| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| Night_wolf Comune mortale
 
  
 
 Registrato: 21/03/07 11:58
 Messaggi: 2
 
 
 | 
			
				|  Inviato: 21 Mar 2007 13:10    Oggetto: |   |  
				| 
 |  
				| Salve a tutti, sono nuovo e ho lo stesso problema del topic 
 Volevo provare i vostri rimedi, tranne che appena accedo a windows, anche in modalità provvisoria, dopo pochissimo tempo esce la shermata d'errore..........
 
 Voi avete una soluzione ?
 
 Grazie
  |  |  
		| Top |  |  
		|  |  
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 21 Mar 2007 15:27    Oggetto: |   |  
				| 
 |  
				| Avresti dovuto aprire un nuovo thread! 
 Ora splitto io.. intanto fai queste operazioni:
 
 Scarica HijackThis, decomprimilo in una cartella tutta sua non temporanea (ad esempio mettilo in C:\HijackThis).
 Avvialo e premi Do a system scan and save a log file, ti si aprirà una finestra di notepad con il risultato della scansione, copia e incolla qua il suo contenuto.
 |  |  
		| Top |  |  
		|  |  
		| Night_wolf Comune mortale
 
  
 
 Registrato: 21/03/07 11:58
 Messaggi: 2
 
 
 | 
			
				|  Inviato: 21 Mar 2007 18:21    Oggetto: |   |  
				| 
 |  
				| Hai ragione scusa........   
 
 ecco fatto come hai detto :
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 17.16.43, on 21/03/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16414)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Acer\eManager\anbmServ.exe
 C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 D:\Anti-virus e anti-spyware\avast4\aswUpdSv.exe
 D:\Anti-virus e anti-spyware\avast4\ashServ.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
 C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 C:\Programmi\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
 C:\Programmi\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
 C:\Programmi\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
 C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 C:\Programmi\CyberLink\Shared Files\RichVideo.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Acer\Acer Arcade\Kernel\TV\CLSched.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\Programmi\Acer\eRecovery\Monitor.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\WINDOWS\RTHDCPL.EXE
 C:\Programmi\Acer\Acer Arcade\PCMService.exe
 C:\acer\epm\epm-dm.exe
 C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
 D:\ANTI-V~1\avast4\ashDisp.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
 C:\WINDOWS\system32\ctfmon.exe
 D:\Programmi per Zippare\WinZip\WZQKPICK.EXE
 C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\MSN Messenger\msnmsgr.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avscan.exe
 C:\hijackThis\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [LaunchApp] Alaunch
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
 O4 - HKLM\..\Run: [AzMixerSel] C:\Programmi\Realtek\InstallShield\AzMixerSel.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 O4 - HKLM\..\Run: [PCMService] "C:\Programmi\Acer\Acer Arcade\PCMService.exe"
 O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
 O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
 O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
 O4 - HKLM\..\Run: [eRecoveryService] C:\Programmi\Acer\eRecovery\Monitor.exe
 O4 - HKLM\..\Run: [avast!] D:\ANTI-V~1\avast4\ashDisp.exe
 O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: WinZip Quick Pick.lnk = D:\Programmi per Zippare\WinZip\WZQKPICK.EXE
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: Tasto di scelta rapida per l'avvio di AutoCAD.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart17.exe
 O8 - Extra context menu item: &Clean Traces - D:\Vari\DAP\Privacy Package\dapcleanerie.htm
 O8 - Extra context menu item: &Download with &DAP - D:\Vari\DAP\dapextie.htm
 O8 - Extra context menu item: &Google Search - res://c:\programmi\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\programmi\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\programmi\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmi\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: Download &all with DAP - D:\Vari\DAP\dapextie2.htm
 O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
 O8 - Extra context menu item: Similar Pages - res://c:\programmi\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\programmi\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
 O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9602.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{0DDC64DA-85C5-4E89-8FBC-4DB6D25B3396}: NameServer = 151.99.125.2,151.99.0.100
 O17 - HKLM\System\CS2\Services\Tcpip\..\{0DDC64DA-85C5-4E89-8FBC-4DB6D25B3396}: NameServer = 151.99.125.2,151.99.0.100
 O17 - HKLM\System\CS4\Services\Tcpip\..\{0DDC64DA-85C5-4E89-8FBC-4DB6D25B3396}: NameServer = 151.99.125.2,151.99.0.100
 O17 - HKLM\System\CS5\Services\Tcpip\..\{0DDC64DA-85C5-4E89-8FBC-4DB6D25B3396}: NameServer = 151.99.125.2,151.99.0.100
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Anti-virus e anti-spyware\avast4\aswUpdSv.exe
 O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
 O23 - Service: avast! Antivirus - Unknown owner - D:\Anti-virus e anti-spyware\avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - D:\Anti-virus e anti-spyware\avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - D:\Anti-virus e anti-spyware\avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
 O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Programmi\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
 O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Programmi\Acer\Acer Arcade\Kernel\TV\CLSched.exe
 O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmi\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
 O23 - Service: EvtEng - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: RegSrvc - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared Files\RichVideo.exe
 O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
 O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 |  |  
		| Top |  |  
		|  |  
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 24 Mar 2007 18:22    Oggetto: |   |  
				| 
 |  
				| ciao! premetto che l'errore può NON dipendere dai malware presenti nel PC, ma da qualche patch di aggiornamento mancante. Dai un'occhiata a questa pagina.
 
 Hai comunque qualche malware.
 
 Scarica FixWebHancer
 
 Disattiva il ripristino del sistema
 Avvia il PC in mod. provvisoria
 avvia Hijack, seleziona "Do a system scan only", metti la spunta a queste voci e premi "Fix Checked"
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 
 trova e cancella
 c:\secure32.html
 
 Ripulisci il sistema con RegSeeker (registro) e CCleaner (file)
 
 rifai il log con Hijack e mettilo qui per il controllo.
 Metti anche un firewall migliore di quello di XP
  |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |