|
| HOMEPAGE | INDICE FORUM | REGOLAMENTO | ::. | NEI PREFERITI | .:: | RSS Forum | RSS News | NEWS web | NEWS software | |
| PUBBLICITA' | | | ARTICOLI | WIN XP | VISTA | WIN 7 | REGISTRI | SOFTWARE | MANUALI | RECENSIONI | LINUX | HUMOR | HARDWARE | DOWNLOAD | | | CERCA nel FORUM » | |
28-03-2008, 17.34.47 | #1 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
May day XP semibloccato
1 avvio lentissimo (4-5') 2 avvio applicazioni come sopra 3 hd gira continuamente. controllato con: avast, a-squared free, reg compact, clean my registry, spybot, hijackthis, tootsje xp optimizer, ccleaner, zone alarm. deframmentato con perfect disk nessun virus spyware o altre schifezze del genere. xp he sp2 PIV 3.4GHz, 1GB ram mb, ASUSTeK Model P5P800, scheda grafica ASUS A9550 Series may day Prima di formattare posso provare qualcos'altro?
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 17.42.03 | #2 |
Le so' .. tutteee
Registrato: 27-11-2002
Loc.: Sorrento
Messaggi: 2.006
|
normalmente ti direi di postere un log di hijaackthis ma ho come una sensazione manda prima un log dell'esecuzione automatica di spybot.
apri spybot - utilità - esecuzione automatica e in alto a dx fai clic su esporta
___________________________________
Chiacchiere e tabaccher e legn, o Banc e Napule nunne 'mpegn |
28-03-2008, 17.42.04 | #3 |
Senior Member
Registrato: 06-02-2008
Messaggi: 260
|
Controlla se per caso l'HD è andato in modalità PIO.
___________________________________
- "Che vitaccia!" disse il Cacciavite. - Non discutere mai con un idiota... ti trascina al suo livello e ti batte con l'esperienza. |
28-03-2008, 17.43.01 | #4 |
Le so' .. tutteee
Registrato: 27-11-2002
Loc.: Sorrento
Messaggi: 2.006
|
giusto cacciavite, nn ci avevo pensato
___________________________________
Chiacchiere e tabaccher e legn, o Banc e Napule nunne 'mpegn |
28-03-2008, 17.50.26 | #5 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
hd è in modalità DMA
avvio spy bot
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 17.54.43 | #6 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
2008-01-28 blindman.exe (1.0.0.7) 2008-01-28 SDDelFile.exe (1.0.2.4) 2008-01-28 SDMain.exe (1.0.0.5) 2007-10-07 SDShred.exe (1.0.1.2) 2008-01-28 SDUpdate.exe (1.0.8.8) 2008-01-28 SDWinSec.exe (1.0.0.11) 2008-01-28 SpybotSD.exe (1.5.2.20) 2008-01-28 TeaTimer.exe (1.5.2.16) 2007-07-12 unins000.exe (51.41.0.0) 2008-01-30 unins001.exe (51.49.0.0) 2008-01-28 Update.exe (1.4.0.6) 2008-01-28 advcheck.dll (1.5.4.5) 2007-04-02 aports.dll (2.1.0.0) 2005-05-31 borlndmm.dll (7.0.4.453) 2005-05-31 delphimm.dll (7.0.4.453) 2007-11-17 DelZip179.dll (1.79.7.4) 2008-01-28 SDFiles.dll (1.5.1.19) 2008-01-28 SDHelper.dll (1.5.0.11) 2008-01-28 Tools.dll (2.1.3.3) 2005-05-31 UnzDll.dll (1.73.1.1) 2005-05-31 ZipDll.dll (1.73.2.0) 2008-03-26 Includes\Cookies.sbi 2007-12-26 Includes\Dialer.sbi 2008-03-26 Includes\DialerC.sbi 2008-03-26 Includes\HeavyDuty.sbi 2008-03-19 Includes\Hijackers.sbi 2008-03-26 Includes\HijackersC.sbi 2008-02-27 Includes\Keyloggers.sbi 2008-03-26 Includes\KeyloggersC.sbi 2004-11-29 Includes\LSP.sbi 2008-03-26 Includes\Malware.sbi 2008-03-26 Includes\MalwareC.sbi 2008-03-26 Includes\PUPS.sbi 2008-03-26 Includes\PUPSC.sbi 2008-03-26 Includes\Revision.sbi 2008-01-09 Includes\Security.sbi 2008-03-26 Includes\SecurityC.sbi 2008-03-19 Includes\Spybots.sbi 2008-03-26 Includes\SpybotsC.sbi 2007-11-06 Includes\Tracks.uti 2008-03-19 Includes\Trojans.sbi 2008-03-26 Includes\TrojansC.sbi 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 17.58.52 | #7 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
Logfile of HijackThis v1.99.1
Scan saved at 16.57.26, on 28/03/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe C:\Programmi\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Programmi\a-squared Free\a2service.exe C:\WINDOWS\ATKKBService.exe C:\Programmi\File comuni\LightScribe\LSSrvc.exe C:\Programmi\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe C:\Programmi\Alwil Software\Avast4\ashWebSv.exe C:\Programmi\Raxco\PerfectDisk\PDEngine.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\Programmi\HP\HP Software Update\HPWuSchd2.exe C:\Programmi\ASUS\Ai Booster\OverClk.exe C:\Programmi\ATI Technologies\ATI.ACE\CLI.EXE C:\Programmi\ATI Technologies\ATI.ACE\cli.exe C:\Programmi\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\rundll32.exe C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe C:\Programmi\Analog Devices\SoundMAX\SMax4.exe C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Programmi\PeerGuardian2\pg2.exe C:\Programmi\TweakRAM\TweakRAM.exe C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\Programmi\ASUS\SmartDoctor\SmartDoctor.exe C:\Programmi\HP\Digital Imaging\bin\hpqimzone.exe C:\Programmi\AdunanzA\eMule_AdnzA.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Programmi\Spybot - Search & Destroy\SpybotSD.exe E:\nero vision temp\winPenPack.exe E:\nero vision temp\winPenPack\Bin\hijackthis\HijackThis.exe
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 18.05.04 | #8 |
Le so' .. tutteee
Registrato: 27-11-2002
Loc.: Sorrento
Messaggi: 2.006
|
hai sbagliato a mandare entrambi i log quello che ci interessa di entrambi è la parte sottostante a quella che hai incollato
___________________________________
Chiacchiere e tabaccher e legn, o Banc e Napule nunne 'mpegn |
28-03-2008, 18.09.46 | #9 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
hijiackthis
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.it/sphome.aspx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Programmi\IEPro\iepro.dll O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe " O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\SMax4.exe" /tray O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [TweakRAM] C:\Programmi\TweakRAM\TweakRAM.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: ASUS Smartdoctor.lnk = C:\Programmi\ASUS\SmartDoctor\SmartDoctor.exe O4 - Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Programmi\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Programmi\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Programmi\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Programmi\IEPro\iepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1191938570625 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Programmi\File comuni\Creative Labs Shared\Service\CreativeLicensing.exe O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe O23 - Service: PACSPTISVR - Unknown owner - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PDExchange - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDExchange.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SsBeSvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 18.11.54 | #10 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
Located: HK_LM:Run, Acrobat Assistant 8.0
command: "C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" file: C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe size: 620152 MD5: A21E70B4F972CA396A80013D0D436350 Located: HK_LM:Run, ATICCC command: "C:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe" file: C:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe size: 90112 MD5: 0DC2E1B6951BD2170BC47F0EEBF629B3 Located: HK_LM:Run, ATIPTA command: C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe file: C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe size: 344064 MD5: C26E9199CD11DE98F4BF4B8FDC136918 Located: HK_LM:Run, avast! command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe size: 79224 MD5: 88D86112DD9F2BB6A603674706C7E846 Located: HK_LM:Run, BluetoothAuthenticationAgent command: rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent file: size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: HK_LM:Run, EPSON Stylus D88 Series command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA BE.EXE /P23 "EPSON Stylus D88 Series" /O6 "USB001" /M "Stylus D88" file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA BE.EXE size: 98304 MD5: 2DB5D295CC797561F01AF10750AF219A Located: HK_LM:Run, HP Software Update command: C:\Programmi\HP\HP Software Update\HPWuSchd2.exe file: C:\Programmi\HP\HP Software Update\HPWuSchd2.exe size: 49152 MD5: AC116F16A7716A720A45D7EA47CFD983 Located: HK_LM:Run, Launch Ai Booster command: "C:\Programmi\ASUS\Ai Booster\OverClk.exe" file: C:\Programmi\ASUS\Ai Booster\OverClk.exe size: 3627008 MD5: FBF38D8A3A9303D69BF9E5E62C5EC3F2 Located: HK_LM:Run, NeroFilterCheck command: C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe file: C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe size: 155648 MD5: C93AB037A8C792D5F8A1A9FC88A7C7C5 Located: HK_LM:Run, RemoteControl command: "C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" file: C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe size: 32768 MD5: 1EEA64D8599B5B7BD8721498E4019CF0 Located: HK_LM:Run, SoundMAX command: "C:\Programmi\Analog Devices\SoundMAX\SMax4.exe" /tray file: C:\Programmi\Analog Devices\SoundMAX\SMax4.exe size: 708608 MD5: 8DA174BF8FEB090DF2B006355508C2E9 Located: HK_LM:Run, SoundMAXPnP command: C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe file: C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe size: 1404928 MD5: 680D55BD887B34E9AE90D47B03941066 Located: HK_LM:Run, SunJavaUpdateSched command: "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe " file: C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe size: 144784 MD5: 836DC47E6CAD975304D1D3EB2F516A1C Located: HK_LM:Run, Zone Labs Client command: "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe" file: C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe size: 968696 MD5: 031E3FF4AB3328716F0945D4822C07D5 Located: HK_CU:RunOnce, NeroHomeFirstStart where: PE_C_ADMINISTRATOR... command: C:\Programmi\File comuni\Ahead\Lib\NMFirstStart.exe file: C:\Programmi\File comuni\Ahead\Lib\NMFirstStart.exe size: 10752 MD5: E15AAD68F518E2C6C91E790FDD6B9820 Located: HK_CU:Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} where: PE_C_CLAUDIA... command: "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" file: C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe size: 143360 MD5: CE8D6FF5BEDDA023F7A1BB3FA34130DE Located: HK_CU:Run, LightScribe Control Panel where: PE_C_CLAUDIA... command: C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden file: C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe size: 451872 MD5: 2950DF0E7445F9E4CA8709FBFFD213C4 Located: HK_CU:Run, MSMSGS where: PE_C_CLAUDIA... command: "C:\Programmi\Messenger\msmsgs.exe" /background file: C:\Programmi\Messenger\msmsgs.exe size: 1694208 MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259 Located: HK_CU:Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} where: PE_C_MARCO... command: "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" file: C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe size: 143360 MD5: CE8D6FF5BEDDA023F7A1BB3FA34130DE Located: HK_CU:Run, ctfmon.exe where: PE_C_MARCO... command: C:\WINDOWS\system32\ctfmon.exe file: C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5B33B4265966EE063C7FBEA28958D9C2 Located: HK_CU:Run, PeerGuardian where: PE_C_MARCO... command: C:\Programmi\PeerGuardian2\pg2.exe file: C:\Programmi\PeerGuardian2\pg2.exe size: 1421824 MD5: 4F2FF640B393438F9C80BD1F72794224 Located: HK_CU:Run, ctfmon.exe where: S-1-5-21-1454471165-1078081533-725345543-1004... command: C:\WINDOWS\system32\ctfmon.exe file: C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5B33B4265966EE063C7FBEA28958D9C2 Located: HK_CU:Run, PeerGuardian where: S-1-5-21-1454471165-1078081533-725345543-1004... command: C:\Programmi\PeerGuardian2\pg2.exe file: C:\Programmi\PeerGuardian2\pg2.exe size: 1421824 MD5: 4F2FF640B393438F9C80BD1F72794224 Located: HK_CU:Run, SpybotSD TeaTimer where: S-1-5-21-1454471165-1078081533-725345543-1004... command: C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe file: C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe size: 2097488 MD5: A9A5DB6AC3721BE698B996913693D73F Located: HK_CU:Run, TweakRAM where: S-1-5-21-1454471165-1078081533-725345543-1004... command: C:\Programmi\TweakRAM\TweakRAM.exe file: C:\Programmi\TweakRAM\TweakRAM.exe size: 1209856 MD5: 6B7B4D20138A293954D4CA14884F7878 Located: Esecuzione automatica (utente), ASUS Smartdoctor.lnk where: C:\Documents and Settings\Maurizio\Menu Avvio\Programmi\Esecuzione automatica... command: C:\Programmi\ASUS\SmartDoctor\SmartDoctor.exe file: C:\Programmi\ASUS\SmartDoctor\SmartDoctor.exe size: 1093632 MD5: 91EC7B54322A49315F60AD4BCA14E0E3
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 18.13.00 | #11 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
Located: Esecuzione automatica (utente), Avvio rapido di HP Image Zone.lnk
where: C:\Documents and Settings\Maurizio\Menu Avvio\Programmi\Esecuzione automatica... command: C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe file: C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe size: 73728 MD5: 806EE198284D569253EB6A1D1180B37D Located: WinLogon, AtiExtEvent command: Ati2evxx.dll file: Ati2evxx.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, crypt32chain command: crypt32.dll file: crypt32.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cryptnet command: cryptnet.dll file: cryptnet.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cscdll command: cscdll.dll file: cscdll.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, ScCertProp command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, Schedule command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, sclgntfy command: sclgntfy.dll file: sclgntfy.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, SensLogn command: WlNotify.dll file: WlNotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, termsrv command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, WgaLogon command: WgaLogon.dll file: WgaLogon.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, wlballoon command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated!
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 18.14.11 | #12 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
Scusate ho spezzato in vari tronconi, i log sono un po' lunghi. gli ultimi sono di spy bot
grazie
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 18.23.08 | #13 |
Le so' .. tutteee
Registrato: 27-11-2002
Loc.: Sorrento
Messaggi: 2.006
|
allora per quanto riguarda spybot comincia col deselzionare le seguenti voci riavvia e poi vediamo
Located: HK_LM:Run, Acrobat Assistant 8.0 command: "C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" file: C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe Located: HK_LM:Run, ATICCC command: "C:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe" file: C:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe Located: HK_LM:Run, ATIPTA command: C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe file: C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe Located: HK_LM:Run, EPSON Stylus D88 Series command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA BE.EXE /P23 "EPSON Stylus D88 Series" /O6 "USB001" /M "Stylus D88" file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA BE.EXE Located: HK_LM:Run, HP Software Update command: C:\Programmi\HP\HP Software Update\HPWuSchd2.exe file: C:\Programmi\HP\HP Software Update\HPWuSchd2.exe Located: HK_LM:Run, Launch Ai Booster command: "C:\Programmi\ASUS\Ai Booster\OverClk.exe" file: C:\Programmi\ASUS\Ai Booster\OverClk.exe Located: HK_LM:Run, NeroFilterCheck command: C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe file: C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe Located: HK_LM:Run, RemoteControl command: "C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" file: C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe Located: HK_LM:Run, SoundMAX command: "C:\Programmi\Analog Devices\SoundMAX\SMax4.exe" /tray file: C:\Programmi\Analog Devices\SoundMAX\SMax4.exe Located: HK_LM:Run, SoundMAXPnP command: C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe file: C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe Located: HK_LM:Run, SunJavaUpdateSched command: "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe " file: C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe Located: HK_CU:RunOnce, NeroHomeFirstStart where: PE_C_ADMINISTRATOR... command: C:\Programmi\File comuni\Ahead\Lib\NMFirstStart.exe file: C:\Programmi\File comuni\Ahead\Lib\NMFirstStart.exe Located: HK_CU:Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} where: PE_C_CLAUDIA... command: "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" file: C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe Located: HK_CU:Run, LightScribe Control Panel where: PE_C_CLAUDIA... command: C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden file: C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe Located: HK_CU:Run, MSMSGS where: PE_C_CLAUDIA... command: "C:\Programmi\Messenger\msmsgs.exe" /background file: C:\Programmi\Messenger\msmsgs.exe Located: HK_CU:Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} where: PE_C_MARCO... command: "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" file: C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe Located: Esecuzione automatica (utente), ASUS Smartdoctor.lnk where: C:\Documents and Settings\Maurizio\Menu Avvio\Programmi\Esecuzione automatica... command: C:\Programmi\ASUS\SmartDoctor\SmartDoctor.exe file: C:\Programmi\ASUS\SmartDoctor\SmartDoctor.exe Located: Esecuzione automatica (utente), Avvio rapido di HP Image Zone.lnk where: C:\Documents and Settings\Maurizio\Menu Avvio\Programmi\Esecuzione automatica... command: C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe file: C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe Located: WinLogon, AtiExtEvent command: Ati2evxx.dll file: Ati2evxx.dll riavvia, facci sapere se ci sono miglioramenti e poi riposta solo il log di hijaack nuovo
___________________________________
Chiacchiere e tabaccher e legn, o Banc e Napule nunne 'mpegn |
28-03-2008, 18.53.42 | #14 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
Sensibilmente migliorato ma l'hd gira un tot.
Ho notato che al 1 avvio di un'applicativo occorre + tempo che al secondo avvio.
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
28-03-2008, 18.54.20 | #15 |
Hero Member
Registrato: 12-07-2001
Loc.: Bologna
Messaggi: 775
|
Logfile of HijackThis v1.99.1
Scan saved at 17.51.20, on 28/03/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe C:\Programmi\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Programmi\a-squared Free\a2service.exe C:\WINDOWS\ATKKBService.exe C:\Programmi\File comuni\LightScribe\LSSrvc.exe C:\Programmi\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe C:\Programmi\Alwil Software\Avast4\ashWebSv.exe C:\Programmi\Raxco\PerfectDisk\PDEngine.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\rundll32.exe C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe C:\Programmi\Analog Devices\SoundMAX\SMax4.exe C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe C:\Programmi\PeerGuardian2\pg2.exe C:\Programmi\TweakRAM\TweakRAM.exe C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE E:\nero vision temp\winPenPack.exe E:\nero vision temp\winPenPack\Bin\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.it/sphome.aspx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Programmi\IEPro\iepro.dll O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe " O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\SMax4.exe" /tray O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [TweakRAM] C:\Programmi\TweakRAM\TweakRAM.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: ASUS Smartdoctor.lnk.disabled O4 - Startup: Avvio rapido di HP Image Zone.lnk.disabled O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Programmi\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Programmi\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Programmi\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Programmi\IEPro\iepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1191938570625 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
___________________________________
Se qualcosa può andar male... lo farà. I° legge di Murphy |
Utenti attualmente attivi che stanno leggendo questa discussione: 1 (0 utenti e 1 ospiti) | |
Strumenti discussione | |
|
|