My problem:
When I search with Google, I'm redirected to a Web page called Analysis Security pretending to search for viruses in my PC ...
I scanned the pc with Panda. The first time Panda has found many errors and has deleted them, now every time I scan Panda finds an infection in the Winlogon.log file, says that disinfected it, but the next time find the same again.
I Paste the files generated by DDS tool.
1. DDS.txt:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Aurel at 12:34:31.40 on 10/08/27
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1023.284 [GMT 2:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Panda Global Protection 2011 *On-access scanning enabled* (Updated) {8BF935E7-731F-4115-B7A5-789FF5087595}
FW: Panda Personal Firewall 2011 *enabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
============== Running Processes ===============
C:\windows\system32\svchost -k DcomLaunch
svchost.exe
C:\windows\system32\svchost.exe -k netsvcs
C:\Programmi\Panda Security\Panda Global Protection 2011\TPSrv.exe
svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\acs.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Programmi\Common Files\Motive\McciCMService.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
C:\windows\system32\nvsvc32.exe
C:\Programmi\Panda Security\Panda Global Protection 2011\PsCtrls.exe
C:\Programmi\Panda Security\Panda Global Protection 2011\PavFnSvr.exe
C:\Programmi\File comuni\Panda Security\PavShld\pavprsrv.exe
C:\windows\system32\IoctlSvc.exe
c:\programmi\panda security\panda global protection 2011\firewall\PSHOST.EXE
C:\Programmi\Panda Security\Panda Global Protection 2011\PsImSvc.exe
C:\Programmi\Panda Security\Panda Global Protection 2011\PskSvc.exe
C:\Programmi\CyberLink\Shared files\RichVideo.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
C:\Programmi\Panda Security\Panda Global Protection 2011\pavsrvx86.exe
C:\Programmi\Panda Security\Panda Global Protection 2011\AVENGINE.EXE
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
C:\Programmi\Logitech\QuickCam\Quickcam.exe
C:\Programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe
C:\Programmi\Panda Security\Panda Global Protection 2011\APVXDWIN.EXE
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Messenger\msmsgs.exe
C:\windows\system32\ctfmon.exe
C:\Programmi\File comuni\Logishrd\LQCVFX\COCIManager.exe
C:\PROGRAMMI\PANDA SECURITY\PANDA GLOBAL PROTECTION 2011\WebProxy.exe
C:\Programmi\Panda Security\Panda Global Protection 2011\SRVLOAD.EXE
C:\Programmi\Panda Security\Panda Global Protection 2011\PavBckPT.exe
C:\windows\explorer.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\windows\system32\taskmgr.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Mozilla Thunderbird\thunderbird.exe
C:\Documents and Settings\Aurel\Desktop\XP\panda\dds.scr
C:\windows\system32\wuauclt.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.it/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Guida per l'accesso a Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programmi\file comuni\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\programmi\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\programmi\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmi\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmi\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\programmi\google\google toolbar\GoogleToolbar_32.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [swg] "c:\programmi\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [MSMSGS] "c:\programmi\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SunJavaUpdateSched] "c:\programmi\file comuni\java\java update\jusched.exe"
mRun: [Smapp] c:\programmi\analog devices\soundmax\SMTray.exe
mRun: [RegistryMechanic]
mRun: [QuickTime Task] "c:\programmi\quicktime\QTTask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [LogitechQuickCamRibbon] "c:\programmi\logitech\quickcam\Quickcam.exe" /hide
mRun: [LogitechCommunicationsManager] "c:\programmi\file comuni\logishrd\lcommgr\Communications_Helper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\programmi\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\programmi\file comuni\adobe\arm\1.0\AdobeARM.exe"
mRun: [APVXDWIN] "c:\programmi\panda security\panda global protection 2011\APVXDWIN.EXE" /s
mRun: [SCANINICIO] "c:\programmi\panda security\panda global protection 2011\Inicio.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\aurel\menuav~1\progra~1\esecuz~1\secuni~1.lnk - c:\programmi\secunia\psi\psi.exe
mPolicies-system: DisableCAD = 1 (0x1)
IE: E&sporta in Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmi\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\programmi\file comuni\microsoft shared\encarta search bar\ENCSBAR.DLL
DPF: Microsoft XML Parser for Java - file:///C:/windows/Java/classes/xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1282229657828
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} - hxxp://zone.msn.com/bingame/zpagames/zpa_hrtz.cab99160.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {8063B298-F15E-467B-8CBA-E81656C53530} = 192.168.1.1,192.168.1.2
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\fileco~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: avldr - avldr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\aurel\datiap~1\mozilla\firefox\profiles\kzzwutae.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://it.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:it:official
FF - prefs.js: keyword.URL - hxxp://it.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=302398&p=
FF - component: c:\programmi\pdfforge toolbar\ff\components\pdfforgeToolbarFF.dll
FF - component: c:\programmi\pdfforge toolbar\ssff\components\SearchSettingsFF.dll
FF - plugin: c:\programmi\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\google\update\1.2.183.27\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\programmi\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programmi\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\programmi\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\programmi\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programmi\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-8-18 26696]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [2010-8-26 76296]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [2010-8-26 53256]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [2010-8-26 22024]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [2010-8-26 193800]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [2010-8-26 159112]
R1 prcmondrv;prcmondrv;c:\windows\system32\drivers\prcmondrv1041.sys [2010-8-18 18432]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [2010-8-26 37896]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [2010-8-26 46856]
R2 AmFSM;AmFSM;c:\windows\system32\drivers\amm8651.sys [2010-8-26 59080]
R2 BCMNTIO;BCMNTIO;c:\progra~1\checkit\diagno~1\BCMNTIO.sys [2010-8-7 3744]
R2 MAPMEM;MAPMEM;c:\progra~1\checkit\diagno~1\MAPMEM.sys [2010-8-7 3904]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\telecom italia\wanminiport1st\srvany.exe [2009-12-14 8192]
R2 Panda Software Controller;Panda Software Controller;c:\programmi\panda security\panda global protection 2011\PsCtrlS.exe [2010-8-26 173312]
R2 PAVFNSVR;Panda Function Service;c:\programmi\panda security\panda global protection 2011\PavFnSvr.exe [2010-8-26 169216]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [2010-8-26 163336]
R2 PavPrSrv;Panda Process Protection Service;c:\programmi\file comuni\panda security\pavshld\PavPrSrv.exe [2010-8-26 62768]
R2 PAVSRV;Panda On-Access Anti-Malware Service;c:\programmi\panda security\panda global protection 2011\pavsrvx86.exe [2010-8-26 314176]
R2 PskSvcRetail;Panda PSK service;c:\programmi\panda security\panda global protection 2011\psksvc.exe [2010-8-26 28928]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys --> c:\windows\system32\drivers\av5flt.sys [?]
R3 ComFiltr;Panda Anti-Dialer;c:\windows\system32\drivers\COMFiltr.sys [2010-8-26 13880]
R3 NETIMFLT01060042;PANDA NDIS IM Filter Miniport v1.6.0.42;c:\windows\system32\drivers\neti1642.sys [2010-8-26 199688]
R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\pavtpk.sys --> c:\windows\system32\PavTPK.sys [?]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\google\update\GoogleUpdate.exe [2010-4-10 136176]
S3 io02;Hardware Access Driver;c:\windows\system32\io02.sys [2010-8-11 2656]
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\pavsrk.sys --> c:\windows\system32\PavSRK.sys [?]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-7-7 14904]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-1-8 27064]
============== File Associations ===============
JSEFile=c:\progra~1\pandas~1\pandag~1\PavScrip.exe "%1" %*
VBEFile=c:\progra~1\pandas~1\pandag~1\PavScrip.exe "%1" %*
VBSFile=c:\progra~1\pandas~1\pandag~1\PavScrip.exe "%1" %*
=============== Created Last 30 ================
2010-08-26 18:46:55 8627 ----a-w- c:\documents and settings\aurel\PAV_FOG.OPC
2010-08-26 18:45:35 8627 ----a-w- c:\windows\system32\PAV_FOG.OPC
2010-08-26 18:33:52 13880 ----a-w- c:\windows\system32\drivers\COMFiltr.sys
2010-08-26 18:26:47 254 ----a-w- c:\windows\system32\PavCPL.dat
2010-08-26 18:26:35 207656 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT.bck
2010-08-26 18:26:35 207656 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT
2010-08-26 18:26:35 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG.bck
2010-08-26 18:26:35 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG
2010-08-26 18:26:04 53256 ----a-w- c:\windows\system32\drivers\dsaflt.sys
2010-08-26 18:26:04 46856 ----a-w- c:\windows\system32\drivers\wnmflt.sys
2010-08-26 18:26:04 193800 ----a-w- c:\windows\system32\drivers\idsflt.sys
2010-08-26 18:25:44 22024 ----a-w- c:\windows\system32\drivers\fnetmon.sys
2010-08-26 18:25:43 76296 ----a-w- c:\windows\system32\drivers\APPFLT.SYS
2010-08-26 18:25:43 159112 ----a-w- c:\windows\system32\drivers\NETFLTDI.SYS
2010-08-26 18:25:32 0 d-----w- c:\docume~1\alluse~1\datiap~1\Backup
2010-08-26 18:24:48 54832 ----a-w- c:\windows\system32\pavcpl.cpl
2010-08-26 18:24:05 193792 ----a-w- c:\windows\system32\TpUtil.dll
2010-08-26 18:24:04 87296 ----a-w- c:\windows\system32\PavLspHook.dll
2010-08-26 18:24:04 55552 ----a-w- c:\windows\system32\pavipc.dll
2010-08-26 18:24:04 107568 ----a-w- c:\windows\system32\SYSTOOLS.DLL
2010-08-26 18:24:01 518400 ----a-w- c:\windows\system32\PavSHook.dll
2010-08-26 18:23:50 199688 ----a-w- c:\windows\system32\drivers\neti1642.sys
2010-08-26 18:23:38 55552 ----a-w- c:\windows\system32\avldr.dll
2010-08-26 18:23:37 59080 ----a-w- c:\windows\system32\drivers\amm8651.sys
2010-08-26 18:23:37 0 d-----w- c:\windows\system32\PAV
2010-08-26 18:23:32 0 d-----w- c:\docume~1\aurel\datiap~1\Panda Security
2010-08-26 18:23:31 0 d-----w- c:\docume~1\alluse~1\datiap~1\Panda Security
2010-08-26 18:22:32 37896 ----a-w- c:\windows\system32\drivers\ShlDrv51.sys
2010-08-26 18:22:31 163336 ----a-w- c:\windows\system32\drivers\PavProc.sys
2010-08-26 18:22:29 0 d-----w- c:\programmi\file comuni\Panda Security
2010-08-26 18:10:50 0 d-----w- C:\AVGTemp
2010-08-26 09:47:13 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-25 16:54:06 0 d-----w- c:\docume~1\aurel\datiap~1\Secunia CSI
2010-08-25 16:46:21 0 d-----w- c:\programmi\Secunia
2010-08-21 09:43:56 0 d-----w- c:\windows\system32\NtmsData
2010-08-20 16:27:47 0 d-----w- c:\programmi\Magical Jelly Bean
2010-08-18 18:46:59 78336 ----a-w- c:\windows\system32\Agent.OMZ.Fix.exe
2010-08-18 18:46:58 80384 ----a-w- c:\windows\system32\o4Patch.exe
2010-08-18 18:46:54 87552 ----a-w- c:\windows\system32\VACFix.exe
2010-08-18 18:46:50 289144 ----a-w- c:\windows\system32\VCCLSID.exe
2010-08-18 18:46:49 79360 ----a-w- c:\windows\system32\swxcacls.exe
2010-08-18 18:46:47 51200 ----a-w- c:\windows\system32\dumphive.exe
2010-08-18 18:46:47 288417 ----a-w- c:\windows\system32\SrchSTS.exe
2010-08-18 18:46:43 135168 ----a-w- c:\windows\system32\swreg.exe
2010-08-18 18:46:42 53248 ----a-w- c:\windows\system32\Process.exe
2010-08-18 17:51:02 26696 ----a-w- c:\windows\system32\drivers\pavboot.sys
2010-08-18 17:50:41 0 d-----w- c:\programmi\Panda Security
2010-08-18 17:39:04 0 d-----w- c:\programmi\Trend Micro
2010-08-18 17:19:42 18432 ----a-w- c:\windows\system32\drivers\prcmondrv1041.sys
2010-08-17 12:40:59 98816 ----a-w- c:\windows\sed.exe
2010-08-17 12:40:59 77312 ----a-w- c:\windows\MBR.exe
2010-08-17 12:40:59 256512 ----a-w- c:\windows\PEV.exe
2010-08-17 12:40:59 161792 ----a-w- c:\windows\SWREG.exe
2010-08-16 22:36:38 0 dc-h--w- c:\windows\ie8
2010-08-16 22:27:25 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-15 11:50:37 0 d-----w- c:\programmi\RescueTime
2010-08-15 07:47:45 0 d-----w- c:\programmi\Wakoopa
2010-08-14 09:32:17 2672 ----a-w- c:\docume~1\aurel\datiap~1\D001335F.DAT
2010-08-11 20:30:06 2656 ----a-w- c:\windows\system32\io02.sys
2010-08-10 03:15:58 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-08-10 03:15:58 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-08-09 23:00:01 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-08-09 22:59:56 0 d-----w- c:\docume~1\alluse~1\datiap~1\Avira
2010-08-09 22:41:43 0 d-----w- c:\programmi\EPSON
2010-08-09 17:46:53 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-08-09 17:46:30 0 d-----w- c:\programmi\LSoft Technologies
2010-08-09 17:27:50 0 d-----w- c:\docume~1\aurel\datiap~1\Canneverbe Limited
2010-08-08 19:57:39 0 d-----w- c:\docume~1\aurel\datiap~1\Malwarebytes
2010-08-08 19:57:05 0 d-----w- c:\docume~1\alluse~1\datiap~1\Malwarebytes
2010-08-08 19:57:03 0 d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-08-07 21:30:52 0 d-----w- c:\windows\system32\wbem\Repository
2010-08-07 21:15:46 8912896 ----a-w- c:\documents and settings\aurel\ntuser.dat.rmbak
2010-08-07 20:08:24 0 d-----w- c:\docume~1\aurel\datiap~1\Symantec
2010-08-07 19:04:30 0 d-----w- c:\programmi\CheckIt
2010-08-07 15:07:46 0 d-----w- c:\programmi\Symantec
2010-08-07 15:02:48 0 d-----w- c:\windows\system32\CatRoot2
2010-08-07 08:39:26 0 d-----w- c:\programmi\Time Stopper
2010-08-07 07:49:48 62592 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2010-08-07 07:22:14 0 d-----w- c:\docume~1\alluse~1\datiap~1\RPT
2010-08-07 07:21:31 0 d-----w- c:\docume~1\alluse~1\datiap~1\ICO
2010-08-07 07:13:07 0 d-----w- c:\docume~1\aurel\datiap~1\tfw
2010-08-01 08:41:43 51328 -c--a-w- c:\windows\system32\dllcache\msdv.sys
2010-08-01 08:41:43 51328 ----a-w- c:\windows\system32\drivers\msdv.sys
2010-08-01 08:41:37 38912 -c--a-w- c:\windows\system32\dllcache\avc.sys
2010-08-01 08:41:37 38912 ----a-w- c:\windows\system32\drivers\avc.sys
2010-08-01 08:41:32 48128 -c--a-w- c:\windows\system32\dllcache\61883.sys
2010-08-01 08:41:32 48128 ----a-w- c:\windows\system32\drivers\61883.sys
2010-07-31 08:20:23 0 d-----w- c:\programmi\file comuni\Apple
==================== Find3M ====================
2010-08-26 18:47:35 1035776 ----a-w- c:\windows\explorer.exe
2010-08-26 18:35:02 562890 ----a-w- c:\windows\system32\perfh010.dat
2010-08-26 18:35:02 109030 ----a-w- c:\windows\system32\perfc010.dat
2010-08-09 10:45:52 139648 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-07-24 08:16:01 290816 ------w- c:\windows\Setup1.exe
2010-07-07 14:05:32 14904 ----a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-29 20:06:40 73216 ------w- c:\windows\ST6UNST.EXE
============= FINISH: 12:37:04.07 ===============
2. Attach.txt:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 07/08/22 10:50:14 AM
System Uptime: 10/08/26 8:29:14 PM (16 hours ago)
Motherboard: ASUSTeK Computer INC. | | P4V800-X
Processor: Intel® Pentium® 4 CPU 2.60GHz | CPU 1 | 2599/200mhz
Processor: Intel® Pentium® 4 CPU 2.60GHz | CPU 1 | 2599/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 76 GiB total, 23.837 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 10/08/26 12:45:44 PM - Punto di arresto del sistema
RP2: 10/08/26 7:24:40 PM - Removed AVG Free 9.0
RP3: 10/08/26 7:35:35 PM - Removed AVG Free 9.0
RP4: 10/08/26 7:37:00 PM - Revo Uninstaller Pro's restore point - AVG Free 9.0
RP5: 10/08/26 7:38:27 PM - Removed AVG Free 9.0
==== Installed Programs ======================
7-Zip 4.65
Active@ ISO Burner
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Reader 8.2.4
Aggiornamento della protezione per Windows Internet Explorer 8 (KB982381)
Aggiornamento della protezione per Windows XP (KB923789)
Aggiornamento per Windows Internet Explorer 8 (KB982632)
Aggiornamento rapido per Windows XP (KB942288-v3)
Alice Messenger
Apple Application Support
Apple Software Update
Assistente per l'accesso a Windows Live
Autodesk DWF Viewer
Avidemux 2.5
AviSynth 2.5
BitTorrent
CCleaner
CDBurnerXP
CheckIt Diagnostics
CodecInstaller 2.10.2
Disk Cleaner (remove only)
EasyClock, Versione 1.0
Explorer Newmedia La Tua Biblioteca Multimediale
Explorer Newmedia La Tua Biblioteca Multimediale (Navigator)
GOM Player
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows XP (KB954550-v5)
I testi
Idealist 3.0 for Windows
Ingresso
Installazione Guidata Alice
Java Auto Updater
Java 6 Update 20
jv16 PowerTools 1.3
K-Lite Codec Pack 2.41 Full
Kea Coloring Book 3.6.0
Learning Essentials for Microsoft Office
Lingua italiana applicazioni 1
Lingua italiana applicazioni 2
Lingua italiana programmi comuni
Logitech QuickCam
Logitech Updater
Magical Jelly Bean KeyFinder
Matemagica, Versione 2.0
matematica_III_elem_1
MediaInfo 0.7.26
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Italian Language Pack
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Math
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft Student 2007 for Learning Essentials
Microsoft Student with Encarta Premium 2008
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft WSE 3.0 Runtime
Mozilla Firefox (3.6.6)
Mozilla Thunderbird (3.1.2)
MSRedist
MSVCRT
MSXML 6.0 Parser (KB933579)
neroxml
Nokia Connectivity Cable Driver
Nokia PC Connectivity Solution
Nokia PC Suite
Norton SystemWorks
NVIDIA Drivers
Pacchetto di driver di Logitech QuickCam
Panda ActiveScan 2.0
Panda Global Protection 2011
Panda Secure Vault 5
Parser MSXML 4.0 SP2 e SDK
PDFCreator
Platform
PowerDVD
Prova D, Versione 1.0
Prova F, Versione 1.0
Prova G, Versione 1.0
Prova I, Versione 1.0
Prova M, Versione 1.0
Prova N, Versione 1.0
Prova O
Prova P, Versione 1.0
Prova Q
Prova R
Prova S
Prova T
Prova U
Prova V, Versione 1.0
Prova Z, Versione 2.0
QuickTime
Registry Mechanic 6.0
Revo Uninstaller Pro 2.4.1
RTC Client API v1.3 msm
Secunia CSI
Secunia PSI
Segoe UI
Skype™ 4.2
SmartSound Quicktracks Plugin
Software per stampante EPSON
Solid Edge V17
SoundMAX
Strumento di caricamento di Windows Live
Tappeto volante
TELL ME MORE
Time Stopper
TP-LINK Wireless Client Utility Installation Program
Ulead Photo Express 3.0 SE
Ulead VideoStudio 8.0
VBA (2627.01)
VBA (2627.3)
Vector Magic
VIA Platform Device Manager
WanMiniport1st
WebFldrs XP
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Imaging Component
Windows Installer Clean Up
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Tools 4.1
WinRAR archiver
==== Event Viewer Messages From Past Week ========
10/08/26 8:49:05 PM, information: Windows File Protection [64005] - Impossibile ripristinare la versione originale e valida del file di sistema protetto explorer.exe. Il processo di ripristino di Protezione file Windows è stato annullato dall'utente, il nome utente è Aurel. La versione del file non corretto è 6.0.2900.3156.
10/08/26 8:35:18 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 8:32:05 PM, error: Service Control Manager [7022] - Servizio Panda On-Access Anti-Malware Service bloccato in partenza.
10/08/26 8:31:28 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 8:30:03 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 8:22:16 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 8:17:10 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 8:01:51 PM, error: Service Control Manager [7000] - Il servizio AVG Free WatchDog non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 8:01:51 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 7:30:22 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 5:48:03 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 12:54:29 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 12:43:30 PM, error: Service Control Manager [7009] - Timeout (30000 millisecondi) durante l'attesa della connessione del servizio Scheda WMI Performance.
10/08/26 12:43:30 PM, error: Service Control Manager [7000] - Il servizio Scheda WMI Performance non è stato avviato per il seguente errore: Il servizio non ha risposto alla richiesta di avvio o controllo nel tempo previsto.
10/08/26 12:42:52 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 12:33:12 PM, error: DCOM [10005] - DCOM ha ricevuto l'errore "%1058" durante il tentativo di avviare il servizio EventSystem con gli argomenti "" per eseguire il server {1BE1F766-5536-11D1-B726-00C04FB926AF}
10/08/26 12:28:40 PM, error: Service Control Manager [7026] - All'avvio non è stato possibile caricare i seguenti driver: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT pavboot prcmondrv RasAcd Rdbss Tcpip
10/08/26 12:28:40 PM, error: Service Control Manager [7001] - Il servizio Servizi IPSEC dipende dal servizio Driver IPSEC che non è stato avviato per il seguente errore: Una periferica collegata al sistema non è in funzione.
10/08/26 12:28:40 PM, error: Service Control Manager [7001] - Il servizio Helper NetBIOS di TCP/IP dipende dal servizio AFD che non è stato avviato per il seguente errore: Una periferica collegata al sistema non è in funzione.
10/08/26 12:28:40 PM, error: Service Control Manager [7001] - Il servizio Client DHCP dipende dal servizio NetBios su Tcpip che non è stato avviato per il seguente errore: Una periferica collegata al sistema non è in funzione.
10/08/26 12:28:03 PM, error: DCOM [10005] - DCOM ha ricevuto l'errore "%1084" durante il tentativo di avviare il servizio StiSvc con gli argomenti "" per eseguire il server {A1F4E726-8CF1-11D1-BF92-0060081ED811}
10/08/26 12:28:01 PM, error: DCOM [10005] - DCOM ha ricevuto l'errore "%1084" durante il tentativo di avviare il servizio EventSystem con gli argomenti "" per eseguire il server {1BE1F766-5536-11D1-B726-00C04FB926AF}
10/08/26 12:27:58 PM, error: DCOM [10005] - DCOM ha ricevuto l'errore "%1084" durante il tentativo di avviare il servizio netman con gli argomenti "" per eseguire il server {BA126AE5-2166-11D1-B1D0-00805FC1270E}
10/08/26 11:32:07 AM, error: AR5523 [5001] - TP-LINK TL-WN620G 11G Wireless Adapter non ha potuto allocare le risorse necessarie all'operazione.
10/08/26 11:31:58 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/26 11:20:46 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/25 2:34:34 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/25 11:40:18 AM, error: W32Time [17] - Time providerNtpClient: si è verificato un errore durante la ricerca DNS del peer configurato manualmente 'time.windows.com,0x1'. NtpClient ritenterà la ricerca DNS fra 15 minuti. Errore Tentativo di operazione del socket verso un host non raggiungibile. (0x80072751)
10/08/25 11:40:06 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/25 11:39:54 AM, error: Ftdisk [49] - Impossibile configurare il file di paging per i dettagli arresto anomalo del sistema. Assicurarsi che la partizione di avvio contenga un file di paging e che lo spazio disponibile sia sufficiente a contenere tutta la memoria fisica.
10/08/25 11:39:54 AM, error: Ftdisk [45] - Impossibile caricare il driver dei dettagli arresto anomalo del sistema.
10/08/25 1:46:44 PM, error: W32Time [17] - Time providerNtpClient: si è verificato un errore durante la ricerca DNS del peer configurato manualmente 'time.windows.com,0x1'. NtpClient ritenterà la ricerca DNS fra 15 minuti. Errore Tentativo di operazione del socket verso un host non raggiungibile. (0x80072751)
10/08/25 1:46:30 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/24 8:19:31 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/22 11:01:15 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/21 9:52:20 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/21 9:16:18 AM, error: Service Control Manager [7026] - All'avvio non è stato possibile caricare i seguenti driver: ViaIde
10/08/21 9:16:18 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/21 8:24:57 PM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
10/08/21 11:25:27 AM, error: Service Control Manager [7011] - Timout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio RemoteRegistry.
10/08/20 10:12:46 AM, error: Service Control Manager [7000] - Il servizio adfs non è stato avviato per il seguente errore: Impossibile trovare il file specificato.
==== End Of File ===========================
I tried to start 3 times GMER but I get a blue screen after 3 minutes from the start of the scan, the pc stops, I get a blue screen where among other says:
Stop: 0x0000008E (0xC0000005, 0x86B5641F, 0xBA44AA90, 0x00000000)
Thanks to anyone for the help.
Attached File(s)
-
DDS.txt (23.73K)
Number of downloads: 3 -
Attach.txt (12.27K)
Number of downloads: 4

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top











