Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

potreste controllarmi il log di HIJACK? Opzioni
Robson
Inviato: Wednesday, October 26, 2005 9:55:21 PM
Rank: Member

Iscritto dal : 10/26/2005
Posts: 0
Ciao Raga!
Ho un problema con un virus (popapoka ( ma poka di quella miseria!!)


Logfile of HijackThis v1.99.1
Scan saved at 21.35.19, on 26/10/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\winjava.exe
C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\atiptaxx.exe
C:\WINNT\System32\norten.pif
C:\WINNT\System32\hhs32.pif
C:\WINNT\System32\nbthlp.exe
C:\WINNT\System32\IEXPL0RE.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\hijackthis\HijackThis.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\Programmi\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\drwtsn32.exe
C:\WINNT\System32\hhs32.pif

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.msn.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1040,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll",AppEntry -REG "Aethra\ADSL EB1070 USB"
O4 - HKLM\..\Run: [KAVPersonal50] C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINNT\System32\iexplore.exe
O4 - HKLM\..\Run: [HTML32 Help System] hhs32.pif
O4 - HKLM\..\Run: [norten Software Intrenet ] norten.pif
O4 - HKLM\..\Run: [System service78] C:\WINNT\etb\pokapoka78.exe
O4 - HKLM\..\RunServices: [HTML32 Help System] hhs32.pif
O4 - HKLM\..\RunServices: [norten Software Intrenet ] norten.pif
O4 - HKCU\..\Run: [HTML32 Help System] hhs32.pif
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunServices: [HTML32 Help System] hhs32.pif
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://it.msn.com
O14 - IERESET.INF: MS_START_PAGE_URL=http://it.msn.com
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmi\ewido\security suite\ewidoctrl.exe
O23 - Service: Enables Java Support (Java) - Unknown owner - C:\WINNT\System32\winjava.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: NetBIOS Helper Service (NetBIOS Helper) - Unknown owner - C:\WINNT\System32\nbthlp.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe

Vi ringrazio raga per eventuali aiuti ,spero solo di essere capace id usare il programma!

Ciao!
Sponsor
Inviato: Wednesday, October 26, 2005 9:55:21 PM

 
alfonso
Inviato: Wednesday, October 26, 2005 10:05:36 PM

Rank: AiutAmico

Iscritto dal : 10/5/2000
Posts: 19,132
Ciao ,
esegui queste operazioni

riavvia in modalità provvisoria, leggi qui come fare
http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=344&SH=N

apri HIJAC THIS ed elimina come indicato in questo articolo
http://www.aiutamici.com/software/descrizione.asp?CodSw=1175
le righe che seguono, (nel caso le righe da eliminare non compaiono in modalità provvisoria, eliminale dalla modalità normale e riavvia il computer).

==================================
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
-
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINNT\System32\iexplore.exe
O4 - HKLM\..\Run: [HTML32 Help System] hhs32.pif
O4 - HKLM\..\Run: [norten Software Intrenet ] norten.pif
O4 - HKLM\..\Run: [System service78] C:\WINNT\etb\pokapoka78.exe
O4 - HKLM\..\RunServices: [HTML32 Help System] hhs32.pif
O4 - HKLM\..\RunServices: [norten Software Intrenet ] norten.pif
O4 - HKCU\..\Run: [HTML32 Help System] hhs32.pif
-
O4 - HKCU\..\RunServices: [HTML32 Help System] hhs32.pif
-
O14 - IERESET.INF: START_PAGE_URL=http://it.msn.com
O14 - IERESET.INF: MS_START_PAGE_URL=http://it.msn.com
-
O23 - Service: Enables Java Support (Java) - Unknown owner - C:\WINNT\System32\winjava.exe
-
O23 - Service: NetBIOS Helper Service (NetBIOS Helper) - Unknown owner - C:\WINNT\System32\nbthlp.exe
==================================

Con la funzione TROVA di Windows, cerca ed elimina questi file,

==================================
hhs32.pif
norten.pif
pokapoka78.exe
winjava.exe
nbthlp.exe
==================================

ELIMINA LA CARTELLA IN ROSSO
C:\WINNT\<font color=red><b>etb</font id=red></b>

Vai a PANNELLO DI CONTROLLO e clicca su OPZIONI INTERNET
nella finestra che si apre clicca i tre pulsanti
ELIMINA COOKIES - ELIMINA FILE - CANCELLA CRONOOLOGIA

al termine utilizza i programmi AD-AWARE e SPYBOT indicati in questo articolo
http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=388&SH=N

Fai una scansione con questo programma
http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=1286

sempre in modalità provvisoria fai una scansione Antivirus.

Nel sistema manca un programma firewall, installa questo
http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=56

Inoltre aggiorna il sistema dal windows update.

Collaboratore Aiutamici
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.