Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Aiuto per rundll32.exe Opzioni
fioribrembani
Inviato: Saturday, November 07, 2009 10:52:39 PM

Rank: Newbie

Iscritto dal : 4/27/2009
Posts: 3
Spero nell 'aiuto di qualche Amico con la A maiuscola! Da oggi ho scoperto Che dal Pannello di Controllo cilckkando su Alcune applicazioni vengono Istallazione Applicazioni, Appare la scritta: Impossibile Trovare il file "
C \ WINDOWS \ rundll32.exe "VERIFICARE il percorso e il nome del file corretti Siano. Voi direte di fare un bel Ripristino di Configurazione di Sistema ... ma il bello, anzi il brutto, è solo trovo Che la data odierna e quelle precedenti disattivate, dunque non è possibile nessun Ripristino tariffa. Allego il log nel caso Possa Essere utile! Ringrazio tutti, anche solo per avermi letto!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.47.48, il 07/11/2009
Piattaforma: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

I processi in esecuzione:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Programmi \ Alwil Software \ Avast4 \ aswUpdSv.exe
C: \ Programmi \ Lavasoft \ Ad-Aware \ aawservice.exe
C: \ Programmi \ Alwil Software \ Avast4 \ ashServ.exe
C: \ WINDOWS \ Explorer.EXE
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ PROGRA ~ 1 \ LAUNCH ~ 1 \ Avast4 \ ashDisp.exe
C: \ Programmi \ QuickTime \ qttask.exe
C: \ Programmi \ File comuni \ Real \ Update_OB \ realsched.exe
C: \ WINDOWS \ VTTimer.exe
C: \ WINDOWS \ system32 \ hkcmd.exe
C: \ Programmi \ ScanSoft \ OmniPageSE4.0 \ OpwareSE4.exe
C: \ Programmi \ Norton Ghost \ Agent \ VProTray.exe
C: \ WINDOWS \ system32 \ igfxtray.exe
C: \ WINDOWS \ system32 \ hkcmd.exe
C: \ Programmi \ Lavasoft \ Ad-Aware \ AAWTray.exe
C: \ Programmi \ Java \ jre6 \ bin \ jusched.exe
C: \ WINDOWS \ system32 \ CTFMON.EXE
C: \ Programmi \ Google \ GoogleToolbarNotifier \ GoogleToolbarNotifier.exe
C: \ Programmi \ File comuni \ Ahead \ Lib \ NMBgMonitor.exe
C: \ Programmi \ IObit \ Advanced SystemCare 3 \ AWC.exe
C: \ Programmi \ a-squared Free \ a2service.exe
C: \ Programmi \ Java \ jre6 \ bin \ jqs.exe
C: \ Programmi \ File comuni \ Motive \ McciCMService.exe
C: \ Programmi \ Norton Ghost \ Agent \ VProSvc.exe
C: \ Documents and Settings \ Luigi \ Documenti \ Acessori \ sp_rsser.exe
C: \ Programmi \ Alwil Software \ Avast4 \ ashMaiSv.exe
C: \ Programmi \ Alwil Software \ Avast4 \ ashWebSv.exe
C: \ Programmi \ File comuni \ Ahead \ Lib \ NMIndexingService.exe
C: \ Programmi \ File comuni \ Ahead \ Lib \ NMIndexStoreSvr.exe
C: \ Programmi \ Uniblue \ RegistryBooster 2010 \ registrybooster.exe
C: \ WINDOWS \ system32 \ wuauclt.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ Programmi \ Internet Explorer \ iexplore.exe
C: \ Programmi \ Internet Explorer \ iexplore.exe
C: \ Programmi \ Internet Explorer \ iexplore.exe
C: \ WINDOWS \ system32 \ spider.exe
C: \ Programmi \ Malwarebytes 'Anti-Malware \ mbam.exe
C: \ Programmi \ Internet Explorer \ iexplore.exe
C: \ Programmi \ Trend Micro \ HijackThis \ HijackThis.exe

R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.google.it/
- R1 HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
- R1 HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
- R0 HKLM \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName = Collegamenti
R3 - URLSearchHook: SearchSettings Class - (E312764E-7706-43F1-8DAB-FCDD2B1E416D) - C: \ Programmi \ Search Settings \ kb128 \ SearchSettings.dll
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C: \ Programmi \ File comuni \ Adobe \ Acrobat \ ActiveX \ AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - (201f27d4-3704-41d6-89c1-aa35e39143ed) - C: \ Programmi \ AskBarDis \ bar \ bin \ askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin per Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - (3CA2F312-6f6e-4B53-A66E-4E65E497C8C0) - (no file)
O2 - BHO: Canon Easy Web Print Helper - (68F9551E-0411-48E4-9AAF-4BC42A6A46BE) - C: \ Programmi \ Canon \ Easy-WebPrint \ EWPBrowseLoader.dll
O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C: \ Programmi \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Programmi \ Google \ GoogleToolbarNotifier \ 5.3.4501.1418 \ swg.dll
O2 - BHO: Google Dictionary sdch compressione - (C84D72FE-E17D-4195-BB24-76C02E2E7C4E) - C: \ Programmi \ Google \ Google Toolbar \ componenti \ fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java (tm) Plug-In 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C: \ Programmi \ Java \ jre6 \ bin \ jp2ssv.dll
O2 - BHO: SearchSettings Class - (E312764E-7706-43F1-8DAB-FCDD2B1E416D) - C: \ Programmi \ Search Settings \ kb128 \ SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Programmi \ Java \ jre6 \ lib \ deploy \ jqs \ IE \ jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - (327C2873-E90D-4c37-AA9D-10AC9BABA46C) - C: \ Programmi \ Canon \ Easy-WebPrint \ Toolband.dll
O3 - Toolbar: Ask Toolbar - (3041d03e-fd4b-44e0-b742-2d9b88305f98) - C: \ Programmi \ AskBarDis \ bar \ bin \ askBar.dll
O3 - Toolbar: Google Toolbar - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - C: \ Programmi \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O4 - HKLM \ .. \ Run: [avast!] C: \ PROGRA ~ 1 \ LAUNCH ~ 1 \ Avast4 \ ashDisp.exe
O4 - HKLM \ .. \ Run: [RemoteControl] C: \ Programmi \ QuickTime \ qttask.exe
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Programmi \ File comuni \ Real \ Update_OB \ realsched.exe"-osboot
O4 - HKLM \ .. \ Run: [SSBkgdUpdate] "C: \ Programmi \ File comuni \ Scansoft Shared \ SSBkgdUpdate \ SSBkgdupdate.exe"-Embedding-boot
O4 - HKLM \ .. \ Run: [SearchSettings] C: \ Programmi \ Search Settings \ SearchSettings.exe
O4 - HKLM \ .. \ Run: [NeroFilterCheck] GSICON.EXE
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Programmi \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [Persistence] C: \ WINDOWS \ system32 \ hkcmd.exe
O4 - HKLM \ .. \ Run: [OpwareSE4] "C: \ Programmi \ ScanSoft \ OmniPageSE4.0 \ OpwareSE4.exe"
O4 - HKLM \ .. \ Run: [Norton Ghost 12.0] "C: \ Programmi \ Norton Ghost \ Agent \ VProTray.exe"
O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ Programmi \ File comuni \ Ahead \ Lib \ NeroCheck.exe
O4 - HKLM \ .. \ Run: [ATIPTA] C: \ WINDOWS \ system32 \ igfxtray.exe
O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ WINDOWS \ system32 \ hkcmd.exe
O4 - HKLM \ .. \ Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Programmi \ Adobe \ Reader 9.0 \ Reader \ Reader_sl.exe"
O4 - HKLM \ .. \ Run: [Adobe ARM] "C: \ Programmi \ File comuni \ Adobe \ ARM \ 1.0 \ AdobeARM.exe"
O4 - HKLM \ .. \ Run: [Ad-Watch] C: \ Programmi \ Lavasoft \ Ad-Aware \ AAWTray.exe
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Programmi \ Java \ jre6 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: Anti [Malwarebytes 'Anti-Malware] C: \ Programmi \ Malwarebytes' Anti-Malware \ mbamgui.exe / install / silent
O4 - HKLM \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE
O4 - HKLM \ .. \ Run: [swg] "C: \ Programmi \ Google \ GoogleToolbarNotifier \ GoogleToolbarNotifier.exe"
O4 - HKLM \ .. \ Run: [Google Update] "C: \ Documents and Settings \ Luigi \ Impostazioni locali \ Dati applicazioni \ Google \ Update \ GoogleUpdate.exe" / c
O4 - HKLM \ .. \ Run: [BgMonitor_ (79662E04-7C6C-4d9f-84C7-88D8A56B10AA)] "C: \ Programmi \ File comuni \ Ahead \ Lib \ NMBgMonitor.exe"
O4 - HKLM \ .. \ Run: [Advanced SystemCare 3] "C: \ Programmi \ IObit \ Advanced SystemCare 3 \ AWC.exe" / startup
O4 - HKLM \ .. \ Run: [UniblueRegistryBooster] "C: \ Programmi \ Uniblue \ RegistryBooster 2010 \ launcher.exe" ritardo 20.000
O4 - HKUS \ S-1-5-19 \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS \ S-1-5-20 \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS \ S-1-5-18 \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User 'SYSTEM')
O4 - HKUS \. DEFAULT \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User 'Default')
O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res: / / C: \ Programmi \ Canon \ Easy-WebPrint \ Toolband.dll / RC_AddToList.html
O8 - Extra context menu item: Anteprima Easy-WebPrint - res: / / C: \ Programmi \ Canon \ Easy-WebPrint \ Toolband.dll / RC_Preview.html
O8 - Extra context menu item: E & sporta in Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000
O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res: / / C: \ Programmi \ Canon \ Easy-WebPrint \ Toolband.dll / RC_HSPrint.html
O8 - Extra context menu item: Stampa Easy-WebPrint - res: / / C: \ Programmi \ Canon \ Easy-WebPrint \ Toolband.dll / RC_Print.html
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL
O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Programmi \ Messenger \ msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Programmi \ Messenger \ msmsgs.exe (file missing)
O16 - DPF: (215B8138-A3CF-44C5-803f-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl. cab
O16 - DPF: (4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A) (qsax Control) - http://quickscan.bitdefender.com/qsax/qsax.cab
O16 - DPF: (CB50428B-657F-47DF-9B32-671F82AA73F7) - http://www.photodex.com/pxplay.cab
O16 - DPF: (D27CDB6E-AE6D-11cf-96B8-444553540000) (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
- O17 HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (7D0D0081-4E26-4B4E-9020-6E653D1DFDC5): NameServer = 208.67.222.222,208.67.220.220
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C: \ Programmi \ a-squared Free \ a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C: \ Programmi \ Alwil Software \ Avast4 \ aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C: \ Programmi \ Alwil Software \ Avast4 \ ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C: \ Programmi \ Alwil Software \ Avast4 \ ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C: \ Programmi \ Alwil Software \ Avast4 \ ashWebSv.exe
O23 - Service: BRPINFO Module (brpinfo32) - Unknown owner - C: \ WINDOWS \ system32 \ rundll32.exe (file missing)
O23 - Service: Servizio di Google Update (gupdate1c9d0b8eec1adc0) (gupdate1c9d0b8eec1adc0) - Google Inc. - C: \ Programmi \ Google \ Update \ GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C: \ Programmi \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Programmi \ File comuni \ InstallShield \ Driver \ 1150 \ Intel 32 \ IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C: \ Programmi \ Java \ jre6 \ bin \ jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C: \ Programmi \ Lavasoft \ Ad-Aware \ aawservice.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C: \ Programmi \ File comuni \ Macromedia Shared \ Service \ Macromedia Licensing.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C: \ Programmi \ File comuni \ Motive \ McciCMService.exe
O23 - Service: NBService - Nero AG - C: \ Programmi \ Nero \ Nero 7 \ Nero BackItUp \ NBService.exe
O23 - Service: NMIndexingService - Nero AG - C: \ Programmi \ File comuni \ Ahead \ Lib \ NMIndexingService.exe
O23 - Service: Norton Ghost - Symantec Corporation - C: \ Programmi \ Norton Ghost \ Agent \ VProSvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C: \ WINDOWS \ system32 \ IoctlSvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C: \ Documents and Settings \ Luigi \ Documenti \ Acessori \ sp_rsser.exe

--
End of file - 11366 bytes
Sponsor
Inviato: Saturday, November 07, 2009 10:52:39 PM

 
r16
Inviato: Saturday, November 07, 2009 11:31:03 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked
R3 - URLSearchHook: SearchSettings Class - (E312764E-7706-43F1-8DAB-FCDD2B1E416D) - C: \ Programmi \ Search Settings \ kb128 \ SearchSettings.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - (3CA2F312-6f6e-4B53-A66E-4E65E497C8C0) - (no file)
O2 - BHO: SearchSettings Class - (E312764E-7706-43F1-8DAB-FCDD2B1E416D) - C: \ Programmi \ Search Settings \ kb128 \ SearchSettings.dll
O3 - Toolbar: Ask Toolbar - (3041d03e-fd4b-44e0-b742-2d9b88305f98) - C: \ Programmi \ AskBarDis \ bar \ bin \ askBar.dll
O4 - HKLM \ .. \ Run: [SearchSettings] C: \ Programmi \ Search Settings \ SearchSettings.exe
O4 - HKLM \ .. \ Run: [NeroFilterCheck] GSICON.EXE
O4 - HKLM \ .. \ Run: [Google Update] "C: \ Documents and Settings \ Luigi \ Impostazioni locali \ Dati applicazioni \ Google \ Update \ GoogleUpdate.exe" / c
O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Programmi \ Messenger \ msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Programmi \ Messenger \ msmsgs.exe (file missing)
O16 - DPF: (215B8138-A3CF-44C5-803f-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex /hcImpl. cab
O16 - DPF: (4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A) (qsax Control) - http://quickscan.bitdefender.com/qsax/qsax.cab
O16 - DPF: (CB50428B-657F-47DF-9B32-671F82AA73F7) - http://www.photodex.com/pxplay.cab

Trova e cancella i file in rosso:
C: \ Programmi \ Search Settings \ SearchSettings.exe (è una cartella)

Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
Nella schermata iniziale di CCleaner, clicca su Opzioni e poi Avanzate, togli il segno di spunta a: Cancella i file in Windows Temp solo se più vecchi di 48 ore. (poi esegui le pulizie)

Riavvia il pc.
Fai una scansione con Malwarebytes e posta il log.
Poi alla fine, riposta anche un nuovo log di HJT.
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.