Pagina 1 di 2 1 2 ultimoultimo
Visualizzazione dei risultati da 1 a 10 su 20

Discussione: Dialer?

  1. #1

    Dialer?

    Ciao a tutti..sono nuovo vi scrivo perchè ho un problema... ho scoperto che si è creata una nuova connessione chiamata "Internet connection", chiama un numero 000 sfruttando il modem adsl. In pratica disconnette regolarmente Alice e si ricollega. La riesco ad eliminare senza problemi, ma si ricrea regolarmente; inoltre ho notato anche un processo attivo (sicuramente incriminato) sotto il nome di 1190916649.dat.exe.
    In più, alcune icone dalla barra di applicazioni (pannello di controllo schede audio e video, e modem) sono scomparse. Norton, Pc-cillin e Bitdefender non riescono a risolvere il problema... con Malware scanner ho beccato chiavi di registro infette, le ho pulite, ma ancora nulla... Ieri sera la connessione 'bastarda' non era comparsa, ma oggi di nuovo.
    Non riesco a capire tra l'altro quanto grave possa essere.. nel senso.. i dialer sfruttano i modem analogici per connettersi a numeri ad alte tariffe... non ho mai sentito di una loro efficacia con le linee adsl! In ogni caso vorrei risolvere il problema... vi posto il log di hijack nel prossimo messaggio, perchè altrimenti supero il tetto dei caratteri. Se potete darmi una mano a capirci qualcosa, siete dei grandi!!
    Grazie da ora!

  2. #2
    Logfile of HijackThis v1.99.1
    Scan saved at 0.30.48, on 05/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
    C:\Programmi\File comuni\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Programmi\FreePOPs\freepopsservice.exe
    C:\Programmi\FreePOPs\freepopsd.exe
    C:\Programmi\M-Audio MobilePre\Install\MPInst.exe
    C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.e xe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Programmi\File comuni\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.ex e
    C:\Programmi\M-Audio MobilePre\MPTask.exe
    C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Programmi\Microsoft Office\Office\1040\OLFSNT40.EXE
    C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Programmi\MSN Messenger\msnmsgr.exe
    C:\Programmi\MSN Messenger\usnsvc.exe
    C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Fraps\fraps.exe
    C:\Programmi\Internet Explorer\iexplore.exe
    C:\Programmi\Internet Explorer\iexplore.exe
    C:\Documents and Settings\UTENTE\Documenti\Andrea\hijackthis\Hijack This.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://2uid.info
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - URLSearchHook: Coolstreaming Tool-Bar v1.0 Toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCool.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: TB Class - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\Programmi\WinBudget\bin\matrix.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Programmi\File comuni\Symantec Shared\coShared\Browser\1.0\NppBho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Coolstreaming Tool-Bar v1.0 Toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCool.dll
    O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Programmi\TextAloud\TAForIE.dll
    O3 - Toolbar: Coolstreaming Tool-Bar v1.0 Toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCool.dll
    O3 - Toolbar: Mostra Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Programmi\File comuni\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
    O4 - HKLM\..\Run: [type32] "C:\Programmi\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmi\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Programmi\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [CTSysVol] C:\Programmi\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Felix] C:\Program Files\ScreenMates\felix.EXE
    O4 - HKCU\..\Run: [Creative Detector] C:\Programmi\Creative\MediaSource\Detector\CTDetec t.exe /R
    O4 - HKCU\..\Run: [StartCCC] C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Iniciar guiños Messenger.lnk = ?
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.ex e
    O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Programmi\M-Audio MobilePre\MPTask.exe
    O4 - Global Startup: Messenger Power Plus 8.1.lnk = C:\Archivos de programa\MSN Messenger\msnmsgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Porta Symantec Fax Starter Edition.lnk = C:\Programmi\Microsoft Office\Office\1040\OLFSNT40.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
    O11 - Options group: [INTERNATIONAL] International*
    O15 - Trusted Zone: http://www.lettere.unito.it
    O15 - Trusted Zone: *.whataboutadog.com
    O15 - Trusted Zone: *.whataboutarabit.com
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {3C38DEE8-BE1A-4DEC-B232-2C78706CC7EA} (GUpdate Class) - http://ps.itv.mop.com/update/update/....10-signed.cab
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab56986.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1121949080593
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{FD941188-6DA6-4386-9992-F67B8C7C286D}: NameServer = 85.37.17.8 85.38.28.73
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

  3. #3
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: FreePOPs - Unknown owner - C:\Programmi\FreePOPs\freepopsservice.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Convalida password di Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
    O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Programmi\M-Audio MobilePre\Install\MPInst.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.e xe



    Eccolo finito... scusate...non ci stava in un solo messaggio...

  4. #4
    ciao maverick,avvia hijackthis,spunta a sinistra su queste voci:

    O15 - Trusted Zone: *.whataboutarabit.com

    O15 - Trusted Zone: *.whataboutadog.com

    O2 - BHO: TB Class - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\Programmi\WinBudget\bin\matrix.dll

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://2uid.info



    e clicca sotto su fix checked.

    poi scarica findawf
    avvialo,clicca un tasto quando te lo dice,al termine del lavoro posta qua il suo relativo log

  5. #5
    Grazie da ora, tecnico24! Ho fixato le voci che hai detto su hijack. Questo è il log di findawf:

    bak folders found
    ~~~~~~~~~~~

    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\WINDOWS\BAK

    11/05/2000 01.00 90.112 UpdReg.EXE
    1 File 90.112 byte
    2 Directory 44.121.792.512 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\DAEMON~1\BAK

    09/11/2005 00.00 128.920 daemon.exe
    1 File 128.920 byte
    2 Directory 44.121.792.512 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\MICROS~4\BAK

    03/06/2004 10.51 172.032 type32.exe
    1 File 172.032 byte
    2 Directory 44.121.788.416 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\MIFB84~1\BAK

    03/06/2004 10.50 204.800 point32.exe
    1 File 204.800 byte
    2 Directory 44.121.788.416 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\QUICKT~1\BAK

    29/06/2007 06.24 286.720 qttask.exe
    1 File 286.720 byte
    2 Directory 44.121.788.416 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\WINAMP\BAK

    21/11/2006 19.38 35.328 winampa.exe
    1 File 35.328 byte
    2 Directory 44.121.788.416 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~2\SCREEN~1\BAK

    12/08/2001 10.37 323.584 felix.EXE
    1 File 323.584 byte
    2 Directory 44.121.788.416 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\WINDOWS\SYSTEM32\BAK

    20/08/2004 00.39 15.360 ctfmon.exe
    11/03/2004 01.26 406.016 PSDrvCheck.exe
    2 File 421.376 byte
    2 Directory 44.121.788.416 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\ANALOG~1\SOUNDMAX\BAK

    30/05/2003 09.42 585.728 Smax4.exe
    03/10/2007 22.43 1.241 SMax4.log
    03/10/2007 20.36 1.241 SMax4_saved.log
    29/05/2003 16.28 790.528 SMax4PNP.exe
    19/09/2007 21.50 118.784 SMWDMIF.dll
    5 File 1.497.522 byte
    2 Directory 44.121.788.416 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\ATITEC~1\ATI.ACE\BAK

    02/01/2006 17.41 45.056 cli.exe
    1 File 45.056 byte
    2 Directory 44.121.788.416 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\ATITEC~1\ATICON~1\BAK

    03/05/2005 21.05 344.064 atiptaxx.exe
    1 File 344.064 byte
    2 Directory 44.121.784.320 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\FILECO~1\SYMANT~1\BAK

    0 File 0 byte
    2 Directory 44.121.784.320 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\HP\HPCORE~1\BAK

    12/05/2004 15.18 241.664 hpcmpmgr.exe
    1 File 241.664 byte
    6 Directory 44.121.784.320 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\HP\HPSOFT~1\BAK

    16/02/2005 23.11 49.152 HPWuSchd2.exe
    1 File 49.152 byte
    2 Directory 44.121.784.320 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\THOMSON\SPEEDT~1\BAK

    05/09/2003 06.59 878.080 Dragdiag.exe
    1 File 878.080 byte
    2 Directory 44.121.784.320 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\ATITEC~1\ATI.ACE\CORE-S~1\BAK

    10/11/2006 12.35 90.112 CLIStart.exe
    1 File 90.112 byte
    2 Directory 44.121.784.320 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\CREATIVE\MEDIAS~1\DETECTOR\BAK

    05/10/2004 09.52 98.304 CTDetect.exe
    1 File 98.304 byte
    2 Directory 44.121.784.320 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: D446-E742

    Directory di C:\PROGRA~1\CREATIVE\SBAUDIGY\SURROU~1\BAK

    15/02/2005 16.10 57.344 CTSysVol.exe
    1 File 57.344 byte
    2 Directory 44.121.784.320 byte disponibili


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    28176 3 Oct 2007 "C:\WINDOWS\UpdReg.EXE"
    90112 11 May 2000 "C:\WINDOWS\bak\UpdReg.EXE"
    28176 3 Oct 2007 "C:\Programmi\DAEMON Tools\daemon.exe"
    128920 9 Nov 2005 "C:\Programmi\DAEMON Tools\bak\daemon.exe"
    28176 3 Oct 2007 "C:\Programmi\Microsoft IntelliType Pro\type32.exe"
    172032 3 Jun 2004 "C:\Programmi\Microsoft IntelliType Pro\bak\type32.exe"
    28176 3 Oct 2007 "C:\Programmi\Microsoft IntelliPoint\point32.exe"
    204800 3 Jun 2004 "C:\Programmi\Microsoft IntelliPoint\bak\point32.exe"
    28176 3 Oct 2007 "C:\Programmi\QuickTime\qttask.exe"
    286720 29 Jun 2007 "C:\Programmi\QuickTime\bak\qttask.exe"
    28176 3 Oct 2007 "C:\Programmi\Winamp\winampa.exe"
    35328 21 Nov 2006 "C:\Programmi\Winamp\bak\winampa.exe"
    323584 12 Aug 2001 "C:\Programmi\Felix\felix.EXE"
    28176 3 Oct 2007 "C:\Program Files\ScreenMates\felix.EXE"
    323584 12 Aug 2001 "C:\Program Files\ScreenMates\bak\felix.EXE"
    245590 27 May 2004 "C:\Documents and Settings\UTENTE\Documenti\Andrea\Svago\felix.exe"
    15360 20 Aug 2004 "C:\WINDOWS\system32\ctfmon.exe"
    15360 20 Aug 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
    28176 3 Oct 2007 "C:\WINDOWS\system32\PSDrvCheck.exe"
    406016 11 Mar 2004 "C:\WINDOWS\system32\bak\PSDrvCheck.exe"
    28176 3 Oct 2007 "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe"
    585728 30 May 2003 "C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe"
    585728 30 May 2003 "C:\Documents and Settings\UTENTE\Documenti\Andrea\Driver scheda audio\AD1985\SM_Panel\Sys\SMax4.exe"
    1331 18 Sep 2007 "C:\Programmi\Analog Devices\SoundMAX\SMax4.log"
    1241 3 Oct 2007 "C:\Programmi\Analog Devices\SoundMAX\bak\SMax4.log"
    28176 3 Oct 2007 "C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe"
    790528 29 May 2003 "C:\Programmi\Analog Devices\SoundMAX\bak\SMax4PNP.exe"
    790528 29 May 2003 "C:\Documents and Settings\UTENTE\Documenti\Andrea\Driver scheda audio\AD1985\SM_PNP\Sys\SMax4PNP.exe"
    1330 17 Sep 2007 "C:\Programmi\Analog Devices\SoundMAX\SMax4_saved.log"
    1241 3 Oct 2007 "C:\Programmi\Analog Devices\SoundMAX\bak\SMax4_saved.log"
    118784 19 Sep 2007 "C:\Programmi\Analog Devices\SoundMAX\SMWDMIF.dll"
    118784 19 Sep 2007 "C:\Programmi\Analog Devices\SoundMAX\bak\SMWDMIF.dll"
    118784 19 Sep 2007 "C:\Documents and Settings\UTENTE\Documenti\Andrea\smwdmif\smwdmif.d ll"
    118784 23 May 2003 "C:\Documents and Settings\UTENTE\Documenti\Andrea\Driver scheda audio\AD1985\SM_Comn\Sys\SMWDMIF.DLL"
    28176 3 Oct 2007 "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe"
    45056 2 Jan 2006 "C:\Programmi\ATI Technologies\ATI.ACE\bak\cli.exe"
    45056 29 Sep 2006 "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLI.exe"
    45056 23 Apr 2007 "C:\WINDOWS\assembly\GAC_MSIL\CLI\2.0.0.0__90ba9c7 0f846762e\CLI.EXE"
    28176 3 Oct 2007 "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    344064 3 May 2005 "C:\Programmi\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
    28176 3 Oct 2007 "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
    241664 12 May 2004 "C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe"
    324 5 Oct 2007 "C:\Programmi\HP\hpcoretech\bak\data\EvntData-1491170020.xml"
    28176 3 Oct 2007 "C:\Programmi\HP\HP Software Update\HPWuSchd2.exe"
    49152 16 Feb 2005 "C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe"
    28176 3 Oct 2007 "C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe"
    878080 5 Sep 2003 "C:\Programmi\Thomson\SpeedTouch USB\bak\Dragdiag.exe"
    878080 5 Sep 2003 "C:\Programmi\Telecom Italia\AdslWizzy\Driver\ThomsonST330\Programs\drag diag.exe"
    28176 3 Oct 2007 "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    90112 10 Nov 2006 "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\bak\CLIStart.exe"
    28176 3 Oct 2007 "C:\Programmi\Creative\MediaSource\Detector\CTDete ct.exe"
    98304 5 Oct 2004 "C:\Programmi\Creative\MediaSource\Detector\bak\CT Detect.exe"
    28176 3 Oct 2007 "C:\Programmi\Creative\SBAudigy\Surround Mixer\CTSysVol.exe"
    57344 15 Feb 2005 "C:\Programmi\Creative\SBAudigy\Surround Mixer\bak\CTSysVol.exe"


    end of report

  6. #6
    ok,a questo punto devi avere pazienza perche analizzo il log.

  7. #7
    Beh..certo!! ci mancherebbe...

  8. #8
    scaricati avenger
    avvialo,clicca su Input script manually,poi sulla lente di ingrandimento.
    nello spazio bianco fai un copia|incolla di tutte queste righe in rosso:



    files to delete:
    C:\WINDOWS\UpdReg.EXE
    C:\Programmi\DAEMON Tools\daemon.exe
    C:\Programmi\Microsoft IntelliType Pro\type32.exe
    C:\Programmi\Microsoft IntelliPoint\point32.exe
    C:\Programmi\QuickTime\qttask.exe
    C:\Programmi\Winamp\winampa.exe
    C:\Program Files\ScreenMates\felix.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\PSDrvCheck.exe
    C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
    C:\Programmi\Analog Devices\SoundMAX\SMax4.log
    C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Programmi\Analog Devices\SoundMAX\SMax4_saved.log
    C:\Programmi\Analog Devices\SoundMAX\SMWDMIF.dll
    C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
    C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
    C:\Programmi\HP\hpcoretech\data\EvntData-1491170020.xml
    C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
    C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe
    C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    C:\Programmi\Creative\MediaSource\Detector\CTDetec t.exe
    C:\Programmi\Creative\SBAudigy\Surround Mixer\CTSysVol.exe


    files to move:
    C:\WINDOWS\bak\UpdReg.EXE | C:\WINDOWS\UpdReg.EXE
    C:\Programmi\DAEMON Tools\bak\daemon.exe | C:\Programmi\DAEMON Tools\daemon.exe
    C:\Programmi\Microsoft IntelliType Pro\bak\type32.exe | C:\Programmi\Microsoft IntelliType Pro\type32.exe
    C:\Programmi\Microsoft IntelliPoint\bak\point32.exe | C:\Programmi\Microsoft IntelliPoint\point32.exe
    C:\Programmi\QuickTime\bak\qttask.exe | C:\Programmi\QuickTime\qttask.exe
    C:\Programmi\Winamp\bak\winampa.exe | C:\Programmi\Winamp\winampa.exe
    C:\Program Files\ScreenMates\bak\felix.EXE | C:\Program Files\ScreenMates\felix.EXE
    C:\WINDOWS\system32\bak\ctfmon.exe | C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\bak\PSDrvCheck.exe | C:\WINDOWS\system32\PSDrvCheck.exe
    C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe | C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
    C:\Programmi\Analog Devices\SoundMAX\bak\SMax4.log | C:\Programmi\Analog Devices\SoundMAX\SMax4.log
    C:\Programmi\Analog Devices\SoundMAX\bak\SMax4PNP.exe | C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Programmi\Analog Devices\SoundMAX\bak\SMax4_saved.log | C:\Programmi\Analog Devices\SoundMAX\SMax4_saved.log
    C:\Programmi\Analog Devices\SoundMAX\bak\SMWDMIF.dll | C:\Programmi\Analog Devices\SoundMAX\SMWDMIF.dll
    C:\Programmi\ATI Technologies\ATI.ACE\bak\cli.exe | C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
    C:\Programmi\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe | C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe | C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
    C:\Programmi\HP\hpcoretech\bak\data\EvntData-1491170020.xml | C:\Programmi\HP\hpcoretech\data\EvntData-1491170020.xml
    C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe | C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
    C:\Programmi\Thomson\SpeedTouch USB\bak\Dragdiag.exe | C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe
    C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\bak\CLIStart.exe | C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    C:\Programmi\Creative\MediaSource\Detector\bak\CTD etect.exe | C:\Programmi\Creative\MediaSource\Detector\CTDetec t.exe
    C:\Programmi\Creative\SBAudigy\Surround Mixer\bak\CTSysVol.exe | C:\Programmi\Creative\SBAudigy\Surround Mixer\CTSysVol.exe




    dopodiche clicca su Done
    poi sul semaforo con luce verde
    due volte si,riavvia il pc e posta qua il log di avenger(C:/avenger.txt)
    Poi dovresti essere a posto.

  9. #9
    Allora... premetto che dopo il riavvio sono ricomparse le icone che prima non c'erano più sulla barra applicazioni, ma tra le connessioni compare ancora la "internet connection".
    In ogni caso questo è il nuovo log di avenger:

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Service s\sltcokac

    *******************

    Script file located at: \??\C:\Documents and Settings\ophwennj.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    File C:\WINDOWS\UpdReg.EXE deleted successfully.
    File C:\Programmi\DAEMON Tools\daemon.exe deleted successfully.
    File C:\Programmi\Microsoft IntelliType Pro\type32.exe deleted successfully.
    File C:\Programmi\Microsoft IntelliPoint\point32.exe deleted successfully.
    File C:\Programmi\QuickTime\qttask.exe deleted successfully.
    File C:\Programmi\Winamp\winampa.exe deleted successfully.
    File C:\Program Files\ScreenMates\felix.EXE deleted successfully.
    File C:\WINDOWS\system32\ctfmon.exe deleted successfully.
    File C:\WINDOWS\system32\PSDrvCheck.exe deleted successfully.
    File C:\Programmi\Analog Devices\SoundMAX\Smax4.exe deleted successfully.
    File C:\Programmi\Analog Devices\SoundMAX\SMax4.log deleted successfully.
    File C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe deleted successfully.
    File C:\Programmi\Analog Devices\SoundMAX\SMax4_saved.log deleted successfully.
    File C:\Programmi\Analog Devices\SoundMAX\SMWDMIF.dll deleted successfully.
    File C:\Programmi\ATI Technologies\ATI.ACE\cli.exe deleted successfully.
    File C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe deleted successfully.
    File C:\Programmi\HP\hpcoretech\hpcmpmgr.exe deleted successfully.


    File C:\Programmi\HP\hpcoretech\data\EvntData-1491170020.xml not found!
    Deletion of file C:\Programmi\HP\hpcoretech\data\EvntData-1491170020.xml failed!

    Could not process line:
    C:\Programmi\HP\hpcoretech\data\EvntData-1491170020.xml
    Status: 0xc0000034

    File C:\Programmi\HP\HP Software Update\HPWuSchd2.exe deleted successfully.
    File C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe deleted successfully.
    File C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe deleted successfully.
    File C:\Programmi\Creative\MediaSource\Detector\CTDetec t.exe deleted successfully.
    File C:\Programmi\Creative\SBAudigy\Surround Mixer\CTSysVol.exe deleted successfully.
    File move operation C:\WINDOWS\bak\UpdReg.EXE|C:\WINDOWS\UpdReg.EXE completed successfully.
    File move operation C:\Programmi\DAEMON Tools\bak\daemon.exe|C:\Programmi\DAEMON Tools\daemon.exe completed successfully.
    File move operation C:\Programmi\Microsoft IntelliType Pro\bak\type32.exe|C:\Programmi\Microsoft IntelliType Pro\type32.exe completed successfully.
    File move operation C:\Programmi\Microsoft IntelliPoint\bak\point32.exe|C:\Programmi\Microsof t IntelliPoint\point32.exe completed successfully.
    File move operation C:\Programmi\QuickTime\bak\qttask.exe|C:\Programmi \QuickTime\qttask.exe completed successfully.
    File move operation C:\Programmi\Winamp\bak\winampa.exe|C:\Programmi\W inamp\winampa.exe completed successfully.
    File move operation C:\Program Files\ScreenMates\bak\felix.EXE|C:\Program Files\ScreenMates\felix.EXE completed successfully.
    File move operation C:\WINDOWS\system32\bak\ctfmon.exe|C:\WINDOWS\syst em32\ctfmon.exe completed successfully.
    File move operation C:\WINDOWS\system32\bak\PSDrvCheck.exe|C:\WINDOWS\ system32\PSDrvCheck.exe completed successfully.
    File move operation C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe|C:\Programmi\Analog Devices\SoundMAX\Smax4.exe completed successfully.
    File move operation C:\Programmi\Analog Devices\SoundMAX\bak\SMax4.log|C:\Programmi\Analog Devices\SoundMAX\SMax4.log completed successfully.
    File move operation C:\Programmi\Analog Devices\SoundMAX\bak\SMax4PNP.exe|C:\Programmi\Ana log Devices\SoundMAX\SMax4PNP.exe completed successfully.
    File move operation C:\Programmi\Analog Devices\SoundMAX\bak\SMax4_saved.log|C:\Programmi\ Analog Devices\SoundMAX\SMax4_saved.log completed successfully.
    File move operation C:\Programmi\Analog Devices\SoundMAX\bak\SMWDMIF.dll|C:\Programmi\Anal og Devices\SoundMAX\SMWDMIF.dll completed successfully.
    File move operation C:\Programmi\ATI Technologies\ATI.ACE\bak\cli.exe|C:\Programmi\ATI Technologies\ATI.ACE\cli.exe completed successfully.
    File move operation C:\Programmi\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe|C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe completed successfully.
    File move operation C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe|C:\Pro grammi\HP\hpcoretech\hpcmpmgr.exe completed successfully.
    File move operation C:\Programmi\HP\hpcoretech\bak\data\EvntData-1491170020.xml|C:\Programmi\HP\hpcoretech\data\Evn tData-1491170020.xml completed successfully.
    File move operation C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe|C:\Programmi\HP\HP Software Update\HPWuSchd2.exe completed successfully.
    File move operation C:\Programmi\Thomson\SpeedTouch USB\bak\Dragdiag.exe|C:\Programmi\Thomson\SpeedTou ch USB\Dragdiag.exe completed successfully.
    File move operation C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\bak\CLIStart.exe|C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe completed successfully.
    File move operation C:\Programmi\Creative\MediaSource\Detector\bak\CTD etect.exe|C:\Programmi\Creative\MediaSource\Detect or\CTDetect.exe completed successfully.
    File move operation C:\Programmi\Creative\SBAudigy\Surround Mixer\bak\CTSysVol.exe|C:\Programmi\Creative\SBAud igy\Surround Mixer\CTSysVol.exe completed successfully.

    Completed script processing.

    *******************

    Finished! Terminate.

  10. #10
    nuovo log di hijackthis+quello di findawf.

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.