| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| becker Mortale devoto
 
  
 
 Registrato: 11/09/07 13:17
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 11 Set 2007 13:25    Oggetto: Log hijackthis da controllare |   |  
				| 
 |  
				|   Ciao!
 ho alcuni problemi nel computer e leggendo il vostro forum ho pensato di fare una scansione con hijack. questo è il log file
 vi prego aiutatemi... ho la tesi tra 15 giorni ed il mio computer non è d'accordo!!!
 
   
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 13.07.31, on 11/09/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\csrss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\S24EvMon.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
 C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\WINDOWS\system32\RemoteControlService.exe
 C:\WINDOWS\system32\ZCfgSvc.exe
 C:\WINDOWS\System32\1XConfig.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
 C:\Programmi\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\System32\RegSrvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
 C:\Programmi\RealVNC\VNC4\WinVNC4.exe
 C:\WINDOWS\ATK0100\Hcontrol.exe
 C:\Progra~1\ASUS\Power4 Gear\BatteryLife.exe
 C:\Progra~1\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\WINDOWS\System32\alg.exe
 C:\WINDOWS\VM_STI.EXE
 C:\WINDOWS\system32\LVCOMSX.EXE
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Java\jre1.5.0_03\bin\jusched.exe
 C:\WINDOWS\vsnpstd2.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\Asus\Asus ChkMail\ChkMail.exe
 C:\Programmi\File comuni\Microsoft Shared\Works Shared\wkcalrem.exe
 C:\WINDOWS\ATK0100\ATKOSD.exe
 C:\Programmi\Security Task Manager\taskman.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Spyware Doctor\swdsvc.exe
 C:\Programmi\Spyware Doctor\SDTrayApp.exe
 C:\Programmi\Spyware Doctor\svcntaux.exe
 C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
 C:\WINDOWS\system32\wbem\wmiprvse.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
 O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll
 O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
 O4 - HKLM\..\Run: [Power_Gear] C:\Progra~1\ASUS\Power4 Gear\BatteryLife.exe 1
 O4 - HKLM\..\Run: [ATIPTA] C:\Progra~1\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Programmi\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
 O4 - HKLM\..\Run: [WorksFUD] C:\Programmi\Microsoft Works\wkfud.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmi\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE NoteCam Sm@rt A300
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_03\bin\jusched.exe
 O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
 O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKLM\..\Run: [SDTray] "C:\Programmi\Spyware Doctor\SDTrayApp.exe"
 O4 - HKLM\..\RunOnce: [MessengerPlusUninstall] C:\WINDOWS\system32\cmd.exe /C "C:\DOCUME~1\michele\IMPOST~1\Temp\MsgPlusUninst.bat"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGDACCESS_1061.dll,InstantAccess
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: ASUS ChkMail.lnk = C:\Programmi\Asus\Asus ChkMail\ChkMail.exe
 O4 - Global Startup: Promemoria del Calendario di Microsoft Works.lnk = ?
 O4 - Global Startup: Windows Desktop Search.lnk = C:\Programmi\MSN Toolbar Suite\DS\02.05.0001.1119\it-it\bin\WindowsSearch.exe
 O4 - Global Startup: Tasto di scelta rapida per l'avvio di AutoCAD.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart17.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O8 - Extra context menu item: &AOL Toolbar search - res://C:\Programmi\AOL Toolbar\toolbar.dll/SEARCH.HTML
 O8 - Extra context menu item: &MSN Search - res://C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll/search.htm
 O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\MSN Toolbar Suite\TAB\02.05.0001.1119\it-it\msntabres.dll/230?473bba3581ed40dfb8bb7af8b21a418
 O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\MSN Toolbar Suite\TAB\02.05.0001.1119\it-it\msntabres.dll/229?473bba3581ed40dfb8bb7af8b21a418
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra button: Alice - {F735A981-612B-480A-9DF5-2BE05C37616C} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 O15 - Trusted Zone: *.energyfactor.com
 O15 - Trusted Zone: *.hardcorefantasyland.com
 O16 - DPF: {00000000-0000-0000-0000-000020040000} - http://www.pgsconnect.com/access/pgs0068.exe
 O16 - DPF: {1604DF98-D1A5-44FE-844A-98D6FD0518D0} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1060_XP.cab
 O16 - DPF: {1CD49DC9-FD88-41FA-B892-47E037267D45} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1059_XP.cab
 O16 - DPF: {31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} - http://akamai.downloadv3.com/binaries/IA/svcsysnet32_EN_XP.cab
 O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
 O16 - DPF: {BFC9677B-8006-4336-9D49-2C797AEFCB9E} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1058_XP.cab
 O16 - DPF: {C6760A07-A574-4705-B113-7856315922C3} - http://akamai.downloadv3.com/binaries/IA/sysnetsvc32_EN_XP.cab
 O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Controllo AcPreview) - file://C:\Programmi\AutoCAD 2002 Ita\AcPreview.ocx
 O16 - DPF: {FA83E942-B796-46DE-9155-1632ECC5473B} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1061_XP.cab
 O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://download.energyfactor.com/dialer/it/activex_259_it.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{39BD5FFE-8BF0-40E9-A7D5-AC5223288BE3}: NameServer = 151.99.125.3,151.99.125.1
 O17 - HKLM\System\CCS\Services\Tcpip\..\{C55561DD-A92D-4EB1-8F55-F89032D70AA1}: NameServer = 151.99.125.3,151.99.125.1
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FF007672-22D7-461C-BD55-5698F0250A5D}: Domain = ciotto
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FF007672-22D7-461C-BD55-5698F0250A5D}: NameServer = 151.99.125.2,151.99.125.3
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
 O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: ITE Remote Control Service (ITECIRService) - ITE Tech. Inc. - C:\WINDOWS\system32\RemoteControlService.exe
 O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
 O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
 O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
 O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
 O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
 O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Programmi\RealVNC\VNC4\WinVNC4.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 11 Set 2007 14:19    Oggetto: |   |  
				| 
 |  
				| benvenuto, becker   
 sarebbe utile anche sapere che tipo di problemi hai con PC
   
 disattiva il ripristino e avvia in modalità provvisoria
 avvia HiJack, seleziona Do a system scan only, metti la spunta alle voci indicate e premi Fix checked:
 
 O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGDACCESS_1061.dll,InstantAccess
 O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
 O9 - Extra button: Alice - {F735A981-612B-480A-9DF5-2BE05C37616C} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
 O15 - Trusted Zone: *.energyfactor.com
 O15 - Trusted Zone: *.hardcorefantasyland.com
 O16 - DPF: {00000000-0000-0000-0000-000020040000} - http://www.pgsconnect.com/access/pgs0068.exe
 O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://download.energyfactor.com/dialer/it/activex_259_it.exe
 O16 - DPF: {1604DF98-D1A5-44FE-844A-98D6FD0518D0} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1060_XP.cab
 O16 - DPF: {1CD49DC9-FD88-41FA-B892-47E037267D45} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1059_XP.cab
 O16 - DPF: {31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} - http://akamai.downloadv3.com/binaries/IA/svcsysnet32_EN_XP.cab
 O16 - DPF: {BFC9677B-8006-4336-9D49-2C797AEFCB9E} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1058_XP.cab
 O16 - DPF: {C6760A07-A574-4705-B113-7856315922C3} - http://akamai.downloadv3.com/binaries/IA/sysnetsvc32_EN_XP.cab
 O16 - DPF: {FA83E942-B796-46DE-9155-1632ECC5473B} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1061_XP.cab
 
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FF007672-22D7-461C-BD55-5698F0250A5D}: Domain = ciotto <-- su quest'ultimo ho qualche dubbio... se lo conosci non eliminarlo
 
 rifai il log con HiJack e mettilo qui
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| becker Mortale devoto
 
  
 
 Registrato: 11/09/07 13:17
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 11 Set 2007 16:24    Oggetto: |   |  
				| 
 |  
				| Grazie per l'aiuto!!   ho fatto quello che mi hai detto.... ecco il nuovo file log
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 16.18.59, on 11/09/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\csrss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\S24EvMon.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
 C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\WINDOWS\system32\RemoteControlService.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
 C:\Programmi\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
 C:\WINDOWS\System32\RegSrvc.exe
 C:\Programmi\Spyware Doctor\svcntaux.exe
 C:\Programmi\Spyware Doctor\swdsvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
 C:\Programmi\RealVNC\VNC4\WinVNC4.exe
 C:\WINDOWS\System32\alg.exe
 C:\WINDOWS\system32\ZCfgSvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\System32\1XConfig.exe
 C:\WINDOWS\system32\wbem\wmiprvse.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\ATK0100\Hcontrol.exe
 C:\Progra~1\ASUS\Power4 Gear\BatteryLife.exe
 C:\Progra~1\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\WINDOWS\VM_STI.EXE
 C:\WINDOWS\system32\LVCOMSX.EXE
 C:\WINDOWS\ATK0100\ATKOSD.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Java\jre1.5.0_03\bin\jusched.exe
 C:\WINDOWS\vsnpstd2.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
 C:\Programmi\Spyware Doctor\SDTrayApp.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 C:\PROGRA~1\MSNMES~1\msnmsgr.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\Asus\Asus ChkMail\ChkMail.exe
 C:\Programmi\File comuni\Microsoft Shared\Works Shared\wkcalrem.exe
 C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
 O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll
 O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
 O4 - HKLM\..\Run: [Power_Gear] C:\Progra~1\ASUS\Power4 Gear\BatteryLife.exe 1
 O4 - HKLM\..\Run: [ATIPTA] C:\Progra~1\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Programmi\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
 O4 - HKLM\..\Run: [WorksFUD] C:\Programmi\Microsoft Works\wkfud.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmi\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE NoteCam Sm@rt A300
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_03\bin\jusched.exe
 O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
 O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKLM\..\Run: [SDTray] "C:\Programmi\Spyware Doctor\SDTrayApp.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: ASUS ChkMail.lnk = C:\Programmi\Asus\Asus ChkMail\ChkMail.exe
 O4 - Global Startup: Promemoria del Calendario di Microsoft Works.lnk = ?
 O4 - Global Startup: Windows Desktop Search.lnk = C:\Programmi\MSN Toolbar Suite\DS\02.05.0001.1119\it-it\bin\WindowsSearch.exe
 O4 - Global Startup: Tasto di scelta rapida per l'avvio di AutoCAD.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart17.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O8 - Extra context menu item: &AOL Toolbar search - res://C:\Programmi\AOL Toolbar\toolbar.dll/SEARCH.HTML
 O8 - Extra context menu item: &MSN Search - res://C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll/search.htm
 O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\MSN Toolbar Suite\TAB\02.05.0001.1119\it-it\msntabres.dll/230?473bba3581ed40dfb8bb7af8b21a418
 O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\MSN Toolbar Suite\TAB\02.05.0001.1119\it-it\msntabres.dll/229?473bba3581ed40dfb8bb7af8b21a418
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
 O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Controllo AcPreview) - file://C:\Programmi\AutoCAD 2002 Ita\AcPreview.ocx
 O17 - HKLM\System\CCS\Services\Tcpip\..\{39BD5FFE-8BF0-40E9-A7D5-AC5223288BE3}: NameServer = 151.99.125.3,151.99.125.1
 O17 - HKLM\System\CCS\Services\Tcpip\..\{C55561DD-A92D-4EB1-8F55-F89032D70AA1}: NameServer = 151.99.125.3,151.99.125.1
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FF007672-22D7-461C-BD55-5698F0250A5D}: Domain = ciotto
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FF007672-22D7-461C-BD55-5698F0250A5D}: NameServer = 151.99.125.2,151.99.125.3
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
 O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: ITE Remote Control Service (ITECIRService) - ITE Tech. Inc. - C:\WINDOWS\system32\RemoteControlService.exe
 O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
 O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
 O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
 O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
 O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
 O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Programmi\RealVNC\VNC4\WinVNC4.exe
 
 --
 End of file - 10163 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 11 Set 2007 16:33    Oggetto: |   |  
				| 
 |  
				| il log è pulito. 
 su questo che mi dici? 	  | Orange ha scritto: |  	  | O17 - HKLM\System\CCS\Services\Tcpip\..\{FF007672-22D7-461C-BD55-5698F0250A5D}: Domain = ciotto <-- su quest'ultimo ho qualche dubbio... se lo conosci non eliminarlo | 
 
 che problemi riscontri?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| becker Mortale devoto
 
  
 
 Registrato: 11/09/07 13:17
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 11 Set 2007 16:43    Oggetto: |   |  
				| 
 |  
				| Dimenticavo di dirti i problemi che ho con il computer... 1)all'accensione mi compare una finestra che mi segnala un errore in EGDACCESS_1061.dll
 2) sto lavorando con dei file DWG di dimensini dai 20 ai 60 Mb ed il computer è molto rallentato: ha difficoltà ad aprire il file e a lavorarci, chiudendomelo sempre in seguito ad un "errore fatale"... (premetto che ho sempre lavorato senza problemi anche con file molto più grandi!)
 3)ho sansionato il pc con molti antivirus, l'unico che rileva qualcosa è Spyware Doctor e mi dice che ho:
 -Application.TrackingCookies(1 infezione)
 - Trojan.Lazar (3 infezioni)
 - Dialer.Instant_Access(17 infezioni)[prima che mi dicessi di chiudere quelle cose erano 90]
 
 il programma l'ho scaricato dalla rete ma non mi permette di cancellare le infezioni salvo acquistarlo.... posso fare in qualche altro modo?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 11 Set 2007 16:50    Oggetto: |   |  
				| 
 |  
				| ora è un'po piu chiara la situazione   
 Scarica FindAWF e avvialo. dalle varie opzioni scegli 1+Invio. il tool farà una rapida scansione ed aprirà il blocco note con dentro il log.
 copia tutto il suo contenuto e postalo qui
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| becker Mortale devoto
 
  
 
 Registrato: 11/09/07 13:17
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 11 Set 2007 17:00    Oggetto: |   |  
				| 
 |  
				| su quel file non so che dirti... sono un comune mortale! ecco il contenuto del log
 
 
 Find AWF report by noahdfear ©2006
 Version 1.40
 
 
 
 bak folders found
 ~~~~~~~~~~~
 
 
 
 Duplicate files of bak directory contents
 ~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 end of report
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| becker Mortale devoto
 
  
 
 Registrato: 11/09/07 13:17
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 11 Set 2007 17:24    Oggetto: |   |  
				| 
 |  
				| Da ieri, avendo problemi con il mio pc ho provato a lavorare anche su quello di mia sorella ma anche li ho riscontrato qualche problemino... seguendo i tuoi consigli, ho cominciato le varie procedure e ho trovato in Task Manager i file WSCNTFY.EXE e SVCHOST.EXE.
 Sul forum ho letto che se si trovano in C:\windows\sistem32 non c'è problema in caso conrtario potrebbero essere virus...   entrambi questi file li ho trovato in C:\windows\sistem32  ma ho trovato anche questi:
 -WSCNTFY.EXE-OB14C27D.pf
 -SWCHOST.EXE-2D5FBD10.pf
 
 che cosa sono?
   
 P.S. di quel file mi sono ricordato che "CIOTTO" è il nick che usa mia sorella
 
 P.P.S. grazie mille per l'aiuto che mi stai dando!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 11 Set 2007 18:13    Oggetto: |   |  
				| 
 |  
				|  	  | becker ha scritto: |  	  | Find AWF report by noahdfear ©2006 Version 1.40
 | 
 
  è pulito. e io invece ci avrei scommesso che la causa fosse quella
   quei processi che stai segnalando non promettono nulla di buono. SWCHOST.EXE dovrebbe appartenere ad un e-mail worm.
 
 facciamo così: scaricati VirIt, aggiornalo e fai lo scan completo del sistema.
 posta il risultato
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| becker Mortale devoto
 
  
 
 Registrato: 11/09/07 13:17
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 11 Set 2007 19:00    Oggetto: |   |  
				| 
 |  
				| Che mi consigli di fare visto che spywaredoctor mi segnala ancora 17 file infetti e il pc va sempre lento? 
 Per quanto riguarda il pc di mia sorella ho fatto la scansione che mi hai detto ma non rileva niente:file infetti 0,file sspetti 0,chiavi registro infetti0.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ste_95 Dio maturo
 
  
  
 Registrato: 03/08/07 14:41
 Messaggi: 1920
 Residenza: Italy
 
 | 
			
				|  Inviato: 11 Set 2007 19:46    Oggetto: |   |  
				| 
 |  
				| come dice orange, fai la scansione con virit, e poi postane il log... |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 11 Set 2007 20:24    Oggetto: |   |  
				| 
 |  
				| becker, segui queste indicazioni di Orange: 
  	  | Orange ha scritto: |  	  | facciamo così: scaricati VirIt, aggiornalo e fai lo scan completo del sistema. posta il risultato
 | 
 Altrimenti, non possiamo andare avanti. Ok?
  |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |