|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#1 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
ne ho beccato uno grosso...
ragazzi...sono giorni che il mio pc è infestato da virus...li ero riusciti ad eliminare tutti ma...ieri mattina accendo il pc e trovo sul desktop un'icona che nn mi è familiare,due tette con sotto scritto istant access...mi accorgo che all'avvio non si carica nessuno programma(nè antivirus nè pannello di controllo ati) ecc... e dopo qlk minuto mi escono degli errori riguardanti nerocheck che non è riuschito a caricarsi oppure jushed(mi pare che si scrive csì) con la solita solfa invia segnalazione errori oppure nn inviare...ma nn è finita...mi ha praticamente paralizzato internet...infatti il browser internet explorer carica la pagina ma poi è come se fosse inutilizzabile in quanto continua a caricare qlks...per andare su internet devo aprire una cartella qualsiasi e scrivere nella barra del percorso come se fosse quella dell'iondirizzo!!!! datemi una dritta non ne posso +...ah...non mi apre gli antivirus nemmeno manualmente
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#2 |
|
Senior Member
Iscritto dal: Mar 2006
Messaggi: 22114
|
datti una lettura a questo articolo:
http://www.megalab.it/articoli.php?id=948 e a questo tread: http://www.hwupgrade.it/forum/showth...ighlight=bagle
__________________
Questa opera è distribuita secondo le regole di licenza Creative Commons salvo diversa indicazione. Chiunque volesse citare il contenuto di questo post deve necessariamente riportare il link originario. |
|
|
|
|
|
#3 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
non è lui...ci sono alcune differenze e poi nel rilevamento nn corrisponde al mio caso...ho provato a reinsallare nod e ci sono riuscito...adesso l'ho aggiornato e sto facendo una scansione...ha trovato questo:Win32/Dialer.RW trojan...qlk altra dritta?
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#4 |
|
Senior Member
Iscritto dal: Mar 2006
Messaggi: 22114
|
vedi se riesci a fare una scansione on line con f-secure oppure scarica active virus shield (kaspersky depotenziato) e fagli fare una scansione da provvisoria, esso è imbattibile in rimozione virus.
__________________
Questa opera è distribuita secondo le regole di licenza Creative Commons salvo diversa indicazione. Chiunque volesse citare il contenuto di questo post deve necessariamente riportare il link originario. |
|
|
|
|
|
#5 |
|
Member
Iscritto dal: Mar 2007
Messaggi: 51
|
Non è Bagle, si tratta del trojan Zonebac aka obfuscated.dr che infetta tutti i processi in avvio automatico, ed è per questo che ti compaiono gli errori di Nero e Java.
Per prima cosa prova a fare la scansione con BitDefender online, da i buoni risultati nella rimozione di questo trojan. Dopo fai la scansione completa con Kaspersky online ed allega qui il report della scansione, cosi potremo verificare se BitDefender sia riuscito ad eliminare tutto. |
|
|
|
|
|
#6 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
grazie x i consili...cm
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#7 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
grazie x i consili...cmq ho notato una cosetta...ci sono attivi 2 processi di internet explorer...(iexplore.exe)...che csa bizzarra
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#8 | |
|
Member
Iscritto dal: Mar 2007
Messaggi: 51
|
Quote:
|
|
|
|
|
|
|
#9 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
scusate ma mi dice che mancano 13 ore alla fine...
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#10 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
ecco il log di hijackthis
Logfile of HijackThis v1.99.1 Scan saved at 12.48.43, on 23/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\ad aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Programmi\Eset\nod32krn.exe C:\WINDOWS\system32\oodag.exe C:\Programmi\Eset\nod32kui.exe C:\Programmi\Java\jre1.5.0_10\bin\bak\jusched.exe C:\Programmi\DAEMON Tools\daemon.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\dllhost.exe C:\Programmi\Prevx1\PXConsole.exe C:\Programmi\Prevx1\PXAgent.exe C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Documents and Settings\Administrator\Desktop\dario\Burdell\sicurezza\hijackthis_199\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Dati applicazioni\Prevx\pxbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar4.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar4.dll O3 - Toolbar: (no name) - {bd0e4d83-654e-4213-965b-fcbe887061f4} - (no file) O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [PrevxOne] "C:\Programmi\Prevx1\PXConsole.exe" O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Scaricare usando &BitSpirit - C:\Programmi\BitSpirit\bsurl.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://francico81italy.spaces.msn.co...d/MsnPUpld.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://filelodge.bolt.com/ImageUploader3.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab32846.cab O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2A002439-E80C-4ABD-B87B-E5A56A9A27E2}: NameServer = 193.70.152.15 193.70.152.25 O18 - Protocol: bw+0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\msgrapp.8.0.0812.00.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\msgrapp.8.0.0812.00.dll O18 - Protocol: offline-8876480 - {24EA00FD-86E4-4649-8504-41CE7C453F99} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\ad aware\aawservice.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe O23 - Service: MSSQLServerADHelper - Unknown owner - C:\Programmi\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (file missing) O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Programmi\Prevx1\PXAgent.exe" -f (file missing) O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#11 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
hem...adesso le ore sn diventate 2....lo lascio girare???
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#12 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
aaaahh ne ha stanato uno
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#13 |
|
Member
Iscritto dal: Mar 2007
Messaggi: 51
|
Boh... io di iexplore.exe ne vedo uno solo, sei sicuro che prima erano 2?
La scansione online lasciala finire, tanto ora vai a pranzare ed il tempo scorrerà più in fretta |
|
|
|
|
|
#14 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
si...quando aprivo il browser in tskmngr me ne segnava 2...cmq c'è qlk altra cosa k nn va nel mio log?
e le ore tornano 3
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt Ultima modifica di +Lonewolf+ : 23-03-2007 alle 12:59. |
|
|
|
|
|
#15 |
|
Member
Iscritto dal: Mar 2007
Messaggi: 51
|
No, non c'è nulla che possa essere visibile nel log di Hijackthis, comunque BitDefender ti dovrebbe riparare tutti questi file, forse eccetto Nod32 perchè hai detto di averlo reinstallato:
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [PrevxOne] "C:\Programmi\Prevx1\PXConsole.exe" O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe |
|
|
|
|
|
#16 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
mmm...e come si spiega il fatto che iexplorer x caricare la pag ci metta 1 sec...ma poi nn lo posso cliccare x un paio di minuti altrimenti si impalla tt???
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#17 | |
|
Member
Iscritto dal: Mar 2007
Messaggi: 51
|
Quote:
Finisci prima a fare le pulizie e dopo valuta le prestazioni del pc |
|
|
|
|
|
|
#18 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
ma nn pèarlo di ora...è da ieri mattina e da prima di aprire qst post che lo fa...
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
|
#19 |
|
Member
Iscritto dal: Mar 2007
Messaggi: 51
|
|
|
|
|
|
|
#20 |
|
Senior Member
Iscritto dal: Oct 2005
Messaggi: 3967
|
me ne ha eliminati 17 per il momento...e siamo a
meno di metà joke.geschenk joke.zappa joke.errore joke.movingomuse joke.briga.A Exploit.Win32.WMF-PFV.C MemScan:Trojan.Dnschanger.V (ce ne sono ben 3!) DeepScan:Generic.Zlob.4.DB44D5B Trojan.FakeCodecs.A Exploit.JS.CVE.D Exploit.ADODB.Stream.AK Trojan.Downloader.JS.Inor.E Trojan.DNSChanger.AN gli altri 2 me li segna solo...ma nn dice il nome
__________________
my pc--->OS Windows 8.1--->CASE raidmax smilodon ---> CPU intel i7 6700K @4.5ghz---> VIDEO AMD Radeon RX480 4gb: ---> MOTHEBOARD MSI Z-170A pro ---> AUDIO Supremefx II blue led --->RAM 2 x 8Gb G.Skill DDR4 3200MHz ---> HD Samsung ssd 850 evo---> powered by Enermax NaxN da 500watt |
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 23:29.




















