Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

dialer Opzioni
lunanera-nera
Inviato: Friday, October 24, 2008 9:32:43 AM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
un amico ha un problemino di dialer si collega con la chiavetta della wind e il SO è vista come lo aiuto a elinarlo?
grazie
Sponsor
Inviato: Friday, October 24, 2008 9:32:43 AM

 
pidue
Inviato: Friday, October 24, 2008 3:30:22 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
Prima fagli scansionare il computer con antivirus e antispyware (SpyBot e Malwarebyte's Anti-Malware), se non risolve, posta un log.





lunanera-nera
Inviato: Saturday, October 25, 2008 10:56:19 AM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
con spybot l'ho fatta e anche con adware non ti dico quante migliaia di cose ha trovato...Brick wall
adesso provvedo a procurarmeli , ma mi chieedevo, sarà mica che quando glielo hanno consegnato c'era windows defender dentro?
grazie pidue
per curiosità, puoi dirmi di più su questo programma, al fine di spiegare alle amiche a cui lo consiglierò perchè installarlo?
ancora grazie
pidue
Inviato: Saturday, October 25, 2008 2:13:12 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
Windows Defender è un antispyware targato Microsoft. Buon programma, non ottimo, di serie con Vista, lo puoi sacricare se hai XP originale. Protegge in tempo reale, affiancalo a Malwarebyte's Anti-Malware, più efficace, che però scansiona solo a richiesta.



lunanera-nera
Inviato: Saturday, October 25, 2008 4:17:46 PM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
ecco perchè allora i loro pc hanno vista ok , io gli ho installato anche adware spybot e spybot blaster ... ho sbagliato? Pray
pidue
Inviato: Saturday, October 25, 2008 5:12:54 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
Puoi benissimo installare SpyBot e anche SpywareBlaster. Non vanno in conflitto con Defender. Lascia perdere Ad-ware. SpywareBlaster crea una blck list di siti assolutamante da evitare. Se hai un firewall è opportuno disattivare il Tea Timer di SpyBot. Leggi qui. Piuttosto, se hai Internet Explorer 7 installa l'estensione WOT, ti tiene lontana dai siti pericolosi se fai ricerche con Google. Lo scarichi da qui.
Ciao.



lunanera-nera
Inviato: Saturday, October 25, 2008 5:41:23 PM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
ok ma solo per vista o anche per xp?
mi sono sempre trovata bene con adware
pidue
Inviato: Saturday, October 25, 2008 5:54:09 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
WOT è un'estensione per Internet Explorer 7, funziona sia su Wp sia su Vista. Installo e poi lancia IE. In questo video lo vedi all'opera.
Se ti sei trovata bene con Ad-aware, allora tienilo.
Ciao.



lunanera-nera
Inviato: Sunday, October 26, 2008 6:39:26 PM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
niente continua ad apparire una cheda di mc fee che gli chiede di installare dei programmi , che faccio? grazie pidue
pidue
Inviato: Sunday, October 26, 2008 6:56:30 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
A questo punto urge una scansione con HijackThis e pubblicazione del log.
http://www.aiutamici.com/software?ID=11175



lunanera-nera
Inviato: Sunday, October 26, 2008 7:08:42 PM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
eccolo:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19.07.49, on 26/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Angelo 2467\AppData\Local\hpqjs.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Digisoft AntiDialer\AntiDialer.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Users\ANGELO~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\HSDPA USB MODEM\USB Modem.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.intl.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.intl.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\\PLFSetL.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [hpqjs] "c:\users\angelo 2467\appdata\local\hpqjs.exe" hpqjs
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Instant Access] C:\Windows\system32\nsinet.exe /res
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - Global Startup: Digisoft AntiDialer.lnk = C:\Program Files\Digisoft AntiDialer\AntiDialer.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{042E4062-3EF3-4AE4-83B0-26BD4800B3BD}: NameServer = 193.70.152.25 193.70.152.15
O17 - HKLM\System\CS1\Services\Tcpip\..\{042E4062-3EF3-4AE4-83B0-26BD4800B3BD}: NameServer = 193.70.152.25 193.70.152.15
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O23 - Service: McAfee Application Installer Cleanup (0270441225043168) (0270441225043168mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\027044~1.EXE
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10079 bytes
pidue
Inviato: Sunday, October 26, 2008 8:53:12 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
Fai bene attenzione a quello che devi fare:
Chiudi HijackThis in una cartella a lui dedicata (possibilmente non sul desktop), altrimenti perdi i backup;

Disattiva il Ripristino configurazione di Sistema ----- > Procedimento per Windows Vista. Start >> Pannello di controllo >> (doppio clic su) Sistema. Sul pannello di sinistra clicca su Protezione di sistema. Togli il segno di spunta dal dall'unità C. ( Quando accedi alla Protezione sistema è probabile che tu debba aspettare qualche attimo prima che si evidenzino le unità disco)
avvia in modalità provvisoria come qui descritto;

Avvia hijackthis, con tutte le applicazioni chiuse, premi su Do a system scan only , spunta ed elimina (fix checked) le seguenti righe:



O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM..Run: [PLFSetL] C:Windows\PLFSetL.exe
O4 - HKCU\..\Run: [Instant Access] C:\Windows\system32\nsinet.exe /res
O23 - Service: McAfee Application Installer Cleanup (0270441225043168) (0270441225043168mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\027044~1.EXE --- > questa è probabilmente la causa di quell'avviso



Start >> Inizia ricerca. Scrivi (o copia e incolla) la stringa %temp%, clicca su Ok, svuota la cartella temp e assicurati che sia svuotata.
Vai su Strumenti >> Opzioni Internet, elimina la cronologia, i files temporanei internet, i cookies;
svuota il cestino;

posta un log aggiornato e riferiscimi se i problemi sono risolti.
Se tutto è a posto crea un nuovo punto di ripristino.




lunanera-nera
Inviato: Sunday, October 26, 2008 10:11:07 PM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
fatto tutto ma non si apre piu defender ma si aprono lo stesso pagina di explorer con dei giochi , segue log e chiedo scusa se non risponderò presto ma ho problemi ad fare il login sul forum

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19.07.49, on 26/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Angelo 2467\AppData\Local\hpqjs.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Digisoft AntiDialer\AntiDialer.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Users\ANGELO~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\HSDPA USB MODEM\USB Modem.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.intl.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.intl.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\\PLFSetL.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [hpqjs] "c:\users\angelo 2467\appdata\local\hpqjs.exe" hpqjs
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Instant Access] C:\Windows\system32\nsinet.exe /res
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - Global Startup: Digisoft AntiDialer.lnk = C:\Program Files\Digisoft AntiDialer\AntiDialer.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{042E4062-3EF3-4AE4-83B0-26BD4800B3BD}: NameServer = 193.70.152.25 193.70.152.15
O17 - HKLM\System\CS1\Services\Tcpip\..\{042E4062-3EF3-4AE4-83B0-26BD4800B3BD}: NameServer = 193.70.152.25 193.70.152.15
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O23 - Service: McAfee Application Installer Cleanup (0270441225043168) (0270441225043168mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\027044~1.EXE
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10079 bytes
pidue
Inviato: Sunday, October 26, 2008 10:32:28 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
lunanera-nera ha scritto:
fatto tutto ma non si apre piu defender

Ti ho tolto due programmi dall'avvio automatico e un servizio che non c'entrano con Defender
Lancia di nuovo HijackThis in provvisoria, fixa questa riga:

O4 - HKCU\..\Run: [hpqjs] "c:\users\angelo 2467\appdata\local\hpqjs.exe" hpqjs
....................................................................................................................
Rimuovi il file in rosso:
_______________________________________
C:\Users\Angelo 2467\AppData\Local\hpqjs.exe
________________________________________
lunanera-nera ha scritto:

ma si aprono lo stesso pagina di explorer con dei giochi , segue log e chiedo scusa se non risponderò presto ma ho problemi ad fare il login sul forum


Questo me lo potevi dire prima.
Allora scarica Combofix , salvalo sul desktop, disabilita l'antivirus e chiudi la connessione a internet.
Lancialo in mod normale e segui scrupolosamente le istruzioni a video.
Al termine, verrà creato un log (C:\ComboFix.txt).

Pubblica il log di ComboFix e riferisci se il problema è risolto.




Rudewolf
Inviato: Monday, October 27, 2008 12:50:55 AM

Rank: AiutAmico

Iscritto dal : 5/2/2006
Posts: 6,184
Da parte di lunanera che ha problemi con il log-in:
Lo farò appena torna il mio amico e che adesso non mi fa usare ne reinstallare lo spyboot.
lunanera-nera
Inviato: Monday, October 27, 2008 4:35:35 PM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
rieccomi, grazie rudewolf .
per pidue il tuo ragionamento era giusto il malware gli ha trovato ben 11 problemi, quello di adesso è un problema diciamo nuovo e inoltre mi ha distrutto spybot e non me lo fa reinstallare.
comunque siccome il pc è di un amico appena lo porta di nuovo, riprovo come mi hai suggeratito grazie e ti faccio sapere ciao
lunanera-nera
Inviato: Sunday, November 02, 2008 4:32:23 PM

Rank: AiutAmico

Iscritto dal : 10/13/2006
Posts: 451
ecco il log .
l'antivirus non sono riuscita a disativarlo anzi per essere sincera non capisco neanche se ce lo abbia?
SEMBRA E DICO SEMBRA che abbiamo risolto, anzi hai risolto il problema del mio amico
GRAZIEEEEEEEEEEE

ComboFix 08-11-01.06 - Angelo 2467 2008-11-02 16.20.51.1 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1040.18.1848 [GMT 1:00]
Eseguito da: F:\ComboFix.exe
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Users\Angelo 2467\AppData\Local\hpqjs.dat
C:\Users\Angelo 2467\AppData\Local\hpqjs.exe
C:\Users\Angelo 2467\AppData\Local\hpqjs_nav.dat
C:\Users\Angelo 2467\AppData\Local\hpqjs_navps.dat
C:\Windows\dialerexe.ini
C:\Windows\system32\x64
C:\Windows\system32\x64\csnp2uvc.dll
C:\Windows\system32\x64\rsnpvc64.dll
C:\Windows\system32\x64\sncduvc.sys
C:\Windows\system32\x64\snp2uvc.sys
C:\Windows\system32\x64\vsnpvc64.dll

.
((((((((((((((((((((((((( Files Creati Da 2008-10-02 al 2008-11-02 )))))))))))))))))))))))))))))))))))
.

2008-10-28 22:44 . 2008-08-05 10:49 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-10-28 22:44 . 2008-08-05 10:49 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-10-28 22:44 . 2008-08-05 10:48 217,088 --a------ C:\Windows\System32\psisrndr.ax
2008-10-28 22:44 . 2008-08-05 10:48 177,664 --a------ C:\Windows\System32\mpg2splt.ax
2008-10-28 22:44 . 2008-08-05 10:48 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-10-28 22:42 . 2008-08-12 04:39 443,392 --a------ C:\Windows\System32\win32spl.dll
2008-10-28 22:42 . 2008-09-18 05:56 147,456 --a------ C:\Windows\System32\Faultrep.dll
2008-10-28 22:42 . 2008-09-18 05:56 125,952 --a------ C:\Windows\System32\wersvc.dll
2008-10-26 19:43 . 2008-10-26 19:43 <DIR> d-------- C:\Program Files\CCleaner
2008-10-26 19:07 . 2008-10-26 19:07 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-26 18:43 . 2008-10-26 18:43 <DIR> d-------- C:\Program Files\WOT
2008-10-26 17:20 . 2008-10-26 17:20 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-10-26 17:20 . 2007-09-04 17:56 164,352 --a------ C:\Windows\System32\unrar.dll
2008-10-26 17:20 . 2008-07-30 20:09 38 --a------ C:\Windows\avisplitter.ini
2008-10-26 17:18 . 2008-10-26 17:18 <DIR> d-------- C:\Users\Angelo 2467\AppData\Roaming\Malwarebytes
2008-10-26 17:18 . 2008-10-26 17:18 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-10-26 17:18 . 2008-10-26 17:18 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-10-26 17:18 . 2008-10-26 17:18 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-26 17:18 . 2008-10-22 16:10 38,496 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-26 17:18 . 2008-10-22 16:10 15,504 --a------ C:\Windows\System32\drivers\mbam.sys
2008-10-26 17:17 . 2008-10-26 17:17 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-10-19 19:38 . 2008-10-26 21:20 <DIR> d-------- C:\Program Files\Digisoft AntiDialer
2008-10-19 17:06 . 2008-10-26 21:24 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-10-19 17:06 . 2008-10-26 21:24 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-10-19 16:40 . 2008-10-20 19:53 <DIR> d-a------ C:\Users\All Users\TEMP
2008-10-19 16:40 . 2008-10-20 19:53 <DIR> d-a------ C:\ProgramData\TEMP
2008-10-19 16:40 . 2008-10-19 16:40 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-10-14 21:01 . 2008-10-02 02:32 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-10-14 21:01 . 2008-10-02 04:49 827,392 --a------ C:\Windows\System32\wininet.dll
2008-10-14 20:57 . 2008-09-18 03:16 2,032,640 --a------ C:\Windows\System32\win32k.sys
2008-10-14 20:53 . 2008-09-18 06:09 3,601,464 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-10-14 20:53 . 2008-09-18 06:09 3,549,240 --a------ C:\Windows\System32\ntoskrnl.exe
2008-10-14 20:50 . 2008-08-27 02:06 288,768 --a------ C:\Windows\System32\drivers\srv.sys
2008-10-12 16:14 . 2008-10-12 16:14 <DIR> d-------- C:\Users\Angelo 2467\AppData\Roaming\Lavasoft
2008-10-12 16:13 . 2008-10-12 16:13 <DIR> d-------- C:\Program Files\Lavasoft
2008-10-12 14:27 . 2008-10-12 14:27 <DIR> d-------- C:\Users\All Users\eMule

2008-10-12 14:27 . 2008-10-12 14:27 <DIR> d-------- C:\ProgramData\eMule
2008-10-12 12:22 . 2008-10-12 12:22 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-10-07 20:06 . 2008-10-07 20:06 <DIR> d-------- C:\Users\All Users\Office Genuine Advantage
2008-10-07 20:06 . 2008-10-07 20:06 <DIR> d-------- C:\ProgramData\Office Genuine Advantage
2008-10-04 21:48 . 2008-10-12 14:27 <DIR> d-------- C:\Program Files\eMule

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 15:14 --------- d-----w C:\Program Files\McAfee
2008-10-26 20:22 --------- d-----w C:\Program Files\Acer GameZone
2008-10-20 18:42 --------- d-----w C:\ProgramData\Microsoft Help
2008-10-15 12:51 --------- d-----w C:\Program Files\Windows Mail
2008-10-08 19:50 --------- d-----w C:\ProgramData\SiteAdvisor
2008-10-08 19:50 --------- d-----w C:\ProgramData\McAfee
2008-10-02 19:31 --------- d-----w C:\Program Files\Microsoft Works
2008-09-28 17:06 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-28 17:06 --------- d-----w C:\Program Files\Windows Live
2008-09-28 17:02 --------- d-----w C:\ProgramData\WLInstaller
2008-09-15 14:56 --------- d-----w C:\ProgramData\Yahoo!
2008-09-15 14:53 --------- d-----w C:\Program Files\Yahoo!
2008-09-15 13:59 --------- d-----w C:\Users\Angelo 2467\AppData\Roaming\Yahoo!
2008-09-11 19:27 --------- d-----w C:\Program Files\MSXML 4.0
2008-08-02 03:26 36,864 ----a-w C:\Windows\System32\cdd.dll
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 01:00 39472 --a------ C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 517632]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-02-29 4670704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 525360]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-10-10 1286144]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 40048]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-05 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-05 8534560]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-05 81920]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-10-17 768520]
"PlayMovie"="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2008-01-22 200704]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-07-21 159744]
"WarReg_PopUp"="C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"RtHDVCpl"="RtHDVCpl.exe" [2007-12-05 C:\Windows\RtHDVCpl.exe]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2008-04-15 535336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{51E1C875-B0C5-4683-9212-75193BE81FB0}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{4816E315-F2A5-4392-B633-FE257EFBC9AF}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B93445C-A457-418F-AE52-B10F07944ED8}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{69EF9026-E012-4ABA-A01F-9C3FDAA2F9D3}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{7996B80A-54DB-4164-B256-2A45760321ED}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{C164E460-7EDE-4F00-8D43-CBCE0DE4605A}"= C:\Program Files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{48546F2B-A5D1-460B-8F28-B922FAFC1283}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{41C6D27F-20B2-4CEC-B4BC-AB3BB40F0325}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{BB0F2513-424A-461C-9DF5-2D17BD04BE49}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{8AD35151-43C5-4B11-9C3B-883A41EB0C2A}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{6CBA6D23-243C-4258-B8C9-80E23DA0BB49}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{11C3F9DB-650C-45EE-9B23-C8E9C089CB59}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{94EAA713-53E9-4173-B7E7-F831C5E8D69D}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{C316B564-AC43-4040-A741-F4A8BB0451E3}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FD3A2B76-8079-44FD-9707-286F6DAD8728}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [2008-01-04 16:15 41456]
R2 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [2007-09-19 51200]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys [2007-05-16 32256]
S3 qcusbser;Mobile Connector USB Device for Legacy Serial Communication;C:\Windows\system32\DRIVERS\cmusbser.sys [2007-10-16 97408]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\.\ShowModem.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\.\ShowModem.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2de117eb-7de5-11dd-ba5f-001b38e3e8e1}]
\shell\AutoRun\command - G:\.\ShowModem.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'

2008-09-14 C:\Windows\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-04-15 C:\Windows\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORFÃOS REMOVIDOS - - - -

HKCU-Run-hpqjs - c:\users\angelo 2467\appdata\local\hpqjs.exe
HKLM-Run-eRecoveryService - (no file)


.
------- Supplementare di scansione -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.tiscali.it/
R0 -: HKLM-Main,Start Page = hxxp://it.intl.acer.yahoo.com
O18 -: Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-02 16:23:42
Windows 6.0.6001 Service Pack 1 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-11-02 16.24.53
ComboFix-quarantined-files.txt 2008-11-02 15:24:47

Pre-Run: 99.191.083.008 byte disponibili
Post-Run: 99,161,702,400 byte disponibili

188 --- E O F --- 2008-10-29 13:32:18
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.