mia sorella ha accettato l'invio di un file "IMG-1382.zip" con dentro "img0794-www.photoupload.exe" e naturalmente l'ha avviato (è chiaramente un immagine...).
naturalmente è un virus e adesso lo invio a tutti i miei contatti e poi mi si blocca messenger...
ho provato a toglierlo con avast spybot, adware ma niente, adesso ho provato msnfix e il log è questo:
MSNFix 1.519
C:\Documents and Settings\Michele\Desktop\MSNFix\MSNFix
Fix effettuato il 24/09/2007 - 20.22.11,95 By Michele
modalità normale
************************ Cercare i files presenti
... C:\WINDOWS\system\explorer.exe
... C:\WINDOWS\IMG-0002.zip
... C:\WINDOWS\IMG-0177.zip
... C:\WINDOWS\IMG-0317.zip
... C:\WINDOWS\IMG-1180.zip
... C:\WINDOWS\IMG-1200.zip
... C:\WINDOWS\IMG-1378.zip
... C:\WINDOWS\IMG-1963.zip
... C:\WINDOWS\IMG-2145.zip
... C:\WINDOWS\IMG-2873.zip
... C:\WINDOWS\IMG-2884.zip
... C:\WINDOWS\IMG-3294.zip
... C:\WINDOWS\IMG-3632.zip
... C:\WINDOWS\IMG-4530.zip
... C:\WINDOWS\IMG-4839.zip
... C:\WINDOWS\IMG-4908.zip
... C:\WINDOWS\IMG-5068.zip
... C:\WINDOWS\IMG-5491.zip
... C:\WINDOWS\IMG-6082.zip
... C:\WINDOWS\IMG-6904.zip
... C:\WINDOWS\IMG-7641.zip
... C:\WINDOWS\IMG-8312.zip
... C:\WINDOWS\IMG-8686.zip
... C:\WINDOWS\IMG-8709.zip
... C:\WINDOWS\IMG-8806.zip
... C:\WINDOWS\IMG-8876.zip
... C:\WINDOWS\IMG-8953.zip
... C:\WINDOWS\IMG-9139.zip
... C:\WINDOWS\IMG-9738.zip
************************ MSNCHK ***** /!\ beta test /!
************************ Ricerca le cartelle presenti
... C:\Install\
... C:\Temp\
************************ Eliminazione dei files
/!\ ... C:\WINDOWS\system\explorer.exe
.. OK ... C:\WINDOWS\IMG-0002.zip
.. OK ... C:\WINDOWS\IMG-0177.zip
.. OK ... C:\WINDOWS\IMG-0317.zip
.. OK ... C:\WINDOWS\IMG-1180.zip
.. OK ... C:\WINDOWS\IMG-1200.zip
.. OK ... C:\WINDOWS\IMG-1378.zip
.. OK ... C:\WINDOWS\IMG-1963.zip
.. OK ... C:\WINDOWS\IMG-2145.zip
.. OK ... C:\WINDOWS\IMG-2873.zip
.. OK ... C:\WINDOWS\IMG-2884.zip
.. OK ... C:\WINDOWS\IMG-3294.zip
.. OK ... C:\WINDOWS\IMG-3632.zip
.. OK ... C:\WINDOWS\IMG-4530.zip
.. OK ... C:\WINDOWS\IMG-4839.zip
.. OK ... C:\WINDOWS\IMG-4908.zip
.. OK ... C:\WINDOWS\IMG-5068.zip
.. OK ... C:\WINDOWS\IMG-5491.zip
.. OK ... C:\WINDOWS\IMG-6082.zip
.. OK ... C:\WINDOWS\IMG-6904.zip
.. OK ... C:\WINDOWS\IMG-7641.zip
.. OK ... C:\WINDOWS\IMG-8312.zip
.. OK ... C:\WINDOWS\IMG-8686.zip
.. OK ... C:\WINDOWS\IMG-8709.zip
.. OK ... C:\WINDOWS\IMG-8806.zip
.. OK ... C:\WINDOWS\IMG-8876.zip
.. OK ... C:\WINDOWS\IMG-8953.zip
.. OK ... C:\WINDOWS\IMG-9139.zip
.. OK ... C:\WINDOWS\IMG-9738.zip
************************ Eliminazione delle cartelle
.. OK ... C:\Install\
.. OK ... C:\Temp\
************************ Pulizia del Registro
I files ancora presenti saranno eliminati al prossimo riavvio
************************ Eliminazione dei files
.. OK ... C:\WINDOWS\system\explorer.exe
************************ Files sospetti
/!\ questi files necessitano di un parere esperto prima di qualsiasi intervento
[C:\WINDOWS\system32\FanFish25.scr] 9C7585571752BDFE9B381CFBFC58078E
[C:\WINDOWS\system32\InsSec.scr] 0E50526D1402DC7BA691E9B94A00B337
[C:\WINDOWS\system32\InsSecRc.scr] 626BF90902548F60F52C4BBCFAFE902D
<b>==></b> Vi saremo grati se vorrete inviare il file <b> C:\DOCUME~1\Michele\Desktop\Upload_Me.zip </b> su
http://upload.changelog.fr I files e le chiavi di registro eliminati sono stati salvati nel file 24092007_20.29.2740.zip
------------------------------------------------------------------------
Auteur : !aur3n7 Contact:
http://changelog.fr ------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
Mentre quello di hijackthis è:
Logfile of HijackThis v1.99.1
Scan saved at 20.32.37, on 24/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmi\Digisoft AntiDialer\AntiDialer.exe
C:\Documents and Settings\Michele\Desktop\Sicurezza\Hj\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file:///C:\Programmi\TOSHIBA\Free Update Service\splash.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.google.it/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {36FBBF76-3E20-A351-3EF4-FA3E3C60F940} - (no file)
O2 - BHO: Spybot-SandD IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {71928ABB-86D5-33EE-E930-29C10B62C517} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - (no file)
O3 - Toolbar: (no name) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - (no file)
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] :systemroot:\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [updateMgr] C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Avvio veloce di Microsoft Office OneNote 2003.lnk = C:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Digisoft AntiDialer.lnk = C:\Programmi\Digisoft AntiDialer\AntiDialer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Scarica con Download andExpress - C:\Programmi\Download Express\Add_Url.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Browser Adjustment - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file:///C:\Programmi\TOSHIBA\Free Update Service\splash.html
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cabO16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) -
http://lazzaro88ne.spaces.live.com/PhotoUpload/MsnPUpld.cabO16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) -
https://safe.tele2.com/inc/accounthelper.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://messenger.zone.msn.com/binary/ZIntro.cab56649.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Miscrosoft Updates Service (MsUpdate) - Unknown owner - C:\WINDOWS\System32\msupd.exe (file missing)
O23 - Service: vcczowjpokyk (MsUpdate6) - Unknown owner - C:\WINDOWS\System32\msupd6.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
QUALCHE CONSIGLIO???????????