Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

perfavoremi controllate il logo hijackthis Opzioni
carducci
Inviato: Thursday, October 20, 2011 8:06:00 PM
Rank: AiutAmico

Iscritto dal : 12/29/2005
Posts: 479
mi controllate perfavore il logo
prima di postare il logo ho fatto tutti i controlli con Malwarebytes' Anti-Malware e con antivirus .
il problema è il computer lento e l'apertura delle pagine web è molto lenta.
uso fastweb
grazie


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19.53.42, on 20/10/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\Programmi\Microsoft Security Client\Antimalware\MsMpEng.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
F:\Programmi\Java\jre6\bin\jqs.exe
F:\Programmi\Microsoft LifeCam\MSCamS32.exe
F:\Programmi\PC Tools Firewall Plus\FWService.exe
F:\WINDOWS\system32\svchost.exe
F:\Programmi\File comuni\Acronis\Fomatik\TrueImageTryStartService.exe
F:\Programmi\Microsoft Security Client\msseces.exe
F:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
F:\WINDOWS\system32\RUNDLL32.EXE
F:\WINDOWS\vVX1000.exe
F:\Programmi\Microsoft IntelliPoint\ipoint.exe
F:\Programmi\PC Tools Firewall Plus\FirewallGUI.exe
F:\Programmi\Windows Live\Messenger\msnmsgr.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Programmi\Glary Utilities\memdefrag.exe
F:\Programmi\Skype\Phone\Skype.exe
F:\Programmi\SlimDrivers\SlimDrivers.exe
F:\Programmi\Windows Live\Contacts\wlcomm.exe
F:\Programmi\Mozilla Firefox\firefox.exe
F:\WINDOWS\system32\msiexec.exe
F:\Programmi\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {f24df03f-d7f1-40b8-a63a-9d2be4908f39} - F:\Programmi\Maps4PC_0c\bar\1.bin\0cSrcAs.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - F:\Programmi\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Programmi\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - F:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {32bfba07-b1fc-4764-bc21-4af8c6188ca5} - (no file)
O4 - HKLM\..\Run: [NeroFilterCheck] F:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MSC] "F:\Programmi\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [ISUSScheduler] "F:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] F:\Programmi\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [VX1000] F:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [IntelliPoint] "F:\Programmi\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [00PCTFW] "F:\Programmi\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKCU\..\Run: [msnmsgr] "F:\Programmi\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Glary Memory Optimizer] "F:\Programmi\Glary Utilities\memdefrag.exe" /autostart
O4 - HKCU\..\Run: [Skype] "F:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [UpdateMyDrivers] F:\Programmi\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe /ot /as /ss
O4 - HKCU\..\Run: [SlimDrivers] "F:\Programmi\SlimDrivers\SlimDrivers.exe" -boot
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: &Search - http://tbedits.mywebsearch.com/one-toolbaredits/menusearch.jhtml?s=200401157&p=YWxdm009YYit&si=maps4pc&a=A5B06B34-4E10-482F-BA8E-AD49E7EBF43B&n=2011091717
O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://F:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Anteprima Easy-WebPrint - res://F:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://F:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://F:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Stampa Easy-WebPrint - res://F:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: f:\windows\system32\nwprovau.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\Programmi\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - F:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - F:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - F:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - Unknown owner - F:\Programmi\PC Tools Firewall Plus\FWService.exe
O23 - Service: ServiceLayer - Nokia - F:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - F:\Programmi\File comuni\Acronis\Fomatik\TrueImageTryStartService.exe

--
End of file - 8079 bytes
Sponsor
Inviato: Thursday, October 20, 2011 8:06:00 PM

 
cbbusto
Inviato: Thursday, October 20, 2011 11:08:56 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Chiudi tutti i programmi e disconnesso, apri HJT fixa ed elimina queste voci:

R3 - URLSearchHook: (no name) - {f24df03f-d7f1-40b8-a63a-9d2be4908f39} - F:\Programmi\Maps4PC_0c\bar\1.bin\0cSrcAs.dll (file missing)

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file

O3 - Toolbar: (no name) - {32bfba07-b1fc-4764-bc21-4af8c6188ca5} - (no file)

O4 - HKCU\..\Run: [UpdateMyDrivers] F:\Programmi\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe /ot /as /ss

O4 - HKCU\..\Run: [SlimDrivers] "F:\Programmi\SlimDrivers\SlimDrivers.exe" -boot

O8 - Extra context menu item: &Search - http://tbedits.mywebsearch.com/one-toolbaredits/menusearch.jhtml?s=200401157&p=Y Wxdm009YYit&si=maps4pc&a=A5B06B34-4E10-482F-BA8E-AD49E7EBF43B&n=2011091717

Visto che usi MSE la protezione in tempo reale di Spybot non serve, ecco quanto afferma la Microsoft:
Disattivare il controllo in tempo reale di ogni altra applicazione antispyware (SpyBot S&D Resident, Ad-aware Ad-watch, ecc.). MSE dispone di un proprio modulo per il controllo antispyware.
Con Malwarebytes hai fatto una scansione completa ed hai aggiornato il sw ? altrimenti rifalla.
Fai una pulizia con Ccleaner compreso il registro.
Vai nella cartella di windows, cerca la cartella Prefetch e la svuoti completamente.
Tieni deframmentato il disco fisso.
Fai sapere. Ciao
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.