| Precedente :: Successivo   | 
	
	
	
		| Autore | 
		Messaggio | 
	
	
		Danilo880 Comune mortale
  
 
  Registrato: 05/02/07 20:47 Messaggi: 2
 
  | 
		
			
				 Inviato: 13 Feb 2007 11:34    Oggetto: Popup ADSERVERPLUS | 
				     | 
			 
			
				
  | 
			 
			
				Salve.
 
Io ho il seguente problema...appena apro firefox si apre una finestra di explorer che si connette al sito adserverplus.
 
Di seguito riporto il log creato con hijack this:
 
 
Logfile of HijackThis v1.99.1
 
Scan saved at 19.41.27, on 05/02/2007
 
Platform: Windows XP SP2 (WinNT 5.01.2600)
 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
 
C:\WINDOWS\system32\winlogon.exe
 
C:\WINDOWS\system32\services.exe
 
C:\WINDOWS\system32\lsass.exe
 
C:\WINDOWS\system32\Ati2evxx.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
 
C:\WINDOWS\system32\Ati2evxx.exe
 
C:\WINDOWS\Explorer.EXE
 
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
 
D:\Programmi\Norton Personal Firewall\ISSVC.exe
 
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
 
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
 
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
 
C:\WINDOWS\system32\spoolsv.exe
 
d:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 
d:\Programmi\Alwil Software\Avast4\ashServ.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
 
C:\Programmi\Canon\CAL\CALMAIN.exe
 
d:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 
d:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 
C:\WINDOWS\Mixer.exe
 
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 
D:\Programmi\Logitech\iTouch\iTouch.exe
 
C:\Programmi\Java\jre1.5.0_09\bin\jusched.exe
 
d:\Programmi\Logitech\MouseWare\system\em_exec.exe
 
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
 
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
 
C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe
 
C:\WINDOWS\system32\ctfmon.exe
 
C:\Programmi\Internet Explorer\iexplore.exe
 
c:\progra~1\intern~1\iexplore.exe
 
C:\Programmi\PowerMenu\PowerMenu.exe
 
D:\Programmi\eMule0.47c\emule.exe
 
D:\Programmi\Mozilla Firefox\firefox.exe
 
C:\Documents and Settings\MED\Desktop\HijackThis.exe
 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 
O2 - BHO: (no name) - AutorunsDisabled - (no file)
 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - d:\PROGRA~1\SPYBOT~1\SDHelper.dll
 
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
 
O2 - BHO: Norton Personal Firewall - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
 
O3 - Toolbar: Norton Personal Firewall - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
 
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
 
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 
O4 - HKLM\..\Run: [zBrowser Launcher] d:\Programmi\Logitech\iTouch\iTouch.exe
 
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
 
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe"
 
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
 
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmi\QuickTime\qttask.exe" -atboottime
 
O4 - HKLM\..\Run: [avast!] d:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
 
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
 
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 
O4 - Global Startup: PowerMenu.lnk = C:\Programmi\PowerMenu\PowerMenu.exe
 
O8 - Extra context menu item: &Clean Traces - d:\Programmi\DAP\Privacy Package\dapcleanerie.htm
 
O8 - Extra context menu item: &Download with &DAP - D:\Programmi\DAP\dapextie.htm
 
O8 - Extra context menu item: Download &all with DAP - D:\Programmi\DAP\dapextie2.htm
 
O8 - Extra context menu item: Download Using &BitSpirit - D:\Programmi\BitSpirit\bsurl.htm
 
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
 
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
 
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
 
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
 
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://danilofreeland.spaces.msn.com//PhotoUpload/MsnPUpld.cab
 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
 
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - d:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 
O23 - Service: avast! Antivirus - Unknown owner - d:\Programmi\Alwil Software\Avast4\ashServ.exe
 
O23 - Service: avast! Mail Scanner - Unknown owner - d:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 
O23 - Service: avast! Web Scanner - Unknown owner - d:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmi\Canon\CAL\CALMAIN.exe
 
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
 
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
 
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
 
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
 
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
 
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - D:\Programmi\Norton Personal Firewall\ISSVC.exe
 
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
 
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
 
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe 
 
 
Che faccio?
 
Grazie mille. | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		camelxxx Comune mortale
  
 
  Registrato: 13/02/07 13:13 Messaggi: 4
 
  | 
		
			
				 Inviato: 13 Feb 2007 13:31    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Anch'io stesso problema:
 
 
Logfile of HijackThis v1.99.1
 
Scan saved at 12.21.19, on 13/02/2007
 
Platform: Windows XP SP2 (WinNT 5.01.2600)
 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
 
C:\WINDOWS\system32\winlogon.exe
 
C:\WINDOWS\system32\services.exe
 
C:\WINDOWS\system32\lsass.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\WINDOWS\system32\spoolsv.exe
 
c:\windows\system32\services.exe
 
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 
C:\WINDOWS\Explorer.EXE
 
C:\WINDOWS\system32\nvsvc32.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\Bonjour\mDNSResponder.exe
 
C:\WINDOWS\Mixer.exe
 
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
 
C:\Programmi\iTunes\iTunesHelper.exe
 
C:\WINDOWS\system32\dla\tfswctrl.exe
 
C:\Programmi\File comuni\Logitech\VidDrvr\LVCOMS.EXE
 
C:\Programmi\lg_fwupdate\fwupdate.exe
 
C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
 
C:\Programmi\ADSL\StarModem ADSL USB MODEM\dslmon.exe
 
C:\WINDOWS\system32\wscntfy.exe
 
C:\Programmi\iPod\bin\iPodService.exe
 
c:\progra~1\intern~1\iexplore.exe
 
C:\Programmi\Internet Explorer\iexplore.exe
 
C:\Programmi\Internet Explorer\iexplore.exe
 
C:\Programmi\MSN Messenger\msnmsgr.exe
 
C:\Programmi\MSN Messenger\usnsvc.exe
 
C:\Programmi\Internet Explorer\iexplore.exe
 
C:\Documents and Settings\silvio\Desktop\HijackThis.exe
 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
 
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
 
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
 
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
 
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
 
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 
O4 - HKLM\..\Run: [IEAgent update check] C:\WINDOWS\system32\iewatch.exe
 
O4 - HKLM\..\Run: [KAVPersonal50] C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
 
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
 
O4 - HKLM\..\Run: [StorageGuard] "C:\Programmi\File comuni\Sonic\Update Manager\sgtray.exe" /r
 
O4 - HKLM\..\Run: [LVCOMS] C:\Programmi\File comuni\Logitech\VidDrvr\LVCOMS.EXE
 
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
 
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
 
O4 - HKLM\..\Run: [LGODDFU] C:\Programmi\lg_fwupdate\fwupdate.exe
 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
 
O4 - HKLM\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
 
O4 - HKLM\..\Run: [tsklvpsk] "c:\windows\system32\tsklvpsk.exe"
 
O4 - HKCU\..\Run: [MSN Webcam Recorder] "C:\Programmi\MSN Webcam Recorder\ml20gui.exe" -silent
 
O4 - HKCU\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
 
O4 - HKCU\..\Run: [README BONE] C:\DOCUME~1\silvio\DATIAP~1\MATHFO~1\ball log.exe
 
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
 
O4 - Global Startup: DSLMON.lnk = ?
 
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Programmi\MP3 Player Utilities 3.75\AMVConverter\grab.html
 
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
 
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
 
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Programmi\MP3 Player Utilities 3.75\MediaManager\grab.html
 
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe
 
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe
 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O10 - Unknown file in Winsock LSP: c:\programmi\bonjour\mdnsnsp.dll
 
O15 - Trusted Zone: *.rossoalice.it
 
O15 - Trusted Zone: *.rossoalice.virgilio.it
 
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
 
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://silvioacab.spaces.live.com//PhotoUpload/MsnPUpld.cab
 
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
 
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
 
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{4132E911-7079-43EF-BA12-AE8A39B26055}: NameServer = 85.37.17.50 85.38.28.76
 
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 
O20 - AppInit_DLLs: MsgPlusLoader.dll
 
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 
O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 
O23 - Service: kavsvc - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
 
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Programmi\File comuni\Macromedia Shared\Service\Macromedia Licensing.exe
 
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		camelxxx Comune mortale
  
 
  Registrato: 13/02/07 13:13 Messaggi: 4
 
  | 
		
			
				 Inviato: 13 Feb 2007 15:22    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				credo di aver risolto con:
 
SUPERAntiSpyware | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Smjert Dio maturo
  
  
  Registrato: 01/04/06 18:19 Messaggi: 1619 Residenza: Perso nella rete
  | 
		
			
				 Inviato: 13 Feb 2007 17:52    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				| @camelxxx: Evita di postare il tuo problema su 2 topic solo per metterlo in risalto.. creane 1 tuo e basta! | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		camelxxx Comune mortale
  
 
  Registrato: 13/02/07 13:13 Messaggi: 4
 
  | 
		
			
				 Inviato: 14 Feb 2007 18:49    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				 	  | Smjert ha scritto: | 	 		  | @camelxxx: Evita di postare il tuo problema su 2 topic solo per metterlo in risalto.. creane 1 tuo e basta! | 	  
 
 
ok, mi ero accorto solo dopo che quel problema nel topic era stato risolto! | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Smjert Dio maturo
  
  
  Registrato: 01/04/06 18:19 Messaggi: 1619 Residenza: Perso nella rete
  | 
		
			
				 Inviato: 14 Feb 2007 19:50    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				#Danilo880:
 
 
Avvia HijackThis, premi Do a system scan only, spunta queste voci e poi premi FixChecked:
 
 	  | Citazione: | 	 		  
 
O2 - BHO: (no name) - AutorunsDisabled - (no file)
 
O8 - Extra context menu item: &Clean Traces - d:\Programmi\DAP\Privacy Package\dapcleanerie.htm
 
O8 - Extra context menu item: &Download with &DAP - D:\Programmi\DAP\dapextie.htm
 
O8 - Extra context menu item: Download &all with DAP - D:\Programmi\DAP\dapextie2.htm 
 
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
 
O4 - HKLM\..\Run: [tsklvpsk] "c:\windows\system32\tsklvpsk.exe" | 	  
 
 
Cancella la cartella D\Programmi\DAP (o disinstalla il programma.. è un download accelerator ma viene considerato come veicolo di Spyware).
 
 
@Camelxxx:
 
 
Avvia HijackThis, premi Do a system scan only, spunta queste voci e poi premi FixChecked(non fixare le voci in rosso se sai cosa sono):
 
 
 	  | Citazione: | 	 		  R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll 
 
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 
O4 - HKLM\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
 
O4 - HKCU\..\Run: [MSN Webcam Recorder] "C:\Programmi\MSN Webcam Recorder\ml20gui.exe" -silent
 
O4 - HKCU\..\Run: [README BONE] C:\DOCUME~1\silvio\DATIAP~1\MATHFO~1\ball log.exe
 
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) | 	  
 
 
Scarica sul desktop questi due tool camuffati:
 
 
Prevx
 
http://www.prevx.com/gromozon.asp
 
 
Symantec
 
http://www.mytempdir.com/1213520
 
 
Fai partire prima il tool Prevx e fagli fare una scansione, alla fine ti chiederà di riavviare il pc, tu accetta.
 
 
Quando ha finito di riavviare il pc tu riavvialo di nuovo in Modalità Provvisoria (quando ti fa il calcolo della memoria, ti segna gli hd collegati ecc premi continuamente F8 finchè non appare un menu, da lì scegli con le freccie la modalità).
 
 
Da lì scompatta l'archivio e fai partire il tool Symantec facendogli fare una scansione.
 
 
Quando ha finito:
 
 	  | Citazione: | 	 		  Apri una cartella qualunque, vai su 
 
Strumenti->Opzioni Cartella->scheda Visualizzazione, 
 
spunta la voce "Visualizza cartelle e file nascosti", togli la spunta a 
 
"Nascondi file protetti di sistema" (digli di sì). 
 
 | 	  
 
 
Cancella questo file (se c'è) C:\DOCUME~1\silvio\DATIAP~1\MATHFO~1\ball log.exe
 
 
Cancella queste cartelle (se sai cosa sono non cancellarle) C:\Programmi\Macrogaming, C:\Programmi\MSN Webcam Recorder, %ProgramFiles%\WinPcap\rpcapd.exe(programfiles dovrebbe essere C:\Programmi\File Comuni ma può anche essere C:\Programmi\Program Files o semplicemente C:\Programmi).
 
 
Riavvia il pc in Modalità Normale
 
 
Vai su Start->Esegui->digita control userpasswords2, ti si apre una finestra con una lista di account, forse ce ne sono alcuni con nomi assurdi (tipo aSFScvE o cose così), selezionali e premi Rimuovi (ASPNET non è da rimuovere!)
 
 
Ora sempre da Esegui dai services.msc, ti si apre una finestra con la lista dei servizi, scorrila e cerca se ci sono delle voci che nella colonna Connessione hanno un valore che non sia Sistema locale o Servizio di rete (se li trovi potrai notare che hanno lo stesso nome di quegli account strani che hai trovato).
 
 
Vai poi in C:\Documents and Settings\ e cancella le cartelle con quel nome assurdo (nome identico agli account precedentemente rimossi).
 
 
Posta un nuovo log di HijackThis, il log del tool Prevx (Gromozon_Removal.log) e del tool Symantec (FixLinkOpt.log) | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		 |