Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

mi controllate il log hijackthis per un virus searchnu 406 pls? Opzioni
mailab
Inviato: Wednesday, June 27, 2012 11:30:02 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
dice nessuna infezione......
mailab
Inviato: Wednesday, June 27, 2012 11:58:07 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
ma qualcosa c è sicuro...anche perchè mi smette di funzionare explorer abb spesso cosi dal nulla...comunque io conbofix ho postato il rapporto,ma non ci ho fatto nulla dopo...non ho cancellato nulla di mia iniziativa..
shapiro
Inviato: Thursday, June 28, 2012 6:35:39 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164

Ora apri una pagina del blocco note e copia incolla quanto segue (non copiare il ''code'')


Code:
Dirlook::
c:\programdata\boost_interprocess

RegNull::
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{27FEB862-BA8D-472A-4B8A-06832EDC2EAF}*]


salva la pagina nominandola obligatoriamente in CFScript.txt
a questo punto trascina e lascia il file CFScript.txt sull'icona di combofix
lascialo lavorare fino alla fine e posta il nuovo log

mailab
Inviato: Thursday, June 28, 2012 6:49:30 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35

fatto!ecco il report



ComboFix 12-06-28.01 - MAILA 28/06/2012 18:42:30.3.4 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.39.1040.18.2935.1719 [GMT 2:00]
Eseguito da: c:\users\MAILA\Desktop\ComboFix.exe
Opzioni usate :: c:\users\MAILA\Documents\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Creati Da 2012-05-28 al 2012-06-28 )))))))))))))))))))))))))))))))))))
.
.
2012-06-28 16:46 . 2012-06-28 16:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-27 14:56 . 2012-06-28 16:46 -------- d-----w- c:\users\MAILA\AppData\Local\temp
2012-06-27 14:44 . 2012-06-28 15:36 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{76816FC7-1FD9-49AD-B92B-CCD433B30AEE}\offreg.dll
2012-06-27 11:36 . 2012-06-27 11:36 -------- d-----w- c:\program files\Common Files\Adobe
2012-06-27 10:59 . 2012-06-27 10:59 -------- d-----w- c:\users\MAILA\AppData\Roaming\Malwarebytes
2012-06-27 10:59 . 2012-06-27 10:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-06-27 10:59 . 2012-06-27 10:59 -------- d-----w- c:\programdata\Malwarebytes
2012-06-27 10:59 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-27 10:52 . 2012-06-27 10:52 -------- d-----w- c:\users\MAILA\AppData\Local\Ilivid Player
2012-06-26 20:48 . 2012-06-26 20:48 388096 ----a-r- c:\users\MAILA\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-26 20:48 . 2012-06-26 20:48 -------- d-----w- c:\program files\Trend Micro
2012-06-26 20:36 . 2012-03-30 10:29 1287024 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-26 20:36 . 2012-04-28 03:19 177152 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-26 20:35 . 2012-04-02 04:40 936960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-06-26 20:35 . 2012-04-02 04:41 1221632 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-06-26 20:35 . 2012-04-02 04:40 989184 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-06-26 20:35 . 2012-04-02 04:40 969216 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-06-26 20:35 . 2012-04-24 04:47 1156608 ----a-w- c:\windows\system32\crypt32.dll
2012-06-26 20:35 . 2012-04-24 04:47 139264 ----a-w- c:\windows\system32\cryptsvc.dll
2012-06-26 20:35 . 2012-04-24 04:47 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-06-26 20:33 . 2012-04-02 04:46 3902320 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-06-26 20:33 . 2012-04-02 04:46 3958128 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-26 20:32 . 2012-05-15 01:12 2342400 ----a-w- c:\windows\system32\win32k.sys
2012-06-26 20:32 . 2012-03-17 07:20 56688 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-26 20:32 . 2012-05-02 04:52 163328 ----a-w- c:\windows\system32\profsvc.dll
2012-06-26 20:32 . 2012-04-26 04:48 57856 ----a-w- c:\windows\system32\rdpwsx.dll
2012-06-26 20:32 . 2012-04-26 04:48 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-06-26 20:32 . 2012-04-26 04:43 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-06-26 20:31 . 2012-03-03 05:40 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2012-06-26 20:31 . 2012-03-03 05:40 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-06-26 20:31 . 2012-03-03 05:40 1074176 ----a-w- c:\windows\system32\DWrite.dll
2012-06-26 20:31 . 2012-03-03 05:40 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-06-26 20:30 . 2012-03-03 05:40 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2012-06-26 20:05 . 2012-06-26 20:05 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-26 20:05 . 2012-06-26 20:05 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-26 14:21 . 2012-05-31 03:41 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{76816FC7-1FD9-49AD-B92B-CCD433B30AEE}\mpengine.dll
2012-06-23 17:15 . 2012-06-23 17:15 -------- d-----w- c:\programdata\boost_interprocess
2012-06-22 10:07 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-22 10:07 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-22 10:07 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-22 10:07 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-22 10:07 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-22 10:07 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-22 10:07 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-22 10:07 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-22 10:07 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-15 18:05 . 2012-06-26 22:07 -------- d-----w- c:\users\MAILA\AppData\Roaming\vlc
2012-06-15 18:02 . 2012-06-15 18:02 -------- d-----w- c:\program files\VideoLAN
2012-06-12 15:57 . 2012-06-12 15:57 -------- d-----w- c:\program files\Microsoft SDKs
2012-06-12 15:41 . 2012-06-12 15:41 -------- d-----w- C:\Hauppauge
2012-06-12 15:34 . 2001-01-12 09:02 53248 ----a-w- c:\windows\system32\MDCustomPanels.ocx
2012-06-12 15:34 . 2000-07-14 21:00 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2012-06-12 15:34 . 1999-05-06 21:00 244232 ----a-w- c:\windows\system32\MsFlxGrd.ocx
2012-06-12 15:34 . 1998-06-25 21:00 89600 ----a-w- c:\windows\system32\MSCAL.OCX
2012-06-12 15:34 . 2002-12-27 10:33 65536 ----a-w- c:\windows\system32\dmcrypto.dll
2012-06-12 15:34 . 1998-06-18 09:33 598288 ----a-w- c:\windows\system32\temp.011
2012-06-12 15:34 . 1998-06-18 09:33 164112 ----a-w- c:\windows\system32\temp.012
2012-06-12 15:34 . 1998-06-18 09:32 147728 ----a-w- c:\windows\system32\temp.013
2012-06-12 15:34 . 1998-06-16 22:13 17920 ----a-w- c:\windows\system32\temp.014
2012-06-12 15:33 . 2012-06-12 15:42 -------- d-----w- c:\program files\WinTV
2012-06-12 15:33 . 2000-03-07 14:22 278581 ----a-w- c:\windows\system32\temp.00F
2012-06-12 15:33 . 2000-02-11 15:58 995383 ----a-w- c:\windows\system32\temp.010
2012-06-12 15:33 . 1998-06-25 00:43 1409024 ----a-w- c:\windows\system32\temp.015
2012-06-12 15:33 . 1998-06-16 18:45 77878 ----a-w- c:\windows\system32\temp.00E
2012-06-12 15:33 . 1998-05-31 14:06 22288 ----a-w- c:\windows\system32\temp.016
2012-06-12 15:32 . 2012-06-12 15:32 -------- d-----w- C:\hcw21nova-t
2012-06-05 09:17 . 2012-06-05 09:17 -------- d-----w- c:\programdata\Microsoft Help
2012-06-05 09:17 . 2012-06-05 09:17 -------- d-----w- c:\users\MAILA\AppData\Local\Microsoft Help
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\boost_interprocess ----
.
2012-06-23 17:15 . 2012-06-23 17:15 12 ----atw- c:\programdata\boost_interprocess\20076B58D850CD01\{1832B446-3F6D-4880-99C1-0B3B26170D94}
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\MAILA\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-03-19 137536]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2010-04-07 5758976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-01-07 1602856]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-04-06 495708]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-08 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-08 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-08 170008]
"FreeFallProtection"="c:\program files\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-08-02 726640]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-11-29 5249024]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-20 487562]
"DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2010-05-20 206336]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-11-04 2219184]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DBRMTray"="c:\dell\DBRM\Reminder\TrayApp.exe" [2010-02-04 7168]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}\Icon3E5562ED7.ico [2011-3-21 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer9"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\Drivers\CtAudDrv.sys [x]
R3 gupdatem;Servizio Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run [x]
S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe86.sys [x]
S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe86.sys [x]
S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe86.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [x]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Audio schermo Intel(R);c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-06-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-26 20:05]
.
2012-06-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2719283518-2909302424-3632810199-1000Core.job
- c:\users\MAILA\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-19 23:06]
.
2012-06-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2719283518-2909302424-3632810199-1000UA.job
- c:\users\MAILA\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-19 23:06]
.
2012-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-16 16:06]
.
2012-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-16 16:06]
.
.
------- Scansione supplementare -------
.
uStart Page = https://www.google.it/
IE: Invia immagine alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Invia pagina alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30po\UserChoice]
@Denied: (2) (S-1-5-21-2719283518-2909302424-3632810199-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30po"
.
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30pp\UserChoice]
@Denied: (2) (S-1-5-21-2719283518-2909302424-3632810199-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30pp"
.
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30ppf\UserChoice]
@Denied: (2) (S-1-5-21-2719283518-2909302424-3632810199-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30ppf"
.
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (S-1-5-21-2719283518-2909302424-3632810199-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2012-06-28 18:47:35
ComboFix-quarantined-files.txt 2012-06-28 16:47
ComboFix2.txt 2012-06-28 14:22
ComboFix3.txt 2012-06-27 15:01
.
Pre-Run: 205.138.452.480 byte disponibili
Post-Run: 205.129.125.888 byte disponibili
.
- - End Of File - - AE615B14B7C6F0A8D71EE2B1DAF6A907
shapiro
Inviato: Thursday, June 28, 2012 8:05:07 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164

elimina a mano questa cartella

c:\users\MAILA\AppData\Local\Ilivid Player


Scarica OTL, e salvalo sul desktop:

http://oldtimer.geekstogo.com/OTL.exe

Clicca sull'icona di OTL che trovi sul tuo desktop .

Clicca su Cleanup.

fai pulizia con ccleaner e posta un log aggiornato di hjt

hai notato se il pc ha degli ''intoppi'' durante la navigazione? riscontri qualche problema in particolare?
mailab
Inviato: Thursday, June 28, 2012 8:24:40 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
adesso faccio tutto...comunque ogni, metti 10 minuti ,smette di fungere e basta....rallentato explorer non mi pare...va normale,ma poi si impalla..
mailab
Inviato: Thursday, June 28, 2012 8:39:03 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:37:52, on 28/06/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.17006)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\dell\DBRM\Reminder\DbrmTrayicon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Trend Micro NSC BHO - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [FreeFallProtection] C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [DBRMTray] C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [DBRMTray] C:\Dell\DBRM\Reminder\TrayApp.exe
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\MAILA\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra 'Tools' menuitem: &Impostazioni di Google Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (file missing)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Sentinel HASP License Manager (hasplms) - SafeNet Inc. - C:\Windows\system32\hasplms.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) - Dell Inc. - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE

--
End of file - 8797 bytes
mailab
Inviato: Thursday, June 28, 2012 8:58:16 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
ah cavolo !dovevo farlo in mod provvisoria....va ben lo stesso o lo rifaccio ?
shapiro
Inviato: Friday, June 29, 2012 6:00:40 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164

avvia una nuova scansione con hijackthis e metti la spunta accanto a queste voci poi premi fix checked



Code:
O2 - BHO: Trend Micro NSC BHO - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (file missing)

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)


non riesco a vedere altro, sembrerebbe a posto

se hai problemi con explorer prova a scaricare l'ultima versione dal sito aiutamici , naviga un po' e dimmi se il pc e' tornato come prima
mailab
Inviato: Friday, June 29, 2012 7:01:51 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
oks!cancellato...intanto ti dico che per esempio su fb posso veder tre foto di numero prima che si impalli...il resto direi che funziona....scarico l'ultimo explorer e scrivo stasera o domani come va!grazie!
shapiro
Inviato: Friday, June 29, 2012 7:52:00 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164


mailab per verificare meglio prova a scaricare anche opera da qui andiamo per esclusione vediamo se e' solo explorer che crea problemi
mailab
Inviato: Friday, June 29, 2012 8:14:00 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
intanto ho riprovato a scaricare chrome,per poi ri toglierlo visto che dici che rallenta solo,solo per vedere se la benedetta pagina iniziale persisteva e.....SI!!!C'è ancora!!!!!ora ritolgo chrome e vedo opera...intanto mozzilla va bene!
mailab
Inviato: Friday, June 29, 2012 8:22:16 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
opera non da problemi...praticamente i due che avevo prima cioè explorer e chrome mi danno problemi ,sti altri no.bu.
miticoalex
Inviato: Friday, June 29, 2012 9:12:19 PM

Rank: AiutAmico

Iscritto dal : 10/19/2010
Posts: 14,635
Salve

Mi pare di aver capito, che la pagina si ripresenta solo su chrome e IE.

Io farei così:

Per Internet explorer, vai su strumenti>opzioni internet>avanzate, reimposta e dai OK.

Per chrome, prova ad eliminare la cartella del profilo; Vai su start, esegui ed incolla %LOCALAPPDATA%\Google\Chrome\User Data\ ,

individua la cartella default, e rinominala. Riavvia chrome.





mailab
Inviato: Friday, June 29, 2012 9:25:05 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
ciao!explorer si impalla solamente,ma la pagina iniziale searchnu406 appare solo con chrome che ora ho disinstallato come mi è stato detto,ora provo a riinstallarlo e fare quello che mi dici!
mmmmmma....cos'è la cartella del profilo?intendi le impostazioni?ou...son abbastanza incapace.... :/
mailab
Inviato: Friday, June 29, 2012 9:46:23 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
se dovevo fare tipo MAILA->appdata->local->chrome o roba del genere ho fatto,cancellato la cartella poi ho copincollato quella roba e rinominato il default..ora vedo se al posto di google come pag iniziale mi ritorna quella roba..
mailab
Inviato: Friday, June 29, 2012 9:49:08 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
mi ritorna.sempre e inesorabilmente,ma non sono certa di aver fatto esattamente quello che volevi ...
shapiro
Inviato: Friday, June 29, 2012 10:17:12 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164

ti ho trovato questo da un sito inglese prova e dimmi se risolvi


Code:
Google Chrome:
1. Aprite Google Chrome.
2. Fare clic sull'icona della chiave inglese in alto a destra del browser.
3. Scegliere "Impostazioni" dal menu a discesa.
4. Selezionare "Basics".
5. Clicca su "Gestione motori di ricerca" nell'ambito del settore Impostazioni di ricerca.
6. Posiziona il puntatore del mouse su un motore di ricerca preferito e fare clic su "Imposta come predefinito".
7. È ora possibile rimuovere provider di indesiderati ricerca cliccando sul segno X.
mailab
Inviato: Friday, June 29, 2012 10:41:05 PM

Rank: AiutAmico

Iscritto dal : 6/26/2012
Posts: 35
ahhhh si si!quello è la prima cosa che ho fatto appena è comparso quel maledetto searchnu...inutile...mi risulta sempre google come schermata iniziale...difatto poi pero si apre searchnu...
shapiro
Inviato: Friday, June 29, 2012 10:43:11 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
non conosco bene chrome....hai provato a reimpostare la pagina ?
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.