Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

controllo testo vundo fix Opzioni
azzurroavita
Inviato: Monday, February 11, 2008 11:10:01 PM
Rank: Newbie

Iscritto dal : 2/9/2008
Posts: 0

VundoFix V6.7.8

Checking Java version...

Sun Java not detected
Scan started at 21.55.43 10/02/2008

Listing files found while scanning....

C:\WINDOWS\system32\byxxutt.dll
C:\WINDOWS\system32\eqxrlbbb.dll
C:\WINDOWS\system32\khfeddb.dll
C:\WINDOWS\system32\khfeeeb.dll
C:\WINDOWS\system32\nnnlmli.dll
C:\WINDOWS\system32\npqss.ini
C:\WINDOWS\system32\npqss.ini2
C:\WINDOWS\system32\opnlifc.dll
C:\WINDOWS\system32\rqrrppo.dll
C:\WINDOWS\system32\sqvmayqy.dll
C:\WINDOWS\system32\ssqpn.dll
C:\windows\system32\zjiddqxb.dllbox

Beginning removal...

Attempting to delete C:\WINDOWS\system32\byxxutt.dll
C:\WINDOWS\system32\byxxutt.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\eqxrlbbb.dll
C:\WINDOWS\system32\eqxrlbbb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\khfeddb.dll
C:\WINDOWS\system32\khfeddb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\khfeeeb.dll
C:\WINDOWS\system32\khfeeeb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnlmli.dll
C:\WINDOWS\system32\nnnlmli.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\npqss.ini
C:\WINDOWS\system32\npqss.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\npqss.ini2
C:\WINDOWS\system32\npqss.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\opnlifc.dll
C:\WINDOWS\system32\opnlifc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqrrppo.dll
C:\WINDOWS\system32\rqrrppo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sqvmayqy.dll
C:\WINDOWS\system32\sqvmayqy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqpn.dll
C:\WINDOWS\system32\ssqpn.dll Has been deleted!

Attempting to delete C:\windows\system32\zjiddqxb.dllbox
C:\windows\system32\zjiddqxb.dllbox Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\byxxutt.dll
C:\WINDOWS\system32\byxxutt.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...
Sponsor
Inviato: Monday, February 11, 2008 11:10:01 PM

 
monsee
Inviato: Monday, February 11, 2008 11:15:22 PM
Rank: AiutAmico

Iscritto dal : 4/5/2005
Posts: 22,971
Ha fatto un bel lavoro, ma... non è riuscito a ripulire tutto il verminaio: hai ancora sul computer -viva e vegeta- la dannatissima byxxutt.dll, la quale si starà certo attrezzando per ricreare nuovamente i suoi "compagni di merende"...
In sintesi: la lotta prosegue e c'è da battagliare ancora.
azzurroavita
Inviato: Monday, February 11, 2008 11:19:24 PM
Rank: Newbie

Iscritto dal : 2/9/2008
Posts: 0
Grazie della vostra risposta anche se il problema non è risolto in quanto su hijack dei file d cancellare ho trovato solo uno cioè
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] FIFA Football 2007 mentre gli altri due
O4 - HKLM\..\RunOnce: [SpybotDeletingA9139] command /c del "C:\WINDOWS\system32\ssqpn.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1043] cmd /c del "C:\WINDOWS\system32\ssqpn.dll_tobedeleted"
non li ho tovati ed anche spybot non riesce a cancellarmi virtumonde.dll....come devo fare?
questo è invece il nuovo testo di hijack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23.16.57, on 11/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
C:\Programmi\File comuni\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\File comuni\Panda Software\PavShld\pavprsrv.exe
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\VEXPLITE\viritsvc.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\VEXPLITE\MONLITE.EXE
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Norton AntiVirus\NAVW32.exe
C:\Programmi\Symantec\LiveUpdate\LUALL.EXE
C:\Programmi\Symantec\LiveUpdate\LuComServer_3_4.EXE
C:\Programmi\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programmi\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programmi\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programmi\File comuni\Symantec Shared\COH\coh32.exe
C:\Documents and Settings\Mohamed\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmi\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKLM\..\Run: [3865ff6c] rundll32.exe "C:\WINDOWS\system32\mfhqrgcl.dll",b
O4 - HKLM\..\RunOnce: [SpybotDeletingA7030] command /c del "C:\WINDOWS\system32\jkkji.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2470] cmd /c del "C:\WINDOWS\system32\jkkji.dll_tobedeleted"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Avvio veloce di Microsoft Office OneNote 2003.lnk = C:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: Alice - {74DC4C18-FCF9-4C24-B294-8787C623AAF4} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.coolstreaming.us/webtv/tvkoo/KooPlayer.ocx
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://azzurroavita.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4718CF2C-50B2-448E-BA35-5E03EB257C68}: NameServer = 85.37.17.9 85.38.28.75
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servizio iPod (iPod Service) - Unknown owner - C:\Programmi\iPod\bin\iPodService.exe (file missing)
O23 - Service: Convalida password di Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Programmi\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Programmi\File comuni\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe

--
End of file - 9779 bytes
r16
Inviato: Tuesday, February 12, 2008 9:27:55 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Ti prego di postare i log e le tue richieste ,sempre nello stesso topic, altrimenti mi viene difficile seguirti.
ssicurati di avere accesso a file e cartelle nascosti
(Pannello di controllo-> Opzioni Cartella-> Visualizzazione)
1) Metti la spunta su: Visualizza file e cartelle nascoste
2) Togli la spunta: nascondi file protetti di sistema

Disattiva il ripristino configurazione di sistema http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121
Avvia in modalità provvisoria
Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked
O4 - HKLM\..\Run: [3865ff6c] rundll32.exe "C:\WINDOWS\system32\mfhqrgcl.dll",b
O4 - HKLM\..\RunOnce: [SpybotDeletingA7030] command /c del "C:\WINDOWS\system32\jkkji.dll_tobedeleted
O4 - HKLM\..\RunOnce: [SpybotDeletingC2470] cmd /c del "C:\WINDOWS\system32\jkkji.dll_tobedeleted"

Trova e cancella i file in rosso: (se con la funzione cerca non riesci,devi farlo a mano.
C:\WINDOWS\system32\byxxutt.dll
"C:\WINDOWS\system32\mfhqrgcl.dll",b
"C:\WINDOWS\system32\jkkji.dll_tobedeleted
"C:\WINDOWS\system32\jkkji.dll_tobedeleted
Quelle dll in C:\WINDOWS\system32 ci sono di sicuro,basta avere la pazienza nel cercarle.(assicurati di avere accesso a file e cartelle nascosti)
Di solito sono in messe in ordine alfabetico.
Scarica questi 2 tool:
Fai girare per primo questo (che è lo stesso di prima)
http://www.atribune.org/ccount/click.php?id=4

In Modalità Provvisoria questo :(e segui le indicazioni a video. )

http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe (posta il log.)

Poi fai:Start\Esegui\digita: regedit \ok\ segui il percorso di questa chiave:
Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Run Once
Clicca sopra la cartella Run Once e elimina (tasto destro) le voci(se le trovi) relazionate a questo:
[SpybotDeletingA7030] command /c del "C:\WINDOWS\system32\jkkji.dll_tobedeleted
[SpybotDeletingC2470] cmd /c del "C:\WINDOWS\system32\jkkji.dll_tobedeleted"





Rifai la scansione di Virit (Modalita Provvisoria) e posta sempre qui il log.

P.S: Se su Spybot hai il TEA TIMER attivato, Disattivalo!






azzurroavita
Inviato: Wednesday, February 13, 2008 12:29:25 PM
Rank: Newbie

Iscritto dal : 2/9/2008
Posts: 0
grazie mille il problema sembra risolto speriamo bene....cmq norton nella scansione completa mi da sempre il virus backdoor graybird....
r16
Inviato: Wednesday, February 13, 2008 6:27:32 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao Dai un'occhiata al Task Manager,( Premere Ctrl + Alt + Canc )
e nella scheda Processi vedi se trovi questo processo :
Svch0st.exe.
Se lo trovi lo Termini.
Fai attenzione a come l'ho scritto,non confonderlo con altri legittimi,e che sono quasi simili.
Poi segui il percorso di questa chiave:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
Clicca sulla cartella Run e vedi (a destra) se trovi questa voce: Svch0st.exe.
Se c'è, tasto destro, e la elimini.
Rifai la scansione con Norton.
Per sicurezza posterei un log di HijackThis .



Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.