| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 03 Giu 2007 14:41    Oggetto: CID (ingsa) |   |  
				| 
 |  
				|  	  | ingsa ha scritto: |  	  | Ciao, anch'io ho il problema del CiD che rompe!! Però non è successo perchè ho installato msn, cioè msn c'è sul mio pc, ma c'è da sempre ma fino ad ora non è successo nulla. Ho utilizzato l'ultima versione di Hijack ed allego il log:
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 0.58.29, on 03/06/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\PROGRA~1\NORTON~1\navapw32.exe
 C:\Programmi\Java\jre1.6.0\bin\jusched.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\WINDOWS\system32\CAPRPCSK.EXE
 c:\progra~1\intern~1\iexplore.exe
 C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Norton AntiVirus\navapsvc.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 C:\Programmi\FreePOPs\freepopsd.exe
 C:\Programmi\OpenOffice.org 2.2\program\soffice.exe
 C:\Programmi\OpenOffice.org 2.2\program\soffice.BIN
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Java\jre1.6.0\bin\jucheck.exe
 C:\WINDOWS\system32\taskmgr.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\DAP\DAP.EXE
 C:\PROGRA~1\WINZIP\winzip32.exe
 C:\Documents and Settings\Leo\Impostazioni locali\Temp\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Programmi\Power Translator\Applications\LEC IE Translation Extension.dll
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
 O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAPONN.EXE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0\bin\jusched.exe"
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [PowerTranslator Pro OLR] C:\PROGRA~1\BVRPSO~1\POWERT~1\BVRPOlr.exe /PowerTranslator Pro
 O4 - HKLM\..\Run: [Skipacidpeakinfo] C:\Documents and Settings\All Users\Dati applicazioni\PopCloseSkipAcid\464.exe
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [settings dog] C:\DOCUME~1\Leo\DATIAP~1\CREATI~1\warnvcmess.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: FreePOPs.lnk = C:\Programmi\FreePOPs\freepopsd.exe
 O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmi\OpenOffice.org 2.2\program\quickstart.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: canon.lnk = C:\Documents and Settings\Leo\Documenti\Driver\The Printer Angel\BJC - The Printer Angel\canon.exe
 O4 - Global Startup: Finestra di stato di Canon LBP-810.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office2\Office10\OSA.EXE
 O8 - Extra context menu item: &Clean Traces - C:\Programmi\DAP\Privacy Package\dapcleanerie.htm
 O8 - Extra context menu item: &Download with &DAP - C:\Programmi\DAP\dapextie.htm
 O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
 O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
 O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Download &all with DAP - C:\Programmi\DAP\dapextie2.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {CB0EEA65-ACBA-477A-A169-10540F204AD7} (PriMusX Control) - file://E:\Prezzari_d_Italia\PriMus-DCFSetup.exe
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
 O23 - Service: Servizio Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Programmi\Norton AntiVirus\navapsvc.exe
 O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
 
 --
 End of file - 9653 bytes
 
 Grazie per l'aiuto!!!
 | 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 03 Giu 2007 14:47    Oggetto: |   |  
				| 
 |  
				| Hijackthis va avviato da una sua cartella non temporanea e non sul desktop. Avvia il pc in modalità provvisoria,
 avvia hjt
 clicca su do a system scan only
 metti il segno di spunta a queste voci:
 
  	  | Citazione: |  	  | O4 - HKLM\..\Run: [Skipacidpeakinfo] C:\Documents and Settings\All Users\Dati applicazioni\PopCloseSkipAcid\464.exe O4 - HKCU\..\Run: [settings dog] C:\DOCUME~1\Leo\DATIAP~1\CREATI~1\warnvcmess.exe
 | 
 clicca su fix checked
 
 Trova ed elimina i seguenti files:
 
  	  | Citazione: |  	  | C:\Documents and Settings\All Users\Dati applicazioni\PopCloseSkipAcid\464.exe C:\Documents and Settings\Leo\Dati applicazioni\CREATI(qualcosa)\warnvcmess.exe
 | 
 riavvia il pc e rifai il log con hjt
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ingsa Eroe
 
  
 
 Registrato: 03/06/07 01:02
 Messaggi: 62
 
 
 | 
			
				|  Inviato: 04 Giu 2007 09:48    Oggetto: |   |  
				| 
 |  
				| Ciao, innanzi tutto grazie per l'aiuto! Poi, ho fatto come mi hai detto, cioè ho trasferito hjt in una cartella non temporanea e non sul desktop; poi ho avviato il pc in modalità provvisoria dopo aver disattivato il ripristino configurazione del sistema (giusto?) ed ho avviato hjt. Però nello spuntare i due files che mi hai detto, non ho trovato il secondo:
 O4 - HKCU\..\Run: [settings dog] C:\DOCUME~1\Leo\DATIAP~1\CREATI~1\warnvcmess.exe
 però l'ho cancellato dalla cartella in cui si trovava.
 Ho riavviato il pc e poi ho rifatto il log che ti allego:
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 9.45.45, on 04/06/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\Programmi\Java\jre1.6.0\bin\jusched.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\Programmi\FreePOPs\freepopsd.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 C:\Programmi\OpenOffice.org 2.2\program\soffice.exe
 C:\WINDOWS\system32\CAPRPCSK.EXE
 C:\Programmi\OpenOffice.org 2.2\program\soffice.BIN
 C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Documents and Settings\Leo\Documenti\Programmini\HiJackThis_v2.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Java\jre1.6.0\bin\jucheck.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Programmi\Power Translator\Applications\LEC IE Translation Extension.dll
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAPONN.EXE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0\bin\jusched.exe"
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [PowerTranslator Pro OLR] C:\PROGRA~1\BVRPSO~1\POWERT~1\BVRPOlr.exe /PowerTranslator Pro
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [settings dog] C:\DOCUME~1\Leo\DATIAP~1\CREATI~1\warnvcmess.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: FreePOPs.lnk = C:\Programmi\FreePOPs\freepopsd.exe
 O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmi\OpenOffice.org 2.2\program\quickstart.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: canon.lnk = C:\Documents and Settings\Leo\Documenti\Driver\The Printer Angel\BJC - The Printer Angel\canon.exe
 O4 - Global Startup: Finestra di stato di Canon LBP-810.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office2\Office10\OSA.EXE
 O8 - Extra context menu item: &Clean Traces - C:\Programmi\DAP\Privacy Package\dapcleanerie.htm
 O8 - Extra context menu item: &Download with &DAP - C:\Programmi\DAP\dapextie.htm
 O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
 O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
 O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Download &all with DAP - C:\Programmi\DAP\dapextie2.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {CB0EEA65-ACBA-477A-A169-10540F204AD7} (PriMusX Control) - file://E:\Prezzari_d_Italia\PriMus-DCFSetup.exe
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
 O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
 
 --
 End of file - 8698 bytes
 
 
 come vedi c'è sempre quel file: quindi?
 Per ora non è uscito nessun CiD ma, che faccio se esce di nuovo?
 
 Comunque grazie ancora dell'aiuto, non pensavo di trovare qualcuno in internet che potesse dare una mano in queste cose!!
 Grazie ancora e buon lavoro!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 04 Giu 2007 10:08    Oggetto: |   |  
				| 
 |  
				| ciao ingsa   
 se le voci non sono presenti in modalità provvisoria vanno fissati in quella normale.
 
 riprova ad eliminare O4 - HKCU\..\Run: [settings dog] C:\DOCUME~1\Leo\DATIAP~1\CREATI~1\warnvcmess.exe
 
 le soluzioni sono due: o metti qui il tuo log HJT, o cerchi da sola di eliminarlo: di solito nel log HJT si trova in posizione O4--**\Run:[nome strano]. 	  | Citazione: |  	  | Per ora non è uscito nessun CiD ma, che faccio se esce di nuovo? | 
 il file si trova in posizione C:\Documents and settings. il nome è variabile...
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| ingsa Eroe
 
  
 
 Registrato: 03/06/07 01:02
 Messaggi: 62
 
 
 | 
			
				|  Inviato: 04 Giu 2007 10:13    Oggetto: |   |  
				| 
 |  
				| Ok, grazie ancora! L'ho tolto in modalità normale e ti posto il log
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 10.12.02, on 04/06/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\Programmi\Java\jre1.6.0\bin\jusched.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\Programmi\FreePOPs\freepopsd.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 C:\Programmi\OpenOffice.org 2.2\program\soffice.exe
 C:\WINDOWS\system32\CAPRPCSK.EXE
 C:\Programmi\OpenOffice.org 2.2\program\soffice.BIN
 C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Java\jre1.6.0\bin\jucheck.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Outlook Express\msimn.exe
 C:\Documents and Settings\Leo\Documenti\Programmini\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
 O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Programmi\Power Translator\Applications\LEC IE Translation Extension.dll
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAPONN.EXE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0\bin\jusched.exe"
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [PowerTranslator Pro OLR] C:\PROGRA~1\BVRPSO~1\POWERT~1\BVRPOlr.exe /PowerTranslator Pro
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: FreePOPs.lnk = C:\Programmi\FreePOPs\freepopsd.exe
 O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmi\OpenOffice.org 2.2\program\quickstart.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: canon.lnk = C:\Documents and Settings\Leo\Documenti\Driver\The Printer Angel\BJC - The Printer Angel\canon.exe
 O4 - Global Startup: Finestra di stato di Canon LBP-810.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office2\Office10\OSA.EXE
 O8 - Extra context menu item: &Clean Traces - C:\Programmi\DAP\Privacy Package\dapcleanerie.htm
 O8 - Extra context menu item: &Download with &DAP - C:\Programmi\DAP\dapextie.htm
 O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
 O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
 O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Download &all with DAP - C:\Programmi\DAP\dapextie2.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {CB0EEA65-ACBA-477A-A169-10540F204AD7} (PriMusX Control) - file://E:\Prezzari_d_Italia\PriMus-DCFSetup.exe
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
 O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
 
 --
 End of file - 8701 bytes
 
 Grazie ancora!!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 04 Giu 2007 12:50    Oggetto: |   |  
				| 
 |  
				| Ora sembra tutto ok. Rilevi altri problemi?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ingsa Eroe
 
  
 
 Registrato: 03/06/07 01:02
 Messaggi: 62
 
 
 | 
			
				|  Inviato: 04 Giu 2007 12:55    Oggetto: |   |  
				| 
 |  
				| Per ora nulla, sono in internet da un bel po' ormai e non è uscito nessun CiD.... Grazie ancora...il solo pensiero che, per risolvere il problema, avrei dovuto portare il pc in assistenza per rimanerne senza per giorni mi faceva venire l'angoscia! Ma grazie al vostro aiuto ho risolto senza problemi!
 Grazie ancora e buon lavoro!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |