Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

mi controllate il log Opzioni
lamidore
Inviato: Saturday, December 03, 2005 1:18:27 PM
Rank: Member

Iscritto dal : 10/10/2001
Posts: 0
Logfile of HijackThis v1.99.1
Scan saved at 13.15.23, on 03/12/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\csrss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
F:\WINDOWS\cGF6em8\command.exe
F:\WINDOWS\Explorer.EXE
F:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
F:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
F:\WINDOWS\csrss.exe
F:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
F:\WINDOWS\System32\CTHELPER.EXE
F:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
F:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
F:\Programmi\Java\j2re1.4.2_04\bin\jusched.exe
F:\Programmi\eMule\emule.exe
F:\Programmi\Opera\Opera.exe
G:\exdesk\aiutamici sicurezza\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.mps.it/paschihome/HomeBanking/flogin1.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - F:\WINDOWS\System32\yabxv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AtiPTA] "F:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] F:\Programmi\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [CTStartup] F:\Programmi\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [CaAvTray] "F:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "F:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Programmi\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "F:\Programmi\Pirelli\Access Gateway USB Network\CnxTrApp.dll",AppEntry -REG "Pirelli\Access Gateway USB"
O4 - HKLM\..\Run: [timessquare] c:\windows\timessquare.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Programmi\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{D6554E0D-78F7-4F3F-A152-7636667AC59D}: NameServer = 85.37.17.50 151.99.125.1
O20 - Winlogon Notify: yabxv - F:\WINDOWS\System32\yabxv.dll
O23 - Service: Ati HotKey Poller - Unknown owner - F:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - F:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Command Service (cmdService) - Unknown owner - F:\WINDOWS\cGF6em8\command.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - F:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: Windows Time Sync (wservtime) - Unknown owner - F:\WINDOWS\csrss.exe
Sponsor
Inviato: Saturday, December 03, 2005 1:18:27 PM

 
scorpions82
Inviato: Sunday, December 04, 2005 4:54:59 AM
Rank: Member

Iscritto dal : 7/22/2003
Posts: 0
Prima leggi qui:
http://www.aiutamici.com/software/view.asp?tipo=home&CodSw=257&SH=N
http://www.aiutamici.com/software/descrizione.asp?CodSw=1175

Questi sono trojan e li devi eliminare
O4 - HKLM\..\Run: [timessquare] c:\windows\timessquare.exe
O23 - Service: Command Service (cmdService) - Unknown owner - F:\WINDOWS\cGF6em8\command.exe

Queste invece non sono riuscito ad identificarle... per queste aspetta alfonso:
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - F:\WINDOWS\System32\yabxv.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{D6554E0D-78F7-4F3F-A152-7636667AC59D}: NameServer = 85.37.17.50 151.99.125.1
O20 - Winlogon Notify: yabxv - F:\WINDOWS\System32\yabxv.dll


Prova a vedere se il file "c:\windows\timessquare.exe" o "F:\WINDOWS\cGF6em8\command.exe" è stato creato nello stesso momento di "yabxv.dll"; se si, allora "yabxv.dll" si tratta di una libreria utilizzata dal trojan.

Ciauz <img src=icon_smile_big.gif border=0 align=middle>
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.