| Autore |
Discussione  |
|
n/a
deleted
    
1470 Messaggi |
Inserito il - 05/12/2005 : 15:54:46
|
Per Hunter1270
Aspetta un attimo,ho visto i post di Vanx e Cypto e mi sono riletta il tuo(mi ero fermata al Bit defender e non ho letto con attenzione il seguito del tuo post)
Un errore del genere può essere causato si dalla Ram ,ma non perchè sia guasta altrimenti,come dice Cypto avresti altri problemi (in pratica o và o non và), è molto più probabile che un'applicazione (Bitdefender)non riesca a leggere nella ram . e il problema credo che sia nel Kernell,non sò che SO hai ma prova ad andare quì e segui le istruzioni per aggionarlo (sono in ITA e molto chiare)
htt*://[www].java[.com]/it/download/help/ikernel.xml |
 |
|
|
hunter1270
Junior Member
 
50 Messaggi |
Inserito il - 05/12/2005 : 17:56:31
|
Questo è il log di Hijacktis Logfile of HijackThis v1.99.1 Scan saved at 17.57.17, on 05/12/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Programmi\File comuni\Real\Update_OB\realsched.exe C:\Programmi\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Programmi\Java\jre1.5.0_01\bin\jusched.exe C:\WINDOWS\System32\rundll32.exe C:\Programmi\AVPersonal\AVGNT.EXE C:\Programmi\AVPersonal\AVGUARD.EXE C:\Programmi\AVPersonal\AVSched32.EXE C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Programmi\AVPersonal\AVWUPSRV.EXE C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe C:\Programmi\File comuni\Microsoft Shared\Works Shared\wkcalrem.exe C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4ss.exe C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4gui.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4gui.exe C:\Programmi\Mozilla Firefox\firefox.exe C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe c:\progra~1\softwin\bitdef~1\bdmcon.exe C:\Documents and Settings\pippopio\Documenti\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = htt*://it.*******[.com]/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = htt*://[www].virgilio.it/free R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O1 - Hosts: 82.195.155.5 c3310.z1301.winmx[.com] c3311.z1301.winmx[.com] c3312.z1301.winmx[.com] c3313.z1301.winmx[.com] c3314.z1301.winmx[.com] c3315.z1301.winmx[.com] c3316.z1301.winmx[.com] c3317.z1301.winmx[.com] c3318.z1301.winmx[.com] c3319.z1301.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1302.winmx[.com] c3311.z1302.winmx[.com] c3312.z1302.winmx[.com] c3313.z1302.winmx[.com] c3314.z1302.winmx[.com] c3315.z1302.winmx[.com] c3316.z1302.winmx[.com] c3317.z1302.winmx[.com] c3318.z1302.winmx[.com] c3319.z1302.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1303.winmx[.com] c3311.z1303.winmx[.com] c3312.z1303.winmx[.com] c3313.z1303.winmx[.com] c3314.z1303.winmx[.com] c3315.z1303.winmx[.com] c3316.z1303.winmx[.com] c3317.z1303.winmx[.com] c3318.z1303.winmx[.com] c3319.z1303.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1304.winmx[.com] c3311.z1304.winmx[.com] c3312.z1304.winmx[.com] c3313.z1304.winmx[.com] c3314.z1304.winmx[.com] c3315.z1304.winmx[.com] c3316.z1304.winmx[.com] c3317.z1304.winmx[.com]c3318.z1304.winmx[.com] c3319.z1304.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1305.winmx[.com] c3311.z1305.winmx[.com] c3312.z1305.winmx[.com] c3313.z1305.winmx[.com] c3314.z1305.winmx[.com] c3315.z1305.winmx[.com] c3316.z1305.winmx[.com] c3317.z1305.winmx[.com] c3318.z1305.winmx[.com] c3319.z1305.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1306.winmx[.com] c3311.z1306.winmx[.com] c3312.z1306.winmx[.com] c3313.z1306.winmx[.com] c3314.z1306.winmx[.com] c3315.z1306.winmx[.com] c3316.z1306.winmx[.com] c3317.z1306.winmx[.com]c3318.z1306.winmx[.com] c3319.z1306.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1301.winmx[.com] c3521.z1301.winmx[.com] c3522.z1301.winmx[.com] c3523.z1301.winmx[.com] c3524.z1301.winmx[.com] c3525.z1301.winmx[.com] c3526.z1301.winmx[.com] c3527.z1301.winmx[.com] c3528.z1301.winmx[.com] c3529.z1301.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1302.winmx[.com] c3521.z1302.winmx[.com] c3522.z1302.winmx[.com] c3523.z1302.winmx[.com] c3524.z1302.winmx[.com] c3525.z1302.winmx[.com] c3526.z1302.winmx[.com] c3527.z1302.winmx[.com] 3528.z1302.winmx[.com] c3529.z1302.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1303.winmx[.com] c3521.z1303.winmx[.com] c3522.z1303.winmx[.com] c3523.z1303.winmx[.com] c3524.z1303.winmx[.com] c3525.z1303.winmx[.com] c3526.z1303.winmx[.com] c3527.z1303.winmx[.com] c3528.z1303.winmx[.com] c3529.z1303.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1304.winmx[.com] c3521.z1304.winmx[.com] c3522.z1304.winmx[.com] c3523.z1304.winmx[.com] c3524.z1304.winmx[.com] c3525.z1304.winmx[.com] c3526.z1304.winmx[.com] c3527.z1304.winmx[.com] c3528.z1304.winmx[.com] c3529.z1304.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1305.winmx[.com] c3521.z1305.winmx[.com] c3522.z1305.winmx[.com] c3523.z1305.winmx[.com] c3524.z1305.winmx[.com] c3525.z1305.winmx[.com] c3526.z1305.winmx[.com] c3527.z1305.winmx[.com] c3528.z1305.winmx[.com] c3529.z1305.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1306.winmx[.com] c3521.z1306.winmx[.com] c3522.z1306.winmx[.com] c3523.z1306.winmx[.com]c3524.z1306.winmx[.com] c3525.z1306.winmx[.com] c3526.z1306.winmx[.com] c3527.z1306.winmx[.com] c3528.z1306.winmx[.com]c3529.z1306.winmx[.com] O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {6754A456-BAD9-11D4-93D3-00B0D03A2F91} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmi\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmi\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Programmi\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [AVGCtrl] "C:\Programmi\AVPersonal\AVGNT.EXE" /min O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [AVSCHED32] C:\Programmi\AVPersonal\AVSched32.EXE /min O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [BDNewsAgent] C:\Programmi\Softwin\BitDefender Free Edition\bdnagent.exe O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe" O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Promemoria del Calendario di Microsoft Works.lnk = ? O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Programmi\Hello\PicasaCapture.dll O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Programmi\Hello\PicasaCapture.dll O14 - IERESET.INF: START_PAGE_URL=htt*://[www].virgilio.it/free O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - htt*://download.mcafee[.com]/molbin/iss-loc/mcfscan/2,1,0,4630/mcfscan .cab O17 - HKLM\System\CCS\Services\Tcpip\..\{BEBD8E77-5F3B-4AE5-9D70-2A1925D8A7C5}: NameServer = 85.37.17.55 151.99.125.1 O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programmi\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programmi\AVPersonal\AVWUPSRV.EXE O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Programmi\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Programmi\File comuni\Softwin\BitDefender Communicator\xcommsvr.exe
Il problema persiste
Grazie a tutti per la vostra gentilezza. |
 |
|
|
n/a
deleted
    
Città: Nascosta
1310 Messaggi |
Inserito il - 05/12/2005 : 18:43:06
|
Non mi sembra molto pulito il tuo log... vedrai che Alex tiguiderà nella pulizia egregiamente....
P.S> Secondo me l'errore non sta nel kernel.....
P.P.S> Fossi in te hunter io installerei SP1 almeno....ciauz ciauz |
 |
|
|
n/a
deleted
    
1470 Messaggi |
Inserito il - 05/12/2005 : 20:02:10
|
| Giusta l'osservazione di Cypto per il momento vai quì htt*://[www].notrace.it/forum2/topic.asp?TOPIC_ID=4901 e segui le istruzioni.dopo posta un log nuovo |
 |
|
|
Er-Gladiatore
Advanced Member
    

Città: Roma
2540 Messaggi |
Inserito il - 05/12/2005 : 20:05:57
|
| CAMBIA P2P PROCURATENE UNO + PULITO. |
 |
|
|
hunter1270
Junior Member
 
50 Messaggi |
Inserito il - 05/12/2005 : 20:39:44
|
Grazie a tutti per le sollecite risposte.Rimedio drastico ma inevitabile.........Ricca formattazione!!!!!!!!!!!! Domani il pc andra' sicuramente meglio!!! Ciao e grazie di nuovo!!! |
 |
|
|
n/a
deleted
    
1470 Messaggi |
Inserito il - 05/12/2005 : 20:50:45
|
Alzi bandiera bianca in fretta,era talmente semplice mettere a posto il log che neanche immagini. Però un lato positivo c'è: la prossima volta sai già cosa fare..... |
 |
|
|
hunter1270
Junior Member
 
50 Messaggi |
Inserito il - 06/12/2005 : 08:25:40
|
| Volevo formattare ma non mi puoi dire che alzo bandiera bianca in fretta..........Ho fatto la scansione con Panda e mi ha trovato un virus,poi ad aware un po' di schifezze poi l'ora era tarda e ho spento tutto.Ora faccio la scansione on line con Trend e poi ti faccio sapere...[.com]unque siete mmmmolto disponibili!!!!!!!!Grazie. |
 |
|
|
n/a
deleted
    
1470 Messaggi |
Inserito il - 06/12/2005 : 08:48:15
|
Citazione: Messaggio inserito da hunter1270
Volevo formattare ma non mi puoi dire che alzo bandiera bianca in fretta..........Ho fatto la scansione con Panda e mi ha trovato un virus,poi ad aware un po' di schifezze poi l'ora era tarda e ho spento tutto.Ora faccio la scansione on line con Trend e poi ti faccio sapere...[.com]unque siete mmmmolto disponibili!!!!!!!!Grazie.
Mi fà piacere leggerti allora alziamo la bandiera di guerra. Le due scansioni online hanno più effetto in simultanea. quando ti rimetti all'opera rifai il tutto come descritto e dopo posta un log di HJK |
 |
|
|
hunter1270
Junior Member
 
50 Messaggi |
Inserito il - 06/12/2005 : 09:45:45
|
Allora.....Trend on line non ha trovato nulla,Spyboot nemmeno e regSeeker pochissima roba. Questo e il log di Hijacthis.Siamo sempre in coma irreversibile o si notano sintomi di miglioramento? Logfile of HijackThis v1.99.1 Scan saved at 9.46.36, on 06/12/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Programmi\File comuni\Real\Update_OB\realsched.exe C:\Programmi\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Programmi\Java\jre1.5.0_01\bin\jusched.exe C:\Programmi\AVPersonal\AVGNT.EXE C:\WINDOWS\System32\rundll32.exe C:\Programmi\AVPersonal\AVSched32.EXE C:\Programmi\AVPersonal\AVGUARD.EXE C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe C:\Programmi\File comuni\Microsoft Shared\Works Shared\wkcalrem.exe C:\Programmi\AVPersonal\AVWUPSRV.EXE C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4ss.exe C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4gui.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4gui.exe C:\Documents and Settings\pippopio\Documenti\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = htt*://it.*******[.com]/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = htt*://[www].virgilio.it/free R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O1 - Hosts: 82.195.155.5 c3310.z1301.winmx[.com] c3311.z1301.winmx[.com] c3312.z1301.winmx[.com] c3313.z1301.winmx[.com] c3314.z1301.winmx[.com] c3315.z1301.winmx[.com] c3316.z1301.winmx[.com] c3317.z1301.winmx[.com] c3318.z1301.winmx[.com] c3319.z1301.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1302.winmx[.com] c3311.z1302.winmx[.com] c3312.z1302.winmx[.com] c3313.z1302.winmx[.com] c3314.z1302.winmx[.com] c3315.z1302.winmx[.com] c3316.z1302.winmx[.com] c3317.z1302.winmx[.com] c3318.z1302.winmx[.com] c3319.z1302.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1303.winmx[.com] c3311.z1303.winmx[.com] c3312.z1303.winmx[.com] c3313.z1303.winmx[.com] c3314.z1303.winmx[.com] c3315.z1303.winmx[.com] c3316.z1303.winmx[.com] c3317.z1303.winmx[.com] c3318.z1303.winmx[.com] c3319.z1303.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1304.winmx[.com] c3311.z1304.winmx[.com] c3312.z1304.winmx[.com] c3313.z1304.winmx[.com] c3314.z1304.winmx[.com] c3315.z1304.winmx[.com] c3316.z1304.winmx[.com] c3317.z1304.winmx[.com]c3318.z1304.winmx[.com] c3319.z1304.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1305.winmx[.com] c3311.z1305.winmx[.com] c3312.z1305.winmx[.com] c3313.z1305.winmx[.com] c3314.z1305.winmx[.com] c3315.z1305.winmx[.com] c3316.z1305.winmx[.com] c3317.z1305.winmx[.com] c3318.z1305.winmx[.com] c3319.z1305.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1306.winmx[.com] c3311.z1306.winmx[.com] c3312.z1306.winmx[.com] c3313.z1306.winmx[.com] c3314.z1306.winmx[.com] c3315.z1306.winmx[.com] c3316.z1306.winmx[.com] c3317.z1306.winmx[.com]c3318.z1306.winmx[.com] c3319.z1306.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1301.winmx[.com] c3521.z1301.winmx[.com] c3522.z1301.winmx[.com] c3523.z1301.winmx[.com] c3524.z1301.winmx[.com] c3525.z1301.winmx[.com] c3526.z1301.winmx[.com] c3527.z1301.winmx[.com] c3528.z1301.winmx[.com] c3529.z1301.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1302.winmx[.com] c3521.z1302.winmx[.com] c3522.z1302.winmx[.com] c3523.z1302.winmx[.com] c3524.z1302.winmx[.com] c3525.z1302.winmx[.com] c3526.z1302.winmx[.com] c3527.z1302.winmx[.com] 3528.z1302.winmx[.com] c3529.z1302.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1303.winmx[.com] c3521.z1303.winmx[.com] c3522.z1303.winmx[.com] c3523.z1303.winmx[.com] c3524.z1303.winmx[.com] c3525.z1303.winmx[.com] c3526.z1303.winmx[.com] c3527.z1303.winmx[.com] c3528.z1303.winmx[.com] c3529.z1303.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1304.winmx[.com] c3521.z1304.winmx[.com] c3522.z1304.winmx[.com] c3523.z1304.winmx[.com] c3524.z1304.winmx[.com] c3525.z1304.winmx[.com] c3526.z1304.winmx[.com] c3527.z1304.winmx[.com] c3528.z1304.winmx[.com] c3529.z1304.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1305.winmx[.com] c3521.z1305.winmx[.com] c3522.z1305.winmx[.com] c3523.z1305.winmx[.com] c3524.z1305.winmx[.com] c3525.z1305.winmx[.com] c3526.z1305.winmx[.com] c3527.z1305.winmx[.com] c3528.z1305.winmx[.com] c3529.z1305.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1306.winmx[.com] c3521.z1306.winmx[.com] c3522.z1306.winmx[.com] c3523.z1306.winmx[.com]c3524.z1306.winmx[.com] c3525.z1306.winmx[.com] c3526.z1306.winmx[.com] c3527.z1306.winmx[.com] c3528.z1306.winmx[.com]c3529.z1306.winmx[.com] O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {6754A456-BAD9-11D4-93D3-00B0D03A2F91} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmi\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmi\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Programmi\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [AVGCtrl] "C:\Programmi\AVPersonal\AVGNT.EXE" /min O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [AVSCHED32] C:\Programmi\AVPersonal\AVSched32.EXE /min O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [BDNewsAgent] C:\Programmi\Softwin\BitDefender Free Edition\bdnagent.exe O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe" O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Promemoria del Calendario di Microsoft Works.lnk = ? O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Programmi\Hello\PicasaCapture.dll O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Programmi\Hello\PicasaCapture.dll O14 - IERESET.INF: START_PAGE_URL=htt*://[www].virgilio.it/free O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - htt*://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro[.com]/housecall/xscan53 .cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - htt*://acs.pandasoftware[.com]/activescan/as5free/asinst .cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - htt*://download.mcafee[.com]/molbin/iss-loc/mcfscan/2,1,0,4630/mcfscan .cab O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programmi\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programmi\AVPersonal\AVWUPSRV.EXE O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Programmi\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Programmi\File comuni\Softwin\BitDefender Communicator\xcommsvr.exe
|
 |
|
|
n/a
deleted
    
Città: eh eh ti piacerebbe saperlo
2419 Messaggi |
Inserito il - 06/12/2005 : 10:05:19
|
Intanto fixa queste voci(cioe con hijackthis le selezioni e poi premi fix checked)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer O1 - Hosts: 82.195.155.5 c3310.z1301.winmx[.com] c3311.z1301.winmx[.com] c3312.z1301.winmx[.com] c3313.z1301.winmx[.com] c3314.z1301.winmx[.com] c3315.z1301.winmx[.com] c3316.z1301.winmx[.com] c3317.z1301.winmx[.com] c3318.z1301.winmx[.com] c3319.z1301.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1302.winmx[.com] c3311.z1302.winmx[.com] c3312.z1302.winmx[.com] c3313.z1302.winmx[.com] c3314.z1302.winmx[.com] c3315.z1302.winmx[.com] c3316.z1302.winmx[.com] c3317.z1302.winmx[.com] c3318.z1302.winmx[.com] c3319.z1302.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1303.winmx[.com] c3311.z1303.winmx[.com] c3312.z1303.winmx[.com] c3313.z1303.winmx[.com] c3314.z1303.winmx[.com] c3315.z1303.winmx[.com] c3316.z1303.winmx[.com] c3317.z1303.winmx[.com] c3318.z1303.winmx[.com] c3319.z1303.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1304.winmx[.com] c3311.z1304.winmx[.com] c3312.z1304.winmx[.com] c3313.z1304.winmx[.com] c3314.z1304.winmx[.com] c3315.z1304.winmx[.com] c3316.z1304.winmx[.com] c3317.z1304.winmx[.com]c3318.z1304.winmx[.com] c3319.z1304.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1305.winmx[.com] c3311.z1305.winmx[.com] c3312.z1305.winmx[.com] c3313.z1305.winmx[.com] c3314.z1305.winmx[.com] c3315.z1305.winmx[.com] c3316.z1305.winmx[.com] c3317.z1305.winmx[.com] c3318.z1305.winmx[.com] c3319.z1305.winmx[.com] O1 - Hosts: 82.195.155.5 c3310.z1306.winmx[.com] c3311.z1306.winmx[.com] c3312.z1306.winmx[.com] c3313.z1306.winmx[.com] c3314.z1306.winmx[.com] c3315.z1306.winmx[.com] c3316.z1306.winmx[.com] c3317.z1306.winmx[.com]c3318.z1306.winmx[.com] c3319.z1306.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1301.winmx[.com] c3521.z1301.winmx[.com] c3522.z1301.winmx[.com] c3523.z1301.winmx[.com] c3524.z1301.winmx[.com] c3525.z1301.winmx[.com] c3526.z1301.winmx[.com] c3527.z1301.winmx[.com] c3528.z1301.winmx[.com] c3529.z1301.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1302.winmx[.com] c3521.z1302.winmx[.com] c3522.z1302.winmx[.com] c3523.z1302.winmx[.com] c3524.z1302.winmx[.com] c3525.z1302.winmx[.com] c3526.z1302.winmx[.com] c3527.z1302.winmx[.com] 3528.z1302.winmx[.com] c3529.z1302.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1303.winmx[.com] c3521.z1303.winmx[.com] c3522.z1303.winmx[.com] c3523.z1303.winmx[.com] c3524.z1303.winmx[.com] c3525.z1303.winmx[.com] c3526.z1303.winmx[.com] c3527.z1303.winmx[.com] c3528.z1303.winmx[.com] c3529.z1303.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1304.winmx[.com] c3521.z1304.winmx[.com] c3522.z1304.winmx[.com] c3523.z1304.winmx[.com] c3524.z1304.winmx[.com] c3525.z1304.winmx[.com] c3526.z1304.winmx[.com] c3527.z1304.winmx[.com] c3528.z1304.winmx[.com] c3529.z1304.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1305.winmx[.com] c3521.z1305.winmx[.com] c3522.z1305.winmx[.com] c3523.z1305.winmx[.com] c3524.z1305.winmx[.com] c3525.z1305.winmx[.com] c3526.z1305.winmx[.com] c3527.z1305.winmx[.com] c3528.z1305.winmx[.com] c3529.z1305.winmx[.com] O1 - Hosts: 82.195.155.5 c3520.z1306.winmx[.com] c3521.z1306.winmx[.com] c3522.z1306.winmx[.com] c3523.z1306.winmx[.com]c3524.z1306.winmx[.com] c3525.z1306.winmx[.com] c3526.z1306.winmx[.com] c3527.z1306.winmx[.com] c3528.z1306.winmx[.com]c3529.z1306.winmx[.com] O2 - BHO: (no name) - {6754A456-BAD9-11D4-93D3-00B0D03A2F91} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Promemoria del Calendario di Microsoft Works.lnk = ? O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Programmi\Hello\PicasaCapture.dll O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Programmi\Hello\PicasaCapture.dll O14 - IERESET.INF: START_PAGE_URL=htt*://[www].virgilio.it/free O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - htt*://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro[.com]/housecall/xscan53 .cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - htt*://acs.pandasoftware[.com]/activescan/as5free/asinst .cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - htt*://download.mcafee[.com]/molbin/iss-loc/mcfscan/2,1,0,4630/mcfscan .cab
mi sembra che qualche schifezza sia stata tolta....prova a fare una scansione online anche qua se non l'hai gia fatta htt*://[www].kaspersky[.com]/virusscanner
riposta un log che poi ti dico cos'altro fare..(mi raccomando per adesso non usare programmi di sharing come emule..winmx e altro...perchè se no non finiamo + di guarirti)....
ciaooooooooo |
 |
|
|
hunter1270
Junior Member
 
50 Messaggi |
Inserito il - 06/12/2005 : 10:36:17
|
Nuovo log Logfile of HijackThis v1.99.1 Scan saved at 10.38.57, on 06/12/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Programmi\File comuni\Real\Update_OB\realsched.exe C:\Programmi\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Programmi\Java\jre1.5.0_01\bin\jusched.exe C:\WINDOWS\System32\rundll32.exe C:\Programmi\AVPersonal\AVGNT.EXE C:\Programmi\AVPersonal\AVGUARD.EXE C:\Programmi\AVPersonal\AVSched32.EXE C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe C:\Programmi\AVPersonal\AVWUPSRV.EXE C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4ss.exe C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4gui.exe C:\Programmi\Kerio\Personal Firewall 4\kpf4gui.exe C:\Documents and Settings\pippopio\Documenti\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = htt*://it.*******[.com]/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = htt*://[www].virgilio.it/free R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmi\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmi\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Programmi\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [AVGCtrl] "C:\Programmi\AVPersonal\AVGNT.EXE" /min O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [AVSCHED32] C:\Programmi\AVPersonal\AVSched32.EXE /min O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [BDNewsAgent] C:\Programmi\Softwin\BitDefender Free Edition\bdnagent.exe O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe" O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programmi\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programmi\AVPersonal\AVWUPSRV.EXE O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Programmi\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Programmi\File comuni\Softwin\BitDefender Communicator\xcommsvr.exe
|
 |
|
|
n/a
deleted
    
Città: eh eh ti piacerebbe saperlo
2419 Messaggi |
Inserito il - 06/12/2005 : 11:23:59
|
bene dai non vedo + cose potenzialmente gravi.....(aspetta anche un parere di alex)....
ma bisogna togliere dall'avvio automatico tutte quelle cose che non servono....
hai regcleaner installato??se non c'è l'hai vai qua
Regcleaner(pulizia registro e avvio) htt*://[www].worldstart[.com]/weekly-download/archives/reg-cleaner4.3.htm
Guida regcleaner htt*://[www].tutorialpc.it/regcleaner.asp
poi ti posto i processi da togliere...
ciaooooo |
 |
|
|
hunter1270
Junior Member
 
50 Messaggi |
Inserito il - 06/12/2005 : 11:28:42
|
Ho installato Reg Cleaner. Che faccio ora? |
 |
|
|
n/a
deleted
    
Città: eh eh ti piacerebbe saperlo
2419 Messaggi |
Inserito il - 06/12/2005 : 11:33:28
|
lo apri e vai su startup list poi vai su file(sopra startup list)--save list as txt...poi copii incolli il txt e lo posti qua..
ciaoooooooo |
 |
|
Discussione  |
|