Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

LOGfile di HijackThis Opzioni
rafapaz
Inviato: Friday, March 04, 2005 5:41:58 PM
Rank: Member

Iscritto dal : 2/17/2005
Posts: 0
Innanzitutto vi ringrazio per la disponibilità ma, nonostante io abbia letto e applicato le istruzioni indicate nell''articolo:
--http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=160&SH=N--,
il problema della non-navigabilità rimane; quindi provo la seconda soluzione propostami.
Questo è il mio LOG.
Grazie mille


Logfile of HijackThis v1.99.1
Scan saved at 14.13.58, on 04/03/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\Programmi\ATI Technologies\Pannello di controllo ATI\atiptaxx.exe C:\WINDOWS\soundman.exe C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\Classic PhoneTools\CapFax.EXE C:\WINDOWS\SOINTGR.EXE C:\Programmi\IPM\Adsl\DataWay\dslstat.exe
C:\WINDOWS\system32\dslagent.exe
C:\Programmi\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\WINDOWS\System32\wsxsvc\wsxsvc.exe
C:\WINDOWS\System32\vmss\vmss.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Corel\Graphics8\programs\MFIndexer.exe
C:\Programmi\EzButton System V2.1\Ezbutton.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\Web_Cpr\WebCpr0.exe C:\Programmi\Web_Rebates\WebRebates0.exe
C:\Programmi\Web_Cpr\WebCpr1.exe
C:\Programmi\Web_Rebates\WebRebates1.exe
C:\DOCUME~1\RAFFAE~1\IMPOST~1\Temp\Directory temporanea 4 per hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tiscali.it
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.topfivesearch.com/sidesearch.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.usefulware.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: PowerSearch - {4E7BD74F-2B8D-469E-A3EE-FB7FA682AA7D} - C:\Programmi\PowerSearch\Toolbar\pwrsdfp\pwrsdp1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Band Class - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - C:\WINDOWS\AdRoar.dll (file missing)
O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-A3EE-FB7FA682AA7D} - C:\Programmi\PowerSearch\Toolbar\pwrsdfp\pwrsdp1.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [CapFax] C:\Programmi\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE
O4 - HKLM\..\Run: [System Service] C:\WINDOWS\System32\msrexe.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Programmi\IPM\Adsl\DataWay\dslstat.exe
icon
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [AST] C:\WINDOWS\AST
O4 - HKLM\..\Run: [PGStub.exe]
C:\DOCUME~1\RAFFAE~1\IMPOST~1\Temp\g181511.exe
O4 - HKLM\..\Run: [AStart] C:\WINDOWS\AStart
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Programmi\MUSICMATCH\MUSICMATCH
Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [WindowsRegKey update] Windowsup.exe
O4 - HKLM\..\Run: [Windows Registers] Svchosters.exe
O4 - HKLM\..\Run: [Local Service] rundll.exe
O4 - HKLM\..\Run: [Microsoft Update Machine] wininigo.exe
O4 - HKLM\..\Run: [System Config Manager] smssl.exe
O4 - HKLM\..\Run: [Microsofts Updates] wuamgrd.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Programmi\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [WebCpr0] "C:\Programmi\Web_Cpr\WebCpr0.exe"
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Programmi\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\System32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINDOWS\System32\vmss\vmss.exe
O4 - HKLM\..\RunServices: [WindowsRegKey update] Windowsup.exe
O4 - HKLM\..\RunServices: [Windows Registers] Svchosters.exe
O4 - HKLM\..\RunServices: [Local Service] rundll.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] wininigo.exe
O4 - HKLM\..\RunServices: [System Config Manager] smssl.exe
O4 - HKLM\..\RunServices: [Microsofts Updates] wuamgrd.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [iedll] c:\WINDOWS\iedll.exe
O4 - HKCU\..\Run: [WKAJPKVEEFGTSY] C:\WINDOWS\UBVSUQWWAYOTJ.exe
O4 - HKCU\..\Run: [WindowsRegKey update] Windowsup.exe
O4 - HKCU\..\Run: [Windows Registers] Svchosters.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] wininigo.exe
O4 - HKCU\..\Run: [Local Service] rundll.exe
O4 - HKCU\..\Run: [Microsofts Updates] wuamgrd.exe
O4 - Startup: EzButton System.lnk = C:\Programmi\EzButton System V2.1\Ezbutton.exe
O4 - Startup: Update Grokster.lnk = C:\Programmi\Grokster\WiseUpdt.exe
O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\programs\MFIndexer.exe
O8 - Extra context menu item: Grokster Support - file://C:\Programmi\GroksterSupport\System\Temp\grokstershop_script0.htm
O8 - Extra context menu item: SirSearch - file://C:\Programmi\PWRSDP1\Cache\SelectedContextSearch.htm
O8 - Extra context menu item: Web Rebates - file://C:\Programmi\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: (no name) - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\td.exe (file missing)
O9 - Extra ''Tools'' menuitem: MaxSpeed - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\td.exe (file
missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider ''c:\windows\system32\lspak.dll'' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.it
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://xxxtrayicon.com/xtrayinst.exe
O16 - DPF: {15320607-1001-1831-1000-118599957123} - ms-its:mhtml:file://C:\path.mht!http://64.200.25.86/hzrhjcm/bzltjpu/aimzcu
v/jkrlhq/arct.chm::/painter.exe
O16 - DPF: {2048B51E-8D74-4762-82CE-B48CF545EEEA} - http://movie.cinemastream.net/sc.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus
scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/BM2/BM2.dll
O20 - Winlogon Notify: Guardian - C:\WINDOWS\system32\msg117.dll (file
missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programmi\File comuni\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
Sponsor
Inviato: Friday, March 04, 2005 5:41:58 PM

 
alfonso
Inviato: Friday, March 04, 2005 8:24:42 PM

Rank: AiutAmico

Iscritto dal : 10/5/2000
Posts: 19,132
Ciao ,
esegui queste operazioni

1) Disattiva il ripristino di configurazione, leggi qui come fare
http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=257&SH=N

2) riavvia in modalità provvisoria, leggi qui come fare
http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=344&SH=N

apri HIJAC THIS ed elimina come indicato in questo articolo
http://www.aiutamici.com/software/descrizione.asp?CodSw=1175
le righe che seguono, (nel caso le righe da eliminare non compaiono in modalità provvisoria, eliminale dalla modalità normale e riavvia il computer).

==================================
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 -
-
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.topfivesearch.com/sidesearch.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.usefulware.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0 R0 -
-
R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: PowerSearch - {4E7BD74F-2B8D-469E-A3EE-FB7FA682AA7D} - C:\Programmi\PowerSearch\Toolbar\pwrsdfp\pwrsdp1.dll
-
O3 - Toolbar: Band Class - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - C:\WINDOWS\AdRoar.dll (file missing)
O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-A3EE-FB7FA682AA7D} - C:\Programmi\PowerSearch\Toolbar\pwrsdfp\pwrsdp1.dll
-
O4 - HKLM\..\Run: [System Service] C:\WINDOWS\System32\msrexe.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
-
O4 - HKLM\..\Run: [AST] C:\WINDOWS\AST
O4 - HKLM\..\Run: [PGStub.exe]
C:\DOCUME~1\RAFFAE~1\IMPOST~1\Temp\g181511.exe
O4 - HKLM\..\Run: [AStart] C:\WINDOWS\AStart
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe
-
O4 - HKLM\..\Run: [WindowsRegKey update] Windowsup.exe
O4 - HKLM\..\Run: [Windows Registers] Svchosters.exe
-
O4 - HKLM\..\Run: [Microsoft Update Machine] wininigo.exe
O4 - HKLM\..\Run: [System Config Manager] smssl.exe
O4 - HKLM\..\Run: [Microsofts Updates] wuamgrd.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Programmi\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [WebCpr0] "C:\Programmi\Web_Cpr\WebCpr0.exe"
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Programmi\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\System32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINDOWS\System32\vmss\vmss.exe
O4 - HKLM\..\RunServices: [WindowsRegKey update] Windowsup.exe
O4 - HKLM\..\RunServices: [Windows Registers] Svchosters.exe
-
O4 - HKLM\..\RunServices: [Microsoft Update Machine] wininigo.exe
O4 - HKLM\..\RunServices: [System Config Manager] smssl.exe
O4 - HKLM\..\RunServices: [Microsofts Updates] wuamgrd.exe
-
O4 - HKCU\..\Run: [iedll] c:\WINDOWS\iedll.exe
O4 - HKCU\..\Run: [WKAJPKVEEFGTSY] C:\WINDOWS\UBVSUQWWAYOTJ.exe
O4 - HKCU\..\Run: [WindowsRegKey update] Windowsup.exe
O4 - HKCU\..\Run: [Windows Registers] Svchosters.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] wininigo.exe
-
O4 - HKCU\..\Run: [Microsofts Updates] wuamgrd.exe
-
O9 - Extra button: (no name) - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\td.exe (file missing)
O9 - Extra ''Tools'' menuitem: MaxSpeed - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\td.exe (file missing)
-
O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider ''c:\windows\system32\lspak.dll'' missing
-
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://xxxtrayicon.com/xtrayinst.exe
O16 - DPF: {15320607-1001-1831-1000-118599957123} - ms-its:mhtml:file://C:\path.mht!http://64.200.25.86/hzrhjcm/bzltjpu/aimzcu
v/jkrlhq/arct.chm::/painter.exe
-
O20 - Winlogon Notify: Guardian - C:\WINDOWS\system32\msg117.dll (file
missing)
==================================

Con la funzione TROVA di Windows, cerca ed elimina questi file,

==================================
INCFIN~1.DLL
pwrsdp1.dll
AdRoar.dll
msrexe.exe
whSurvey.exe
PGStub.exe
g181511.exe
ARUpdate.exe
Windowsup.exe
Svchosters.exe
wininigo.exe
smssl.exe
wuamgrd.exe
WebRebates0.exe
WebCpr0.exe
BundleOuter.EXE
wsxsvc.exe
vmss.exe
iedll.exe
UBVSUQWWAYOTJ.exe
td.exe
lspak.dll
msg117.dll
==================================

<font color=red>Svuota</font id=red> la cartella C:\DOCUME~1\RAFFAE~1\IMPOST~1\<font color=red><b>Temp</font id=red></b>

al termine utilizza i programmi AD-AWARE e SPYBOT indicati in questo articolo
http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=388&SH=N

sempre in modalità provvisoria fai una scansione Antivirus

quindi riavvia il computer e controlla se il problema e risolto, se e tutto OK riattiva il ripristino configurazione disattivato all'inizio di questa procedura.

BLOCCO QUESTO FORUM PERCHé DA UNO DEI LINK VIENE CARICATO UN VIRUS - APRI UN NUOVO FORUM PER CONTINUARE IL DISCORSO.

Collaboratore Aiutamici
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.