| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| petenzella Mortale devoto
 
  
 
 Registrato: 29/05/07 14:00
 Messaggi: 7
 
 
 | 
			
				|  Inviato: 29 Mag 2007 14:53    Oggetto: Aiuto cid !!!! |   |  
				| 
 |  
				| non so cosa fare ho usato  CCLEANER, e fatto la scansione con nod32 ma ho letto che non e un virus e quindi nn viene rilevato leggendo ho saputo di hijackthis e ecco il risultato vi chiedo solo di essere  semplici nello spiegare xche nn e che ci capisco molto: 
 Logfile of HijackThis v1.99.1
 Scan saved at 14.51.48, on 29/05/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16441)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\HPQ\Quick Launch Buttons\EabServr.exe
 C:\WINDOWS\System32\igfxtray.exe
 C:\WINDOWS\System32\hkcmd.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\Programmi\Eset\nod32kui.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Eset\nod32krn.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Ulead Systems\Ulead Photo Express 4.0\CalCheck.exe
 C:\PROGRA~1\Webshots\webshots.scr
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\Directory temporanea 1 per hijackthis_199.zip\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmi\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
 O4 - HKLM\..\Run: [Blue Cake Pop Meta] C:\Documents and Settings\All Users\Dati applicazioni\FaceFragBlueCake\Thunk Dale.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [BitTorrent] "C:\Programmi\BitTorrent\bittorrent.exe" --force_start_minimized
 O4 - Startup: Webshots.lnk = C:\Programmi\Webshots\Launcher.exe
 O4 - Global Startup: Ulead Photo Express Calendar Checker.lnk = C:\Programmi\Ulead Systems\Ulead Photo Express 4.0\CalCheck.exe
 O8 - Extra context menu item: &Webshots Photo Search - res://C:\Programmi\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O12 - Plugin for .UVR: C:\Programmi\Internet Explorer\Plugins\NPUPano.dll
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1168278813725
 O17 - HKLM\System\CCS\Services\Tcpip\..\{0ECD35D5-6E69-48FE-99F7-95BFB87B386A}: NameServer = 192.168.1.1
 O17 - HKLM\System\CS1\Services\Tcpip\..\{0ECD35D5-6E69-48FE-99F7-95BFB87B386A}: NameServer = 192.168.1.1
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmi\HPQ\SHARED\HPQWMI.exe
 O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Programmi\Eset\nod32krn.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 
 
 
  auitatemi vi prego sto impazzendo  |  |  
		| Top |  |  
		|  |  
		| petenzella Mortale devoto
 
  
 
 Registrato: 29/05/07 14:00
 Messaggi: 7
 
 
 | 
			
				|  Inviato: 29 Mag 2007 15:06    Oggetto: SCUSATEMI |   |  
				| 
 |  
				| prima di fare l'operezione sopra ho disattivato ripristino config. ma non ho riavviato in modalità provvisoria devo farlo? |  |  
		| Top |  |  
		|  |  
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 29 Mag 2007 17:49    Oggetto: |   |  
				| 
 |  
				| ciao, benvenuto/a!   
 devi avviare in mod. provvisoria solo per fissare le voci con HiJack...
   
 ora: avvia in mod. provvisoria
 avvia HiJack, seleziona "do a system scan only", metti la spunta a queste voci e premi "Fix checked":
 
 O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
 O4 - HKLM\..\Run: [Blue Cake Pop Meta] C:\Documents and Settings\All Users\Dati applicazioni\FaceFragBlueCake\Thunk Dale.exe
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 
 trova e cancella Thunk Dale.exe (in C:\Documents and Settings)
 
 riposta il log aggiornato
 |  |  
		| Top |  |  
		|  |  
		| petenzella Mortale devoto
 
  
 
 Registrato: 29/05/07 14:00
 Messaggi: 7
 
 
 | 
			
				|  Inviato: 30 Mag 2007 15:08    Oggetto: Ho fatto come hai detto |   |  
				| 
 |  
				| Ecco l'aggiornamento ora navigo un po e controllo se e sparito Grazieeee; Logfile of HijackThis v1.99.1
 Scan saved at 15.07.07, on 30/05/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16441)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Eset\nod32krn.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\HPQ\Quick Launch Buttons\EabServr.exe
 C:\WINDOWS\System32\igfxtray.exe
 C:\WINDOWS\System32\hkcmd.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\Programmi\Eset\nod32kui.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Ulead Systems\Ulead Photo Express 4.0\CalCheck.exe
 C:\PROGRA~1\Webshots\webshots.scr
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\Directory temporanea 4 per hijackthis_199.zip\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmi\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [BitTorrent] "C:\Programmi\BitTorrent\bittorrent.exe" --force_start_minimized
 O4 - Startup: Webshots.lnk = C:\Programmi\Webshots\Launcher.exe
 O4 - Global Startup: Ulead Photo Express Calendar Checker.lnk = C:\Programmi\Ulead Systems\Ulead Photo Express 4.0\CalCheck.exe
 O8 - Extra context menu item: &Webshots Photo Search - res://C:\Programmi\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O12 - Plugin for .UVR: C:\Programmi\Internet Explorer\Plugins\NPUPano.dll
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1168278813725
 O17 - HKLM\System\CCS\Services\Tcpip\..\{0ECD35D5-6E69-48FE-99F7-95BFB87B386A}: NameServer = 192.168.1.1
 O17 - HKLM\System\CS1\Services\Tcpip\..\{0ECD35D5-6E69-48FE-99F7-95BFB87B386A}: NameServer = 192.168.1.1
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmi\HPQ\SHARED\HPQWMI.exe
 O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Programmi\Eset\nod32krn.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 |  |  
		| Top |  |  
		|  |  
		| petenzella Mortale devoto
 
  
 
 Registrato: 29/05/07 14:00
 Messaggi: 7
 
 
 | 
			
				|  Inviato: 30 Mag 2007 15:31    Oggetto: |   |  
				| 
 |  
				| Sono passati piu di 20 minuti quindi credo di aver eliminato il microbo grazieeee |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |