| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| fpieropan Comune mortale
 
  
 
 Registrato: 07/08/10 14:11
 Messaggi: 1
 
 
 | 
			
				|  Inviato: 07 Ago 2010 14:19    Oggetto: nod32 mi dice l'indirizzo è stato bloccato |   |  
				| 
 |  
				| ciao a tutti,ho letto cosa è stato scritto all'altro utente e ho usato hijackthis e questo è cio che mi è venuto fuori.vi premetto che di cmputer so veramente poco.mi affido a voi,grazie 
 Logfile of Trend Micro HijackThis v2.0.4
 Scan saved at 14.08.55, on 07/08/2010
 Platform: Windows XP SP3 (WinNT 5.01.2600)
 MSIE: Internet Explorer v8.00 (8.00.6001.18702)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\AVG\AVG9\avgchsvx.exe
 C:\Programmi\AVG\AVG9\avgrsx.exe
 C:\Programmi\AVG\AVG9\avgcsrvx.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\WINDOWS\RTHDCPL.EXE
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\WINDOWS\system32\TPSMain.exe
 C:\Programmi\TOSHIBA\ConfigFree\NDSTray.exe
 C:\WINDOWS\system32\igfxsrvc.exe
 C:\Programmi\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
 C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
 C:\Programmi\TOSHIBA\ConfigFree\CFSServ.exe
 C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
 C:\Programmi\File comuni\Java\Java Update\jusched.exe
 C:\PROGRA~1\AVG\AVG9\avgtray.exe
 C:\Programmi\ESET\ESET NOD32 Antivirus\egui.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 C:\WINDOWS\system32\TPSBattM.exe
 C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
 C:\Programmi\Skype\Phone\Skype.exe
 C:\Documents and Settings\OCCIONI\Dati applicazioni\Dropbox\bin\Dropbox.exe
 C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
 C:\WINDOWS\system32\agrsmsvc.exe
 C:\Programmi\AVG\AVG9\avgwdsvc.exe
 C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe
 C:\Programmi\AVG\AVG9\avgnsx.exe
 C:\Programmi\Java\jre6\bin\jqs.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exe
 C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
 C:\WINDOWS\system32\TODDSrv.exe
 C:\WINDOWS\system32\wbem\wmiapsrv.exe
 C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
 C:\Programmi\File comuni\Java\Java Update\jucheck.exe
 C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\OCCIONI\Documenti\Downloads\HiJackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = homepage.cab.unipd.it/proxy/proxy.pac
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programmi\AVG\AVG9\Toolbar\IEToolbar.dll
 O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG9\avgssie.dll
 O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmi\Microsoft Office\Office12\GrooveShellExtensions.dll
 O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programmi\AVG\AVG9\Toolbar\IEToolbar.dll
 O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
 O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
 O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
 O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Programmi\AVG\AVG9\Toolbar\IEToolbar.dll
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
 O4 - HKLM\..\Run: [DDWMon] C:\Programmi\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [topi] C:\Programmi\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
 O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
 O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [egui] "C:\Programmi\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
 O4 - HKCU\..\Run: [{7E568A94-BE8F-4EA8-FFB2-F578DC6E80E8}] "C:\Documents and Settings\OCCIONI\Dati applicazioni\Ahic\abepl.exe"
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: Dropbox.lnk = C:\Documents and Settings\OCCIONI\Dati applicazioni\Dropbox\bin\Dropbox.exe
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
 O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
 O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
 O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223749219531
 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1223748019859
 O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
 O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
 O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Programmi\AVG\AVG9\Toolbar\IEToolbar.dll
 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmi\Microsoft Office\Office12\GrooveSystemServices.dll
 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG9\avgpp.dll
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
 O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Programmi\AVG\AVG9\Toolbar\ToolbarBroker.exe
 O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG9\avgwdsvc.exe
 O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Programmi\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
 O23 - Service: ESET Service (ekrn) - ESET - C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe
 O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
 O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Programmi\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
 O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe
 
 --
 End of file - 11237 bytes
 |  |  
		| Top |  |  
		|  |  
		| R16 Dio maturo
 
  
  
 Registrato: 07/03/08 22:58
 Messaggi: 10129
 
 
 | 
			
				|  Inviato: 07 Ago 2010 14:30    Oggetto: Re: nod32 mi dice l'indirizzo è stato bloccato |   |  
				| 
 |  
				|  	  | fpieropan ha scritto: |  	  | ciao a tutti,ho letto cosa è stato scritto all'altro utente e ho usato hijackthis e questo è cio che mi è venuto fuori.vi premetto che di cmputer so veramente poco.mi affido a voi,grazie 
 | 
 
 Ciao fpieropan, e benvenuto.
   Non è permesso accodarsi ad altre discussioni.
 Apri un topic tutto tuo, e spiega meglio che puoi il problema.
 Questo consentirà di seguirti meglio, per risolvere il problema.
 Ciao!
 
 edit by bdoriano: ho splittato la discussione.
  |  |  
		| Top |  |  
		|  |  
		| R16 Dio maturo
 
  
  
 Registrato: 07/03/08 22:58
 Messaggi: 10129
 
 
 | 
			
				|  Inviato: 07 Ago 2010 15:03    Oggetto: |   |  
				| 
 |  
				| Ciao. 
 Disistalla 1 dei 2 antivirus che hai installato:
 NOD32
 AVG9
 
 Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked
 
  	  | Citazione: |  	  | O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [topi] C:\Programmi\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
 O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\OCCIONI\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
 O4 - HKCU\..\Run: [{7E568A94-BE8F-4EA8-FFB2-F578DC6E80E8}] "C:\Documents and Settings\OCCIONI\Dati applicazioni\Ahic\abepl.exe"
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
 O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.
 O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
 | 
 
 Pulisci i files temporanei con CCleaner (registro compreso)
 http://forum.zeusnews.com/viewtopic.php?p=282670#282670
 
 Segui le istruzioni di questo topic per eliminare gli ADS:
 http://forum.zeusnews.com/viewtopic.php?t=45223
 
 Scarica e installa la versione Free di SuperAntispyware:
 link
 lo configuri come da immagini :
 http://www.zeusnews.it/zz_upload/img/PSV/SAS/7477731.jpg
 http://www.zeusnews.it/zz_upload/img/PSV/SAS/9926902.jpg
 Esegui una scansione completa.
 
 Segui le istruzioni di questo topic per usare MBAM:
 http://forum.zeusnews.com/viewtopic.php?p=297823#297823
 Esegui una scansione completa.
 Elimina gli eventuali file infetti trovati.
 
 Carica i log di SuperAntispyware, MBAM, su WikiSend (o FreeFileHosting) e posta il Forum Link che ti viene assegnato.
 link
 |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |