|
|
|
![]() |
|
Strumenti |
![]() |
#4361 |
Senior Member
Iscritto dal: Nov 2002
Città: Catania----Etna, fucina degli dei! Mammoriano inside!!
Messaggi: 3267
|
scusate, ma la mia fidanzata usando il mio pc si è andata a ficcare in uno dei suoi siti del bip.....è comparna una schermata del nod32 che avvertiva della presenza di un trojian e mo vi posto il log fatto per vedere se è sfuggito qualche virus......tnx
Logfile of HijackThis v1.99.1 Scan saved at 23.09.13, on 16/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Programmi\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\wscntfy.exe C:\Programmi\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Programmi\Eset\nod32kui.exe C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe C:\Programmi\Winamp\winampa.exe C:\Programmi\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe D:\Software free\Anti spyware\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O4 - HKLM\..\Run: [NVMixerTray] "C:\Programmi\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
__________________
PC1: HP Compaq CQ60-204el PC2: Lenovo Ideapad 110-15isk @ Samsung 840 evo 240gb + 12gb ram Powered by Denon x3000/Klipsch RF-82/RC-62/RB-61/Philips DVP3010/PCH 210A/LG 42ln570s + dongle wifi |
![]() |
![]() |
![]() |
#4362 |
Senior Member
Iscritto dal: Oct 2004
Città: Milano
Messaggi: 2641
|
Questo log è pulito
![]()
__________________
FOXYLADY è un MASCHIO!! Un amico è una persona che sa tutto di te e nonostante questo gli piaci |
![]() |
![]() |
![]() |
#4363 |
Senior Member
Iscritto dal: Dec 2001
Città: Palermo
Messaggi: 1090
|
Maledetto IEXPLORE scritto maiuscolo!!
Logfile of HijackThis v1.99.1
Scan saved at 11.28.17, on 17/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\system32\spoolsv.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\system32\CTHELPER.EXE D:\Programmi\File comuni\Logitech\PktDrvr\LVCOMS.EXE D:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe D:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe D:\WINDOWS\system32\rundll32.exe D:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe D:\WINDOWS\system32\ctfmon.exe D:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe D:\PROGRA~1\FILECO~1\PCSuite\Services\SERVIC~1.EXE D:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe D:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe D:\Programmi\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe D:\Programmi\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe D:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe D:\Programmi\ewido\security suite\ewidoctrl.exe D:\Programmi\ewido\security suite\ewidoguard.exe D:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\Programmi\Mozilla Firefox\firefox.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\system32\taskmgr.exe D:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe D:\Programmi\Internet Explorer\IEXPLORE.EXE D:\WINDOWS\system32\NOTEPAD.EXE D:\Documents and Settings\Muratore\Documenti\Antivirus & Firewall\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.yahoo.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\programmi\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\programmi\google\googletoolbar1.dll O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [LVCOMS] D:\Programmi\File comuni\Logitech\PktDrvr\LVCOMS.EXE O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray O4 - HKLM\..\Run: [DataLayer] D:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Programmi\D-Tools\daemon.exe" -lang 1033 -noicon O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Programmi\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [kis] "D:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Global Startup: Bluetooth Manager.lnk = ? O8 - Extra context menu item: Aggiungi a Kaspersky Anti-Banner - D:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - D:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmi\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmi\Messenger\msmsgs.exe O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll O20 - Winlogon Notify: !SASWinLogon - D:\Programmi\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Adobe LM Service - Unknown owner - D:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - D:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing) O23 - Service: ewido security suite control - ewido networks - D:\Programmi\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - D:\Programmi\ewido\security suite\ewidoguard.exe Come tanti utenti, penso di essermi preso anche io 'sto Trojan, ma nn capisco come eliminarlo...Ewido, Kaspersky e SuperAntiSpyware nn sono serviti... |
![]() |
![]() |
![]() |
#4364 |
Senior Member
Iscritto dal: Apr 2006
Messaggi: 22462
|
è pulito
__________________
amd a64x2 4400+ sk939;asus a8n-sli; 2x1gb ddr400; x850 crossfire; 2 x western digital abys 320gb|| asus g1
Se striscia fulmina, se svolazza l'ammazza |
![]() |
![]() |
![]() |
#4365 |
Senior Member
Iscritto dal: Dec 2001
Città: Palermo
Messaggi: 1090
|
Si, ho notato, ma xchè allora nel Task Manager mi si attiva quando entro in Internet Explorer, mandandomi in errore il sistema?
|
![]() |
![]() |
![]() |
#4366 | |
Senior Member
Iscritto dal: Jun 2003
Città: ..By The Sea..
Messaggi: 564
|
Quote:
__________________
Without Contraries is no Progression... |
|
![]() |
![]() |
![]() |
#4367 | |
Senior Member
Iscritto dal: Dec 2001
Città: Palermo
Messaggi: 1090
|
Quote:
|
|
![]() |
![]() |
![]() |
#4368 | |
Senior Member
Iscritto dal: Jun 2003
Città: ..By The Sea..
Messaggi: 564
|
Quote:
La directory è quella standard di internet explorer, quindi questo trojan dovrebbe sostituirsi a internet explorer originale, o modificarne l'eseguibile.. Prova a far analizzare iexplore.exe su www.virustotal.com
__________________
Without Contraries is no Progression... |
|
![]() |
![]() |
![]() |
#4369 | |
Senior Member
Iscritto dal: Dec 2001
Città: Palermo
Messaggi: 1090
|
Quote:
L'ho trovato anche su C:\WINDOWS\Prefetch |
|
![]() |
![]() |
![]() |
#4370 | |
Senior Member
Iscritto dal: Apr 2006
Messaggi: 22462
|
Quote:
__________________
amd a64x2 4400+ sk939;asus a8n-sli; 2x1gb ddr400; x850 crossfire; 2 x western digital abys 320gb|| asus g1
Se striscia fulmina, se svolazza l'ammazza |
|
![]() |
![]() |
![]() |
#4371 |
Senior Member
Iscritto dal: Dec 2001
Città: Palermo
Messaggi: 1090
|
Strano, nn capisco il xchè di questo errore, allora..
![]() |
![]() |
![]() |
![]() |
#4372 |
Member
Iscritto dal: Apr 2006
Messaggi: 105
|
Salve .Potete dare un'occhiata al log?...Il nod mi segnala qualche problema ma non sono sicuro.....grazie.
Inoltre, sempre il nod continua a segnalarmi problemi con un programma che ho rimosso: per la precisione Spy boot search & destroy(non riesco nemmeno a risalire a dove si trovino i files segnalati...avete qualche consiglio?? Logfile of HijackThis v1.99.1 Scan saved at 2.59.08, on 20/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Programmi\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Programmi\Eset\nod32krn.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe C:\Programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\eHome\ehmsas.exe C:\ATI-CPanel\atiptaxx.exe C:\WINDOWS\system32\CTHELPER.EXE C:\Programmi\Java\jre1.5.0_01\bin\jusched.exe C:\Programmi\File comuni\Microsoft Shared\Works Shared\WkUFind.exe C:\Programmi\File comuni\Real\Update_OB\realsched.exe C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe C:\Programmi\Windows Defender\MSASCui.exe C:\Programmi\Eset\nod32kui.exe C:\WINDOWS\system32\ctfmon.exe C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Programmi\ESET\nod32.exe C:\Programmi\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\massimiliano\Impostazioni locali\Temporary Internet Files\Content.IE5\ID03A1U5\HijackThis[1].exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.creative.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O1 - Hosts: 205.238.40.1 winmx.com O1 - Hosts: 205.238.40.1 www.winmx.com O1 - Hosts: 205.238.40.1 err.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3520.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3521.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3522.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3523.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3524.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3525.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3526.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3527.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3528.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3529.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3520.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3521.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3522.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3523.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3524.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3525.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3526.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3527.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3528.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3529.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3520.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3521.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3522.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3523.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3524.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3525.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3526.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3527.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3528.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3529.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3520.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3521.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3522.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3523.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3524.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3525.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3526.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3527.z1304.winmx.com O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {598F4775-6FB6-477B-9842-E0426824E077} - C:\DOCUME~1\MASSIM~1\IMPOST~1\Temp\~DP4.dll (file missing) O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing) O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Programmi\Canon\Easy-WebPrint\EWPBrowseLoader.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing) O2 - BHO: (no name) - {C159A653-40C1-4B75-9F67-4518AFA5FAA1} - C:\WINDOWS\system32\kerbesos.dll (file missing) O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmi\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [Collegamento alla pagina delle proprietà di High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmi\File comuni\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Programmi\File comuni\InstallShield\UpdateService\ISUSPM.exe" -startup O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\Belkin\Software Bluetooth\btsendto_ie_ctx.htm O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O14 - IERESET.INF: START_PAGE_URL=http://www.creative.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O17 - HKLM\System\CCS\Services\Tcpip\..\{399E3014-A6CB-4AFA-8849-054B6F1EF056}: NameServer = 193.70.192.25,193.70.152.25 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\Sptisrv.exe O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe |
![]() |
![]() |
![]() |
#4373 |
Member
Iscritto dal: Nov 2006
Messaggi: 81
|
Raga ho un problema con qualche cavolo di virus...
1)Uno è un dialer che riesco a eliminare con ewido ma si ripresenta all'accensione del PC. 2)Inoltre vi è un altro virus che tutte le volte che io clicco con il tasto destro del mouse mi inizializza il programma di installazione del mio antivirus (symantec client security) Io vi posto il log di Hijackthis, ditemi se c'è qualcosa di 'insano': Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Programmi\Symantec AntiVirus\DefWatch.exe C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\Programmi\Symantec AntiVirus\Rtvscan.exe C:\Programmi\Canon\CAL\CALMAIN.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Programmi\File comuni\Symantec Shared\ccApp.exe C:\Programmi\QuickTime\qttask.exe C:\WINDOWS\system32\ctfmon.exe C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe C:\Programmi\Alice ti aiuta\bin\mpbtn.exe C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe C:\Programmi\eMule\eMule.exe C:\WINDOWS\system32\svchost.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\Windows Media Player\wmplayer.exe C:\WINDOWS\system32\msiexec.exe C:\Documents and Settings\User\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgilio.it/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_08\bin\ssv.dll O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {E7E9F57E-2947-40B1-9BBF-0896D19C092F} - C:\DOCUME~1\User\IMPOST~1\Temp\~DP25.dll O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [RSGate] C:\Documents and Settings\User\Impostazioni locali\Temporary Internet Files\Content.IE5\TODTIMHX\drf1165672099[1].htm.exe -a O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{E7EE783E-0391-4EB9-935D-AD51AD2360E7}: NameServer = 85.37.17.5 85.38.28.77 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmi\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programmi\Symantec AntiVirus\DefWatch.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programmi\ewido anti-spyware 4.0\guard.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programmi\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programmi\Symantec AntiVirus\Rtvscan.exe |
![]() |
![]() |
![]() |
#4374 | |
Senior Member
Iscritto dal: Jun 2003
Città: ..By The Sea..
Messaggi: 564
|
Quote:
O4 - HKCU\..\Run: [RSGate] C:\Documents and Settings\User\Impostazioni locali\Temporary Internet Files\Content.IE5\TODTIMHX\drf1165672099[1].htm.exe -a Manualmente fai anche questi controlli con regedit: start -> esegui -> regedit . Poi spostati con i + fino a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run e guarda nella parte destra della finestra se ci sono dei valori diversi da (default). Sempre con regedit controlla dentro a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows che valore ha la voce appinit_dlls
__________________
Without Contraries is no Progression... |
|
![]() |
![]() |
![]() |
#4375 |
Junior Member
Iscritto dal: Dec 2005
Messaggi: 15
|
mi dite se c'è qualcosa da fixare??
ogfile of HijackThis v1.99.1 Scan saved at 17.27.48, on 20/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programmi\File comuni\Symantec Shared\ccProxy.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Programmi\Norton Internet Security\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe C:\Programmi\Virtual CD v4 SDK\system\vcssecs.exe C:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Programmi\Java\jre1.5.0_09\bin\jusched.exe C:\Programmi\File comuni\Symantec Shared\ccApp.exe C:\Apps\Powercinema\PCMService.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe C:\Programmi\QuickTime\qttask.exe C:\WINDOWS\system32\ctfmon.exe C:\Programmi\MSN Messenger\msnmsgr.exe C:\Programmi\Creative\MediaSource\Detector\CTDetect.exe C:\WINDOWS\twain_32\Trust\Direct Webscan\WATCH.exe C:\Programmi\eMule\emule.exe C:\WINDOWS\system32\msiexec.exe C:\Programmi\File comuni\Real\Update_OB\realsched.exe C:\Documents and Settings\OVVIO\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Collegamento alla pagina delle proprietà di High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_09\bin\jusched.exe" O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programmi\Norton Internet Security\UrlLstCk.exe O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB001" /M "Stylus D68" O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [DataLayer] C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Creative Detector] C:\Programmi\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [BitTorrent] "C:\Programmi\BitTorrent\bittorrent.exe" --force_start_minimized O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Avvio veloce di Microsoft Office OneNote 2003.lnk = C:\Programmi\microsoft office\office11\ONENOTEM.EXE O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\Trust\Direct Webscan\WATCH.exe O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{D8B047BB-970C-4E57-9C30-65883F8AA02F}: NameServer = 85.37.17.42 85.38.28.87 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: Servizio Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Programmi\Virtual CD v4 SDK\system\vcssecs.exe Grazie |
![]() |
![]() |
![]() |
#4376 | |
Senior Member
Iscritto dal: Jun 2003
Città: ..By The Sea..
Messaggi: 564
|
Quote:
O2 - BHO: (no name) - {598F4775-6FB6-477B-9842-E0426824E077} - C:\DOCUME~1\MASSIM~1\IMPOST~1\Temp\~DP4.dll (file missing) O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing) O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing) O2 - BHO: (no name) - {C159A653-40C1-4B75-9F67-4518AFA5FAA1} - C:\WINDOWS\system32\kerbesos.dll (file missing) anche se essendo tutte voci i cui file risultano inesistenti, non dovrebbe cambiare niente. Per quanto riguarda spybot, forse nod32 ti segnalerà i file di backup che si trovano in questa cartella: Documents and Settings\All Users\Dati Applicazioni\Spybot - Search & Destroy\Recovery Non costituiscono alcun pericolo, comunque se hai disinstallato il programma puoi anche eliminarli tutti manualmente.
__________________
Without Contraries is no Progression... |
|
![]() |
![]() |
![]() |
#4377 |
Member
Iscritto dal: Apr 2006
Messaggi: 105
|
Grazie 1000 bReAkDoWn.Fixero il foxabile....per i file spyboot,...sono proprio quelli.Il problema(sono un a frana!!!) è che non riesco a ritrovare la cartella dove sono situati, nel senso che fino ad "All users" ci arrivo ma non ritrovo la cartella "dati applicazioni" e non capisco che fine abbia fatto.Mi sai aiutare?? Thanks a lot!
|
![]() |
![]() |
![]() |
#4378 | |
Senior Member
Iscritto dal: Jun 2003
Città: ..By The Sea..
Messaggi: 564
|
Quote:
__________________
Without Contraries is no Progression... |
|
![]() |
![]() |
![]() |
#4379 | |
Member
Iscritto dal: Nov 2006
Messaggi: 81
|
Quote:
Ho fatto il controllo manuale come mi avevi detto e la vole HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows che valore ha la voce appinit_dlls non riporta alcun valore. Per fixare devo andare in modalità provvisaria. Saresti così gentile da spiegarmi la procedura? Te lo chiedo perchè ho fatto una ricerca e, sia nel forum che nel thread di Hijackthis non ho trovato nulla. Grazie!!! |
|
![]() |
![]() |
![]() |
#4380 | |
Senior Member
Iscritto dal: Jun 2003
Città: ..By The Sea..
Messaggi: 564
|
Quote:
__________________
Without Contraries is no Progression... |
|
![]() |
![]() |
![]() |
Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 15:36.