| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| CassieLince Mortale pio
 
  
 
 Registrato: 22/09/07 15:17
 Messaggi: 25
 
 
 | 
			
				|  Inviato: 01 Dic 2007 11:47    Oggetto: problemi con avgamsvr.exe |   |  
				| 
 |  
				| Ciao! 
 ho letto questo post per cercare informazioni, perchè anche io non riesco più ad installare nessun antivirus a causa dell'assenza del file avgamsvr.exe, e dai vari scan che ho fatto online penso di aver capito di aver anche io una infezione da beagle. POtete aiutarmi a debellarlo?
 Grazie mille!
 (sono giorni che ci provo da sola ma senza riuscirci!)
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| CassieLince Mortale pio
 
  
 
 Registrato: 22/09/07 15:17
 Messaggi: 25
 
 
 | 
			
				|  Inviato: 01 Dic 2007 12:45    Oggetto: |   |  
				| 
 |  
				| Questo è il log di Elibagle. 
 Forse quello sono riuscita a debellarlo ieri, allora, ho eliminato alcuni file sospetti...
 
 
 Sat Dec 01 10:54:31 2007
 EliBagle v10.75  (c)2007 S.G.H. / Satinfo S.L.
 ----------------------------------------------
 Lista de Acciones (por Acción Directa):
 C:\WINDOWS\SYSTEM32\DRIVERS\HIDR.EXE --> Eliminado Bagle
 C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Eliminado Bagle (rootkit)
 Eliminada Carpeta "%WinDir%\exefld"
 Eliminada Carpeta "%AppData%\Hidires"
 Restaurada Clave: "SafeBoot\Minimal y Network"
 
 Sat Dec 01 10:55:59 2007
 EliBagle v10.75  (c)2007 S.G.H. / Satinfo S.L.
 ----------------------------------------------
 Lista de Acciones (por Exploración):
 Explorando Unidad C:\
 
 Nº Total de Directorios:   8190
 Nº Total de Ficheros:      85315
 Nº de Ficheros Analizados: 11414
 Nº de Ficheros Infectados: 0
 Nº de Ficheros Limpiados:  0
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ste_95 Dio maturo
 
  
  
 Registrato: 03/08/07 14:41
 Messaggi: 1920
 Residenza: Italy
 
 | 
			
				|  Inviato: 01 Dic 2007 12:48    Oggetto: |   |  
				| 
 |  
				| Già dovresti trovarti meglio...comunque: 
 Collegati a Kaspersky on-line scanner e fai la scansione estesa, come indicato qui.
 Salva il risultato della scansione in un file (in formato HTML), carica il file su Freefilehosting e posta qui il link che ti viene assegnato.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| CassieLince Mortale pio
 
  
 
 Registrato: 22/09/07 15:17
 Messaggi: 25
 
 
 | 
			
				|  Inviato: 01 Dic 2007 12:48    Oggetto: |   |  
				| 
 |  
				| Log file di Hijackthis 
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 11.47.40, on 01/12/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 C:\Programmi\Intel\Wireless\Bin\WLKeeper.exe
 C:\WINDOWS\system32\LEXBCES.EXE
 C:\WINDOWS\system32\LEXPPS.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Intel\Wireless\Bin\ZcfgSvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
 C:\Programmi\IVT Corporation\BlueSoleil\BTNtService.exe
 C:\Programmi\Intel\Wireless\Bin\ifrmewrk.exe
 C:\WINDOWS\system32\igfxsrvc.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
 C:\Program Files\Libero\Adsl\dslstat.exe
 C:\Program Files\Libero\Adsl\dslagent.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Winamp\winampa.exe
 C:\Programmi\Java\jre1.5.0_09\bin\jusched.exe
 C:\Programmi\D-Tools\daemon.exe
 C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe
 C:\Programmi\USB Disk Win98 Driver\Res.EXE
 C:\Programmi\Musicmatch\Musicmatch Jukebox\mmtask.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Skype\Phone\Skype.exe
 C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
 C:\Programmi\Lexmark 1200 Series\lxczbmon.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\Programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 C:\Programmi\CyberLink\Shared Files\RichVideo.exe
 C:\WINDOWS\System32\PAStiSvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
 C:\Programmi\Skype\Plugin Manager\SkypePM.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\hp\Desktop\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.occhiodilince.net/
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - J:\Spybot - Search & Destroy\SDHelper.dll (file missing)
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [IntelZeroConfig] C:\Programmi\Intel\Wireless\bin\ZCfgSvc.exe
 O4 - HKLM\..\Run: [IntelWireless] C:\Programmi\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
 O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [RemoteControl] "C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Libero\Adsl\dslstat.exe icon
 O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Libero\Adsl\dslagent.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_09\bin\jusched.exe"
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmi\D-Tools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Programmi\USB Disk Win98 Driver\Res.EXE
 O4 - HKLM\..\Run: [mmtask] "C:\Programmi\Musicmatch\Musicmatch Jukebox\mmtask.exe"
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: BlueSoleil.lnk = ?
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
 O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://parili.spaces.live.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1164217094093
 O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://occhiodilincenet.spaces.live.com/PhotoUpload/MsnPUpld.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
 O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
 O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
 O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5173/mcfscan.cab
 O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe (file missing)
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe (file missing)
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe (file missing)
 O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programmi\IVT Corporation\BlueSoleil\BTNtService.exe
 O23 - Service: EvtEng - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
 O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 O23 - Service: RegSrvc - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared Files\RichVideo.exe
 O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)
 O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmi\Intel\Wireless\Bin\WLKeeper.exe
 O24 - Desktop Component 1: MuggleNet's Deathly Hallows/Order of the Phoenix Countdown - http://www.mugglenet.com/countdown/desktop-dhootp.html
 
 --
 End of file - 11726 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ste_95 Dio maturo
 
  
  
 Registrato: 03/08/07 14:41
 Messaggi: 1920
 Residenza: Italy
 
 | 
			
				|  Inviato: 01 Dic 2007 12:51    Oggetto: |   |  
				| 
 |  
				|  	  | ste_95 ha scritto: |  	  | Collegati a Kaspersky on-line scanner e fai la scansione estesa, come indicato qui. Salva il risultato della scansione in un file (in formato HTML), carica il file su Freefilehosting e posta qui il link che ti viene assegnato.
 | 
 
 Il tuo log è pulito, esegui i passaggi qui sopra per piacere
   
 ps. alla fine dovrai reinstallare il tuo antivirus
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| CassieLince Mortale pio
 
  
 
 Registrato: 22/09/07 15:17
 Messaggi: 25
 
 
 | 
			
				|  Inviato: 01 Dic 2007 12:51    Oggetto: |   |  
				| 
 |  
				|  	  | ste_95 ha scritto: |  	  | Già dovresti trovarti meglio...comunque: 
 
 Sì, grazie mille! sono riuscita a re installare Spybot! Cmq per sicurezza farò l'ennesima scansione con kaspersky per stare più tranquilla! grazie mille!
 
 Collegati a Kaspersky on-line scanner e fai la scansione estesa, come indicato qui.
 Salva il risultato della scansione in un file (in formato HTML), carica il file su Freefilehosting e posta qui il link che ti viene assegnato.
 | 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |