| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| Venere80 Eroe in grazia degli dei
 
  
 
 Registrato: 18/07/07 20:28
 Messaggi: 92
 
 
 | 
			
				|  Inviato: 15 Feb 2008 20:35    Oggetto: Processo svchost.exe troppo grande e alta compr byte inviati |   |  
				| 
 |  
				| Chiedo lumi su una situazione creatasi nel mio portatile. Il pc è pulito dopo un grande aiuto ricevuto proprio su questo forum da Sante un mese fa. L' unica stranezza è un processo svchost.exe che durante la navigazione è sempre "carico" nell' ordine dei 30.000 Kb ed infatti le pagine si aprono piuttosto lentamente, con un tasso di compressione di byte inviati sempre sul 20%, quando invece li ho sempre avuti sul 5%.
 Poi aprendo il task manager la CPU schizza al 70% e un secondo dopo oscilla tra 10 e 4%
  Altra stranezza, è normale che quando si legga una pagina web i dati inviati e ricevuti si fermino? A me lo fa spesso. Grazie e ciao a tutti.
 |  |  
		| Top |  |  
		|  |  
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 15 Feb 2008 20:42    Oggetto: |   |  
				| 
 |  
				| Ciao Venere80   Iniziamo daccapo...
 Posta un log di Hijackthis...
 |  |  
		| Top |  |  
		|  |  
		| Venere80 Eroe in grazia degli dei
 
  
 
 Registrato: 18/07/07 20:28
 Messaggi: 92
 
 
 | 
			
				|  Inviato: 15 Feb 2008 21:29    Oggetto: |   |  
				| 
 |  
				| Ciao grande Sante, scusa se non ti ho risposto subito, ma stavo navigando per provare il pc. Ecco il log di Hijackthis. 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 19.52.34, on 15/02/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\ibmpmsvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\IPSSVC.EXE
 C:\Programmi\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
 C:\Programmi\ThinkPad\Bluetooth Software\bin\btwdins.exe
 C:\Programmi\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
 C:\Programmi\Diskeeper Corporation\Diskeeper\DkService.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
 C:\Programmi\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
 C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 C:\Programmi\Spyware Terminator\sp_rsser.exe
 c:\programmi\lenovo\system update\suservice.exe
 C:\Programmi\File comuni\Lenovo\tvt_reg_monitor_svc.exe
 C:\WINDOWS\system32\TpKmpSVC.exe
 C:\Programmi\Lenovo\Rescue and Recovery\rrservice.exe
 C:\Programmi\File comuni\Lenovo\Scheduler\tvtsched.exe
 C:\Programmi\Lenovo\Rescue and Recovery\ADM\IUService.exe
 C:\Programmi\File comuni\Lenovo\Logger\logmon.exe
 C:\Programmi\ThinkPad\ConnectUtilities\AcSvc.exe
 C:\Programmi\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
 C:\WINDOWS\system32\wbem\wmiapsrv.exe
 C:\Programmi\Lenovo\Client Security Solution\cssauth.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Lenovo\Client Security Solution\tvtpwm_tray.exe
 C:\PROGRA~1\SYMANT~2\SYMANT~1\vptray.exe
 C:\Programmi\File comuni\Lenovo\Scheduler\scheduler_proxy.exe
 C:\WINDOWS\system32\tp4serv.exe
 C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
 C:\Programmi\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
 C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe
 C:\Programmi\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
 C:\Programmi\Analog Devices\Core\smax4pnp.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Picasa2\PicasaMediaDetector.exe
 C:\Programmi\Lenovo\SafeGuard PrivateDisk\pdservice.exe
 C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
 C:\WINDOWS\System32\DLA\DLACTRLW.EXE
 C:\Programmi\Lenovo\AwayTask\AwaySch.EXE
 C:\PROGRA~1\THINKV~1\AMSG\amsg.exe
 C:\Programmi\ThinkPad\ConnectUtilities\ACWLIcon.exe
 C:\Programmi\ThinkPad\ConnectUtilities\ACTray.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Windows Media Player\WMPNSCFG.exe
 C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\Programmi\ThinkPad\Bluetooth Software\BTTray.exe
 C:\Program Files\Digital Line Detect\DLG.exe
 C:\Programmi\Diskeeper Corporation\Diskeeper\DkIcon.exe
 C:\Hijack\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lenovo.com/welcome/thinkpad
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Programmi\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
 O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~1\vptray.exe
 O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Programmi\File comuni\Lenovo\Scheduler\scheduler_proxy.exe
 O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
 O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Programmi\ThinkPad\Utilities\TpKmapAp.exe -helper
 O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
 O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
 O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe"
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
 O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
 O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
 O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmi\Picasa2\PicasaMediaDetector.exe
 O4 - HKLM\..\Run: [PDService.exe] "C:\Programmi\Lenovo\SafeGuard PrivateDisk\pdservice.exe"
 O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
 O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
 O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
 O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Programmi\Diskeeper Corporation\Diskeeper\DkIcon.exe"
 O4 - HKLM\..\Run: [cssauth] "C:\Programmi\Lenovo\Client Security Solution\cssauth.exe" silent
 O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
 O4 - HKLM\..\Run: [AwaySch] C:\Programmi\Lenovo\AwayTask\AwaySch.EXE
 O4 - HKLM\..\Run: [AMSG] C:\PROGRA~1\THINKV~1\AMSG\amsg.exe
 O4 - HKLM\..\Run: [ACWLIcon] C:\Programmi\ThinkPad\ConnectUtilities\ACWLIcon.exe
 O4 - HKLM\..\Run: [ACTray] C:\Programmi\ThinkPad\ConnectUtilities\ACTray.exe
 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [WMPNSCFG] C:\Programmi\Windows Media Player\WMPNSCFG.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: Digital Line Detect.lnk = ?
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/thinkpad
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://download.boulder.ibm.com/ibmdl/pub/pc/pccbbs/bp_pc/acpir.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167387531215
 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{D35CAF2C-A1A6-472A-99A0-2EFDD7E55C40}: NameServer = 131.xxx.xx.20,131.xxx.xx.25
 O20 - Winlogon Notify: AwayNotify - C:\Programmi\Lenovo\AwayTask\AwayNotify.dll
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Programmi\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
 O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Programmi\ThinkPad\ConnectUtilities\AcSvc.exe
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\ThinkPad\Bluetooth Software\bin\btwdins.exe
 O23 - Service: DefWatch - Symantec Corporation - C:\Programmi\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
 O23 - Service: Diskeeper - Diskeeper Corporation - C:\Programmi\Diskeeper Corporation\Diskeeper\DkService.exe
 O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
 O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Programmi\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
 O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
 O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
 O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\programmi\lenovo\system update\suservice.exe
 O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Programmi\File comuni\Lenovo\tvt_reg_monitor_svc.exe
 O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
 O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Programmi\Lenovo\Rescue and Recovery\rrservice.exe
 O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Programmi\File comuni\Lenovo\Scheduler\tvtsched.exe
 O23 - Service: tvtnetwk - Unknown owner - C:\Programmi\Lenovo\Rescue and Recovery\ADM\IUService.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
 --
 End of file - 12077 bytes
 
 Grazie infinite ancora.
  |  |  
		| Top |  |  
		|  |  
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 16 Feb 2008 00:56    Oggetto: |   |  
				| 
 |  
				| Il log di HJT sembra pulito... Segui questa discussione
 relativa a Combofix, e fai la scansione del PC postando il risultato come indicato. Fai anche la Scansione con GMER
 Ricorda che i log di GMER sono due: Autostart e Rootkit. Postali su www.freefilehosting.net come indicato quì
 |  |  
		| Top |  |  
		|  |  
		| Venere80 Eroe in grazia degli dei
 
  
 
 Registrato: 18/07/07 20:28
 Messaggi: 92
 
 
 | 
			
				|  Inviato: 16 Feb 2008 21:05    Oggetto: |   |  
				| 
 |  
				| Ciao Sante. Ecco nell'ordine i log di Combo e Hijackthis. 
 
  	  | Citazione: |  	  | ComboFix 08-02-16.2 - Mionome 2008-02-16 15.08.29.3 - NTFSx86 Microsoft Windows XP Professional  5.1.2600.2.1252.1.1040.18.180 [GMT 1:00]
 Eseguito da: C:\Documents and Settings\Mionome\Desktop\ComboFix.exe
 * Creato nuovo punto di ripristino
 
 WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
 .
 
 (((((((((((((((((((((((((   Files Creati Da 2008-01-16 al 2008-02-16  )))))))))))))))))))))))))))))))))))
 .
 
 2008-01-24 20:29 . 2007-09-24 23:31	69,632	--a------	C:\WINDOWS\system32\javacpl.cpl
 2008-01-24 19:52 . 2008-01-24 19:52	<DIR>	d--------	C:\Programmi\File comuni\Java
 2008-01-24 16:46 . 2008-01-24 18:36	<DIR>	d--------	C:\Programmi\Pulitore registro
 2008-01-23 13:36 . 2008-01-23 13:36	51,232	--a------	C:\wwdc.exe
 2008-01-19 02:09 . 2008-02-16 15:12	3,352,608	--ahs----	C:\WINDOWS\system32\drivers\fidbox.dat
 2008-01-19 02:09 . 2008-02-16 13:05	39,860	--ahs----	C:\WINDOWS\system32\drivers\fidbox.idx
 2008-01-19 01:58 . 2008-01-19 01:58	<DIR>	d--------	C:\Documents and Settings\All Users\Dati applicazioni\MailFrontier
 2008-01-19 01:57 . 2008-01-19 01:58	<DIR>	d--------	C:\WINDOWS\system32\ZoneLabs
 2008-01-19 01:57 . 2008-01-19 01:57	<DIR>	d--------	C:\Programmi\Zone Labs
 2008-01-19 01:57 . 2007-12-13 19:27	1,086,952	--a------	C:\WINDOWS\system32\zpeng24.dll
 2008-01-19 01:57 . 2008-02-16 13:42	358,830	--a------	C:\WINDOWS\system32\vsconfig.xml
 2008-01-19 01:43 . 2008-02-16 13:45	<DIR>	d--------	C:\WINDOWS\Internet Logs
 
 .
 ((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2008-02-10 16:45	5,427	----a-w	C:\WINDOWS\system32\EGATHDRV.SYS
 2008-02-02 10:07	---------	d---a-w	C:\Programmi\Spyware Terminator
 2008-01-29 19:19	---------	d---a-w	C:\Documents and Settings\All Users\Dati applicazioni\Spyware Terminator
 2008-01-24 19:29	---------	d---a-w	C:\Programmi\Java
 2008-01-18 22:13	---------	d---a-w	C:\Programmi\Picasa2
 2008-01-15 00:33	210,416	----a-w	C:\Programmi\zaSetup_it.exe
 2008-01-13 22:45	---------	d---a-w	C:\Programmi\File comuni\Lenovo
 2008-01-11 18:24	127,378	----a-w	C:\avenger.zip
 2008-01-11 05:32	44,544	------w	C:\WINDOWS\system32\dllcache\pngfilt.dll
 2007-12-19 22:50	347,136	------w	C:\WINDOWS\system32\dllcache\dxtmsft.dll
 2007-12-18 09:51	179,584	------w	C:\WINDOWS\system32\drivers\mrxdav.sys
 2007-12-18 09:51	179,584	------w	C:\WINDOWS\system32\dllcache\mrxdav.sys
 2007-12-13 18:28	42,384	----a-w	C:\WINDOWS\zllsputility_loc0410.dll
 2007-12-13 18:27	75,248	----a-w	C:\WINDOWS\zllsputility.exe
 2007-12-13 18:27	54,672	----a-w	C:\WINDOWS\system32\vsutil_loc0410.dll
 2007-12-13 18:27	21,904	----a-w	C:\WINDOWS\system32\imsinstall_loc0410.dll
 2007-12-13 18:27	17,808	----a-w	C:\WINDOWS\system32\imslsp_install_loc0410.dll
 2007-12-08 05:04	3,592,192	----a-w	C:\WINDOWS\system32\dllcache\mshtml.dll
 2007-12-06 11:03	70,656	------w	C:\WINDOWS\system32\dllcache\ie4uinit.exe
 2007-12-06 11:03	625,664	------w	C:\WINDOWS\system32\dllcache\iexplore.exe
 2007-12-06 11:00	13,824	------w	C:\WINDOWS\system32\dllcache\ieudinit.exe
 2007-12-06 04:59	161,792	------w	C:\WINDOWS\system32\dllcache\ieakui.dll
 2007-12-04 18:40	550,912	----a-w	C:\WINDOWS\system32\dllcache\oleaut32.dll
 2007-12-04 18:40	550,912	------w	C:\WINDOWS\system32\oleaut32.dll
 2007-07-27 19:28	502,055	-c--a-w	C:\Programmi\gmer.zip
 .
 
 (((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 ----a-w         2,778,112 2007-09-21 19:29:58  C:\Programmi\Spyware Terminator\bak\SpywareTerminatorShield.exe
 ----a-w         2,778,112 2008-01-17 22:00:23  C:\Programmi\Spyware Terminator\Spywareterminatorshield.Exe
 
 ----a-w            15,360 2004-08-19 21:00:00  C:\WINDOWS\system32\bak\ctfmon.exe
 ----a-w            15,360 2004-08-19 21:00:00  C:\WINDOWS\system32\ctfmon.exe
 
 .
 (((((((((((((((((((((((((((((((((((((   Punti Reg Caricati   ))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 REGEDIT4
 *Nota* i valori vuoti & legittimi/default non sono visualizzati.
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "updateMgr"="C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
 "MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
 "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 22:00 15360]
 "WMPNSCFG"="C:\Programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 22:56 204288]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "vptray"="C:\PROGRA~1\SYMANT~2\SYMANT~1\vptray.exe" [2002-08-22 11:56 77824]
 "TVT Scheduler Proxy"="C:\Programmi\File comuni\Lenovo\Scheduler\scheduler_proxy.exe" [2007-07-10 15:16 540672]
 "TrackPointSrv"="tp4serv.exe" [2005-07-12 19:55 94208 C:\WINDOWS\system32\tp4serv.exe]
 "TPKMAPHELPER"="C:\Programmi\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-02 22:00 856064]
 "TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-07-25 02:19 94208]
 "TP4EX"="tp4ex.exe" [2005-10-17 01:11 65536 C:\WINDOWS\system32\TP4EX.exe]
 "SpywareTerminator"="C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe" [2008-01-17 23:00 2778112]
 "SoundMAXPnP"="C:\Programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 01:11 925696]
 "SoundMAX"="C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" [2005-05-06 15:06 716800]
 "PWRMGRTR"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-25 17:13 151552]
 "Picasa Media Detector"="C:\Programmi\Picasa2\PicasaMediaDetector.exe" [2006-03-16 00:07 421888]
 "PDService.exe"="C:\Programmi\Lenovo\SafeGuard PrivateDisk\pdservice.exe" [2006-03-13 16:38 41472]
 "LPManager"="C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe" [2006-07-04 17:11 110592]
 "ISUSScheduler"="C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
 "ISUSPM Startup"="C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
 "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-07-25 07:21 94208]
 "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-07-25 07:21 118784]
 "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-07-25 07:17 77824]
 "EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2006-02-23 18:22 237568]
 "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2006-02-02 05:20 122940]
 "DiskeeperSystray"="C:\Programmi\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 16:24 196696]
 "cssauth"="C:\Programmi\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 18:13 2341632]
 "BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-25 17:13 208896]
 "AwaySch"="C:\Programmi\Lenovo\AwayTask\AwaySch.EXE" [2006-08-16 18:07 69632]
 "AMSG"="C:\PROGRA~1\THINKV~1\AMSG\amsg.exe" [2005-11-14 07:23 487424]
 "ACWLIcon"="C:\Programmi\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-08-26 00:17 110592]
 "ACTray"="C:\Programmi\ThinkPad\ConnectUtilities\ACTray.exe" [2006-08-26 00:22 409600]
 "ZoneAlarm Client"="C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 19:27 919016]
 "SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
 
 [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
 "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 22:00 15360]
 
 C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
 Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
 BTTray.lnk - C:\Programmi\ThinkPad\Bluetooth Software\BTTray.exe [2006-05-31 14:51:02 622653]
 Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-11-16 17:33:35 24576]
 Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 08:01:04 83360]
 
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
 C:\Programmi\Lenovo\AwayTask\AwayNotify.dll 2006-08-16 18:07 49152 C:\Programmi\Lenovo\AwayTask\AwayNotify.dll
 
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
 notifyf2.dll 2005-07-05 15:45 28672 C:\WINDOWS\system32\notifyf2.dll
 
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
 tphklock.dll 2005-11-30 12:16 24576 C:\WINDOWS\system32\tphklock.dll
 
 R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS [2005-11-08 09:27]
 R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\Drivers\IBMBLDID.sys [2006-01-13 00:33]
 R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2007-09-21 20:31]
 R1 TPPWRIF;TPPWRIF;C:\WINDOWS\system32\drivers\Tppwrif.sys [2006-05-25 17:13]
 R2 DbgMsg;Debug Message;C:\WINDOWS\System32\Drivers\DbgMsg.sys [2004-07-21 09:38]
 R2 PrivateDisk;PrivateDisk;C:\Programmi\Lenovo\SafeGuard PrivateDisk\PrivateDiskM.sys [2006-03-13 16:05]
 R2 smi2;smi2;C:\Programmi\SMI2\smi2.sys [2006-07-14 15:55]
 R3 Tp4Track;PS/2 TrackPoint Driver;C:\WINDOWS\system32\DRIVERS\tp4track.sys [2005-07-12 19:55]
 S3 mbr;mbr;C:\DOCUME~1\MIONOME~1\IMPOST~1\Temp\mbr.sys []
 S3 MosIrUsb;MosIrUsb.sys;C:\WINDOWS\system32\DRIVERS\MosIrUsb.sys []
 S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
 
 .
 Contenuto della cartella 'Scheduled Tasks'
 "2008-02-16 14:11:57 C:\WINDOWS\Tasks\PMTask.job"
 - C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE
 "2007-07-08 21:10:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
 - C:\Programmi\Symantec\LiveUpdate\NDETECT.EXE
 .
 **************************************************************************
 
 catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
 Rootkit scan 2008-02-16 15:12:32
 Windows 5.1.2600 Service Pack 2 NTFS
 
 scansione processi nascosti ...
 
 scansione entrate autostart nascoste ...
 
 Scansione files nascosti ...
 
 Scansione completata con successo
 Files nascosti: 0
 
 **************************************************************************
 .
 --------------------- DLLs Loaded Under Running Processes ---------------------
 
 PROCESS: C:\WINDOWS\system32\winlogon.exe
 -> C:\WINDOWS\system32\tphklock.dll
 -> C:\WINDOWS\system32\NavLogon.dll
 .
 Ora fine scansione: 2008-02-16 15.13.24
 .
 2008-02-15 20:03:09	--- E O F ---
 | 
 
 
 
  	  | Citazione: |  	  | Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 19.13.47, on 16/02/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\ibmpmsvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\IPSSVC.EXE
 C:\Programmi\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
 C:\Programmi\ThinkPad\Bluetooth Software\bin\btwdins.exe
 C:\Programmi\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
 C:\Programmi\Diskeeper Corporation\Diskeeper\DkService.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
 C:\Programmi\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
 C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 C:\Programmi\Spyware Terminator\sp_rsser.exe
 c:\programmi\lenovo\system update\suservice.exe
 C:\Programmi\File comuni\Lenovo\tvt_reg_monitor_svc.exe
 C:\WINDOWS\system32\TpKmpSVC.exe
 C:\Programmi\Lenovo\Rescue and Recovery\rrservice.exe
 C:\Programmi\File comuni\Lenovo\Scheduler\tvtsched.exe
 C:\Programmi\Lenovo\Rescue and Recovery\ADM\IUService.exe
 C:\Programmi\ThinkPad\ConnectUtilities\AcSvc.exe
 C:\Programmi\File comuni\Lenovo\Logger\logmon.exe
 C:\Programmi\Lenovo\Client Security Solution\cssauth.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
 C:\Programmi\Lenovo\Client Security Solution\tvtpwm_tray.exe
 C:\WINDOWS\system32\wbem\wmiapsrv.exe
 C:\PROGRA~1\SYMANT~2\SYMANT~1\vptray.exe
 C:\Programmi\File comuni\Lenovo\Scheduler\scheduler_proxy.exe
 C:\WINDOWS\system32\tp4serv.exe
 C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
 C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe
 C:\Programmi\Analog Devices\Core\smax4pnp.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Picasa2\PicasaMediaDetector.exe
 C:\Programmi\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
 C:\Programmi\Lenovo\SafeGuard PrivateDisk\pdservice.exe
 C:\Programmi\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
 C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
 C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
 C:\WINDOWS\System32\DLA\DLACTRLW.EXE
 C:\Programmi\Lenovo\AwayTask\AwaySch.EXE
 C:\PROGRA~1\THINKV~1\AMSG\amsg.exe
 C:\Programmi\ThinkPad\ConnectUtilities\ACWLIcon.exe
 C:\Programmi\ThinkPad\ConnectUtilities\ACTray.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Windows Media Player\WMPNSCFG.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\ThinkPad\Bluetooth Software\BTTray.exe
 C:\Program Files\Digital Line Detect\DLG.exe
 C:\Programmi\Diskeeper Corporation\Diskeeper\DkIcon.exe
 C:\Hijack\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lenovo.com/welcome/thinkpad
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Programmi\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
 O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~1\vptray.exe
 O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Programmi\File comuni\Lenovo\Scheduler\scheduler_proxy.exe
 O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
 O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Programmi\ThinkPad\Utilities\TpKmapAp.exe -helper
 O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
 O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
 O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe"
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
 O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
 O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
 O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmi\Picasa2\PicasaMediaDetector.exe
 O4 - HKLM\..\Run: [PDService.exe] "C:\Programmi\Lenovo\SafeGuard PrivateDisk\pdservice.exe"
 O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
 O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
 O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
 O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Programmi\Diskeeper Corporation\Diskeeper\DkIcon.exe"
 O4 - HKLM\..\Run: [cssauth] "C:\Programmi\Lenovo\Client Security Solution\cssauth.exe" silent
 O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
 O4 - HKLM\..\Run: [AwaySch] C:\Programmi\Lenovo\AwayTask\AwaySch.EXE
 O4 - HKLM\..\Run: [AMSG] C:\PROGRA~1\THINKV~1\AMSG\amsg.exe
 O4 - HKLM\..\Run: [ACWLIcon] C:\Programmi\ThinkPad\ConnectUtilities\ACWLIcon.exe
 O4 - HKLM\..\Run: [ACTray] C:\Programmi\ThinkPad\ConnectUtilities\ACTray.exe
 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [WMPNSCFG] C:\Programmi\Windows Media Player\WMPNSCFG.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: Digital Line Detect.lnk = ?
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/thinkpad
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://download.boulder.ibm.com/ibmdl/pub/pc/pccbbs/bp_pc/acpir.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167387531215
 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{D35CAF2C-A1A6-472A-99A0-2EFDD7E55C40}: NameServer = 131.xxx.xx.20,131.xxx.xx.25
 O20 - Winlogon Notify: AwayNotify - C:\Programmi\Lenovo\AwayTask\AwayNotify.dll
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Programmi\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
 O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Programmi\ThinkPad\ConnectUtilities\AcSvc.exe
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\ThinkPad\Bluetooth Software\bin\btwdins.exe
 O23 - Service: DefWatch - Symantec Corporation - C:\Programmi\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
 O23 - Service: Diskeeper - Diskeeper Corporation - C:\Programmi\Diskeeper Corporation\Diskeeper\DkService.exe
 O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
 O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Programmi\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
 O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
 O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
 O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\programmi\lenovo\system update\suservice.exe
 O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Programmi\File comuni\Lenovo\tvt_reg_monitor_svc.exe
 O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
 O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Programmi\Lenovo\Rescue and Recovery\rrservice.exe
 O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Programmi\File comuni\Lenovo\Scheduler\tvtsched.exe
 O23 - Service: tvtnetwk - Unknown owner - C:\Programmi\Lenovo\Rescue and Recovery\ADM\IUService.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
 --
 End of file - 11991 bytes
 | 
 
 Ed ecco i report di Gmer autotstart
 http://www.freefilehosting.net/download/3c5km
 
 E quello di Gmer rootkit
 http://www.freefilehosting.net/download/3c5l0
 
 Grazie e a presto.
  |  |  
		| Top |  |  
		|  |  
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 16 Feb 2008 21:19    Oggetto: |   |  
				| 
 |  
				| Anche questi log sono puliti. Allora, eliminiano qualche programma inutile all'avvio e vedi se da ancora quei fastidi; se ti servono puoi sempre ripsistinarli; quindi avvia HJT e fixa queste righe:
 
  	  | Citazione: |  	  | O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmi\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
 | 
 Riavvia il PC;
 Se hai ancora quei fastidi, apri il task manager e individua quale/i processo/i salgono alle stelle e indicali quì.
 |  |  
		| Top |  |  
		|  |  
		| Venere80 Eroe in grazia degli dei
 
  
 
 Registrato: 18/07/07 20:28
 Messaggi: 92
 
 
 | 
			
				|  Inviato: 16 Feb 2008 21:40    Oggetto: |   |  
				| 
 |  
				| Ok ora vado a mangiare e poi eseguo le operazioni. Dopo aver digitato password e il mio nickname è apparsa la finestra "Completamento automatico password"
  . Ed entrando in una mia casella di posta si è presentata la voce  "altre persone potrebbero vedere le informazioni inviate". Tutte novità   Verso le 22 risarò on line.
 
  |  |  
		| Top |  |  
		|  |  
		| Venere80 Eroe in grazia degli dei
 
  
 
 Registrato: 18/07/07 20:28
 Messaggi: 92
 
 
 | 
			
				|  Inviato: 17 Feb 2008 01:12    Oggetto: |   |  
				| 
 |  
				| Ho fatto come mi avevi detto, ma i valori sono rimasti inalterati. 
 Leggendo il task manager
 quelli più alti sono Explorer.exe 29.000 Kb, che appartiene al mio nome utente,
 Rtvscan.exe (Norton antivirus) 24.000 e rotti del nome utente System,
 Svchost.exe  16.000 circa, sotto il nome utente System,
 Sp.rsser.exe (Spyware terminator) poco più di 13.000  sotto il nome utente System e
 Win Logon 11.000 circa sotto il nome utente System,
 tutti sia a connessione disattivata che attiva
 Poi quando mi connetto Iexplore.exe schizza a 40.000 Kb sotto il mio nome utente.
 
 Temo sia qualcosa relativa al sistema operativo. Che ne pensi?
  |  |  
		| Top |  |  
		|  |  
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 17 Feb 2008 18:15    Oggetto: |   |  
				| 
 |  
				| Ho controllato alcuni valori nel mio sistema e addirittura alcuni sono ancora più alti dei tuoi; per es. svchost.exe arriva fino a 27.600 KB; il tuo PC fino ad adesso è risultato pulito; quindi ritengo che siano normali e comunque variano da sistema a sistema. Puoi fare le scansioni con il tuo antivirus e/o antispyware giusto per controllare;
 |  |  
		| Top |  |  
		|  |  
		| Venere80 Eroe in grazia degli dei
 
  
 
 Registrato: 18/07/07 20:28
 Messaggi: 92
 
 
 | 
			
				|  Inviato: 18 Feb 2008 20:44    Oggetto: |   |  
				| 
 |  
				| Ho capito, sotto il profilo della sicurezza sono tranquilla, ma noto stranezze come quella di alcuni programmi di aggioramento di windows che è da 4 giorni che non riesco a scaricare definitivamente. L' icona gialla appare e segnala di essere al 60% del download poi sparisce e riappare dopo 20 minuti ed è al 61%.   E' meglio che vada al forum connettività o windows, che dici?
 Ti ringrazio tanto e ti saluto.
  |  |  
		| Top |  |  
		|  |  
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 18 Feb 2008 21:00    Oggetto: |   |  
				| 
 |  
				| Puoi provare a chiedere in quella sezione. Gli aggiornamenti di Windows all'inizio sono frequenti, poi diventano sporadici.... 
  |  |  
		| Top |  |  
		|  |  
		| Venere80 Eroe in grazia degli dei
 
  
 
 Registrato: 18/07/07 20:28
 Messaggi: 92
 
 
 | 
			
				|  Inviato: 19 Feb 2008 20:24    Oggetto: |   |  
				| 
 |  
				| D' accordo. Un' ultima curiosità. Ma dove posso imparare tante cose contro i malware, tipo capire un log di Hijack, o Gmer o Suspectfile ecc. Non ti voglio rubare il lavoro
   Grazie ancora
  |  |  
		| Top |  |  
		|  |  
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 19 Feb 2008 23:23    Oggetto: |   |  
				| 
 |  
				| No, figurati...non si tratta di "rubare" il lavoro; questo lo si fa nel tempo libero, cercando di dare una mano agli altri. 
 Ma veniamo alla tua domanda alla quale non è semplice dare una risposta:
 non esiste una "ricetta", tutto dipende dall'esperienza;
 devi cercare di analizzare parecchi di questi log, anche di altri forum sulla sicurezza e cercare di identificare così i vari malware, confrontando poi le tue decisioni con quelli che effettivamente vengono presi dagli esperti.
 il log di Hijackthis lo puoi incollare nell'apposito box sul sito www.hijackthis.de/it; ti dà una mano a identificare le righe che devono essere rimosse, ma anche quì ovviamente ci vuole cautela prima di procedere. I log di GMER e Systemscan (ma soprattutto quest'ultimo) sono i più complicati da analizzare....
 Io personalmente, ho studiato i vari log per circa un anno prima di cimentarmi effettivamente, ma tu potresti arrivarci anche prima, quindi armati di pazienza...!
 
 
 
  |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |