|
|
|
![]() |
|
Strumenti |
![]() |
#1 |
Junior Member
Iscritto dal: Sep 2007
Messaggi: 13
|
[Win XP] virus che consuma memoria?
Salve ragazzi,
intanto saluto tutti, vi leggo spesso e devo dire che questo forum è sicuramente la migliore risorsa dover poter trovare la soluzione al proprio problema. Vengo al mio: da qualche giorno ho il pc "paralizzato", non mi si aprono le applicazioni se ne è già aperta una (compare un errore di windows che dice "risorse di sistema insufficienti per completare questo servizio"), e riesco a navigare,male tra l'altro, avendo una sola finestra del browser aperta. Ho fatto la deframmentazione ma niente, e tra l'altro in modalità provvisoria va tutto bene, quindi non sembrerebbe un problema di hardware. Potrebbe essere quindi un virus? Mi affido a voi, sperando in un vostro aiuto e ringraziando anticipatamente: ecco il log di hijackthis: Codice:
Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 13.49.32, on 15/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\Internet Explorer\iexplore.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Programmi\Spyware Doctor\sdhelp.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\File comuni\Real\Update_OB\realsched.exe C:\Programmi\QuickTime\qttask.exe C:\Programmi\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\wuauclt.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\Hijackthis\HiJackThis_v2.exe C:\WINDOWS\System32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cust...//my.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 80.25.130.118:80 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.1.1;localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Salva oggetto con Net Transport - C:\Programmi\Xi\NetTransport 2\NTAddLink.html O8 - Extra context menu item: Salva tutti gli oggetti con Net Transport - C:\Programmi\Xi\NetTransport 2\NTAddList.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {F5BC716E-2650-4B08-9235-C110CF95017F} (Connessione Tiscali) - http://selfcare.tiscali.it/scripts/o...oneTiscali.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A1420BB7-960A-41F9-AA1E-B62EE421A442}: NameServer = 212.216.112.112,212.216.172.62 O18 - Protocol: bw+0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documenti\Settings\bot.dll O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documenti\Settings\partnership.dll O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documenti\Settings\winsys2f.dll O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\Programmi\Spyware Doctor\sdhelp.exe -- End of file - 17238 bytes Ultima modifica di luchett : 16-12-2007 alle 10:28. |
![]() |
![]() |
![]() |
#2 |
Senior Member
Iscritto dal: Feb 2002
Città: Bologna
Messaggi: 533
|
Riedita il tuo post seguendo le regole di sezione sennò non otterrai nessuna risposta !
![]()
__________________
Packard Bell X1052 - Processore Intel Core 2 Quad Q6600 (2400 Mhz) - Ram 3072 Mb - Hard Disk 500 GB - Scheda video NVidia GEF 8600GS ![]() Portatile Fujitsu Siemens M1439G ![]() |
![]() |
![]() |
![]() |
#3 |
Senior Member
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
|
Il tuo pc è chiaramente infetto e per pulirlo bisogna procedere per piccoli passi.
La prima cosa da fare è prendere visioone delle Regole di Sezione che ti daranno le indicazioni per come inserire i log nei thread di quest'area, inoltre ti dirige verso la guida per una disinfezione preventiva. Quindi pertanto dovrai rieditare subito il tuo messaggio eliminado il log ![]() La prima cosa da fare è disabilitare il ripristino di configurazione e tenerlo spento fino alla fine. Poi lanci "Eset ADS revelear" facendo attenzione a fargli scansionare solo gli hd e non le unità ottiche. Elimina tutto quello che troverà, non elimina file ma solo i metadati dei file che nel 98% dei casi vengono usati a scopi maligni, il 2% restante sono varie info delle fotografie tipo diaframma usato, macchina, sensibilità.. Fatto questo prova a-squared-free ma versione da linea di comando è liberamente scaricabile sul sito della Emilsoft e per sapere come usarlo basta che nella "Guida per Disinfettare" clicki sul nome "a-squared free 3.x". metti in quarantena tutto cio che trovi e salva il log! procedi così fino alla scansione di un antivirus a scelta se online o con Dr.Web, anche in questo caso salvati il log, e poi quando torni qui metti tutti i log. mi raccomando è importante che ci siano tutti i log! grazie per la collaborazione ![]()
__________________
"Visti da vicino siamo tutti strani..." ~|~ What Defines a Community? ~|~ Thread eMule Ufficiale ~|~ Online Armor in Italiano ~|~ Regole di Sezione ~|► Guida a PrivateFirewall
|
![]() |
![]() |
![]() |
#4 |
Junior Member
Iscritto dal: Sep 2007
Messaggi: 13
|
Intanto mi scuso per aver "infranto le regole" stamattina
![]() Ho fatto le scansione consigliate ma il problema persiste. Allego i file di log di eset ads e a-squared, per ciò che riguarda l'antivirus sono riuscito a fare un paio di scansioni online sia con symantec che con panda, entrambe hanno rilevato 6-7 infezioni, ma il problema è che non riesco a tirare fuori il log...il pc si pianta per il solito problema. Va bene se ne faccio una con antivir in locale? Ecco i log delle scansioni eseguite: Ultima modifica di luchett : 17-12-2007 alle 00:35. |
![]() |
![]() |
![]() |
#5 |
Bannato
Iscritto dal: Oct 2007
Città: Palermo
Messaggi: 4623
|
ciao
hai fatto la scansione con prevx csi?ti consiglio di farlo,cosi come indicato nella guida, x quanto riguarda le scansioni online: prova bitdefender che ti da la possibilità di salvare il report se ricordo bene, al limite fai una "foto" ai risultati e allega qui l'immagine ![]() |
![]() |
![]() |
![]() |
#6 | |
Senior Member
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
|
Apri HJT e fixa queste:
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documenti\Settings\bot.dll O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documenti\Settings\partnership.dll O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documenti\Settings\winsys2f.dll Poi scarica Avenger. Eseguilo e seleziona Input Script Manually, clicca sulla lente e inserisci: Quote:
Poi allega il log che trovi in c:\avenger.txt P.S. Ma non hai un antivirus? Devi anche aggiornare java.
__________________
Kaspersky Virus Removal Tool | Avira AntiVir Rescue System | Threatfire in Italiano | Norton User Account Control (beta) La tua prossima affermazione sarà un No? Rispondi con un Si o un No.
![]() Ultima modifica di Nuz : 16-12-2007 alle 18:35. |
|
![]() |
![]() |
![]() |
#7 |
Junior Member
Iscritto dal: Sep 2007
Messaggi: 13
|
ecco il file di avenger:
Codice:
////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Error: could not create zip file. Error code: 1813 ////////////////////////////////////////// Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\pvhbluwh ******************* Script file located at: \??\C:\dtukxitr.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File C:\Documents and Settings\All Users\Documenti\Settings\bot.dll deleted successfully. File C:\Documents and Settings\All Users\Documenti\Settings\partnership.dll deleted successfully. File C:\Documents and Settings\All Users\Documenti\Settings\winsys2f.dll deleted successfully. Completed script processing. ******************* Finished! Terminate. |
![]() |
![]() |
![]() |
#8 |
Senior Member
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
|
Ok, ora servono il log di PrevxCSI e quello di una scansione on-line.
P.S. Però non mi hai detto se hai un antivirus o se non lo riesci ad installare. E' importante saperlo.
__________________
Kaspersky Virus Removal Tool | Avira AntiVir Rescue System | Threatfire in Italiano | Norton User Account Control (beta) La tua prossima affermazione sarà un No? Rispondi con un Si o un No.
![]() |
![]() |
![]() |
![]() |
#9 |
Junior Member
Iscritto dal: Sep 2007
Messaggi: 13
|
non sono riuscito a capire come si salva il log di prevx Csi, però ho fatto una stamp della schermata che trovate qui:
http://www.zshare.net/image/5674803c8bf450/ Per quanto riguarda l'antivirus ho installato antivir |
![]() |
![]() |
![]() |
#10 |
Bannato
Iscritto dal: Oct 2007
Città: Palermo
Messaggi: 4623
|
hai un bel rootkit...
io ti consiglio panda antirootkit, scaricalo da qui avira l'hai installato dopo il log di hijackthis? ti funziona? |
![]() |
![]() |
![]() |
#11 | |
Senior Member
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
|
1) Scarica Avenger. Eseguilo e seleziona Input Script Manually, clicca sulla lente e inserisci:
Quote:
Poi allega il log che trovi in c:\avenger.txt 2) Fai uno scan con gmer e riporta il log delle sole righe rosse, se ci sono. Edit: fai anche lo scan con panda antrootkit come suggerito da murack83pa.
__________________
Kaspersky Virus Removal Tool | Avira AntiVir Rescue System | Threatfire in Italiano | Norton User Account Control (beta) La tua prossima affermazione sarà un No? Rispondi con un Si o un No.
![]() Ultima modifica di Nuz : 16-12-2007 alle 20:10. |
|
![]() |
![]() |
![]() |
#12 | |
Bannato
Iscritto dal: Jul 2007
Città: Riverside House
Messaggi: 3333
|
Quote:
![]() Disattiva il Ripristino configurazione di sistema ovvero procedi in questa maniera: ● tasto destro del mouse sull'icona Risorse del Computer ● seleziona la voce Proprietà ● apri la scheda Ripristino configurazione di Sistema ● spunta la voce Disattiva ripristino configurazione di sistema ● conferma, la modifica, con Applica e, poi Ok Lo lasci disattivato fino a quanto non avremo risolto il problema Prima di ogni altra cosa, scarica ed installa ANTIVIR PERSONAL EDITION FREE: clicca qui per il download ● una volta installato, scarica gli aggiornamenti e poi, esegui una scansione completa del sistema. qui trovi la Guida di configurazione per Antivir pubblicata da Juninho (leggi, attentamente, i primi tre post), ed altre cose importanti ed interessanti in relazione ad Antivir. Se necessiti di informazioni o spiegazioni, posta, in quella discussione CCLEANER: clicca qui per il download una volta installato, lancia il programma, nel menu di sinistra portati alla voce Opzioni e nella finestra successiva clicca su: ● Impostazioni, e spunta la voce Cancellazione sicura (lenta) poi su: ● Avanzate, togli la spunta alla voce Cancella solo file più vecchi di 48 ore ● alla voce Pulizia, spunta tutte le voci comprese nella sezione Avanzate ● nel menu a sinistra, clicca sulla voce Pulizia, clicca su tasto Avvia Pulizia per eseguire la scansione ● sempre nel menu a sinistra, clicca sulla voce Registro, spunta tutte le voci comprese nella sezione, clicca sul tasto Trova problemi ed avvia una scansione ● al termine della scansione clicca sulla voce Ripara selezionati e prosegui PANDA ANTIROOTKIT: clicca qui per il download Non è necessaria l'installazione (è un tool stand-alone); una volta lanciato, si aggiorna in automatico ed esegue la scansione (ovviamente rimuove tutti gli eventuali rootkit che rileva) TRENDMICRO ROOTKIT BOOSTER: clicca qui per il download scompattalo ed eseguilo (è un tool standalone) e vedi se rileva qualcosa. Al termine riavvia ed allega un nuovo log di HThis Ultima modifica di Riverside : 16-12-2007 alle 21:49. |
|
![]() |
![]() |
![]() |
#13 | |
Senior Member
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
|
Quote:
![]() stesso discorso per i tuoi amici.. il log di Eset ADS Revelear non mente... certo che accettare determinati contenutis enza nemmeno usare uno straccio di protezione... non capisco per cosa poi chiedi aiuto ![]()
__________________
"Visti da vicino siamo tutti strani..." ~|~ What Defines a Community? ~|~ Thread eMule Ufficiale ~|~ Online Armor in Italiano ~|~ Regole di Sezione ~|► Guida a PrivateFirewall
|
|
![]() |
![]() |
![]() |
#14 |
Senior Member
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
|
Avevo proprio omesso di controllare il log di ADSR. A questo punto, come ho fatto anche in quest'altra occasione, luchett ti consiglio di muovere quel log modificando il post relativo. Il contenuto ha chiari riferimenti a informazioni del tutto personali ( privacy ).
__________________
Kaspersky Virus Removal Tool | Avira AntiVir Rescue System | Threatfire in Italiano | Norton User Account Control (beta) La tua prossima affermazione sarà un No? Rispondi con un Si o un No.
![]() Ultima modifica di Nuz : 17-12-2007 alle 00:08. |
![]() |
![]() |
![]() |
#15 | |
Junior Member
Iscritto dal: Sep 2007
Messaggi: 13
|
Quote:
Codice:
Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\whrrvnuh ******************* Script file located at: \??\C:\Documents and Settings\vaiijmnf.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File C:\WINDOWS\system32\svchost.exe:exe.exe not found! Deletion of file C:\WINDOWS\system32\svchost.exe:exe.exe failed! Could not process line: C:\WINDOWS\system32\svchost.exe:exe.exe Status: 0xc0000034 Completed script processing. ******************* Finished! Terminate. |
|
![]() |
![]() |
![]() |
#16 |
Senior Member
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
|
Scarica SDFix e salvalo sul desktop
Fai doppio click su SDFix.exe e il tool andrà ad estrarsi in C:\SDFix Poi avvia il sistema in modalità provvisoria. Apri la cartella SDFix situata in C:\ e fai un doppio click su RunThis.bat per lanciare lo script, seleziona Y per avviare la pulizia. Quando te lo chiederà premi un tasto per riavviare (il sistema sarà piu lungo nell'avviarsi perchè lo script eseguirà l'eliminazione dei file trovati). Quando apparirà il desktop il tool terminerà il suo lavoro e visualizzerà il messaggio "Finished". Premi un tasto per terminare lo script e ricaricare le icone del desktop. Il log sarà visualizzato automaticamente,altrimenti potrai trovarlo in C:\SDFix\Report.txt
__________________
Kaspersky Virus Removal Tool | Avira AntiVir Rescue System | Threatfire in Italiano | Norton User Account Control (beta) La tua prossima affermazione sarà un No? Rispondi con un Si o un No.
![]() Ultima modifica di Nuz : 17-12-2007 alle 09:01. |
![]() |
![]() |
![]() |
#17 |
Junior Member
Iscritto dal: Sep 2007
Messaggi: 13
|
Ecco qua...
p.s il pc sembra andare nuovamente bene ![]() Codice:
SDFix: Version 1.118 Run by luca on 17/12/2007 at 20.16 Microsoft Windows XP [Versione 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Name: ICF Path: C:\WINDOWS\system32\svchost.exe:exe.exe ICF - Deleted Restoring Windows Registry Values Restoring Windows Default Hosts File Restoring Missing Security Center Service Restoring Missing SharedAccess Service Rebooting... Service asc355O - Deleted after Reboot Service asc3550p - Deleted after Reboot Normal Mode: Checking Files: Trojan Files Found: C:\WINDOWS\SYSTEM32\DLH9JK~1.EXE - Deleted C:\Documents and Settings\luca\Dati applicazioni\Install.dat - Deleted C:\WINDOWS\system32\dlh9jkd1q8.exe - Deleted C:\WINDOWS\system32\kr_done1 - Deleted C:\WINDOWS\system32\vx.tll - Deleted C:\WINDOWS\system32\drivers\asc3550p.sys - Deleted Removing Temp Files... ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-17 20:31:21 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\\Programmi\\MSN Messenger\\msnmsgr.exe"="C:\\Programmi\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Programmi\\MSN Messenger\\livecall.exe"="C:\\Programmi\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:svchost" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "C:\\Programmi\\MSN Messenger\\msnmsgr.exe"="C:\\Programmi\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Programmi\\MSN Messenger\\livecall.exe"="C:\\Programmi\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files: --------------- File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes: Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Programmi\Messenger\msmsgs.exe" Fri 24 Sep 2004 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Thu 15 May 2003 43,008 ...H. --- "C:\Programmi\File comuni\Adobe\ESD\DLMCleanup.exe" Wed 14 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\42240f0e0835cbb61b7f5567bf62437b\BIT2.tmp" Sat 23 Dec 2006 444 ...HR --- "C:\Documents and Settings\luca\Dati applicazioni\SecuROM\UserData\securom_v7_01.bak" Fri 24 Sep 2004 4,348 ...H. --- "C:\Documents and Settings\luca\Documenti\Musica\Backup licenza\drmv1key.bak" Sun 2 Dec 2007 20 A..H. --- "C:\Documents and Settings\luca\Documenti\Musica\Backup licenza\drmv1lic.bak" Sat 30 Oct 2004 400 ...H. --- "C:\Documents and Settings\luca\Documenti\Musica\Backup licenza\drmv2key.bak" Sun 2 Dec 2007 1,536 A..H. --- "C:\Documents and Settings\luca\Documenti\Musica\Backup licenza\drmv2lic.bak" Finished! |
![]() |
![]() |
![]() |
#18 |
Senior Member
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
|
Fai un altro log di HiJackThis, così verifichiamo se è tutto ok.
__________________
Kaspersky Virus Removal Tool | Avira AntiVir Rescue System | Threatfire in Italiano | Norton User Account Control (beta) La tua prossima affermazione sarà un No? Rispondi con un Si o un No.
![]() |
![]() |
![]() |
![]() |
#19 |
Junior Member
Iscritto dal: Sep 2007
Messaggi: 13
|
Codice:
Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 20.59.46, on 17/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Programmi\a-squared Free\a2service.exe C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Programmi\Spyware Doctor\sdhelp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\notepad.exe C:\Programmi\PrevxCSI\prevxcsi.exe C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Programmi\MSN Messenger\msnmsgr.exe C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\Hijackthis\HiJackThis_v2.exe C:\WINDOWS\System32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 80.25.130.118:80 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.1.1;localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll O4 - HKLM\..\Run: [PrevxCSI] "C:\Programmi\PrevxCSI\prevxcsi.exe" -boot O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Salva oggetto con Net Transport - C:\Programmi\Xi\NetTransport 2\NTAddLink.html O8 - Extra context menu item: Salva tutti gli oggetti con Net Transport - C:\Programmi\Xi\NetTransport 2\NTAddList.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {F5BC716E-2650-4B08-9235-C110CF95017F} (Connessione Tiscali) - http://selfcare.tiscali.it/scripts/oneclick/ConnessioneTiscali.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A1420BB7-960A-41F9-AA1E-B62EE421A442}: NameServer = 212.216.112.112,212.216.172.62 O18 - Protocol: bw+0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {561E21D0-DFD1-4887-B098-5BAD77AC7503} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe (file missing) O23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\Programmi\Spyware Doctor\sdhelp.exe -- End of file - 17761 bytes |
![]() |
![]() |
![]() |
#20 |
Senior Member
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
|
Ora pare tutto OK. Puoi riattivare il Ripristino Configurazione di Sistema. Sarebbe meglio se installassi un firewall, puoi chiedere consiglio qui:
http://www.hwupgrade.it/forum/showthread.php?t=1559488 Aspetta però che qualcun altro abbia visto il log, perchè ci sono delle voci apparentemente legittime che però si ripetono troppe volte. Intanto cerco di capirne di più.
__________________
Kaspersky Virus Removal Tool | Avira AntiVir Rescue System | Threatfire in Italiano | Norton User Account Control (beta) La tua prossima affermazione sarà un No? Rispondi con un Si o un No.
![]() |
![]() |
![]() |
![]() |
Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 14:33.