Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Virus incurabile per Norton Opzioni
laretta
Inviato: Wednesday, January 21, 2009 9:08:24 PM

Rank: AiutAmico

Iscritto dal : 10/7/2005
Posts: 435
Buona seraAngel Il mio Norton ha appena rilevato un virus W32. Silly P2P, purtroppo il programma dice che non esistono azioni correttive.Che devo fare? Vi posto il log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21.06.24, on 21/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Symantec Shared\AppCore\AppSvc32.exe
C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\VM_STI.EXE
C:\Programmi\Windows Defender\MSASCui.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmi\File comuni\Symantec Shared\SecurityHistory\mcui32.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgilio.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Programmi\File comuni\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Programmi\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Programmi\File comuni\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmi\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Post Image to Blog - res://C:\Programmi\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Scarica con Download &Express - C:\Programmi\Download Express\Add_Url.htm
O8 - Extra context menu item: Tag This Image - res://C:\Programmi\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Translate Page - http://www.geocities.com/mockba80/translate1.0.txt
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Programmi\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Programmi\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Programmi\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\FRONTP~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone: *.rossoalice.it
O15 - Trusted Zone: www.virgilio.it
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class) - http://www.symantec.com/techsupp/activedata/nprdtinf.cab
O16 - DPF: {4D054067-DE3A-48F9-B19B-BCD229B9AE8D} (PrinterHelpEtcActiveX Control) - http://www.samsungdp.com/printerhelp/ActiveX/DrPrinter.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase969.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198957987359
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4871/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A532CD96-4545-4D36-B2E7-1D30B9389DFD}: NameServer = 85.37.17.50 85.38.28.76
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Network WanMiniport First Position - Unknown owner - C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Programmi\File comuni\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe

--
End of file - 12146 bytes


Per favore cosa controlla il processo Sys fader? E' un messaggio che mi compare in fase di spegnimento.Grazie!
Sponsor
Inviato: Wednesday, January 21, 2009 9:08:24 PM

 
pidue
Inviato: Wednesday, January 21, 2009 9:17:16 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
Ciao, rita, dal log non si evince nulla.

Scarica VirIt , installalo e aggiornalo. Fai due scansioni in modalità provvisoria e pubblica il rapporto.

Scarica Combofix , salvalo sul desktop, disabilita l'antivirus e chiudi la connessione a internet.
Lancialo in mod normale e segui scrupolosamente le istruzioni a video.
Al termine, verrà creato un log in C:\ComboFix.txt che tu pubblicherai.




laretta
Inviato: Wednesday, January 21, 2009 9:47:47 PM

Rank: AiutAmico

Iscritto dal : 10/7/2005
Posts: 435
Grazie Pietro,mi metto subito al lavoro.Per quanto riguarda il processo Sys fader devo pure preoccuparmi? Giacche' ci siamo, perche no? Grazie! :-)
pidue
Inviato: Wednesday, January 21, 2009 9:58:51 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
laretta ha scritto:
Grazie Pietro,mi metto subito al lavoro.Per quanto riguarda il processo Sys fader devo pure preoccuparmi? Giacche' ci siamo, perche no? Grazie! :-)


Il processo Sys Fader non è pericoloso. Qui trovi notizie al riguardo. http://www.suspectfile.com/forum/viewtopic.php?f=4&t=2098. Dovrebbe essere legato alla scheda video, purtroppo non ho trovato soluzione per farlo scomparire, ma continuo a cercare.
Drool



pidue
Inviato: Wednesday, January 21, 2009 10:05:48 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
monsee
Inviato: Thursday, January 22, 2009 12:35:42 AM
Rank: AiutAmico

Iscritto dal : 4/5/2005
Posts: 22,971
laretta
Inviato: Thursday, January 22, 2009 5:33:44 AM

Rank: AiutAmico

Iscritto dal : 10/7/2005
Posts: 435
Grazie Monsee! :-)
laretta
Inviato: Thursday, January 22, 2009 5:52:45 AM

Rank: AiutAmico

Iscritto dal : 10/7/2005
Posts: 435
pidue ha scritto:
Ciao, rita, dal log non si evince nulla.

Scarica VirIt , installalo e aggiornalo. Fai due scansioni in modalità provvisoria e pubblica il rapporto.

Scarica Combofix , salvalo sul desktop, disabilita l'antivirus e chiudi la connessione a internet.
Lancialo in mod normale e segui scrupolosamente le istruzioni a video.
Al termine, verrà creato un log in C:\ComboFix.txt che tu pubblicherai.


Ho eseguito tutto come mi hai suggerito. Quelle scansioni lunghissime in mod.provvisoriad'oh! Be' sono reperibile per cui non importa se sono rimasta in piedi con gli occhi al pc e l 'orecchio al tel. Allora, di seguito trovi i rapporti di entrambe le scansioni.Al completamento di Combofix (non dispongo di una consolle di ripristino d'emergenza, io non l'ho installata, come il prog mi ha chiesto, dovevo??) in basso e' venuta fuori l'iconcina di SpYbot, quella con il lucchetto,a segnalare 120929 processi inseriti nella lista neraThink .Ho pensato cosi' di fare una scansione anche con Spy: Chiave di registro Drive Cleaner 2006 HKEY-CLASSES-ROOT\CLSID\INPROC SERVER 32.Questo e' cio' che ha rilevato.
Hai per caso letto nella sez dedicata a WIN XP un mio post, di qualche giorno fa, riguardo a problemi che ho nella visualizzazione in IE? Puo' essere tutto correlato?Think . Ti ringrazio tantissimo ma tantissimo.Boo hoo! Buona giornata!




Rapporto VirIt

VirIT eXplorer Lite Log

[SCANSIONE DELLA MEMORIA]
[SCANSIONE DELLA MEMORIA]
OK

21/01/2009 - 22:16:49

[SCANSIONE DEL REGISTRO]
OK

[A:]
BOOT SECTOR: OK


[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Programmi\Microsoft AntiSpyware\gcASSoapLib.dll Infetto da Trojan.Win32.Vundo.FQ
* * * RIMOSSO * * *
C:\System Volume Information\_restore{CD748773-6157-4EB2-A650-5996436AC5CB}\RP562\A0114402.dll Infetto da Trojan.Win32.Vundo.FQ
* * * RIMOSSO * * *

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[H:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 149271.
Files Totali: 149271.
Chiavi Registro rimosse: 0.
Virus Rimossi: 2.


22/01/2009 - 01:17:13

[SCANSIONE DEL REGISTRO]
OK

[A:]
BOOT SECTOR: OK


[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[H:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 149277.
Files Totali: 149277.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.




Rapporto Combofix



ComboFix 09-01-21.02 - Rita 2009-01-22 4.41.29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1023.544 [GMT 1:00]
Eseguito da: c:\documents and settings\Rita\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *enabled*
* Creato nuovo punto di ripristino

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Downloaded Program Files\qy60q3v

.
((((((((((((((((((((((((( Files Creati Da 2008-12-22 al 2009-01-22 )))))))))))))))))))))))))))))))))))
.

2009-01-21 22:01 . 2008-03-17 19:23 39,808 --a------ c:\windows\system32\drivers\VIRAGTLT.SYS
2009-01-21 22:00 . 2009-01-22 00:03 <DIR> d-------- C:\VEXPLITE
2009-01-18 18:21 . 2009-01-18 18:21 <DIR> d-------- c:\programmi\File comuni\Acronis
2009-01-18 18:21 . 2009-01-18 18:21 <DIR> d-------- c:\programmi\Acronis
2009-01-18 18:21 . 2009-01-18 18:21 211,520 --a------ c:\windows\system32\drivers\timntr.sys
2009-01-18 18:21 . 2009-01-18 18:21 126,976 --a------ c:\windows\system32\snapapi.dll
2009-01-18 18:21 . 2009-01-18 18:21 82,464 --a------ c:\windows\system32\drivers\snapman.sys
2009-01-18 18:21 . 2009-01-18 18:21 37,888 --a------ c:\windows\system32\setupnt.dll
2009-01-18 18:21 . 2009-01-18 18:21 28,896 --a------ c:\windows\system32\drivers\tifsfilt.sys
2009-01-15 17:47 . 2009-01-15 17:47 <DIR> d-------- C:\9640daa3fe6febe430072acecc4b54
2009-01-14 19:38 . 2009-01-15 18:25 1,374 --a------ c:\windows\imsins.BAK
2009-01-12 19:34 . 2009-01-12 19:34 <DIR> d-------- c:\programmi\AMS Photo Effects
2008-12-31 17:51 . 2009-01-01 10:08 <DIR> d-------- c:\programmi\Spybot - Search & Destroy
2008-12-28 12:37 . 2008-12-28 12:37 <DIR> d-------- c:\windows\Samsung
2008-12-28 12:37 . 2008-03-11 03:17 479,232 --a------ c:\windows\ssndii.exe
2008-12-28 12:37 . 2008-01-10 14:39 44,544 --a------ c:\windows\system32\msxml4a.dll
2008-12-28 12:37 . 2008-01-10 14:39 21,776 --a------ c:\windows\system32\msxml2a.dll
2008-12-28 12:36 . 2008-01-10 13:15 151,552 --a------ c:\windows\system32\ssp2mci.exe
2008-12-28 12:36 . 2008-01-10 13:15 65,536 --a------ c:\windows\system32\ssp2mci.dll
2008-12-28 12:36 . 2008-01-10 13:17 22,723 --a------ c:\windows\system32\ssp2ml3.dll
2008-12-28 12:36 . 2008-01-10 13:17 361 --a------ c:\windows\system32\ssp2ml3.smt
2008-12-28 12:35 . 2008-12-28 12:35 <DIR> d-------- c:\windows\system32\drivers\Samsung
2008-12-28 12:35 . 2008-12-28 12:59 <DIR> d-------- c:\programmi\Samsung
2008-12-28 12:35 . 2008-01-10 02:34 41,984 --------- c:\windows\system32\drivers\DGIVECP.SYS
2008-12-28 12:35 . 2008-01-10 02:33 11,502 --------- c:\windows\Dr. Printer Icon.ico
2008-12-28 12:34 . 2008-04-13 20:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-12-28 12:34 . 2008-04-13 20:47 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2008-12-26 12:28 . 2008-12-26 12:28 <DIR> dr------- c:\documents and settings\NetworkService.NT AUTHORITY\Preferiti
2008-12-26 01:29 . 2008-12-26 01:29 <DIR> d-------- c:\programmi\Free WMA to MP3 Converter
2008-12-26 01:18 . 2008-12-26 01:18 33,846 --a------ c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.bmp
2008-12-26 01:18 . 2008-12-26 01:18 3,396 --a------ c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-22 03:27 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Symantec
2009-01-21 22:14 --------- d-----w c:\programmi\Microsoft AntiSpyware
2009-01-21 21:01 --------- d-----w c:\programmi\File comuni\Symantec Shared
2009-01-18 23:16 6,580 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-01-06 01:04 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 01:04 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-01-06 01:04 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 01:04 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-06 01:04 --------- d-----w c:\programmi\Symantec
2009-01-03 19:59 --------- d-----w c:\programmi\CrossLoop
2009-01-01 22:34 --------- d-----w c:\programmi\File comuni\Adobe
2008-12-31 17:21 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Spybot - Search & Destroy
2008-12-28 11:59 --------- d--h--w c:\programmi\InstallShield Installation Information
2008-12-26 00:18 10,886,008 ----a-w c:\windows\system32\SpoonUninstall.exe
2008-12-22 22:23 --------- d-----w c:\documents and settings\Rita\Dati applicazioni\Alien Skin
2008-12-19 20:04 --------- d-----w c:\programmi\UltraVNC
2008-12-15 14:13 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-15 14:13 --------- d-----w c:\programmi\Java
2008-12-12 20:10 --------- d-----w c:\programmi\Xvid
2008-12-11 19:49 --------- d-----w c:\programmi\Telecom Italia
2008-12-11 19:48 --------- d-----w c:\programmi\Alice ti aiuta
2008-12-11 19:47 --------- d-----w c:\programmi\Motive
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-04 20:46 180,224 ----a-w c:\windows\system32\xvidvfw.dll
2008-12-04 20:42 815,104 ----a-w c:\windows\system32\xvidcore.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-07-27 18:38 48,880 ----a-w c:\documents and settings\Rita\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-04-09 20:11 357,768 ----a-w c:\documents and settings\Rita\SymXPep2.dll
2006-01-28 13:10 48,496 ----a-w c:\documents and settings\user\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-01-04 19:03 88 --sh--r c:\windows\system32\650E5BBDAD.sys
2006-09-14 19:59 56 --sh--r c:\windows\system32\A58BD5A46F.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"ccApp"="c:\programmi\File comuni\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\programmi\Norton Internet Security\osCheck.exe" [2007-01-14 771704]
"Symantec PIF AlertEng"="c:\programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"VIRIT LITE MONITOR"="c:\vexplite\MONLITE.EXE" [2009-01-21 249856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Avvio^Programmi^Esecuzione automatica^Adobe Reader Synchronizer.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Avvio^Programmi^Esecuzione automatica^Alice ti aiuta.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Avvio^Programmi^Esecuzione automatica^Avvio veloce di Adobe Reader.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Avvio^Programmi^Esecuzione automatica^Device Detector 3.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AliceRE_McciTrayApp]
--a------ 2006-11-21 15:26 936960 c:\progra~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\McciTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Probe]
--a------ 2002-12-06 16:07 617984 c:\program files\ASUS\Probe\AsusProb.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel File Shell Monitor]
--a------ 2007-10-30 19:52 16200 c:\programmi\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 03:14 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
--a------ 2006-04-21 15:41 438359 c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 01:41 8523776 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 01:41 81920 c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PE2CKFNT SE]
--------- 1998-07-03 11:51 25088 c:\programmi\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr]
--a------ 2008-04-14 06:19 536576 c:\windows\Samsung\PanelMgr\SSMMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-08-18 18:41 1832272 c:\programmi\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-12-15 15:13 136600 c:\programmi\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 01:41 1626112 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Programmi\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\HelpCtr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Media Player\\wmplayer.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16525:UDP"= 16525:UDP:Rosso Alice UDP

R0 VIRAGTLT;VIRAGTLT;c:\windows\system32\drivers\VIRAGTLT.SYS [2009-01-21 39808]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-25 99376]
R4 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [2008-12-11 8192]
R4 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;c:\programmi\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-04-09 554352]
R4 viritsvclite;Virit eXplorer Lite;c:\vexplite\viritsvc.exe [2007-10-10 57344]
R4 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2008-08-19 6016]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-08-19 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2007-07-15 7680]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2008-08-19 23296]
S4 SSPORT;SSPORT; [x]

--- Altri Servizi/Drivers In Memoria ---

*NewlyCreated* - COMHOST

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd5e0072-6ab9-11dd-a150-0015e9f10984}]
\Shell\Auto\command - Start.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contenuto della cartella 'Scheduled Tasks'

2008-12-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

2009-01-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

2009-01-16 c:\windows\Tasks\Norton Internet Security - Scansione completa sistema - Rita.job
- c:\programmi\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-01-14 02:09]

2009-01-20 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe []

2009-01-22 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe []
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.virgilio.it/
uInternet Settings,ProxyOverride = 127.0.0.1
IE: &Add animation to IncrediMail Style Box - c:\progra~1\INCRED~1\bin\resources\WebMenuImg.htm
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Post Image to Blog - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5003
IE: Scarica con Download &Express - c:\programmi\Download Express\Add_Url.htm
IE: Tag This Image - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5002
IE: Translate Page - http://www.geocities.com/mockba80/translate1.0.txt
IE: Transload Image to ImageShack - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5004
IE: Upload All Images to ImageShack - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5000
IE: Upload Image to ImageShack - c:\programmi\ImageShackToolbar\ImageShackToolbar.dll/5001
Trusted Zone: rossoalice.it
Trusted Zone: virgilio.it\www
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
DPF: Microsoft XML Parser for Java
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-22 04:48:13
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\S-1-5-21-1715567821-343818398-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{91E308A6-1BB7-6A37-F082-ADE8D45B519B}*]
"oakheeeggdhiicjjejalofmbaemeai"=hex:6a,61,70,69,61,63,70,6f,6a,62,62,64,61,70,
70,67,62,6e,64,67,00,fd
"naeiokfikedhmjgkbaleegobmhfc"=hex:6a,61,70,69,61,63,70,6f,6a,62,62,64,61,70,
70,67,62,6e,64,67,00,fd
"oaogalgamdpbiachjlmojkhnkalmik"=hex:63,61,6f,69,69,62,00,7c
.
Ora fine scansione: 2009-01-22 4.52.21
ComboFix-quarantined-files.txt 2009-01-22 03:52:17

Pre-Run: 44.909.973.504 byte disponibili
Post-Run: 45,522,595,840 byte disponibili

232 --- E O F --- 2009-01-15 17:25:56
pidue
Inviato: Thursday, January 22, 2009 9:23:24 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
Ciao, avevi alcune tracce del virus Vundo che VirIt ti ha rimosso. Un altro malware te lo ha tolto ComboFix. Silly P2P è legato a qualche variante del worm delle pen drive.
Se usi una chiavetta, collegala al computer e scansionale con Perlovga Removal Tool. La scansione dura pochissimo, poi riavvia.
Buona serata. Drool



Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.