| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| tommy83 Comune mortale
 
  
 
 Registrato: 05/07/07 10:42
 Messaggi: 1
 
 
 | 
			
				|  Inviato: 05 Lug 2007 10:50    Oggetto: |   |  
				| 
 |  
				| Qualcuno mi aiuta?ho lo stesso problema, quando navigo in IE mi escono finestrelle popup anche se ho il blocco... 
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 10.47.51, on 05/07/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 C:\WINDOWS\system32\spoolsv.exe
 c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
 C:\WINDOWS\system32\RUNDLL32.EXE
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
 C:\PROGRA~1\LAUNCH~1\LManager.exe
 C:\WINDOWS\system32\LVCOMSX.EXE
 c:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
 C:\Programmi\Acer\OrbiCam\CameraAssistant.exe
 C:\Programmi\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
 C:\WINDOWS\system32\ElkCtrl.exe
 C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
 C:\Programmi\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
 C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
 C:\Programmi\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
 C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
 C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
 C:\Programmi\iTunes\iTunesHelper.exe
 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
 C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\Programmi\WinPop\winpop.exe
 C:\PROGRA~1\FILECO~1\PCSuite\Services\SERVIC~1.EXE
 C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
 C:\Programmi\WIDCOMM\Bluetooth Software\BTTray.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
 C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
 C:\Programmi\CyberLink\Shared Files\RichVideo.exe
 C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Acer\Acer Arcade\Kernel\TV\CLSched.exe
 C:\Programmi\Canon\CAL\CALMAIN.exe
 C:\Programmi\iPod\bin\iPodService.exe
 C:\WINDOWS\system32\wbem\wmiapsrv.exe
 C:\WINDOWS\system32\wbem\unsecapp.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\MSN Messenger\msnmsgr.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Documents and Settings\Amministratore\Desktop\HiJackThis_v2\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [ntiMUI] C:\Programmi\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
 O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
 O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
 O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programmi\Acer\OrbiCam\CameraAssistant.exe
 O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
 O4 - HKLM\..\Run: [ImageItEncrypt] C:\WINDOWS\system32\ImageItEncrypt.exe
 O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
 O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
 O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
 O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu420.exe 61A847B5BBF72816309B284503996897C881250221C8670836AC4FA7C8833201749139
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [WinPop] C:\Programmi\WinPop\winpop.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Acer Empowering Technology.lnk = ?
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Invia a periferica &Bluetooth... - c:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com.ezproxy1.lib.asu.edu/lib/asulib/support/plugins/ebraryRdr.cab
 O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://tommy83tommy.spaces.live.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
 O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmi\Canon\CAL\CALMAIN.exe
 O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Programmi\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
 O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Programmi\Acer\Acer Arcade\Kernel\TV\CLSched.exe
 O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmi\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
 O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
 O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
 O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
 O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared Files\RichVideo.exe
 O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Programmi\WinPcap\rpcapd.exe
 O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 
 --
 End of file - 11483 bytes
 
 
 
 Symantec Trojan.Vundo Removal Tool 1.5.0
 The process "iexplore.exe" might be affected by the threat. It has been suspended.
 The process "iexplore.exe" might be affected by the threat. It has been suspended.
 The process "iexplore.exe" might be affected by the threat. It has been terminated.
 The process "iexplore.exe" might be affected by the threat. It has been terminated.
 |  |  
		| Top |  |  
		|  |  
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 05 Lug 2007 14:23    Oggetto: |   |  
				| 
 |  
				| ciao tommy83, benvenuto   
 disattiva il ripristino e avvia in mod. provvisoria
 avvi HiJack, seleziona "Do a system scan only", metti la spunta alle voci indicate e premi "Fix checked":
 
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu420.exe 61A847B5BBF72816309B284503996897C881250221C8670836AC4FA7C8833201749139
 O4 - HKCU\..\Run: [WinPop] C:\Programmi\WinPop\winpop.exe
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com.ezproxy1.lib.asu.edu/lib/asulib/support/plugins/ebraryRdr .cab
 
 trova e cancella: C:\WINDOWS\retadpu420.exe  e C:\Programmi\WinPop\winpop.exe
 
 dai un'occhiata anche al registro:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Run ed elimina il valore WinPop C:\Programmi\WinPop\winpop.exe
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ed elimina runner1 C:\WINDOWS\retadpu420.exe
 
 rifai il log e mettilo qui per un controllo
 |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |