View Full Version : Problemi vari con Spyware
KaiserSin
05-10-2005, 18:17
Buonasera a tutti, mi sono appena registrato su questo bel forum, un complimento a tutti^^
Volevo proporvi un problema con alcuni Spyware.
Dopo un pò che carico il mio windows 2000 mi appare un triangolino con un punto esclamativo in basso a sinistra nella barra delle applicazioni.
Cliccandoci 2 volte mi apre un sito dove mi consiglia di scaricare alcuni Anti-Spyware, ogni volta diversi(Spy-Trooper, PSGuard ecc..)
Volevo trovare un modo efficente per togliere questa seccatura. Ho provato con ad-aware, virit explorer lite, avast.. ma niente.
Poi ho un altro problema, ogni tanto mi appare una finestrella di windows che mi dice:
System performance notice
Performance of your system is extremely low.
The main reason is adware popups. To improve performance of your PC you have to remove or block popup's source from operating system.
Please, use special software to remove adware materials from your computer. Click ok to get full list of aviable popup blocking software.
Chiedo aiuto!
Ringrazio anticipatamente tutti per aver letto questo post^^.
andorra24
05-10-2005, 18:30
Ciao, fai una scansione approfondita con ewido: http://download.ewido.net/ewido-setup.exe
BravoGT83
05-10-2005, 18:43
fai una pulizia con Ccleaner sia HD che registro con back-up
poi fai la scansione con ewido e poi posta il log di hijackthis
gli trovi su www.filehippo.com
KaiserSin
05-10-2005, 19:29
Non sono pratico di questi programmi poichè non li ho mai usati^^
spero di aver fatto tutto come si deve^^
Logfile of HijackThis v1.99.1
Scan saved at 20.28.16, on 05/10/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Programmi\Sygate\SPF\smc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\Programmi\Sitecom\Software Bluetooth\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\Programmi\Executive Software\Diskeeper\DkService.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Programmi\File comuni\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINNT\Explorer.EXE
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\WINNT\system32\msole32.exe
C:\WINNT\system32\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb03.exe
C:\Programmi\D-Tools\daemon.exe
C:\Programmi\DynDNS Updater\DynDNS.exe
C:\Programmi\Sitecom\Software Bluetooth\BTTray.exe
C:\Programmi\Anti-Spyware Blocker\Anti-Virus.exe
C:\Documents and Settings\Administrator\Documenti\yhub388t1_ita_by_PeppezZ\YHub.exe
F:\Download DC++\zDCPlusPlus0668z1\zDCPlusPlus.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\WINNT\system32\wuauclt.exe
C:\Programmi\File comuni\Softwin\BitDefender Update Service\livesrv.exe
C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\ewido\security suite\ewidoguard.exe
C:\Programmi\ewido\security suite\ewidoctrl.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Programmi\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmi\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] "C:\Programmi\Softwin\BitDefender9\bdoesrv.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\softwin\BITDEF~1\bdswitch.exe"
O4 - HKLM\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Administrator"
O4 - HKCU\..\Run: [DynDNS Updater] "C:\Programmi\DynDNS Updater\DynDNS.exe"
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Administrator"
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = C:\Programmi\Sitecom\Software Bluetooth\BTTray.exe
O4 - Global Startup: Free WebSite Tools.lnk = C:\Programmi\CoffeeCup Software\CoffeeCup Free FTP\ThirtyDayTimer.exe
O4 - Global Startup: Anti-Spyware Blocker.lnk = C:\Programmi\Anti-Spyware Blocker\Anti-Virus.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\Sitecom\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\Sitecom\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\Sitecom\Software Bluetooth\btsendto_ie.htm
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.skymasters.biz
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123587585921
O16 - DPF: {81A81DD2-A261-442A-B9B1-DF10A2542020} (Siebel Option Pack for IE 7.5.3) - https://fieldsrv.skytv.it/ecommunications_enu/16199/applets/SiebelOptionPack.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B34A2CA2-C122-4B21-AF62-2773167BD750}: NameServer = 192.168.0.1
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmi\Sitecom\Software Bluetooth\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Programmi\Executive Software\Diskeeper\DkService.exe
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmi\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmi\ewido\security suite\ewidoguard.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Programmi\File comuni\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Programmi\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Programmi\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Programmi\File comuni\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
andorra24
05-10-2005, 19:57
Fixa:
C:\WINNT\system32\msole32.exe
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.skymasters.biz
O16 - DPF: {81A81DD2-A261-442A-B9B1-DF10A2542020} (Siebel Option Pack for IE 7.5.3) - https://fieldsrv.skytv.it/ecommunic...lOptionPack.cab
Ci sono queste 2 voci :
C:\Programmi\Anti-Spyware Blocker\Anti-Virus.exe
O4 - Global Startup: Anti-Spyware Blocker.lnk = C:\Programmi\Anti-Spyware Blocker\Anti-Virus.exe
Questo anti-spyware blocker l'hai installato tu? Non mi sembra molto affidabile e ti consiglierei di disinstallarlo.
KaiserSin
05-10-2005, 20:21
fatto! :D
Grazie tante^^
KaiserSin
05-10-2005, 20:45
Ancora il triangolino in basso non se ne è andato accidenti.. potete darmi altri consigli?
grazie.
andorra24
05-10-2005, 21:03
Ripeti la scansione in modalita' provvisoria. Usa anche Spybot:http://fileforum.betanews.com/detail/Spybot_Search_and_Destroy/1043809773/1
juninho85
08-10-2005, 15:10
hai anti-spyware blocker installato...sbaglio?:D
BravoGT83
09-10-2005, 08:29
hai anti-spyware blocker installato...sbaglio?:D
credo di no :D
juninho85
09-10-2005, 10:21
credo di no :D
io credo di si :D
andorra24
09-10-2005, 11:40
Disinstalla al piu' presto anti-spyware blocker perche e' un prodotto inaffidabile ed e' pure inserito nella rogue list di spywarewarrior perche' da' molti falsi positivi che hanno lo scopo di convincere gli utenti ad usare il loro prodotto.
BravoGT83
09-10-2005, 11:49
io credo di si :D
si lo so:D:D:D
è un programma del cacchio come ha detto andorra ;)
KaiserSin
10-10-2005, 17:20
risolto tutto!
Grazie a tutti per i consigli e la disponibilità^^
vBulletin® v3.6.4, Copyright ©2000-2025, Jelsoft Enterprises Ltd.