Pagina 1 di 3 1 2 3 ultimoultimo
Visualizzazione dei risultati da 1 a 10 su 21
  1. #1
    Utente di HTML.it
    Registrato dal
    Oct 2007
    Messaggi
    17

    Problema "internet Connection"

    Ciao, anche io ho lo stesso problema di questa connessione ke si crea da sola internet connection.
    Ho letto e questo è quanto:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18.48.08, on 19/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Programmi\SolidDocuments\SolidConverterPDF\SCPD F\SolidPdfService.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmi\Virtual CD v4 SDK\system\vcssecs.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Programmi\DAEMON Tools\daemon.exe
    C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Programmi\C6 Messenger\c6Messenger.exe
    C:\WINDOWS\system32\mioengine.exe
    C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Programmi\Java\jre1.6.0_02\bin\bak\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    c:\programmi\internet explorer\iexplore.exe
    C:\Documents and Settings\Andrea\Desktop\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bi...e=6&key=SEARCH
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.d ll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
    O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Programmi\SolidDocuments\SolidConverterPDF\SCPD F\ExploreExtPDF.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Programmi\SolidDocuments\SolidConverterPDF\SCPD F\ExploreExtPDF.dll
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.d ll
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe "
    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [PCMService] "c:\apps\Powercinema\PCMService.exe"
    O4 - HKLM\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [StartCCC] "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: C6 Messenger.lnk = C:\Programmi\C6 Messenger\c6Messenger.exe
    O4 - Startup: My Vodafone.it.lnk = C:\Documents and Settings\Andrea\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio
    O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\it.htm
    O15 - Trusted Zone: *.doginhispen.com
    O15 - Trusted Zone: *.whataboutadog.com
    O16 - DPF: {4D21BDFC-A621-4DE6-87DA-7C952D0ADF7E} (P00RecImageCtrl Class) - http://87.28.114.25:8000/push03.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/re...s/MSNPUpld.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab
    O16 - DPF: {8A96EAE5-D262-4226-A517-304C88B53F1F} (ProfileAccessCtrl Class) - http://87.28.114.25:8000/access01.cab
    O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} (DownloaderActiveX Control) - http://c6.community.alice.it/downloa...derActiveX.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
    O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Programmi\SolidDocuments\SolidConverterPDF\SCPD F\SolidPdfService.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Programmi\Virtual CD v4 SDK\system\vcssecs.exe

    --
    End of file - 9333 bytes





    -----------CONTINUA--------

  2. #2
    Utente di HTML.it
    Registrato dal
    Oct 2007
    Messaggi
    17
    --------CONTINUA--------



    Find AWF report by noahdfear ©2006
    Version 1.40



    bak folders found
    ~~~~~~~~~~~

    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\APPS\ABOARD\BAK

    02/05/2003 11.31 24.576 ABoard.exe
    1 File 24.576 byte
    2 Directory 43.248.881.664 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\APPS\POWERC~1\BAK

    08/10/2004 04.14 81.920 PCMService.exe
    1 File 81.920 byte
    2 Directory 43.248.881.664 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\ATITEC~1\ATICON~1\BAK

    21/04/2004 22.10 335.872 atiptaxx.exe
    1 File 335.872 byte
    2 Directory 43.248.877.568 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\DAEMON~1\BAK

    12/11/2006 12.48 157.592 daemon.exe
    1 File 157.592 byte
    2 Directory 43.248.877.568 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\QUICKT~1\BAK

    16/02/2007 10.54 282.624 qttask.exe
    1 File 282.624 byte
    2 Directory 43.248.877.568 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\WINDOWS\SYSTEM32\BAK

    20/08/2004 00.39 15.360 ctfmon.exe
    1 File 15.360 byte
    2 Directory 43.248.877.568 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\GRISOFT\AVG7\BAK

    13/09/2007 16.35 421.888 avgcc.exe
    1 File 421.888 byte
    2 Directory 43.248.877.568 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\MACROG~1\SWEETIM\BAK

    27/12/2006 16.53 73.840 SweetIM.exe
    1 File 73.840 byte
    2 Directory 43.248.877.568 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\NOKIA\NOKIAP~1\BAK

    18/06/2007 15.10 271.360 LaunchApplication.exe
    1 File 271.360 byte
    2 Directory 43.248.877.568 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\ADOBE\ACROBA~2.0\READER\BAK

    30/03/2006 17.45 313.472 AdobeUpdateManager.exe
    1 File 313.472 byte
    2 Directory 43.248.893.952 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\FILECO~1\AHEAD\LIB\BAK

    01/03/2007 15.57 153.136 NeroCheck.exe
    1 File 153.136 byte
    2 Directory 43.248.893.952 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\FILECO~1\REAL\UPDATE~1\BAK

    26/02/2007 20.03 180.269 realsched.exe
    1 File 180.269 byte
    2 Directory 43.248.873.472 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

    12/07/2007 04.00 132.496 jusched.exe
    1 File 132.496 byte
    2 Directory 43.248.873.472 byte disponibili


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    27660 8 Oct 2007 "C:\APPS\ABOARD\ABoard.exe"
    24576 2 May 2003 "C:\APPS\ABOARD\bak\ABoard.exe"
    27660 8 Oct 2007 "C:\APPS\Powercinema\PCMService.exe"
    81920 8 Oct 2004 "C:\APPS\Powercinema\bak\PCMService.exe"
    27660 8 Oct 2007 "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    335872 21 Apr 2004 "C:\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
    171464 18 Sep 2007 "C:\Programmi\DAEMON Tools\daemon.exe"
    157592 12 Nov 2006 "C:\Programmi\DAEMON Tools\bak\daemon.exe"
    27660 8 Oct 2007 "C:\Programmi\QuickTime\qttask.exe"
    282624 16 Feb 2007 "C:\Programmi\QuickTime\bak\qttask.exe"
    15360 20 Aug 2004 "C:\WINDOWS\system32\ctfmon.exe"
    15360 20 Aug 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
    421888 10 Oct 2007 "C:\Programmi\Grisoft\AVG7\avgcc.exe"
    421888 13 Sep 2007 "C:\Programmi\Grisoft\AVG7\bak\avgcc.exe"
    27660 8 Oct 2007 "C:\Programmi\Macrogaming\SweetIM\SweetIM.exe"
    73840 27 Dec 2006 "C:\Programmi\Macrogaming\SweetIM\bak\SweetIM. exe"
    271360 18 Jun 2007 "C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe"
    271360 18 Jun 2007 "C:\Programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe"
    27660 8 Oct 2007 "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe"
    313472 30 Mar 2006 "C:\Programmi\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe"
    27660 8 Oct 2007 "C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe"
    153136 1 Mar 2007 "C:\Programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe"
    27660 8 Oct 2007 "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"
    180269 26 Feb 2007 "C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe"
    32881 23 Feb 2004 "C:\Programmi\Java\j2re1.4.2_04\bin\jusched.ex e"
    49263 9 Nov 2006 "C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe "
    83608 14 Mar 2007 "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe "
    27660 8 Oct 2007 "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe "
    132496 12 Jul 2007 "C:\Programmi\Java\jre1.6.0_02\bin\bak\jusched.exe "


    end of report


    GRAZIE

  3. #3
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    Fixa:
    O15 - Trusted Zone: *.doginhispen.com
    O15 - Trusted Zone: *.whataboutadog.com
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)

    scarica avenger => http://swandog46.geekstogo.com/avenger.zip in una cartella dedicata (es: c:\avenger\)
    scompattalo => clicca su input script manually e poi sulla lente di ingrandimento
    incolla questo script nello spazio bianco:

    files to delete:
    C:\APPS\ABOARD\ABoard.exe
    C:\APPS\Powercinema\PCMService.exe
    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Programmi\DAEMON Tools\daemon.exe
    C:\Programmi\QuickTime\qttask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Grisoft\AVG7\avgcc.exe
    C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
    C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
    C:\Programmi\File comuni\Real\Update_OB\realsched.exe
    C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe


    files to move:
    C:\APPS\ABOARD\bak\ABoard.exe | C:\APPS\ABOARD\ABoard.exe
    C:\APPS\Powercinema\bak\PCMService.exe | C:\APPS\Powercinema\PCMService.exe
    C:\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe | C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Programmi\DAEMON Tools\bak\daemon.exe | C:\Programmi\DAEMON Tools\daemon.exe
    C:\Programmi\QuickTime\bak\qttask.exe | C:\Programmi\QuickTime\qttask.exe
    C:\WINDOWS\system32\bak\ctfmon.exe | C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Grisoft\AVG7\bak\avgcc.exe | C:\Programmi\Grisoft\AVG7\avgcc.exe
    C:\Programmi\Macrogaming\SweetIM\bak\SweetIM.exe | C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    C:\Programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe | C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\Programmi\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe | C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
    C:\Programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe | C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
    C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe | C:\Programmi\File comuni\Real\Update_OB\realsched.exe
    C:\Programmi\Java\jre1.6.0_02\bin\bak\jusched.exe | C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe


    clicca su Done => sul semaforo => due volte si => dovrebbe riavviarsi il pc da solo, altrimenti riavvialo tu.
    posta il log di avenger, il report di Find AWF e il log di hijackthis.

  4. #4
    Utente di HTML.it
    Registrato dal
    Oct 2007
    Messaggi
    17
    fatto tutto ecco qui:
    Avenger Pre-Processor log

    Syntax error in line. Line will be ignored.
    Error code: 0
    Line: C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe |


    Syntax error in line --- invalid file move request. Line will be ignored.
    Error code: 0
    Line: C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe


    Error: could not create zip file.
    Error code: 0


    //////////////////////////////////////////


    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Service s\wmdueium

    *******************

    Script file located at: \??\C:\Program Files\wmnohhqc.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:



    Could not open file C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe for deletion
    Deletion of file C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe failed!

    Could not process line:
    C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\CREATOR\Remind_XP.exe for deletion
    Deletion of file C:\WINDOWS\CREATOR\Remind_XP.exe failed!

    Could not process line:
    C:\WINDOWS\CREATOR\Remind_XP.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\SMINST\RECGUARD.EXE for deletion
    Deletion of file C:\WINDOWS\SMINST\RECGUARD.EXE failed!

    Could not process line:
    C:\WINDOWS\SMINST\RECGUARD.EXE
    Status: 0xc000003a



    Could not open file C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe for deletion
    Deletion of file C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe failed!

    Could not process line:
    C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP\HP Software Update\HPwuSchd2.exe for deletion
    Deletion of file C:\Programmi\HP\HP Software Update\HPwuSchd2.exe failed!

    Could not process line:
    C:\Programmi\HP\HP Software Update\HPwuSchd2.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe for deletion
    Deletion of file C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe failed!

    Could not process line:
    C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Sony\SonicStage\bak\SsAAD.exe for deletion
    Deletion of file C:\Programmi\Sony\SonicStage\bak\SsAAD.exe failed!

    Could not process line:
    C:\Programmi\Sony\SonicStage\bak\SsAAD.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe for deletion
    Deletion of file C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe failed!

    Could not process line:
    C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe for deletion
    Deletion of file C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe failed!

    Could not process line:
    C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe for deletion
    Deletion of file C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe failed!

    Could not process line:
    C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP DigitalMedia Archive\bak\DMAScheduler.exe for move operation
    File move operation C:\Programmi\HP DigitalMedia Archive\bak\DMAScheduler.exe|C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe failed!

    Could not process line:
    C:\Programmi\HP DigitalMedia Archive\bak\DMAScheduler.exe|C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\CREATOR\bak\Remind_XP.exe for move operation
    File move operation C:\WINDOWS\CREATOR\bak\Remind_XP.exe|C:\WINDOWS\CR EATOR\Remind_XP.exe failed!

    Could not process line:
    C:\WINDOWS\CREATOR\bak\Remind_XP.exe|C:\WINDOWS\CR EATOR\Remind_XP.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\SMINST\bak\RECGUARD.EXE for move operation
    File move operation C:\WINDOWS\SMINST\bak\RECGUARD.EXE|C:\WINDOWS\SMIN ST\RECGUARD.EXE failed!

    Could not process line:
    C:\WINDOWS\SMINST\bak\RECGUARD.EXE|C:\WINDOWS\SMIN ST\RECGUARD.EXE
    Status: 0xc000003a



    Could not open file C:\Programmi\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe for move operation
    File move operation C:\Programmi\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe|C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe failed!

    Could not process line:
    C:\Programmi\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe|C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP\HP Software Update\bak\HPwuSchd2.exe for move operation
    File move operation C:\Programmi\HP\HP Software Update\bak\HPwuSchd2.exe|C:\Programmi\HP\HP Software Update\HPwuSchd2.exe failed!

    Could not process line:
    C:\Programmi\HP\HP Software Update\bak\HPwuSchd2.exe|C:\Programmi\HP\HP Software Update\HPwuSchd2.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Intel\Intel Matrix Storage Manager\bak\iaanotif.exe for move operation
    File move operation C:\Programmi\Intel\Intel Matrix Storage Manager\bak\iaanotif.exe|C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe failed!

    Could not process line:
    C:\Programmi\Intel\Intel Matrix Storage Manager\bak\iaanotif.exe|C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Sony\SonicStage\bak\SsAAD.exe for move operation
    File move operation C:\Programmi\Sony\SonicStage\bak\SsAAD.exe|C:\Prog rammi\Sony\SonicStage\bak\SsAAD.exe failed!

    Could not process line:
    C:\Programmi\Sony\SonicStage\bak\SsAAD.exe|C:\Prog rammi\Sony\SonicStage\bak\SsAAD.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\bak\hphupd08.exe for move operation
    File move operation C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\bak\hphupd08.exe|C:\Programmi\HP\Dig ital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe failed!

    Could not process line:
    C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\bak\hphupd08.exe|C:\Programmi\HP\Dig ital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Java\jre1.5.0_11\bin\bak\jusched.exe for move operation
    File move operation C:\Programmi\Java\jre1.5.0_11\bin\bak\jusched.exe| C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe failed!

    Could not process line:
    C:\Programmi\Java\jre1.5.0_11\bin\bak\jusched.exe| C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
    Status: 0xc000003a



    File C:\WINDOWS\UpdReg.EXE not found!
    Deletion of file C:\WINDOWS\UpdReg.EXE failed!

    Could not process line:
    C:\WINDOWS\UpdReg.EXE
    Status: 0xc0000034


    Completed script processing.

    *******************

    Finished! Terminate.//////////////////////////////////////////


    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Service s\apycmxcn

    *******************

    Script file located at: \??\C:\Documents and Settings\mldwxpeb.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:



    Could not open file C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe for deletion
    Deletion of file C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe failed!

    Could not process line:
    C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\CREATOR\Remind_XP.exe for deletion
    Deletion of file C:\WINDOWS\CREATOR\Remind_XP.exe failed!

    Could not process line:
    C:\WINDOWS\CREATOR\Remind_XP.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\SMINST\RECGUARD.EXE for deletion
    Deletion of file C:\WINDOWS\SMINST\RECGUARD.EXE failed!

    Could not process line:
    C:\WINDOWS\SMINST\RECGUARD.EXE
    Status: 0xc000003a



    Could not open file C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe for deletion
    Deletion of file C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe failed!

    Could not process line:
    C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
    Status: 0xc000003a


    ------continua-------

  5. #5
    Utente di HTML.it
    Registrato dal
    Oct 2007
    Messaggi
    17
    -------continua-----



    Could not open file C:\Programmi\HP\HP Software Update\HPwuSchd2.exe for deletion
    Deletion of file C:\Programmi\HP\HP Software Update\HPwuSchd2.exe failed!

    Could not process line:
    C:\Programmi\HP\HP Software Update\HPwuSchd2.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe for deletion
    Deletion of file C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe failed!

    Could not process line:
    C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Sony\SonicStage\bak\SsAAD.exe for deletion
    Deletion of file C:\Programmi\Sony\SonicStage\bak\SsAAD.exe failed!

    Could not process line:
    C:\Programmi\Sony\SonicStage\bak\SsAAD.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe for deletion
    Deletion of file C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe failed!

    Could not process line:
    C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe for deletion
    Deletion of file C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe failed!

    Could not process line:
    C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe for deletion
    Deletion of file C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe failed!

    Could not process line:
    C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP DigitalMedia Archive\bak\DMAScheduler.exe for move operation
    File move operation C:\Programmi\HP DigitalMedia Archive\bak\DMAScheduler.exe|C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe failed!

    Could not process line:
    C:\Programmi\HP DigitalMedia Archive\bak\DMAScheduler.exe|C:\Programmi\HP DigitalMedia Archive\DMAScheduler.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\CREATOR\bak\Remind_XP.exe for move operation
    File move operation C:\WINDOWS\CREATOR\bak\Remind_XP.exe|C:\WINDOWS\CR EATOR\Remind_XP.exe failed!

    Could not process line:
    C:\WINDOWS\CREATOR\bak\Remind_XP.exe|C:\WINDOWS\CR EATOR\Remind_XP.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\SMINST\bak\RECGUARD.EXE for move operation
    File move operation C:\WINDOWS\SMINST\bak\RECGUARD.EXE|C:\WINDOWS\SMIN ST\RECGUARD.EXE failed!

    Could not process line:
    C:\WINDOWS\SMINST\bak\RECGUARD.EXE|C:\WINDOWS\SMIN ST\RECGUARD.EXE
    Status: 0xc000003a



    Could not open file C:\Programmi\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe for move operation
    File move operation C:\Programmi\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe|C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe failed!

    Could not process line:
    C:\Programmi\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe|C:\Programmi\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP\HP Software Update\bak\HPwuSchd2.exe for move operation
    File move operation C:\Programmi\HP\HP Software Update\bak\HPwuSchd2.exe|C:\Programmi\HP\HP Software Update\HPwuSchd2.exe failed!

    Could not process line:
    C:\Programmi\HP\HP Software Update\bak\HPwuSchd2.exe|C:\Programmi\HP\HP Software Update\HPwuSchd2.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Intel\Intel Matrix Storage Manager\bak\iaanotif.exe for move operation
    File move operation C:\Programmi\Intel\Intel Matrix Storage Manager\bak\iaanotif.exe|C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe failed!

    Could not process line:
    C:\Programmi\Intel\Intel Matrix Storage Manager\bak\iaanotif.exe|C:\Programmi\Intel\Intel Matrix Storage Manager\iaanotif.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\Sony\SonicStage\bak\SsAAD.exe for move operation
    File move operation C:\Programmi\Sony\SonicStage\bak\SsAAD.exe|C:\Prog rammi\Sony\SonicStage\bak\SsAAD.exe failed!

    Could not process line:
    C:\Programmi\Sony\SonicStage\bak\SsAAD.exe|C:\Prog rammi\Sony\SonicStage\bak\SsAAD.exe
    Status: 0xc000003a



    Could not open file C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\bak\hphupd08.exe for move operation
    File move operation C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\bak\hphupd08.exe|C:\Programmi\HP\Dig ital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe failed!

    Could not process line:
    C:\Programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\bak\hphupd08.exe|C:\Programmi\HP\Dig ital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    Status: 0xc000003a

    Could not open file C:\Programmi\Java\jre1.5.0_11\bin\bak\jusched.exe for move operation
    File move operation C:\Programmi\Java\jre1.5.0_11\bin\bak\jusched.exe| C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe failed!

    Could not process line:
    C:\Programmi\Java\jre1.5.0_11\bin\bak\jusched.exe| C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
    Status: 0xc000003a

    Completed script processing.
    *******************
    Finished! Terminate.

  6. #6
    Utente di HTML.it
    Registrato dal
    Oct 2007
    Messaggi
    17
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10.27.09, on 20/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Programmi\SolidDocuments\SolidConverterPDF\SCPD F\SolidPdfService.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmi\Virtual CD v4 SDK\system\vcssecs.exe
    C:\WINDOWS\Explorer.EXE
    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Programmi\DAEMON Tools\daemon.exe
    C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\mioengine.exe
    C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
    C:\Documents and Settings\Andrea\Desktop\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bi...e=6&key=SEARCH
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.d ll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
    O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Programmi\SolidDocuments\SolidConverterPDF\SCPD F\ExploreExtPDF.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Programmi\SolidDocuments\SolidConverterPDF\SCPD F\ExploreExtPDF.dll
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.d ll
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe "
    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [PCMService] "c:\apps\Powercinema\PCMService.exe"
    O4 - HKLM\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [StartCCC] "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: C6 Messenger.lnk = C:\Programmi\C6 Messenger\c6Messenger.exe
    O4 - Startup: My Vodafone.it.lnk = C:\Documents and Settings\Andrea\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio
    O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\it.htm
    O16 - DPF: {4D21BDFC-A621-4DE6-87DA-7C952D0ADF7E} (P00RecImageCtrl Class) - http://87.28.114.25:8000/push03.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/re...s/MSNPUpld.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab
    O16 - DPF: {8A96EAE5-D262-4226-A517-304C88B53F1F} (ProfileAccessCtrl Class) - http://87.28.114.25:8000/access01.cab
    O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} (DownloaderActiveX Control) - http://c6.community.alice.it/downloa...derActiveX.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
    O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Programmi\SolidDocuments\SolidConverterPDF\SCPD F\SolidPdfService.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Programmi\Virtual CD v4 SDK\system\vcssecs.exe

    --
    End of file - 9104 bytes

  7. #7
    Utente di HTML.it
    Registrato dal
    Oct 2007
    Messaggi
    17
    Find AWF report by noahdfear ©2006
    Version 1.40



    bak folders found
    ~~~~~~~~~~~

    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\APPS\ABOARD\BAK

    02/05/2003 11.31 24.576 ABoard.exe
    1 File 24.576 byte
    2 Directory 43.240.189.952 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\APPS\POWERC~1\BAK

    08/10/2004 04.14 81.920 PCMService.exe
    1 File 81.920 byte
    2 Directory 43.240.189.952 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\ATITEC~1\ATICON~1\BAK

    21/04/2004 22.10 335.872 atiptaxx.exe
    1 File 335.872 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\DAEMON~1\BAK

    12/11/2006 12.48 157.592 daemon.exe
    1 File 157.592 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\QUICKT~1\BAK

    16/02/2007 10.54 282.624 qttask.exe
    1 File 282.624 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\WINDOWS\SYSTEM32\BAK

    20/08/2004 00.39 15.360 ctfmon.exe
    1 File 15.360 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\GRISOFT\AVG7\BAK

    13/09/2007 16.35 421.888 avgcc.exe
    1 File 421.888 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\MACROG~1\SWEETIM\BAK

    27/12/2006 16.53 73.840 SweetIM.exe
    1 File 73.840 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\NOKIA\NOKIAP~1\BAK

    18/06/2007 15.10 271.360 LaunchApplication.exe
    1 File 271.360 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\ADOBE\ACROBA~2.0\READER\BAK

    30/03/2006 17.45 313.472 AdobeUpdateManager.exe
    1 File 313.472 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\FILECO~1\AHEAD\LIB\BAK

    01/03/2007 15.57 153.136 NeroCheck.exe
    1 File 153.136 byte
    2 Directory 43.240.185.856 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\FILECO~1\REAL\UPDATE~1\BAK

    26/02/2007 20.03 180.269 realsched.exe
    1 File 180.269 byte
    2 Directory 43.240.181.760 byte disponibili
    Il volume nell'unit… C Š HDD
    Numero di serie del volume: A08F-9E0B

    Directory di C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

    12/07/2007 04.00 132.496 jusched.exe
    1 File 132.496 byte
    2 Directory 43.240.181.760 byte disponibili


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    27660 8 Oct 2007 "C:\APPS\ABOARD\ABoard.exe"
    24576 2 May 2003 "C:\APPS\ABOARD\bak\ABoard.exe"
    27660 8 Oct 2007 "C:\APPS\Powercinema\PCMService.exe"
    81920 8 Oct 2004 "C:\APPS\Powercinema\bak\PCMService.exe"
    27660 8 Oct 2007 "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    335872 21 Apr 2004 "C:\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
    171464 18 Sep 2007 "C:\Programmi\DAEMON Tools\daemon.exe"
    157592 12 Nov 2006 "C:\Programmi\DAEMON Tools\bak\daemon.exe"
    27660 8 Oct 2007 "C:\Programmi\QuickTime\qttask.exe"
    282624 16 Feb 2007 "C:\Programmi\QuickTime\bak\qttask.exe"
    15360 20 Aug 2004 "C:\WINDOWS\system32\ctfmon.exe"
    15360 20 Aug 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
    421888 10 Oct 2007 "C:\Programmi\Grisoft\AVG7\avgcc.exe"
    421888 13 Sep 2007 "C:\Programmi\Grisoft\AVG7\bak\avgcc.exe"
    27660 8 Oct 2007 "C:\Programmi\Macrogaming\SweetIM\SweetIM.exe"
    73840 27 Dec 2006 "C:\Programmi\Macrogaming\SweetIM\bak\SweetIM. exe"
    271360 18 Jun 2007 "C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe"
    271360 18 Jun 2007 "C:\Programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe"
    27660 8 Oct 2007 "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe"
    313472 30 Mar 2006 "C:\Programmi\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe"
    27660 8 Oct 2007 "C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe"
    153136 1 Mar 2007 "C:\Programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe"
    27660 8 Oct 2007 "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"
    180269 26 Feb 2007 "C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe"
    32881 23 Feb 2004 "C:\Programmi\Java\j2re1.4.2_04\bin\jusched.ex e"
    49263 9 Nov 2006 "C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe "
    83608 14 Mar 2007 "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe "
    27660 8 Oct 2007 "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe "
    132496 12 Jul 2007 "C:\Programmi\Java\jre1.6.0_02\bin\bak\jusched.exe "


    end of report


    grazie dell'aiuto

  8. #8
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    scusa... ma sei sicuro di aver inserito lo script fatto per te?
    ..no perchè vedo tutte cose che non c'entrano! guarda:

    Could not open file C:\Programmi\Pinnacle\Shared Files\Programs\MediaCenterService\bak\PMC.Service. Main.exe for deletion
    oppure
    Could not open file C:\WINDOWS\CREATOR\bak\Remind_XP.exe for move operation
    File move operation :\WINDOWS\CREATOR\bak\Remind_XP.exe|C:\WINDOWS\CRE ATOR\Remind_XP.exe failed!

    non sono i comandi che ti ho inserito io!!
    Rifai tutto nuovamente a partire da avenger. Salva i risultati dello script, aprili e confrontali con quelli vecchi: se sono uguali ti fermi.. altrimenti vai avanti come richiesto.

  9. #9
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    Hai inserito lo script di quest'altro thread http://forum.html.it/forum/showthrea...readid=1171438
    Ci vuole l'arte anche in questo...

  10. #10
    Utente di HTML.it
    Registrato dal
    Oct 2007
    Messaggi
    17
    rifaccio tutto:

    //////////////////////////////////////////
    Avenger Pre-Processor log
    //////////////////////////////////////////

    Error: could not create zip file.
    Error code: 0


    //////////////////////////////////////////


    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Service s\rykbqbft

    *******************

    Script file located at: \??\C:\Program Files\edvqdbil.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    File C:\APPS\ABOARD\ABoard.exe deleted successfully.
    File C:\APPS\Powercinema\PCMService.exe deleted successfully.
    File C:\ATI Technologies\ATI Control Panel\atiptaxx.exe deleted successfully.
    File C:\Programmi\DAEMON Tools\daemon.exe deleted successfully.
    File C:\Programmi\QuickTime\qttask.exe deleted successfully.
    File C:\WINDOWS\system32\ctfmon.exe deleted successfully.
    File C:\Programmi\Grisoft\AVG7\avgcc.exe deleted successfully.
    File C:\Programmi\Macrogaming\SweetIM\SweetIM.exe deleted successfully.
    File C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe deleted successfully.
    File C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe deleted successfully.
    File C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe deleted successfully.
    File C:\Programmi\File comuni\Real\Update_OB\realsched.exe deleted successfully.
    File C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe deleted successfully.
    File move operation C:\APPS\ABOARD\bak\ABoard.exe|C:\APPS\ABOARD\ABoar d.exe completed successfully.
    File move operation C:\APPS\Powercinema\bak\PCMService.exe|C:\APPS\Pow ercinema\PCMService.exe completed successfully.
    File move operation C:\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe|C:\ATI Technologies\ATI Control Panel\atiptaxx.exe completed successfully.
    File move operation C:\Programmi\DAEMON Tools\bak\daemon.exe|C:\Programmi\DAEMON Tools\daemon.exe completed successfully.
    File move operation C:\Programmi\QuickTime\bak\qttask.exe|C:\Programmi \QuickTime\qttask.exe completed successfully.
    File move operation C:\WINDOWS\system32\bak\ctfmon.exe|C:\WINDOWS\syst em32\ctfmon.exe completed successfully.
    File move operation C:\Programmi\Grisoft\AVG7\bak\avgcc.exe|C:\Program mi\Grisoft\AVG7\avgcc.exe completed successfully.
    File move operation C:\Programmi\Macrogaming\SweetIM\bak\SweetIM.exe|C :\Programmi\Macrogaming\SweetIM\SweetIM.exe completed successfully.
    File move operation C:\Programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe|C:\Programmi\Nokia\Nok ia PC Suite 6\LaunchApplication.exe completed successfully.
    File move operation C:\Programmi\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe|C:\Programmi \Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe completed successfully.
    File move operation C:\Programmi\File comuni\Ahead\Lib\bak\NeroCheck.exe|C:\Programmi\Fi le comuni\Ahead\Lib\NeroCheck.exe completed successfully.
    File move operation C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe|C:\Program mi\File comuni\Real\Update_OB\realsched.exe completed successfully.
    File move operation C:\Programmi\Java\jre1.6.0_02\bin\bak\jusched.exe| C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe completed successfully.

    Completed script processing.

    *******************

    Finished! Terminate.

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved.