Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

pc lento in tutto Opzioni
klaus124
Inviato: Sunday, September 14, 2008 11:41:26 AM

Rank: Member

Iscritto dal : 9/16/2006
Posts: 24
accendo il pc e solo per avere il desktop sul video ci mette un eternità clicco sull'icona della connessione e si connette a stento apro qualsiasi browser e devo aggiornare la pagina 2 o 3 volte vi posto il Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11.30.50, on 14/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\COMODO\Firewall\cmdagent.exe
C:\Programmi\Eset\nod32krn.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Programmi\COMODO\Firewall\cfp.exe
C:\Programmi\Eset\nod32kui.exe
C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\hijackthis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\StarModem\StarModem USB Network\CnxTrApp.dll",AppEntry -REG "Conexant\Conexant USB Network"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programmi\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Programmi\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1208598239640
O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Programmi\COMODO\Firewall\cmdagent.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe

--
End of file - 4650 bytes ditemi come posso risolvere grazie
Sponsor
Inviato: Sunday, September 14, 2008 11:41:26 AM

 
r16
Inviato: Sunday, September 14, 2008 11:51:58 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Non hai grossi problemi. (il log intendo)
Elimina questa voce:
O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - (no file)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebCon trol.cab?1208598239640
Provvedi a svuotare del suo contenuto la cartella Prefetch :


clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223

Puoi provare a fare una scansione con Combofix, vediamo se trova qualcosa.
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,e dopo aver scaricato COMBOFIX, chiudi la connessione.

Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Salvalo sul desktop.
Doppio click su combofix.exe (comparirà una videata.)
Digita 1 premi Invio e segui le indicazioni.
Al termine, verrà creato un file log chiamato C:\ComboFix.txt. Postalo qui.
Durante l'operazione di scansione è importante non usare il PC e attendere pazientemente la fine delle operazioni.




Disinstalla combofix in questo modo: (dopo aver postato il log)
Start
Esegui
nella finestra di dialogo, digita (oppure, copia ed incolla) questo comando: Combofix /u e premi invio poi cancella le cartelle in "C" di combofix (qoobox)


klaus124
Inviato: Sunday, September 14, 2008 7:39:22 PM

Rank: Member

Iscritto dal : 9/16/2006
Posts: 24
ho fatto tutto quello che mi hai detto ed ecco il log di ComboFix 08-09-13.05 - user 2008-09-14 19.11.45.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.608 [GMT 2:00]
Eseguito da: C:\Documents and Settings\user\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
* Resident AV is active


ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((( Files Creati Da 2008-08-14 al 2008-09-14 )))))))))))))))))))))))))))))))))))
.

2008-09-11 17:05 . 2008-09-11 17:26 202 --a------ C:\WINDOWS\system\CmiCnfg.ini
2008-09-11 16:45 . 2003-07-02 04:42 27,904 --a------ C:\WINDOWS\system32\drivers\VIAAGP1.SYS
2008-09-11 16:40 . 2008-09-14 19:20 <DIR> d-------- C:\TEMP\_ISTMP1.DIR
2008-09-11 16:40 . 2008-09-11 16:40 <DIR> d-------- C:\Documents and Settings\user\WINDOWS
2008-09-11 16:34 . 2008-09-14 19:20 <DIR> d-------- C:\TEMP
2008-09-11 16:13 . 2001-08-31 13:00 113,222 --a--c--- C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-09-11 16:13 . 2001-08-31 13:00 41,029 --a--c--- C:\WINDOWS\system32\dllcache\zcorem.dll
2008-09-11 16:13 . 2001-08-31 13:00 36,937 --a--c--- C:\WINDOWS\system32\dllcache\zclientm.exe
2008-09-11 16:13 . 2001-08-31 13:00 29,760 --a--c--- C:\WINDOWS\system32\dllcache\znetm.dll
2008-09-11 16:13 . 2001-08-31 13:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-09-11 16:13 . 2001-08-31 13:00 13,894 --a--c--- C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-09-11 16:13 . 2001-08-31 13:00 4,677 --a--c--- C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-09-11 16:11 . 2004-08-03 22:32 571,392 --a--c--- C:\WINDOWS\system32\dllcache\tintlgnt.ime
2008-09-11 16:10 . 2001-08-31 13:00 2,178,131 --a--c--- C:\WINDOWS\system32\dllcache\shvlres.dll
2008-09-11 16:09 . 2001-08-31 13:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-09-11 16:08 . 2001-08-31 13:00 1,158,818 --a--c--- C:\WINDOWS\system32\dllcache\korwbrkr.lex
2008-09-11 16:07 . 2004-08-03 22:31 811,064 --a--c--- C:\WINDOWS\system32\dllcache\imjp81k.dll
2008-09-11 16:06 . 2001-08-31 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-09-11 16:06 . 2001-08-31 13:00 10,129,408 --a--c--- C:\WINDOWS\system32\dllcache\hwxkor.dll
2008-09-11 16:06 . 2001-08-31 13:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-09-11 16:06 . 2001-08-31 13:00 1,175,635 --a--c--- C:\WINDOWS\system32\dllcache\hrtzres.dll
2008-09-11 16:06 . 2004-08-19 15:39 268,288 --a--c--- C:\WINDOWS\system32\dllcache\httpext.dll
2008-09-11 16:06 . 2004-08-19 15:39 61,440 --a--c--- C:\WINDOWS\system32\dllcache\httpod51.dll
2008-09-11 16:06 . 2001-08-31 13:00 57,409 --a--c--- C:\WINDOWS\system32\dllcache\hrtz.dll
2008-09-11 16:06 . 2001-08-31 13:00 42,573 --a--c--- C:\WINDOWS\system32\dllcache\hrtzzm.exe
2008-09-11 16:06 . 2004-08-19 15:39 39,936 --a--c--- C:\WINDOWS\system32\dllcache\hostmib.dll
2008-09-11 16:06 . 2004-08-19 15:39 8,192 --a--c--- C:\WINDOWS\system32\dllcache\httpmb51.dll
2008-09-11 16:04 . 2001-08-31 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-09-11 16:03 . 2001-08-31 13:00 1,817,687 --a--c--- C:\WINDOWS\system32\dllcache\bckgres.dll
2008-09-11 16:02 . 2004-08-19 15:39 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-09-11 16:01 . 2004-08-19 15:39 290,816 --a--c--- C:\WINDOWS\system32\dllcache\adsiis51.dll
2008-09-11 15:57 . 2008-09-11 15:57 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-09-11 15:56 . 2001-08-31 13:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-09-11 15:56 . 2008-09-11 15:56 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-09-11 15:37 . 2001-08-31 13:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-09-11 15:37 . 2001-08-31 13:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-09-11 15:37 . 2001-08-31 13:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-09-11 15:37 . 2001-08-31 13:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-09-11 15:36 . 2008-09-11 15:36 <DIR> d--h----- C:\Documents and Settings\Default User\Risorse di stampa
2008-09-11 15:36 . 2008-09-11 15:36 <DIR> d--h----- C:\Documents and Settings\Default User\Risorse di rete
2008-09-11 15:36 . 2008-09-11 15:36 <DIR> d-------- C:\Documents and Settings\Default User\Preferiti
2008-09-11 15:36 . 2008-09-11 15:36 <DIR> d-------- C:\Documents and Settings\Default User\Documenti
2008-09-11 15:35 . 2004-08-19 17:22 1,014,202 -ra------ C:\WINDOWS\SETB2.tmp
2008-09-08 09:26 . 2008-09-08 13:49 982,016 --ahs---- C:\WINDOWS\system32\atjscript
2008-09-08 09:25 . 2008-09-08 09:25 <DIR> d-------- C:\Programmi\AlphaTESTER
2008-09-08 09:25 . 2003-04-21 16:43 385,536 --a------ C:\WINDOWS\system32\js32.dll
2008-09-02 11:24 . 2008-09-05 16:11 <DIR> d-------- C:\Programmi\nLite
2008-08-31 17:26 . 2008-08-31 17:26 <DIR> d-------- C:\Documents and Settings\user\Dati applicazioni\KC Softwares
2008-08-20 10:04 . 2008-09-14 13:38 1,220,354,080 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-20 10:04 . 2008-09-14 11:23 14,003,516 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-20 10:04 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\24219396.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 16:54 524,288 ----a-w C:\WINDOWS\system32\drivers\CnxE2FS.bin
2008-09-13 19:33 --------- d-----w C:\Programmi\eMule
2008-09-11 15:53 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-09-11 15:05 --------- d-----w C:\Programmi\C-Media 3D Audio
2008-09-09 15:15 25,992 -c--a-w C:\WINDOWS\system32\pgdfgsvc.exe
2008-09-05 10:33 --------- d-----w C:\Programmi\Malwarebytes' Anti-Malware
2008-09-04 08:08 --------- d---a-w C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-09-04 08:07 --------- d-----w C:\Programmi\SpywareBlaster
2008-09-02 06:44 --------- d-----w C:\Documents and Settings\user\Dati applicazioni\U3
2008-09-01 22:16 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-01 22:16 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-09-01 07:30 --------- d-----w C:\Programmi\Spybot - Search & Destroy
2008-08-31 15:26 --------- d-----w C:\Programmi\KC Softwares
2008-08-31 13:34 --------- d-----w C:\Programmi\Notepad++
2008-08-31 13:34 --------- d-----w C:\Documents and Settings\user\Dati applicazioni\Notepad++
2008-07-29 15:18 --------- d-----w C:\Programmi\EvilLyrics
2008-07-29 15:06 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-07-17 12:45 --------- d-----w C:\Documents and Settings\user\Dati applicazioni\PCF-VLC
2008-07-17 12:43 --------- d-----w C:\Documents and Settings\user\Dati applicazioni\Participatory Culture Foundation
2008-07-16 10:27 --------- d-----w C:\Programmi\a-squared Free
2008-06-24 16:12 295,936 -c--a-w C:\WINDOWS\system32\wmpeffects.dll
2008-05-18 15:34 78,440 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\firstlsp.reg.dat
2008-02-19 11:23 47,360 ----a-w C:\Documents and Settings\user\Dati applicazioni\pcouffin.sys
2007-12-26 17:28 502,055 -c--a-w C:\Programmi\gmer.zip
2007-12-25 10:44 122,168 -c--a-w C:\Programmi\modalità provv BootSafe.exe
2006-05-24 14:38 233,472 -c--a-w C:\Programmi\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-18 15:00 204,895 -c--a-w C:\Programmi\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 12:41 77,824 -c--a-w C:\Programmi\mozilla firefox\plugins\ctframeplayerobject.dll
2006-05-18 14:59 426,081 -c--a-w C:\Programmi\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 10:19 458,752 -c--a-w C:\Programmi\mozilla firefox\plugins\imagickrt.dll
2006-04-10 16:35 139,264 -c--a-w C:\Programmi\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 09:10 204,800 -c--a-w C:\Programmi\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 09:42 106,496 -c--a-w C:\Programmi\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 09:22 212,992 -c--a-w C:\Programmi\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 09:21 167,936 -c--a-w C:\Programmi\mozilla firefox\plugins\RLVoiceUnpacker.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CnxTrApp"="C:\Programmi\StarModem\StarModem USB Network\CnxTrApp.dll" [2003-07-07 247296]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
"COMODO Firewall Pro"="C:\Programmi\COMODO\Firewall\cfp.exe" [2008-06-02 1655552]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2008-06-02 949376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 44544]

C:\Documents and Settings\user\Menu Avvio\Programmi\Esecuzione automatica\
ERUNT AutoBackup.lnk - C:\Programmi\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"WRP"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 14:41 294912 C:\Programmi\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Tutorial_SW.lnk]
backup=C:\WINDOWS\pss\Tutorial_SW.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Watch.lnk]
backup=C:\WINDOWS\pss\Watch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^user^Menu Avvio^Programmi^Esecuzione automatica^HDDlife.lnk]
backup=C:\WINDOWS\pss\HDDlife.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^user^Menu Avvio^Programmi^Esecuzione automatica^MRU-Blaster Scheduler.lnk]
backup=C:\WINDOWS\pss\MRU-Blaster Scheduler.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^user^Menu Avvio^Programmi^Esecuzione automatica^MRU-Blaster Silent Clean.lnk]
backup=C:\WINDOWS\pss\MRU-Blaster Silent Clean.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^user^Menu Avvio^Programmi^Esecuzione automatica^Secunia PSI (RC1).lnk]
backup=C:\WINDOWS\pss\Secunia PSI (RC1).lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0wl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\is-EP8G0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC-Checkup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedItUpEX
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a--c--- 2005-06-28 22:05 344064 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a--c--- 2005-09-08 12:06 94208 C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
--a------ 2008-06-02 10:04 1655552 C:\Programmi\COMODO\Firewall\cfp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-19 15:39 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-03 11:24 133104 C:\Documents and Settings\user\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a--c--- 2004-10-13 18:21 1694208 c:\WINDOWS\$hf_mig$\KB887472\SP2QFE\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:54 5674352 C:\Programmi\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a--c--- 2007-05-11 03:08 2512392 C:\WINDOWS\system32\oodtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra--c--- 2006-01-30 18:00 98304 C:\Programmi\Hewlett-Packard\OrderReminder\OrderReminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
-ra------ 2005-06-20 12:53 1056768 C:\Programmi\VIA\RAID\raid_tool.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-05-28 10:33 1506544 C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2006-09-07 19:19 15872 C:\Programmi\Unlocker\UnlockerAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VIRIT LITE MONITOR]
--a------ 2008-08-31 17:38 245760 C:\VEXPLITE\MONLITE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"usnjsvc"=3 (0x3)
"a2free"=2 (0x2)
"ose"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"HDDlife HDD Access service"=2 (0x2)
"viritsvclite"=2 (0x2)
"SbieSvc"=3 (0x3)
"is-EP8G0"=2 (0x2)
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programmi\\eMule\\emule.exe"=
"%windir%\\system32\\sessmgr.exe"=

R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 39808]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-06-01 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-06-01 24208]
R1 is-EP8G0drv;is-EP8G0drv;C:\WINDOWS\system32\drivers\24219396.sys [2008-03-05 148496]
S4 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-08-31 57344]
.
Contenuto della cartella 'Scheduled Tasks'
.
- - - - ORFÃOS REMOVIDOS - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\user\Dati applicazioni\Mozilla\Firefox\Profiles\x5bvbo1h.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.yahoo.it
FF -: plugin - C:\Documents and Settings\user\Impostazioni locali\Dati applicazioni\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF -: plugin - C:\Programmi\Mozilla Firefox\plugins\npRLCT4Player.dll
FF -: plugin - C:\Programmi\Yahoo!\Common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-14 19:20:44
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-09-14 19:25:52
ComboFix-quarantined-files.txt 2008-09-14 17:25:27

Pre-Run: 94,173,220,864 byte disponibili
Post-Run: 94,163,460,096 byte disponibili

237 --- E O F --- 2008-05-14 17:17:34
r16
Inviato: Sunday, September 14, 2008 10:43:13 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Combofix non rileva nulla.
C'e una voce che non mi piace:
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
Il file scritto in rosso alcune case di antivirus,lo ritengono legittimo, altre (Prevx per esempio) lo ritengono un Malware.
Fossi in te farei cosi:
Io la eliminerei , poi, se qualcosa non funziona,lo posso sempre ripristinare dal backup di HijackThis.
Però tieni conto che io non sono te.Drool
klaus124
Inviato: Tuesday, September 16, 2008 12:18:32 PM

Rank: Member

Iscritto dal : 9/16/2006
Posts: 24
scusa r16 nella cartella di hijackthis ci sono i backup fatti in precedenza se dovessi inserirli x qualche problema come devo fare hanno un estensione che se la clicco mi apre la finestra... apri con... e li che faccio? ti posto l'immagine dei file cosi capisci meglio ScreenShot001.jpg forse è meglio con questo [img=http://img178.imageshack.us/img178/7053/screenshot001ue5.th.jpg] grazie
r16
Inviato: Tuesday, September 16, 2008 5:41:33 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao klaus124 .
Non centra niente quella cartella per ripristinare i backup.
Per ripristinare un file eliminato da HijackThis fai cosi:
Lancia HijackThis.
Clicca su :" View the list of backup".
Ti comparirà, una schermata con tutti i file eliminati.
Basta mettere la spunta sulla casellina del file che vuoi ripristinare, e cliccare su "Restore".
E il gioco è fatto.
klaus124
Inviato: Wednesday, September 17, 2008 9:43:17 AM

Rank: Member

Iscritto dal : 9/16/2006
Posts: 24
so proprio de marmo............................... grazie
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.