| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| sandrino Mortale pio
 
  
 
 Registrato: 30/03/07 21:56
 Messaggi: 28
 
 
 | 
			
				|  Inviato: 12 Apr 2007 15:15    Oggetto: Finestre explorer Cid |   |  
				| 
 |  
				| Scusate ragazzi...ops...Dei... qualche settimana fà avevo richiesto un aiuto per delle finestre explorer che rompono le p... aprendosi quando vogliono...pensavo di aver risolto ma purtroppo mi fanno ancora compagnia...
 Allego il log di hijacket...
 
 Logfile of HijackThis v1.99.1
 Scan saved at 15.08.10, on 12/04/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Programmi\IPM\Adsl\DataWay\dslstat.exe
 C:\WINDOWS\system32\dslagent.exe
 C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\WINDOWS\system32\slserv.exe
 C:\Programmi\Sygate\SPF\smc.exe
 C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 c:\progra~1\intern~1\iexplore.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\eMule\eMule.exe
 C:\Programmi\Hijackthis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
 O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
 O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [DSLSTATEXE] C:\Programmi\IPM\Adsl\DataWay\dslstat.exe icon
 O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
 O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [windowbits] C:\DOCUME~1\Sandrino\DATIAP~1\SECOND~1\tool axis.exe
 O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FEBD3A4C-542B-4DDC-BF1D-87D0BAF13258}: NameServer = 85.37.17.49 85.38.28.91
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
 O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 
 Grazie
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 12 Apr 2007 18:47    Oggetto: |   |  
				| 
 |  
				| ciao! con Hijack fissa questa voce
 O4 - HKCU\..\Run: [windowbits] C:\DOCUME~1\Sandrino\DATIAP~1\SECOND~1\tool axis.exe
 
 trova e elimina la cartella
 C:\DOCUME~1\Sandrino\DATIAP~1\SECOND~1\tool axis.exe
 
 dai una ripulita con CCleaner e dovresti essere a posto
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| sandrino Mortale pio
 
  
 
 Registrato: 30/03/07 21:56
 Messaggi: 28
 
 
 | 
			
				|  Inviato: 13 Apr 2007 15:23    Oggetto: |   |  
				| 
 |  
				| Grazie...ora ci provo...vado in modalità provissoria a fare questo lavoro? |  | 
	
		| Top |  | 
	
		|  | 
	
		| chemicalbit Dio maturo
 
  
  
 Registrato: 01/04/05 18:59
 Messaggi: 18597
 Residenza: Milano
 
 | 
			
				|  Inviato: 13 Apr 2007 16:05    Oggetto: |   |  
				| 
 |  
				| Sì, per fixaare con HijackThis, da modalità provvisoria |  | 
	
		| Top |  | 
	
		|  | 
	
		| Damelli Comune mortale
 
  
 
 Registrato: 02/05/07 12:32
 Messaggi: 1
 
 
 | 
			
				|  Inviato: 02 Mag 2007 12:34    Oggetto: |   |  
				| 
 |  
				| Salve, anke io ho il solito problema.. Potete perfavore darmi una mano... Grazie.. 
 Logfile of HijackThis v1.99.1
 Scan saved at 12.27.40, on 02/05/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.5700.0006)
 
 Running processes:
 D:\WINDOWS\System32\smss.exe
 D:\WINDOWS\system32\winlogon.exe
 D:\WINDOWS\system32\services.exe
 D:\WINDOWS\system32\lsass.exe
 D:\WINDOWS\system32\Ati2evxx.exe
 D:\WINDOWS\system32\svchost.exe
 D:\WINDOWS\System32\svchost.exe
 D:\WINDOWS\system32\Ati2evxx.exe
 D:\WINDOWS\system32\spoolsv.exe
 D:\Programmi\Belkin\Software Bluetooth\bin\btwdins.exe
 D:\Programmi\Eset\nod32krn.exe
 D:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 D:\WINDOWS\system32\svchost.exe
 D:\WINDOWS\system32\wscntfy.exe
 D:\WINDOWS\Explorer.EXE
 D:\Programmi\Eset\nod32kui.exe
 D:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
 D:\WINDOWS\system32\RunDll32.exe
 D:\Programmi\Game Accelerator\gamexl.exe
 D:\Programmi\Microsoft IntelliType Pro\type32.exe
 D:\Programmi\Microsoft IntelliPoint\point32.exe
 D:\Programmi\MSN Messenger\MsnMsgr.Exe
 D:\WINDOWS\system32\ctfmon.exe
 D:\Programmi\ICQ6\ICQ.exe
 D:\Programmi\Belkin\Software Bluetooth\BTTray.exe
 D:\Programmi\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
 D:\Programmi\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about-blank.in
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O1 - Hosts: 193.203.227.71 www.betandwin.com
 O1 - Hosts: 195.72.134.100 www.bwin.com
 O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
 O4 - HKLM\..\Run: [nod32kui] "D:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [GameXL] "D:\Programmi\Game Accelerator\gamexl.exe"
 O4 - HKLM\..\Run: [type32] "D:\Programmi\Microsoft IntelliType Pro\type32.exe"
 O4 - HKLM\..\Run: [IntelliPoint] "D:\Programmi\Microsoft IntelliPoint\point32.exe"
 O4 - HKLM\..\Run: [Google Desktop Search] "D:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe" /startup
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKLM\..\Run: [InfoData] rundll32.exe "D:\WINDOWS\system32\pjbmdvmc.dll",realset
 O4 - HKCU\..\Run: [msnmsgr] "D:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [ICQ] "D:\Programmi\ICQ6\ICQ.exe" silent
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: hp psc 1000 series.lnk = ?
 O4 - Global Startup: hpoddt01.exe.lnk = ?
 O4 - Global Startup: Messenger Power Live 9.lnk = D:\Programmi\MSN Messenger\msngserv.exe
 O4 - Global Startup: Microsoft Office.lnk = D:\Programmi\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: (no name) - {85e1f530-48f4-11d9-9629-08ff2ffc9f67} - (no file)
 O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmi\Belkin\Software Bluetooth\btsendto_ie.htm
 O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmi\Belkin\Software Bluetooth\btsendto_ie.htm
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Programmi\ICQ6\ICQ.exe
 O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Programmi\ICQ6\ICQ.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O20 - AppInit_DLLs: D:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: Adobe LM Service - Adobe Systems - D:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Programmi\Belkin\Software Bluetooth\bin\btwdins.exe
 O23 - Service: GoogleDesktopManager - Google - D:\Programmi\Google\Google Desktop Search\GoogleDesktopManager.exe
 O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - D:\Programmi\Eset\nod32krn.exe
 O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 02 Mag 2007 12:47    Oggetto: |   |  
				| 
 |  
				| ciao, Damelli e benvenuto sull'Olimpo!   non è proprio lo stesso il tuo problema....
 
 scarica questo tool
 avvialo, seleziona Scan for Vundo. alla fine della scansione clicca Remove Vundo.
 
 disattiva il ripristino di configurazione del sistema
 avvia in modalità provvisoria
 avvia HiJack seleziona "Do a system scan only", metti la spunta a queste voci e premi "Fix checked" (i primi due solo se non li hai messi tu!)
 
 O1 - Hosts: 193.203.227.71 www.betandwin.com
 O1 - Hosts: 195.72.134.100 www.bwin.com
 O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
 O4 - HKLM\..\Run: [InfoData] rundll32.exe "D:\WINDOWS\system32\pjbmdvmc.dll",realset
 O9 - Extra button: (no name) - {85e1f530-48f4-11d9-9629-08ff2ffc9f67} - (no file)
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 
 posta qui il log del tool e uno aggiornato di HiJack
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |