Dopo l'uso di Symantec Security Cheek,mi ha trovato i seguenti file infetti,cosa posso fare senza formattare:
C:\Windows\adiras.exe con Dialer Generic.
C:\Windows\system32\lmf32v.dll_tobedeleted,con Adware.LinkMaker
C:\Windows\system32\lmf32v_tobedeleted.con Spyware.Goidr.
C:\Windows\system32\Preinstaller_exe.con Adware.Incredifind.
C:\Windows\Downloaded Program Files\WinCtlAdx.dll,con Adware.SyncroAd
C:\Mindows\Downloaded Program File\WinCtlAdx.dll, con Packed.Adware
C:\Program\File comuni\WhenU\EmbedSe.dll,con
Adware.Weathercast
C:\Programmi\ARESCOM\adiras.exe,con Dialer.Generic.
NB. In memoria nessun virus.(Ti allego Log)
Logfile of HijackThis v1.99.1
Scan saved at 23.42.36, on
12/03/2005
Platform: Windows XP SP2 (WinNT
5.01.2600)
MSIE: Internet Explorer v6.00
SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.ex
e
C:\WINDOWS\system32\services.ex
e
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.ex
e
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\CTSVCCDA.EX
E
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\system32\drivers\Kod
akCCS.exe
C:\Programmi\Norton
AntiVirus\navapsvc.exe
C:\Programmi\Dantz\Retrospect\r
etrorun.exe
C:\WINDOWS\system32\Ati2evxx.ex
e
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ScsiAccess.
EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\LexmarkX84-X85\ACMo
nitor_X84-X85.exe
C:\PROGRA~1\LexmarkX84-X85\AcBt
nMgr_X84-X85.exe
C:\PROGRA~1\Maxtor\OneTouch\Uti
ls\OneTouch.exe
C:\Programmi\RAMpage\RAMpage.ex
e
C:\PROGRA~1\Norton
AntiVirus\navapw32.exe
C:\Programmi\File
comuni\Real\Update_OB\realsched
.exe
C:\Programmi\QuickTime\qttask.e
xe
C:\Programmi\File comuni\ACD
Systems\IT\DevDetect.exe
C:\Programmi\ATI
Technologies\ATI Control
Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Panicware\Pop-Up
Stopper Free Edition\PSFree.exe
C:\Programmi\ARESCOM\Modem
Telindus Arescom
ND220\dslmon.exe
C:\Programmi\GetRight\getright.
exe
C:\Programmi\GetRight\getright.
exe
C:\Programmi\PopTray\PopTray.ex
e
C:\Programmi\Acoo
Browser\AcooBrowser.exe
C:\Programmi\Messenger\msmsgs.e
xe
C:\WINDOWS\system32\cidaemon.ex
e
C:\Documents and
Settings\Osvaldo\Desktop\Hijack
This.exe
R0 -
HKCU\Software\Microsoft\Interne
t Explorer\Main,Start Page =
http://www.virgilio.it/home/index.html
R1 -
HKLM\Software\Microsoft\Interne
t
Explorer\Main,Default_Page_URL
=
http://www.creative.comR0 -
HKCU\Software\Microsoft\Interne
t Explorer\Main,Local Page =
R0 -
HKLM\Software\Microsoft\Interne
t Explorer\Main,Local Page =
R0 -
HKCU\Software\Microsoft\Interne
t
Explorer\Toolbar,LinksFolderNam
e =
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D
6BE0B3} -
C:\Programmi\Adobe\Reader\Activ
eX\AcroIEHelper.dll
O2 - BHO: bho2gr Class -
{31FF080D-12A3-439A-A2EF-4BA95A
3148E8} -
C:\Programmi\GetRight\xx2gr.dll
O2 - BHO: (no name) -
{53707962-6F74-2D53-2644-206D79
42484F} - C:\PROGRA~1\Spybot -
Search & Destroy\SDHelper.dll
O2 - BHO: IEWatchObj Class -
{9527D42F-D666-11D3-B8DD-006008
38CD5F} -
C:\WINDOWS\System32\IETie.dll
O2 - BHO: NAV Helper -
{BDF3E430-B101-42AD-A544-FADC6B
084872} - C:\Programmi\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus
-
{42CDD1BF-3FFB-4238-8AD1-7859DF
00B1D6} - C:\Programmi\Norton
AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Lexmark
X84-X85 Button Monitor]
C:\PROGRA~1\LexmarkX84-X85\ACMo
nitor_X84-X85.exe
O4 - HKLM\..\Run: [Lexmark
X84-X85 Button Manager]
C:\PROGRA~1\LexmarkX84-X85\AcBt
nMgr_X84-X85.exe
O4 - HKLM\..\Run: [PrinTray]
C:\WINDOWS\System32\spool\DRIVE
RS\W32X86\3\printray.exe
O4 - HKLM\..\Run:
[MaxtorOneTouch]
C:\PROGRA~1\Maxtor\OneTouch\Uti
ls\OneTouch.exe
O4 - HKLM\..\Run: [Tweak UI]
RUNDLL32.EXE
TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [RAMpage]
"C:\Programmi\RAMpage\RAMpage.e
xe" M=30 T=4
P="C:\Programmi\RAMpage\RAMpage
Config.exe"
O4 - HKLM\..\Run: [NAV Agent]
C:\PROGRA~1\Norton
AntiVirus\navapw32.exe
O4 - HKLM\..\Run: [TkBellExe]
"C:\Programmi\File
comuni\Real\Update_OB\realsched
.exe" -osboot
O4 - HKLM\..\Run: [QuickTime
Task]
"C:\Programmi\QuickTime\qttask.
exe" -atboottime
O4 - HKLM\..\Run: [Device
Detector] DevDetect.exe
-autorun
O4 - HKLM\..\Run: [Symantec
NetDriver Monitor]
C:\PROGRA~1\SymNetDrv\SNDMon.ex
e
O4 - HKLM\..\Run: [ATIPTA]
C:\Programmi\ATI
Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKCU\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run:
[PopUpStopperFreeEdition]
"C:\Programmi\Panicware\Pop-Up
Stopper Free
Edition\PSFree.exe"
O4 - HKCU\..\Run: [ccleaner]
"C:\Programmi\CCleaner\ccleaner
.exe" /AUTO
O4 - Startup: HDDlife.lnk =
C:\Programmi\BinarySense\HDDlif
e\HDDlife.exe
O4 - Startup: PopTray.lnk =
C:\Programmi\PopTray\PopTray.ex
e
O4 - Global Startup: DSLMON.lnk
= ?
O4 - Global Startup: GetRight -
Tray Icon.lnk =
C:\Programmi\GetRight\getright.
exe
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C
608501} -
C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem:
Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C
608501} -
C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) -
{4B30061A-5D22-11D3-80F8-009027
6F843F} -
C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem:
Cerca con pgweb -
{4B30061A-5D22-11D3-80F8-009027
6F843F} -
C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PGWeb -
{4B30061A-5D23-11D3-80F8-009027
6F843F} -
C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button:
@C:\Programmi\Messenger\Msgslan
g.dll,-61144 -
{FB5F1910-F110-11d2-BB9E-00C04F
795683} -
C:\Programmi\Messenger\msmsgs.e
xe
O9 - Extra 'Tools' menuitem:
@C:\Programmi\Messenger\Msgslan
g.dll,-61144 -
{FB5F1910-F110-11d2-BB9E-00C04F
795683} -
C:\Programmi\Messenger\msmsgs.e
xe
O14 - IERESET.INF:
START_PAGE_URL=http://www.creat
ive.com
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.c
ab
O16 - DPF:
{2BC66F54-93A8-11D3-BEB6-00105A
A9B6AE} (Symantec AntiVirus
scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSnif
f.cab
O16 - DPF:
{644E432F-49D3-41A1-8DD5-E09916
2EEEC5} (Symantec RuFSI Utility
Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/ca
bsa.cab
O16 - DPF:
{9A9307A0-7DA4-4DAF-B042-5009F2
9E09E1} (ActiveScan Installer
Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF:
{EF791A6B-FC12-4C68-99EF-FB9E20
7A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfs
can/2,0,0,4429/mcfscan.cab
O17 -
HKLM\System\CCS\Services\Tcpip
..\{328CCDCB-3148-4F2D-B0FC-459
C049EB081}: NameServer =
85.37.17.7 151.99.125.1
O23 - Service: Ati HotKey
Poller - ATI Technologies Inc.
-
C:\WINDOWS\system32\Ati2evxx.ex
e
O23 - Service: ATI Smart -
Unknown owner -
C:\WINDOWS\system32\ati2sgag.ex
e
O23 - Service: Creative Service
for CDROM Access - Creative
Technology Ltd -
C:\WINDOWS\System32\CTSVCCDA.EX
E
O23 - Service: Provvedere al
Servizio Sicurezza
(GEARSecurity) - GEAR Software
-
C:\WINDOWS\System32\gearsec.exe
O23 - Service: Kodak Camera
Connection Software (KodakCCS)
- Eastman Kodak Company -
C:\WINDOWS\system32\drivers\Kod
akCCS.exe
O23 - Service: Servizio Norton
AntiVirus Auto-Protect
(navapsvc) - Symantec
Corporation -
C:\Programmi\Norton
AntiVirus\navapsvc.exe
O23 - Service: Retrospect
Launcher (RetroLauncher) -
Dantz Development Corporation -
C:\Programmi\Dantz\Retrospect\r
etrorun.exe
O23 - Service: ScriptBlocking
Service (SBService) - Symantec
Corporation -
C:\PROGRA~1\FILECO~1\SYMANT~1\S
CRIPT~1\SBServ.exe
O23 - Service: ScsiAccess -
Unknown owner -
C:\WINDOWS\System32\ScsiAccess.
EXE
O23 - Service: Symantec Network
Drivers Service (SNDSrvc) -
Symantec Corporation -
C:\Programmi\File
comuni\Symantec
Shared\SNDSrvc.exe