| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| crissal Mortale pio
 
  
 
 Registrato: 27/03/07 13:19
 Messaggi: 22
 
 
 | 
			
				|  Inviato: 27 Mar 2007 13:24    Oggetto: cid pubblicità |   |  
				| 
 |  
				| le ho provate tutte mi date uno sguardo  ??? grazieee!!!   
 Logfile of HijackThis v1.99.1
 Scan saved at 13.21.05, on 27/03/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\WINDOWS\ATKKBService.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Programmi\Winamp\winampa.exe
 C:\Programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Microsoft ActiveSync\wcescomm.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\eMule\emule.exe
 c:\progra~1\intern~1\iexplore.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Programmi\No-IP\DUC20.exe
 C:\PROGRA~1\MICROS~2\rapimgr.exe
 C:\PROGRA~1\INCRED~1\bin\IMApp.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\PROGRA~1\INCRED~1\bin\IncMail.exe
 C:\DOCUME~1\SALVAT~1\IMPOST~1\Temp\Rar$EX00.813\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
 O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [IncrediMail] C:\Programmi\IncrediMail\bin\IncMail.exe /c
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmi\Microsoft ActiveSync\wcescomm.exe"
 O4 - HKCU\..\Run: [Beep Clock] C:\DOCUME~1\SALVAT~1\DATIAP~1\BASHMA~1\Mode one.exe
 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programmi\eMule\emule.exe -AutoStart
 O4 - Startup: No-IP DUC.lnk = C:\Programmi\No-IP\DUC20.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra 'Tools' menuitem: Crea preferito portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{3F48C699-C848-438E-88F7-3EEA2E115FCF}: NameServer = 192.168.1.1
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 27 Mar 2007 14:01    Oggetto: |   |  
				| 
 |  
				| Ciao! 
 Sposta HijackThis in una cartella non temporanea (ad esempio C:\HijackThis), fallo ripartire e posta un nuovo log perfavore.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| crissal Mortale pio
 
  
 
 Registrato: 27/03/07 13:19
 Messaggi: 22
 
 
 | 
			
				|  Inviato: 28 Mar 2007 13:39    Oggetto: grazie |   |  
				| 
 |  
				|  Io ho letto qualche discussione di altri miei soci di cid, solo che io non sono riuscito ad entrare in pc provvisorio  ed ho cercato di cancellare qualcosa in pc normale  per il momento non mi appare nulla come cid pero non so se c'è ancora residui. ecco il mio log un se per favore qualcuno mi da un okkiata ......grazieee!!
 
 Logfile of HijackThis v1.99.1
 Scan saved at 13.18.25, on 28/03/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\WINDOWS\ATKKBService.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Programmi\Winamp\winampa.exe
 C:\Programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Microsoft ActiveSync\wcescomm.exe
 C:\Programmi\eMule\emule.exe
 C:\Programmi\No-IP\DUC20.exe
 c:\progra~1\intern~1\iexplore.exe
 C:\PROGRA~1\MICROS~2\rapimgr.exe
 C:\PROGRA~1\INCRED~1\bin\IMApp.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\hijackers\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
 O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [IncrediMail] C:\Programmi\IncrediMail\bin\IncMail.exe /c
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmi\Microsoft ActiveSync\wcescomm.exe"
 O4 - HKCU\..\Run: [Beep Clock] C:\DOCUME~1\SALVAT~1\DATIAP~1\BASHMA~1\Mode one.exe
 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programmi\eMule\emule.exe -AutoStart
 O4 - Startup: No-IP DUC.lnk = C:\Programmi\No-IP\DUC20.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra 'Tools' menuitem: Crea preferito portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{3F48C699-C848-438E-88F7-3EEA2E115FCF}: NameServer = 192.168.1.1
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| madvero Amministratore
 
  
  
 Registrato: 05/07/05 21:42
 Messaggi: 19518
 Residenza: L'immagine ha il solo scopo di rappresentare il prodotto.
 
 | 
			
				|  Inviato: 28 Mar 2007 13:50    Oggetto: |   |  
				| 
 |  
				|  	  | Citazione: |  	  | c:\progra~1\intern~1\iexplore.exe | 
 fai la scansione su questo che non mi convince.
 
  	  | Citazione: |  	  | O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) | 
 questo cos'è?
 
  	  | Citazione: |  	  | O4 - HKCU\..\Run: [Beep Clock] C:\DOCUME~1\SALVAT~1\DATIAP~1\BASHMA~1\Mode one.exe | 
 e questo?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| crissal Mortale pio
 
  
 
 Registrato: 27/03/07 13:19
 Messaggi: 22
 
 
 | 
			
				|  Inviato: 28 Mar 2007 15:48    Oggetto: ci provo |   |  
				| 
 |  
				| ascolta, ma se li cancello c'è la possibilità che mi riappare ancora?  |  | 
	
		| Top |  | 
	
		|  | 
	
		| madvero Amministratore
 
  
  
 Registrato: 05/07/05 21:42
 Messaggi: 19518
 Residenza: L'immagine ha il solo scopo di rappresentare il prodotto.
 
 | 
			
				|  Inviato: 28 Mar 2007 21:38    Oggetto: |   |  
				| 
 |  
				| sì. se in esecuzione automatica si è infilato qualcosa che al riavvio del sistema va a beccare un eseguibile che te li reinstalla.
 comunque prima di eli minare qualunque cosa verifica.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Big Fuckin' Leccio Mortale devoto
 
  
 
 Registrato: 26/03/07 20:14
 Messaggi: 9
 
 
 | 
			
				|  Inviato: 28 Mar 2007 22:28    Oggetto: |   |  
				| 
 |  
				| Anke io ho questo cavolo di spyware o virus quello che è!!!!!!! 'Sto cacchio di CiD.... allego il LOG aiutatemi x favore!
 NN M RISP MAI NESSUNO LE HO PROVATE TUTTE AIUTATEMI X FAVORE!!
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\slserv.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\Messenger\msmsgs.exe
 C:\PROGRA~1\MSNMES~1\msnmsgr.exe
 C:\Programmi\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
 C:\Programmi\Winamp\winamp.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Hijack\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe"
 O4 - HKLM\..\Run: [OM_Monitor] C:\Programmi\OLYMPUS\OLYMPUS Master\FirstStart.exe
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
 O4 - HKLM\..\Run: [optionflawplatformping] C:\Documents and Settings\All Users\Dati applicazioni\RealLiteOptionFlaw\Start Bait.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [OM_Monitor] C:\Programmi\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = C:\Programmi\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: Apri immagine in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1040\phdintl.dll/phdContext.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://ogghia.spaces.live.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: InstallShield Licensing Service - Macrovision - C:\Programmi\File comuni\InstallShield Shared\Service\InstallShield Licensing Service.exe
 O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| madvero Amministratore
 
  
  
 Registrato: 05/07/05 21:42
 Messaggi: 19518
 Residenza: L'immagine ha il solo scopo di rappresentare il prodotto.
 
 | 
			
				|  Inviato: 28 Mar 2007 22:40    Oggetto: |   |  
				| 
 |  
				| dove non ti risponde mai nessuno? non qui !
   
 dammi cinque minuti...
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| madvero Amministratore
 
  
  
 Registrato: 05/07/05 21:42
 Messaggi: 19518
 Residenza: L'immagine ha il solo scopo di rappresentare il prodotto.
 
 | 
			
				|  Inviato: 28 Mar 2007 22:46    Oggetto: |   |  
				| 
 |  
				|  	  | Citazione: |  	  | C:\PROGRA~1\MSNMES~1\msnmsgr.exe | 
 questo controllalo: ce l'hai già nella cartella dedicata sotto c:\programmi
 
  	  | Citazione: |  	  | R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm | 
 questo tiralo via
 
  	  | Citazione: |  	  | O4 - HKLM\..\Run: [optionflawplatformping] C:\Documents and Settings\All Users\Dati applicazioni\RealLiteOptionFlaw\Start Bait.exe | 
 questo cos'è?
 se non lo hai installato tu, tiralo via.
 
  	  | Citazione: |  	  | O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) | 
 
  	  | Citazione: |  	  | O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) | 
 questi tirali via (sono inutili)
 
 comunque non mi sembri messo poi così male.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| crissal Mortale pio
 
  
 
 Registrato: 27/03/07 13:19
 Messaggi: 22
 
 
 | 
			
				|  Inviato: 29 Mar 2007 13:22    Oggetto: ancora cid |   |  
				| 
 |  
				| ancora cid       come mi comporto mi dici passo passo grazieeee
   
 
 Logfile of HijackThis v1.99.1
 Scan saved at 13.18.05, on 29/03/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\WINDOWS\ATKKBService.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Programmi\Winamp\winampa.exe
 C:\Programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Microsoft ActiveSync\wcescomm.exe
 C:\Programmi\eMule\emule.exe
 c:\progra~1\intern~1\iexplore.exe
 C:\Programmi\No-IP\DUC20.exe
 C:\PROGRA~1\MICROS~2\rapimgr.exe
 C:\PROGRA~1\INCRED~1\bin\IMApp.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\hijackers\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
 O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [IncrediMail] C:\Programmi\IncrediMail\bin\IncMail.exe /c
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmi\Microsoft ActiveSync\wcescomm.exe"
 O4 - HKCU\..\Run: [Beep Clock] C:\DOCUME~1\SALVAT~1\DATIAP~1\BASHMA~1\Mode one.exe
 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programmi\eMule\emule.exe -AutoStart
 O4 - Startup: No-IP DUC.lnk = C:\Programmi\No-IP\DUC20.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
 O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra 'Tools' menuitem: Crea preferito portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{3F48C699-C848-438E-88F7-3EEA2E115FCF}: NameServer = 192.168.1.1
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| madvero Amministratore
 
  
  
 Registrato: 05/07/05 21:42
 Messaggi: 19518
 Residenza: L'immagine ha il solo scopo di rappresentare il prodotto.
 
 | 
			
				|  Inviato: 29 Mar 2007 13:43    Oggetto: |   |  
				| 
 |  
				| senti, ma hai il ripristino configurazione di sistema di windows attivato? se la risposta è sì, per il momento disattivalo, prima di fare le modifiche.
 e controlla che in esecuzione automatica non ci sia niente di strano.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| crissal Mortale pio
 
  
 
 Registrato: 27/03/07 13:19
 Messaggi: 22
 
 
 | 
			
				|  Inviato: 29 Mar 2007 15:45    Oggetto: ??!! |   |  
				| 
 |  
				| fatto ed ho disabilitato il ripristino e cancellato in run le cose che erano strane , mi sono riapparsi i cid riecco il log.....   Logfile of HijackThis v1.99.1
 Scan saved at 15.43.37, on 29/03/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\WINDOWS\ATKKBService.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Programmi\Winamp\winampa.exe
 C:\Programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Microsoft ActiveSync\wcescomm.exe
 C:\Programmi\eMule\emule.exe
 c:\progra~1\intern~1\iexplore.exe
 C:\Programmi\No-IP\DUC20.exe
 C:\PROGRA~1\MICROS~2\rapimgr.exe
 C:\PROGRA~1\INCRED~1\bin\IMApp.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\hijackers\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
 O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [IncrediMail] C:\Programmi\IncrediMail\bin\IncMail.exe /c
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmi\Microsoft ActiveSync\wcescomm.exe"
 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programmi\eMule\emule.exe -AutoStart
 O4 - Startup: No-IP DUC.lnk = C:\Programmi\No-IP\DUC20.exe
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra 'Tools' menuitem: Crea preferito portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{3F48C699-C848-438E-88F7-3EEA2E115FCF}: NameServer = 192.168.1.1
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Big Fuckin' Leccio Mortale devoto
 
  
 
 Registrato: 26/03/07 20:14
 Messaggi: 9
 
 
 | 
			
				|  Inviato: 29 Mar 2007 23:47    Oggetto: |   |  
				| 
 |  
				| Grazie Madvero!! Ti chiedo l'ultimo favore
 invio il LOG.....potresti controllare se ora è tutto a posto? grazie!!!
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\slserv.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\PROGRA~1\MSNMES~1\msnmsgr.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\Winamp\winamp.exe
 C:\Programmi\Microsoft Office\Office10\WINWORD.EXE
 C:\WINDOWS\explorer.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Hijack\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe"
 O4 - HKLM\..\Run: [OM_Monitor] C:\Programmi\OLYMPUS\OLYMPUS Master\FirstStart.exe
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [OM_Monitor] C:\Programmi\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = C:\Programmi\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: Apri immagine in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1040\phdintl.dll/phdContext.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://ogghia.spaces.live.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: InstallShield Licensing Service - Macrovision                                                     - C:\Programmi\File comuni\InstallShield Shared\Service\InstallShield Licensing Service.exe
 O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| madvero Amministratore
 
  
  
 Registrato: 05/07/05 21:42
 Messaggi: 19518
 Residenza: L'immagine ha il solo scopo di rappresentare il prodotto.
 
 | 
			
				|  Inviato: 29 Mar 2007 23:48    Oggetto: Re: ??!! |   |  
				| 
 |  
				|  	  | crissal ha scritto: |  	  | ho cancellato in run le cose che erano strane | 
 esattamente, dove hai cancellato?
 aspetta che guardo il nuovo log.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| madvero Amministratore
 
  
  
 Registrato: 05/07/05 21:42
 Messaggi: 19518
 Residenza: L'immagine ha il solo scopo di rappresentare il prodotto.
 
 | 
			
				|  Inviato: 29 Mar 2007 23:52    Oggetto: |   |  
				| 
 |  
				| non mi sembra che il log abbia niente di strano... hai cancellato tutti i cookie e i file temp?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| madvero Amministratore
 
  
  
 Registrato: 05/07/05 21:42
 Messaggi: 19518
 Residenza: L'immagine ha il solo scopo di rappresentare il prodotto.
 
 | 
			
				|  Inviato: 29 Mar 2007 23:53    Oggetto: |   |  
				| 
 |  
				| fai una cosa: la prossima volta che ti si apre il pop up pubblicitario, posta l'elenco delle applicazioni e dei processi attivi presenti in task manager. |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 30 Mar 2007 14:01    Oggetto: |   |  
				| 
 |  
				| @crissal: non mi pare tu abbia cancellato i file (o in questo caso la cartella) dato che HijackThis cancella solo le chiavi di registro. 
 Quindi riavvia il pc in Modalità Provvisoria (quando ti fa il calcolo della memoria, ti segna gli hd collegati ecc premi continuamente F8 finchè non appare un menu, da lì scegli con le freccie la modalità).
 
 Cancella questa cartella C:\Document And Settings\SALVATqualcosa\DatiApplicazioni\BASHMAqualcosa
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |