serte Mortale pio
  
 
  Registrato: 15/06/08 21:58 Messaggi: 27
 
  | 
		
			
				 Inviato: 24 Mar 2009 13:35    Oggetto: non funzionano antivirus e antispyware | 
				     | 
			 
			
				
  | 
			 
			
				AIUTISSIMO!!!! Sul mio pc XP SP3 ho inavventatamente aperto un file scaricato da emule senza prima controllarlo ed è successo di tutto: prima avast mi ha avvisato che qualche programma cercava di disattivarlo, e, ovviamente gli ho confermato di non proseguire. A quel punto il pc si è resettato ed è ripartito disattivando completamente avast e zone alarm, in più i vari programmi tipo hijackthis, cwshredder e runscanner non partono più (sono riuscito ad usare hijackthis da una chiavetta e vi allego il file, ma sembra pulito). Ho provato ad installare software come spybot search&destroy, sopho rootkit, ma dopo l'installazione l'eseguibile non parte avvisandomi che si tratta di un'applicazione win32 non valida.
 
Aggiungo che non mi è possibile accedere alla m odalità provvisoria in quanto un avviso su sfondo blu mi dice che il computer è stato bloccato per evitare danni, e, ovviamente, non mi funziona il ripristino configurazione.
 
Insomma sono nei guai fino al collo.Vi prego aiutatemi 
 
 
 
 
Logfile of Trend Micro HijackThis v2.0.2
 
Scan saved at 10.51.34, on 24/03/2009
 
Platform: Windows XP SP3 (WinNT 5.01.2600)
 
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
 
Boot mode: Normal
 
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
 
C:\WINDOWS\system32\winlogon.exe
 
C:\WINDOWS\system32\services.exe
 
C:\WINDOWS\system32\lsass.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\WINDOWS\system32\brsvc01a.exe
 
C:\WINDOWS\system32\spoolsv.exe
 
C:\WINDOWS\system32\brss01a.exe
 
C:\Programmi\Keymaestro\Multimedia Keyboard\nhksrv.exe
 
C:\Programmi\Java\jre6\bin\jqs.exe
 
C:\Programmi\McAfee\SiteAdvisor\McSACore.exe
 
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exe
 
C:\Programmi\CDBurnerXP\NMSAccessU.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\TomTom HOME 2\TomTomHOMEService.exe
 
C:\WINDOWS\Explorer.EXE
 
C:\WINDOWS\RTHDCPL.EXE
 
C:\WINDOWS\ZSSnp211.exe
 
C:\WINDOWS\Domino.exe
 
C:\Programmi\Spamihilator\spamihilator.exe
 
C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe
 
C:\Programmi\TechSmith\SnagIt 9\SnagIt32.exe
 
C:\Programmi\TechSmith\SnagIt 9\TSCHelp.exe
 
C:\Programmi\TechSmith\SnagIt 9\SnagPriv.exe
 
C:\Programmi\TechSmith\SnagIt 9\snagiteditor.exe
 
C:\WINDOWS\Explorer.EXE
 
D:\HijackThis (ESEGUIRE COME AMMINISTRATORE).exe
 
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgilio.it/
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 
R3 - URLSearchHook: ITALIA version Toolbar - {323d5e65-9ec7-481e-a888-5bbe30b80dfb} - C:\Programmi\ITALIA_version\tbITAL.dll
 
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programmi\TechSmith\SnagIt 9\SnagItBHO.dll
 
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
 
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
 
O2 - BHO: ITALIA version Toolbar - {323d5e65-9ec7-481e-a888-5bbe30b80dfb} - C:\Programmi\ITALIA_version\tbITAL.dll
 
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
 
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar.dll
 
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
 
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
 
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmi\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll
 
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
 
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
 
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Programmi\Power Translator\Applications\LEC IE Translation Extension.dll
 
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programmi\TechSmith\SnagIt 9\SnagItIEAddin.dll
 
O3 - Toolbar: TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL
 
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar.dll
 
O3 - Toolbar: ITALIA version Toolbar - {323d5e65-9ec7-481e-a888-5bbe30b80dfb} - C:\Programmi\ITALIA_version\tbITAL.dll
 
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
 
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 
O4 - HKLM\..\Run: [SetDefPrt] C:\Programmi\Brother\Brmfl05a\BrStDvPt.exe
 
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
 
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
 
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
 
O4 - HKLM\..\Run: [Spamihilator] "C:\Programmi\Spamihilator\spamihilator.exe"
 
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programmi\Unlocker\UnlockerAssistant.exe"
 
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
 
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
 
O4 - HKCU\..\Run: [Power Translator 9] C:\Programmi\Power Translator\Applications\Power Translator 9.exe
 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 
O4 - Global Startup: SnagIt 9.lnk = C:\Programmi\TechSmith\SnagIt 9\SnagIt32.exe
 
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
 
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
 
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Programmi\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll
 
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
 
O23 - Service: Servizio di Google Update (gupdate1c9a08def7bc54e) (gupdate1c9a08def7bc54e) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
 
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
 
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Programmi\Power Translator\LogoMedia TranslateDotNet Server.exe
 
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Programmi\McAfee\SiteAdvisor\McSACore.exe
 
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
 
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programmi\Keymaestro\Multimedia Keyboard\nhksrv.exe
 
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 
O23 - Service: NMSAccessU - Unknown owner - C:\Programmi\CDBurnerXP\NMSAccessU.exe
 
O23 - Service: TomTomHOMEService - TomTom - C:\Programmi\TomTom HOME 2\TomTomHOMEService.exe
 
 
--
 
End of file - 8649 bytes | 
			 
		  |