buongiorno a tutti mi sono appena iscritta e sono disperata<img src=icon_smile_sad.gif border=0 align=middle><img src=icon_smile_sad.gif border=0 align=middle>
da una settimana circa il mio pc e' impazzito...finestre che si aprono da sole, homepage modificata ad ogni avvio navigazione rallentata....
ho lanciato ad.aware, spy boot,spyswepper...problemi ne ha trovati ma all'avvio si ricomincia ...non ne posso di piu' veramente.....
vi copio il file di hijacthis con la speranza che qualcuno mi aiuti
grazie mony
Logfile of HijackThis v1.99.1
Scan saved at 14.35.47, on 20/03/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\msiconfig.exe
C:\WINDOWS\axdcfasb.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Webroot\Spy Sweeper\WRSSSDK.exe
C:\instp.exe
C:\WINDOWS\System32\noproujz.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\scrnasc.exe
C:\Programmi\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\scrnasc.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\WinZip\WZQKPICK.EXE
c:\windows\mousepad4.exe
c:\windows\mousepad4.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\Programmi\Network Monitor\netmon.exe
C:\WINDOWS\bW9uaWNh\command.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\unzipped\hijackthis[1]\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://searchbar.findthewebsiteyouneed.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://searchbar.findthewebsiteyouneed.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://searchbar.findthewebsiteyouneed.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.findthewebsiteyouneed.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://searchbar.findthewebsiteyouneed.comR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://searchbar.findthewebsiteyouneed.comR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {6001CDF7-6F45-471b-A203-0225615E35A7} - C:\WINDOWS\DH.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O4 - HKLM\..\Run: [mlp] C:\instp.exe
O4 - HKLM\..\Run: [Windows update adbpro] update32.exe
O4 - HKLM\..\Run: [spd] C:\instp.exe
O4 - HKLM\..\Run: [Windows Firewall Monitor] C:\instp.exe
O4 - HKLM\..\Run: [Virtual CD v6] grplscd.exe
O4 - HKLM\..\Run: [Microsoft FixUp] noproujz.exe
O4 - HKLM\..\Run: [mlink32] c:\windows\system32\derd\tmlink32.exe
O4 - HKLM\..\Run: [Virtual CD v8] lfcujzj.exe
O4 - HKLM\..\Run: [Crnsasad] scrnsscd.exe
O4 - HKLM\..\Run: [WinDLL (bee.dll)] rundll32.exe C:\WINDOWS\System32\bee.dll,start
O4 - HKLM\..\Run: [keyboard] c:\windows\keyboard4.exe
O4 - HKLM\..\Run: [Araeer] scrnseer.exe
O4 - HKLM\..\Run: [Crnserad] scrnasc.exe
O4 - HKLM\..\Run: [Realtek Sound Manager] mmyfhhj.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Programmi\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [asdgs] C:\instp.exe
O4 - HKLM\..\Run: [mousepad] c:\windows\mousepad4.exe
O4 - HKLM\..\RunServices: [mlp] C:\instp.exe
O4 - HKLM\..\RunServices: [Windows update adbpro] update32.exe
O4 - HKLM\..\RunServices: [spd] C:\instp.exe
O4 - HKLM\..\RunServices: [Windows Firewall Monitor] C:\instp.exe
O4 - HKLM\..\RunServices: [Virtual CD v6] grplscd.exe
O4 - HKLM\..\RunServices: [Microsoft FixUp] noproujz.exe
O4 - HKLM\..\RunServices: [Virtual CD v8] lfcujzj.exe
O4 - HKLM\..\RunServices: [Crnsasad] scrnsscd.exe
O4 - HKLM\..\RunServices: [Araeer] scrnseer.exe
O4 - HKLM\..\RunServices: [Crnserad] scrnasc.exe
O4 - HKLM\..\RunServices: [Realtek Sound Manager] mmyfhhj.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [mlink32] c:\windows\system32\derd\tsmlink32.exe
O4 - HKCU\..\Run: [Crnsasad] scrnsscd.exe
O4 - HKCU\..\Run: [Araeer] scrnseer.exe
O4 - HKCU\..\Run: [Crnserad] scrnasc.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Cerca con Google - res://c:\programmi\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Traduci parola in italiano - res://c:\programmi\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Link a ritroso - res://c:\programmi\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pagine simili - res://c:\programmi\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Versione cache della pagina - res://c:\programmi\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Programmi\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138271792756O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) -
http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4719/mcfscan.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\jNvart.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bW9uaWNh\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MS Ins Config (MSiCFG) - Unknown owner - C:\WINDOWS\msiconfig.exe
O23 - Service: Network Monitor - Unknown owner - C:\Programmi\Network Monitor\netmon.exe
O23 - Service: sdktemp - Unknown owner - C:\WINDOWS\axdcfasb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Programmi\Webroot\Spy Sweeper\WRSSSDK.exe