Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Log Highjack This, problema virus che si rigenerano Opzioni
ruffolo
Inviato: Tuesday, March 26, 2013 12:29:40 AM
Rank: Member

Iscritto dal : 2/11/2013
Posts: 15
maopapof ha scritto:
@shapiro .....

perfavore non far perdere tempo a chi anni or sono veniva ad imparare con modestia in questo sito ed era anche un po' simpatico ............. :O))))
oggi si sente tanto superiore che ha fatto nascere tanti troll che lo voglion pià per ..... il cul proprio lui ... il manager del sapere :O)))))

tu shapiro che sembravi un troll dell'aiuto ..... rimani pure come sei .... perché nel tempo sei rimasto .... come sei .... grazie , penso ... a nome di tutti :O) ... noi .... io incluso :O)


Mao, non so se hai notato ma, sembra che quando qualcuno chiede aiuto nella sezione virus i due informatic coglion si "palleggiano" il malcapitato.
Prendilo tu, no prendilo tu. Io non posso, devo andare in bagno, prendilo tu che è ancora caldo.

Quanta boria che tira a Trieste.
gray1
Inviato: Tuesday, March 26, 2013 12:36:28 AM
Rank: Member

Iscritto dal : 3/25/2013
Posts: 10
Un ringraziamento a tutti coloro che mi hanno aiutato, il problema riguardante quei due virus sembra ormai risolto.
Adesso, dato che mi avete gentilmente informato del fatto che il mio pc non è proprio ben messo, potete dirmi quale procedura dovrei attuare per sistemarlo? Considerate che sono un neofita e che dunque non saprei tradurre gerghi troppo tecnici, inoltre, se si dovesse parlare di cambiare antivirus, sappiate che in precedenza avevo Avira, rimosso per via della troppa pesantezza (il computer non è proprio nuovissimo).
shapiro
Inviato: Tuesday, March 26, 2013 10:47:06 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
gray1 dobbiamo finire, hai ancora delle infezioni da eliminare

ora apri blocco note di windows e copiaci dentro questo codice (non copiare Code)


Code:
file::
c:\docume~1\ALLUSE~1\LOCALS~1\Temp\msiehqywo.com

folder::
c:\documents and settings\Gabry\Dati applicazioni\Ifdoq
c:\documents and settings\Gabry\Dati applicazioni\Udzaed
c:\documents and settings\Papà\Dati applicazioni\Uzma
c:\documents and settings\Papà\Dati applicazioni\Iguc

registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"20689"=-

Fcopy::
c:\windows\system32\dllcache\tcpip.sys|c:\windows\system32\drivers\tcpip.sys


Salva il file nella stessa posizione dove è presente combofix.exe e chiamalo CFScript.txt
Adesso trascina il file CFScript.txt sull'icona rossa di combofix.exe
Riavvia il pc se ti viene richiesto dal programma.
Riavvia e posta il contenuto del file C:\ComboFix.txt

Fai anche questa scansione, vediamo se e' rimasta qualche traccia dell'infezione

Scarica OTL e salvalo sul desktop

Metti la spunta su SCAN ALL USERS.

Sotto output, metti la spunta su minimal output

Clicca sulla freccettina di File Age e seleziona 60 Days

Metti la spunta a LOP Check e Purity Check.

Clicca su RUN SCAN

Lascia fare la scansione senza interferire.

Al termine della scansione trovi due log sul desktop. OTL.txt ed Extras.txt, salvali e caricali su Wikisend
gray1
Inviato: Tuesday, March 26, 2013 5:08:55 PM
Rank: Member

Iscritto dal : 3/25/2013
Posts: 10
Ho fatto come hai detto. Una volta trascinato il file di testo sull'icona, il programma ha avviato la sua solita procedura per poi restituirmi il log, che ho salvato sul desktop, per poi riavviare il pc e copiarne il contenuto qui sotto:

ComboFix 13-03-24.03 - Gabry 26/03/2013 16.31.33.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.767.497 [GMT 1:00]
Eseguito da: c:\documents and settings\Gabry\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Gabry\Desktop\CFScript.txt
AV: AVG Internet Security 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
FILE ::
"c:\docume~1\ALLUSE~1\LOCALS~1\Temp\msiehqywo.com"
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Gabry\Dati applicazioni\Ifdoq
c:\documents and settings\Gabry\Dati applicazioni\Udzaed
c:\documents and settings\Gabry\Dati applicazioni\Udzaed\yxify.gow
.
.
--------------- FCopy ---------------
.
c:\windows\system32\dllcache\tcpip.sys --> c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((( Files Creati Da 2013-02-26 al 2013-03-26 )))))))))))))))))))))))))))))))))))
.
.
2013-03-25 12:07 . 2013-03-25 12:07 -------- d-----w- c:\documents and settings\Davide\Dati applicazioni\{4E42D881-E4CB-4819-8B25-77DE46AE4BE1}
2013-03-25 09:54 . 2013-03-25 09:54 -------- d-----w- c:\documents and settings\Gabry\Impostazioni locali\Dati applicazioni\Identities
2013-03-24 22:48 . 2013-03-24 22:48 -------- d-----w- c:\documents and settings\Gabry\Dati applicazioni\{4E42D881-E4CB-4819-8B25-77DE46AE4BE1}
2013-03-24 19:52 . 2013-03-24 19:52 -------- d-----w- c:\documents and settings\Papà\Impostazioni locali\Dati applicazioni\MFAData
2013-03-24 18:48 . 2013-03-24 18:48 -------- d-----w- c:\documents and settings\Papà\Impostazioni locali\Dati applicazioni\Identities
2013-03-24 18:47 . 2013-03-25 17:04 -------- d-----w- c:\documents and settings\Papà\Dati applicazioni\Roxi
2013-03-24 18:47 . 2013-03-24 18:47 -------- d-----w- c:\documents and settings\Papà\Dati applicazioni\Uzma
2013-03-24 18:47 . 2013-03-24 18:47 -------- d-----w- c:\documents and settings\Papà\Dati applicazioni\Iguc
2013-03-24 18:47 . 2013-03-24 18:47 -------- d-----w- c:\documents and settings\Papà\Dati applicazioni\{4E42D881-E4CB-4819-8B25-77DE46AE4BE1}
2013-03-18 22:07 . 2013-03-18 22:07 -------- d-----w- c:\programmi\Dropbox
2013-03-18 22:05 . 2013-03-25 15:59 -------- d-----w- c:\documents and settings\Papà\Dati applicazioni\Dropbox
2013-03-17 12:08 . 2013-03-17 12:08 -------- d-----w- c:\documents and settings\Papà\Impostazioni locali\Dati applicazioni\Mozilla
2013-03-17 12:07 . 2013-03-17 12:07 -------- d-----w- c:\programmi\File comuni\Symantec Shared
2013-03-17 12:06 . 2013-03-17 12:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Norton
2013-03-10 10:51 . 2013-03-10 10:51 -------- d-----w- c:\documents and settings\Davide\Impostazioni locali\Dati applicazioni\Mozilla
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-13 10:05 . 2013-01-09 16:03 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-13 10:05 . 2013-01-09 16:03 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-09 15:06 . 2013-01-09 15:07 93640 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-09 15:06 . 2013-01-09 15:07 859072 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-09 15:06 . 2013-01-09 15:07 779704 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-09 15:06 . 2013-01-09 15:07 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-08 09:02 . 2013-03-08 09:02 263064 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-01-07 . D00F73D11221805D21F3357AF10426DA . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-01-28 14:49 281760 ----a-w- c:\programmi\File comuni\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Agedke"="c:\documents and settings\Gabry\Dati applicazioni\Ivam\cezuw.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zune Launcher"="c:\programmi\Zune\ZuneLauncher.exe" [2011-08-05 159456]
"AVG_UI"="c:\programmi\AVG\AVG2013\avgui.exe" [2012-12-11 3147384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2011-01-07 128512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"20689"="c:\docume~1\ALLUSE~1\LOCALS~1\Temp\msiehqywo.com" [2012-06-02 98375]
.
c:\documents and settings\Papà\Menu Avvio\Programmi\Esecuzione automatica\
Dropbox.lnk - c:\documents and settings\Gabry\Dati applicazioni\Dropbox\bin\Dropbox.exe [N/A]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-12-03 07:35 946352 ----a-w- c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-01-03 21:51 37296 ----a-w- c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserChoice]
2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 11:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWPersistentQueuedReporting]
2007-02-26 00:01 437160 ----a-w- c:\programmi\File comuni\Microsoft Shared\DW\DWTRIG20.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 23:47 31016 ----a-w- c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-10-19 15:18 17875120 ----a-r- c:\programmi\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 08:04 252848 ----a-w- c:\programmi\File comuni\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [15/10/2012 3.48.52 55776]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [21/09/2012 3.46.00 177376]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [14/09/2012 3.05.20 35552]
R0 mv61xxmm;mv61xxmm;c:\windows\system32\drivers\mv61xxmm.sys [07/01/2011 7.39.23 5632]
R0 mv64xxmm;mv64xxmm;c:\windows\system32\drivers\mv64xxmm.sys [07/01/2011 7.39.24 5632]
R0 mvxxmm;mvxxmm;c:\windows\system32\drivers\mvxxmm.sys [07/01/2011 7.39.24 5632]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [22/10/2012 13.02.46 179936]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [21/09/2012 3.45.54 19936]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [02/10/2012 3.30.38 159712]
R2 avgwd;AVG WatchDog;c:\programmi\AVG\AVG2013\avgwdsvc.exe [22/10/2012 13.05.08 196664]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [07/01/2011 7.17.36 9472]
S2 AVGIDSAgent;AVGIDSAgent;c:\programmi\AVG\AVG2013\avgidsagent.exe [15/11/2012 23.34.30 5814904]
S4 SkypeUpdate;Skype Updater;c:\programmi\Skype\Updater\Updater.exe [19/10/2012 16.14.08 160944]
.
Contenuto della cartella 'Scheduled Tasks'
.
2013-03-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-09 10:05]
.
2013-01-21 c:\windows\Tasks\ROC_REG_JAN.job
- c:\documents and settings\All Users\Dati applicazioni\AVG January 2013 Campaign\ROC.exe [2013-01-21 21:16]
.
2013-01-21 c:\windows\Tasks\ROC_REG_JAN_DELETE.job
- c:\documents and settings\All Users\Dati applicazioni\AVG January 2013 Campaign\ROC.exe [2013-01-21 21:16]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\programmi\File comuni\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\programmi\File comuni\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\programmi\File comuni\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Gabry\Dati applicazioni\Mozilla\Firefox\Profiles\03a0n3qj.default\
FF - ExtSQL: 2013-02-02 20:06; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; c:\programmi\File comuni\DVDVideoSoft\plugins\ff
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-03-26 16:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_137_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_137_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
Ora fine scansione: 2013-03-26 16:39:35
ComboFix-quarantined-files.txt 2013-03-26 15:39
ComboFix2.txt 2013-03-25 12:53
ComboFix3.txt 2013-03-24 23:27
.
Pre-Run: 116.714.139.648 byte disponibili
Post-Run: 116.705.435.648 byte disponibili
.
- - End Of File - - E3A066B606653EE03C8DFBD6D1D0F7F1

Ecco qui i due log caricati in seguito alla scansione con OTL:

http://wikisend.com/download/395300/Extras.Txt
http://wikisend.com/download/200844/OTL.Txt

shapiro
Inviato: Tuesday, March 26, 2013 8:38:32 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164

apri otl e copia sotto "Custom Scans\Fixes" questo codice


Code:
:OTL
DRV - (WDICA) --  File not found
DRV - (PDRFRAME) --  File not found
DRV - (PDRELI) --  File not found
DRV - (PDFRAME) --  File not found
DRV - (PDCOMP) --  File not found
DRV - (PCIDump) --  File not found
DRV - (lbrtfdc) --  File not found
DRV - (i2omgmt) --  File not found
DRV - (Changer) --  File not found
DRV - (catchme) -- C:\DOCUME~1\Gabry\IMPOST~1\Temp\catchme.sys File not found
O4 - HKU\S-1-5-21-484763869-682003330-842925246-1006..\Run: [Agedke] "C:\Documents and Settings\Gabry\Dati applicazioni\Ivam\cezuw.exe" File not found
O4 - Startup: C:\Documents and Settings\Papà\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk =  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 20689 = C:\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\msiehqywo.com ()
[2013/03/25 00.13.39 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/03/25 00.12.16 | 005,044,071 | R--- | C] (Swearware) -- C:\Documents and Settings\Gabry\Desktop\ComboFix.exe
[2013/03/24 19.47.57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Papà\Dati applicazioni\Iguc
[2013/03/24 19.47.57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Papà\Dati applicazioni\Uzma


:Files
ipconfig /flushdns /c



clicca su RUN FIX e posta il log generato

Fammi sapere come va il pc, se e' tutto a posto passiamo alle pulizie
gray1
Inviato: Tuesday, March 26, 2013 9:12:32 PM
Rank: Member

Iscritto dal : 3/25/2013
Posts: 10
========== OTL ==========
Service WDICA stopped successfully!
Service WDICA deleted successfully!
File File not found not found.
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
File File not found not found.
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
File File not found not found.
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
File File not found not found.
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
File File not found not found.
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
File File not found not found.
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
File File not found not found.
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
File File not found not found.
Service Changer stopped successfully!
Service Changer deleted successfully!
File File not found not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\DOCUME~1\Gabry\IMPOST~1\Temp\catchme.sys File not found not found.
Registry value HKEY_USERS\S-1-5-21-484763869-682003330-842925246-1006\Software\Microsoft\Windows\CurrentVersion\Run\\Agedke deleted successfully.
C:\Documents and Settings\Papà\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\20689 deleted successfully.
C:\Documents and Settings\All Users\Local Settings\Temp\msiehqywo.com moved successfully.
C:\Qoobox\Quarantine\Registry_backups folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\URTTemp folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32 folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS folder moved successfully.
C:\Qoobox\Quarantine\C\RECYCLER\S-1-5-18\$fc9e16af965d53aae896795a20f982be folder moved successfully.
C:\Qoobox\Quarantine\C\RECYCLER\S-1-5-18 folder moved successfully.
C:\Qoobox\Quarantine\C\RECYCLER folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\user\Preferiti folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\user folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Gabry\Dati applicazioni\Udzaed folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Gabry\Dati applicazioni\Ivam folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Gabry\Dati applicazioni\Ifdoq folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Gabry\Dati applicazioni folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Gabry folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings folder moved successfully.
C:\Qoobox\Quarantine\C folder moved successfully.
C:\Qoobox\Quarantine folder moved successfully.
Folder move failed. C:\Qoobox\BackEnv scheduled to be moved on reboot.
C:\Qoobox folder moved successfully.
C:\Documents and Settings\Gabry\Desktop\ComboFix.exe moved successfully.
C:\Documents and Settings\Papà\Dati applicazioni\Iguc folder moved successfully.
C:\Documents and Settings\Papà\Dati applicazioni\Uzma folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Configurazione IP di Windows
Svuotata la cache del resolver DNS.
C:\Documents and Settings\Gabry\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Gabry\Desktop\cmd.txt deleted successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 03262013_210543

Files\Folders moved on Reboot...
File\Folder C:\Qoobox\BackEnv not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Per ora sembrerebbe non avere alcun problema, tranne alcuni file di testo e non che sono comparsi nel desktop, la loro icona è semitrasparente e portano il nome di vecchi file da me personalmente scritti e salvati, con l'unica differenza che hanno il nome leggermente storpiato. Non sono documenti importanti, quindi se devono essere eliminati posso ovviamente farlo, aspetto tue indicazioni.
shapiro
Inviato: Tuesday, March 26, 2013 9:18:45 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164

vediamo se vanno via dopo con otl

apri otl e clicca su cleanup il pc si riavviera' e rimuovera' correttamente otl

disattiva e riattiva il ripristino, fai pulizia con ccleaner dei file temp

da pannello di controllo rimuovi java e reinstallalo dal sito ufficiale

allega anche una nuova scansione con hijackthis

gray1
Inviato: Tuesday, March 26, 2013 9:20:53 PM
Rank: Member

Iscritto dal : 3/25/2013
Posts: 10
Prima di procedere, il ripristino era già disattivato. È un problema o posso comunque andare avanti?
shapiro
Inviato: Tuesday, March 26, 2013 9:22:44 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164


se era disattivato ora puoi riattivarlo

ricorda di creare un nuovo punto una volta riattivato
gray1
Inviato: Wednesday, March 27, 2013 8:20:47 PM
Rank: Member

Iscritto dal : 3/25/2013
Posts: 10
Tutto fatto.
Ecco il log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20.19.15, on 27/03/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Programmi\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AVG\AVG2013\avgidsagent.exe
C:\Programmi\AVG\AVG2013\avgwdsvc.exe
c:\Programmi\Zune\ZuneBusEnum.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\Zune\ZuneLauncher.exe
C:\Programmi\AVG\AVG2013\avgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmi\Java\jre7\bin\jqs.exe
C:\Documents and Settings\Gabry\Desktop\HiJackThis(1).exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll
O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Programmi\File comuni\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O4 - HKLM\..\Run: [Zune Launcher] "c:\Programmi\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Programmi\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Programmi\File comuni\DVDVideoSoft\plugins\freeytvdownloader.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Programmi\File comuni\DVDVideoSoft\plugins\freeytmp3downloader.htm
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Programmi\File comuni\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Programmi\File comuni\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programmi\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programmi\Mozilla Maintenance Service\maintenanceservice.exe

--
End of file - 5702 bytes
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.