Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

Non mi funzionano gli antispyware e gli aggiornamenti etc.

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

Non mi funzionano gli antispyware e gli aggiornamenti etc.

Messaggioda Armal » lun nov 24, 2008 11:03 pm

Ho un problema che da un paio di giorni mi affligge il pc, in breve questo che presuppongo sia un bellissimo virus mi blocca gli antispyware, non solo..l' aggiornamento del mio antivirus è bloccato (avg 8.0) e non mi apre le pagine internet releative al download di antispyware,ho fatto una scansione con avg e mi ha rilevato un paio di cose,successivamente ho fatto pure un giro con hijackthis di cui vi posto i logLogfile of HijackThis v1.99.1
Scan saved at 21.18.22, on 24/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
C:\Programmi\File comuni\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmi\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\Programmi\OpenOffice.org 2.2\program\soffice.exe
C:\Programmi\OpenOffice.org 2.2\program\soffice.BIN
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Windows Live\Messenger\msnmsgr.exe
C:\Programmi\Windows Live\Messenger\usnsvc.exe
C:\Programmi\Safari\Safari.exe
C:\Programmi\AVG\AVG8\avgscanx.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmi\AVG\AVG8\avgui.exe
C:\Documents and Settings\giorgio\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O1 - Hosts: 195.24.77.120 L2authd.lineage2.com # Frintezza Shard
O1 - Hosts: 195.24.77.120 L2testauthd.lineage2.com # Frintezza Shard
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com # Bypass GameGuard's Error
O2 - BHO: (no name) - {73259091-9574-4ED8-A40F-7F65AFC28634} - (no file)
O2 - BHO: (no name) - {E6FD8D57-97A0-4538-BE9F-17FAFD18DDEB} - (no file)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Programmi\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmi\File comuni\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programmi\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Programmi\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll",AppEntry -REG "Aethra\ADSL EB1070 USB"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmi\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: &Clean Traces - C:\Programmi\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Programmi\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Programmi\DAP\dapextie2.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\programmi\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{024151B0-6248-4149-93DB-A6D036F1AC90}: NameServer = 85.37.17.44 85.38.28.90
O17 - HKLM\System\CS1\Services\Tcpip\..\{024151B0-6248-4149-93DB-A6D036F1AC90}: NameServer = 85.37.17.44 85.38.28.90
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

da quel che ho visto potrebbe essere bugle e ho usato findykill da voi consigliato ma nulla, potete aiutarmi per favore ? grazie in anticipo
Avatar utente
Armal
Neo Iscritto
Neo Iscritto
 
Messaggi: 4
Iscritto il: lun nov 24, 2008 10:27 pm

Re: Non mi funzionano gli antispyware e gli aggiornamenti etc.

Messaggioda Amantide » lun nov 24, 2008 11:06 pm

Ciao e benvenuto. [:)]

Scarica ComboFix ed esegui la scansione seguendo queste istruzioni (giù in fondo). Al termine della scansione verrà creato il file di report C:\combofix.txt, copia qui il suo contenuto.
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Re: Non mi funzionano gli antispyware e gli aggiornamenti etc.

Messaggioda Armal » lun nov 24, 2008 11:13 pm

questo simpatico virus mi da page not found pure per combofix...non so che fare vedo se riesco a farmelo dare
Avatar utente
Armal
Neo Iscritto
Neo Iscritto
 
Messaggi: 4
Iscritto il: lun nov 24, 2008 10:27 pm


Re: Non mi funzionano gli antispyware e gli aggiornamenti etc.

Messaggioda Amantide » lun nov 24, 2008 11:30 pm

Scarica il ComboFix rinominato da qui e vedi se magari riesci ad eseguire la scansione dalla modalità provvisoria.
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Re: Non mi funzionano gli antispyware e gli aggiornamenti etc.

Messaggioda Armal » lun nov 24, 2008 11:37 pm

ComboFix 08-11-23.02 - giorgio 2008-11-24 23:27:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.254 [GMT 1:00]

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\giorgio\Dati applicazioni\SpeedRunner
c:\documents and settings\giorgio\Dati applicazioni\SpeedRunner\config.cfg
c:\documents and settings\giorgio\Impostazioni locali\Temporary Internet Files\bestwiner.stt
c:\documents and settings\giorgio\Impostazioni locali\Temporary Internet Files\fbk.sts
c:\windows\system32\drivers\TDSSpqlt.sys
c:\windows\system32\pac.txt
c:\windows\system32\TDSShrxm.dll
c:\windows\system32\TDSSkkbi.log
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSmtvd.dat
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoiqn.dll
c:\windows\system32\TDSSrhyp.log
c:\windows\system32\TDSSsahc.dll
c:\windows\system32\TDSSvtql.dll
c:\windows\system32\TDSSxfum.dll
c:\windows\system32\vFMVwyxx.ini
c:\windows\system32\vFMVwyxx.ini2

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS


((((((((((((((((((((((((( Files Creati Da 2008-10-24 al 2008-11-24 )))))))))))))))))))))))))))))))))))
.

2008-11-24 22:18 . 2008-11-24 23:05 <DIR> d-------- c:\programmi\FindyKill
2008-11-24 21:56 . 2008-11-24 21:56 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\TuneUp Software
2008-11-24 21:46 . 2008-11-24 21:46 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-11-24 21:46 . 2008-11-24 21:46 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-11-24 21:46 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 21:46 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 21:27 . 2008-11-24 21:27 <DIR> d-------- c:\documents and settings\giorgio\Dati applicazioni\Uniblue
2008-11-24 20:41 . 2007-05-28 23:31 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di stampa
2008-11-24 20:41 . 2007-05-28 23:31 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di rete
2008-11-24 20:41 . 2007-05-28 23:31 <DIR> d-------- c:\documents and settings\Administrator\Preferiti
2008-11-24 20:41 . 2007-05-28 21:38 <DIR> d--h----- c:\documents and settings\Administrator\Modelli
2008-11-24 20:41 . 2007-05-28 23:31 <DIR> dr------- c:\documents and settings\Administrator\Menu Avvio
2008-11-24 20:41 . 2007-05-28 23:31 <DIR> d--h----- c:\documents and settings\Administrator\Impostazioni locali
2008-11-24 20:41 . 2007-05-28 23:31 <DIR> d-------- c:\documents and settings\Administrator\Documenti
2008-11-24 20:41 . 2007-05-28 23:31 <DIR> dr-h----- c:\documents and settings\Administrator\Dati applicazioni
2008-11-24 20:41 . 2008-11-24 20:42 <DIR> d-------- c:\documents and settings\Administrator
2008-11-23 19:35 . 2008-11-23 19:35 4,608 --ahs---- c:\windows\system32\Thumbs.db
2008-11-23 19:33 . 2008-11-23 19:33 <DIR> d-------- c:\documents and settings\giorgio\Dati applicazioni\Antispyware
2008-11-23 17:37 . 2008-11-23 19:18 <DIR> d-------- c:\documents and settings\giorgio\Dati applicazioni\Twain
2008-11-23 17:35 . 2008-11-23 17:36 <DIR> d-------- c:\documents and settings\giorgio\Dati applicazioni\NI.GSCNS
2008-11-22 14:23 . 2008-11-22 14:23 <DIR> d-------- c:\documents and settings\giorgio\Dati applicazioni\Motive
2008-11-19 19:12 . 2008-11-23 17:36 <DIR> d-------- c:\windows\system32\dPI19
2008-11-19 19:12 . 2008-11-19 19:12 <DIR> d-------- c:\temp\FT62
2008-11-19 19:12 . 2008-11-19 19:12 <DIR> d-------- C:\Temp
2008-11-15 18:58 . 2008-11-19 22:30 116 --a------ c:\windows\NeroDigital.ini
2008-11-15 18:26 . 2008-11-15 19:24 281 --a------ c:\windows\hpqgrcpy.INI
2008-11-15 14:57 . 2008-11-15 14:57 <DIR> d-------- c:\programmi\Microsoft Games
2008-11-13 23:12 . 2008-09-04 18:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-13 23:12 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 18:00 . 2008-11-11 18:00 <DIR> d-------- c:\documents and settings\NetworkService\Dati applicazioni\Xfire
2008-11-04 17:25 . 2008-11-04 17:25 <DIR> d-------- c:\documents and settings\giorgio\Dati applicazioni\TuneUp Software
2008-11-04 17:25 . 2008-11-04 17:25 355,584 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-11-04 17:25 . 2008-05-29 09:28 28,416 --a------ c:\windows\system32\uxtuneup.dll
2008-11-04 17:24 . 2008-11-07 21:40 <DIR> d-------- c:\programmi\TuneUp Utilities 2008
2008-11-04 17:24 . 2008-11-04 17:24 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\TuneUp Software
2008-11-04 17:20 . 2008-11-04 17:20 <DIR> d-------- c:\windows\Vbox
2008-11-04 17:20 . 2008-11-04 17:20 <DIR> d-------- c:\programmi\TI Education
2008-11-03 22:11 . 2005-05-27 17:23 2,180,096 -ra------ c:\windows\system32\drivers\LVSVF2.sys
2008-11-03 22:04 . 2005-12-09 15:31 245,824 -ra------ c:\windows\system32\InstExec.exe
2008-11-03 22:04 . 2005-12-09 15:35 245,824 -ra------ c:\windows\Instexec.exe
2008-11-03 22:04 . 2005-12-09 15:31 719 -ra------ c:\windows\system32\InstExec.ini
2008-11-03 22:02 . 2008-11-03 22:02 <DIR> d-------- c:\programmi\Logitech
2008-11-03 22:02 . 2008-11-03 22:04 <DIR> d-------- c:\programmi\File comuni\Logitech
2008-11-03 22:02 . 2006-01-05 07:56 350,720 --a------ c:\windows\system32\camcpl.cpl
2008-11-03 22:02 . 2006-01-05 07:47 323,584 --a------ c:\windows\system32\CamCplRes.dll
2008-11-03 22:02 . 2004-11-01 17:22 262,144 --a------ c:\windows\system32\ElkCtrl.exe
2008-11-03 22:02 . 2006-01-05 08:13 152,576 --a------ c:\windows\system32\VxLib.dll
2008-11-03 22:02 . 2006-01-05 08:07 135,680 --a------ c:\windows\system32\VLib.dll
2008-11-03 22:02 . 2005-12-07 19:17 86,016 -ra------ c:\windows\system32\vatee.ax
2008-11-03 22:02 . 2004-11-01 17:22 57,344 --a------ c:\windows\system32\ElkCtlPS.dll
2008-11-03 22:02 . 2006-01-05 08:04 40,960 --a------ c:\windows\system32\VxLibRes.dll
2008-11-01 14:35 . 2008-11-01 14:35 <DIR> d--h----- c:\windows\PIF
2008-11-01 14:09 . 2008-11-24 20:22 <DIR> d--h----- C:\$AVG8.VAULT$
2008-10-30 02:24 . 2008-10-30 02:24 42,320 --a------ c:\windows\system32\xfcodec.dll
2008-10-26 18:32 . 2008-10-26 18:34 <DIR> d-------- c:\programmi\DAP
2008-10-26 18:32 . 2008-11-24 21:48 <DIR> d-a------ c:\documents and settings\All Users\Dati applicazioni\TEMP
2008-10-26 18:32 . 2008-10-26 18:32 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SpeedBit
2008-10-26 18:32 . 2008-10-26 18:32 479,298 --a------ c:\windows\system32\wbocx.ocx
2008-10-26 18:32 . 2008-10-26 18:32 172,032 --a------ c:\windows\system32\AniGIF.ocx
2008-10-26 18:32 . 2008-10-26 18:32 50,688 --a------ c:\windows\system32\wbhelp2.dll
2008-10-25 21:56 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-24 21:03 --------- d-----w c:\documents and settings\giorgio\Dati applicazioni\OpenOffice.org2
2008-11-23 20:27 --------- d-----w c:\programmi\SUPERAntiSpyware
2008-11-23 20:27 --------- d-----w c:\programmi\File comuni\Wise Installation Wizard
2008-11-23 16:53 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\avg8
2008-11-23 16:33 --------- d-----w c:\documents and settings\giorgio\Dati applicazioni\Xfire
2008-11-23 10:09 --------- d-----w c:\programmi\Lineage II
2008-11-22 17:08 --------- d-----w c:\programmi\Xfire
2008-11-22 13:23 --------- d-----w c:\programmi\Alice ti aiuta
2008-11-20 17:47 --------- d--h--w c:\programmi\InstallShield Installation Information
2008-11-08 15:44 --------- d-----w c:\documents and settings\giorgio\Dati applicazioni\teamspeak2
2008-10-29 17:27 --------- d-----w c:\documents and settings\giorgio\Dati applicazioni\Apple Computer
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 17:20 --------- d-----w c:\programmi\File comuni\Adobe
2008-10-18 08:29 --------- d-----w c:\programmi\iTunes
2008-10-18 08:29 --------- d-----w c:\programmi\iPod
2008-10-18 08:29 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2008-10-18 08:29 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-18 08:28 --------- d-----w c:\programmi\QuickTime
2008-10-18 08:28 --------- d-----w c:\programmi\Bonjour
2008-10-18 08:27 --------- d-----w c:\programmi\Apple Software Update
2008-10-18 08:26 --------- d-----w c:\programmi\File comuni\Apple
2008-10-18 08:19 --------- d-----w c:\programmi\Safari
2008-10-18 08:18 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Apple
2008-10-18 08:12 160 ----a-w c:\documents and settings\giorgio\Dati applicazioni\wklnhst.dat
2008-10-18 06:52 --------- d-----w c:\programmi\NETGEAR
2008-10-18 06:52 --------- d-----w c:\programmi\File comuni\InstallShield
2008-10-17 09:22 --------- d-----w c:\programmi\Microsoft CAPICOM 2.1.0.2
2008-10-15 19:08 --------- d-----w c:\programmi\Microsoft Picture It! 9
2008-10-15 19:04 --------- d-----w c:\programmi\Microsoft Works
2008-10-15 18:59 --------- d-----w c:\programmi\Microsoft Works Suite 2004
2008-10-15 17:07 --------- d-----w c:\programmi\HP
2008-10-15 17:07 --------- d-----w c:\programmi\Hewlett-Packard
2008-10-15 17:07 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Hewlett-Packard
2008-10-15 17:05 --------- d-----w c:\programmi\File comuni\HP
2008-10-15 17:04 --------- d-----w c:\programmi\File comuni\Hewlett-Packard
2008-10-15 16:53 82,380 ----a-w c:\windows\system32\drivers\AFS2K.SYS
2008-10-14 18:43 --------- d-----w c:\documents and settings\giorgio\Dati applicazioni\SUPERAntiSpyware.com
2008-10-14 18:43 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-10-14 18:07 --------- d-----w c:\programmi\Teamspeak2_RC2
2008-10-14 17:36 --------- dcsh--w c:\programmi\File comuni\WindowsLiveInstaller
2008-10-14 17:36 --------- d-----w c:\programmi\Windows Live
2008-10-14 17:30 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\WLInstaller
2008-10-14 17:24 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-10-14 17:18 --------- d-----w c:\programmi\Motive
2008-10-14 17:18 --------- d-----w c:\programmi\Common Files
2008-10-14 17:18 --------- d-----w c:\programmi\Aethra
2008-10-14 17:16 --------- d-----w c:\programmi\Telecom Italia
2008-10-10 09:48 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys
2008-10-10 09:48 --------- d-----w c:\programmi\AVG
2008-10-01 11:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-14 1234712]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-25 188416]
"HPHUPD05"="c:\programmi\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 49152]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2003-08-21 483328]
"HP Software Update"="c:\programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\programmi\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"Microsoft Works Update Detection"="c:\programmi\File comuni\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 50688]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"LogitechCameraAssistant"="c:\programmi\Logitech\Video\CameraAssistant.exe" [2006-01-05 489472]
"LogitechVideo[inspector]"="c:\programmi\Logitech\Video\InstallHelper.exe" [2006-01-05 08:15 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"CnxTrApp"="c:\programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll" [2004-04-20 247296]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-09-06 413696]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

c:\documents and settings\giorgio\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 2.2.lnk - c:\programmi\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2008-10-14 212992]
Avvio rapido di HP Image Zone.lnk - c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]
HP Digital Imaging Monitor.lnk - c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]
WG111v2 Smart Wizard Wireless Setting.lnk - c:\programmi\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2008-10-18 745472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.XVID"= xvid.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll
"VIDC.XFR1"= xfcodec.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\Xfire\\xfire.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-10-10 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-10-10 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-10 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-10-10 76040]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2008-10-18 66048]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe -k netsvcs [2004-08-19 14336]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2008-10-18 167808]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-11-04 355584]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenuto della cartella 'Scheduled Tasks'

2008-10-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-11-24 c:\windows\Tasks\Verifica e correzione automatica.job
- c:\programmi\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:27]

2008-11-22 c:\windows\Tasks\WebReg 20081122185720.job
- c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe [2004-05-28 21:47]
.
- - - - ORFÃOS REMOVIDOS - - - -

HKCU-Run-Uniblue RegistryBooster 2009 - c:\programmi\Uniblue\RegistryBooster\RegistryBooster.exe
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)


.
------- Supplementare di scansione -------
.
FireFox -: Profile - c:\documents and settings\giorgio\Dati applicazioni\Mozilla\Firefox\Profiles\9lxd04g2.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://it.start.mozilla.com/firefox?cli ... t:official
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-24 23:32:01
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\WgaLogon.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\Logitech\LVMVFM\LVPrcSrv.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\osk.exe
c:\programmi\OpenOffice.org 2.2\program\soffice.exe
c:\windows\system32\msswchx.exe
c:\programmi\OpenOffice.org 2.2\program\soffice.bin
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Ora fine scansione: 2008-11-24 23:34:32 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-11-24 22:34:26

Pre-Run: 53,323,968,512 byte disponibili
Post-Run: 53,260,177,408 byte disponibili

271 --- E O F --- 2008-11-24 20:39:05

grazie all aiuto della ragazza eccovi qua il report
Avatar utente
Armal
Neo Iscritto
Neo Iscritto
 
Messaggi: 4
Iscritto il: lun nov 24, 2008 10:27 pm

Re: Non mi funzionano gli antispyware e gli aggiornamenti etc.

Messaggioda Amantide » lun nov 24, 2008 11:56 pm

Penso che tutto ciò che c'era da rimuovere ha rimosso Combofix, nel log non vedo nient'altro di sospetto.

Riscontri ancora gli stessi problemi di prima?
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Re: Non mi funzionano gli antispyware e gli aggiornamenti etc.

Messaggioda Armal » lun nov 24, 2008 11:58 pm

no tutto perfetto grazieeeeeee [^] aggiornamenti e pagine, tutto libero
Avatar utente
Armal
Neo Iscritto
Neo Iscritto
 
Messaggi: 4
Iscritto il: lun nov 24, 2008 10:27 pm

Re: Non mi funzionano gli antispyware e gli aggiornamenti etc.

Messaggioda Amantide » mar nov 25, 2008 12:07 am

Ottimo [^]
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 7 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising