Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

Errore caricamento ctccw32.dll

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

Errore caricamento ctccw32.dll

Messaggioda fanale » lun set 17, 2007 9:34 pm

Ciao ragazzi ho un problema, tornato dalle ferie ho acceso il pc e ho trovato un virus (trojan).Ho fatto la scansione e rilevato il virus, l'antivirus mi diceva: operazione consigliata eliminare il file. Così facendo tutte le volte che accendo il pc esce scritto:errore durante il caricaricamento di ctccw32.dll impossibil trovare il modulo specificato. Cosa significa tutto ciò? Grazie mille a chi mi risponde. [:)]

ba_61: titoli e sezione appropriati
Avatar utente
fanale
Aficionado
Aficionado
 
Messaggi: 38
Iscritto il: ven set 14, 2007 8:10 pm
Località: Cinisello Balsamo(MI)

Messaggioda jordan air » lun set 17, 2007 9:50 pm

dovresti usare il programma hijackthis e fare una scansione e fixare la voce O4 - HKLM\..\Run: [gfxtray] rundll32 ctccw32.dll,findwnd. Fixando questa voce dovresti risolvere il problema

una volta fixata la voce fai una scansione con ad-aware o simili e pulizia con ccleaner.

Fammi sapere se va.
My pc: Intel core i5 750; Corsair 2gb DDR3 pc-12600; Ati 6790 (1gb); Asus P7H55 - V; Antec True Power 650W; WD 465gb 16mb-Samsung 186gb; CM 690
Avatar utente
jordan air
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3155
Iscritto il: sab feb 03, 2007 1:26 pm
Località: Milano

Messaggioda fanale » mar set 18, 2007 11:10 pm

Ciao a tutti, grazie jordan air per avermi risposto. Ho letto quello che mi hai scritto e ho scaricato il progamma hijackthis e ho fatto la scansione . Ho cercato la voce che mi hai detto e lò fissata, però non ho fatto la scansione con ad-awares perché e tardi e ci provo domani con calma. GRAZIE TANTE COMUNQUE TI FACCIO SAPERE DOMANI CIAO [:)]
Avatar utente
fanale
Aficionado
Aficionado
 
Messaggi: 38
Iscritto il: ven set 14, 2007 8:10 pm
Località: Cinisello Balsamo(MI)


Messaggioda fanale » mer set 19, 2007 10:50 pm

Ciao a tutti ho fatto quello che mi avete detto, ho fixato la voce, ho fatto una scansione con ad-aware e ho trovato 6 oggetti a rischio che ho eliminato e 94 oggetti in quarantena che sono questi: ArchiveData(auto-quarantine- 2007-09-19 22-26-19.bckp)
Referencefile : SE1R192 17.09.2007
======================================================

MICROGAMING
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : S-1-5-21-3066440050-1064970366-1622610228-1006\software\microgaming

TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[1]=IECache Entry : Cookie:fanale@spylog.com/
obj[2]=IECache Entry : Cookie:fanale@zedo.com/
obj[3]=IECache Entry : Cookie:fanale@tradedoubler.com/
obj[4]=IECache Entry : Cookie:fanale@tribalfusion.com/
obj[5]=IECache Entry : Cookie:fanale@com.com/
obj[6]=IECache Entry : Cookie:fanale@statcounter.com/
obj[7]=IECache Entry : Cookie:fanale@serving-sys.com/
obj[8]=IECache Entry : Cookie:fanale@studenti.adbureau.net/
obj[9]=IECache Entry : Cookie:fanale@fastclick.net/
obj[10]=IECache Entry : Cookie:fanale@revsci.net/
obj[11]=IECache Entry : Cookie:fanale@bravenet.com/
obj[12]=IECache Entry : Cookie:fanale@c2.zedo.com/
obj[13]=IECache Entry : Cookie:fanale@ad.yieldmanager.com/
obj[14]=IECache Entry : Cookie:fanale@webads.it/
obj[15]=IECache Entry : Cookie:fanale@doubleclick.net/
obj[16]=IECache Entry : Cookie:fanale@tacoda.net/
obj[17]=IECache Entry : Cookie:fanale@as1.falkag.de/
obj[18]=IECache Entry : Cookie:fanale@adfarm1.adition.com/
obj[19]=IECache Entry : Cookie:fanale@atdmt.com/
obj[20]=IECache Entry : Cookie:fanale@bs.serving-sys.com/
obj[21]=IECache Entry : Cookie:fanale@mediaplex.com/
ArchiveData(auto-quarantine- 2007-09-19 22-26-42.bckp)
Referencefile : SE1R192 17.09.2007
======================================================

MICROGAMING
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : S-1-5-21-3066440050-1064970366-1622610228-1006\software\microgaming

TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[1]=IECache Entry : Cookie:fanale@spylog.com/
obj[2]=IECache Entry : Cookie:fanale@zedo.com/
obj[3]=IECache Entry : Cookie:fanale@tradedoubler.com/
obj[4]=IECache Entry : Cookie:fanale@tribalfusion.com/
obj[5]=IECache Entry : Cookie:fanale@com.com/
obj[6]=IECache Entry : Cookie:fanale@statcounter.com/
obj[7]=IECache Entry : Cookie:fanale@serving-sys.com/
obj[8]=IECache Entry : Cookie:fanale@studenti.adbureau.net/
obj[9]=IECache Entry : Cookie:fanale@fastclick.net/
obj[10]=IECache Entry : Cookie:fanale@revsci.net/
obj[11]=IECache Entry : Cookie:fanale@bravenet.com/
obj[12]=IECache Entry : Cookie:fanale@c2.zedo.com/
obj[13]=IECache Entry : Cookie:fanale@ad.yieldmanager.com/
obj[14]=IECache Entry : Cookie:fanale@webads.it/
obj[15]=IECache Entry : Cookie:fanale@doubleclick.net/
obj[16]=IECache Entry : Cookie:fanale@tacoda.net/
obj[17]=IECache Entry : Cookie:fanale@as1.falkag.de/
obj[18]=IECache Entry : Cookie:fanale@adfarm1.adition.com/
obj[19]=IECache Entry : Cookie:fanale@atdmt.com/
obj[20]=IECache Entry : Cookie:fanale@bs.serving-sys.com/
obj[21]=IECache Entry : Cookie:fanale@mediaplex.com/

ArchiveData(auto-quarantine- 2007-09-19 22-26-43.bckp)
Referencefile : SE1R192 17.09.2007
======================================================

MICROGAMING
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : S-1-5-21-3066440050-1064970366-1622610228-1006\software\microgaming

TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[1]=IECache Entry : Cookie:fanale@spylog.com/
obj[2]=IECache Entry : Cookie:fanale@zedo.com/
obj[3]=IECache Entry : Cookie:fanale@tradedoubler.com/
obj[4]=IECache Entry : Cookie:fanale@tribalfusion.com/
obj[5]=IECache Entry : Cookie:fanale@com.com/
obj[6]=IECache Entry : Cookie:fanale@statcounter.com/
obj[7]=IECache Entry : Cookie:fanale@serving-sys.com/
obj[8]=IECache Entry : Cookie:fanale@studenti.adbureau.net/
obj[9]=IECache Entry : Cookie:fanale@fastclick.net/
obj[10]=IECache Entry : Cookie:fanale@revsci.net/
obj[11]=IECache Entry : Cookie:fanale@bravenet.com/
obj[12]=IECache Entry : Cookie:fanale@c2.zedo.com/
obj[13]=IECache Entry : Cookie:fanale@ad.yieldmanager.com/
obj[14]=IECache Entry : Cookie:fanale@webads.it/
obj[15]=IECache Entry : Cookie:fanale@doubleclick.net/
obj[16]=IECache Entry : Cookie:fanale@tacoda.net/
obj[17]=IECache Entry : Cookie:fanale@as1.falkag.de/
obj[18]=IECache Entry : Cookie:fanale@adfarm1.adition.com/
obj[19]=IECache Entry : Cookie:fanale@atdmt.com/
obj[20]=IECache Entry : Cookie:fanale@bs.serving-sys.com/
obj[21]=IECache Entry : Cookie:fanale@mediaplex.com/

ArchiveData(auto-quarantine- 2007-09-19 22-26-46.bckp)
Referencefile : SE1R192 17.09.2007
======================================================

MICROGAMING
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : S-1-5-21-3066440050-1064970366-1622610228-1006\software\microgaming

TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[1]=IECache Entry : Cookie:fanale@spylog.com/
obj[2]=IECache Entry : Cookie:fanale@zedo.com/
obj[3]=IECache Entry : Cookie:fanale@tradedoubler.com/
obj[4]=IECache Entry : Cookie:fanale@tribalfusion.com/
obj[5]=IECache Entry : Cookie:fanale@com.com/
obj[6]=IECache Entry : Cookie:fanale@statcounter.com/
obj[7]=IECache Entry : Cookie:fanale@serving-sys.com/
obj[8]=IECache Entry : Cookie:fanale@studenti.adbureau.net/
obj[9]=IECache Entry : Cookie:fanale@fastclick.net/
obj[10]=IECache Entry : Cookie:fanale@revsci.net/
obj[11]=IECache Entry : Cookie:fanale@bravenet.com/
obj[12]=IECache Entry : Cookie:fanale@c2.zedo.com/
obj[13]=IECache Entry : Cookie:fanale@ad.yieldmanager.com/
obj[14]=IECache Entry : Cookie:fanale@webads.it/
obj[15]=IECache Entry : Cookie:fanale@doubleclick.net/
obj[16]=IECache Entry : Cookie:fanale@tacoda.net/
obj[17]=IECache Entry : Cookie:fanale@as1.falkag.de/
obj[18]=IECache Entry : Cookie:fanale@adfarm1.adition.com/
obj[19]=IECache Entry : Cookie:fanale@atdmt.com/
obj[20]=IECache Entry : Cookie:fanale@bs.serving-sys.com/
obj[21]=IECache Entry : Cookie:fanale@mediaplex.com/

ArchiveData(auto-quarantine- 2007-09-19 23-15-53.bckp)
Referencefile : SE1R192 17.09.2007
======================================================

TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=IECache Entry : Cookie:fanale@spylog.com/
obj[1]=IECache Entry : Cookie:fanale@statse.webtrendslive.com/
obj[2]=IECache Entry : Cookie:fanale@zedo.com/
obj[3]=IECache Entry : Cookie:fanale@ad.pro-advertising.com/
obj[4]=IECache Entry : Cookie:fanale@c2.zedo.com/
obj[5]=IECache Entry : Cookie:fanale@atdmt.com/ ///////////////////////////////////////////////////////////////////////////////////////////// Dopo ho fatto una pulizia con ccleaner e ho riavviato il pc . HO ANCORA QUESTO PROBLEMA cosaltro devo fare. RISPONDETEMI VI PREGO GRAZIE [:)]
Avatar utente
fanale
Aficionado
Aficionado
 
Messaggi: 38
Iscritto il: ven set 14, 2007 8:10 pm
Località: Cinisello Balsamo(MI)

Messaggioda crazy.cat » gio set 20, 2007 6:51 am

Vediamo il log di hijackthis.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda fanale » ven set 21, 2007 10:28 pm

Ciao ragazzi, ecco il log che mi avete chiesto. Fatemi sapere GRAZIE [sadbye] [:)] Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22.24.04, on 18/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Acer\Acer eConsole\MediaServerService.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe
C:\Programmi\Norton AntiVirus\navapsvc.exe
C:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\Programmi\Acer\Acer eMode Management\AspireService.exe
C:\Programmi\Acer\Acer eConsole\MediaSync.exe
C:\Program Files\Acer TV-FM\PCMService.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe
C:\Programmi\D-Tools\daemon.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe
C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Programmi\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Programmi\LG PC Suite\LG PC Sync\LGSyncManager.exe
C:\Programmi\MSN Messenger\usnsvc.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Fanale\Impostazioni locali\Temporary Internet Files\Content.IE5\8L4NC707\HiJackThis_v2[1].exe
C:\Programmi\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fastweb.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Multi_Media_Italy toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMult.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Multi_Media_Italy toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMult.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Programmi\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [AspireService] C:\Programmi\Acer\Acer eMode Management\AspireService.exe
O4 - HKLM\..\Run: [MediaSync] C:\Programmi\Acer\Acer eConsole\MediaSync.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer TV-FM\PCMService.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmi\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Office SturtUp] osa9.exe
O4 - HKLM\..\Run: [gfxtray] rundll32 ctccw32.dll,findwnd
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Programmi\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Programmi\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?cc90fb39bbe24d5288f8d98e48f6df28
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?cc90fb39bbe24d5288f8d98e48f6df28
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.scaricandomp3.com/link/" (file missing)
O9 - Extra 'Tools' menuitem: Scaricando MP3 - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.scaricandomp3.com/link/" (file missing)
O9 - Extra button: Scaricando MP3 - {810B72CB-566A-409B-B6A3-31F720C16FAE} - C:\WINDOWS\system32\Scaricando MP3 (file missing)
O9 - Extra button: (no name) - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.cercasulweb.com/itmp3/" (file missing)
O9 - Extra 'Tools' menuitem: Cersa Sul Web - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.cercasulweb.com/itmp3/" (file missing)
O9 - Extra button: ScaricaMP3 - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\Fanale\Dati applicazioni\ScaricaMP3[1].exe (file missing)
O9 - Extra button: Cersa Sul Web - {F4445FEB-6D20-47CB-9ACF-9D142A7F680A} - C:\WINDOWS\system32\Cersa Sul Web (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-it.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acer Media Server - Acer Inc. - C:\Programmi\Acer\Acer eConsole\MediaServerService.exe
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Servizio Auto-Protect di Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Programmi\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmi\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe

--
End of file - 14060 bytes
Avatar utente
fanale
Aficionado
Aficionado
 
Messaggi: 38
Iscritto il: ven set 14, 2007 8:10 pm
Località: Cinisello Balsamo(MI)

Messaggioda crazy.cat » sab set 22, 2007 7:21 am

Rifai la scansione con hijackthis, selezioni le caselle di queste righe e premi Fix checked per cancellarle.
Riavvii il pc e vedi se si riforma questa
O4 - HKLM\..\Run: [gfxtray] rundll32 ctccw32.dll,findwnd
Controlla se il file ctccw32.dll è presente nel tuo pc.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [gfxtray] rundll32 ctccw32.dll,findwnd
O9 - Extra button: (no name) - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.scaricandomp3.com/link/" (file missing)
O9 - Extra 'Tools' menuitem: Scaricando MP3 - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.scaricandomp3.com/link/" (file missing)
O9 - Extra button: Scaricando MP3 - {810B72CB-566A-409B-B6A3-31F720C16FAE} - C:\WINDOWS\system32\Scaricando MP3 (file missing)
O9 - Extra button: (no name) - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.cercasulweb.com/itmp3/" (file missing)
O9 - Extra 'Tools' menuitem: Cersa Sul Web - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.cercasulweb.com/itmp3/" (file missing)
O9 - Extra button: ScaricaMP3 - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\Fanale\Dati applicazioni\ScaricaMP3[1].exe (file missing)
O9 - Extra button: Cersa Sul Web - {F4445FEB-6D20-47CB-9ACF-9D142A7F680A} - C:\WINDOWS\system32\Cersa Sul Web (file missing)
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda fanale » sab set 22, 2007 9:10 pm

ciao raga finalmente ho risolto il mio problema grazie tante siete stati proprio di grande aiuto. [applauso+] [ciao]
Avatar utente
fanale
Aficionado
Aficionado
 
Messaggi: 38
Iscritto il: ven set 14, 2007 8:10 pm
Località: Cinisello Balsamo(MI)

Errore caricamento ctccw32.dll

Messaggioda yumechan83 » sab mar 22, 2008 10:47 am

Salve, sono una nuova iscritta e anche io ho lo stesso problema...
Ho scaricato hijackthis e ho fatto la scansione..
il risultato è stato questo,...potete aiutarmi?......

Grazie!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10.29.09, on 22/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Programmi\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Jepssen\Desktop\WLinstaller.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jepssen\Desktop\HijackThis.exe
C:\Programmi\Windows Live\installer\Dashboard.exe
C:\Programmi\Windows Live\installer\WLSetupSvc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart17.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programmi\Symantec AntiVirus\DefWatch.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programmi\Symantec AntiVirus\SavRoam.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programmi\Symantec AntiVirus\Rtvscan.exe

--
End of file - 6343 bytes
Avatar utente
yumechan83
Neo Iscritto
Neo Iscritto
 
Messaggi: 17
Iscritto il: sab mar 22, 2008 10:35 am

Re: Errore caricamento ctccw32.dll

Messaggioda crazy.cat » sab mar 22, 2008 11:22 am

yumechan83 ha scritto:il risultato è stato questo,...potete aiutarmi?..

Nel log il file ctccw32.dll non si vede.
Per rimuovere la scritta dall'avvio devi andare nel registro di configurazione
Start - esegui - scrivi regedit e premi Ok
Vai su modifica - trova e scrivi ctccw32.dll, poi rimuovi tutte le chiavi di registro che trovi, dopo la prima prosegui con F3 sino in fondo al registro.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda yumechan83 » sab mar 22, 2008 11:41 am

infatti mi chiedevo quello..........come mai non c'è?..possibile che sia perché ho il symantec in scansione..? a me continua a trovarmelo in continuazione l'antivirus..

mi mette:
Backdoor.trojan Cleaned by delection 2 osa9.dll

Trojan.Dropper Cleaned by delection 3 ctccw32.dll

A ogni scan cosi..e non riesco a toglierli..ripararli e nient'altro..

Comunque provo a fare come mi hai suggerito!!
Grazie!!
Avatar utente
yumechan83
Neo Iscritto
Neo Iscritto
 
Messaggi: 17
Iscritto il: sab mar 22, 2008 10:35 am

Messaggioda crazy.cat » sab mar 22, 2008 11:48 am

Per i file "difficili" puoi provare ad usare Killlbox o Unlocker ed eliminare i file infetti.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda yumechan83 » sab mar 22, 2008 4:17 pm

..và..!! Forse ce l'ho davvero fatta!!!

Grazie mille per i consigli ed il supporto!! [^]
Avatar utente
yumechan83
Neo Iscritto
Neo Iscritto
 
Messaggi: 17
Iscritto il: sab mar 22, 2008 10:35 am


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 11 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising