| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| Teseus Mortale adepto
 
  
 
 Registrato: 02/07/07 21:01
 Messaggi: 30
 
 
 | 
			
				|  Inviato: 02 Lug 2007 21:09    Oggetto: Infezioni varie |   |  
				| 
 |  
				| Per favore...poichè nn ne capisco molto di questo programma (HIJACKTHIS). però so che da qui si scopre qualche cosa che nn và nel pc,gradirei gentilmente un aiuto su cosa eliminare e come tra la lista..Cmq un problema di sicuro ce l'ho...ovvero il maledetto Cid che mi apre le finestre di pubbl...cmq poi a volte il PC ,oltre a qst probl,sfarfalla con altri probl(tipo rallentamenti e blocco...)...ed ora ecco qui il LogFile 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 20.48.29, on 02/07/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16473)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\Programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
 C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
 C:\Programmi\Java\j2re1.4.2_03\bin\jusched.exe
 C:\Programmi\iTunes\iTunesHelper.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Programmi\Windows Defender\MSASCui.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\system32\CAPRPCSN.EXE
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\Programmi\iPod\bin\iPodService.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\Programmi\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
 C:\Programmi\MSN Messenger\msnmsgr.exe
 C:\Programmi\MSN Messenger\livecall.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Documents and Settings\Ditommaso\Documenti\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O1 - Hosts: 205.238.40.2 www.winmx.com
 O1 - Hosts: 205.238.40.2 err.winmx.com
 O1 - Hosts: 205.238.40.2 c3310.z1301.winmx.com
 O1 - Hosts: 67.18.233.36 c3311.z1301.winmx.com
 O1 - Hosts: 82.43.224.20 c3312.z1301.winmx.com
 O1 - Hosts: 209.67.209.50 c3313.z1301.winmx.com
 O1 - Hosts: 212.227.64.159 c3314.z1301.winmx.com
 O1 - Hosts: 205.238.40.2 c3315.z1301.winmx.com
 O1 - Hosts: 67.18.233.36 c3316.z1301.winmx.com
 O1 - Hosts: 82.43.224.20 c3317.z1301.winmx.com
 O1 - Hosts: 209.67.209.50 c3318.z1301.winmx.com
 O1 - Hosts: 212.227.64.159 c3319.z1301.winmx.com
 O1 - Hosts: 205.238.40.2 c3310.z1302.winmx.com
 O1 - Hosts: 67.18.233.36 c3311.z1302.winmx.com
 O1 - Hosts: 82.43.224.20 c3312.z1302.winmx.com
 O1 - Hosts: 209.67.209.50 c3313.z1302.winmx.com
 O1 - Hosts: 212.227.64.159 c3314.z1302.winmx.com
 O1 - Hosts: 205.238.40.2 c3315.z1302.winmx.com
 O1 - Hosts: 67.18.233.36 c3316.z1302.winmx.com
 O1 - Hosts: 82.43.224.20 c3317.z1302.winmx.com
 O1 - Hosts: 209.67.209.50 c3318.z1302.winmx.com
 O1 - Hosts: 212.227.64.159 c3319.z1302.winmx.com
 O1 - Hosts: 82.43.224.20 c3310.z1303.winmx.com
 O1 - Hosts: 67.18.233.36 c3311.z1303.winmx.com
 O1 - Hosts: 205.238.40.2 c3312.z1303.winmx.com
 O1 - Hosts: 209.67.209.50 c3313.z1303.winmx.com
 O1 - Hosts: 212.227.64.159 c3314.z1303.winmx.com
 O1 - Hosts: 82.43.224.20 c3315.z1303.winmx.com
 O1 - Hosts: 67.18.233.36 c3316.z1303.winmx.com
 O1 - Hosts: 205.238.40.2 c3317.z1303.winmx.com
 O1 - Hosts: 209.67.209.50 c3318.z1303.winmx.com
 O1 - Hosts: 212.227.64.159 c3319.z1303.winmx.com
 O1 - Hosts: 205.238.40.2 c3310.z1304.winmx.com
 O1 - Hosts: 67.18.233.36 c3311.z1304.winmx.com
 O1 - Hosts: 82.43.224.20 c3312.z1304.winmx.com
 O1 - Hosts: 209.67.209.50 c3313.z1304.winmx.com
 O1 - Hosts: 212.227.64.159 c3314.z1304.winmx.com
 O1 - Hosts: 205.238.40.2 c3315.z1304.winmx.com
 O1 - Hosts: 67.18.233.36 c3316.z1304.winmx.com
 O1 - Hosts: 82.43.224.20 c3317.z1304.winmx.com
 O1 - Hosts: 209.67.209.50 c3318.z1304.winmx.com
 O1 - Hosts: 212.227.64.159 c3319.z1304.winmx.com
 O1 - Hosts: 205.238.40.2 c3310.z1305.winmx.com
 O1 - Hosts: 67.18.233.36 c3311.z1305.winmx.com
 O1 - Hosts: 82.43.224.20 c3312.z1305.winmx.com
 O1 - Hosts: 209.67.209.50 c3313.z1305.winmx.com
 O1 - Hosts: 212.227.64.159 c3314.z1305.winmx.com
 O1 - Hosts: 205.238.40.2 c3315.z1305.winmx.com
 O1 - Hosts: 67.18.233.36 c3316.z1305.winmx.com
 O1 - Hosts: 82.43.224.20 c3317.z1305.winmx.com
 O1 - Hosts: 209.67.209.50 c3318.z1305.winmx.com
 O1 - Hosts: 212.227.64.159 c3319.z1305.winmx.com
 O1 - Hosts: 205.238.40.2 c3310.z1306.winmx.com
 O1 - Hosts: 67.18.233.36 c3311.z1306.winmx.com
 O1 - Hosts: 82.43.224.20 c3312.z1306.winmx.com
 O1 - Hosts: 209.67.209.50 c3313.z1306.winmx.com
 O1 - Hosts: 212.227.64.159 c3314.z1306.winmx.com
 O1 - Hosts: 205.238.40.2 c3315.z1306.winmx.com
 O1 - Hosts: 67.18.233.36 c3316.z1306.winmx.com
 O1 - Hosts: 82.43.224.20 c3317.z1306.winmx.com
 O1 - Hosts: 209.67.209.50 c3318.z1306.winmx.com
 O1 - Hosts: 212.227.64.159 c3319.z1306.winmx.com
 O1 - Hosts: 205.238.40.2 c3520.z1301.winmx.com
 O1 - Hosts: 67.18.233.36 c3521.z1301.winmx.com
 O1 - Hosts: 82.43.224.20 c3522.z1301.winmx.com
 O1 - Hosts: 209.67.209.50 c3523.z1301.winmx.com
 O1 - Hosts: 212.227.64.159 c3524.z1301.winmx.com
 O1 - Hosts: 205.238.40.2 c3525.z1301.winmx.com
 O1 - Hosts: 67.18.233.36 c3526.z1301.winmx.com
 O1 - Hosts: 82.43.224.20 c3527.z1301.winmx.com
 O1 - Hosts: 209.67.209.50 c3528.z1301.winmx.com
 O1 - Hosts: 212.227.64.159 c3529.z1301.winmx.com
 O1 - Hosts: 205.238.40.2 c3520.z1302.winmx.com
 O1 - Hosts: 67.18.233.36 c3521.z1302.winmx.com
 O1 - Hosts: 82.43.224.20 c3522.z1302.winmx.com
 O1 - Hosts: 209.67.209.50 c3523.z1302.winmx.com
 O1 - Hosts: 212.227.64.159 c3524.z1302.winmx.com
 O1 - Hosts: 205.238.40.2 c3525.z1302.winmx.com
 O1 - Hosts: 67.18.233.36 c3526.z1302.winmx.com
 O1 - Hosts: 82.43.224.20 c3527.z1302.winmx.com
 O1 - Hosts: 209.67.209.50 c3528.z1302.winmx.com
 O1 - Hosts: 212.227.64.159 c3529.z1302.winmx.com
 O1 - Hosts: 205.238.40.2 c3520.z1303.winmx.com
 O1 - Hosts: 67.18.233.36 c3521.z1303.winmx.com
 O1 - Hosts: 82.43.224.20 c3522.z1303.winmx.com
 O1 - Hosts: 209.67.209.50 c3523.z1303.winmx.com
 O1 - Hosts: 212.227.64.159 c3524.z1303.winmx.com
 O1 - Hosts: 205.238.40.2 c3525.z1303.winmx.com
 O1 - Hosts: 67.18.233.36 c3526.z1303.winmx.com
 O1 - Hosts: 82.43.224.20 c3527.z1303.winmx.com
 O1 - Hosts: 209.67.209.50 c3528.z1303.winmx.com
 O1 - Hosts: 212.227.64.159 c3529.z1303.winmx.com
 O1 - Hosts: 205.238.40.2 c3520.z1304.winmx.com
 O1 - Hosts: 67.18.233.36 c3521.z1304.winmx.com
 O1 - Hosts: 82.43.224.20 c3522.z1304.winmx.com
 O1 - Hosts: 209.67.209.50 c3523.z1304.winmx.com
 O1 - Hosts: 212.227.64.159 c3524.z1304.winmx.com
 O1 - Hosts: 205.238.40.2 c3525.z1304.winmx.com
 O1 - Hosts: 67.18.233.36 c3526.z1304.winmx.com
 O1 - Hosts: 82.43.224.20 c3527.z1304.winmx.com
 O1 - Hosts: 209.67.209.50 c3528.z1304.winmx.com
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {16875E09-927B-4494-82BD-158A1CD46BA0} - (no file)
 O2 - BHO: (no name) - {1B68470C-2DEF-493B-8A4A-8E2D81BE4EA5} - (no file)
 O2 - BHO: (no name) - {621D36CC-09F4-44F6-BA4C-C8FBEAA00207} - (no file)
 O2 - BHO: (no name) - {6AC3806F-8B39-4746-9C38-6B01CB7331FF} - (no file)
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: (no name) - {860AFC99-2262-4F26-B8AB-20715DBDE6AD} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Web Desk - {BD2E165D-1BC6-23AA-345B-1C234F173CBD} - (no file)
 O2 - BHO: (no name) - {D4DFC1D8-2D2E-4962-B0D0-389FBA0F76B5} - (no file)
 O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
 O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\System32\Spool\Drivers\w32x86\2\CAPONN.EXE
 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programmi\File comuni\Roxio Shared\System\EngUtil.exe"
 O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
 O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_03\bin\jusched.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
 O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [ccleaner] "C:\Programmi\CCleaner\ccleaner.exe" /AUTO
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Finestra di stato di Canon LBP-800.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll (file missing)
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll (file missing)
 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.it
 O15 - Trusted Zone: http://www.sostanze.it
 O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab50997.cab
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {1230CB21-C88D-11CF-0000-000000000000} - http://www.browserupdate.co.uk/cabs/customers/12345863/it010002.cab
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://grecen94unitedstates.spaces.live.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1144071530904
 O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab50997.cab
 O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5049/mcfscan.cab
 O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{0066D0D3-64E2-482B-AF74-52278D792184}: NameServer = 85.37.17.16 85.38.28.68
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O20 - Winlogon Notify: clbcatex - C:\WINDOWS\system32\clbcatix.dll (file missing)
 O20 - Winlogon Notify: st3 - C:\WINDOWS\system32\st3.dll (file missing)
 O20 - Winlogon Notify: style2 - C:\WINDOWS\system32\winstyle3.dll (file missing)
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 02 Lug 2007 21:47    Oggetto: |   |  
				| 
 |  
				| ciao, Teseus, benvenuto   
 disattiva il ripristino e avvia in mod. provvisoria
 avvia HiJack, seleziona "do a system scan only", metti la spunta alle voci indicate e premi "Fix checked":
 
 
  	  | Citazione: |  	  | O2 - BHO: (no name) - {16875E09-927B-4494-82BD-158A1CD46BA0} - (no file) O2 - BHO: (no name) - {1B68470C-2DEF-493B-8A4A-8E2D81BE4EA5} - (no file)
 O2 - BHO: (no name) - {621D36CC-09F4-44F6-BA4C-C8FBEAA00207} - (no file)
 O2 - BHO: (no name) - {6AC3806F-8B39-4746-9C38-6B01CB7331FF} - (no file)
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: (no name) - {860AFC99-2262-4F26-B8AB-20715DBDE6AD} - (no file)
 O2 - BHO: Web Desk - {BD2E165D-1BC6-23AA-345B-1C234F173CBD} - (no file)
 O2 - BHO: (no name) - {D4DFC1D8-2D2E-4962-B0D0-389FBA0F76B5} - (no file)
 
 O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
 
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll (file missing)
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll (file missing)
 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 
 O16 - DPF: {1230CB21-C88D-11CF-0000-000000000000} - http://www.browserupdate.co.uk/cabs/customers/12345863/it010002.cab
 
 O20 - Winlogon Notify: clbcatex - C:\WINDOWS\system32\clbcatix.dll (file missing)
 O20 - Winlogon Notify: st3 - C:\WINDOWS\system32\st3.dll (file missing)
 O20 - Winlogon Notify: style2 - C:\WINDOWS\system32\winstyle3.dll (file missing)
 | 
 
 Dai una ripulita ai files temporanei con CCleaner e/o ATF Cleaner
 rifai un nuovo log HJT e mettilo qui per un controllo.
 
 Evita, per favore, il linguaggio SMS:  rende difficile la lettura ed è anche vietato dal regolamento del forum.
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| Benny Moderatore Hardware e Networking
 
  
  
 Registrato: 28/01/06 15:35
 Messaggi: 6382
 Residenza: Non troppo vicino, mai troppo lontano
 
 | 
			
				|  Inviato: 02 Lug 2007 21:57    Oggetto: |   |  
				| 
 |  
				| Caspita Orange, sei troppo veloce... 
 Io darei anche una pulita a tutte le voci tipo
 
  	  | Codice: |  	  | O1 - Hosts: [...] .winmx.com | 
 comprese le prime due:
 
  	  | Codice: |  	  | O1 - Hosts: 205.238.40.2 www . winmx.com O1 - Hosts: 205.238.40.2 err.winmx.com
 | 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 02 Lug 2007 22:03    Oggetto: |   |  
				| 
 |  
				| non ho niente di meglio da fare questa sera.. 	  | Benny ha scritto: |  	  | Caspita Orange, sei troppo veloce... | 
   
 
 lo farei anch'io 	  | Benny ha scritto: |  	  | Io darei anche una pulita a tutte le voci tipo 
  	  | Codice: |  	  | O1 - Hosts: [...] .winmx.com | 
 | 
   ma se Teseus usa WinMX non sono da cancellare.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 02 Lug 2007 23:37    Oggetto: |   |  
				| 
 |  
				| Inoltre Teseus sei sprovvisto di firewall, installane uno (es. Zone Alarm, Outpost etc). Ciao.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Teseus Mortale adepto
 
  
 
 Registrato: 02/07/07 21:01
 Messaggi: 30
 
 
 | 
			
				|  Inviato: 03 Lug 2007 12:20    Oggetto: |   |  
				| 
 |  
				| Ragazzi vi ringrazio per il vostro aiuto.Ho levato pure gli host di winMX perchè tanto non lo susavo più.Inoltre per quanto riguarda il firwall ho Windows firwall.ed ora ecco il mio logfile attuale. 
 Logfile of HijackThis v1.99.1
 Scan saved at 12.13.36, on 03/07/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16473)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
 C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
 C:\Programmi\Java\j2re1.4.2_03\bin\jusched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\iTunes\iTunesHelper.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Programmi\Windows Defender\MSASCui.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
 C:\WINDOWS\system32\CAPRPCSN.EXE
 C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\Programmi\iPod\bin\iPodService.exe
 C:\Programmi\Alwil Software\Avast4\setup\avast.setup
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\Ditommaso\Documenti\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
 O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\System32\Spool\Drivers\w32x86\2\CAPONN.EXE
 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programmi\File comuni\Roxio Shared\System\EngUtil.exe"
 O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
 O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_03\bin\jusched.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
 O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [ccleaner] "C:\Programmi\CCleaner\ccleaner.exe" /AUTO
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Finestra di stato di Canon LBP-800.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.it
 O15 - Trusted Zone: http://www.sostanze.it
 O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab50997.cab
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://grecen94unitedstates.spaces.live.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1144071530904
 O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab50997.cab
 O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5049/mcfscan.cab
 O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 03 Lug 2007 12:52    Oggetto: |   |  
				| 
 |  
				|  	  | Teseus ha scritto: |  	  | Inoltre per quanto riguarda il firwall ho Windows firwall. | 
 Allora non hai nessun firewall degno di questo nome.
   Qui trovi alcuni validi firewall.
 Ti consiglio ZoneAlarm o PCTools. (che sono in italiano).
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| Teseus Mortale adepto
 
  
 
 Registrato: 02/07/07 21:01
 Messaggi: 30
 
 
 | 
			
				|  Inviato: 03 Lug 2007 12:56    Oggetto: |   |  
				| 
 |  
				| Ok,grazie per i consigli.Ma alla fine ,per quanto riguarda il LogFile è tutto apposto?Il CiD sembra che non rompa più,speriamo che continui così,vi faròà sicuramente sapere se ho problemi.CIAO! |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 03 Lug 2007 15:50    Oggetto: |   |  
				| 
 |  
				| hai fatto bene 	  | Teseus ha scritto: |  	  | Ho levato pure gli host di winMX perchè tanto non lo susavo più. | 
   
 il log è pulito.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |