Visualizzazione dei risultati da 1 a 7 su 7
  1. #1

    Popup

    Salve ho un problema di popup vi posto un log di hijackthis

    codice:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16.17.51, on 13/02/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Safe mode with network support
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://g.live.com/9uxp9en-us/hpg_lnk2
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [AzMixerSel] C:\Programmi\Realtek\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [INPROCOMMWireless] C:\Programmi\Atheros\Wireless\Utility\WlanUtil.exe
    O4 - HKLM\..\Run: [BroadcomWireless] C:\Programmi\Broadcom\Wireless\Utility\WlanUtil.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\WINDOWS\TEMP\E_SF5.tmp" /EF "HKCU"
    O4 - HKCU\..\Run: [kqocyki] "c:\documents and settings\marino\impostazioni locali\dati applicazioni\kqocyki.exe" kqocyki
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
    O4 - Global Startup: BTTray.lnk = ?
    O8 - Extra context menu item: &Google Search - res://C:\Programmi\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Collegamenti a ritroso - res://C:\Programmi\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Pagine simili - res://C:\Programmi\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Versione cache della pagina - res://C:\Programmi\Google\GoogleToolbar1.dll/cmcache.html
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared files\RichVideo.exe
    
    --
    End of file - 5797 bytes

  2. #2
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    ciao scottied...
    scarica navilog1.exe_il mafioso

    Riavvia il computer in modalità provvisoria: all'avvio del pc, prima che inizi a caricare Windows, premi ripetutamente F8. Uscirà la finestra del menu Opzioni avanzate di Windows => scegli modalità provvisoria (usa il tasto freccia ^).
    Esegui Navilog1 e scegli l'opzione 2 (Automatic Cleaning) e dai l'ok (eseguirà la pulizia dei files infetti trovati)
    Quando finisce, riavvia il pc in modalità normale

    Svuota C:\WINDOWS\Prefetch
    Ripulisci con CCleaner i file temporanei e cookie (eseguilo 2 volte).

    stesso da modalità normale, riesegui navilog1 (scegli opzione 1) e posta il rapporto
    ...
    :x:_::_:*:_::_: )(:_:*:_:*:__::_:°FM°:_: )(:_:*:_:x:___

  3. #3
    Ciao ho fatto tutto quello che mi hai detto.
    Ecco il rapporto:

    codice:
    Search Navipromo version 3.7.3 began on 16/02/2009 at 12.18.19,31
    
    !!! Warning, this report may include legitimate files/programs !!!
    !!! Post this report on the forum you are being helped !!!
    !!! Don't continue with removal unless instructed by an authorized helper !!!
    
    Fix running from C:\Programmi\navilog1
    
    Updated on 13.02.2009 at 18h00 by IL-MAFIOSO
    
    Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 X2 Mobile Technology TL-50 )
    BIOS : Ver 1.00PARTTBL
    USER : Marino ( Administrator )
    BOOT : Normal boot
    
    Antivirus : avast! antivirus 4.8.1335 [VPS 090213-0] 4.8.1335 (Activated)
    
    
    C:\ (Local Disk) - NTFS - Total:44 Go (Free:35 Go)
    D:\ (Local Disk) - FAT32 - Total:44 Go (Free:37 Go)
    E:\ (CD or DVD)
    
    
    Search done in normal mode
    
    *** Searching for installed Software ***
    
    
    *** Search folders in "C:\WINDOWS" ***
    
    
    *** Search folders in "C:\Programmi" ***
    
    
    *** Search folders in "C:\Documents and Settings\All Users\menuav~1\progra~1" ***
    
    
    *** Search folders in "C:\Documents and Settings\All Users\menuav~1" ***
    
    
    *** Search folders in "c:\docume~1\alluse~1\datiap~1" ***
    
    
    *** Search folders in "C:\Documents and Settings\Marino\datiap~1" *** 
    
    
    *** Search folders in "C:\Documents and Settings\Marino\impost~1\datiap~1" *** 
    
    
    *** Search folders in "C:\Documents and Settings\Marino\menuav~1\progra~1" *** 
    
    
    *** Search with GenericNaviSearch ***
    !!! Possibility of legitimate files in the result !!!
    !!! Must always be checked before manually deleting !!!
    
    * Scan in "C:\WINDOWS\system32" *
    
    * Scan in "C:\Documents and Settings\Marino\impost~1\datiap~1" * 
    
    
    
    *** Search files *** 
    
    
    
    *** Search specific Registry keys ***
    !! Following keys are not certainly all infected !!
    
    
    *** Complementary Search ***
    (Search specific files)
    
    1)Search new Instant Access files :
    
    
    2)Heuristic Search :
    
    * In "C:\WINDOWS\system32" :
    
    
    * In "C:\Documents and Settings\Marino\impost~1\datiap~1" : 
    
    
    3)Certificates Search :
    
    Egroup certificate not found !
    Electronic-Group certificate not found !
    Montorgueil certificate not found !
    OOO-Favorit certificate not found !
    Sunny-Day-Design-Ltd certificate not found !
    
    4)Search others known folders and files :
    
    
    
    *** Search completed on 16/02/2009 at 12.19.15,00 ***

  4. #4
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    bene, non dovrebbero esserci più problemi.
    il pc come va?
    ...
    :x:_::_:*:_::_: )(:_:*:_:*:__::_:°FM°:_: )(:_:*:_:x:___

  5. #5
    Effettivamente bene!!
    :-D

  6. #6
    Ciao Deifobe.
    Mi controlleresti anche questo log?

    codice:
    Search Navipromo version 3.7.3 began on 16/02/2009 at 17.22.50,17
    
    !!! Warning, this report may include legitimate files/programs !!!
    !!! Post this report on the forum you are being helped !!!
    !!! Don't continue with removal unless instructed by an authorized helper !!!
    
    Fix running from C:\Programmi\navilog1
    
    Updated on 13.02.2009 at 18h00 by IL-MAFIOSO
    
    Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Uniprocessor Free : Processore Intel Pentium II )
    BIOS : KBC Version 82.15
    USER : Alessio ( Administrator )
    BOOT : Normal boot
    
    Antivirus : avast! antivirus 4.8.1290 [VPS 090216-0] 4.8.1290 (Activated)
    
    
    C:\ (Local Disk) - NTFS - Total:102 Go (Free:91 Go)
    D:\ (Local Disk) - NTFS - Total:7 Go (Free:0 Go)
    E:\ (Local Disk) - NTFS - Total:1 Go (Free:1 Go)
    F:\ (CD or DVD)
    
    
    Search done in normal mode
    
    *** Searching for installed Software ***
    
    
    *** Search folders in "C:\WINDOWS" ***
    
    
    *** Search folders in "C:\Programmi" ***
    
    
    *** Search folders in "C:\Documents and Settings\All Users\menuav~1\progra~1" ***
    
    
    *** Search folders in "C:\Documents and Settings\All Users\menuav~1" ***
    
    
    *** Search folders in "c:\docume~1\alluse~1\datiap~1" ***
    
    
    *** Search folders in "C:\Documents and Settings\Alessio\datiap~1" *** 
    
    
    *** Search folders in "C:\Documents and Settings\Alessio\impost~1\datiap~1" *** 
    
    
    *** Search folders in "C:\Documents and Settings\Alessio\menuav~1\progra~1" *** 
    
    
    *** Search with GenericNaviSearch ***
    !!! Possibility of legitimate files in the result !!!
    !!! Must always be checked before manually deleting !!!
    
    * Scan in "C:\WINDOWS\system32" *
    
    * Scan in "C:\Documents and Settings\Alessio\impost~1\datiap~1" * 
    
    
    
    *** Search files *** 
    
    
    
    *** Search specific Registry keys ***
    !! Following keys are not certainly all infected !!
    
    
    *** Complementary Search ***
    (Search specific files)
    
    1)Search new Instant Access files :
    
    
    2)Heuristic Search :
    
    * In "C:\WINDOWS\system32" :
    
    
    * In "C:\Documents and Settings\Alessio\impost~1\datiap~1" : 
    
    
    3)Certificates Search :
    
    Egroup certificate not found !
    Electronic-Group certificate not found !
    Montorgueil certificate not found !
    OOO-Favorit certificate not found !
    Sunny-Day-Design-Ltd certificate not found !
    
    4)Search others known folders and files :
    
    
    
    *** Search completed on 16/02/2009 at 17.23.22,73 ***

  7. #7
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    :P ok, ma riceverai a casa una doppia parcella.

    Ok anche questo

    ciao...
    ...
    :x:_::_:*:_::_: )(:_:*:_:*:__::_:°FM°:_: )(:_:*:_:x:___

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved.