| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 04 Mag 2007 08:25    Oggetto: [roxydale] CiD (e non solo..) |   |  
				| 
 |  
				| Inviato da roxydale 
 Ciao!! anch'io ho problemi con la pubblicità CiD..  allego il log:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 16.48.54, on 03/05/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16414)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Documents and Settings\Enrico\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.quipo.it/planetis
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
 O1 - Hosts: 207.44.196.219 auto.search.msn.com #NETVISION
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
 O2 - BHO: SmartShopper - {2BA1C226-EC1B-4471-A65F-D0688AC6EE3A} - C:\Programmi\SmartShopper\Bin\2.0.20\SmrtShpr.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
 O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Programmi\DAP\DAP.EXE" /STARTUP
 O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
 O4 - HKLM\..\Run: [FASTTRACKPassepartout] C:\WINDOWS\Passepartout.exe -A
 O4 - HKLM\..\Run: [FASTTRACKAdulti] C:\WINDOWS\Adulti.exe -A
 O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
 O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [TRANSHOLEVIEWBOLT] C:\Documents and Settings\All Users\Dati applicazioni\NurbWinTransHole\proxy bind.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
 O4 - HKLM\..\Run: [Regen] "C:\Programmi\OnSpec\All Users\Regen\Regen.exe" /STARTUP
 O4 - HKLM\..\Run: [HP Software Update] "G:\HP Software Update\HPWuSchd2.exe"
 O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] Need for Speed Carbon
 O4 - HKLM\..\Run: [Babylon Client] G:\Babylon\Babylon.exe -AutoStart
 O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
 O4 - HKLM\..\Run: [bagwindeal.exe] c:\windows\bagwindeal.exe reconnect
 O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Programmi\Google\Gmail Notifier\gnotify.exe
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
 O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\linewsrv.exe /run
 O4 - HKCU\..\Run: [FASTTRACKPassepartout] C:\WINDOWS\Passepartout.exe -A
 O4 - HKCU\..\Run: [FASTTRACKAdulti] C:\WINDOWS\Adulti.exe -A
 O4 - HKCU\..\Run: [Free Download Manager] C:\Programmi\Free Download Manager\fdm.exe -autorun
 O4 - HKCU\..\Run: [ares] "C:\Programmi\Ares\Ares.exe" -h
 O4 - HKCU\..\Run: [Tool Slow] C:\DOCUME~1\Enrico\DATIAP~1\CHICUS~1\Dvd16name.exe
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - Startup: OpenOffice.org 2.0.lnk = C:\Programmi\OpenOffice.org 2.0\program\quickstart.exe
 O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = G:\Digital Imaging\bin\hpqthb08.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Bluetooth Manager.lnk = ?
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = G:\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Clean Traces - C:\Programmi\DAP\Privacy Package\dapcleanerie.htm
 O8 - Extra context menu item: &Download with &DAP - C:\Programmi\DAP\dapextie.htm
 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm610YYIT
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: Download &all with DAP - C:\Programmi\DAP\dapextie2.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Translate with &Babylon - res://G:\Babylon\Utils\BabylonIEPI.dll/Translate.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Programmi\SmartShopper\Bin\2.0.20\SmrtShpr.dll
 O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Programmi\SmartShopper\Bin\2.0.20\SmrtShpr.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\it.htm
 O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
 O16 - DPF: {1230CB21-C88D-11CF-0000-000000000000} - http://www.browserupdate.co.uk/cabs/customers/12345863/it010004.cab
 O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFWBInitialSetup1.0.0.15.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://punkina91.spaces.live.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {82EDCE41-48A9-41F8-8E4E-808067A32F60} - http://uv97vqm3.com/aa6942fb/50310/1/xp/BestMoney.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
 O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.quickstaraccess.com/10705-23.exe
 O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
 O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
 O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
 O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmi\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
 O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Programmi\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
 O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
 O23 - Service: WebJku - Unknown owner - \\?\C:\Programmi\File comuni\System\con.exe (file missing)
 O23 - Service: Zaep Engine (Zaep) - Unknown owner - G:\Zaep\Zaep.exe" -service (file missing)
 
 vi prego help me!!! grazie ciao!!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 04 Mag 2007 09:11    Oggetto: |   |  
				| 
 |  
				| ciao, roxydale e benvenuto. credo che il Cid è l'ultimo dei tuoi problemi...
   
 dai un'occhiata qui e segui i consigli.
 dopo di che torna con un nuovo log.
 
 
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 04 Mag 2007 09:13    Oggetto: Re: [roxydale] CiD (e non solo..) |   |  
				| 
 |  
				| Ciao Roxydale, prima di tutto, metti hijackthis in una sua cartella.
 Poi disattiva il ripristino configurazione di sistema, attiva la visualizzazione dei files nascosti e di sistema, avvia in modalità provvisoria. (Qui trovi come fare)
 
 Di carne al fuoco ce n'è parecchia
   Quando sei in modalità provvisoria:
 - avvia hijack
 - Do a system scan only
 - metti il segno di spunta alle voci seguenti:
 
  	  | roxydale ha scritto: |  	  | O4 - HKLM\..\Run: [FASTTRACKPassepartout] C:\WINDOWS\Passepartout.exe -A O4 - HKLM\..\Run: [FASTTRACKAdulti] C:\WINDOWS\Adulti.exe -A
 O4 - HKLM\..\Run: [TRANSHOLEVIEWBOLT] C:\Documents and Settings\All Users\Dati applicazioni\NurbWinTransHole\proxy bind.exe
 ***O4 - HKLM\..\Run: [Regen] "C:\Programmi\OnSpec\All Users\Regen\Regen.exe" /STARTUP
 O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] Need for Speed Carbon
 O4 - HKLM\..\Run: [Babylon Client] G:\Babylon\Babylon.exe -AutoStart
 O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
 O4 - HKLM\..\Run: [bagwindeal.exe] c:\windows\bagwindeal.exe reconnect
 O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\linewsrv.exe /run
 O4 - HKCU\..\Run: [FASTTRACKPassepartout] C:\WINDOWS\Passepartout.exe -A
 O4 - HKCU\..\Run: [FASTTRACKAdulti] C:\WINDOWS\Adulti.exe -A
 O4 - HKCU\..\Run: [Tool Slow] C:\DOCUME~1\Enrico\DATIAP~1\CHICUS~1\Dvd16name.exe
 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm610YYIT
 ***O16 - DPF: {1230CB21-C88D-11CF-0000-000000000000} - http://www.browserupdate.co.uk/cabs/customers/12345863/it010004.cab
 ***O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFWBInitialSetup1.0.0.15.cab
 O16 - DPF: {82EDCE41-48A9-41F8-8E4E-808067A32F60} - http://uv97vqm3.com/aa6942fb/50310/1/xp/BestMoney.cab
 O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.quickstaraccess.com/10705-23.exe
 O23 - Service: WebJku - Unknown owner - \\?\C:\Programmi\File comuni\System\con.exe (file missing)
 O23 - Service: Zaep Engine (Zaep) - Unknown owner - G:\Zaep\Zaep.exe" -service (file missing)
 | 
 
 ATTENZIONE: ho indicato con *** le voci su cui ho dei dubbi, se tu sai che ti servono e che sono sicure non mettere il segno di spunta.
 
 clicca su fix checked.
 riavvia il pc e riposta il log di hijack che poi ci sarà altro da fare...
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 04 Mag 2007 09:17    Oggetto: |   |  
				| 
 |  
				| Ho visto solo ora che Orange ti ha già risposto.  |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 04 Mag 2007 09:21    Oggetto: |   |  
				| 
 |  
				|  	  | bdoriano ha scritto: |  	  | Ho visto solo ora che Orange ti ha già risposto.  | 
 
   (mi sembrava la via più semplice al momento..)
 
 
 mattiniero anche tu?
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 04 Mag 2007 09:28    Oggetto: |   |  
				| 
 |  
				| Eh già!   La prima mattina e la tarda sera sono i momenti più tranquilli della giornata.
   
 Mi sa che mi dovrò spulciare tutti i forum per vedere le risposte "general-purpose" e non dover ogni volta riscoprire l'acqua calda!
  |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |