| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| ulfgar Comune mortale
 
  
 
 Registrato: 18/08/07 10:24
 Messaggi: 4
 
 
 | 
			
				|  Inviato: 18 Ago 2007 10:30    Oggetto: |   |  
				| 
 |  
				| Anche io mi sono beccato lo stesso virus che mi ha eliminato il file rasapi.dll facendo l'antivir... Leggendo il forum ci ho smanettato qui e la credo di averlo ripulito ma mi sembra che mi dia ancora problemi.
 Ho installato anche zoneallarm e il traffico delle connessione controllate mi sembra comunque sospetto.
 Allego il file della scansione fatta con HiJackThis_v2
 
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 10.19.48, on 18/08/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 C:\WINDOWS\system32\DVDRAMSV.exe
 C:\WINDOWS\system32\HDDSvc.exe
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Toshiba\TOSHIBA Applet\TAPPSRV.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Programmi\Toshiba\Toshiba Applet\thotkey.exe
 C:\WINDOWS\system32\TPSMain.exe
 C:\Programmi\TOSHIBA\ConfigFree\NDSTray.exe
 C:\Programmi\TOSHIBA\Tvs\TvsTray.exe
 C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
 C:\windows\system32\services.exe
 C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
 C:\WINDOWS\system32\TPSBattM.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe
 C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 C:\WINDOWS\system32\RAMASST.exe
 C:\Documents and Settings\Alfeo\Desktop\HiJackThis_v2\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programmi\Free Download Manager\iefdmcks.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [THotkey] C:\Programmi\Toshiba\Toshiba Applet\thotkey.exe
 O4 - HKLM\..\Run: [PadTouch] C:\Programmi\TOSHIBA\Touch and Launch\PadExe.exe
 O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
 O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
 O4 - HKLM\..\Run: [Tvs] C:\Programmi\TOSHIBA\Tvs\TvsTray.exe
 O4 - HKLM\..\Run: [SmoothView] C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
 O4 - HKLM\..\Run: [updixrqr] "c:\windows\system32\updixrqr.exe"
 O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe"
 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
 O4 - HKLM\..\Run: [HDInspector.exe] C:\Programmi\Hard Drive Inspector\HDInspector.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
 O8 - Extra context menu item: Scarica con Free Download Manager - file://C:\Programmi\Free Download Manager\dllink.htm
 O8 - Extra context menu item: Scarica selezionati con Free Download Manager - file://C:\Programmi\Free Download Manager\dlselected.htm
 O8 - Extra context menu item: Scarica tutto con Free Download Manager - file://C:\Programmi\Free Download Manager\dlall.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1180187758677
 O17 - HKLM\System\CCS\Services\Tcpip\..\{2C3E93EF-6BDE-4033-B5BD-FEFA3312FF06}: NameServer = 151.99.125.2,151.99.125.3
 O17 - HKLM\System\CS1\Services\Tcpip\..\{2C3E93EF-6BDE-4033-B5BD-FEFA3312FF06}: NameServer = 151.99.125.2,151.99.125.3
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
 O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (http://www.altrixsoft.com/) - C:\WINDOWS\system32\HDDSvc.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Programmi\Toshiba\TOSHIBA Applet\TAPPSRV.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
 --
 End of file - 7784 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ulfgar Comune mortale
 
  
 
 Registrato: 18/08/07 10:24
 Messaggi: 4
 
 
 | 
			
				|  Inviato: 19 Ago 2007 18:56    Oggetto: |   |  
				| 
 |  
				| ok ho fatto come mi hai detto. Grazie per la risposta tempestiva.
 ho cancellato fixato la voce che mi hai detto ti allego e ho rifatto lo scan.
 
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 18.54.40, on 19/08/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 C:\WINDOWS\system32\DVDRAMSV.exe
 C:\WINDOWS\system32\HDDSvc.exe
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Toshiba\TOSHIBA Applet\TAPPSRV.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Programmi\Toshiba\Toshiba Applet\thotkey.exe
 C:\WINDOWS\system32\TPSMain.exe
 C:\Programmi\TOSHIBA\ConfigFree\NDSTray.exe
 C:\Programmi\TOSHIBA\Tvs\TvsTray.exe
 C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
 C:\windows\system32\winlogon.exe
 C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
 C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe
 C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Programmi\Hard Drive Inspector\HDInspector.exe
 C:\WINDOWS\system32\TPSBattM.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\HiJackThis_v2\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programmi\Free Download Manager\iefdmcks.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [THotkey] C:\Programmi\Toshiba\Toshiba Applet\thotkey.exe
 O4 - HKLM\..\Run: [PadTouch] C:\Programmi\TOSHIBA\Touch and Launch\PadExe.exe
 O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
 O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
 O4 - HKLM\..\Run: [Tvs] C:\Programmi\TOSHIBA\Tvs\TvsTray.exe
 O4 - HKLM\..\Run: [SmoothView] C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
 O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe"
 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
 O4 - HKLM\..\Run: [HDInspector.exe] C:\Programmi\Hard Drive Inspector\HDInspector.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O8 - Extra context menu item: Scarica con Free Download Manager - file://C:\Programmi\Free Download Manager\dllink.htm
 O8 - Extra context menu item: Scarica selezionati con Free Download Manager - file://C:\Programmi\Free Download Manager\dlselected.htm
 O8 - Extra context menu item: Scarica tutto con Free Download Manager - file://C:\Programmi\Free Download Manager\dlall.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1180187758677
 O17 - HKLM\System\CCS\Services\Tcpip\..\{2C3E93EF-6BDE-4033-B5BD-FEFA3312FF06}: NameServer = 151.99.125.2,151.99.125.3
 O17 - HKLM\System\CS1\Services\Tcpip\..\{2C3E93EF-6BDE-4033-B5BD-FEFA3312FF06}: NameServer = 151.99.125.2,151.99.125.3
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
 O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (http://www.altrixsoft.com/) - C:\WINDOWS\system32\HDDSvc.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Programmi\Toshiba\TOSHIBA Applet\TAPPSRV.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
 --
 End of file - 7529 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ulfgar Comune mortale
 
  
 
 Registrato: 18/08/07 10:24
 Messaggi: 4
 
 
 | 
			
				|  Inviato: 19 Ago 2007 19:46    Oggetto: |   |  
				| 
 |  
				| Fatto anche la scansione gmer. Allego i file.
 
 Passo 1 direct link http://www.freefilehosting.net/download/MTM1Njk=
 Html code <a href="http://www.freefilehosting.net/files/MTM1Njk=">passo 1.txt</a>
 
 Passo 2 direct link http://www.freefilehosting.net/download/MTM1NzA=
 Html code <a href="http://www.freefilehosting.net/files/MTM1NzA=">passo 2.txt</a>
 
 Allego anche la scansione fatta nuovamente con HiJackThis_v2
 
 dirct link http://www.freefilehosting.net/download/MTM1NzI=
 
 Html code <a href="http://www.freefilehosting.net/files/MTM1NzI=">hijackthis84.log</a>
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 19 Ago 2007 20:34    Oggetto: |   |  
				| 
 |  
				| Ciao. Il log di HJT mi sembra pulito. Scarica Avenger e mettilo in una sua cartella in C:\
 
 http://swandog46.geekstogo.com/avenger.zip
 Avvia AVENGER
 Clicca su input script manually
 Clicca sulla lente d'ingrandimento
 Inserisci queste righe:
 
 Files to delete:
 c:\windows\system32\srescan.sys
 
 Clicca su Done
 Clicca sul semaforo
 Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
 Al termine dell'operazione, posta qui il risultato con un log aggiornato di hijackthis.
 
 Inoltre hai dimenticato la scansione con FindAWF.
 Guarda di nuovo il passaggio 1 e fai la scansione e incolla quì il risultato.
 
 Dimmi che problemi da ancora il PC...
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 19 Ago 2007 23:50    Oggetto: |   |  
				| 
 |  
				|  	  | Sante62 ha scritto: |  	  | Files to delete: c:\windows\system32\srescan.sys
 | 
 srescan.sys è un file della suite ZoneAlarm.
 Ti consiglio di evitare la cancellazione.
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 20 Ago 2007 01:18    Oggetto: |   |  
				| 
 |  
				| Si...scusate l'abbacchio  |  | 
	
		| Top |  | 
	
		|  | 
	
		| ulfgar Comune mortale
 
  
 
 Registrato: 18/08/07 10:24
 Messaggi: 4
 
 
 | 
			
				|  Inviato: 20 Ago 2007 07:17    Oggetto: |   |  
				| 
 |  
				|  	  | Sante62 ha scritto: |  	  | Inoltre hai dimenticato la scansione con FindAWF. Guarda di nuovo il passaggio 1 e fai la scansione e incolla quì il risultato.
 
 Dimmi che problemi da ancora il PC...
 | 
 
 Ho fatto esattamente quel che stava scritto.
 Grazie a tutti per il momento sembra andare bene, testo il pc per un paio di giorni se mi dite che la scansione va bene e vediamo un pò se il virus è stato tolto
  grazie ancora |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |