Visualizzazione dei risultati da 1 a 4 su 4
  1. #1

    Problema Con Explorer e secure32.html

    Anche io sono incappato nel problema con IE e secure32.html e seguendo i vostri consigli ho ricavato il log con Hijack !!!

    Vi chiedo gentilmente quali voci debba eliminare per risolvere il problema !!

    Grazie !!!

    P.S. purtroppo sono nuovo del forum e non riesco al incollare comletamente il log di hijack poichè supero il limite massimo di caratteri. Spero di fare il giusto incollandolo in 2 differenti messaggi !!

    Nuovamente grazie a tutti


    Logfile of HijackThis v1.99.1
    Scan saved at 0.16.04, on 20/01/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
    C:\Programmi\Microsoft IntelliPoint\point32.exe
    C:\Programmi\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA IE.EXE
    C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe
    C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe
    C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
    C:\Programmi\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\HPConfig.exe
    C:\Programmi\HPQ\Notebook Utilities\HPWirelessMgr.exe
    C:\Programmi\Sony\MD Simple Burner\NetMDSB.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Runner.EXE
    C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Programmi\WinClamAVShield\sp_clam.exe
    C:\Documents and Settings\io\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O1 - Hosts: 81.211.105.6 www.0190-dialer.com
    O1 - Hosts: 81.211.105.6 www.22469.com
    O1 - Hosts: 81.211.105.6 www.3wisp.com
    O1 - Hosts: 81.211.105.6 www.adult-cinema.org
    O1 - Hosts: 81.211.105.6 www.adultfreehosting.com
    O1 - Hosts: 81.211.105.6 www.adulthosting.com
    O1 - Hosts: 81.211.105.6 www.adultlinks1.com
    O1 - Hosts: 81.211.105.6 www.adultmegamovies.com
    O1 - Hosts: 81.211.105.6 www.adultsexmovie.net
    O1 - Hosts: 81.211.105.6 www.adultwall.com
    O1 - Hosts: 81.211.105.6 www.afro-sex.com
    O1 - Hosts: 81.211.105.6 www.agreathost.net
    O1 - Hosts: 81.211.105.6 www.alehina.com
    O1 - Hosts: 81.211.105.6 www.allnichestgp.com
    O1 - Hosts: 81.211.105.6 www.allowednet.com
    O1 - Hosts: 81.211.105.6 www.amateurlips.com
    O1 - Hosts: 81.211.105.6 www.amateurnudephoto.com
    O1 - Hosts: 81.211.105.6 www.amateursgonebad.com
    O1 - Hosts: 81.211.105.6 www.ambersamateurhardcore.com
    O1 - Hosts: 81.211.105.6 www.anyamateur.com
    O1 - Hosts: 81.211.105.6 www.apornhost.com
    O1 - Hosts: 81.211.105.6 www.findmodels.com
    O1 - Hosts: 81.211.105.6 www.asianscum.com
    O1 - Hosts: 81.211.105.6 www.awethumbs.com
    O1 - Hosts: 81.211.105.6 www.badassxxx.com
    O1 - Hosts: 81.211.105.6 www.badbimbo.com
    O1 - Hosts: 81.211.105.6 www.beautifulbondage.com
    O1 - Hosts: 81.211.105.6 www.bestpornhost.com
    O1 - Hosts: 81.211.105.6 www.biggestdickinporn.net
    O1 - Hosts: 81.211.105.6 www1.3wisp.com
    O1 - Hosts: 81.211.105.6 www1.kinghost.com
    O1 - Hosts: 81.211.105.6 www1.ndhosting.com
    O1 - Hosts: 81.211.105.6 www1.sexls.com
    O1 - Hosts: 81.211.105.6 www1.toptgphost.com
    O1 - Hosts: 81.211.105.6 www1.xfreehosting.com
    O1 - Hosts: 81.211.105.6 www10.kinghost.com
    O1 - Hosts: 81.211.105.6 www11.kinghost.com
    O1 - Hosts: 81.211.105.6 www12.kinghost.com
    O1 - Hosts: 81.211.105.6 www2.3wisp.com
    O1 - Hosts: 81.211.105.6 www2.kinghost.com
    O1 - Hosts: 81.211.105.6 www2.ndhosting.com
    O1 - Hosts: 81.211.105.6 www2.toptgphost.com
    O1 - Hosts: 81.211.105.6 www2.xfreehosting.com
    O1 - Hosts: 81.211.105.6 www2.zpornstars.com
    O1 - Hosts: 81.211.105.6 www3.kinghost.com
    O1 - Hosts: 81.211.105.6 www3.ndhosting.com
    O1 - Hosts: 81.211.105.6 www3.xfreehosting.com
    O1 - Hosts: 81.211.105.6 www3.zpornstars.com
    O1 - Hosts: 81.211.105.6 www30.smutserver.com
    O1 - Hosts: 81.211.105.6 www31.smutserver.com
    O1 - Hosts: 81.211.105.6 www32.smutserver.com
    O1 - Hosts: 81.211.105.6 www4.kinghost.com
    O1 - Hosts: 81.211.105.6 www4.xfreehosting.com
    O1 - Hosts: 81.211.105.6 www4.zpornstars.com
    O1 - Hosts: 81.211.105.6 www5.kinghost.com
    O1 - Hosts: 81.211.105.6 www6.kinghost.com
    O1 - Hosts: 81.211.105.6 www7.kinghost.com
    O1 - Hosts: 81.211.105.6 www8.kinghost.com
    O1 - Hosts: 81.211.105.6 www9.kinghost.com
    O1 - Hosts: 81.211.105.6 www.bigmovies.com
    O1 - Hosts: 81.211.105.6 www.bigpornvideos.com
    O1 - Hosts: 81.211.105.6 www.big-xxx-movies.com
    O1 - Hosts: 81.211.105.6 www.samplehosting.com
    O1 - Hosts: 81.211.105.6 www.blinghosting.com
    O1 - Hosts: 81.211.105.6 www.blitz-hosting.com
    O1 - Hosts: 81.211.105.6 www.boyanxxx.com
    O1 - Hosts: 81.211.105.6 www.bustyx.com
    O1 - Hosts: 81.211.105.6 www.cleanadulthost.com
    O1 - Hosts: 81.211.105.6 www.cleanpornhost.com
    O1 - Hosts: 81.211.105.6 www.cyberxxxhost.com
    O1 - Hosts: 81.211.105.6 www.dialcom.com
    O1 - Hosts: 81.211.105.6 www.eldererotica.tv
    O1 - Hosts: 81.211.105.6 www.ethniccash.com
    O1 - Hosts: 81.211.105.6 www.exploitedblackteens.net
    O1 - Hosts: 81.211.105.6 www.exscapeporn.com
    O1 - Hosts: 81.211.105.6 www.fantasiegirl.com
    O1 - Hosts: 81.211.105.6 www.fastmailer.info
    O1 - Hosts: 81.211.105.6 www.filth-hostz.com
    O1 - Hosts: 81.211.105.6 www.free-freeporn.com
    O1 - Hosts: 81.211.105.6 www.free-xxx-server.com
    O1 - Hosts: 81.211.105.6 www.freexxxvideoclip.com
    O1 - Hosts: 81.211.105.6 www.fvotd.com
    O1 - Hosts: 81.211.105.6 www.galaporn.com
    O1 - Hosts: 81.211.105.6 www.18#######s.com
    O1 - Hosts: 81.211.105.6 www.bigtitsroundasses.com
    O1 - Hosts: 81.211.105.6 www.bikinivoyeur.com
    O1 - Hosts: 81.211.105.6 www.blacksonblondes.com
    O1 - Hosts: 81.211.105.6 www.easydrunkgirls.com
    O1 - Hosts: 81.211.105.6 www.markscash.com
    O1 - Hosts: 81.211.105.6 www.milfwhore.com
    O1 - Hosts: 81.211.105.6 www.springbreakspycam.com
    O1 - Hosts: 81.211.105.6 www.sweetmoney.com
    O1 - Hosts: 81.211.105.6 www.wildclubvideos.com
    O1 - Hosts: 81.211.105.6 www.gallys.camcorderxxx.com
    O1 - Hosts: 81.211.105.6 www.gallys.nastydollars.com
    O1 - Hosts: 81.211.105.6 www.gayhost4free.com
    O1 - Hosts: 81.211.105.6 www.ghostgalleries.com
    O1 - Hosts: 81.211.105.6 www.girls2.twistys.net
    O1 - Hosts: 81.211.105.6 www.greatfreehost.com
    O1 - Hosts: 81.211.105.6 www.hanksgalleries.com
    O1 - Hosts: 81.211.105.6 www.hjemmesex.dk

  2. #2

    Seconda parte del log

    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton AntiVirus\NavShExt.dll (file missing)
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [Desktop Zoom] C:\Programmi\HPQ\Desktop Zoom\hpwinadj.exe -s
    O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
    O4 - HKLM\..\Run: [TV Now] C:\Programmi\HPQ\Notebook Utilities\TvNow.exe /RK
    O4 - HKLM\..\Run: [Display Settings] C:\Programmi\HPQ\Notebook Utilities\hptasks.exe /s
    O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
    O4 - HKLM\..\Run: [Cpqset] C:\Programmi\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 4.exe
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmi\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBContr oller
    O4 - HKLM\..\Run: [USBToolTip] "C:\Programmi\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [\\GIOVANNI\EPSON Stylus C46 Series (Copia 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T 1.EXE /P44 "\\GIOVANNI\EPSON Stylus C46 Series (Copia 1)" /O6 "USB002" /M "Stylus C46"
    O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmi\SlySoft\CloneCD\CloneCDTray.exe" /s
    O4 - HKLM\..\Run: [\\GIOVANNI\EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA IE.EXE /P41 "\\GIOVANNI\EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe "
    O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\system32\autosys.exe
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: LG SyncManager.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Runner.EXE
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Scarica con FlashGet - C:\Programmi\FlashGet\jc_link.htm
    O8 - Extra context menu item: Scarica tutto con FlashGet - C:\Programmi\FlashGet\jc_all.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {30499022-8ED7-42B4-8C60-364061C3E5B1} - http://mufxggfi.com/610dcc68/55000/1/xp/RealSpace.cab
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
    O17 - HKLM\System\CCS\Services\Tcpip\..\{47131A33-730E-43E8-8642-5E8309425A21}: NameServer = 212.48.4.15,62.48.150.4
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
    O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Programmi\HPQ\Notebook Utilities\HPWirelessMgr.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Programmi\Sony\MD Simple Burner\NetMDSB.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: SysCtd - Unknown owner - \\?\C:\Programmi\File comuni\System\com3.exe (file missing)

  3. #3
    Utente di HTML.it L'avatar di holifay
    Registrato dal
    May 2005
    Messaggi
    1,330
    prima di postare il log è meglio se fai qualche scansione antivirus online, come Kaspersky e altre. Segui le indicazioni della guida che trovi nel post in rilievo. L'eliminazione dei file infetti con il solo hijackthis non è detto sia del tutto risolutiva
    Pensi di avere un file infetto? Invialo a SuspectFile

  4. #4

    Risolto

    Grazie mille a Holifay per la pronta risposta. Chiedo scusa per l'inesperienza nell'ambito del forum (come ho scritto sono nuovo di pacca) e visto il problema che avevo, ho cercato con google il quale mi ha proposto una pagina di questo forum dove si trattava dell'argomento.
    Solamente dopo aver inserito la mia richiesta di aiuto mi sono accorto che si trattava di una discussione molto vecchia.

    Comunque sia, avevo fatto più di una scansione prima di postare il log senza risultato, poi nel pomeriggio ho fatto una ricerca digitando la parola SmitFrau che da quel che ho capito poteva essere il virus causa del mio problema.
    Così facendo sono capitato su alcuni forum che consigliavano l'utilizzo di smitRem per risolvere il problema. Il risultato è stato ottimo infatti sono riuscito ad eliminare il problema con explorer che ora mi permette di reimpostare la pagina iniziale a mio piacimento.

    Grazie mille e scusate il disturbo

    Ciao !!!

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.