PROBLEMA URGENTE con explorer!!!
  • In diretta da GamesVillage.it
    • News
    • -
    • In Evidenza
    • -
    • Recensioni
    • -
    • RetroGaming
    • -
    • Anteprime
    • -
    • Video
    • -
    • Cinema

Visualizzazione risultati da 1 a 11 di 11

Discussione: PROBLEMA URGENTE con explorer!!!

Cambio titolo
  1. #1
    e domani sarà peggio... L'avatar di Dagoth Gares
    Registrato il
    10-06
    Località
    A Fanculo
    Messaggi
    1.174

    PROBLEMA URGENTE con explorer!!!

    explorer.exe, ogni qualvolta ke si apre, mi si chiude subito dopo automaticamente e continua così, imperterrito fino a quando nn si chiude completamente!! nn so se sia un virus o qualcosa!! sto appena facendo delle scansioni!! come posso riselvere??
    AIUTATEMI VI PREGO!!


  2. #2
    Utente L'avatar di speaker
    Registrato il
    05-05
    Località
    C:\WINDOWS\system32
    Messaggi
    2.378
    Citazione Luigi Miolli
    explorer.exe, ogni qualvolta ke si apre, mi si chiude subito dopo automaticamente e continua così, imperterrito fino a quando nn si chiude completamente!! nn so se sia un virus o qualcosa!! sto appena facendo delle scansioni!! come posso riselvere??
    AIUTATEMI VI PREGO!!
    hai provato ad avviare in modalità provvisoria?

  3. #3
    THENEW
    Ospite
    potresti provare a reinstallare internet explorer !!!

  4. #4
    Utente L'avatar di speaker
    Registrato il
    05-05
    Località
    C:\WINDOWS\system32
    Messaggi
    2.378
    Citazione THENEW
    potresti provare a reinstallare internet explorer !!!
    non è internet explorer che gli da problemi, bensì explorer.exe il processo di windows. non c'entra na mazza con internet

  5. #5
    e domani sarà peggio... L'avatar di Dagoth Gares
    Registrato il
    10-06
    Località
    A Fanculo
    Messaggi
    1.174
    ho fatto una scansione antivirus e nn è risultato niente!! come posso fare??
    credo sia un trojan ke mi entra in continuazione attraverso internet explorer 7 (difatti ogni minuto si apre una finestra pubblicitaria). ora provo ad avviare in modalità provvisoria ma ke ci concludo così?? come firewall uso Sygate e come antivirus avast!

    edit: ho anke fatto una scansione con Hijackthis ma nn è risultato nulla di strano, con windows defender mi trova un trojan chiamato "Virtumonde" ma nn riesce ad eliminarlo xké subito dopo appare un errore!! 8(

    edit2: ho eliminato il trojan con VundoFix ma rientra subito dopo e mi richiude subito explorer.exe, di continuo!!
    ora posto il log di HijackThis, spero proprio mi sappiate aiutare xké sta diventando davvero fastidioso!

    Spoiler:
    Logfile of HijackThis v1.99.1
    Scan saved at 22.53.16, on 31/08/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmi\Sygate\SPF\smc.exe
    C:\Programmi\Avast4\aswUpdSv.exe
    C:\Programmi\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Programmi\Avast4\ashMaiSv.exe
    C:\Programmi\Avast4\ashWebSv.exe
    C:\PROGRA~1\Avast4\ashDisp.exe
    C:\Programmi\Windows Defender\MSASCui.exe
    C:\Programmi\IObit SmartDefrag\IObit SmartDefrag.exe
    C:\Programmi\Stardock\TopDesk\topdesk.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\LClock\LClock.exe
    C:\Programmi\Vista Sidebar\sidebar.exe
    C:\PROGRA~1\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Documents and Settings\Administrator\Desktop\VundoFix.exe
    C:\Documents and Settings\Administrator\Desktop\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.alice.it/search/home/index.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.alice.it
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www.alice.it:80
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O1 - Hosts: 85.18.118.210 L2testauthd.lineage2.com
    O1 - Hosts: 85.18.118.210 L2authd.lineage2.com
    O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {3EFC2AA3-E517-4C13-8FA9-FC3C07CCE07F} - C:\WINDOWS\system32\jkhfe.dll (file missing)
    O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programmi\Stardock\Desktop Sidebar\sbhelp.dll
    O2 - BHO: (no name) - {5CCC1460-FE83-4545-ADD8-CD32B290AE0C} - C:\WINDOWS\system32\pmkhg.dll (file missing)
    O2 - BHO: (no name) - {60D13203-2DC3-4E31-8909-E70BEC39F8} - C:\WINDOWS\system32\ljjgdde.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {B8662238-E99D-4CCC-B482-A0DE9FDDC956} - C:\WINDOWS\system32\ddaby.dll (file missing)
    O2 - BHO: (no name) - {D99D4785-DE3C-4D1D-8EFD-FE9BB65B2BDC} - C:\WINDOWS\system32\vturq.dll (file missing)
    O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Programmi\Styler\TB\StylerTB.dll
    O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [SmartDefrag] "C:\Programmi\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
    O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Programmi\Stardock\WinCustomize\BootSkin\BootSkin. exe" /StartupJobs
    O4 - HKLM\..\Run: [TopDesk] C:\Programmi\Stardock\TopDesk\topdesk.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LClock] C:\Programmi\LClock\LClock.exe
    O4 - Startup: Thoosje Sidebar .lnk = C:\Programmi\Vista Sidebar\sidebar.exe
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmi\Stardock\Desktop Sidebar\sbhelp.dll
    O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmi\Stardock\Desktop Sidebar\sbhelp.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Programmi\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - https://my.levelupgames.ph/keycrypt/npkcx.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3B2309-72D9-48F8-A6D3-F3AD76B11635}: NameServer = 192.168.0.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{71C5913E-FF23-434E-8627-361EB0CF25D0}: NameServer = 85.37.17.58 85.38.28.94
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmi\File comuni\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FILECO~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
    O20 - Winlogon Notify: ljjgdde - C:\WINDOWS\SYSTEM32\ljjgdde.dll
    O20 - Winlogon Notify: tapiperf32 - C:\WINDOWS\SYSTEM32\tapiperf32.dll
    O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

    Ultima modifica di Dagoth Gares; 31-08-2007 alle 22:53:59


  6. #6
    e domani sarà peggio... L'avatar di Dagoth Gares
    Registrato il
    10-06
    Località
    A Fanculo
    Messaggi
    1.174
    nessuno può aiutarmi?? almeno un modo per bloccare questo dannatissimo trojan!!


  7. #7
    Utente L'avatar di Cero
    Registrato il
    09-05
    Località
    Neive
    Messaggi
    8.203

  8. #8
    Utente L'avatar di FulValBot
    Registrato il
    11-06
    Località
    Roma
    Messaggi
    16.201
    Citazione Luigi Miolli
    ho fatto una scansione antivirus e nn è risultato niente!! come posso fare??
    credo sia un trojan ke mi entra in continuazione attraverso internet explorer 7 (difatti ogni minuto si apre una finestra pubblicitaria). ora provo ad avviare in modalità provvisoria ma ke ci concludo così?? come firewall uso Sygate e come antivirus avast!

    edit: ho anke fatto una scansione con Hijackthis ma nn è risultato nulla di strano, con windows defender mi trova un trojan chiamato "Virtumonde" ma nn riesce ad eliminarlo xké subito dopo appare un errore!! 8(

    edit2: ho eliminato il trojan con VundoFix ma rientra subito dopo e mi richiude subito explorer.exe, di continuo!!
    ora posto il log di HijackThis, spero proprio mi sappiate aiutare xké sta diventando davvero fastidioso!

    Spoiler:
    Logfile of HijackThis v1.99.1
    Scan saved at 22.53.16, on 31/08/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmi\Sygate\SPF\smc.exe
    C:\Programmi\Avast4\aswUpdSv.exe
    C:\Programmi\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Programmi\Avast4\ashMaiSv.exe
    C:\Programmi\Avast4\ashWebSv.exe
    C:\PROGRA~1\Avast4\ashDisp.exe
    C:\Programmi\Windows Defender\MSASCui.exe
    C:\Programmi\IObit SmartDefrag\IObit SmartDefrag.exe
    C:\Programmi\Stardock\TopDesk\topdesk.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\LClock\LClock.exe
    C:\Programmi\Vista Sidebar\sidebar.exe
    C:\PROGRA~1\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Documents and Settings\Administrator\Desktop\VundoFix.exe
    C:\Documents and Settings\Administrator\Desktop\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.alice.it/search/home/index.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.alice.it
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www.alice.it:80
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O1 - Hosts: 85.18.118.210 L2testauthd.lineage2.com
    O1 - Hosts: 85.18.118.210 L2authd.lineage2.com
    O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {3EFC2AA3-E517-4C13-8FA9-FC3C07CCE07F} - C:\WINDOWS\system32\jkhfe.dll (file missing)
    O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programmi\Stardock\Desktop Sidebar\sbhelp.dll
    O2 - BHO: (no name) - {5CCC1460-FE83-4545-ADD8-CD32B290AE0C} - C:\WINDOWS\system32\pmkhg.dll (file missing)
    O2 - BHO: (no name) - {60D13203-2DC3-4E31-8909-E70BEC39F8} - C:\WINDOWS\system32\ljjgdde.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {B8662238-E99D-4CCC-B482-A0DE9FDDC956} - C:\WINDOWS\system32\ddaby.dll (file missing)
    O2 - BHO: (no name) - {D99D4785-DE3C-4D1D-8EFD-FE9BB65B2BDC} - C:\WINDOWS\system32\vturq.dll (file missing)
    O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Programmi\Styler\TB\StylerTB.dll
    O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [SmartDefrag] "C:\Programmi\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
    O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Programmi\Stardock\WinCustomize\BootSkin\BootSkin. exe" /StartupJobs
    O4 - HKLM\..\Run: [TopDesk] C:\Programmi\Stardock\TopDesk\topdesk.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LClock] C:\Programmi\LClock\LClock.exe
    O4 - Startup: Thoosje Sidebar .lnk = C:\Programmi\Vista Sidebar\sidebar.exe
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmi\Stardock\Desktop Sidebar\sbhelp.dll
    O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmi\Stardock\Desktop Sidebar\sbhelp.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Programmi\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - https://my.levelupgames.ph/keycrypt/npkcx.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3B2309-72D9-48F8-A6D3-F3AD76B11635}: NameServer = 192.168.0.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{71C5913E-FF23-434E-8627-361EB0CF25D0}: NameServer = 85.37.17.58 85.38.28.94
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmi\File comuni\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FILECO~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
    O20 - Winlogon Notify: ljjgdde - C:\WINDOWS\SYSTEM32\ljjgdde.dll
    O20 - Winlogon Notify: tapiperf32 - C:\WINDOWS\SYSTEM32\tapiperf32.dll
    O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

    fixa questa roba:

    O2 - BHO: (no name) - {3EFC2AA3-E517-4C13-8FA9-FC3C07CCE07F} - C:\WINDOWS\system32\jkhfe.dll (file missing)

    O2 - BHO: (no name) - {5CCC1460-FE83-4545-ADD8-CD32B290AE0C} - C:\WINDOWS\system32\pmkhg.dll (file missing)

    O2 - BHO: (no name) - {60D13203-2DC3-4E31-8909-E70BEC39F8} - C:\WINDOWS\system32\ljjgdde.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA5E23E045} - (no file)

    O2 - BHO: (no name) - {B8662238-E99D-4CCC-B482-A0DE9FDDC956} - C:\WINDOWS\system32\ddaby.dll (file missing)

    O2 - BHO: (no name) - {D99D4785-DE3C-4D1D-8EFD-FE9BB65B2BDC} - C:\WINDOWS\system32\vturq.dll (file missing)

    O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - https://my.levelupgames.ph/keycrypt/npkcx.cab

    O20 - Winlogon Notify: ljjgdde - C:\WINDOWS\SYSTEM32\ljjgdde.dll

    O20 - Winlogon Notify: tapiperf32 - C:\WINDOWS\SYSTEM32\tapiperf32.dll


    cmq le scansioni le devi fare in modalità provvisoria senza ripristino. anche hijackthis usalo in modalità provvisoria NON di rete.

  9. #9
    e domani sarà peggio... L'avatar di Dagoth Gares
    Registrato il
    10-06
    Località
    A Fanculo
    Messaggi
    1.174
    appena cerco di fixare questa stringa la stringa: O2 - BHO: (no name) - {60D13203-2DC3-4E31-8909-E70BEC39F8} - C:\WINDOWS\system32\ljjgdde.dll


    mi appare questo messaggio, anke in modalità provvisoria:

    Spoiler:


    cosa dovrei fare??
    il problema è ke nn fixa quella stringa!!


  10. #10
    Utente L'avatar di speaker
    Registrato il
    05-05
    Località
    C:\WINDOWS\system32
    Messaggi
    2.378
    dice di chiudere tutte le finestre aperte (sia di internet explorer che di windows)

  11. #11
    Utente L'avatar di FulValBot
    Registrato il
    11-06
    Località
    Roma
    Messaggi
    16.201
    devi chiudere le altre finestre e lasciare solo hijackthis aperto. normalmente le scansioni si fanno senza altri programmi aperti, non è una cosa nuova, si sapeva...

Regole di Scrittura

  • Tu non puoi inviare nuove discussioni
  • Tu non puoi inviare risposte
  • Tu non puoi inviare allegati
  • Tu non puoi modificare i tuoi messaggi
  •