Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

il pc di mio cugino Opzioni
simone85
Inviato: Saturday, November 22, 2008 3:01:59 PM

Rank: AiutAmico

Iscritto dal : 4/6/2008
Posts: 866
Salve, sono a casa di mio cugino perchè mi ha detto che il suo pc non va affatto bene, e in effetti secondo me è infettato, posto il log.. per tentare di di salvarlo. Grazie

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14.58.38, on 22/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\System32\USBPlug.exe
C:\Program Files\Lexmark Z2300 Series\lxdpmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
C:\Users\manu\AppData\Local\ycimmok.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Users\manu\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Eset\nod32kui.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Users\manu\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\wsqmcons.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.intl.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [dscService] C:\Windows\system32\USBPlug.exe
O4 - HKLM\..\Run: [lxdpmon.exe] "C:\Program Files\Lexmark Z2300 Series\lxdpmon.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ycimmok] "c:\users\manu\appdata\local\ycimmok.exe" ycimmok
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Ritaglio schermata e avvio di OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: VirtualExpander.lnk = C:\Users\manu\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: eNetHook.dll
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - - C:\Windows\system32\lxcgcoms.exe
O23 - Service: lxdp_device - - C:\Windows\system32\lxdpcoms.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10136 bytes
Sponsor
Inviato: Saturday, November 22, 2008 3:01:59 PM

 
simone85
Inviato: Sunday, November 23, 2008 5:43:03 PM

Rank: AiutAmico

Iscritto dal : 4/6/2008
Posts: 866
vabè, proverò ad analizzarlo solo.. grazie lo stesso
r16
Inviato: Sunday, November 23, 2008 6:10:45 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
simone85 ha scritto:
vabè, proverò ad analizzarlo solo.. grazie lo stesso

Dai simone85 ,non ti arrabbiare.
Tuo cugino, ha Vista.
Purtroppo, le mie conoscenze su Vista sono piuttosto limitate, e piuttosto di fare danni, alle volte è meglio tacere.
Comunque, fixa queste voci: (queste sono sicuro)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223

scarica ed installa MalwareBytes:
clicca qui per il download : http://www.malwarebytes.org/
esegui una scansione completa del sistema e, una volta terminata la scansione, allega il log che verrà rilasciato
Prima di fare la scansione AGGIORNALO.

Fai una scansione on-line con con kaspersky
http://www.kaspersky.com/virusscanner

Clicca su Kaspersky Online Scanner
Clicca su Accept
Si avvierà un Update
Vai nella colonna di sinistra dove c'è scritto Scan e scegli my computer
Finita la scansione in fondo a destra, clicca sulla la voce View Scan Report, e poi clicca su "Save Report As" e salvalo sul desktop (per postarlo qui).
Aggiorna Java;
http://www.aiutaamici.com/software?ID=11134
Poi simone85, non sei proprio un novellino, se vedi che il pc presenta ancora problemi, fagli fare una scansione con Combofix, nelle modalità che sicuramente sai.
E mi posti il relativo log assieme a quello di Malwarebytes.
simone85
Inviato: Sunday, November 23, 2008 6:28:54 PM

Rank: AiutAmico

Iscritto dal : 4/6/2008
Posts: 866
hihihi, è stata una piccola e affettuosa provocazione r16, fatta col sorriso sulle labbra.., spero di non essere stato scortese, se si, perdonami Pray

tornando al pc, anche io con vista non vado daccordo.. il problema è che si aprono sempre le solite pagine stressanti quando naviga.. stasera si muore di freddo quindi non se ne parla di uscire da casa e andare da lui domani mattina applicherò ciò che mi hai consigliato.. Thanks!!
simone85
Inviato: Monday, November 24, 2008 7:33:35 PM

Rank: AiutAmico

Iscritto dal : 4/6/2008
Posts: 866
ciao r16, questo è il log di combofix:
ComboFix 08-11-23.02 - manu 2008-11-24 19.26.32.1 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1040.18.1184 [GMT 1:00]
Eseguito da: c:\users\manu\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\manu\AppData\Local\ycimmok.dat
c:\users\manu\AppData\Local\ycimmok.exe
c:\users\manu\AppData\Local\ycimmok_nav.dat
c:\users\manu\AppData\Local\ycimmok_navps.dat
c:\users\manu\FAVORI~1\Videos.url
c:\users\manu\Favorites\Videos.url
c:\windows\system32\x64

.
((((((((((((((((((((((((( Files Creati Da 2008-10-24 al 2008-11-24 )))))))))))))))))))))))))))))))))))
.

2008-11-22 16:33 . 2008-11-22 16:52 96,976 --a------ c:\windows\System32\drivers\klin.dat
2008-11-22 16:33 . 2008-11-22 16:52 87,855 --a------ c:\windows\System32\drivers\klick.dat
2008-11-22 16:32 . 2008-11-24 19:14 <DIR> d-------- c:\users\All Users\Kaspersky Lab
2008-11-22 16:32 . 2008-11-24 19:14 <DIR> d-------- c:\programdata\Kaspersky Lab
2008-11-22 16:32 . 2008-11-22 16:32 <DIR> d-------- c:\program files\Kaspersky Lab
2008-11-22 16:32 . 2008-11-24 19:03 4,039,200 --ahs---- c:\windows\System32\drivers\fidbox.dat
2008-11-22 16:32 . 2008-11-24 19:26 450,592 --ahs---- c:\windows\System32\drivers\fidbox2.dat
2008-11-22 16:32 . 2008-11-24 19:03 33,684 --ahs---- c:\windows\System32\drivers\fidbox.idx
2008-11-22 16:32 . 2008-11-24 19:26 3,668 --ahs---- c:\windows\System32\drivers\fidbox2.idx
2008-11-22 16:30 . 2008-11-22 16:30 <DIR> d-------- c:\users\All Users\Kaspersky Lab Setup Files
2008-11-22 16:30 . 2008-11-22 16:30 <DIR> d-------- c:\programdata\Kaspersky Lab Setup Files
2008-11-22 14:58 . 2008-11-22 14:58 <DIR> d-------- c:\program files\Trend Micro
2008-11-22 14:24 . 2008-11-22 14:24 <DIR> d-------- C:\PerfLogs
2008-11-12 09:55 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 09:55 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 09:55 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-03 18:42 . 2008-11-03 18:42 <DIR> d-------- c:\users\manu\AppData\Roaming\Malwarebytes
2008-11-03 18:42 . 2008-11-03 18:42 <DIR> d-------- c:\users\All Users\Malwarebytes
2008-11-03 18:42 . 2008-11-03 18:42 <DIR> d-------- c:\programdata\Malwarebytes
2008-11-03 18:42 . 2008-11-03 18:42 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-03 18:42 . 2008-10-22 16:10 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-03 18:42 . 2008-10-22 16:10 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-10-30 11:45 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-30 11:45 . 2008-01-19 08:36 37,888 --a------ c:\windows\System32\printcom.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-24 18:02 --------- d-----w c:\program files\Lx_cats
2008-11-24 17:54 --------- d-----w c:\programdata\GamesBar
2008-11-24 17:54 --------- d-----w c:\program files\Acer GameZone
2008-11-22 16:06 --------- d-----w c:\program files\eMule
2008-11-22 15:26 --------- d-----w c:\program files\ESET
2008-11-22 13:35 174 --sha-w c:\program files\desktop.ini
2008-11-22 13:27 --------- d-----w c:\program files\Windows Sidebar
2008-11-22 13:27 --------- d-----w c:\program files\Windows Photo Gallery
2008-11-22 13:27 --------- d-----w c:\program files\Windows Mail
2008-11-22 13:27 --------- d-----w c:\program files\Windows Journal
2008-11-22 13:27 --------- d-----w c:\program files\Windows Collaboration
2008-11-22 13:27 --------- d-----w c:\program files\Windows Calendar
2008-11-22 13:26 --------- d-----w c:\program files\Windows Defender
2008-11-22 13:05 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-11-22 13:05 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-11-13 16:51 --------- d-----w c:\programdata\Microsoft Help
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-08-13 14:41 334 ----a-w c:\users\manu\AppData\Roaming\wklnhst.dat
2008-04-18 16:05 92,064 ----a-w c:\users\manu\mqdmmdm.sys
2008-04-18 16:05 9,232 ----a-w c:\users\manu\mqdmmdfl.sys
2008-04-18 16:05 79,328 ----a-w c:\users\manu\mqdmserd.sys
2008-04-18 16:05 66,656 ----a-w c:\users\manu\mqdmbus.sys
2008-04-18 16:05 6,208 ----a-w c:\users\manu\mqdmcmnt.sys
2008-04-18 16:05 5,936 ----a-w c:\users\manu\mqdmwhnt.sys
2008-04-18 16:05 4,048 ----a-w c:\users\manu\mqdmcr.sys
2008-04-18 16:05 25,600 ----a-w c:\users\manu\usbsermptxp.sys
2008-04-18 16:05 22,768 ----a-w c:\users\manu\usbsermpt.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-09 845360]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"eAudio"="c:\acer\Empowering Technology\eAudio\eAudio.exe" [2007-05-09 1286144]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-12 457728]
"EzPrint"="c:\program files\Lexmark 2300 Series\ezprint.exe" [2007-04-29 103344]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-05-03 206952]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-04-04 678672]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"dscService"="c:\windows\system32\USBPlug.exe" [2005-03-01 278528]
"lxdpmon.exe"="c:\program files\Lexmark Z2300 Series\lxdpmon.exe" [2008-03-27 656040]
"LXCGCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2007-02-22 73728]
"lxcgmon.exe"="c:\program files\Lexmark 2300 Series\lxcgmon.exe" [2007-04-29 205744]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-10 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-05-07 c:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

c:\users\manu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
VirtualExpander.lnk - c:\users\manu\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe [2008-03-16 474808]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2001-01-12 535336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll eNetHook.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4B0751C5-784B-403C-956E-DC5CCB6177DF}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BB86AB3F-5A5B-4CF1-A043-70B99CF3C7DB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A2527E5E-2B9E-4247-91E8-DB394D49473E}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{F687A61F-981B-4F51-87E8-F6638F7E7418}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{47956FC8-36AC-4C18-B68B-2A14FBBE1282}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{84895A17-328E-4F95-81A5-7DB717CDD81C}"= c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{0A13BE49-2B62-470D-AAD0-3EE360B3A47A}"= c:\program files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{B488E90E-A860-4209-80F4-6A0D458FC76C}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{671CB9C9-2E09-4DFF-8CEF-D1AB1F3D075F}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{73CB679F-E3BE-4411-B698-82BA2D079972}"= c:\program files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{A721887E-D5B3-44CE-9740-4453470F753E}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{2F011741-A436-4B3B-AF1A-8F3CAE1AFC52}"= c:\program files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{7FE56284-BF1E-4485-9F54-50CB31129A2F}"= c:\program files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{20A9B4B3-52C2-4AA6-8223-66978D69ECB6}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{505BCF9E-56EF-498A-AF4B-EFD5F08628D7}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{146605B1-88E3-472B-A0A7-560CCECFC66A}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{D4639763-73BA-4A4E-A694-4D7D05D0E9F6}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{1BFB9EA4-5E99-40BA-8D7B-CE3751436635}"= UDP:c:\windows\System32\lxdpcoms.exe:Lexmark Communications System
"{2724A735-F55E-4111-9CA4-614E65C2573C}"= TCP:c:\windows\System32\lxdpcoms.exe:Lexmark Communications System
"{8D3BA477-0CC5-4E3E-AF25-3576274EC8C5}"= UDP:c:\windows\System32\lxcgcoms.exe:Lexmark Communications System
"{60E53207-0ED7-4A9F-9721-385661776349}"= TCP:c:\windows\System32\lxcgcoms.exe:Lexmark Communications System
"{1C09487F-0553-4276-BCD6-654C9059F455}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxcgpswx.exe:Printer Status Window
"{322EC77C-EF95-4A82-974B-305BD1EDC1E7}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxcgpswx.exe:Printer Status Window
"{0938EB96-9C9E-4B22-B765-0FE3A7A5E768}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{FFCC859F-940C-4BE7-95CA-D8B3192F0524}c:\\program files\\lexmark z2300 series\\lxdpmon.exe"= UDP:c:\program files\lexmark z2300 series\lxdpmon.exe:Printer Device Monitor
"UDP Query User{103D42C4-3A87-4BDC-8493-A4DA4C6E30D0}c:\\program files\\lexmark z2300 series\\lxdpmon.exe"= TCP:c:\program files\lexmark z2300 series\lxdpmon.exe:Printer Device Monitor
"TCP Query User{757C5907-BC9C-4F77-86A2-A5B6A13D4BE0}c:\\program files\\lexmark z2300 series\\lxdpmon.exe"= UDP:c:\program files\lexmark z2300 series\lxdpmon.exe:Printer Device Monitor
"UDP Query User{7D3AD50D-4F41-4329-BCE1-63D5CA753192}c:\\program files\\lexmark z2300 series\\lxdpmon.exe"= TCP:c:\program files\lexmark z2300 series\lxdpmon.exe:Printer Device Monitor
"TCP Query User{F8AA5FC8-A32F-4131-8210-D2760531823C}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{ED8269F6-CE02-45CF-B8F9-38C21CBD3C2E}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{583670C8-463F-4B5E-B593-AF648613A7E9}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{10C9D537-CACF-4655-AD39-FA7535EF1AA6}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{22E6695E-002D-4808-B25D-EF64BDFA5F27}c:\\ludopoli\\ludopoli.exe"= UDP:c:\ludopoli\ludopoli.exe:ludopoli
"UDP Query User{CC34EFE6-E995-4E27-AAE1-E2B765DCA808}c:\\ludopoli\\ludopoli.exe"= TCP:c:\ludopoli\ludopoli.exe:ludopoli
"TCP Query User{B82ACC13-5748-4B31-B40A-3A882414D2A8}c:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\italian\\setup.exe"= UDP:c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\italian\setup.exe:Kaspersky Internet Security 2009 Setup
"UDP Query User{90AED05B-7722-4C9F-B121-563CA028A785}c:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\italian\\setup.exe"= TCP:c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\italian\setup.exe:Kaspersky Internet Security 2009 Setup

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2008-03-26 20496]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};\??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [2007-07-03 22:20:08 13560]
R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2001-01-12 50688]
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service []
R2 TeamViewer;TeamViewer 3;"c:\program files\TeamViewer3\TeamViewer_Host.exe" -service [2008-01-28 94208]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2008-04-06 2591232]
R3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-04-06 32256]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-04-06 179712]
S3 qcusbser;Qualcomm USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\qcusbser.sys [2008-04-09 64640]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'

2008-11-24 c:\windows\Tasks\User_Feed_Synchronization-{FF2624F4-0DEC-4341-BF07-FB9D05D38EA2}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
- - - - ORFÃOS REMOVIDOS - - - -

HKCU-Run-ycimmok - c:\users\manu\appdata\local\ycimmok.exe
HKCU-Run-Acer Tour Reminder - (no file)


.
------- Supplementare di scansione -------
.
FireFox -: Profile - c:\users\manu\AppData\Roaming\Mozilla\Firefox\Profiles\3iuckwn2.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.yahoo.com
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\Yahoo!\common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-24 19:29:23
Windows 6.0.6001 Service Pack 1 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

- - - - - - - > 'winlogon.exe'(744)
c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
c:\progra~1\KASPER~1\KASPER~1\kloehk.dll

- - - - - - - > 'lsass.exe'(692)
c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
.
Ora fine scansione: 2008-11-24 19.30.51
ComboFix-quarantined-files.txt 2008-11-24 18:30:48

Pre-Run: 33.254.408.192 byte disponibili
Post-Run: 33,119,879,168 byte disponibili

212 --- E O F --- 2008-11-24 17:21:52
r16
Inviato: Monday, November 24, 2008 10:42:03 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao Simone.
Hai fixato le voci di HJT ?
Combofix a levato alcune fetecchie:
c:\users\manu\AppData\Local\ycimmok.dat
c:\users\manu\AppData\Local\ycimmok.exe
c:\users\manu\AppData\Local\ycimmok_nav.dat
c:\users\manu\AppData\Local\ycimmok_navps.dat
c:\users\manu\FAVORI~1\Videos.url
c:\users\manu\Favorites\Videos.url
c:\windows\system32\x64

Vediamo se Malwarebytes, e la scansione di Kaspersky rilevano ancora qualcosa.
Come và il pc del cugino?
simone85
Inviato: Monday, November 24, 2008 11:14:08 PM

Rank: AiutAmico

Iscritto dal : 4/6/2008
Posts: 866
oggi ho fixato le voci di hjt e appunto ho utilizzato combo, purtroppo per il lavoro che facciamo non ho avuto proprio tempo di effettuare le altre operazioni, gli ho detto di non utilizzare il pc cosi domani scansiono con malwarebytes e kaspersky, grazie mille r16 domani ti faro sapere
r16
Inviato: Monday, November 24, 2008 11:17:12 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ok.
Ricordati anche di aggiornare il Java.(eliminando prima le versioni obsolete)
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.