Capito...
Vabbè, grazie lo stesso di tutto!
ciao ciao
Capito...
Vabbè, grazie lo stesso di tutto!
ciao ciao
Anche nel mio pc ho trovato il virus "mswinvks.exe" e con hijackthis mi è venuta fuori questo log, cosa devo fare dopo aver fatto la scansione?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12.02.56, on 27/02/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\Explorer.EXE
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ospiti\Desktop\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://update.zonelabs.com/downloadr...eqId=977106934
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F3 - REG:win.ini: load=C:\Documents and Settings\Ospiti\Dati applicazioni\Microsoft\mswinvks.exe
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugi n.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleTo olbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [shmntact] C:\Documents and Settings\All Users\Dati applicazioni\shmntact\qnevmpub.exe
O4 - HKCU\..\Run: [lZAZopfzxU] C:\Documents and Settings\All Users\Dati applicazioni\kdungdgn\yfktenkj.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Collegamento a LEGGERE PRIMA DI ACCENDERE I COMPUTER.lnk = C:\Documents and Settings\Ospiti\Documenti\LEGGERE PRIMA DI ACCENDERE I COMPUTER.pdf
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Gestione servizi.lnk = C:\Programmi\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: HBPS Utilities.lnk = C:\Programmi\HBPS Utilities\KMGLBSMT.exe
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: MSSQL$SIPA - Unknown owner - C:\Programmi\Microsoft SQL Server\MSSQL$SIPA\Binn\sqlservr.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SQLAgent$SIPA - Unknown owner - C:\Programmi\Microsoft SQL Server\MSSQL$SIPA\Binn\sqlagent.EXE (file missing)
O24 - Desktop Component 0: (no name) - (no file)
--
End of file - 6218 bytes
ciao
apri hijackthis e fixa queste voci
F3 - REG:win.ini: load=C:\Documents and Settings\Ospiti\Dati applicazioni\Microsoft\mswinvks.exe
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKCU\..\Run: [shmntact] C:\Documents and Settings\All Users\Dati applicazioni\shmntact\qnevmpub.exe
O4 - HKCU\..\Run: [lZAZopfzxU] C:\Documents and Settings\All Users\Dati applicazioni\kdungdgn\yfktenkj.exe
O24 - Desktop Component 0: (no name) - (no file)
scarica malwarebytes da qui
Aggiornalo e fai una scansione completa del computer. Posta il rapporto ottenuto. Per ora non rimuovere nessuna eventuale minaccia rilevata
Malwarebytes' Anti-Malware 1.44
Versione del database: 3784
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
24/02/2010 15.48.22
mbam-log-2010-02-24 (15-47-58).txt
Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 212939
Tempo trascorso: 1 hour(s), 42 minute(s), 3 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 10
Valori di registro infetti: 2
Elementi dato del registro infetti: 2
Cartelle infette: 32
File infetti: 48
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
HKEY_CLASSES_ROOT\CLSID\{ca356d79-679b-4b4c-8e49-5af97014f4c1} (Adware.Starware) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d49e9d35-254c-4c6a-9d17-95018d228ff5} (Adware.Starware) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{ca356d79-679b-4b4c-8e49-5af97014f4c1} (Adware.Starware) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{d49e9d35-254c-4c6a-9d17-95018d228ff5} (Adware.Starware) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{db893839-10f0-4af9-92fa-b23528f530af} (Trojan.Dialer) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{ca356d79-679b-4b4c-8e49-5af97014f4c1} (Adware.Starware) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\starware356 (Adware.Starware) -> No action taken.
HKEY_CLASSES_ROOT\WUSN.1 (Adware.WhenU) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\starware356 (Adware.Starware) -> No action taken.
Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{d49e9d35-254c-4c6a-9d17-95018d228ff5} (Adware.Starware) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> No action taken.
Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Cartelle infette:
C:\Documents and Settings\All Users\Dati applicazioni\Starware356 (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\buttons (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\contexts (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\SimpleUpdate (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356 (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\BrowserSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Configurator (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ErrorSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Games (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Games\images (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Games\images\active (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Games\images\default (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Layouts (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Manager (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Movies (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Movies\images (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Movies\images\active (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Movies\images\default (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\RecipeSearch_Foreign (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Recipes_Foreign (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\RelatedSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ScreensaversMarketingSite Pager (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ScreensaversMarketingSite Pager\images (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ScreensaversMarketingSite Pager\images\active (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ScreensaversMarketingSite Pager\images\default (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Toolbar (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ToolbarLogo (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ToolbarSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\TravelSearch (Adware.Starware) -> No action taken.
C:\Programmi\Starware356 (Adware.Starware) -> No action taken.
C:\Programmi\Starware356\bin (Adware.Starware) -> No action taken.
C:\Programmi\Starware356\icons (Adware.Starware) -> No action taken.
File infetti:
C:\Documents and Settings\Salimbene\Impostazioni locali\Temporary Internet Files\Content.IE5\IHRTXJ1V\Setup_101s6[2].exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Salimbene\Impostazioni locali\Temporary Internet Files\Content.IE5\NWF5TI7X\Setup_101s6[1].exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\contexts\Error.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\contexts\Related.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\contexts\Travel.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\SimpleUpdate\ProductMessa gingConfig.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\SimpleUpdate\ProductMessa gingConfig.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\SimpleUpdate\SimpleUpdate Config.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\SimpleUpdate\SimpleUpdate Config.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\SimpleUpdate\TimerManager Config.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Dati applicazioni\Starware356\SimpleUpdate\TimerManager Config.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\BrowserSearch\BrowserSear ch.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\BrowserSearch\BrowserSear ch.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Configurator\Configurator .xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Configurator\Configurator .xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ErrorSearch\ErrorSearchOp tions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ErrorSearch\ErrorSearchOp tions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Games\GamesOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Games\GamesOptions.xml.ba ckup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Games\images\active\Games 0.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Layouts\ToolbarLayout.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Layouts\ToolbarLayout.xml .backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Manager\ManagerOptions.xm l (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Manager\ManagerOptions.xm l.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Movies\MoviesOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Movies\MoviesOptions.xml. backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Movies\images\active\Movi es0.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\RecipeSearch_Foreign\Reci peSearch_ForeignOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\RecipeSearch_Foreign\Reci peSearch_ForeignOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Recipes_Foreign\Recipes_F oreignOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Recipes_Foreign\Recipes_F oreignOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\RelatedSearch\RelatedSear chOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\RelatedSearch\RelatedSear chOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ScreensaversMarketingSite Pager\ScreensaversMarketingSitePagerOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ScreensaversMarketingSite Pager\ScreensaversMarketingSitePagerOptions.xml.ba ckup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ScreensaversMarketingSite Pager\images\active\ScreensaversMarketingSitePager 0.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Toolbar\TBProductsOptions .xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\Toolbar\TBProductsOptions .xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ToolbarLogo\ToolbarLogoOp tions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ToolbarLogo\ToolbarLogoOp tions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ToolbarSearch\ToolbarSear chOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\ToolbarSearch\ToolbarSear chOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\TravelSearch\TravelSearch Options.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\Salimbene\Dati applicazioni\Starware356\TravelSearch\TravelSearch Options.xml.backup (Adware.Starware) -> No action taken.
C:\Programmi\Starware356\brand.bmp (Adware.Starware) -> No action taken.
C:\Programmi\Starware356\Starware356Config.xml (Adware.Starware) -> No action taken.
C:\Programmi\Starware356\Starware356Uninstall.exe (Adware.Starware) -> No action taken.
C:\Programmi\Starware356\icons\star_16.ico (Adware.Starware) -> No action taken
ciao....anche io mi sono beccata sto virus o cavallo di troia come si suole chiamare....ho effettuato una scansione con il programma Malwerebytes e mi sono usciti tutti questi files infetti che faccio??li elimino tutti???
Buonasera
Tiziana puoi eliminarli tutti
pulisci il sistema con ccleaner seguendo questa guida
scansiona il pc con combofix per controllare se e' rimasta qualche altra infezione
(non installare la recovery console)
Lascia lavorare il programma senza interferire
Allega il rapporto C:\ComboFix.txt nella tua risposta.