![]() |
|
#1
|
|||
|
|||
|
OK, allora mi sembra aver raccolto una qualche forma di malware che ha disattivato l'opzione di cambiare gli aggiornamenti automatici, lasciando loro permanantly spento.
Entra di HJT: Logfile di Trend Micro HijackThis v2.0.2 Scan salvato in 18:45:43, a 31/03/2008 Piattaforma: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Processi in esecuzione: C: \ WINDOWS.NEW \ System32 \ smss.exe C: \ WINDOWS.NEW \ system32 \ winlogon.exe C: \ WINDOWS.NEW \ system32 \ services.exe C: \ WINDOWS.NEW \ system32 \ lsass.exe C: \ WINDOWS.NEW \ system32 \ svchost.exe C: \ Program Files \ Windows Defender \ MsMpEng.exe C: \ WINDOWS.NEW \ System32 \ svchost.exe C: \ Program Files \ Ahead \ InCD \ InCD \ InCDsrv.exe C: \ WINDOWS.NEW \ system32 \ svchost.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccProxy.exe C: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe C: \ WINDOWS.NEW \ system32 \ spoolsv.exe C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe C: \ Program Files \ Bonjour \ mDNSResponder.exe C: \ WINDOWS.NEW \ System32 \ svchost.exe C: \ Program Files \ Common Files \ Microsoft Shared \ VS7Debug \ Mdm.exe C: \ WINDOWS.NEW \ system32 \ nvsvc32.exe C: \ WINDOWS.NEW \ System32 \ HPZipm12.exe C: \ Program Files \ Dantz \ Retrospect \ retrorun.exe C: \ PROGRA ~ 1 \ Dantz \ RETROS ~ 1 \ wdsvc.exe C: \ WINDOWS.NEW \ System32 \ svchost.exe C: \ Program Files \ Microsoft \ UPHCS \ uphclean.exe C: \ WINDOWS.NEW \ System32 \ Ltmoh.exe C: \ WINDOWS.NEW \ system32 \ taskswitch.exe C: \ Program Files \ lg_fwupdate \ fwupdate.exe C: \ Program Files \ SiteAdvisor \ 6021 \ SiteAdv.exe C: \ Program Files \ Windows Defender \ MSASCui.exe C: \ Program Files \ Ahead \ InCD \ InCD \ InCD.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe C: \ Program Files \ Java \ jre1.6.0_05 \ bin \ jusched.exe C: \ Program Files \ iTunes \ iTunesHelper.exe C: \ Program Files \ Unlocker \ UnlockerAssistant.exe C: \ WINDOWS.NEW \ system32 \ ctfmon.exe C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe C: \ Program Files \ NETGEAR \ GA311 \ GA311.exe C: \ Program Files \ NETGEAR \ WPN111 \ wpn111.exe C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor.exe C: \ Program Files \ iPod \ bin \ iPodService.exe C: \ WINDOWS.NEW \ explorer.exe C: \ Program Files \ Common Files \ Symantec Shared \ la CCPD-LC \ symlcsvc.exe C: \ WINDOWS.NEW \ system32 \ Wuauclt.exe C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WLLoginProxy.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.google.co.uk/ig?hl=en R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Local Page = R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Local Page = R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int Ethernet Impostazioni, ProxyOverride = *. locali O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll O2 - BHO: (no name) - (089FD14D-132B-48FC-8861-0048AE113215) - C: \ Program Files \ SiteAdvisor \ 6066 \ SiteAdv.dll O2 - BHO: RealPlayer Download and Record Plugin per Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: Spybot-S & D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ SpyBot ~ 1 \ SDHelper.dll O2 - BHO: NCO 2,0 IE BHO - (602ADB0E-4AFF-4217-8AA1-95DAC4DFA408) - C: \ Program Files \ Common Files \ Symantec Shared \ coShared \ Browser \ 2.0 \ coIEPlg.dll O2 - BHO: Symantec Intrusion Prevention - (6D53EC84-6AAE-4787-AEEE-F4628F01010C) - C: \ PROGRA ~ 1 \ COMUNE ~ 1 \ SYMANT ~ 1 \ IDS \ IPSBHO.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_05 \ bin \ ssv.dll O2 - BHO: FoxyTunes Toolbar Helper - (784D8FBC-4165-4D88-90FB-62907ACDD045) - C: \ Program Files \ FoxyTunes \ ForInternetExplorer \ componenti \ Internet Explorer \ FoxyTunesForIE.dll O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - c: \ Programmi \ Google \ googletoolbar3.dll O2 - BHO: Windows Live Toolbar Helper - (BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ Windows Live Toolbar \ msntb.dll O3 - Toolbar: McAfee SiteAdvisor - (0BF43445-2F28-4351-9252-17FE6E806AA0) - C: \ Program Files \ SiteAdvisor \ 6066 \ SiteAdv.dll O3 - Toolbar: Gotuit Toolbar - (3f59a812-9c30-4ecd-938d-dd73e7c6497d) - (no file) O3 - Toolbar: Toolbar FoxyTunes - (1D1901C3-F72A-46F3-9DBB-0AAA0DEEF6DF) - C: \ Program Files \ FoxyTunes \ ForInternetExplorer \ componenti \ Internet Explorer \ FoxyTunesForIE.dll O3 - Toolbar: & Google - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - c: \ Programmi \ Google \ googletoolbar3.dll O3 - Toolbar: Windows Live Toolbar - (BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ Windows Live Toolbar \ msntb.dll O3 - Toolbar: Show Norton Toolbar - (7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA) - C: \ Program Files \ Common Files \ Symantec Shared \ coShared \ Browser \ 2.0 \ CoIEPlg.dll O4 - HKLM \ .. \ Run: [LtMoh] C: \ WINDOWS.NEW \ System32 \ Ltmoh.exe O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ WINDOWS.NEW \ system32 \ NeroCheck.exe O4 - HKLM \ .. \ Run: [CoolSwitch] C: \ WINDOWS.NEW \ system32 \ taskswitch.exe O4 - HKLM \ .. \ Run: [LGODDFU] "C: \ Program Files \ lg_fwupdate \ fwupdate.exe" blrun O4 - HKLM \ .. \ Run: [SiteAdvisor] "C: \ Program Files \ SiteAdvisor \ 6021 \ SiteAdv.exe" O4 - HKLM \ .. \ Run: [Windows Defender] "C: \ Program Files \ Windows Defender \ MSASCui.exe"-hide O4 - HKLM \ .. \ Run: [InCD] "C: \ Program Files \ Ahead \ InCD \ InCD \ InCD.exe" O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [osCheck] "C: \ Programmi \ Norton Internet Security \ osCheck.exe" O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS.NEW \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS.NEW \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_05 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe" O4 - HKLM \ .. \ Run: [UnlockerAssistant] "C: \ Program Files \ Unlocker \ UnlockerAssistant.exe" O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS.NEW \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe O4 - HKCU \ .. \ Run: [WMPNSCFG] C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ System32 \ ctfmon.exe (User 'SERVIZIO LOCALE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ System32 \ ctfmon.exe (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ System32 \ ctfmon.exe (User 'SYSTEM') O4 - HKUS \ S-1-5-18 \ .. \ RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ System32 \ ctfmon.exe (User 'Default user') O4 - HKUS \. DEFAULT \ .. \ RunOnce: [RunNarrator] Narrator.exe (User 'Default user') O4 - Global Startup: GA311 Smart Wizard Utility.lnk = C: \ Program Files \ NETGEAR \ GA311 \ GA311.exe O4 - Global Startup: HP Instant support.lnk = C: \ Program Files \ Hewlett-Packard \ HP Instant Support DI \ bin \ matcli.exe O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk =? O4 - Global Startup: NkbMonitor.exe.lnk = C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor.exe O8 - Extra contesto voce di menu: ieSpell & Opzioni - res: / / C: \ Program Files \ ieSpell \ iespell.dll / SPELLOPTION.HTM O8 - Extra contesto voce di menu: & Windows Live Search - res: / / C: \ Program Files \ Windows Live Toolbar \ msntb.dll / search.htm O8 - Extra contesto voce di menu: Check & Spelling - res: / / C: \ Program Files \ ieSpell \ iespell.dll / SPELLCHECK.HTM O8 - Extra contesto voce di menu: Scarica tutto con Free Download Manager -- file: / / C: \ Programmi Files \ Free Download Manager \ dlall.htm O8 - Extra contesto voce di menu: Scarica selezionati con Free Download Manager -- file: / / C: \ Programmi Files \ Free Download Manager \ dlselected.htm O8 - Extra contesto voce di menu: Scarica con Free Download Manager -- file: / / C: \ Programmi Files \ Free Download Manager \ dllink.htm O8 - Extra contesto voce di menu: E & sporta in Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ micros ~ 2 \ Office10 \ EXCEL.EXE/3000 O8 - Extra contesto voce di menu: Ricerca sul Merriam Webster -- file: / / C: \ Programmi Files \ ieSpell \ Merriam Webster.HTM O8 - Extra contesto voce di menu: Cerca su Wikipedia -- file: / / C: \ Programmi Files \ ieSpell \ wikipedia.HTM O9 - Extra pulsante: Rileva video - (0028E570-E86D-4ceb-A108-76158C18DEF3) - C: \ Program Files \ videodetect \ videodetect.dll O9 - Extra 'Tools' menuitem: Rileva video - (0028E570-E86D-4ceb-A108-76158C18DEF3) - C: \ Program Files \ videodetect \ videodetect.dll O9 - Extra pulsante: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_05 \ bin \ ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_05 \ bin \ ssv.dll O9 - Extra pulsante: ieSpell - (0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8) - C: \ Program Files \ ieSpell \ iespell.dll O9 - Extra 'Tools' menuitem: ieSpell - (0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8) - C: \ Program Files \ ieSpell \ iespell.dll O9 - Extra pulsante: (no name) - (1606D6F9-9D3B-4aea-A025-ED5B2FD488E7) - C: \ Program Files \ ieSpell \ iespell.dll O9 - Extra 'Tools' menuitem: ieSpell Opzioni - (1606D6F9-9D3B-4aea-A025-ED5B2FD488E7) - C: \ Program Files \ ieSpell \ iespell.dll O9 - Extra pulsante: cioè picture downloader - (8F05069A-4BC5-4175-8B19-76A413464C90) - C: \ PROGRA ~ 1 \ IE_PIC ~ 1 \ \ iedownloader.exe O9 - Extra pulsante: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) - res: / / C: \ Program Files \ BitComet \ tools \ BitCometBHO_1.2.1.2.dll/206 (file mancanti) O9 - Extra pulsante: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ SpyBot ~ 1 \ SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ SpyBot ~ 1 \ SDHelper.dll O9 - Extra pulsante: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS.NEW \ Network Diagnostic \ xpnetdiag.exe O9 - Extra 'Tools' menuitem: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS.NEW \ Network Diagnostic \ xpnetdiag.exe O9 - Extra pulsante: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' menuitem: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe Ø10 - Unknown file in Winsock LSP: c: \ windows.new \ system32 \ nwprovau.dll Ø16 - DPF: (01010E00-5E80-11D8-9E86-0007E96C65AE) (SupportSoft SmartIssue) -- http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab Ø16 - DPF: (01012101-5E80-11D8-9E86-0007E96C65AE) (SupportSoft Script Runner Class) -- http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab Ø16 - DPF: (05D44720-58E3-49E6-BDF6-D00330E511D3) (StagingUI Object) -- http://zone.msn.com/binFrameWork/v10...I.cab46479.cab Ø16 - DPF: (0742B9EF-8C83-41CA-BFBA-830A59E23533) (Microsoft Data Collection Control) -- https: / / support.microsoft.com / OAS / ActiveX / MSDcode.cab Ø16 - DPF: (1F2F4C9E-6F09-47BC-970d-3C54734667FE) -- http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab Ø16 - DPF: (2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B) (DownloadManager Control) -- http://dlmanager.akamaitools.com.edg...ex-2.0.6.0.cab Ø16 - DPF: (2BC66F54-93A8-11D3-BEB6-00105AA9B6AE) (Symantec AntiVirus scanner) -- http://security.symantec.com/sscv6/S...in/AvSniff.cab Ø16 - DPF: (2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5) (Microsoft Data Collection Control) -- https: / / support.microsoft.com / OAS / ActiveX / odc.cab Ø16 - DPF: (3451DEDE-631F-421C-8127-FD793AFC6CC8) (ActiveDataInfo Class) -- http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab Ø16 - DPF: (34F12AFD-E9B5-492a-85D2-40FA4535BE83) (AxProdInfoCtl Class) -- http://www.symantec.com/techsupp/act...a/nprdtinf.cab Ø16 - DPF: (3BB54395-5982-4788-8AF4-B5388FFDD0D8) -- http://zone.msn.com/BinFrameWork/v10...y.cab32846.cab Ø16 - DPF: (44990200-3C9D-426D-81DF-AAB636FA4345) (Symantec SmartIssue) -- http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab Ø16 - DPF: (44990301-3C9D-426D-81DF-AAB636FA4345) (Symantec Script Runner Class) -- http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab Ø16 - DPF: (5736C456-EA94-4AAC-BB08-917ABDD035B3) -- http://zone.msn.com/binframework/v10...t.cab32846.cab Ø16 - DPF: (5ED80217-570B-4DA9-BF44-BE107C0EC166) (Windows Live Safety Center Base Module) -- http://cdn.scan.onecare.live.com/res...scbase8300.cab Ø16 - DPF: (644E432F-49D3-41A1-8DD5-E099162EEEC5) (Symantec RuFSI Utility Class) -- http://security.symantec.com/sscv6/S.../bin/cabsa.cab Ø16 - DPF: (67A5F8DC-1A4B-4D66-9F24-A704AD929EEE) (System Requirements Lab) -- http://www.nvidia.com/content/Driver...sysreqlab2.cab Ø16 - DPF: (6A344D34-5231-452A-8A57-D064AC9B7862) (Symantec Download Manager) -- https: / / webdl.symantec.com / ActiveX / symdlmgr.cab Ø16 - DPF: (6B75345B-AA36-438A-BBE6-4078B4C6984D) (HpProductDetection Class) -- http://h20270.www2.hp.com/ediags/gmn...tDetection.cab Ø16 - DPF: (6E32070A-766D-4EE6-879c-DC1FA91D2FC3) (MUWebControl Class) -- http://update.microsoft.com/microsof...?1125163370105 Ø16 - DPF: (AB86CE53-AC9F-449F-9399-D8ABCA09EC09) -- https: / / h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx Ø16 - DPF: (B3E22EA2-A579-11D2-847A-00C04F7605B6) -- file: / / E: \ 0000C5DD \ wpxfp01a \ comune \ e. .. codice \ odweb.cab Ø16 - DPF: (B8BE5E93-A60C-4D26-A2DC-220313175592) (ZoneIntro Class) -- http://cdn2.zone.msn.com/binFramewor...o.cab34246.cab Ø16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab Ø16 - DPF: (CE28D5D2-60CF-4C7D-9FE8-0F47A3308078) (ActiveDataInfo Class) -- http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab Ø16 - DPF: (D1E7CBDA-E60E-4970-A01C-37301EF7BF98) (Measurement Services Client v.3.11) -- http://advisor.futuremark.com/global/msc311.cab Ø16 - DPF: (DA2AA6CF-5C7A-4B71-BC3B-C771BB369937) (StadiumProxy Class) -- http://zone.msn.com/binframework/v10...y.cab41227.cab Ø16 - DPF: (E7D2588A-7FB5-47DC-8830-832605661009) (Live Collaboration) -- http://livenj01.rightnowtech.com/556.../java/RntX.cab Ø16 - DPF: (E8F628B5-259A-4734-97EE-BA914D7BE941) (Driver Agent ActiveX Control) -- http://plugin.driveragent.com/files/driveragent.cab Ø16 - DPF: (EB387D2F-E27B-4D36-979E-847D1036C65D) (QDiagHUpdateObj Class) -- http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326 Ø16 - DPF: (FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1) (DownloadManager Control) -- http://dlm.tools.akamai.com/dlmanage...ex-2.2.1.6.cab Ø18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ PROGRA ~ 1 \ COMUNE ~ 1 \ Skype \ SKYPE4 ~ 1.DLL O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C: \ Program Files \ Bonjour \ mDNSResponder.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Symantec Network Proxy (CCProxy) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccProxy.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ VAScanner \ comHost.exe O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Common Files \ InstallShield \ Driver \ 1150 \ Intel 32 \ IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C: \ Program Files \ Ahead \ InCD \ InCD \ InCDsrv.exe O23 - Service: iPod Service - Apple Inc. - C: \ Program Files \ iPod \ bin \ iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C: \ WINDOWS.NEW \ system32 \ nvsvc32.exe O23 - Service: PML Driver HPZ12 - HP - C: \ WINDOWS.NEW \ System32 \ HPZipm12.exe O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C: \ Program Files \ Dantz \ Retrospect \ retrorun.exe O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C: \ PROGRA ~ 1 \ Dantz \ RETROS ~ 1 \ wdsvc.exe O23 - Service: Symantec Core LC - Unknown proprietario - C: \ Program Files \ Common Files \ Symantec Shared \ la CCPD-LC \ symlcsvc.exe -- Fine del file - 17835 bytes |
|
#2
|
||||||||||||
|
||||||||||||
waw ora thats un mattone di testo
Il mio sistema: MEAN MACHINE!
|
|
#3
|
|||
|
|||
|
Non vedo alcun malware nel registro.
Sono HijackThis fissa queste voci.
Vorrei sapere come si ottiene, possiamo sempre eseguire scansioni a rendere più sicuro. |
|
#4
|
|||
|
|||
|
Non ho trovato nulla che aiutano ... grazie per il link però.
Ho allegato uno screenshot che mostra solo quello che voglio dire - questa è la speranza di utilizzo. |
|
#5
|
|||
|
|||
|
Sei loggato come amministratore?
|
|
#6
|
|||
|
|||
|
Yup .. che è stata la prima cosa che ho controllato, pensando che si era cambiato. E 'lo stesso su altri account amministratore come bene.
|
|
#7
|
|||
|
|||
|
Avete programmi di sicurezza installati in modo che esso può avere per disabili. xp-Antispy?
È possibile passare alla chiave del Registro di sistema e modificare il valore predefinito e riattivare manualmente. Vai a Start> Esegui, digitare regedit e fare clic su OK Trova la chiave: HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ au Nel riquadro di destra, cercare una chiave chiamata noautoupdate Cambia il valore di un 1 a 0 Riavviare e vedere se è cambiato. |
|
#8
|
|||
|
|||
|
Spiacenti, solo in questa corsa.
Vai a http://www.kellys-korner-xp.com/xp.htm vai alla sezione tweaks e ottenere il tweak chiamato "Windows Update grigio - Ripristino". |
|
#9
|
|||
|
|||
|
That's great, grazie evilfantasy un milione! Sembra che il minore infezione ho avuto è stato estraneo a questo.
Ancora una volta, cheers. |
|
#10
|
|||
|
|||
|
Nessun problema.
|