Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

controllo log di hijack grazie mille Opzioni
faccino
Inviato: Friday, February 26, 2010 11:38:47 AM
Rank: AiutAmico

Iscritto dal : 2/3/2005
Posts: 38
mi controllereste il log di hijackthis
grazie mille siete grandi come sempre

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11.31.46, on 26/02/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\PROGRA~1\NETSUP~1\client32.exe
C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Programmi\CA\eTrust Antivirus\InoRpc.exe
C:\Programmi\CA\eTrust Antivirus\InoRT.exe
C:\Programmi\CA\eTrust Antivirus\InoTask.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Programmi\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\UltraVNC\WinVNC.exe
C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
C:\Documents and Settings\Administrator\Documenti\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O2 - BHO: IEHlprObj Class - {F171A450-7AF5-43E1-AFED-EDC826A1B0F5} - C:\WINDOWS\system32\bgdferw0.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [WinVNC] "C:\Programmi\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Programmi\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Programmi\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [hjdsdse] C:\WINDOWS\system32\oukdfgr.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: TL-WN321G Wireless Utility.lnk = C:\Programmi\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PokerStars.it - {C4046502-6524-4d87-896C-878F57D1FF07} - C:\Programmi\PokerStars.IT\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoTask.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Programmi\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: VNC Server (winvnc) - UltraVNC - C:\Programmi\UltraVNC\WinVNC.exe

--
End of file - 7909 bytes
Sponsor
Inviato: Friday, February 26, 2010 11:38:47 AM

 
paolopa
Inviato: Friday, February 26, 2010 11:54:41 AM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
c è una riga che stando ad internet viene rilevata come possibile malware.
fai una scansione con mbam:lo scarichi,lo AGGIORNI e fai una scansione COMPLETA.che problemi riscontri?
http://software.aiutamici.com/software?ID=80346
sara' anche meglio disinstallare spybot ed reinstallarlo senza teatimer,ma a questo penseremo dopo.
devi anche aggiornare all sp3,è importante per la sicurezza.
shapiro
Inviato: Friday, February 26, 2010 11:55:31 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ciao

nel log ci sono delle voci che non sono niente di buono

Avvia Hijack e clicca su "do a system scan only"
Metti la spunta a queste voci e clicca su "fix checked"


Code:
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: IEHlprObj Class - {F171A450-7AF5-43E1-AFED-EDC826A1B0F5} - C:\WINDOWS\system32\bgdferw0.dll

O4 - HKCU\..\Run: [hjdsdse] C:\WINDOWS\system32\oukdfgr.exe


scarica malwarebytes

1) lo installi
2) lo aggiorni
3) fai una scansione scegliendo la modalità completa
4) NON eliminare per ora le ventuali minacce che rileva
5) finita la scansione seleziona il tabellino log, apri il file di testo e postalo sul forum

@paolopa

non avevo visto il tuo post, scusami

@faccino

esegui la procedura di paolopa dopo aver eliminato le voci da hijackthis
paolopa
Inviato: Friday, February 26, 2010 12:02:16 PM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
@shapiro:ma di cosa ti scusi?stai scherzando?anzi,sono contento che lo assisti tu,io ho solo da imparare da voi!!!
ps:intervieni sempre tranquillamente e serenamente nei miei post,mi da tranquillita' sapere che qualcuno controlla!!! :-)
faccino
Inviato: Friday, February 26, 2010 1:58:44 PM
Rank: AiutAmico

Iscritto dal : 2/3/2005
Posts: 38
allora ho fatto quello che mi avete detto.
ho fatto il log di malware ed ho eliminato quello che mi ha segnalato, ma per caso vi devo inviare il log?
shapiro
Inviato: Friday, February 26, 2010 1:59:47 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
si faccino se posti il log e' meglio
faccino
Inviato: Friday, February 26, 2010 3:24:36 PM
Rank: AiutAmico

Iscritto dal : 2/3/2005
Posts: 38
Malwarebytes' Anti-Malware 1.44
Versione del database: 3510
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

26/02/2010 13.39.43
mbam-log-2010-02-26 (13-39-32).txt

Tipo di scansione: Scansione completa (A:\|C:\|D:\|E:\|G:\|)
Elementi scansionati: 160541
Tempo trascorso: 44 minute(s), 50 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 4
Valori di registro infetti: 0
Elementi dato del registro infetti: 1
Cartelle infette: 0
File infetti: 47

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_CLASSES_ROOT\iehlprobj.iehlprobj.1 (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{f171a44f-7af5-43e1-afed-edc826a1b0f5} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{f171a442-7af5-43e1-afed-edc826a1b0f5} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f171a450-7af5-43e1-afed-edc826a1b0f5} (Trojan.Vundo) -> No action taken.

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> No action taken.

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
C:\autorun.inf (Spyware.OnlineGames) -> No action taken.
C:\lhylec9x.cmd (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Administrator\ntuser.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Administrator\Documenti\hijackthis\backups\backup-20100226-121834-474.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP77\A0005878.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP77\A0005879.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP77\A0005880.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP77\A0007877.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP77\A0007878.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP78\A0007896.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP78\A0007906.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP78\A0007907.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP79\A0007909.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP79\A0013907.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP79\A0013908.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP79\A0013909.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP79\A0014906.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP79\A0014907.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP79\A0014908.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0014914.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0015906.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0015907.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0015908.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0015917.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0015918.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0015919.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0017918.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0017919.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP80\A0017920.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0017923.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0018917.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0018918.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0018919.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0019917.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0019918.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0019919.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0020917.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0020918.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0020919.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0022917.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0022918.dll (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP81\A0022919.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP82\A0022922.cmd (Spyware.OnlineGames) -> No action taken.
C:\System Volume Information\_restore{844D415E-0EFB-4498-9A7D-E94B16374614}\RP82\A0022924.dll (Spyware.OnlineGames) -> No action taken.
C:\WINDOWS\SYSTEM32\hyrteas0.dll (Spyware.OnlineGames) -> No action taken.
C:\WINDOWS\SYSTEM32\hyrteas1.dll (Spyware.OnlineGames) -> No action taken.
C:\WINDOWS\SYSTEM32\oukdfgr.exe (Spyware.OnlineGames) -> No action taken.
paolopa
Inviato: Friday, February 26, 2010 3:33:25 PM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
elimina cio' che ti ha trovato malwarebytes,hai per caso utilizzato pendrive o hd esterni?hai un file autorun.inf,e se l hai fatto bisognera' bonificare anche loro.
faccino
Inviato: Friday, February 26, 2010 3:39:52 PM
Rank: AiutAmico

Iscritto dal : 2/3/2005
Posts: 38
infatti si, molte chiavette e un paio di hd come devo fare
paolopa
Inviato: Friday, February 26, 2010 3:46:08 PM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
ne parliamo dopo degli apparati esterni,ora vorrei essere certo che ripuliamo il pc:
Scarica Combofix

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Salvalo sul desktop.

Importante: dopo aver scaricato COMBOFIX chiudi la connessione,Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso)

Doppio click su combofix.exe (comparirà una videata.)

E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix) tu ignorali.

Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.

Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.
faccino
Inviato: Friday, February 26, 2010 5:43:32 PM
Rank: AiutAmico

Iscritto dal : 2/3/2005
Posts: 38
ComboFix 10-02-25.02 - Administrator 26/02/2010 17.26.32.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1023.738 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-5045331736-8801109860-230933314-8124
c:\recycler\S-1-5-21-5493163615-6015586582-950040096-5573
c:\recycler\S-1-5-21-5573854980-7114772169-368918471-9884
c:\recycler\S-1-5-21-7754361953-9394796715-497768423-4303
c:\recycler\S-1-5-21-8811569654-8511519200-060536118-2265
c:\recycler\S-1-5-21-9125589906-4477717380-854772337-3091
c:\windows\srchasst\NLS302EN.LEX

.
((((((((((((((((((((((((( Files Creati Da 2010-01-26 al 2010-02-26 )))))))))))))))))))))))))))))))))))
.

2010-03-06 16:37 . 2010-03-06 16:37 -------- d-----w- c:\programmi\Live-Player
2010-02-26 11:20 . 2010-02-26 11:20 5115824 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-07 15:14 . 2009-05-25 07:54 -------- dc----w- c:\documents and settings\Administrator\Dati applicazioni\Skype
2010-03-07 15:09 . 2009-05-25 07:55 -------- dc----w- c:\documents and settings\Administrator\Dati applicazioni\skypePM
2010-02-26 11:27 . 2009-10-12 15:02 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-02-23 14:25 . 2003-11-05 22:24 76144 ----a-w- c:\windows\system32\PERFC010.DAT
2010-02-23 14:25 . 2003-11-05 22:24 451300 ----a-w- c:\windows\system32\PERFH010.DAT
2010-01-07 15:07 . 2009-10-12 15:02 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-10-12 15:02 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\programmi\Alcohol Soft\Alcohol 52\axcmd.exe" [2009-04-02 203416]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"="c:\progra~1\CA\ETRUST~1\realmon.exe" [2003-02-13 493024]
"WinVNC"="c:\programmi\UltraVNC\WinVNC.exe" [2003-09-21 630848]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-09-06 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
TL-WN321G Wireless Utility.lnk - c:\programmi\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe [2009-7-22 622592]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Cisco Systems VPN Client.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Cisco Systems VPN Client.lnk
backup=c:\windows\pss\Cisco Systems VPN Client.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Collegamento a Terminal.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Collegamento a Terminal.lnk
backup=c:\windows\pss\Collegamento a Terminal.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^collegamento_a_terminal.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\collegamento_a_terminal.lnk
backup=c:\windows\pss\collegamento_a_terminal.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-12-17 12:28 684032 ----a-w- c:\programmi\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell MFP Color Laser Printer 3115cn Launcher]
2006-08-10 14:06 389120 ----a-w- c:\programmi\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLPSP]
2006-02-22 23:00 192512 ----a-w- c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\dlpsp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 22:11 49152 ----a-w- c:\programmi\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2006-06-30 17:08 40960 ----a-w- c:\programmi\Dell Printers\paperport\IndexSearch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 ----a-w- c:\programmi\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2003-05-02 15:19 4640768 ----a-w- c:\windows\SYSTEM32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2006-06-30 17:08 36864 ----a-w- c:\programmi\Dell Printers\paperport\pptd40nt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-09-06 13:09 413696 ----a-w- c:\programmi\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-10-14 09:22 155648 ----a-r- c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

R2 DLSDB;Dell Printer Status Database;c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\dlsdbnt.exe [11/12/2006 12.52.53 135168]
R2 fssfltr;FssFltr;c:\windows\SYSTEM32\DRIVERS\fssfltr_tdi.sys [06/11/2009 11.01.53 54752]
S0 sptd;sptd;c:\windows\SYSTEM32\DRIVERS\sptd.sys [22/04/2009 11.15.41 717296]
S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys --> c:\windows\system32\DRIVERS\EAPPkt.sys [?]
S3 fsssvc;Servizio Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22.48.42 704864]
.
Contenuto della cartella 'Scheduled Tasks'

2010-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2003-11-19 c:\windows\Tasks\Symantec NetDetect.job
- c:\programmi\Symantec\LiveUpdate\NDETECT.EXE [2003-11-05 10:27]
.
.
------- Scansione supplementare -------
.
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\programmi\PokerStars.IT\PokerStarsUpdate.exe
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\5hpdh84c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.it
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - component: c:\programmi\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKU-Default-Run-swg - c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-HP AutoIndexer - c:\programmi\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe
MSConfigStartUp-HP SchedIndexer - c:\programmi\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe
MSConfigStartUp-OrderReminder - c:\programmi\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
MSConfigStartUp-StatusClient 2 - c:\programmi\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
MSConfigStartUp-swg - c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-TomcatStartup 2 - c:\programmi\Hewlett-Packard\Toolbox\hpbpsttp.exe
MSConfigStartUp-websx - c:\programmi\websx\int139750.exe
AddRemove-HijackThis - c:\documents and settings\Administrator\Desktop\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-26 17:31
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(516)
c:\progra~1\NETSUP~1\pcihooks.dll
.
Ora fine scansione: 2010-02-26 17:37:27
ComboFix-quarantined-files.txt 2010-02-26 16:37

Pre-Run: 59.629.207.552 byte disponibili
Post-Run: 59.616.948.224 byte disponibili

- - End Of File - - 29279953DB99179CD0BDBA152620A328
faccino
Inviato: Friday, February 26, 2010 5:46:20 PM
Rank: AiutAmico

Iscritto dal : 2/3/2005
Posts: 38
adesso sto chiudendo. cmq riprenderò con entrambi i pc lunedì. ci sarai?
shapiro
Inviato: Friday, February 26, 2010 5:52:35 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
come antivirus usi eTrust o il norton?

potresti provare avìra

non sembra esserci niente di dannoso nel log, adesso lo controllo meglio
paolopa
Inviato: Friday, February 26, 2010 5:53:43 PM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
vedrai che qualcuno ci sara',segui solo questo consiglio:dimenticati delle pendrive e degli hd esterni sino a che non saranno stati bonificati.buon weekend.
faccino
Inviato: Friday, February 26, 2010 5:57:23 PM
Rank: AiutAmico

Iscritto dal : 2/3/2005
Posts: 38
grazie mille per il vostro costante aiuto buon week end anche a te
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.