| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| violetstar Comune mortale
 
  
 
 Registrato: 03/08/07 10:47
 Messaggi: 1
 
 
 | 
			
				|  Inviato: 03 Ago 2007 10:52    Oggetto: |   |  
				| 
 |  
				| aiuto ragazzi..a quanto pare mi sono beccata anche io sto virus. non me ne intendo molto di pc ma ho provato a fare la scansione con hijackthis..spero di averla fatta giusta..ve la posto:
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 10.42.51, on 03/08/2007
 Platform: Windows XP SP1 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
 C:\Programmi\Eset\nod32kui.exe
 C:\WINDOWS\Samsung\LaserSMMgr\ssmmgr.exe
 C:\windows\system32\svchost.exe
 C:\WINDOWS\System32\cisvc.exe
 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
 C:\Programmi\Java\j2re1.4.2_10\bin\jusched.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Eset\nod32krn.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\System32\tcpsvcs.exe
 C:\WINDOWS\System32\snmp.exe
 C:\Programmi\iTunes\iTunesHelper.exe
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
 C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
 C:\Programmi\iPod\bin\iPodService.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\cidaemon.exe
 C:\Programmi\Mozilla Firefox\firefox.exe
 C:\Programmi\WinRAR\WinRAR.exe
 C:\DOCUME~1\Utente\IMPOST~1\Temp\Rar$EX00.938\HiJackThis_v2.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.tiscali.it/
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.tiscali.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: WebManager Class - {D5792AA9-D373-4039-8670-2CDAB6A71F15} - C:\Programmi\BitDownload\TorrentManager.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
 O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
 O4 - HKLM\..\Run: [Samsung LBP SM] "C:\WINDOWS\Samsung\LaserSMMgr\ssmmgr.exe" /autorun
 O4 - HKLM\..\Run: [updfodsl] "c:\windows\system32\updfodsl.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [LogonStudio] "C:\Programmi\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
 O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /F "C:\WINDOWS\TEMP\E_S2B68.tmp" /EF "HKLM"
 O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_10\bin\jusched.exe
 O4 - HKLM\..\Run: [thirdthisbirddate] C:\Documents and Settings\All Users\Dati applicazioni\scr five third this\mapidale.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINDOWS\System32\firewall.exe
 O4 - HKLM\..\Run: [Advanced DHTML Enable] C:\WINDOWS\System32\angydeb.exe
 O4 - HKLM\..\Run: [stupid creative poll axis] C:\Documents and Settings\All Users\Dati applicazioni\Memo save stupid creative\Program Bind.exe
 O4 - HKLM\..\Run: [Noun Date Rule Axis] C:\Documents and Settings\All Users\Dati applicazioni\blue shim axis memo\Way Load Rdr.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
 O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [SkipClose] C:\DOCUME~1\Utente\DATIAP~1\ENCSOF~1\DateBoobRef.exe
 O4 - HKCU\..\Run: [BitTorrent] "C:\Programmi\BitTorrent\bittorrent.exe" --force_start_minimized
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: stuqgq.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O16 - DPF: {F5BC716E-2650-4B08-9235-C110CF95017F} (Connessione Tiscali) - http://selfcare.tiscali.it/scripts/oneclick/ConnessioneTiscali.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{C4A52BEB-FB22-4EE9-BAED-D5F30DC6B4A0}: NameServer = 80.68.177.58,151.99.0.100
 O17 - HKLM\System\CCS\Services\Tcpip\..\{DC65113E-987F-4AF9-BA6C-2D7187C5B76F}: NameServer = 85.37.17.7 85.38.28.95
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Programmi\Eset\nod32krn.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 
 --
 End of file - 8130 bytes
 
 qualcuno mi da una mano su cosa devo fare?
 grazie in anticipo
  |  |  
		| Top |  |  
		|  |  
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 03 Ago 2007 19:48    Oggetto: |   |  
				| 
 |  
				| Ciao violetstar,   
 Hijackthis va salvato in una sua cartella non temporanea e non sul desktop.
   
 Avvia il pc in modalità provvisoria
 esegui hijackthis
 clicca su do a system scan only
 metti il segno di spunta a queste voci:
 
  	  | Citazione: |  	  | O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [updfodsl] "c:\windows\system32\updfodsl.exe"
 O4 - HKLM\..\Run: [thirdthisbirddate] C:\Documents and Settings\All Users\Dati applicazioni\scr five third this\mapidale.exe
 O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINDOWS\System32\firewall.exe
 O4 - HKLM\..\Run: [Advanced DHTML Enable] C:\WINDOWS\System32\angydeb.exe
 O4 - HKLM\..\Run: [stupid creative poll axis] C:\Documents and Settings\All Users\Dati applicazioni\Memo save stupid creative\Program Bind.exe
 O4 - HKLM\..\Run: [Noun Date Rule Axis] C:\Documents and Settings\All Users\Dati applicazioni\blue shim axis memo\Way Load Rdr.exe
 O4 - HKCU\..\Run: [SkipClose] C:\DOCUME~1\Utente\DATIAP~1\ENCSOF~1\DateBoobRef.exe
 O4 - Startup: stuqgq.exe
 | 
 clicca fix checked
 Riavvia il pc in modalità normale, rifai il log di hijackthis e postalo
 
 PS: se vuoi, puoi presentarti qui
 |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |