KB954211)
Aggiornamento della protezione per Windows XP (KB954459)
Aggiornamento della protezione per Windows XP (KB954600)
Aggiornamento della protezione per Windows XP (KB955069)
Aggiornamento della protezione per Windows XP (KB956391)
Aggiornamento della protezione per Windows XP (KB956572)
Aggiornamento della protezione per Windows XP (KB956744)
Aggiornamento della protezione per Windows XP (KB956802)
Aggiornamento della protezione per Windows XP (KB956803)
Aggiornamento della protezione per Windows XP (KB956841)
Aggiornamento della protezione per Windows XP (KB956844)
Aggiornamento della protezione per Windows XP (KB957095)
Aggiornamento della protezione per Windows XP (KB957097)
Aggiornamento della protezione per Windows XP (KB958644)
Aggiornamento della protezione per Windows XP (KB958687)
Aggiornamento della protezione per Windows XP (KB958690)
Aggiornamento della protezione per Windows XP (KB958869)
Aggiornamento della protezione per Windows XP (KB959426)
Aggiornamento della protezione per Windows XP (KB960225)
Aggiornamento della protezione per Windows XP (KB960715)
Aggiornamento della protezione per Windows XP (KB960803)
Aggiornamento della protezione per Windows XP (KB960859)
Aggiornamento della protezione per Windows XP (KB961371)
Aggiornamento della protezione per Windows XP (KB961373)
Aggiornamento della protezione per Windows XP (KB961501)
Aggiornamento della protezione per Windows XP (KB968537)
Aggiornamento della protezione per Windows XP (KB969059)
Aggiornamento della protezione per Windows XP (KB969898)
Aggiornamento della protezione per Windows XP (KB969947)
Aggiornamento della protezione per Windows XP (KB970238)
Aggiornamento della protezione per Windows XP (KB970430)
Aggiornamento della protezione per Windows XP (KB970483)
Aggiornamento della protezione per Windows XP (KB971468)
Aggiornamento della protezione per Windows XP (KB971486)
Aggiornamento della protezione per Windows XP (KB971557)
Aggiornamento della protezione per Windows XP (KB971633)
Aggiornamento della protezione per Windows XP (KB971657)
Aggiornamento della protezione per Windows XP (KB971961)
Aggiornamento della protezione per Windows XP (KB972270)
Aggiornamento della protezione per Windows XP (KB973346)
Aggiornamento della protezione per Windows XP (KB973354)
Aggiornamento della protezione per Windows XP (KB973507)
Aggiornamento della protezione per Windows XP (KB973525)
Aggiornamento della protezione per Windows XP (KB973869)
Aggiornamento della protezione per Windows XP (KB973904)
Aggiornamento della protezione per Windows XP (KB974112)
Aggiornamento della protezione per Windows XP (KB974318)
Aggiornamento della protezione per Windows XP (KB974392)
Aggiornamento della protezione per Windows XP (KB974571)
Aggiornamento della protezione per Windows XP (KB975025)
Aggiornamento della protezione per Windows XP (KB975254)
Aggiornamento della protezione per Windows XP (KB975467)
Aggiornamento della protezione per Windows XP (KB975560)
Aggiornamento della protezione per Windows XP (KB975561)
Aggiornamento della protezione per Windows XP (KB975562)
Aggiornamento della protezione per Windows XP (KB975713)
Aggiornamento della protezione per Windows XP (KB977165)
Aggiornamento della protezione per Windows XP (KB977816)
Aggiornamento della protezione per Windows XP (KB977914)
Aggiornamento della protezione per Windows XP (KB978037)
Aggiornamento della protezione per Windows XP (KB978251)
Aggiornamento della protezione per Windows XP (KB978262)
Aggiornamento della protezione per Windows XP (KB978338)
Aggiornamento della protezione per Windows XP (KB978542)
Aggiornamento della protezione per Windows XP (KB978601)
Aggiornamento della protezione per Windows XP (KB978706)
Aggiornamento della protezione per Windows XP (KB979309)
Aggiornamento della protezione per Windows XP (KB979482)
Aggiornamento della protezione per Windows XP (KB979559)
Aggiornamento della protezione per Windows XP (KB979683)
Aggiornamento della protezione per Windows XP (KB979687)
Aggiornamento della protezione per Windows XP (KB980195)
Aggiornamento della protezione per Windows XP (KB980218)
Aggiornamento della protezione per Windows XP (KB980232)
Aggiornamento della protezione per Windows XP (KB980436)
Aggiornamento della protezione per Windows XP (KB981322)
Aggiornamento della protezione per Windows XP (KB981852)
Aggiornamento della protezione per Windows XP (KB981957)
Aggiornamento della protezione per Windows XP (KB981997)
Aggiornamento della protezione per Windows XP (KB982132)
Aggiornamento della protezione per Windows XP (KB982214)
Aggiornamento della protezione per Windows XP (KB982665)
Aggiornamento della protezione per Windows XP (KB982802)
Aggiornamento della sicurezza per Microsoft Windows (KB2564958)
Aggiornamento di Windows XP (KB943729)
Aggiornamento per Microsoft Windows (KB971513)
Aggiornamento per Windows Internet Explorer 7 (KB976749)
Aggiornamento per Windows Internet Explorer 8 (KB2447568)
Aggiornamento per Windows Internet Explorer 8 (KB2598845)
Aggiornamento per Windows Internet Explorer 8 (KB2632503)
Aggiornamento per Windows Internet Explorer 8 (KB975364)
Aggiornamento per Windows Internet Explorer 8 (KB976662)
Aggiornamento per Windows Internet Explorer 8 (KB978506)
Aggiornamento per Windows Internet Explorer 8 (KB980182)
Aggiornamento per Windows Internet Explorer 8 (KB982632)
Aggiornamento per Windows XP (KB2141007)
Aggiornamento per Windows XP (KB2345886)
Aggiornamento per Windows XP (KB2467659)
Aggiornamento per Windows XP (KB2492386)
Aggiornamento per Windows XP (KB2541763)
Aggiornamento per Windows XP (KB2616676-v2)
Aggiornamento per Windows XP (KB2616676)
Aggiornamento per Windows XP (KB2641690)
Aggiornamento per Windows XP (KB2661254-v2)
Aggiornamento per Windows XP (KB2718704)
Aggiornamento per Windows XP (KB2736233)
Aggiornamento per Windows XP (KB2749655)
Aggiornamento per Windows XP (KB951072-v2)
Aggiornamento per Windows XP (KB951978)
Aggiornamento per Windows XP (KB955759)
Aggiornamento per Windows XP (KB955839)
Aggiornamento per Windows XP (KB961503)
Aggiornamento per Windows XP (KB967715)
Aggiornamento per Windows XP (KB968389)
Aggiornamento per Windows XP (KB971029)
Aggiornamento per Windows XP (KB971737)
Aggiornamento per Windows XP (KB973687)
Aggiornamento per Windows XP (KB973815)
Aggiornamento rapido per Windows Internet Explorer 7 (KB947864)
Aggiornamento rapido per Windows XP (KB2158563)
Aggiornamento rapido per Windows XP (KB2443685)
Aggiornamento rapido per Windows XP (KB2570791)
Aggiornamento rapido per Windows XP (KB2633952)
Aggiornamento rapido per Windows XP (KB2756822)
Aggiornamento rapido per Windows XP (KB942288-v3)
Aggiornamento rapido per Windows XP (KB952287)
Aggiornamento rapido per Windows XP (KB961118)
Aggiornamento rapido per Windows XP (KB970653-v3)
Aggiornamento rapido per Windows XP (KB976098-v2)
Aggiornamento rapido per Windows XP (KB979306)
Aggiornamento rapido per Windows XP (KB981793)
AudioGenie
Avanquest update
Beghelli catalogue 03 / 2011
Bing Bar
Carambis Driver Updater
Catalogo multimediale 5.4
CCleaner
Cda Product Service - shared component
Compatibility Pack for the 2007 Office system
CURVES1
CutePDF Writer 2.7
Data Doctor Recovery Pen Drive (Demo)
Disano catalogue 07 / 2011
DLux 5.4
DriverFinder
DWG TrueView 2013
Edilclima - Classificazione energetica preliminare
Edilclima - Tariffe VVF
Edilclima Programmi
Epson Easy Photo Print 2
EPSON Scan
Epson Stylus SX210_SX410_TX210_TX410 Manuale
EPSON SX410 Series Printer Uninstall
ER Mapper ECW JPEG 2000 Plug-in for Firefox [3.4.0.242]
ER Mapper ECW JPEG 2000 Plug-in for Internet Explorer [3.4.0.242]
ERUNT 1.1j
EVEREST Home Edition v2.20
ffdshow [rev 3128] [2009-11-08]
FileZilla Client 3.3.4.1
Final Media Player 2010
FreshDiagnose
FreshUI
FxFoto by Triscape
getPlus® for Adobe
Gewiss catalogue 03 / 2011
GoFTP v2
Google Chrome
Google Update Helper
Hard Disk Low Level Format Tool 2.36 build 1181
Hijackthis 1.99.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
HP Deskjet 1280
HWiNFO32 Version 3.43
IDEAL Administration
IHMC CmapTools v4.09
IIS UrlScan Tool 2.0 (Uninstall)
Image Web Server IE Plugins 2,0,0,104
ImageConverter Plus 7.0
InfoFind 1.00.0764
Java Auto Updater
LG Internet Kit
LG PC Sync
LG Phone Manager
Librerie Progem agosto 2006
Librerie Progem giugno 2006
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
Liveupdate4
Lizardtech DjVu Control (autoinstall)
Logitech SetPoint 6.32
Malwarebytes Anti-Malware versione 1.65.0.1400
MemoRex - Disinstallazione
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - ITA
Microsoft .NET Framework 3.5 - Language Pack SP1 (italiano)
Microsoft .NET Framework 3.5 Language Pack SP1 - ita
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile - Language Pack (ITA)
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Access database engine 2007 (Italian)
Microsoft Security Client
Microsoft Security Essentials
Microsoft SQL Server Compact 4.0 ITA
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Motorola Phone Tools
Mozilla Firefox (3.6.13)
Mozilla Thunderbird (2.0.0.12)
MSI VideoGenie Application
MV RegClean 5.0 English
Net Controller 1.0.2
Nitro Reader 2
Norman Virus Control
Norton SystemWorks 2005 Premier
Norton SystemWorks 2005 Premier (Symantec Corporation)
NVIDIA Drivers
NVIDIA Install Application
NVIDIA nView Desktop Manager
NVIDIA Update Components
OTC1
Pacchetto provider Microsoft servizio crittografia smart card di base
Pannello di controllo NVIDIA 301.42
PC Wizard 2012.2.11
PDF24 Creator 4.9.0
Perfect Fix version 2011.01.01
PerfectDisk 12.5 Professional
Progem 2006 2.0
PSPad editor
Quest3D Viewers 2.5a2
QuizFaber v2.10
RegCompact Pro 2.6.7
RegCure Pro
Registry Easy v5.6
RegZooka
Reimage Repair
Roguescanfix 1.5
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile - Language Pack (ITA) (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile - Language Pack (ITA) (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Windows Search 4 - KB963093
Sintalex PARSIFAL 626-quinquies
SIW version 2008-07-15
SoftPerfect Network Protocol Analyzer 2.6
Software per stampante EPSON
Spybot - Search & Destroy
SpywareBlaster 4.4
SSC Service Utility v4.20
Stellar Phoenix NTFS 2.2
Stime perizie pareri
Super-Charger
Total Commander (Remove or Repair)
Triscape FxFoto
TurboPOI 1.1
Unlocker 1.8.6
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
vanBasco's Karaoke Player
VsdSize 2.9
WebFldrs XP
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Essentials
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
WinRAR gestione archivi
WinZip
Wise Registry Cleaner 5.9.1
Wubi
XML Paper Specification Shared Components Language Pack 1.0
XML Paper Specification Shared Components Pack 1.0
.
==== End Of File ===========================
- dds.txt
DDS (Ver_2012-10-19.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_37
Run by Pezzola at 9:26:14 on 2012-10-27
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1194 [GMT 2:00]
.
AV: Norman Security Suite *Enabled/Updated* {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: Sygate Personal Firewall *Enabled*
.
============== Running Processes ================
.
C:\Norman\Npm\bin\ELOGSVC.EXE
C:\Norman\Ngs\Bin\Nnf.exe
C:\Norman\Ngs\Bin\Nprosec.exe
c:\Programmi\Microsoft Security Client\MsMpEng.exe
C:\Norman\Npm\Bin\Zanda.exe
C:\Norman\npm\bin\nvoy.exe
C:\Programmi\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Acronis\Agent\agent.exe
C:\Programmi\Acronis\BackupServer\backupserver.exe
C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
C:\Documents and Settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\WINDOWS\System32\GEARSec.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Norman\Nvc\bin\nhs.exe
C:\Programmi\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
C:\Programmi\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Documents and Settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmi\UPHClean\uphclean.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Programmi\Unlocker\UnlockerAssistant.exe
C:\Programmi\Acronis\TrueImageWorkstation\TimounterMonitor.exe
C:\Programmi\File comuni\Acronis\Schedule2\schedhlp.exe
C:\Programmi\Logitech\SetPointP\SetPoint.exe
C:\Programmi\Hewlett-Packard\HP Deskjet 1280\Toolbox\mpm.exe
C:\Programmi\RAMpage\RAMpage.exe
C:\Programmi\PDF24\pdf24.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\MemoRex\MemoRex.exe
C:\Programmi\File comuni\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Programmi\File comuni\Raxco\Shared\PDEngine.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Norman\Npm\Bin\scheduler.exe
C:\Norman\Npm\Bin\Njeeves.exe
C:\WINDOWS\System32\alg.exe
C:\Norman\nse\bin\NSESVC.EXE
C:\Norman\Nvc\bin\nvcoas.exe
C:\Documents and Settings\Pezzola\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pezzola\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pezzola\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pezzola\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pezzola\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Programmi\Microsoft\BingBar\7.1.391.0\SeaPort.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.it/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://ie.search.msn.com
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: DIALux 3.1 ULDBrowserHelper Class: {69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2} - c:\programmi\dialux\DLXShellExtension.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\programmi\java\jre6\bin\ssv.dll
BHO: Guida per l'accesso a Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\programmi\file comuni\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - c:\programmi\epson software\easy photo print\EPTBL.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\programmi\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\programmi\google\googletoolbarnotifier\2.0.301.7164\swg.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\programmi\microsoft\bingbar\7.1.391.0\BingExt.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\programmi\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\programmi\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - c:\programmi\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - c:\programmi\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: &Google: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
TB: &Google: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
TB: EPSON Web-To-Page: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - c:\programmi\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - c:\programmi\epson software\easy photo print\EPTBL.dll
mRun: [SmcService] c:\progra~1\sygate\spf\smc.exe -startgui
mRun: [UnlockerAssistant] "c:\programmi\unlocker\UnlockerAssistant.exe"
mRun: [MemoREX] "c:\programmi\memorex\MemoRexStart.exe"
mRun: [AcronisTimounterMonitor] c:\programmi\acronis\trueimageworkstation\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\programmi\file comuni\acronis\schedule2\schedhlp.exe"
mRun: [EvtMgr6] c:\programmi\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [Reimage: Post-Reboot] c:\reimageundo\postreboot\PR.lnk
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [HPWS myPrintMileage Agent] c:\programmi\hewlett-packard\hp deskjet 1280\toolbox\mpm.exe
mRun: [RAMpage] "c:\programmi\rampage\rampage.exe" m=28 t=500 lg p="c:\programmi\rampage\RAMpageConfig.exe"
mRun: [PDFPrint] c:\programmi\pdf24\pdf24.exe
mRun: [SunJavaUpdateSched] "c:\programmi\file comuni\java\java update\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\fileco~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\pezzola\menuav~1\progra~1\esecuz~1\erunta~1.lnk - c:\programmi\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\pezzola\menuav~1\progra~1\esecuz~1\erunta~1.lnk - c:\programmi\erunt\AUTOBACK.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108839
mPolicies-Explorer: NoDriveAutoRun = dword:67108839
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: Converti destinazione link in file PDF esistente - <no file>
IE: Converti i link selezionati in Adobe PDF - <no file>
IE: Converti i link selezionati in file PDF esistente - <no file>
IE: Converti nel file PDF esistente - <no file>
IE: Converti selezione in file PDF esistente - <no file>
IE: E&sporta in Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\programmi\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\programmi\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmi\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1342891569406
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342460922875
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
TCP: NameServer = 192.168.109.1
TCP: Interfaces\{B5BDC287-0999-46D3-B695-8375C1C9994F} : DHCPNameServer = 192.168.109.1
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\programmi\belarc\advisor\system\BAVoilaX.dll
Handler: bw+0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw+0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw-0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw-0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw00 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw00s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw10 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw10s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw20 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw20s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw30 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw30s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw40 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw40s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw50 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw50s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw60 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw60s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw70 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw70s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw80 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw80s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw90 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bw90s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwa0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwa0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwb0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwb0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwc0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwc0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwd0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwd0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwe0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwe0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwf0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwf0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwg0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwg0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwh0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwh0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwi0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwi0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwj0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwj0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwk0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwk0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwl0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwl0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwm0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwm0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwn0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwn0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwo0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwo0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwp0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwp0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwq0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwq0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwr0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwr0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bws0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bws0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwt0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwt0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwu0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwu0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwv0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwv0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bww0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bww0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwx0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwx0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwy0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwy0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwz0 - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: bwz0s - {ef847dea-e666-44aa-8a4e-f48df8ecc5e4} - LocalServer32 - <no file>
Handler: dialux - {8352FA4C-39C6-11D3-ADBA-00A0244FB1A2} - c:\programmi\dialux\DLXToolBox.dll
Handler: offline-8876480 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - LocalServer32 - <no file>
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\programmi\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\programmi\file comuni\skype\Skype4COM.dll
Name-Space Handler: ftp\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} - c:\hd di giulio\programmi\getright\xx2gr.dll
Name-Space Handler: http\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} - c:\hd di giulio\programmi\getright\xx2gr.dll
Notify: LBTWlgn - c:\programmi\file comuni\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\programmi\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 relog_ap
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\pezzola\dati applicazioni\mozilla\firefox\profiles\qokng74k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.startup.homepage - hxxp://it.msn.com/?pc=WLEM&ocid=bb7hp
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - plugin: c:\documents and settings\pezzola\impostazioni locali\dati applicazioni\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\programmi\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\programmi\earth resource mapping\image web server\firefox plug-in\NP_NCS6.dll
FF - plugin: c:\programmi\earth resource mapping\image web server\firefox plug-in\NP_NCSPB6.dll
FF - plugin: c:\programmi\earth resource mapping\image web server\firefox plug-in\NP_NCSTB6.dll
FF - plugin: c:\programmi\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\programmi\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\programmi\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\programmi\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\programmi\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\programmi\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\programmi\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\programmi\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\programmi\microsoft\office live\npOLW.dll
FF - plugin: c:\programmi\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF - Ext: Dictionary Switcher: dictionary-switcher@design-noir.de - %profile%\extensions\dictionary-switcher@design-noir.de
FF - Ext: Dizionario italiano: it-IT@dictionaries.addons.mozilla.org - %profile%\extensions\it-IT@dictionaries.addons.mozilla.org
FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\programmi\java\jre6\lib\deploy\jqs\ff
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-4-28 64288]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 193552]
R0 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [2007-5-25 46816]
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2004-7-29 138801]
R1 amdtools;AMD Special Tools Driver;c:\windows\system32\drivers\amdtools.sys [2006-5-2 21632]
R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\programmi\hwinfo32\HWiNFO32.SYS [2010-3-20 19320]
R1 MpKsl5e074fdb;MpKsl5e074fdb;c:\documents and settings\all users\dati applicazioni\microsoft\microsoft antimalware\definition updates\{ab36d07a-6c45-42da-b54d-7a2bb6edfb25}\MpKsl5e074fdb.sys [2012-10-27 29904]
R1 NGS;Norman General Security Driver;c:\norman\ngs\bin\ngs.sys [2010-8-18 26744]
R1 NPROSEC;Norman Security driver;c:\norman\ngs\bin\nprosec.sys [2010-8-18 91136]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2004-7-29 46800]
R1 PsSdk41;PsSdk41;c:\windows\system32\drivers\pssdk41.sys [2008-7-19 36928]
R1 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.sys [2008-7-19 53312]
R2 AcronisAgent;Acronis Remote Agent;c:\programmi\file comuni\acronis\agent\agent.exe [2007-1-31 325152]
R2 AcronisBackupServerService;Acronis Backup Server Service;c:\programmi\acronis\backupserver\backupserver.exe [2007-1-31 9089752]
R2 BCMNTIO;BCMNTIO;c:\progra~1\checkit\diagno~1\BCMNTIO.sys [2005-4-9 3744]
R2 ccEvtMgr;Symantec Event Manager;c:\programmi\file comuni\symantec shared\CCEVTMGR.EXE [2004-9-6 197992]
R2 ccSetMgr;Symantec Settings Manager;c:\programmi\file comuni\symantec shared\CCSETMGR.EXE [2004-9-6 181608]
R2 eusk2par;Aladdin SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [2005-9-27 25680]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2011-4-20 54760]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2011-10-8 12184]
R2 MAPMEM;MAPMEM;c:\progra~1\checkit\diagno~1\MAPMEM.sys [2005-4-9 3904]
R2 Ndiskio;Ndiskio;c:\norman\nse\bin\ndiskio.sys [2009-10-19 22880]
R2 NHS;Norman Hash Server;c:\norman\nvc\bin\nhs.exe [2012-5-15 793520]
R2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\programmi\nitro pdf\reader 2\NitroPDFReaderDriverService2.exe [2012-9-13 196112]
R2 NNFSVC;Norman Network Filtering service;c:\norman\ngs\bin\nnf.exe [2010-8-18 231216]
R2 Norman ZANDA;Norman ZANDA;c:\norman\npm\bin\zanda.exe [2007-5-25 431320]
R2 NPROSECSVC;Norman Security service;c:\norman\ngs\bin\nprosec.exe [2010-8-18 90144]
R2 NProtectService;Norton Unerase Protection;c:\progra~1\norton~1\norton~1\NPROTECT.EXE [2004-9-9 99432]
R2 nregsec;Norman Registry Security driver;c:\norman\ngs\bin\nregsec.sys [2010-8-18 61496]
R2 NVOY;Norman Resource Provider;c:\norman\npm\bin\nvoy.exe [2009-7-8 100936]
R2 PDFSFilter;PDFsFilter;c:\windows\system32\drivers\PDFsFilter.sys [2012-5-10 68464]
R2 RVIEGVST;VSC VST Engine;c:\programmi\roland\virtual sound canvas vst\RVIEg01VST.sys [2008-3-31 188276]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\all users\dati applicazioni\skype\toolbars\skype c2c service\c2c_service.exe [2012-8-13 3064000]
R2 Symantec Core LC;Symantec Core LC;c:\programmi\file comuni\symantec shared\ccpd-lc\symlcsvc.exe [2006-2-2 819352]
R3 BBUpdate;BBUpdate;c:\programmi\microsoft\bingbar\7.1.391.0\SeaPort.EXE [2012-6-11 240208]
R3 nsesvc;Norman Scanner Engine Service;c:\norman\nse\bin\nsesvc.exe [2012-8-27 288104]
R3 nvcoas;Norman Virus Control on-access component;c:\norman\nvc\bin\nvcoas.exe [2012-7-5 287312]
R3 Scheduler;Norman Scheduler Service;c:\norman\npm\bin\scheduler.exe [2009-7-8 99312]
R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [2008-3-31 951284]
S1 jkrdyanj;jkrdyanj;\??\c:\windows\system32\drivers\jkrdyanj.sys --> c:\windows\system32\drivers\jkrdyanj.sys [?]
S2 BBSvc;BingBar Service;c:\programmi\microsoft\bingbar\7.1.391.0\BBSvc.EXE [2012-6-11 193616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 First;First; [x]
S2 gupdate;Google Update Service (gupdate);c:\programmi\google\update\GoogleUpdate.exe [2010-1-11 135664]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\programmi\nvidia corporation\nvidia update core\daemonu.exe [2012-5-22 1262400]
S2 SkypeUpdate;Skype Updater;c:\programmi\skype\updater\Updater.exe [2012-7-13 160944]
S3 aawservice;Lavasoft Ad-Aware Service;c:\programmi\lavasoft\ad-aware\AAWService.exe [2010-8-12 1378040]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-2 250808]
S3 at2400;AT-2400 PCI Ethernet NDIS 5.0 Driver;c:\windows\system32\drivers\at2400m5.sys [2001-5-2 20053]
S3 ccPwdSvc;Symantec Password Validation;c:\programmi\file comuni\symantec shared\CCPWDSVC.EXE [2004-9-6 79208]
S3 cpuz132;cpuz132; [x]
S3 cpuz135;cpuz135;c:\programmi\cpuid\pc wizard 2012\pcwiz_x32.sys [2012-8-14 24880]
S3 dfg;dfg;c:\windows\system32\drivers\dfg.sys [2012-7-2 23552]
S3 DialComService;DIAL Communication Service;c:\programmi\dial gmbh\dial communication framework\DialComService.exe [2011-5-15 1639216]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [2005-9-27 43968]
S3 FLASHSYS;FLASHSYS;c:\programmi\msi\live update 4\lu4\FlashSys.sys [2009-9-20 9216]
S3 fsssvc;Servizio Windows Live Family Safety;c:\programmi\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\google\update\GoogleUpdate.exe [2010-1-11 135664]
S3 IACtrl;IA Analysing v2.0;c:\programmi\pointdev\ideal administration\IACtrl.exe [2008-4-20 118784]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [2010-3-10 24216]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\programmi\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15264]
S3 MSI_DVD_010507;MSI_DVD_010507;\??\c:\programmi\msi\live update 5\dvdsys32_100507.sys --> c:\programmi\msi\live update 5\DVDSYS32_100507.sys [?]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;\??\c:\programmi\msi\live update 5\msibios32_100507.sys --> c:\programmi\msi\live update 5\msibios32_100507.sys [?]
S3 MSI_VGASYS_010507;MSI_VGASYS_010507;\??\c:\programmi\msi\live update 5\vgasys32_100507.sys --> c:\programmi\msi\live update 5\VGASYS32_100507.sys [?]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\c:\programmi\msi\live update 5\ntiolib.sys --> c:\programmi\msi\live update 5\NTIOLib.sys [?]
S3 nvcfsr;nvcfsr;c:\norman\nvc\bin\nvcfsr.sys [2008-4-19 9032]
S3 nvcoafl51;nvcoafl51;c:\norman\nvc\bin\nvcoafl51.sys [2008-4-19 32584]
S3 nvcoaft51;nvcoaft51;c:\norman\nvc\bin\nvcoaft51.sys [2008-4-19 132168]
S3 nvcoarc51;nvcoarc51;c:\norman\nvc\bin\nvcoarc51.sys [2008-4-19 25544]
S3 NVCScheduler;Norman Virus Control Scheduler; [x]
S3 PortReporter;Port Reporter;c:\programmi\portreporter\PortReporter.exe [2008-7-26 90183]
S3 RSC4_A02;U.S. Robotics Wireless USB Adapter Driver;c:\windows\system32\drivers\rsc4usb.sys --> c:\windows\system32\drivers\RSC4USB.sys [?]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [2004-5-31 820133]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-19 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 vsdatant;vsdatant; [x]
.
=============== File Associations ===============
.
FileExt: .scr: AutoCADScriptFile="c:\windows\notepad.exe" "%1"
FileExt: .txt: Applications\wordpad.exe="c:\programmi\windows nt\accessori\WORDPAD.EXE" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2012-10-27 06:39:15 29904 ----a-w- c:\documents and settings\all users\dati applicazioni\microsoft\microsoft antimalware\definition updates\{ab36d07a-6c45-42da-b54d-7a2bb6edfb25}\MpKsl5e074fdb.sys
2012-10-26 12:53:55 6918632 ----a-w- c:\documents and settings\all users\dati applicazioni\microsoft\microsoft antimalware\definition updates\{ab36d07a-6c45-42da-b54d-7a2bb6edfb25}\mpengine.dll
2012-10-24 10:58:58 27152 ----a-w- c:\windows\system32\nitrolocalmon2.dll
2012-10-24 10:58:58 18448 ----a-w- c:\windows\system32\nitrolocalui2.dll
2012-10-24 10:58:41 -------- d-----w- c:\programmi\Nitro PDF
2012-10-24 10:58:41 -------- d-----w- c:\programmi\file comuni\Nitro PDF
2012-10-24 09:05:16 6918632 ------w- c:\documents and settings\all users\dati applicazioni\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-09-29 16:40:48 -------- d-----w- C:\Pennetta mia
2012-09-29 16:03:32 -------- d-----w- c:\programmi\file comuni\Raxco
.
==================== Find3M ====================
.
2012-10-10 08:45:01 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-10 08:45:01 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-10 07:00:00 129536 ----a-w- c:\windows\system32\EcCmd.dll
2012-09-24 13:32:24 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-24 13:32:20 473072 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-24 11:51:47 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-07 15:04:46 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-07 13:59:33 512 ----a-w- c:\windows\WRF.COM
2012-09-05 08:19:54 9216 ----a-w- c:\windows\system32\Native.exe
2012-08-30 20:03:50 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:05:06 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:05:04 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:05:04 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07:15 385024 ----a-w- c:\windows\system32\html.iec
2012-08-24 13:53:53 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-08-23 06:27:05 2152448 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-23 06:27:04 2031104 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-16 09:26:03 46816 ----a-w- c:\windows\system32\drivers\nvcw32mf.sys
2012-08-14 09:55:04 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2008-05-09 11:56:16 221224 ----a-w- c:\programmi\accesschk.exe
.
============= FINISH: 9:27:59,51 ===============
When I install a program the screen begin black, with a whithe-square cursor.
The pc begins always slower.
I have some problem with .Net Framewor 2.0 SP2.
I am looking forward to the suggestions.
Gianfry
  • 0

#4
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,266 posts
Hello Gianfry


These are the programs I would like you to run next, if you have any problems with these just skip it and run the next one.


-AdwCleaner-

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

--RogueKiller--

  • Download & SAVE to your Desktop RogueKiller or from here
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+

Gringo
  • 0

#5
Gianfry

Gianfry

    New Member

  • Member
  • Pip
  • 9 posts
- I post the report of AdwCleaner:
# AdwCleaner v2.005 - Logfile creato il 29/10/2012 alle 08:48:57
# Aggiornamento 14/10/2012 by Xplode
# Sistema Operativo : Microsoft Windows XP Service Pack 3 (32 bits)
# Utente : Pezzola - PEZZOLA
# Modalità Avvio : Modalità Normale
# Eseguito da : C:\Downloads\Windows XP\Controllo by Geekstogo\04 - AdwCleaner\adwcleaner.exe
# Opzioni [Elimina]


***** [Servizi] *****


***** [File / Cartelle] *****

Cartella Eliminato : C:\Documents and Settings\All Users\Dati applicazioni\Tarma Installer

***** [Registro] *****

Chiave Eliminata : HKCU\Software\Headlight
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E1230F8-EA50-42A9-983C-D22ABC2EED3B}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{6E4C89CF-3061-4EE4-B22A-B7A8AAEA5CB3}
Chiave Eliminata : HKLM\Software\Conduit
Chiave Eliminata : HKLM\Software\Freeze.com
Chiave Eliminata : HKLM\Software\Headlight
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com
Chiave Eliminata : HKLM\Software\Tarma Installer

***** [Browser Internet] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registro Pulito.

*************************

AdwCleaner[S1].txt - [1801 octets] - [29/10/2012 08:48:57]

########## EOF - C:\AdwCleaner[S1].txt - [1861 octets] ##########

When I run RogueKiller I obtain an stop error BSOD 0x1000008E
Gianfry
  • 0

#6
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,266 posts
Hello

I Would like you to do the following.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
  • 0

#7
Gianfry

Gianfry

    New Member

  • Member
  • Pip
  • 9 posts
This is the ComboFix report:
ComboFix 12-10-29.04 - Pezzola 29-10-2012 18:29:41.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1272 [GMT 1:00]
Eseguito da: c:\documents and settings\Pezzola\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Norman Security Suite *Disabled/Updated* {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
FW: Sygate Personal Firewall *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\0.bak
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\Pezzola\WINDOWS
C:\DSCF0001.JPG
C:\DSCF0002.JPG
C:\DSCF0003.JPG
C:\DSCF0004.JPG
C:\Dscf0005 ritagliata.jpg
C:\DSCF0005.JPG
C:\DSCF0006.JPG
C:\DSCF0007.JPG
C:\DSCF0008.JPG
C:\Dscf0009 ritagliata.jpg
C:\DSCF0009.JPG
C:\Dscf0057.jpg
c:\windows\IsUn0410.exe
c:\windows\system32\C
c:\windows\system32\dbcdbf32.dll
c:\windows\system32\SET50.tmp
c:\windows\system32\SET52.tmp
c:\windows\unin0410.exe
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_EPSONSTATUSAGENT2
-------\Service_EPSONStatusAgent2
.
.
((((((((((((((((((((((((( Files Creati Da 2012-09-28 al 2012-10-29 )))))))))))))))))))))))))))))))))))
.
.
2012-10-29 16:15 . 2012-10-29 16:15 388096 ----a-r- c:\documents and settings\Pezzola\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-10-29 16:15 . 2012-10-29 16:15 -------- d-----w- c:\programmi\Trend Micro
2012-10-29 08:03 . 2012-10-29 08:03 13952 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2012-10-28 18:51 . 2012-10-12 05:56 6918632 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{A2F8A12C-2D21-4186-AE2C-5BCD923006C0}\mpengine.dll
2012-10-28 00:21 . 2012-10-12 05:56 6918632 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-10-27 15:51 . 2012-10-27 15:51 -------- d-----w- c:\programmi\FileHippo.com
2012-10-24 10:58 . 2012-09-13 00:17 27152 ----a-w- c:\windows\system32\nitrolocalmon2.dll
2012-10-24 10:58 . 2012-09-13 00:17 18448 ----a-w- c:\windows\system32\nitrolocalui2.dll
2012-10-24 10:58 . 2012-10-24 10:58 -------- d-----w- c:\programmi\Nitro PDF
2012-10-24 10:58 . 2012-10-24 10:58 -------- d-----w- c:\programmi\File comuni\Nitro PDF
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 08:45 . 2012-05-02 09:08 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-10 08:45 . 2011-06-16 07:22 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-10 07:00 . 2012-04-24 16:19 129536 ----a-w- c:\windows\system32\EcCmd.dll
2012-09-29 18:54 . 2008-10-16 14:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-24 13:32 . 2012-06-23 13:37 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-24 13:32 . 2010-04-28 13:31 473072 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-24 11:51 . 2007-05-25 16:05 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-07 13:59 . 2004-05-31 10:15 512 ----a-w- c:\windows\WRF.COM
2012-09-05 08:19 . 2011-05-08 15:17 9216 ----a-w- c:\windows\system32\Native.exe
2012-08-30 20:03 . 2010-10-24 20:25 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:05 . 2004-08-19 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:05 . 2004-08-19 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:05 . 2004-08-19 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-19 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2004-08-19 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-08-23 06:27 . 2008-06-27 17:24 2152448 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-23 06:27 . 2008-06-27 17:24 2031104 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-16 09:26 . 2007-05-25 17:22 46816 ----a-w- c:\windows\system32\drivers\nvcw32mf.sys
2012-08-14 09:55 . 2011-10-08 07:52 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2008-05-09 11:56 . 2008-05-16 14:10 221224 ----a-w- c:\programmi\accesschk.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"UnlockerAssistant"="c:\programmi\Unlocker\UnlockerAssistant.exe" [2008-03-01 15872]
"MemoREX"="c:\programmi\MemoRex\MemoRexStart.exe" [2003-07-29 332288]
"AcronisTimounterMonitor"="c:\programmi\Acronis\TrueImageWorkstation\TimounterMonitor.exe" [2007-01-31 1862112]
"Acronis Scheduler2 Service"="c:\programmi\File comuni\Acronis\Schedule2\schedhlp.exe" [2007-01-31 140832]
"EvtMgr6"="c:\programmi\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1387288]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
"HPWS myPrintMileage Agent"="c:\programmi\Hewlett-Packard\HP Deskjet 1280\Toolbox\mpm.exe" [2004-12-01 102400]
"RAMpage"="c:\programmi\RAMpage\RAMpage.exe" [2006-03-30 11296]
"PDFPrint"="c:\programmi\PDF24\pdf24.exe" [2012-09-06 162408]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-09-17 254896]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Pezzola\Menu Avvio\Programmi\Esecuzione automatica\
ERUNT AutoBackup.lnk - c:\programmi\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
CoreCenter.lnk - c:\programmi\MSI\Core Center\CoreCenter.exe [2007-12-2 932864]
DigiCell.lnk - c:\programmi\MSI\DigiCell\DigiCell.exe [2005-10-18 1343488]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2011-06-17 07:33 66328 ----a-w- c:\programmi\File comuni\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MIDI3"=vscapi.dll
"WAVE2"=vscapi.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Logitech SetPoint.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Windows Search.lnk]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programmi\\Acronis\\TrueImageWorkstation\\TrueImage.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programmi\\GoFTP\\GoFTP.exe"=
"c:\\Programmi\\File comuni\\XPressUpdate\\XPressUpdate.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Hewlett-Packard\\HP Deskjet 1280\\Toolbox\\HPWSTBX.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Gestione remota Windows
"12520:UDP"= 12520:UDP:UDP 12520
"19555:TCP"= 19555:TCP:TCP 19555
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [28-04-2010 16:29 64288]
R0 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [25-05-2007 18:22 46816]
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [29-07-2004 3:33 138801]
R1 amdtools;AMD Special Tools Driver;c:\windows\system32\drivers\amdtools.sys [02-05-2006 16:45 21632]
R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\programmi\HWiNFO32\HWiNFO32.SYS [20-03-2010 17:26 19320]
R1 NGS;Norman General Security Driver;c:\norman\Ngs\Bin\ngs.sys [18-08-2010 18:16 26744]
R1 NPROSEC;Norman Security driver;c:\norman\Ngs\Bin\nprosec.sys [18-08-2010 18:16 91136]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [29-07-2004 4:13 46800]
R1 PsSdk41;PsSdk41;c:\windows\system32\drivers\pssdk41.sys [19-07-2008 20:01 36928]
R1 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.sys [19-07-2008 20:01 53312]
R2 AcronisAgent;Acronis Remote Agent;c:\programmi\File comuni\Acronis\Agent\agent.exe [31-01-2007 12:30 325152]
R2 AcronisBackupServerService;Acronis Backup Server Service;c:\programmi\Acronis\BackupServer\backupserver.exe [31-01-2007 14:26 9089752]
R2 BBSvc;BingBar Service;c:\programmi\Microsoft\BingBar\7.1.391.0\BBSvc.EXE [11-06-2012 15:22 193616]
R2 BCMNTIO;BCMNTIO;c:\progra~1\CheckIt\DIAGNO~1\BCMNTIO.sys [09-04-2005 16:00 3744]
R2 eusk2par;Aladdin SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [27-09-2005 17:15 25680]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [08-10-2011 8:51 12184]
R2 MAPMEM;MAPMEM;c:\progra~1\CheckIt\DIAGNO~1\MAPMEM.sys [09-04-2005 16:00 3904]
R2 Ndiskio;Ndiskio;c:\norman\Nse\bin\ndiskio.sys [19-10-2009 8:38 22880]
R2 NHS;Norman Hash Server;c:\norman\Nvc\BIN\nhs.exe [15-05-2012 21:05 793520]
R2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\programmi\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe [13-09-2012 1:18 196112]
R2 NNFSVC;Norman Network Filtering service;c:\norman\Ngs\Bin\nnf.exe [18-08-2010 18:16 231216]
R2 NPROSECSVC;Norman Security service;c:\norman\Ngs\Bin\nprosec.exe [18-08-2010 18:16 90144]
R2 NProtectService;Norton Unerase Protection;c:\progra~1\NORTON~1\NORTON~1\NPROTECT.EXE [09-09-2004 14:32 99432]
R2 nregsec;Norman Registry Security driver;c:\norman\Ngs\Bin\nregsec.sys [18-08-2010 18:16 61496]
R2 NVOY;Norman Resource Provider;c:\norman\npm\bin\nvoy.exe [08-07-2009 8:11 100936]
R2 PDFSFilter;PDFsFilter;c:\windows\system32\drivers\PDFsFilter.sys [10-05-2012 11:28 68464]
R2 RVIEGVST;VSC VST Engine;c:\programmi\Roland\Virtual Sound Canvas VST\RVIEg01VST.sys [31-03-2008 16:01 188276]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe [13-08-2012 12:33 3064000]
R3 nsesvc;Norman Scanner Engine Service;c:\norman\Nse\bin\nsesvc.exe [27-08-2012 8:23 288104]
R3 Scheduler;Norman Scheduler Service;c:\norman\npm\bin\scheduler.exe [08-07-2009 8:11 99312]
R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [31-03-2008 15:59 951284]
S1 jkrdyanj;jkrdyanj;\??\c:\windows\system32\drivers\jkrdyanj.sys --> c:\windows\system32\drivers\jkrdyanj.sys [?]
S1 MpKsl7ec1a6fd;MpKsl7ec1a6fd;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{A2F8A12C-2D21-4186-AE2C-5BCD923006C0}\MpKsl7ec1a6fd.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{A2F8A12C-2D21-4186-AE2C-5BCD923006C0}\MpKsl7ec1a6fd.sys [?]
S2 First;First; [x]
S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [11-01-2010 9:10 135664]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\programmi\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [22-05-2012 19:16 1262400]
S2 SkypeUpdate;Skype Updater;c:\programmi\Skype\Updater\Updater.exe [13-07-2012 12:28 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [02-05-2012 10:08 250808]
S3 at2400;AT-2400 PCI Ethernet NDIS 5.0 Driver;c:\windows\system32\drivers\at2400m5.sys [02-05-2001 8:41 20053]
S3 BBUpdate;BBUpdate;c:\programmi\Microsoft\BingBar\7.1.391.0\SeaPort.EXE [11-06-2012 15:22 240208]
S3 cpuz135;cpuz135;c:\programmi\CPUID\PC Wizard 2012\pcwiz_x32.sys [14-08-2012 10:43 24880]
S3 dfg;dfg;c:\windows\system32\drivers\dfg.sys [02-07-2012 19:43 23552]
S3 DialComService;DIAL Communication Service;c:\programmi\DIAL GmbH\DIAL Communication Framework\DialComService.exe [15-05-2011 21:57 1639216]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [27-09-2005 17:15 43968]
S3 FLASHSYS;FLASHSYS;c:\programmi\MSI\Live Update 4\LU4\FlashSys.sys [20-09-2009 11:38 9216]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [11-01-2010 9:10 135664]
S3 IACtrl;IA Analysing v2.0;c:\programmi\Pointdev\IDEAL Administration\IACtrl.exe [20-04-2008 15:09 118784]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [10-03-2010 7:18 24216]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\programmi\Lavasoft\Ad-Aware\kernexplorer.sys [12-08-2010 13:15 15264]
S3 MSI_DVD_010507;MSI_DVD_010507;\??\c:\programmi\MSI\Live Update 5\DVDSYS32_100507.sys --> c:\programmi\MSI\Live Update 5\DVDSYS32_100507.sys [?]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;\??\c:\programmi\MSI\Live Update 5\msibios32_100507.sys --> c:\programmi\MSI\Live Update 5\msibios32_100507.sys [?]
S3 MSI_VGASYS_010507;MSI_VGASYS_010507;\??\c:\programmi\MSI\Live Update 5\VGASYS32_100507.sys --> c:\programmi\MSI\Live Update 5\VGASYS32_100507.sys [?]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\c:\programmi\MSI\Live Update 5\NTIOLib.sys --> c:\programmi\MSI\Live Update 5\NTIOLib.sys [?]
S3 nvcfsr;nvcfsr;c:\norman\Nvc\BIN\nvcfsr.sys [19-04-2008 19:03 9032]
S3 nvcoafl51;nvcoafl51;c:\norman\Nvc\BIN\nvcoafl51.sys [19-04-2008 19:03 32584]
S3 nvcoaft51;nvcoaft51;c:\norman\Nvc\BIN\nvcoaft51.sys [19-04-2008 19:03 132168]
S3 nvcoarc51;nvcoarc51;c:\norman\Nvc\BIN\nvcoarc51.sys [19-04-2008 19:03 25544]
S3 nvcoas;Norman Virus Control on-access component;c:\norman\Nvc\BIN\nvcoas.exe [05-07-2012 8:23 287312]
S3 NVCScheduler;Norman Virus Control Scheduler; [x]
S3 PortReporter;Port Reporter;c:\programmi\PortReporter\PortReporter.exe [26-07-2008 15:26 90183]
S3 RSC4_A02;U.S. Robotics Wireless USB Adapter Driver;c:\windows\system32\DRIVERS\RSC4USB.sys --> c:\windows\system32\DRIVERS\RSC4USB.sys [?]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [31-05-2004 7:17 820133]
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - WS2IFSL
*Deregistered* - uphcleanhlp
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-10-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 15:36]
.
2012-10-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-02 08:45]
.
2012-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-11 08:10]
.
2012-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-11 08:10]
.
2012-10-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1202660629-854245398-1003Core.job
- c:\documents and settings\Pezzola\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-03-11 13:15]
.
2012-10-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1202660629-854245398-1003UA.job
- c:\documents and settings\Pezzola\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-03-11 13:15]
.
2012-10-29 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\programmi\Microsoft Security Client\MpCmdRun.exe [2012-09-12 15:25]
.
2012-10-29 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-04-23 15:17]
.
2012-10-29 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-04-23 15:17]
.
2007-08-27 c:\windows\Tasks\One Button Checkup di Norton SystemWorks.job
- c:\programmi\Norton SystemWorks\OBC.exe [2004-11-18 10:15]
.
2012-10-29 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\programmi\File comuni\ParetoLogic\UUS3\UUS3.dll [2012-06-27 21:07]
.
2012-10-29 c:\windows\Tasks\ParetoLogic Update Version3 Startup Task.job
- c:\programmi\File comuni\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-08-09 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\programmi\File comuni\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-10-29 c:\windows\Tasks\RegCure Pro.job
- c:\programmi\ParetoLogic\RegCure Pro\RegCurePro.exe [2012-08-27 20:23]
.
2012-10-28 c:\windows\Tasks\Symantec Drmc.job
- c:\programmi\File comuni\Symantec Shared\SymDrmc.exe [2004-10-27 10:48]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchAssistant = hxxp://ie.search.msn.com
IE: Converti destinazione link in file PDF esistente
IE: Converti i link selezionati in Adobe PDF
IE: Converti i link selezionati in file PDF esistente
IE: Converti nel file PDF esistente
IE: Converti selezione in file PDF esistente
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.109.1
Name-Space Handler: ftp\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} - c:\hd di giulio\Programmi\GetRight\xx2gr.dll
Name-Space Handler: http\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} - c:\hd di giulio\Programmi\GetRight\xx2gr.dll
FF - ProfilePath - c:\documents and settings\Pezzola\Dati applicazioni\Mozilla\Firefox\Profiles\qokng74k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.startup.homepage - hxxp://it.msn.com/?pc=WLEM&ocid=bb7hp
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
.
.
------- Associazioni dei file -------
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
AddRemove-{E80728E6-2C35-4972-AC3F-408B84C406FB} - c:\docume~1\ALLUSE~1\DATIAP~1\TARMAI~1\{E8072~1\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-29 18:42
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\vsdatant]
"ImagePath"=""
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(912)
c:\programmi\file comuni\logishrd\bluetooth\LBTWlgn.dll
.
- - - - - - - > 'lsass.exe'(968)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'explorer.exe'(5344)
c:\windows\system32\WININET.dll
c:\windows\system32\AcSignIcon.dll
c:\windows\system32\SSSensor.dll
c:\programmi\File comuni\Autodesk Shared\AcSignCore16.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\WS_FTP Pro\nsftpch.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\norman\Npm\bin\ELOGSVC.EXE
c:\programmi\Microsoft Security Client\MsMpEng.exe
c:\norman\Npm\Bin\Zanda.exe
c:\programmi\Sygate\SPF\smc.exe
c:\programmi\File comuni\Acronis\Schedule2\schedul2.exe
c:\windows\System32\drivers\CDAC11BA.EXE
c:\programmi\File comuni\Symantec Shared\ccSetMgr.exe
c:\programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
c:\documents and settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40ST7.EXE
c:\documents and settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\windows\System32\GEARSec.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\Raxco\PerfectDisk\PDAgent.exe
c:\windows\system32\tcpsvcs.exe
c:\progra~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
c:\programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\programmi\UPHClean\uphclean.exe
c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\programmi\File comuni\Symantec Shared\ccEvtMgr.exe
c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\programmi\MemoRex\MemoRex.exe
c:\programmi\Reimage\Reimage Repair\Reimage.exe
c:\programmi\File comuni\LogiShrd\KHAL3\KHALMNPR.EXE
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\File comuni\Raxco\Shared\PDEngine.exe
c:\norman\Npm\Bin\Njeeves.exe
c:\windows\system32\wscntfy.exe
c:\programmi\Raxco\PerfectDisk\PDAgentS1.exe
.
**************************************************************************
.
Ora fine scansione: 2012-10-29 18:51:22 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-10-29 17:51
ComboFix2.txt 2010-09-09 18:49
ComboFix3.txt 2010-09-09 10:21
.
Pre-Run: 35.357.384.704 byte disponibili
Post-Run: 35.549.126.656 byte disponibili
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin /usepmtimer
c:\wubildr.mbr="Ubuntu"
.
- - End Of File - - 9DD50AFE047A4E3827A0DD80435ABCB2
At this moment I have not any problem.
The pc seems to be faster.
I wait your suggestions.
Thank you
Gianfry
  • 0

#8
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,266 posts
Hello

I would like to see a report that combofix makes.

extra combofix report

  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box
C:\Qoobox\Add-Remove Programs.txt
  • click ok

copy and paste the report into this topic for me to review

Gringo
  • 0

#9
Gianfry

Gianfry

    New Member

  • Member
  • Pip
  • 9 posts
This is the extra Combofix report:
3F Filippi catalogue 03 / 2011
ABB DOC2
ABB Software Desktop 2
ABB Sophie 1.1.0.0
ABBIQ 3.0
Able2Doc v5.0
Ad-Aware
Adenix S.M.A.R.T. Explorer 1.0
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Shockwave Player 11.5
Aggiornamento critico per Windows Media Player 11 (KB959772)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB931768)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB933566)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB937143)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB938127)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB939653)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB942615)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB944533)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB950759)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB953838)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB956390)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB958215)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB960714)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB961260)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB963027)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB969897)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB972260)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB974455)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB976325)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2183461)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2360131)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2416400)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2482017)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2497640)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2510531)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2530548)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2544521)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2559049)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2586448)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2618444)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2647516)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2675157)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2699988)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2722913)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB2744842)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB971961)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB976325)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB978207)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB981332)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB982381)
Aggiornamento della protezione per Windows Media Player (KB2378111)
Aggiornamento della protezione per Windows Media Player (KB952069)
Aggiornamento della protezione per Windows Media Player (KB954155)
Aggiornamento della protezione per Windows Media Player (KB968816)
Aggiornamento della protezione per Windows Media Player (KB973540)
Aggiornamento della protezione per Windows Media Player (KB975558)
Aggiornamento della protezione per Windows Media Player (KB978695)
Aggiornamento della protezione per Windows Media Player 10 (KB936782)
Aggiornamento della protezione per Windows Media Player 11 (KB954154)
Aggiornamento della protezione per Windows XP (KB2079403)
Aggiornamento della protezione per Windows XP (KB2115168)
Aggiornamento della protezione per Windows XP (KB2121546)
Aggiornamento della protezione per Windows XP (KB2124261)
Aggiornamento della protezione per Windows XP (KB2160329)
Aggiornamento della protezione per Windows XP (KB2229593)
Aggiornamento della protezione per Windows XP (KB2259922)
Aggiornamento della protezione per Windows XP (KB2279986)
Aggiornamento della protezione per Windows XP (KB2286198)
Aggiornamento della protezione per Windows XP (KB2290570)
Aggiornamento della protezione per Windows XP (KB2296011)
Aggiornamento della protezione per Windows XP (KB2296199)
Aggiornamento della protezione per Windows XP (KB2347290)
Aggiornamento della protezione per Windows XP (KB2360937)
Aggiornamento della protezione per Windows XP (KB2387149)
Aggiornamento della protezione per Windows XP (KB2393802)
Aggiornamento della protezione per Windows XP (KB2412687)
Aggiornamento della protezione per Windows XP (KB2419632)
Aggiornamento della protezione per Windows XP (KB2423089)
Aggiornamento della protezione per Windows XP (KB2436673)
Aggiornamento della protezione per Windows XP (KB2440591)
Aggiornamento della protezione per Windows XP (KB2443105)
Aggiornamento della protezione per Windows XP (KB2476490)
Aggiornamento della protezione per Windows XP (KB2476687)
Aggiornamento della protezione per Windows XP (KB2478960)
Aggiornamento della protezione per Windows XP (KB2478971)
Aggiornamento della protezione per Windows XP (KB2479628)
Aggiornamento della protezione per Windows XP (KB2479943)
Aggiornamento della protezione per Windows XP (KB2481109)
Aggiornamento della protezione per Windows XP (KB2483185)
Aggiornamento della protezione per Windows XP (KB2485376)
Aggiornamento della protezione per Windows XP (KB2485663)
Aggiornamento della protezione per Windows XP (KB2503658)
Aggiornamento della protezione per Windows XP (KB2503665)
Aggiornamento della protezione per Windows XP (KB2506212)
Aggiornamento della protezione per Windows XP (KB2506223)
Aggiornamento della protezione per Windows XP (KB2507618)
Aggiornamento della protezione per Windows XP (KB2507938)
Aggiornamento della protezione per Windows XP (KB2508272)
Aggiornamento della protezione per Windows XP (KB2508429)
Aggiornamento della protezione per Windows XP (KB2509553)
Aggiornamento della protezione per Windows XP (KB2511455)
Aggiornamento della protezione per Windows XP (KB2524375)
Aggiornamento della protezione per Windows XP (KB2535512)
Aggiornamento della protezione per Windows XP (KB2536276-v2)
Aggiornamento della protezione per Windows XP (KB2536276)
Aggiornamento della protezione per Windows XP (KB2544893-v2)
Aggiornamento della protezione per Windows XP (KB2544893)
Aggiornamento della protezione per Windows XP (KB2555917)
Aggiornamento della protezione per Windows XP (KB2562937)
Aggiornamento della protezione per Windows XP (KB2566454)
Aggiornamento della protezione per Windows XP (KB2567053)
Aggiornamento della protezione per Windows XP (KB2567680)
Aggiornamento della protezione per Windows XP (KB2570222)
Aggiornamento della protezione per Windows XP (KB2570947)
Aggiornamento della protezione per Windows XP (KB2584146)
Aggiornamento della protezione per Windows XP (KB2585542)
Aggiornamento della protezione per Windows XP (KB2592799)
Aggiornamento della protezione per Windows XP (KB2598479)
Aggiornamento della protezione per Windows XP (KB2603381)
Aggiornamento della protezione per Windows XP (KB2618451)
Aggiornamento della protezione per Windows XP (KB2619339)
Aggiornamento della protezione per Windows XP (KB2620712)
Aggiornamento della protezione per Windows XP (KB2621440)
Aggiornamento della protezione per Windows XP (KB2624667)
Aggiornamento della protezione per Windows XP (KB2631813)
Aggiornamento della protezione per Windows XP (KB2633171)
Aggiornamento della protezione per Windows XP (KB2639417)
Aggiornamento della protezione per Windows XP (KB2641653)
Aggiornamento della protezione per Windows XP (KB2646524)
Aggiornamento della protezione per Windows XP (KB2647518)
Aggiornamento della protezione per Windows XP (KB2653956)
Aggiornamento della protezione per Windows XP (KB2655992)
Aggiornamento della protezione per Windows XP (KB2659262)
Aggiornamento della protezione per Windows XP (KB2660465)
Aggiornamento della protezione per Windows XP (KB2661637)
Aggiornamento della protezione per Windows XP (KB2676562)
Aggiornamento della protezione per Windows XP (KB2685939)
Aggiornamento della protezione per Windows XP (KB2686509)
Aggiornamento della protezione per Windows XP (KB2691442)
Aggiornamento della protezione per Windows XP (KB2695962)
Aggiornamento della protezione per Windows XP (KB2698365)
Aggiornamento della protezione per Windows XP (KB2705219)
Aggiornamento della protezione per Windows XP (KB2707511)
Aggiornamento della protezione per Windows XP (KB2709162)
Aggiornamento della protezione per Windows XP (KB2712808)
Aggiornamento della protezione per Windows XP (KB2718523)
Aggiornamento della protezione per Windows XP (KB2719985)
Aggiornamento della protezione per Windows XP (KB2723135)
Aggiornamento della protezione per Windows XP (KB2724197)
Aggiornamento della protezione per Windows XP (KB2731847)
Aggiornamento della protezione per Windows XP (KB923561)
Aggiornamento della protezione per Windows XP (KB938464)
Aggiornamento della protezione per Windows XP (KB946648)
Aggiornamento della protezione per Windows XP (KB950762)
Aggiornamento della protezione per Windows XP (KB950974)
Aggiornamento della protezione per Windows XP (KB951066)
Aggiornamento della protezione per Windows XP (KB951376-v2)
Aggiornamento della protezione per Windows XP (KB951748)
Aggiornamento della protezione per Windows XP (KB952004)
Aggiornamento della protezione per Windows XP (KB952954)
Aggiornamento della protezione per Windows XP (KB953155)
Aggiornamento della protezione per Windows XP (KB953839)
Aggiornamento della protezione per Windows XP (KB954211)
Aggiornamento della protezione per Windows XP (KB954459)
Aggiornamento della protezione per Windows XP (KB954600)
Aggiornamento della protezione per Windows XP (KB955069)
Aggiornamento della protezione per Windows XP (KB956391)
Aggiornamento della protezione per Windows XP (KB956572)
Aggiornamento della protezione per Windows XP (KB956744)
Aggiornamento della protezione per Windows XP (KB956802)
Aggiornamento della protezione per Windows XP (KB956803)
Aggiornamento della protezione per Windows XP (KB956841)
Aggiornamento della protezione per Windows XP (KB956844)
Aggiornamento della protezione per Windows XP (KB957095)
Aggiornamento della protezione per Windows XP (KB957097)
Aggiornamento della protezione per Windows XP (KB958644)
Aggiornamento della protezione per Windows XP (KB958687)
Aggiornamento della protezione per Windows XP (KB958690)
Aggiornamento della protezione per Windows XP (KB958869)
Aggiornamento della protezione per Windows XP (KB959426)
Aggiornamento della protezione per Windows XP (KB960225)
Aggiornamento della protezione per Windows XP (KB960715)
Aggiornamento della protezione per Windows XP (KB960803)
Aggiornamento della protezione per Windows XP (KB960859)
Aggiornamento della protezione per Windows XP (KB961371)
Aggiornamento della protezione per Windows XP (KB961373)
Aggiornamento della protezione per Windows XP (KB961501)
Aggiornamento della protezione per Windows XP (KB968537)
Aggiornamento della protezione per Windows XP (KB969059)
Aggiornamento della protezione per Windows XP (KB969898)
Aggiornamento della protezione per Windows XP (KB969947)
Aggiornamento della protezione per Windows XP (KB970238)
Aggiornamento della protezione per Windows XP (KB970430)
Aggiornamento della protezione per Windows XP (KB970483)
Aggiornamento della protezione per Windows XP (KB971468)
Aggiornamento della protezione per Windows XP (KB971486)
Aggiornamento della protezione per Windows XP (KB971557)
Aggiornamento della protezione per Windows XP (KB971633)
Aggiornamento della protezione per Windows XP (KB971657)
Aggiornamento della protezione per Windows XP (KB971961)
Aggiornamento della protezione per Windows XP (KB972270)
Aggiornamento della protezione per Windows XP (KB973346)
Aggiornamento della protezione per Windows XP (KB973354)
Aggiornamento della protezione per Windows XP (KB973507)
Aggiornamento della protezione per Windows XP (KB973525)
Aggiornamento della protezione per Windows XP (KB973869)
Aggiornamento della protezione per Windows XP (KB973904)
Aggiornamento della protezione per Windows XP (KB974112)
Aggiornamento della protezione per Windows XP (KB974318)
Aggiornamento della protezione per Windows XP (KB974392)
Aggiornamento della protezione per Windows XP (KB974571)
Aggiornamento della protezione per Windows XP (KB975025)
Aggiornamento della protezione per Windows XP (KB975254)
Aggiornamento della protezione per Windows XP (KB975467)
Aggiornamento della protezione per Windows XP (KB975560)
Aggiornamento della protezione per Windows XP (KB975561)
Aggiornamento della protezione per Windows XP (KB975562)
Aggiornamento della protezione per Windows XP (KB975713)
Aggiornamento della protezione per Windows XP (KB977165)
Aggiornamento della protezione per Windows XP (KB977816)
Aggiornamento della protezione per Windows XP (KB977914)
Aggiornamento della protezione per Windows XP (KB978037)
Aggiornamento della protezione per Windows XP (KB978251)
Aggiornamento della protezione per Windows XP (KB978262)
Aggiornamento della protezione per Windows XP (KB978338)
Aggiornamento della protezione per Windows XP (KB978542)
Aggiornamento della protezione per Windows XP (KB978601)
Aggiornamento della protezione per Windows XP (KB978706)
Aggiornamento della protezione per Windows XP (KB979309)
Aggiornamento della protezione per Windows XP (KB979482)
Aggiornamento della protezione per Windows XP (KB979559)
Aggiornamento della protezione per Windows XP (KB979683)
Aggiornamento della protezione per Windows XP (KB979687)
Aggiornamento della protezione per Windows XP (KB980195)
Aggiornamento della protezione per Windows XP (KB980218)
Aggiornamento della protezione per Windows XP (KB980232)
Aggiornamento della protezione per Windows XP (KB980436)
Aggiornamento della protezione per Windows XP (KB981322)
Aggiornamento della protezione per Windows XP (KB981852)
Aggiornamento della protezione per Windows XP (KB981957)
Aggiornamento della protezione per Windows XP (KB981997)
Aggiornamento della protezione per Windows XP (KB982132)
Aggiornamento della protezione per Windows XP (KB982214)
Aggiornamento della protezione per Windows XP (KB982665)
Aggiornamento della protezione per Windows XP (KB982802)
Aggiornamento della sicurezza per Microsoft Windows (KB2564958)
Aggiornamento di Windows XP (KB943729)
Aggiornamento per Microsoft Windows (KB971513)
Aggiornamento per Windows Internet Explorer 7 (KB976749)
Aggiornamento per Windows Internet Explorer 8 (KB2447568)
Aggiornamento per Windows Internet Explorer 8 (KB2598845)
Aggiornamento per Windows Internet Explorer 8 (KB2632503)
Aggiornamento per Windows Internet Explorer 8 (KB975364)
Aggiornamento per Windows Internet Explorer 8 (KB976662)
Aggiornamento per Windows Internet Explorer 8 (KB978506)
Aggiornamento per Windows Internet Explorer 8 (KB980182)
Aggiornamento per Windows Internet Explorer 8 (KB982632)
Aggiornamento per Windows XP (KB2141007)
Aggiornamento per Windows XP (KB2345886)
Aggiornamento per Windows XP (KB2467659)
Aggiornamento per Windows XP (KB2492386)
Aggiornamento per Windows XP (KB2541763)
Aggiornamento per Windows XP (KB2616676-v2)
Aggiornamento per Windows XP (KB2616676)
Aggiornamento per Windows XP (KB2641690)
Aggiornamento per Windows XP (KB2661254-v2)
Aggiornamento per Windows XP (KB2718704)
Aggiornamento per Windows XP (KB2736233)
Aggiornamento per Windows XP (KB2749655)
Aggiornamento per Windows XP (KB951072-v2)
Aggiornamento per Windows XP (KB951978)
Aggiornamento per Windows XP (KB955759)
Aggiornamento per Windows XP (KB955839)
Aggiornamento per Windows XP (KB961503)
Aggiornamento per Windows XP (KB967715)
Aggiornamento per Windows XP (KB968389)
Aggiornamento per Windows XP (KB971029)
Aggiornamento per Windows XP (KB971737)
Aggiornamento per Windows XP (KB973687)
Aggiornamento per Windows XP (KB973815)
Aggiornamento rapido per Windows Internet Explorer 7 (KB947864)
Aggiornamento rapido per Windows XP (KB2158563)
Aggiornamento rapido per Windows XP (KB2443685)
Aggiornamento rapido per Windows XP (KB2570791)
Aggiornamento rapido per Windows XP (KB2633952)
Aggiornamento rapido per Windows XP (KB2756822)
Aggiornamento rapido per Windows XP (KB942288-v3)
Aggiornamento rapido per Windows XP (KB952287)
Aggiornamento rapido per Windows XP (KB961118)
Aggiornamento rapido per Windows XP (KB970653-v3)
Aggiornamento rapido per Windows XP (KB976098-v2)
Aggiornamento rapido per Windows XP (KB979306)
Aggiornamento rapido per Windows XP (KB981793)
AudioGenie
Avanquest update
Beghelli catalogue 03 / 2011
Bing Bar
Carambis Driver Updater
Catalogo multimediale 5.4
CCleaner
Cda Product Service - shared component
Compatibility Pack for the 2007 Office system
CURVES1
CutePDF Writer 2.7
Data Doctor Recovery Pen Drive (Demo)
Disano catalogue 07 / 2011
DLux 5.4
DriverFinder
DWG TrueView 2013
Edilclima - Classificazione energetica preliminare
Edilclima - Tariffe VVF
Edilclima Programmi
Epson Easy Photo Print 2
EPSON Scan
Epson Stylus SX210_SX410_TX210_TX410 Manuale
EPSON SX410 Series Printer Uninstall
ER Mapper ECW JPEG 2000 Plug-in for Firefox [3.4.0.242]
ER Mapper ECW JPEG 2000 Plug-in for Internet Explorer [3.4.0.242]
ERUNT 1.1j
EVEREST Home Edition v2.20
ffdshow [rev 3128] [2009-11-08]
FileHippo.com Update Checker
FileZilla Client 3.3.4.1
Final Media Player 2010
FreshDiagnose
FreshUI
FxFoto by Triscape
getPlus® for Adobe
Gewiss catalogue 03 / 2011
GoFTP v2
Google Chrome
Google Update Helper
Hard Disk Low Level Format Tool 2.36 build 1181
HiJackThis
HijackThis 1.99.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
HP Deskjet 1280
HWiNFO32 Version 3.43
IDEAL Administration
IHMC CmapTools v4.09
IIS UrlScan Tool 2.0 (Uninstall)
Image Web Server IE Plugins 2,0,0,104
ImageConverter Plus 7.0
InfoFind 1.00.0764
Java Auto Updater
LG Internet Kit
LG PC Sync
LG Phone Manager
Librerie Progem agosto 2006
Librerie Progem giugno 2006
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
Liveupdate4
Lizardtech DjVu Control (autoinstall)
Logitech SetPoint 6.32
Malwarebytes Anti-Malware versione 1.65.1.1000
MemoRex - Disinstallazione
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - ITA
Microsoft .NET Framework 3.5 - Language Pack SP1 (italiano)
Microsoft .NET Framework 3.5 Language Pack SP1 - ita
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile - Language Pack (ITA)
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Access database engine 2007 (Italian)
Microsoft Security Client
Microsoft Security Essentials
Microsoft SQL Server Compact 4.0 ITA
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Motorola Phone Tools
Mozilla Firefox (3.6.13)
Mozilla Thunderbird (2.0.0.12)
MSI VideoGenie Application
MV RegClean 5.0 English
Net Controller 1.0.2
Nitro Reader 2
Norman Virus Control
Norton SystemWorks 2005 Premier
Norton SystemWorks 2005 Premier (Symantec Corporation)
NVIDIA Drivers
NVIDIA Install Application
NVIDIA nView Desktop Manager
NVIDIA Update Components
OTC1
Pacchetto provider Microsoft servizio crittografia smart card di base
Pannello di controllo NVIDIA 301.42
PC Wizard 2012.2.11
PDF24 Creator 4.9.0
Perfect Fix version 2011.01.01
PerfectDisk 12.5 Professional
Progem 2006 2.0
PSPad editor
Quest3D Viewers 2.5a2
QuizFaber v2.10
RegCompact Pro 2.6.7
RegCure Pro
Registry Easy v5.6
RegZooka
Reimage Repair
Roguescanfix 1.5
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile - Language Pack (ITA) (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile - Language Pack (ITA) (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Windows Search 4 - KB963093
Sintalex PARSIFAL 626-quinquies
SIW version 2008-07-15
SoftPerfect Network Protocol Analyzer 2.6
Software per stampante EPSON
Spybot - Search & Destroy
SpywareBlaster 4.6
SSC Service Utility v4.20
Stellar Phoenix NTFS 2.2
Stime perizie pareri
Super-Charger
Total Commander (Remove or Repair)
Triscape FxFoto
TurboPOI 1.1
Unlocker 1.8.6
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
vanBasco's Karaoke Player
VsdSize 2.9
WebFldrs XP
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Essentials
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
WinRAR gestione archivi
WinZip
Wise Registry Cleaner 5.9.1
Wubi
XML Paper Specification Shared Components Language Pack 1.0
XML Paper Specification Shared Components Pack 1.0
  • 0

#10
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,266 posts
Clean Out Temp Files

  • This small application you may want to keep and use once a week to keep the computer clean.

    Download CCleaner from here http://www.ccleaner.com/

  • Run the installer to install the application.
  • When it gives you the option to install Yahoo toolbar uncheck the box next to it.
  • Run CCleaner. (make sure under Windows tab all the boxes of Internet Explorer and Windows explorer are checked. Under System check Empty Recycle Bin and Temporary Files. Under Application tab all the boxes should be checked).
  • Click Run Cleaner.
  • Close CCleaner.


: Malwarebytes' Anti-Malware :

  • Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Download HijackThis

If you have any problems running Hijackthis see NOTE** below (Host file not read, blank notepad ...)

  • Go Here to download HijackThis Installer
  • Save HijackThis Installer to your desktop.
  • Double-click on the HijackThis Installer icon on your desktop. (Vista and Win 7 right click and run as admin)
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on Edit > Select All then click on Edit > Copy to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT use the AnalyseThis button its findings are dangerous if misinterpreted.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.


NOTE**
sometimes we have to run it like this To run HijackThis as an administrator, right-click HijackThis.exe
(located: C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe)<--32bit
(located: C:\Program Files(86)\Trend Micro\HiJackThis\HiJackThis.exe)<--64bit
and select to run as administrator

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • report from Hijackthis
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo

  • 0
<

Advertisement


#11
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,266 posts
Greetings


I have not heard from you in a couple of days so I am coming by to check on you to see if you are having problems or you just need some more time.

Also to remind you that it is very important that we finish the process completely so as to not get reinfected. I will let you know when we are complete and I will ask to remove our tools




Gringo
  • 0

#12
Gianfry

Gianfry

    New Member

  • Member
  • Pip
  • 9 posts
I post the logs requested:
MBAM log
Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Versione database: v2012.10.31.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Pezzola :: PEZZOLA [amministratore]

31-10-2012 9:18:59
mbam-log-2012-10-31 (09-18-59).txt

Tipo di scansione: Scansione veloce
Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File di sistema | Euristica/Extra | Euristica/Shuriken | PUP | PUM
Opzioni di scansione disattivate: P2P
Elementi esaminati: 261229
Tempo impiegato: 13 minuti, 35 secondi

Processi rilevati in memoria: 0
(non sono stati rilevati elementi nocivi)

Moduli di memoria rilevati: 0
(non sono stati rilevati elementi nocivi)

Chiavi di registro rilevate: 0
(non sono stati rilevati elementi nocivi)

Valori di registro rilevati: 0
(non sono stati rilevati elementi nocivi)

Voci rilevate nei dati di registro: 0
(non sono stati rilevati elementi nocivi)

Cartelle rilevate: 0
(non sono stati rilevati elementi nocivi)

File rilevati: 0
(non sono stati rilevati elementi nocivi)

(fine)

HijackThis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:59:00, on 02-11-2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Norman\Npm\bin\ELOGSVC.EXE
C:\Norman\Ngs\Bin\Nnf.exe
C:\Norman\Ngs\Bin\Nprosec.exe
C:\WINDOWS\system32\svchost.exe
c:\Programmi\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Norman\Npm\Bin\Zanda.exe
C:\Norman\npm\bin\nvoy.exe
C:\Programmi\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Acronis\BackupServer\backupserver.exe
C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
C:\Programmi\Microsoft\BingBar\7.1.391.0\BBSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
C:\Documents and Settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\WINDOWS\System32\GEARSec.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Norman\Nvc\bin\nhs.exe
C:\Programmi\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
C:\Programmi\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Documents and Settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmi\UPHClean\uphclean.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Programmi\Unlocker\UnlockerAssistant.exe
C:\Programmi\Acronis\TrueImageWorkstation\TimounterMonitor.exe
C:\Programmi\File comuni\Acronis\Schedule2\schedhlp.exe
C:\Programmi\Logitech\SetPointP\SetPoint.exe
C:\Programmi\Hewlett-Packard\HP Deskjet 1280\Toolbox\mpm.exe
C:\Programmi\RAMpage\RAMpage.exe
C:\Programmi\PDF24\pdf24.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\MemoRex\MemoRex.exe
C:\Programmi\File comuni\LogiShrd\KHAL3\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\File comuni\Raxco\Shared\PDEngine.exe
C:\Norman\Npm\Bin\scheduler.exe
C:\Norman\Npm\Bin\Njeeves.exe
C:\Norman\Nvc\bin\nvcoas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\NDP20SP2-KB974417-x86.exe
c:\f96b75040895983d69ba\HotFixInstaller.exe
C:\WINDOWS\system32\msiexec.exe
c:\WINDOWS\system32\MsiExec.exe
c:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\Pezzola\Desktop\HijackThis.exe
C:\Programmi\Microsoft\BingBar\7.1.391.0\SeaPort.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DIALux 3.1 ULDBrowserHelper Class - {69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2} - C:\Programmi\DIALux\DLXShellExtension.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programmi\Microsoft\BingBar\7.1.391.0\BingExt.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Programmi\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programmi\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [MemoREX] "C:\Programmi\MemoRex\MemoRexStart.exe"
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Programmi\Acronis\TrueImageWorkstation\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Programmi\File comuni\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [EvtMgr6] C:\Programmi\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPWS myPrintMileage Agent] C:\Programmi\Hewlett-Packard\HP Deskjet 1280\Toolbox\mpm.exe
O4 - HKLM\..\Run: [RAMpage] "C:\Programmi\RAMpage\RAMpage.exe" M=28 T=500 LG P="C:\Programmi\RAMpage\RAMpageConfig.exe"
O4 - HKLM\..\Run: [PDFPrint] C:\Programmi\PDF24\pdf24.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Programmi\ERUNT\AUTOBACK.EXE
O4 - Global Startup: CoreCenter.lnk = C:\Programmi\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: DigiCell.lnk = C:\Programmi\MSI\DigiCell\DigiCell.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.updat...b?1342891569406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1342460922875
O18 - Protocol: bw+0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw+0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw-0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw-0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw00 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw00s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw10 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw10s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw20 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw20s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw30 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw30s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw40 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw40s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw50 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw50s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw60 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw60s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw70 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw70s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw80 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw80s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw90 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bw90s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwa0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwa0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwb0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwb0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwc0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwc0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwd0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwd0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwe0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwe0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwf0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwf0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwg0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwg0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwh0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwh0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwi0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwi0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwj0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwj0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwk0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwk0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwl0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwl0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwm0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwm0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwn0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwn0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwo0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwo0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwp0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwp0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwq0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwq0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwr0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwr0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bws0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bws0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwt0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwt0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwu0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwu0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwv0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwv0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bww0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bww0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwx0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwx0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwy0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwy0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwz0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: bwz0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: offline-8876480 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Programmi\File comuni\Acronis\Agent\agent.exe
O23 - Service: Acronis Backup Server Service (AcronisBackupServerService) - Acronis - C:\Programmi\Acronis\BackupServer\backupserver.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: DIAL Communication Service (DialComService) - Unknown owner - C:\Programmi\DIAL GmbH\DIAL Communication Framework\DialComService.exe
O23 - Service: Norman eLogger Service (eLoggerSvc6) - Norman ASA - C:\Norman\Npm\bin\ELOGSVC.EXE
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Programmi\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IA Analysing v2.0 (IACtrl) - Unknown owner - C:\Programmi\Pointdev\IDEAL Administration\IACtrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmi\File comuni\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norman Hash Server (NHS) - Unknown owner - C:\Norman\Nvc\bin\nhs.exe
O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Programmi\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
O23 - Service: Norman Network Filtering service (NNFSVC) - Norman ASA - C:\Norman\Ngs\Bin\Nnf.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\Npm\Bin\Njeeves.exe
O23 - Service: Norman ZANDA - Norman ASA - C:\Norman\Npm\Bin\Zanda.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Programmi\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norman Security service (NPROSECSVC) - Norman ASA - C:\Norman\Ngs\Bin\Nprosec.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:\Norman\nse\bin\NSESVC.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - (no file)
O23 - Service: Norman Resource Provider (NVOY) - Norman ASA - C:\Norman\npm\bin\nvoy.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Programmi\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Programmi\File comuni\Raxco\Shared\PDEngine.exe
O23 - Service: Port Reporter (PortReporter) - Unknown owner - C:\Programmi\PortReporter\portreporter.exe
O23 - Service: Norman Scheduler Service (Scheduler) - Norman ASA - C:\Norman\Npm\Bin\scheduler.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Programmi\Skype\Updater\Updater.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 21137 bytes
Gianfry
  • 0

#13
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,266 posts
Greetings

These logs are looking very good, we are almost done!!! Just one more scan to go.

:Remove unneeded start-up entries:

This part of the fix is purely optional
These are programs that start up when you turn on your computer but don't need to be, any of these programs you can click on their icons (or start from the control panel) and start the program when you need it. By stopping these programs you will boot up faster and your computer will work faster.

If you have any problems running Hijackthis see NOTE** below (Host file not read, blank notepad ...)

  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    • O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programmi\Unlocker\UnlockerAssistant.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
      O18 - Protocol: bw+0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw+0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw-0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw-0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw00 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw00s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw10 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw10s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw20 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw20s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw30 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw30s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw40 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw40s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw50 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw50s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw60 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw60s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw70 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw70s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw80 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw80s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw90 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bw90s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwa0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwa0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwb0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwb0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwc0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwc0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwd0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwd0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwe0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwe0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwf0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwf0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwg0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwg0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwh0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwh0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwi0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwi0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwj0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwj0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwk0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwk0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwl0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwl0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwm0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwm0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwn0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwn0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwo0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwo0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwp0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwp0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwq0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwq0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwr0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwr0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bws0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bws0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwt0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwt0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwu0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwu0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwv0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwv0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bww0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bww0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwx0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwx0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwy0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwy0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwz0 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: bwz0s - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
      O18 - Protocol: offline-8876480 - {EF847DEA-E666-44AA-8A4E-F48DF8ECC5E4} - (no file)
  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application.

    NOTE**You can research each of those lines >here< and see if you want to keep them or not
    just copy the name between the brackets and paste into the search space
    O4 - HKLM\..\Run: [IntelliPoint]


NOTE**
sometimes we have to run it like this To run HijackThis as an administrator, right-click HijackThis.exe
(located: C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe)<--32bit
(located: C:\Program Files(86)\Trend Micro\HiJackThis\HiJackThis.exe)<--64bit
and select to run as administrator

Eset Online Scanner

**Note** You will need to use Internet explorer for this scan - Vista and win 7 right click on IE shortcut and run as admin

Go Eset web page to run an online scanner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • click on the Run ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
  • When asked, allow the add/on to be installed
    • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings, ensure the options
    Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • wait for the virus definitions to be downloaded
  • Wait for the scan to finish

When the scan is complete

  • If no threats were found
  • put a checkmark in "Uninstall application on close"
  • close program
  • report to me that nothing was found

  • If threats were found
  • click on "list of threats found"
  • click on "export to text file" and save it as ESET SCAN and save to the desktop
  • Click on back
  • put a checkmark in "Uninstall application on close"
  • click on finish
  • close program
  • copy and paste the report here


Gringo
  • 0

#14
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,266 posts
Greetings


I have not heard from you in a couple of days so I am coming by to check on you to see if you are having problems or you just need some more time.

Also to remind you that it is very important that we finish the process completely so as to not get reinfected. I will let you know when we are complete and I will ask to remove our tools




Gringo
  • 0

#15
Gianfry

Gianfry

    New Member

  • Member
  • Pip
  • 9 posts
Hello Gringo,
ESET spends a lot of time doing scan (after 4 hours arrived at 51 %).
I run ESET during the last three nights, but every morning I found the office without electric power, with the main switch off. ESET found 27 threats up to 51 % of the scan. Have a little patience, I am tryng to solve the problem.
Greetings
Gianfry
  • 0

Advertisement




Similar Topics: to delete on not to delete? [Solved]     x


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured