| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 06 Gen 2008 15:04    Oggetto: * problema CiD |   |  
				| 
 |  
				| Ciao! ringrazio in anticipo chi mi aiuterà a risolvere questo problema...per un po' era sparito togliendo Msn Plus, poi è ricomparso...
 Segue il Log
 Grazie!
 Federica
 
 --------------------------------------------
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 14.01.14, on 06/01/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 C:\Programmi\Bonjour\mDNSResponder.exe
 C:\WINDOWS\system32\cisvc.exe
 C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\slmdmsr.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\cidaemon.exe
 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\WINDOWS\system32\VTTimer.exe
 C:\WINDOWS\system32\VTtrayp.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\WINDOWS\system32\drivers\Icon.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\WINDOWS\vsnpstd.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe
 C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
 C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 C:\Programmi\WinZip\WZQKPICK.EXE
 C:\PROGRA~1\Grisoft\AVG7\avgw.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
 C:\WINDOWS\explorer.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 C:\HiJackThis\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ig?hl=it
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\Federica\Desktop\Stef personal files!\rpbrowserrecordplugin.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
 O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
 O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\system32\STDSB.EXE
 O4 - HKLM\..\Run: [Icon] C:\WINDOWS\system32\drivers\Icon.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S83.tmp" /EF "HKLM"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
 O4 - HKLM\..\Run: [blue delete title meow] C:\Documents and Settings\All Users\Dati applicazioni\up hold blue delete\SLOW DUMB.exe
 O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\Federica\IMPOST~1\Temp\MsgPlusUninstall.exe" /Cleanup
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Kodak EasyShare software.lnk = C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmi\Bonjour\ExplorerPlugin.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slmdmsr.exe
 
 --
 End of file - 9686 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 06 Gen 2008 17:42    Oggetto: |   |  
				| 
 |  
				| ciao xfaith84 benvenuta   
 Scarica ATF Cleaner e RBKiller
 
 Avvia ATF Cleaner; metti la spunta su Select all (se usi Firefox o Opera spunta anche le loro opzioni)
 clicca Empty selected e aspetta il messaggio Done cleaning!
 eventualmente ripeti per FF e/o Opera
 
 Avvia RBKiller, clicca Scan; a scansione terminata conferma l'eliminazione dei eventuali files trovati
 
 disattiva il ripristino e avvia in modalità provvisoria
 avvia HijackThis, seleziona Do a system scan only, metti la spunta alle voci indicate (se presenti) e premi Fix checked:
 
 O4 - HKLM\..\Run: [Icon] C:\WINDOWS\system32\drivers\Icon.exe
 O4 - HKLM\..\Run: [blue delete title meow] C:\Documents and Settings\All Users\Dati applicazioni\up hold blue delete\SLOW DUMB.exe
 O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\Federica\IMPOST~1\Temp\MsgPlusUninstall.exe" /Cleanup
 
 Trova e cancella:
 C:\Documents and Settings\All Users\Dati applicazioni\up hold blue delete\SLOW DUMB.exe
 
 Avvia in modalità normale, rifai il log HJT e postalo insieme al risultato di RBKiller (scanlog.txt)
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 06 Gen 2008 18:35    Oggetto: |   |  
				| 
 |  
				| innanzitutto grazie mille per l'aiuto tempestivo! per RBkiller non posso postare nulla, visto che dopo lo scan non mi ha evidenziato problemi ("No RAPIDBLASTER processes detected")
 Per il log con HJ, segue qui sotto
 
 incrocio le dita e speriamo in bene...grazie ancora
 
 ----------
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 17.32.29, on 06/01/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 C:\Programmi\Bonjour\mDNSResponder.exe
 C:\WINDOWS\system32\cisvc.exe
 C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\slmdmsr.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\WINDOWS\system32\VTTimer.exe
 C:\WINDOWS\system32\VTtrayp.exe
 C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\WINDOWS\vsnpstd.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe
 C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe
 C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 C:\Programmi\WinZip\WZQKPICK.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
 C:\HiJackThis\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ig?hl=it
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\Federica\Desktop\Stef personal files!\rpbrowserrecordplugin.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
 O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
 O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\system32\STDSB.EXE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S83.tmp" /EF "HKLM"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
 O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Kodak EasyShare software.lnk = C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmi\Bonjour\ExplorerPlugin.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slmdmsr.exe
 
 --
 End of file - 9170 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 06 Gen 2008 23:42    Oggetto: |   |  
				| 
 |  
				| ciao. il log sembra pulito, ma giusto per stare tranquilli: fai una scansione on-line con Kaspersky in modalità estesa, come indicato qui. Carica il risultato su Freefilehosting.net e posta il link.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 07 Gen 2008 22:34    Oggetto: |   |  
				| 
 |  
				| sto per mettermi a piangere... ho acceso il pc per fare quello che mi avevi detto e le maledettissima pubblicità son tornate!
 ho notato che accendendo il pc mi è uscita la finestra di spybot relativa alle modifiche e mi chiedeva se volevo acconsentire alla modifica dell'aggiunta di blue delete title meow; ovviamente ho negato la cosa ma mi stanno comparendo le pubblicità comunque.
 Ho rifatto il log... è qui sotto.
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 21.29.03, on 07/01/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 C:\Programmi\Bonjour\mDNSResponder.exe
 C:\WINDOWS\system32\cisvc.exe
 C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\slmdmsr.exe
 C:\WINDOWS\system32\svchost.exe
 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\WINDOWS\system32\VTTimer.exe
 C:\WINDOWS\system32\VTtrayp.exe
 C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\WINDOWS\vsnpstd.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe
 C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe
 C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 C:\Programmi\WinZip\WZQKPICK.EXE
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
 C:\HiJackThis\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ig?hl=it
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\Federica\Desktop\Stef personal files!\rpbrowserrecordplugin.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
 O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
 O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\system32\STDSB.EXE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S83.tmp" /EF "HKLM"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Kodak EasyShare software.lnk = C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmi\Bonjour\ExplorerPlugin.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slmdmsr.exe
 
 --
 End of file - 9292 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 07 Gen 2008 23:16    Oggetto: |   |  
				| 
 |  
				| ok...spero di aver fatto tutto giusto autostart autostart9.txt
 
 rootkit
 rootkit7.txt
 
 incrocio le dita...e ti ringrazio nuovamente
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 07 Gen 2008 23:27    Oggetto: |   |  
				| 
 |  
				| Anche i logs di gmer mi sembrano a posto. Facciamo un altro controllo: segui le istruzioni di questo topic per postare il log di combofix.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 07 Gen 2008 23:51    Oggetto: |   |  
				| 
 |  
				| eccomi...mentre andava ho visto che mi cancellava C:\WINDOWS\system32\drivers\Icon.exe che peraltro avevo già eliminato ieri e che nel log di HJ di un'ora fa non compariva più..
 comunque, il link è qui
 
 log13.txt
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 08 Gen 2008 22:28    Oggetto: |   |  
				| 
 |  
				| ciao, sono passata per aggiornare. Da quando ho usato combofix non è più riapparso nulla. Credo sia per quel file che ha cancellato, anche se non capisco perchè in hijack non fosse più ricomparso... Beh, almeno per ora va tutto bene. Grazie ancora! e incrociamo le dita..
 federica
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 10 Gen 2008 11:35    Oggetto: |   |  
				| 
 |  
				| Ci sono un paio di files da eliminare. 
 Scarica avenger e scompattalo in una sua cartella non temporanea e non sul desktop
 
 Avvia AVENGER
 Clicca su input script manually
 Clicca sulla lente d'ingrandimento
 Inserisci queste righe:
 
  	  | Citazione: |  	  | files to delete: C:\WINDOWS\Tasks\AFD36DDB91AD1F07.job
 c:\docume~1\ivan\datiap~1\dvdlis~1\Tick slow bend.exe
 | 
 Clicca su Done
 Clicca sul semaforo
 Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
 Al termine dell'operazione, posta qui il risultato di Avenger con un log aggiornato di hijackthis.
 
 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| kinanera Comune mortale
 
  
 
 Registrato: 13/01/08 01:41
 Messaggi: 4
 
 
 | 
			
				|  Inviato: 13 Gen 2008 01:55    Oggetto: |   |  
				| 
 |  
				| Aspetta aspetta...se hai istallato Messenger Live Plus ho io la soluzione per te. Avevo lo stesso problema e pensando fosse un visur o chissà cosa ho fatto scansioni su scansioni senza risultato. Ora invece ho risolto. Perchè? Perchè le finestre CID NON SONO VIRUS, bensì degli sponsor allegati alla versione "plus" di messenger live. Ecco cosa fare: vai su start,impostazioni accesso ai programmi, cambia e rimuovi programmi. Dovresti trovare il programma sotto il nome "Messenger Plus Live &Sponsor (CiD)"o roba simile (io almeno l'ho trovato con questo nome. Clicca su cambia/rimuovi e infine su RIMUOVI SOLO SPONSOR, altrimenti ti cancella anche il programma stesso.
 Tutto qui. Molto semplice. Più del previsto....per fortuna
 Ciao a tutti
 
 ps:passate l'informazione a chi ha problemi di questo tipo anche su gli altri topic
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 13 Gen 2008 11:39    Oggetto: |   |  
				| 
 |  
				| Peccato che, nel caso di xfaith84, avesse già disinstallato MessengerPlus e il problema sia riapparso nonostante la disinstallazione.  |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 15 Gen 2008 20:31    Oggetto: |   |  
				| 
 |  
				| non sto capendo...ho fatto quella cosa con avenger e mi ha dato errore precisamente, nel log c'è scritto
 
 //////////////////////////////////////////
 Avenger Pre-Processor log
 //////////////////////////////////////////
 
 Fatal error:  could not create new script file.
 Error code: 0
 Error logged to errorlog.txt.  Aborting now!
 
 io ho fatto tutto come detto...i file sono giusti perchè ho fatto copiaincolla da quelli che mi hai scritto tu.
 In più non capisco perchè a me siano spariti i CiD, ma nell'identità di mio padre no!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 15 Gen 2008 20:39    Oggetto: |   |  
				| 
 |  
				| rettifico c'ho riprovato e stavolta è andata
 il log di avenger è
 
 Logfile of The Avenger version 1, by Swandog46
 Running from registry key:
 \Registry\Machine\System\CurrentControlSet\Services\xnjhgenx
 
 *******************
 
 Script file located at: \??\C:\Documents and Settings\hmlaaihf.txt
 Script file opened successfully.
 
 Script file read successfully
 
 Backups directory opened successfully at C:\Avenger
 
 *******************
 
 Beginning to process script file:
 
 File C:\WINDOWS\Tasks\AFD36DDB91AD1F07.job deleted successfully.
 File c:\docume~1\ivan\datiap~1\dvdlis~1\Tick slow bend.exe deleted successfully.
 
 Completed script processing.
 
 *******************
 
 Finished!  Terminate.
 
 
 il log di hijack invece è
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 19.36.20, on 15/01/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\WINDOWS\system32\VTTimer.exe
 C:\WINDOWS\system32\VTtrayp.exe
 C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\WINDOWS\vsnpstd.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe
 C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
 C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 C:\Programmi\WinZip\WZQKPICK.EXE
 C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 C:\Programmi\Bonjour\mDNSResponder.exe
 C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\slmdmsr.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\HiJackThis\HiJackThis_v2.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ig?hl=it
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\Federica\Desktop\Stef personal files!\rpbrowserrecordplugin.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
 O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
 O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\system32\STDSB.EXE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Kodak EasyShare software.lnk = C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 O4 - Global Startup: Post-it® Software Notes.lnk = C:\Programmi\3M\PSNotes2\Psn2.exe
 O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmi\Bonjour\ExplorerPlugin.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slmdmsr.exe
 
 --
 End of file - 8991 bytes
 
 
 
 grazie ancora..
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 16 Gen 2008 01:03    Oggetto: |   |  
				| 
 |  
				| Il log di hijackthis sembra pulito. Riscontri ancora problemi? 
 Se vuoi, collegati a Kaspersky on-line scanner e fai la scansione estesa, come indicato qui.
 Salva il risultato della scansione in un file (in formato HTML), carica il file su Freefilehosting e posta qui il link che ti viene assegnato.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 18 Gen 2008 19:08    Oggetto: |   |  
				| 
 |  
				| in realtà sì, nel senso che io continuo a non averli più mentre mio padre li ha nella sua identità...e non capisco perchè. Comunque, in questi giorni sono un po' presa per lavoro, appena posso (vist che ho letto che è un procedimento un po' lungo) faccio quello che mi hai detto e speriamo...
 grazie
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 23 Gen 2008 14:30    Oggetto: |   |  
				| 
 |  
				| finalmente ho avuto tempo per farlo! soprattutto perchè ci ha messo un'ora e mezza.. Inutile dire che il problema ce l'ho ancora, sempre e solo nell'identità di mio padre, mentre nella mia il problema è sparito.
 
 Qui il report
 report kaspersky5.html
 
 grazie!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 23 Gen 2008 14:37    Oggetto: |   |  
				| 
 |  
				| Fai una scansione hijackthis e una con combofix dall'identità di tuo padre. 
 Nel log di Kaspersky c'è un virus, ma basta disabilitare il ripristino di sistema per eliminarlo.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| xfaith84 Mortale pio
 
  
 
 Registrato: 06/01/08 14:54
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 23 Gen 2008 16:13    Oggetto: |   |  
				| 
 |  
				| allora... qui c'è il link al report di combofix ComboFix21.txt
 
 e qui c'è il log di hijack
 ---
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 15:03, on 2008-01-23
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 C:\Programmi\Bonjour\mDNSResponder.exe
 C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\slmdmsr.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 C:\Programmi\Windows Live\Messenger\usnsvc.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
 C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\WINDOWS\system32\VTTimer.exe
 C:\WINDOWS\system32\VTtrayp.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\WINDOWS\vsnpstd.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe
 C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe
 C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\WinZip\WZQKPICK.EXE
 C:\PROGRA~1\Grisoft\AVG7\avgw.exe
 C:\WINDOWS\explorer.exe
 C:\HiJackThis\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\Federica\Desktop\Stef personal files!\rpbrowserrecordplugin.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
 O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Programmi\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
 O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\system32\STDSB.EXE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [Audio trans] C:\DOCUME~1\Ivan\DATIAP~1\DVDLIS~1\Title Cash Tray.exe
 O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-21-839522115-179605362-725345543-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Federica')
 O4 - HKUS\S-1-5-21-839522115-179605362-725345543-1004\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe (User 'Federica')
 O4 - HKUS\S-1-5-21-839522115-179605362-725345543-1004\..\Run: [PC Suite Tray] "C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray (User 'Federica')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Kodak EasyShare software.lnk = C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 O4 - Global Startup: Post-it® Software Notes.lnk = C:\Programmi\3M\PSNotes2\Psn2.exe
 O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmi\Bonjour\ExplorerPlugin.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slmdmsr.exe
 
 --
 End of file - 10080 bytes
 
 
 ma per cancellare il virus devo fare come ho fatto per spuntare i file su hijack? (quindi disabilitando il ripristino di sistema e in modalità provvisoria?) poi cancelo il file direttamente dalla sua cartella?
 aiuto...prima o poi lo abbatterò sto dannatissimo cid...
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |