Dopo che hai selezionato, spingi enter. Per verificare prova ad incollare su notepad.pippobaudo ha scritto:@pippobaudo hai risolto? vai nel prompt di dos e scrivi ipconfig /all e incolla quel che dice, così capiamo un pó come sei messo
no non ancora
allora : scusa l'ignoranza ma se faccio ipconfig nel prompt come faccio a copiare se seleziono tutto poi non mi fa copiare
Problemi di PC? Risolve tutto il vs. Inchiostro Simpatico
Moderatori: Super Zeta, AlexSmith
Regole del forum
Non aprite topic per ogni sciocchezza, usate quelli già presenti!
Non aprite topic per ogni sciocchezza, usate quelli già presenti!
Gli ultimi 195 metri di una maratona sono la ragione che ti spinge a correre i precedenti 42.000.
Ma infatti stavo aspettando i tuoi consigli la mia era solo una proposta.phoenix ha scritto: @paul se fai come dici te, io che ti aiuto a fare? kaspersky è indecente, il sp3 ha finito di inguaiare il tuo pc... t'ho detto usa trojan remover, nient'altro! aspetta quel che ti dico, nn fare passi a casaccio. Avvia trojan remover, postami il log. Poi scarica un file di servizio di spool da internet e installalo... poi rifai log di hijackthis e postamelo ( se riesci da windows ad andare in modalità console è una gran cosa )
Allora ho scaricato il prog. da qui:
http://www.xnavigation.net/view/857/tro ... nload.html
la scansione ha dato esito positivo nel senso che non ci sono infezioni, ad ogni modo ti posto il log:
***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.7.6.2570. For information, email support@simplysup.com
[Unregistered version]
Scan started at: 10.02.59 24 mar 2009
Using Database v7306
Operating System: Windows XP Home Edition (SP2) [Build: 5.1.2600]
File System: NTFS
UserData directory: C:\Documents and Settings\Emanuele\Dati applicazioni\Simply Super Software\Trojan Remover\
Database directory: C:\Programmi\Trojan Remover\
Logfile directory: C:\Documents and Settings\Emanuele\Documenti\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Programmi\Trojan Remover\
Running with Administrator privileges
************************************************************
************************************************************
10.02.59: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
************************************************************
10.03.00: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
Key value: [Explorer.exe]
File: Explorer.exe
C:\WINDOWS\Explorer.exe
1034752 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
Key value: [C:\WINDOWS\system32\userinit.exe,]
File: C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
25088 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
This key's "UIHost" value calls the following program:
Key value: [logonui.exe]
File: logonui.exe
C:\WINDOWS\system32\logonui.exe
515584 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Value Name: load
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: CTStartup
Value Data: C:\Programmi\Creative\Splash Screen\CTEaxSpl.EXE /run
C:\Programmi\Creative\Splash Screen\CTEaxSpl.EXE
28672 bytes
Created: 16/11/2007 18.49
Modified: 14/09/2001 18.10
Company: Creative Technology Ltd.
--------------------
Value Name: TrojanScanner
Value Data: C:\Programmi\Trojan Remover\Trjscan.exe /boot
C:\Programmi\Trojan Remover\Trjscan.exe
1303432 bytes
Created: 24/03/2009 9.54
Modified: 20/03/2009 19.54
Company: Simply Super Software
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: ctfmon.exe
Value Data: C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
15360 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
This Registry Key appears to be empty
************************************************************
10.03.02: Scanning -----SHELLEXECUTEHOOKS-----
ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
File: shell32.dll - this file is expected and has been left in place
----------
************************************************************
10.03.02: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
************************************************************
10.03.02: Scanning -----ACTIVE SCREENSAVER-----
No active ScreenSaver found to scan.
************************************************************
10.03.02: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
Key: {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
Path: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
C:\Programmi\Outlook Express\setup50.exe
73728 bytes
Created: 10/09/2005 16.41
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
----------
Key: {7790769C-0471-11d2-AF11-00C04FA35D02}
Path: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
C:\Programmi\Outlook Express\setup50.exe
73728 bytes
Created: 10/09/2005 16.41
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
----------
************************************************************
10.03.03: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: AppMgmt
%SystemRoot%\System32\appmgmts.dll - file is globally excluded (file cannot be found)
--------------------
Key: HidServ
%SystemRoot%\System32\hidserv.dll - file is globally excluded (file cannot be found)
--------------------
************************************************************
10.03.05: Scanning ----- SERVICES REGISTRY KEYS -----
Key: Ad-Watch Connect Filter
ImagePath: \??\C:\WINDOWS\system32\drivers\NSDriver.sys
C:\WINDOWS\system32\drivers\NSDriver.sys - [file not found to scan]
----------
Key: Afc
ImagePath: system32\drivers\Afc.sys
C:\WINDOWS\system32\drivers\Afc.sys
11776 bytes
Created: 13/02/2007 1.14
Modified: 23/02/2005 14.58
Company: Arcsoft, Inc.
----------
Key: apanr
ImagePath: C:\WINDOWS\Downlo~1\huiis\ghvsgw.exe
C:\WINDOWS\Downlo~1\huiis\ghvsgw.exe - [file not found to scan]
----------
Key: atimtag
ImagePath: System32\DRIVERS\atimtag.sys
C:\WINDOWS\System32\DRIVERS\atimtag.sys - [file not found to scan]
----------
Key: Autodesk Licensing Service
ImagePath: "C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe"
C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
74360 bytes
Created: 30/01/2006 0.38
Modified: 30/01/2006 0.38
Company: Autodesk, Inc.
----------
Key: catchme
ImagePath: \??\C:\DOCUME~1\Emanuele\IMPOST~1\Temp\catchme.sys - this file is globally excluded
----------
Key: COMMONFX.DLL
ImagePath: system32\COMMONFX.DLL
C:\WINDOWS\system32\COMMONFX.DLL
110592 bytes
Created: 04/01/2009 21.32
Modified: 11/09/2001 5.20
Company: Creative Technology Ltd
----------
Key: CT20XUT.DLL
ImagePath: system32\CT20XUT.DLL
C:\WINDOWS\system32\CT20XUT.DLL
164608 bytes
Created: 12/04/2007 8.10
Modified: 12/04/2007 8.10
Company: Creative Technology Ltd.
----------
Key: ctac32k
ImagePath: System32\drivers\ctac32k.sys
C:\WINDOWS\System32\drivers\ctac32k.sys
110168 bytes
Created: 04/01/2009 21.32
Modified: 01/11/2001 8.31
Company: Creative Technology Ltd
----------
Key: ctaud2k
ImagePath: system32\drivers\ctaud2k.sys
C:\WINDOWS\system32\drivers\ctaud2k.sys
439296 bytes
Created: 10/04/2007 4.20
Modified: 08/12/2005 11.55
Company: Creative Technology Ltd
----------
Key: CTAUDFX.DLL
ImagePath: system32\CTAUDFX.DLL
C:\WINDOWS\system32\CTAUDFX.DLL
546048 bytes
Created: 12/04/2007 8.10
Modified: 12/04/2007 8.10
Company: Creative Technology Ltd
----------
Key: ctdvda2k
ImagePath: system32\drivers\ctdvda2k.sys
C:\WINDOWS\system32\drivers\ctdvda2k.sys
340704 bytes
Created: 04/01/2009 21.13
Modified: 10/11/2005 17.06
Company: [no info]
----------
Key: CTEAPSFX.DLL
ImagePath: system32\CTEAPSFX.DLL
C:\WINDOWS\system32\CTEAPSFX.DLL
196608 bytes
Created: 04/01/2009 21.32
Modified: 11/09/2001 5.21
Company: Creative Technology Ltd
----------
Key: CTEDSPFX.DLL
ImagePath: system32\CTEDSPFX.DLL
C:\WINDOWS\system32\CTEDSPFX.DLL
280320 bytes
Created: 12/04/2007 8.10
Modified: 12/04/2007 8.10
Company: Creative Technology Ltd
----------
Key: CTEDSPIO.DLL
ImagePath: system32\CTEDSPIO.DLL
C:\WINDOWS\system32\CTEDSPIO.DLL
128768 bytes
Created: 12/04/2007 8.10
Modified: 12/04/2007 8.10
Company: Creative Technology Ltd
----------
Key: CTEDSPSY.DLL
ImagePath: system32\CTEDSPSY.DLL
C:\WINDOWS\system32\CTEDSPSY.DLL
323328 bytes
Created: 12/04/2007 8.10
Modified: 12/04/2007 8.10
Company: Creative Technology Ltd
----------
Key: CTERFXFX.DLL
ImagePath: system32\CTERFXFX.DLL
C:\WINDOWS\system32\CTERFXFX.DLL
94976 bytes
Created: 12/04/2007 8.10
Modified: 12/04/2007 8.10
Company: Creative Technology Ltd
----------
Key: CTEXFIFX.DLL
ImagePath: system32\CTEXFIFX.DLL
C:\WINDOWS\system32\CTEXFIFX.DLL
1317632 bytes
Created: 12/04/2007 8.10
Modified: 12/04/2007 8.10
Company: Creative Technology Ltd.
----------
Key: CTHWIUT.DLL
ImagePath: system32\CTHWIUT.DLL
C:\WINDOWS\system32\CTHWIUT.DLL
66816 bytes
Created: 12/04/2007 8.10
Modified: 12/04/2007 8.10
Company: Creative Technology Ltd.
----------
Key: ctprxy2k
ImagePath: System32\drivers\ctprxy2k.sys
C:\WINDOWS\System32\drivers\ctprxy2k.sys
11036 bytes
Created: 04/01/2009 21.32
Modified: 11/09/2001 5.10
Company: Creative Technology Ltd
----------
Key: CTSBLFX.DLL
ImagePath: system32\CTSBLFX.DLL
C:\WINDOWS\system32\CTSBLFX.DLL
598016 bytes
Created: 04/01/2009 21.32
Modified: 11/09/2001 5.23
Company: Creative Technology Ltd
----------
Key: ctsfm2k
ImagePath: System32\drivers\ctsfm2k.sys
C:\WINDOWS\System32\drivers\ctsfm2k.sys
207572 bytes
Created: 04/01/2009 21.32
Modified: 18/10/2001 9.46
Company: Creative Technology Ltd
----------
Key: eamon
ImagePath: system32\DRIVERS\eamon.sys
C:\WINDOWS\system32\DRIVERS\eamon.sys
39944 bytes
Created: 08/10/2008 8.42
Modified: 08/10/2008 8.42
Company: ESET
----------
Key: easdrv
ImagePath: system32\DRIVERS\easdrv.sys
C:\WINDOWS\system32\DRIVERS\easdrv.sys
53256 bytes
Created: 08/10/2008 8.42
Modified: 08/10/2008 8.42
Company: ESET
----------
Key: EhttpSrv
ImagePath: "C:\Programmi\ESET\ESET NOD32 Antivirus\EHttpSrv.exe"
C:\Programmi\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
19200 bytes
Created: 08/10/2008 8.53
Modified: 08/10/2008 8.53
Company: ESET
----------
Key: ekrn
ImagePath: "C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe"
C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe
468224 bytes
Created: 08/10/2008 8.47
Modified: 08/10/2008 8.47
Company: ESET
----------
Key: emu10kx
ImagePath: system32\drivers\e10kx2k.sys
C:\WINDOWS\system32\drivers\e10kx2k.sys
1758336 bytes
Created: 04/01/2009 21.32
Modified: 05/11/2001 5.02
Company: Creative Technology Ltd
----------
Key: emupia
ImagePath: System32\drivers\emupia2k.sys
C:\WINDOWS\System32\drivers\emupia2k.sys
154284 bytes
Created: 04/01/2009 21.32
Modified: 11/09/2001 5.14
Company: Creative Technology Ltd
----------
Key: epfwtdir
ImagePath: system32\DRIVERS\epfwtdir.sys
C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
34312 bytes
Created: 08/10/2008 8.50
Modified: 08/10/2008 8.50
Company: [no info]
----------
Key: ha10kx2k
ImagePath: system32\drivers\ha10kx2k.sys
C:\WINDOWS\system32\drivers\ha10kx2k.sys
754176 bytes
Created: 10/04/2007 4.29
Modified: 08/12/2005 11.55
Company: Creative Technology Ltd
----------
Key: hap16v2k
ImagePath: system32\drivers\hap16v2k.sys
C:\WINDOWS\system32\drivers\hap16v2k.sys
154112 bytes
Created: 10/04/2007 4.31
Modified: 08/12/2005 11.55
Company: Creative Technology Ltd
----------
Key: hap17v2k
ImagePath: system32\drivers\hap17v2k.sys
C:\WINDOWS\system32\drivers\hap17v2k.sys
179712 bytes
Created: 10/04/2007 4.32
Modified: 08/12/2005 11.55
Company: Creative Technology Ltd
----------
Key: HPZid412
ImagePath: system32\DRIVERS\HPZid412.sys
C:\WINDOWS\system32\DRIVERS\HPZid412.sys
-R- 51056 bytes
Created: 20/09/2005 14.28
Modified: 05/01/2004 10.44
Company: HP
----------
Key: HPZipr12
ImagePath: system32\DRIVERS\HPZipr12.sys
C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
-R- 16496 bytes
Created: 20/09/2005 14.28
Modified: 05/01/2004 10.44
Company: HP
----------
Key: HPZius12
ImagePath: system32\DRIVERS\HPZius12.sys
C:\WINDOWS\system32\DRIVERS\HPZius12.sys
-R- 21488 bytes
Created: 20/09/2005 14.28
Modified: 05/01/2004 10.44
Company: HP
----------
Key: HSFHWBS2
ImagePath: System32\DRIVERS\HSFBS2S2.sys
C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys
220032 bytes
Created: 19/09/2005 16.05
Modified: 03/08/2004 21.41
Company: Conexant Systems, Inc.
----------
Key: HSF_DP
ImagePath: System32\DRIVERS\HSFDPSP2.sys
C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys
1041536 bytes
Created: 19/09/2005 16.05
Modified: 03/08/2004 21.41
Company: Conexant Systems, Inc.
----------
Key: InCDFs
ImagePath: system32\drivers\InCDFs.sys
C:\WINDOWS\system32\drivers\InCDFs.sys - [file not found to scan]
----------
Key: InCDPass
ImagePath: system32\drivers\InCDPass.sys
C:\WINDOWS\system32\drivers\InCDPass.sys - [file not found to scan]
----------
Key: InCDRm
ImagePath: system32\drivers\InCDRm.sys
C:\WINDOWS\system32\drivers\InCDRm.sys - [file not found to scan]
----------
Key: klif
ImagePath: system32\drivers\klif.sys
C:\WINDOWS\system32\drivers\klif.sys
134160 bytes
Created: 17/05/2008 15.18
Modified: 05/07/2007 13.34
Company: Kaspersky Lab
----------
Key: mbr
ImagePath: \??\C:\DOCUME~1\Emanuele\IMPOST~1\Temp\mbr.sys - this file is globally excluded
----------
Key: MDM
ImagePath: "C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE"
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
322120 bytes
Created: 19/06/2003 22.25
Modified: 19/06/2003 22.25
Company: Microsoft Corporation
----------
Key: ms_mpu401
ImagePath: system32\drivers\msmpu401.sys
C:\WINDOWS\system32\drivers\msmpu401.sys
2944 bytes
Created: 19/09/2005 14.39
Modified: 17/08/2001 21.00
Company: Microsoft Corporation
----------
Key: ose
ImagePath: "C:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE"
C:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE
89136 bytes
Created: 28/07/2003 19.28
Modified: 28/07/2003 19.28
Company: Microsoft Corporation
----------
Key: ossrv
ImagePath: system32\drivers\ctoss2k.sys
C:\WINDOWS\system32\drivers\ctoss2k.sys
186944 bytes
Created: 04/01/2009 21.32
Modified: 11/09/2001 5.10
Company: Creative Technology Ltd.
----------
Key: ousb2hub
ImagePath: system32\DRIVERS\ousb2hub.sys
C:\WINDOWS\system32\DRIVERS\ousb2hub.sys
56960 bytes
Created: 13/02/2007 1.13
Modified: 01/03/2006 8.40
Company: OrangeWare Corporation
----------
Key: ousbehci
ImagePath: System32\Drivers\ousbehci.sys
C:\WINDOWS\System32\Drivers\ousbehci.sys
46080 bytes
Created: 13/02/2007 1.13
Modified: 01/03/2006 8.40
Company: OrangeWare Corporation
----------
Key: PfModNT
ImagePath: \??\C:\WINDOWS\system32\PfModNT.sys
C:\WINDOWS\system32\PfModNT.sys
6752 bytes
Created: 04/01/2009 21.31
Modified: 17/12/1999 1.00
Company: Creative Technology Ltd.
----------
Key: Pml Driver HPZ12
ImagePath: C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\HPZipm12.exe
65795 bytes
Created: 05/01/2004 10.44
Modified: 05/01/2004 10.44
Company: HP
----------
Key: Secdrv
ImagePath: System32\DRIVERS\secdrv.sys
C:\WINDOWS\System32\DRIVERS\secdrv.sys
27440 bytes
Created: 31/08/2001 13.00
Modified: 31/08/2001 13.00
Company: [no info]
----------
Key: setup_7.0.0.180_17.05.2008_14-34
ImagePath: "C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_17.05.2008_14-34.exe" -r
C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_17.05.2008_14-34.exe - [file not found to scan]
----------
Key: SNP2STD
ImagePath: system32\DRIVERS\snp2sxp.sys
C:\WINDOWS\system32\DRIVERS\snp2sxp.sys
10192896 bytes
Created: 13/02/2007 1.12
Modified: 18/11/2005 18.29
Company:
----------
Key: sptd
ImagePath: System32\Drivers\sptd.sys - this file is globally excluded
----------
Key: StarWindService
ImagePath: C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
217600 bytes
Created: 02/04/2005 2.51
Modified: 02/04/2005 2.51
Company: Rocket Division Software
----------
Key: SwPrv
ImagePath: C:\WINDOWS\System32\dllhost.exe /Processid:{52CEE186-157C-45CF-B345-DB5A083F6DA6}
C:\WINDOWS\System32\dllhost.exe
5120 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
----------
Key: U81xbus
ImagePath: system32\DRIVERS\U81xbus.sys
C:\WINDOWS\system32\DRIVERS\U81xbus.sys
-R- 52352 bytes
Created: 09/03/2006 19.16
Modified: 22/03/2005 3.20
Company: MCCI
----------
Key: U81xmdfl
ImagePath: system32\DRIVERS\U81xmdfl.sys
C:\WINDOWS\system32\DRIVERS\U81xmdfl.sys
-R- 6064 bytes
Created: 09/03/2006 19.17
Modified: 22/03/2005 3.20
Company: MCCI
----------
Key: U81xmdm
ImagePath: system32\DRIVERS\U81xmdm.sys
C:\WINDOWS\system32\DRIVERS\U81xmdm.sys
-R- 84480 bytes
Created: 09/03/2006 19.17
Modified: 22/03/2005 3.20
Company: MCCI
----------
Key: U81xmgmt
ImagePath: system32\DRIVERS\U81xmgmt.sys
C:\WINDOWS\system32\DRIVERS\U81xmgmt.sys
-R- 77472 bytes
Created: 09/03/2006 19.18
Modified: 22/03/2005 3.20
Company: MCCI
----------
Key: U81xobex
ImagePath: system32\DRIVERS\U81xobex.sys
C:\WINDOWS\system32\DRIVERS\U81xobex.sys
-R- 75456 bytes
Created: 09/03/2006 19.20
Modified: 22/03/2005 3.20
Company: MCCI
----------
Key: UPSmart
ImagePath: C:\Programmi\Commander Pro\UPServ.exe UPSmart
C:\Programmi\Commander Pro\UPServ.exe
61440 bytes
Created: 04/02/2008 11.41
Modified: 01/11/1999 15.02
Company:
----------
Key: USBAAPL
ImagePath: System32\Drivers\usbaapl.sys
C:\WINDOWS\System32\Drivers\usbaapl.sys - [file not found to scan]
----------
Key: usnjsvc
ImagePath: "C:\Programmi\MSN Messenger\usnsvc.exe"
C:\Programmi\MSN Messenger\usnsvc.exe
97136 bytes
Created: 19/01/2007 11.54
Modified: 19/01/2007 11.54
Company: Microsoft Corporation
----------
Key: viaagp1
ImagePath: System32\DRIVERS\viaagp1.sys
C:\WINDOWS\System32\DRIVERS\viaagp1.sys
27904 bytes
Created: 02/07/2003 3.42
Modified: 02/07/2003 3.42
Company: VIA Technologies, Inc.
----------
Key: ViaIde
ImagePath: System32\DRIVERS\viaidexp.sys
C:\WINDOWS\System32\DRIVERS\viaidexp.sys
6144 bytes
Created: 18/10/2001 11.00
Modified: 18/10/2001 11.00
Company: VIA Technologies, Inc.
----------
Key: wanusb
ImagePath: System32\DRIVERS\gwausb.sys
C:\WINDOWS\System32\DRIVERS\gwausb.sys
252338 bytes
Created: 10/09/2005 16.52
Modified: 28/02/2002 9.35
Company: GlobeSpan Inc.
----------
Key: Wdm1
ImagePath: System32\Drivers\usbbc.sys
C:\WINDOWS\System32\Drivers\usbbc.sys
-R- 15576 bytes
Created: 26/09/2005 14.09
Modified: 18/11/2002 7.00
Company:
----------
Key: winachsf
ImagePath: System32\DRIVERS\HSFCXTS2.sys
C:\WINDOWS\System32\DRIVERS\HSFCXTS2.sys
685056 bytes
Created: 19/09/2005 16.05
Modified: 03/08/2004 21.41
Company: Conexant Systems, Inc.
----------
Key: WMPNetworkSvc
ImagePath: "C:\Programmi\Windows Media Player\WMPNetwk.exe"
C:\Programmi\Windows Media Player\WMPNetwk.exe
918528 bytes
Created: 02/11/2006 22.56
Modified: 02/11/2006 22.56
Company: Microsoft Corporation
----------
************************************************************
10.03.32: Scanning -----VXD ENTRIES-----
Checking the following VxD entries:
************************************************************
10.03.32: Scanning ----- WINLOGON\NOTIFY DLLS -----
************************************************************
10.03.32: Scanning ----- CONTEXTMENUHANDLERS -----
Key: Eset Smart Security - Context Menu Shell Extension
CLSID: {B089FE88-FB52-11D3-BDF1-0050DA34150D}
Path: C:\Programmi\ESET\ESET NOD32 Antivirus\shellExt.dll
C:\Programmi\ESET\ESET NOD32 Antivirus\shellExt.dll
169216 bytes
Created: 08/10/2008 8.57
Modified: 08/10/2008 8.57
Company: ESET
----------
Key: ICQLiteMenu
CLSID: {73B24247-042E-4EF5-ADC2-42F62E6FD654}
Path: C:\Programmi\ICQLite\ICQLiteShell.dll
C:\Programmi\ICQLite\ICQLiteShell.dll
57443 bytes
Created: 02/04/2006 18.17
Modified: 10/04/2005 13.55
Company:
----------
Key: WinRAR
CLSID: {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Path: C:\Programmi\WinRAR\rarext.dll
C:\Programmi\WinRAR\rarext.dll
125952 bytes
Created: 22/09/2005 0.12
Modified: 03/08/2005 21.32
Company: [no info]
----------
Key: Yahoo! Mail
CLSID: {5464D816-CF16-4784-B9F3-75C0DB52B499}
Path: C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
190496 bytes
Created: 11/12/2006 12.28
Modified: 30/10/2006 14.50
Company: Yahoo! Inc.
----------
Key: {EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}
Path: C:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll
C:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll
114688 bytes
Created: 05/09/2005 9.37
Modified: 05/09/2005 9.37
Company: Nero AG
----------
************************************************************
10.03.34: Scanning ----- FOLDER\COLUMNHANDLERS -----
Key: {7D4D6379-F301-4311-BEBA-E26EB0561882}
File: C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll
C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll
1802240 bytes
Created: 03/09/2005 12.58
Modified: 03/09/2005 12.58
Company: Nero AG
----------
Key: {F9DB5320-233E-11D1-9F84-707F02C10627}
File: C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.dll
C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.dll
372736 bytes
Created: 10/05/2007 22.54
Modified: 10/05/2007 22.54
Company: Adobe Systems, Inc.
----------
************************************************************
10.03.35: Scanning ----- BROWSER HELPER OBJECTS -----
Key: {02478D38-C3F9-4EFB-9B51-7695ECA05670}
BHO: C:\Programmi\Yahoo!\Companion\Installs\cpn0\yt.dll
C:\Programmi\Yahoo!\Companion\Installs\cpn0\yt.dll
440384 bytes
Created: 11/12/2006 12.27
Modified: 26/10/2006 10.28
Company: Yahoo! Inc.
----------
Key: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
BHO: C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
62080 bytes
Created: 22/10/2006 23.08
Modified: 22/10/2006 23.08
Company: Adobe Systems Incorporated
----------
Key: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
BHO: C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
440056 bytes
Created: 15/12/2006 3.09
Modified: 15/12/2006 3.23
Company: Sun Microsystems, Inc.
----------
Key: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
BHO: C:\Programmi\Windows Live Toolbar\msntb.dll
C:\Programmi\Windows Live Toolbar\msntb.dll
546320 bytes
Created: 19/10/2007 11.20
Modified: 19/10/2007 11.20
Company: Microsoft Corporation
----------
************************************************************
10.03.38: Scanning ----- SHELLSERVICEOBJECTS -----
************************************************************
10.03.38: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----
************************************************************
10.03.38: Scanning ----- IMAGEFILE DEBUGGERS -----
No "Debugger" entries found.
************************************************************
10.03.38: Scanning ----- APPINIT_DLLS -----
The AppInit_DLLs value is blank or does not exist
************************************************************
10.03.40: Scanning ----- SECURITY PROVIDER DLLS -----
************************************************************
10.03.40: Scanning ------ COMMON STARTUP GROUP ------
[C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica]
The Common Startup Group attempts to load the following file(s) at boot time:
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini
-HS- 84 bytes
Created: 10/09/2005 17.34
Modified: 10/09/2005 16.43
Company: [no info]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini - no action taken on this file
--------------------
SpeedWeb ADSL USB Modem.lnk - links to [file not found to scan]
SpeedWeb ADSL USB Modem.lnk - links to a nonexistent file
--------------------
************************************************************
No User Startup Groups were located to check
************************************************************
10.04.01: Scanning ----- SCHEDULED TASKS -----
Taskname: Verifica aggiornamenti per Windows Live Toolbar.job
File: C:\Programmi\Windows Live Toolbar\MSNTBUP.EXE
C:\Programmi\Windows Live Toolbar\MSNTBUP.EXE
99856 bytes
Created: 19/10/2007 11.20
Modified: 19/10/2007 11.20
Company: Microsoft Corporation
Parameters: [blank]
Next Run Time: 24/03/2009 10.50.00
Status: L'operazione verrà eseguita al prossimo orario pianificato
Creator: Emanuele
Comments: [blank]
----------
************************************************************
10.04.01: Scanning ----- SHELLICONOVERLAYIDENTIFIERS -----
Key: AutoCAD Digital Signatures Icon Overlay Handler
CLSID: {36A21736-36C2-4C11-8ACB-D4136F2B57BD}
File: C:\WINDOWS\system32\AcSignIcon.dll
C:\WINDOWS\system32\AcSignIcon.dll
136312 bytes
Created: 25/02/2004 1.35
Modified: 25/02/2004 1.35
Company: Autodesk
----------
************************************************************
10.04.02: Scanning ----- DEVICE DRIVER ENTRIES -----
Value: vidc.LEAD
File: LCODCCMP.DLL
C:\WINDOWS\system32\LCODCCMP.DLL
364544 bytes
Created: 24/04/2002 11.42
Modified: 24/04/2002 11.42
Company: LEAD Technologies, Inc.
----------
Value: msacm.siren
File: sirenacm.dll
C:\WINDOWS\system32\sirenacm.dll
51056 bytes
Created: 19/01/2007 11.53
Modified: 19/01/2007 11.53
Company: Microsoft Corp.
----------
Value: VIDC.wmv3
File: wmv9vcm.dll
C:\WINDOWS\system32\wmv9vcm.dll
1415680 bytes
Created: 27/12/2005 11.40
Modified: 23/06/2003 2.44
Company: Microsoft Corporation
----------
Value: VIDC.DIVX
File: divx.dll
C:\WINDOWS\system32\divx.dll
682496 bytes
Created: 17/01/2008 23.46
Modified: 04/12/2007 2.33
Company: DivX, Inc.
----------
Value: VIDC.YV12
File: yv12vfw.dll
C:\WINDOWS\system32\yv12vfw.dll
217088 bytes
Created: 17/01/2008 23.46
Modified: 25/01/2004 17.18
Company: www.helixcommunity.org
----------
Value: msacm.ac3acm
File: ac3acm.acm
C:\WINDOWS\system32\ac3acm.acm
118784 bytes
Created: 17/01/2008 23.46
Modified: 21/09/2007 1.52
Company: fccHandler
----------
Value: msacm.lameacm
File: lameACM.acm
C:\WINDOWS\system32\lameACM.acm
389120 bytes
Created: 17/01/2008 23.46
Modified: 24/09/2006 16.11
Company: http://www.mp3dev.org/
----------
Value: VIDC.FFDS
File: ff_vfw.dll
C:\WINDOWS\system32\ff_vfw.dll
7680 bytes
Created: 17/01/2008 23.46
Modified: 24/12/2007 13.49
Company: [no info]
----------
Value: msacm.ctmp3
File: C:\WINDOWS\system32\ctmp3.acm
C:\WINDOWS\system32\ctmp3.acm
364544 bytes
Created: 13/01/2009 17.48
Modified: 13/06/2001 9.33
Company: Creative Technology Ltd.
----------
************************************************************
10.04.09: ----- ADDITIONAL CHECKS -----
PE386 rootkit checks completed
----------
Winlogon registry rootkit checks completed
----------
Heuristic checks for hidden files/drivers completed
----------
Layered Service Provider entries checks completed
----------
Windows Explorer Policies checks completed
----------
Desktop Wallpaper: C:\Documents and Settings\Emanuele\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
C:\Documents and Settings\Emanuele\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
9437238 bytes
Created: 24/10/2005 1.40
Modified: 04/03/2009 12.18
Company: [no info]
----------
Web Desktop Wallpaper: %USERPROFILE%\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
C:\Documents and Settings\Emanuele\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
9437238 bytes
Created: 24/10/2005 1.40
Modified: 04/03/2009 12.18
Company: [no info]
----------
DNS Server information:
Interface:
NameServers: 85.37.17.5 85.38.28.77
Checks for rogue DNS NameServers completed
----------
----------
Additional checks completed
************************************************************
10.04.12: Scanning ----- RUNNING PROCESSES -----
C:\WINDOWS\System32\smss.exe
50688 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\csrss.exe
6144 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\winlogon.exe
504832 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\services.exe
108544 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\lsass.exe
13312 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\svchost.exe
14336 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\System32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\System32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\System32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\system32\spoolsv.exe
57856 bytes
Created: 30/10/2008 14.20
Modified: 13/04/2008 18.14
Company: Microsoft Corporation
--------------------
C:\WINDOWS\Explorer.EXE - file already scanned
--------------------
C:\WINDOWS\system32\CTsvcCDA.EXE
44032 bytes
Created: 13/01/2009 17.49
Modified: 13/12/1999 1.01
Company: Creative Technology Ltd
--------------------
C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe - file already scanned
--------------------
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE - file already scanned
--------------------
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe - file already scanned
--------------------
C:\Programmi\Trojan Remover\Trjscan.exe - file already scanned
--------------------
C:\WINDOWS\System32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\system32\ctfmon.exe - file already scanned
--------------------
C:\WINDOWS\System32\alg.exe
44544 bytes
Created: 31/08/2001 13.00
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\wscntfy.exe
13824 bytes
Created: 19/09/2005 16.05
Modified: 19/08/2004 14.39
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\wuauclt.exe
53080 bytes
Created: 10/09/2005 16.39
Modified: 30/07/2007 18.19
Company: Microsoft Corporation
--------------------
C:\Documents and Settings\Emanuele\Dati applicazioni\Simply Super Software\Trojan Remover\xmr6.exe
FileSize: 2933624
[This is a Trojan Remover component]
--------------------
************************************************************
10.04.19: Checking HOSTS file
No malicious entries were found in the HOSTS file
************************************************************
=== NO CHANGES HAVE BEEN MADE TO YOUR SYSTEM FILES ===
Scan completed at: 10.04.20 24 mar 2009
Total Scan time: 00.01.20
************************************************************
Ultima modifica di paolu79 il 24/03/2009, 10:07, modificato 1 volta in totale.
Ciao Maestro!
Il mio notebook inizia a pompare fin troppa aria... ok, è vecchio di 3 anni, puó essere la polvere puó essere qualcos'altro... peró volevo sapere se magari intanto puó essere un sovraccarico della CPU per colpa di qualche programma invadente. Ti posto il log di Hijackthis, magari con un'occhiata riesci a capire se c'è qualcosa di troppo
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10.01.02, on 24/03/09
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\Cisco Systems\VPN Client\cvpnd.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\Apoint2K\Apoint.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Apoint2K\Apntex.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programmi\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmi\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 1412828078
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/s ... DEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/i ... ection.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/ ... dl.sun.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmi\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmi\HPQ\shared\hpqwmi.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 7043 bytes
Il mio notebook inizia a pompare fin troppa aria... ok, è vecchio di 3 anni, puó essere la polvere puó essere qualcos'altro... peró volevo sapere se magari intanto puó essere un sovraccarico della CPU per colpa di qualche programma invadente. Ti posto il log di Hijackthis, magari con un'occhiata riesci a capire se c'è qualcosa di troppo
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10.01.02, on 24/03/09
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\Cisco Systems\VPN Client\cvpnd.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\Apoint2K\Apoint.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Apoint2K\Apntex.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programmi\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmi\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 1412828078
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/s ... DEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/i ... ection.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/ ... dl.sun.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmi\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmi\HPQ\shared\hpqwmi.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 7043 bytes
C'è, nelle cose umane, una marea che colta nel flusso conduce alla fortuna ma perduta, l'intero viaggio della nostra vita si arena su fondali di miseria. Ora noi navighiamo in un mare aperto dobbiamo dunque prendere la corrente finchè è a favore
oppure fallire l'impresa avanti a noi
oppure fallire l'impresa avanti a noi
scusa per "un file di servizio di spool" intendi il file "Spooler SubSystem App" di 56.5 kb? ovvero quello che compare nei processi in task manager quando lancio una stampa? grazie mille.phoenix ha scritto: @paul se fai come dici te, io che ti aiuto a fare? kaspersky è indecente, il sp3 ha finito di inguaiare il tuo pc... t'ho detto usa trojan remover, nient'altro! aspetta quel che ti dico, nn fare passi a casaccio. Avvia trojan remover, postami il log. Poi scarica un file di servizio di spool da internet e installalo... poi rifai log di hijackthis e postamelo ( se riesci da windows ad andare in modalità console è una gran cosa )

alice 20mb con modem w-gate 2+phoenix ha scritto:@xisco che rete hai?
Ezechiele 25,17. "Il cammino dell'uomo timorato è minacciato da ogni parte dall'iniquità degli esseri egoisti e dalla tirannia degli uomini malvagi. Benedetto sia colui che nel nome della carità e della buona volontà conduce i deboli attraverso la valle delle tenebre perchè egli è in verità il pastore di suo fratello e il ricercatore dei figli smarriti e la mia giustizia calerà sopra di loro con grandissima vendetta e furiosissimo sdegno su coloro che si proveranno ad ammorbare e distruggere i miei fratelli e tu saprai che il mio nome è quello del Signore quando farà calare la mia vendetta sopra di te."
faccio calcoli geotecnici e strutturali.. tipo che per vedere un risultato completo ci impiego un mese e mezzo con l'amd4200 (computer che gira h24). Quindi un po' di potenza in piu' non guasterebbe (e quello dovrebbe andare 2.5volte il mio)...poi con 4core posso lanciare 2 analisi (i progs finalmente sfruttano almeno 2 core)phoenix ha scritto:
@mrz dipende da che uso fai del pc... pkè ti serve potenza di calcolo? fai video? programmi? per le usb 3.0 serve almeno un annetto, e saranno MOOOLTO potenti
l'alimentatore da 600 potrebbe andare, la ram anche... il punto è che spendere tanto per un desktop ora a mio avviso è altamente sconsigliabile per il fatto che tra 2 anni
circa ci sarà una grossa rivoluzione, a partire da windows 7 che inizierà a girare, a partire dai nuovi supporti touch a doppia mandata che rivoluzioneranno in toto l'hardware video ( e conseguente sistema operativo, ció renderà windows se7en necessario ) ecc
"Meglio una bionda oggi che una gallina domani".
da A Beautiful mind
da A Beautiful mind
- cimmeno
- Storico dell'impulso
- Messaggi: 5233
- Iscritto il: 19/07/2004, 2:21
- Località: milano
- Contatta:
due consigli spassionatimrz29to ha scritto: faccio calcoli geotecnici e strutturali.. tipo che per vedere un risultato completo ci impiego un mese e mezzo con l'amd4200 (computer che gira h24). Quindi un po' di potenza in piu' non guasterebbe (e quello dovrebbe andare 2.5volte il mio)...poi con 4core posso lanciare 2 analisi (i progs finalmente sfruttano almeno 2 core)
a) se il software per questi calcoli è disponibile solo per windows, rimani assolutamente a windows xp. troiate come vista etc sottraggono potenza di calcolo
se invece simili calcoli possono essere fatti sotto tutti i sistemi operativi, usa altri sistemi operativi più solidi e meno ingordi. freebsd, solaris, linux vedi tu
b) se hai diverse macchine a disposizione e tutta questa necessità di megaflops, prova a iniziare un discorso legato al grid computing.
in qusto modo sul momento puoi evitare di spendere pe run quad core che comunque costa, e man mano aumentare la potenza di calcolo complessiva.
Ultima modifica di cimmeno il 24/03/2009, 20:34, modificato 1 volta in totale.
donne italiane!
se sentite il bisogno di azioni concrete...
FATE POMPINI!!!!
se sentite il bisogno di azioni concrete...
FATE POMPINI!!!!
- cimmeno
- Storico dell'impulso
- Messaggi: 5233
- Iscritto il: 19/07/2004, 2:21
- Località: milano
- Contatta:
ragiona su un particolaremrz29to ha scritto:grazie, infatti sono un fanboy di xp,
ed ogni sera dico una preghierina per chi ha inventato il visual basic.
a) visual basic lo paghi, python e perl no
b) spendendo ore/uomo su visual basic avrai un prodotto che girerà solo su windows, facendo lo stesso con python e perl potrai usare quel codice ovunque.
donne italiane!
se sentite il bisogno di azioni concrete...
FATE POMPINI!!!!
se sentite il bisogno di azioni concrete...
FATE POMPINI!!!!
premetto che concordo con i due primi consigli di cimmeno... ma nel secondo reply lo vedo troppo di parte
cimme, nn capisco pkè alcuni *nixari si fissano sulla divinità del loro mondo... perchè non ammettere che ci sono lati positivi e lati negativi? Io uso entrambi e ognuno dei due ha i suoi nei... perl è ottimo, potrai usarlo ovunque, ma vogliamo mettere con la semplicità e con la sintassi del basic? un niubbo che nn ha mai programmato se vede il perl o il python si darà probabilmente all'ippica, invece col visual basic puó avere un approccio morbidissimo... cavolo se win e derivati son tanto usati un motivo ci sarà ...
p.s. dopo che mi hai spiegato l'utilizzo, ti consiglio ancor di più di aspettare a comprare il desktop, il cloud computing tra brevissimo farà la sua scalata al successo e i vari sistemi ne risentiranno
cimme, nn capisco pkè alcuni *nixari si fissano sulla divinità del loro mondo... perchè non ammettere che ci sono lati positivi e lati negativi? Io uso entrambi e ognuno dei due ha i suoi nei... perl è ottimo, potrai usarlo ovunque, ma vogliamo mettere con la semplicità e con la sintassi del basic? un niubbo che nn ha mai programmato se vede il perl o il python si darà probabilmente all'ippica, invece col visual basic puó avere un approccio morbidissimo... cavolo se win e derivati son tanto usati un motivo ci sarà ...
p.s. dopo che mi hai spiegato l'utilizzo, ti consiglio ancor di più di aspettare a comprare il desktop, il cloud computing tra brevissimo farà la sua scalata al successo e i vari sistemi ne risentiranno
- El Diablo
- Storico dell'impulso
- Messaggi: 26696
- Iscritto il: 26/10/2007, 1:16
- Località: Abruzzo,Texas,Inferno
- Contatta:
w-gate 2+,buttalo,ne guadagnerai in salute e in fede,perchè sarai meno blasfemoXisco ha scritto:alice 20mb con modem w-gate 2+phoenix ha scritto:@xisco che rete hai?

Se mi dici che ti funziona alla perfezione,sei uno dei pochi fortunati

"Più le cose cambiano, più restano le stesse"
"I lesbo sono migliori se leggermente asimmetrici" Gargarozzo
"I lesbo sono migliori se leggermente asimmetrici" Gargarozzo