| Precedente :: Successivo   | 
	
	
	
		| Autore | 
		Messaggio | 
	
	
		stoner Mortale devoto
  
 
  Registrato: 23/07/07 14:44 Messaggi: 7
 
  | 
		
			
				 Inviato: 23 Lug 2007 16:34    Oggetto: il pc si blocca totalmente, virus? | 
				     | 
			 
			
				
  | 
			 
			
				ciao a ttt!!!
 
da un po' di giorni il mio pc si blocca e per farlo ripartire devo resettarlo. ho fatto scansioni con l'antivirus ma non ce ne sono.
 
ho usato hijackthis, allego il risultato:
 
 
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 
Scan saved at 16.30.48, on 23/07/2007
 
Platform: Windows XP SP2 (WinNT 5.01.2600)
 
Boot mode: Normal
 
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
 
C:\WINDOWS\system32\winlogon.exe
 
C:\WINDOWS\system32\services.exe
 
C:\WINDOWS\system32\lsass.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\Windows Defender\MsMpEng.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\Programmi\Ahead\InCD\InCDsrv.exe
 
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 
C:\WINDOWS\Explorer.EXE
 
C:\Programmi\Alwil Software\Avast4\ashServ.exe
 
C:\Programmi\Ahead\InCD\InCD.exe
 
C:\WINDOWS\RTHDCPL.EXE
 
C:\WINDOWS\system32\RUNDLL32.EXE
 
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
C:\WINDOWS\system32\ctfmon.exe
 
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
 
C:\WINDOWS\system32\spoolsv.exe
 
C:\Programmi\OpenOffice.org 2.2\program\soffice.exe
 
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
 
C:\Programmi\OpenOffice.org 2.2\program\soffice.BIN
 
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
 
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
 
C:\Programmi\HP\Digital Imaging\bin\hpqSTE08.exe
 
C:\WINDOWS\system32\nvsvc32.exe
 
c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 
C:\Programmi\MSN Messenger\usnsvc.exe
 
C:\Programmi\MSN Messenger\msnmsgr.exe
 
C:\Programmi\eMule\emule.exe
 
C:\Programmi\Internet Explorer\iexplore.exe
 
C:\Programmi\HiJackthis\HiJackThis_v2.exe
 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/oggi/indexbb.html
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 
O4 - HKLM\..\Run: [InCD] C:\Programmi\Ahead\InCD\InCD.exe
 
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
 
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 
O4 - HKCU\..\Run: [IncrediMail] C:\Programmi\IncrediMail\bin\IncMail.exe /c
 
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmi\OpenOffice.org 2.2\program\quickstart.exe
 
O4 - Startup: Registration Tom Clancy's Splinter Cell 3 - Chaos Theory.LNK = C:\Programmi\Ubisoft\Tom Clancy's Splinter Cell Chaos Theory\Register\RegistrationReminder.exe
 
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
 
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
 
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
 
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
 
O15 - Trusted Zone: http://www.msi.com.tw
 
O16 - DPF: Yahoo! Pool 2 - http://download2.games.yahoo.com/games/clients/y/poti_x.cab
 
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
 
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
 
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
 
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
 
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
 
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
 
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D7D1878-260F-4C9A-855E-8E7EEE409872}: NameServer = 85.37.17.14 85.38.28.78
 
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
 
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
 
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
 
 
--
 
End of file - 8805 bytes | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Sante62 Dio maturo
  
  
  Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
  | 
		
			
				 Inviato: 23 Lug 2007 17:07    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ciao.
 
 
esegui hijackthis 
 
clicca su scan 
 
metti il segno di spunta a sinistra di queste voci:
 
 
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 
 
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 
 
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)  
 
  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file  
 
 
O15 - Trusted Zone: http://www.msi.com.tw questo se lo conosci non eliminarlo.
 
 
clicca fix checked 
 
Riavvia il pc, rifai il log di hijackthis e postalo 
 
 
Poi, fai anche questi passaggi: 
 
http://forum.zeusnews.com/viewtopic.php?p=194965#194965 passaggio 1 - 
 
 
http://forum.zeusnews.com/viewtopic.php?p=194966#194966 passaggio 2 - | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		stoner Mortale devoto
  
 
  Registrato: 23/07/07 14:44 Messaggi: 7
 
  | 
		
			
				 Inviato: 23 Lug 2007 18:22    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ecco il log di HijackThis
 
 
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 
Scan saved at 18.16.51, on 23/07/2007
 
Platform: Windows XP SP2 (WinNT 5.01.2600)
 
Boot mode: Normal
 
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
 
C:\WINDOWS\system32\winlogon.exe
 
C:\WINDOWS\system32\services.exe
 
C:\WINDOWS\system32\lsass.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\Windows Defender\MsMpEng.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\Programmi\Ahead\InCD\InCDsrv.exe
 
C:\WINDOWS\Explorer.EXE
 
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 
C:\Programmi\Alwil Software\Avast4\ashServ.exe
 
C:\Programmi\Ahead\InCD\InCD.exe
 
C:\WINDOWS\RTHDCPL.EXE
 
C:\WINDOWS\system32\RUNDLL32.EXE
 
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
C:\WINDOWS\system32\ctfmon.exe
 
C:\Programmi\MSN Messenger\MsnMsgr.Exe
 
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 
C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
 
C:\Programmi\OpenOffice.org 2.2\program\soffice.exe
 
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
 
C:\WINDOWS\system32\spoolsv.exe
 
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
 
C:\Programmi\OpenOffice.org 2.2\program\soffice.BIN
 
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
 
C:\Programmi\HP\Digital Imaging\bin\hpqSTE08.exe
 
C:\WINDOWS\system32\nvsvc32.exe
 
c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 
C:\WINDOWS\system32\wuauclt.exe
 
C:\Programmi\Internet Explorer\iexplore.exe
 
C:\Programmi\HiJackthis\HiJackThis_v2.exe
 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/oggi/indexbb.html
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 
O4 - HKLM\..\Run: [InCD] C:\Programmi\Ahead\InCD\InCD.exe
 
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 
O4 - HKCU\..\Run: [IncrediMail] C:\Programmi\IncrediMail\bin\IncMail.exe /c
 
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmi\OpenOffice.org 2.2\program\quickstart.exe
 
O4 - Startup: Registration Tom Clancy's Splinter Cell 3 - Chaos Theory.LNK = C:\Programmi\Ubisoft\Tom Clancy's Splinter Cell Chaos Theory\Register\RegistrationReminder.exe
 
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
 
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
 
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
 
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
 
O15 - Trusted Zone: http://www.msi.com.tw
 
O16 - DPF: Yahoo! Pool 2 - http://download2.games.yahoo.com/games/clients/y/poti_x.cab
 
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
 
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
 
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
 
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
 
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
 
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
 
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D7D1878-260F-4C9A-855E-8E7EEE409872}: NameServer = 85.37.17.14 85.38.28.78
 
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
 
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
 
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
 
 
--
 
 
 
 
FindAWF
 
Find AWF report by noahdfear ©2006
 
 
 
  bak folders found
 
  ~~~~~~~~~~~
 
 
 
 
  Duplicate files of bak directory contents
 
  ~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
  end of report
 
 
link n°1 gmer:
 
http://www.freefilehosting.net/download/NDA5NA==
 
 
link n°2 gmer: 
 
http://www.freefilehosting.net/download/NDEwMA== | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Sante62 Dio maturo
  
  
  Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
  | 
		
			
				 Inviato: 24 Lug 2007 01:52    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Il log di HJT è pulito.
 
Anche i log di GMER mi sembrano a posto.
 
Tu riscontri ancora problemi? | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		stoner Mortale devoto
  
 
  Registrato: 23/07/07 14:44 Messaggi: 7
 
  | 
		
			
				 Inviato: 24 Lug 2007 14:51    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				| si, si è bloccato ancora. Cmq grazie mille per l'aiuto!!! | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Sante62 Dio maturo
  
  
  Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
  | 
		
			
				 Inviato: 24 Lug 2007 20:24    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Scusa, ma si blocca all'avvio?
 
Quando stai facendo qualche operazione in particolare?
 
Emette qualche messaggio di errore?
 
Dacci più informazioni possibili.
 
Ciao. | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		stoner Mortale devoto
  
 
  Registrato: 23/07/07 14:44 Messaggi: 7
 
  | 
		
			
				 Inviato: 24 Lug 2007 21:14    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				| si blocca qualche volta quando faccio scansioni con l'antivirus, a volte quando navigo in internet... | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Sante62 Dio maturo
  
  
  Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
  | 
		
			
				 Inviato: 24 Lug 2007 23:15    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Dici che si blocca qualche volta......
 
Proviamo a fare una scansione online con Kaspersky, quì è scritto come fare: http://forum.zeusnews.com/viewtopic.php?t=21705
 
Potrebbe essere necessario che disattivi l'antivirus e il firewall mentre scarichi i file necessari e chiudi tutti i programmi e finestre aperte. Quando inizia la scansione del PC, disconnettiti da internet.
 
Quando ha finito carica il risultato su www.freefilehosting.net e metti quì il link che ti viene assegnato.
 
Ciao. | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Sante62 Dio maturo
  
  
  Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
  | 
		
			
				 Inviato: 24 Lug 2007 23:41    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Comunque, ho l'impressione che sia questa la riga che ti provoca il blocco:
 
 
O15 - Trusted Zone: http://www.msi.com.tw  | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		stoner Mortale devoto
  
 
  Registrato: 23/07/07 14:44 Messaggi: 7
 
  | 
		
			
				 Inviato: 25 Lug 2007 12:59    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				ecco il link:
 
http://www.freefilehosting.net/download/NDYzMg== 
 
 
tolgo anche O15 - Trusted Zone: http://www.msi.com.tw | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Sante62 Dio maturo
  
  
  Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
  | 
		
			
				 Inviato: 25 Lug 2007 15:01    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ciao.
 
Disattiva il ripristino configurazione di sistema:
 
http://forum.zeusnews.com/viewtopic.php?t=22084
 
 
Scarica Avenger http://swandog46.geekstogo.com/avenger.zip
 
 
Avvialo, Clicca su Input Script Manually;
 
Clicca sulla lente d'ingrandimento 
 
All'interno del box bianco, copia e incolla la seguente scritta in rosso:
 
 
Files to Delete:
 
C:\WINDOWS\system\smss.exe Clicca su Done;
 
Clicca sul semaforo. Il PC si riavvierà Se non è così riavvialo tu.
 
Alla fine dell'operazione posta quì il log rilasciato.
 
Lo trovi su C:\Avenger.txt
 
Vedi come va il PC adesso.
 
Ciao. | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		stoner Mortale devoto
  
 
  Registrato: 23/07/07 14:44 Messaggi: 7
 
  | 
		
			
				 Inviato: 25 Lug 2007 16:49    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				ciao
 
ecco il log:
 
Logfile of The Avenger version 1, by Swandog46
 
Running from registry key:
 
\Registry\Machine\System\CurrentControlSet\Services\cmcsapxd
 
 
*******************
 
 
Script file located at: \??\C:\WINDOWS\system32\squdpdta.txt
 
Script file opened successfully.
 
 
Script file read successfully
 
 
Backups directory opened successfully at C:\Avenger
 
 
*******************
 
 
Beginning to process script file:
 
 
File C:\WINDOWS\system\smss.exe deleted successfully.
 
 
Completed script processing.
 
 
*******************
 
 
Finished!  Terminate.
 
 
grazie per l'aiuto   
 
se si blocca ancora te lo dirò. ciao | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Sante62 Dio maturo
  
  
  Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
  | 
		
			
				 Inviato: 25 Lug 2007 18:01    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				OK   | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		 |