Condividi:        

mi potete dare un controllo per favore?

Come rimuovere virus e spyware? Le carte di credito sono davvero sicure in rete? È possibile navigare anonimi? Con quali programmi tutelare la propria privacy? Come proteggere i file importanti? Se volete una risposta a queste e altre domande questo è il luogo giusto!

Moderatori: m.paolo, kadosh, Luke57

mi potete dare un controllo per favore?

Postdi ventus85 » 03/03/07 12:35

Il computer si è rallentato parecchio in questi giorni, credo ci sia un po' di robaccia.
Posto i log relativi...
hijackthis
Codice: Seleziona tutto
Logfile of HijackThis v1.99.1
Scan saved at 12.33.11, on 03/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\QuickTime\bak\qttask.exe
C:\Programmi\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\OpenOffice.org 2.0\program\soffice.exe
C:\Programmi\OpenOffice.org 2.0\program\soffice.BIN
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmi\ESTsoft\ALZip\ALZip.exe
C:\Documents and Settings\utente\Impostazioni locali\Temp\_AZTMP41_\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Programmi\Conexant\AccessRunner ADSL\CnxDslTb.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\bak\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [ApacheTomcatMonitor] "C:\Programmi\Apache Software Foundation\Tomcat 5.5\bin\tomcat5w.exe" //MS//Tomcat5
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\RegistrySmart.exe" -boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Programmi\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MySQL - Unknown owner - C:\Programmi\MySQL\MySQL.exe (file missing)
O23 - Service: Apache Tomcat 4.1 (Tomcat4) - Unknown owner - C:\Programmi\Apache Software Foundation\Tomcat 4.1\bin\tomcat4.exe" //RS//Tomcat4 (file missing)
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Programmi\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
Fixwareout
Codice: Seleziona tutto
Fixwareout
Last edited 12/06/2006
Post this report in the forums please
...
Prerun check
[HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""

...
...
Reg Entries that were deleted
...

Random Runs removed from HKLM
...
...
 
PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
 
»»»»» Searching by size/names...
 
»»»»»
Search five digit cs, dm kd and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal
 
Other suspects.
C:\WINDOWS\System32\{FA29CA2B-1D5B-4C36-BF17-101CE5F022C8}.exe
 
»»»»» Misc files.
 
»»»»» Checking for older varients covered by the Rem3 tool.
...
Postrun check
[HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""

antivirus AntiVir
Codice: Seleziona tutto
AntiVir PersonalEdition Classic
Report file date: martedì 27 febbraio 2007  10:12

Scanning for 685357 virus strains and unwanted programs.

Licensed to:      Avira AntiVir PersonalEdition Classic
Serial number:    0000149996-ADJIE-0001
Platform:         Windows XP
Windows version:  (Service Pack 2)  [5.1.2600]
Username:         utente
Computer name:    UTENTE-1549B299

Version information:
BUILD.DAT    : 217           12749 Bytes  05/12/2006 17:00:00
AVSCAN.EXE   : 7.0.3.5      208936 Bytes  17/01/2007 07:21:54
AVSCAN.DLL   : 7.0.3.1       35880 Bytes  14/12/2006 09:00:25
LUKE.DLL     : 7.0.3.2      143400 Bytes  14/12/2006 09:00:26
LUKERES.DLL  : 7.0.2.0        9256 Bytes  14/12/2006 09:00:26
ANTIVIR0.VDF : 6.35.0.1    7371264 Bytes  31/05/2006 08:05:04
ANTIVIR1.VDF : 6.37.1.151  4303360 Bytes  23/02/2007 08:08:38
ANTIVIR2.VDF : 6.37.1.152     2048 Bytes  23/02/2007 08:08:38
ANTIVIR3.VDF : 6.37.1.168    49152 Bytes  27/02/2007 09:10:37
AVEWIN32.DLL : 7.3.1.38    2322944 Bytes  24/02/2007 08:08:38
AVPREF.DLL   : 7.0.2.0       23592 Bytes  14/12/2006 09:00:25
AVREP.DLL    : 6.37.1.100  1142824 Bytes  17/02/2007 08:08:40
AVRPBASE.DLL : 7.0.0.0     2162728 Bytes  30/03/2006 08:43:31
AVPACK32.DLL : 7.2.0.5      368680 Bytes  29/10/2006 09:52:28
AVREG.DLL    : 7.0.1.2       30760 Bytes  17/01/2007 07:21:54
NETNT.DLL    : 6.32.0.0       6696 Bytes  27/09/2005 07:56:49
RCIMAGE.DLL  : 7.0.1.3     2097192 Bytes  14/12/2006 09:00:24
RCTEXT.DLL   : 7.0.12.1      77864 Bytes  14/12/2006 09:00:24

Configuration settings for the scan:
Jobname..........................: Manual Selection
Configuration file...............: C:\Documents and Settings\All Users\Dati applicazioni\AntiVir PersonalEdition Classic\PROFILES\folder.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: F:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: martedì 27 febbraio 2007  10:12

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Modules have been scanned
Scan process 'avcenter.exe' - '1' Modules have been scanned
Scan process 'wuauclt.exe' - '1' Modules have been scanned
Scan process 'SpybotSD.exe' - '1' Modules have been scanned
Scan process 'IEXPLORE.EXE' - '1' Modules have been scanned
Scan process 'alg.exe' - '1' Modules have been scanned
Scan process 'wmiprvse.exe' - '1' Modules have been scanned
Scan process 'soffice.bin' - '1' Modules have been scanned
Scan process 'soffice.exe' - '1' Modules have been scanned
Scan process 'reader_sl.exe' - '1' Modules have been scanned
Scan process 'msmsgs.exe' - '1' Modules have been scanned
Scan process 'avgnt.exe' - '1' Modules have been scanned
Scan process 'NeroCheck.exe' - '1' Modules have been scanned
Scan process 'SOUNDMAN.EXE' - '1' Modules have been scanned
Scan process 'wdfmgr.exe' - '1' Modules have been scanned
Scan process 'explorer.exe' - '1' Modules have been scanned
Scan process 'ati2evxx.exe' - '1' Modules have been scanned
Scan process 'tomcat4.exe' - '1' Modules have been scanned
Scan process 'mysqld-nt.exe' - '1' Modules have been scanned
Scan process 'avguard.exe' - '1' Modules have been scanned
Scan process 'sched.exe' - '1' Modules have been scanned
Scan process 'spoolsv.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'ati2evxx.exe' - '1' Modules have been scanned
Scan process 'lsass.exe' - '1' Modules have been scanned
Scan process 'services.exe' - '1' Modules have been scanned
Scan process 'winlogon.exe' - '1' Modules have been scanned
Scan process 'csrss.exe' - '1' Modules have been scanned
Scan process 'smss.exe' - '1' Modules have been scanned
33 processes with 33 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
      [NOTE]      No virus was found!
Boot sector 'F:\'
      [NOTE]      In the drive 'F:\' no data medium is inserted!

Starting to scan the registry.
The registry was scanned ( 21 files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
      [WARNING]   The file could not be opened!
C:\WINDOWS\system32\modqaozs.exe
      [WARNING]   The file could not be opened!
Begin scan in 'F:\'
The path F:\ could not be found!
Impossibile trovare il file specificato.



End of the scan: martedì 27 febbraio 2007  11:17
Used time:  1:04:33 min

The scan has been done completely.

  12953 Scanning directories
 970912 Files were scanned
      0 viruses and/or unwanted programs were found
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      2 Files cannot be scanned
 970912 Files not concerned
   6423 Archives were scanned
      2 Warnings
      5 Notes


Vi ringrazio in anticipo....
Avatar utente
ventus85
Utente Senior
 
Post: 327
Iscritto il: 05/07/06 09:36

Sponsor
 

Postdi SkunkWorks 68 » 03/03/07 12:45

A vedere così non mi sembra ci sia nulla fuori posto...
volendo un file missing nel log da fixare.
Fai una bella pulizia dei files temporanei con CCleaner e un defrag e vedi se cambia qualcosa.
ciao
Avatar utente
SkunkWorks 68
Utente Senior
 
Post: 2336
Iscritto il: 03/03/07 08:55

Postdi ventus85 » 03/03/07 19:48

SkunkWorks 68 ha scritto:A vedere così non mi sembra ci sia nulla fuori posto...
volendo un file missing nel log da fixare.
Fai una bella pulizia dei files temporanei con CCleaner e un defrag e vedi se cambia qualcosa.
ciao

Ok, ora lo faccio...se non cambia nulla posto di nuovo...grazie intanto x ora!
Avatar utente
ventus85
Utente Senior
 
Post: 327
Iscritto il: 05/07/06 09:36


Torna a Sicurezza e Privacy


Topic correlati a "mi potete dare un controllo per favore?":


Chi c’è in linea

Visitano il forum: Nessuno e 32 ospiti