| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| Boston Dio minore
 
  
  
 Registrato: 12/07/05 18:49
 Messaggi: 557
 Residenza: L'isola che non c'è... vicino Roma
 
 | 
			
				|  Inviato: 17 Feb 2008 11:13    Oggetto: La scansione online trova un adware |   |  
				| 
 |  
				| Ciao a tutti, spero non appena qualcuno ne abbia il tempo di ricevere un consiglio.... 
 Ho effettuato una scansione on line del mio pc e mi ha detto di aver trovato adware_memwatcher.
 
 Il mio antivirus sul pc (kaspersky regolarmente acquistato) non mi rivela nulla.
 
 Ho provato a fargli fare anche la scansione in modalità provvisoria ma niente...
 
 Qualche suggerimento?? Grazie e buona domenica
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 17 Feb 2008 12:10    Oggetto: |   |  
				| 
 |  
				| adware = Advertsing Software (programma spara-pubblicità). 
 Non tutti gli antivirus li ritengono pericolosi.
   Se vuoi fare un controllo, segui le istruzioni di questo topic per postare il log di hijackthis.
 
 PS: per cortesia, usa titoli più esplicativi per il problema che segnali. Grazie mille per la collaborazione.
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| Boston Dio minore
 
  
  
 Registrato: 12/07/05 18:49
 Messaggi: 557
 Residenza: L'isola che non c'è... vicino Roma
 
 | 
			
				|  Inviato: 17 Feb 2008 12:18    Oggetto: |   |  
				| 
 |  
				| Ciao, scusa ma appena sveglio le sinapsi non erano tutte a pieno regime   
 Grazie x la tua veloce risposta.
 
 Il log mi da questo:
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 11.17.04, on 17/02/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16608)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
 C:\Programmi\Bonjour\mDNSResponder.exe
 C:\Programmi\Executive Software\Diskeeper\DkService.exe
 C:\WINDOWS\system32\drivers\KodakCCS.exe
 C:\Programmi\richcomm\PowerManagerLite\PMLiteServer.exe
 C:\WINDOWS\system32\ScsiAccess.EXE
 C:\Programmi\SPAMfighter\sfus.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.EXE
 C:\Programmi\QuickTime\QTTask.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\WINDOWS\VM_STI.EXE
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
 C:\Programmi\SPAMfighter\SFAgent.exe
 C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
 C:\Programmi\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
 C:\Programmi\richcomm\PowerManagerLite\PowermanagerLite.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\Philips\SPC 200NC PC Camera\TrayMin200.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Programmi\MemoRex\MemoRex.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\Programmi\Executive Software\Diskeeper\DfrgFat.exe
 C:\Programmi\Executive Software\Diskeeper\DkIcon.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 C:\Documents and Settings\UMBERTO\Documenti\File ricevuti\HiJackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
 O4 - HKLM\..\Run: [EPSON Stylus C48 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.EXE /P23 "EPSON Stylus C48 Series" /O6 "USB001" /M "Stylus C48"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Programmi\Executive Software\Diskeeper\DkIcon.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKLM\..\Run: [MemoREX] "C:\Programmi\MemoRex\MemoRexStart.exe"
 O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
 O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Programmi\SPAMfighter\SFAgent.exe" update delay 60
 O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Kodak software updater.lnk = C:\Programmi\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
 O4 - Global Startup: PowerManagerLite.lnk = ?
 O4 - Global Startup: TrayMin300.exe.lnk = ?
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
 O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
 O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Programmi\Executive Software\Diskeeper\DkService.exe
 O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
 O23 - Service: PMLiteServer - richcomm - C:\Programmi\richcomm\PowerManagerLite\PMLiteServer.exe
 O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Programmi\SPAMfighter\sfus.exe
 
 --
 End of file - 8165 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 17 Feb 2008 13:50    Oggetto: |   |  
				| 
 |  
				| Il log di hijackthis sembra pulito. 
 Giusto per sicurezza, segui le istruzioni di questo topic per postare il log di combofix.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Boston Dio minore
 
  
  
 Registrato: 12/07/05 18:49
 Messaggi: 557
 Residenza: L'isola che non c'è... vicino Roma
 
 | 
			
				|  Inviato: 17 Feb 2008 15:32    Oggetto: |   |  
				| 
 |  
				| Grazie ancora... 
 appena possibile termino i controlli che mi dici
   
 Buona domenica a presto...
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |