| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| agatina Eroe
 
  
 
 Registrato: 29/05/07 12:44
 Messaggi: 50
 
 
 | 
			
				|  Inviato: 20 Dic 2007 22:30    Oggetto: c'e' qualcosa che non va |   |  
				| 
 |  
				| da qualche giorno in internet vengo reindirizzato a false pagine di google e outlook express si apre da solo. norton non segnala nulla... questo e' il log
 grazie se mi potrete dare una mano.
 
 Logfile of HijackThis v1.99.1
 Scan saved at 21.20.00, on 20/12/2007
 Platform: Windows XP  (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 (6.00.2600.0000)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Ahead\InCD\InCDsrv.exe
 C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
 C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
 C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
 C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
 C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
 C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\a-squared Anti-Dialer\a2service.exe
 C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
 C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\File comuni\Symantec Shared\ccApp.exe
 C:\Programmi\iTunes\iTunesHelper.exe
 C:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe
 C:\Programmi\a-squared Anti-Dialer\a2adguard.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\Programmi\iPod\bin\iPodService.exe
 C:\Programmi\D-Link\AirPlus G\AirGCFG.exe
 C:\Programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe
 C:\WINDOWS\svc.exe
 C:\WINDOWS\runsql.exe
 C:\WINDOWS\svzip.exe
 C:\WINDOWS\sv.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\WINDOWS\svhoster.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\WinZip\WZQKPICK.EXE
 C:\PROGRA~1\WINZIP\winzip32.exe
 C:\Documents and Settings\elenina\Impostazioni locali\Temp\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
 O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
 O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
 O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
 O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
 O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe"
 O4 - HKLM\..\Run: [a-squared Anti-Dialer] "C:\Programmi\a-squared Anti-Dialer\a2adguard.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
 O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Programmi\D-Link\AirPlus G\AirGCFG.exe
 O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [netc] C:\WINDOWS\svc.exe
 O4 - HKLM\..\Run: [netzip] C:\WINDOWS\svzip.exe
 O4 - HKLM\..\Run: [runsql] C:\WINDOWS\runsql.exe
 O4 - HKLM\..\Run: [UpdateWin] C:\WINDOWS\System32\ahuit.exe
 O4 - HKLM\..\Run: [netsv32] C:\WINDOWS\sv.exe
 O4 - HKLM\..\Run: [net64] C:\WINDOWS\svhoster.exe
 O4 - HKLM\..\RunServices: [UpdateWin] C:\WINDOWS\System32\ahuit.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - HKCU\..\Run: [UpdateWin] C:\WINDOWS\System32\ahuit.exe
 O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\elenina\IMPOST~1\Temp\winlogon.exe
 O4 - HKCU\..\RunServices: [UpdateWin] C:\WINDOWS\System32\ahuit.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O23 - Service: a-squared Anti-Dialer Service (a2AntiDialer) - Emsi Software GmbH - C:\Programmi\a-squared Anti-Dialer\a2service.exe
 O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Programmi\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\ccPwdSvc.exe
 O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
 O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmi\Norton Internet Security\comHost.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
 O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
 O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\SAVScan.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
 |  |  
		| Top |  |  
		|  |  
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 20 Dic 2007 22:40    Oggetto: |   |  
				| 
 |  
				| Prima di iniziare, Hijackthis va salvato in una sua cartella non temporanea e non sul desktop.   
 Disabilita il ripristino di sistema e avvia il pc in modalità provvisoria
 esegui hijackthis
 clicca su do a system scan only
 metti il segno di spunta a queste voci:
 
  	  | Citazione: |  	  | O4 - HKLM\..\Run: [netc] C:\WINDOWS\svc.exe O4 - HKLM\..\Run: [netzip] C:\WINDOWS\svzip.exe
 O4 - HKLM\..\Run: [runsql] C:\WINDOWS\runsql.exe
 O4 - HKLM\..\Run: [UpdateWin] C:\WINDOWS\System32\ahuit.exe
 O4 - HKLM\..\Run: [netsv32] C:\WINDOWS\sv.exe
 O4 - HKLM\..\Run: [net64] C:\WINDOWS\svhoster.exe
 O4 - HKLM\..\RunServices: [UpdateWin] C:\WINDOWS\System32\ahuit.exe
 O4 - HKCU\..\Run: [UpdateWin] C:\WINDOWS\System32\ahuit.exe
 O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\elenina\IMPOST~1\Temp\winlogon.exe
 O4 - HKCU\..\RunServices: [UpdateWin] C:\WINDOWS\System32\ahuit.exe
 | 
 clicca fix checked
 Riavvia il pc in modalità normale, rifai il log di hijackthis e postalo
 
 Scarica e installa il service pack 2 prima possibile, mi raccomando!!
 |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |