Precedente :: Successivo |
Autore |
Messaggio |
capitanjack Mortale adepto


Registrato: 30/11/06 06:00 Messaggi: 35 Residenza: Palermo
|
Inviato: 30 Nov 2006 06:08 Oggetto: Cos'è kasber.exe ??? |
|
|
Ciao a tutti.
Controllando con task manager ho trovato kasber.exe in esecuzione e (con msconfig) anche nei programmi caricati all'avvio.
L'ho rimosso da entrambi ma cercando informazioni sia su google che yahoo che msn non trovo nulla in italiano
qualcuno mi sa dare info in proposito?
Grazie, sia per la risposta che mi vorrete dare che x tutte le volte che mi siete stati d'aiuto "indiretto" (solo consultazione).
Marco |
|
Top |
|
 |
Smjert Dio maturo


Registrato: 01/04/06 18:19 Messaggi: 1619 Residenza: Perso nella rete
|
Inviato: 30 Nov 2006 12:45 Oggetto: |
|
|
Intanto benvenuto!
Trovo pochissimo... credo sia un malware.
Per accertarsene caricalo su questo sito http://www.virustotal.com (premi in alto Sfoglia, seleziona il file e poi premi Send, aspetta che tutti gli antivirus analizzino il tuo file e poi posta il risultato) |
|
Top |
|
 |
capitanjack Mortale adepto


Registrato: 30/11/06 06:00 Messaggi: 35 Residenza: Palermo
|
Inviato: 30 Nov 2006 16:47 Oggetto: |
|
|
Grazie
ecco il risultato:
STATUS: FINISHEDComplete scanning result of "kasber.exe", received in VirusTotal at 11.30.2006, 15:37:10 (CET).
Antivirus Version Update Result
AntiVir 7.2.0.46 11.30.2006 Worm/IRCBot.620544
Authentium 4.93.8 11.30.2006 no virus found
Avast 4.7.892.0 11.30.2006 no virus found
AVG 386 11.30.2006 no virus found
BitDefender 7.2 11.30.2006 Trojan.Flood.22016
CAT-QuickHeal 8.00 11.30.2006 RiskWare.mIRC.6.03 (Not a Virus)
ClamAV devel-20060426 11.30.2006 no virus found
DrWeb 4.33 11.30.2006 BackDoor.IRC.based
eSafe 7.0.14.0 11.30.2006 suspicious Trojan/Worm
eTrust-InoculateIT 23.73.72 11.29.2006 Win32/IRCFlood.mIRC32!Worm
eTrust-Vet 30.3.3223 11.30.2006 Win32/IRCFlood
Ewido 4.0 11.30.2006 no virus found
Fortinet 2.82.0.0 11.30.2006 W32/MircFlood!tr
F-Prot 3.16f 11.30.2006 no virus found
F-Prot4 4.2.1.29 11.30.2006 no virus found
Ikarus 0.2.65.0 11.30.2006 no virus found
Kaspersky 4.0.2.24 11.30.2006 not-a-virus:Client-IRC.Win32.mIRC.603
McAfee 4907 11.29.2006 IRC/Flood.mirc
Microsoft 1.1804 11.30.2006 no virus found
NOD32v2 1892 11.30.2006 probably unknown NewHeur_PE virus
Norman 5.80.02 11.30.2006 W32/Ircbot.AMG
Panda 9.0.0.4 11.29.2006 Suspicious file
Prevx1 V2 11.30.2006 Application.PrcView.A
Sophos 4.11.0 11.16.2006 no virus found
TheHacker 6.0.3.126 11.29.2006 Aplicacion/mIRC.603
UNA 1.83 11.29.2006 Backdoor.mIRC-based.F43F
VBA32 3.11.1 11.30.2006 BackDoor.IRC.based
VirusBuster 4.3.15:9 11.30.2006 Trojan.Flood.BW
Aditional Information
File size: 574464 bytes
MD5: b3027dffa9bbac7e1999223cf737200b
SHA1: 04f7be390d135405b5d1925b205c0c871301b522
packers: UPX
packers: UPX
packers: UPX
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PXC=91986400359 |
|
Top |
|
 |
capitanjack Mortale adepto


Registrato: 30/11/06 06:00 Messaggi: 35 Residenza: Palermo
|
Inviato: 30 Nov 2006 16:56 Oggetto: |
|
|
tieni presente che ho installato
Norton - Zone Alarm - Ad Aware - Spybot - Yahoo! Anti-Spy
pur facendo tutte le scansioni non segnalano nessun problema |
|
Top |
|
 |
capitanjack Mortale adepto


Registrato: 30/11/06 06:00 Messaggi: 35 Residenza: Palermo
|
Inviato: 30 Nov 2006 17:15 Oggetto: |
|
|
nella stessa cartella (C:\WINDOWS\system32\xcvnm) contenente "kasber" trovo anche i seguenti file .exe:
"cult", "few", e "kh"
(Ho formattato la settimana scorsa e, subito domo l'installazione di XP mi sono connesso solo a Windows update x scaricare il SP2 dopodichè ho installato Norton e ZA prima di navigare. Nonostante ciò mi sono ritrovato kh e kasber nella cartella documenti! Li avevo rimossi pensando di aver risolto invece...)
Seguono i risultati di VirusTotal riguardanti i file di cui sopra:
Complete scanning result of "cult.exe", received in VirusTotal at 11.30.2006, 15:47:47 (CET).
Antivirus Version Update Result
AntiVir 7.2.0.46 11.30.2006 no virus found
Authentium 4.93.8 11.30.2006 no virus found
Avast 4.7.892.0 11.30.2006 no virus found
AVG 386 11.30.2006 no virus found
BitDefender 7.2 11.30.2006 no virus found
CAT-QuickHeal 8.00 11.30.2006 no virus found
ClamAV devel-20060426 11.30.2006 no virus found
DrWeb 4.33 11.30.2006 no virus found
eSafe 7.0.14.0 11.30.2006 no virus found
eTrust-InoculateIT 23.73.72 11.29.2006 no virus found
eTrust-Vet 30.3.3223 11.30.2006 no virus found
Ewido 4.0 11.30.2006 no virus found
Fortinet 2.82.0.0 11.30.2006 PrcView
F-Prot 3.16f 11.30.2006 no virus found
F-Prot4 4.2.1.29 11.30.2006 no virus found
Ikarus 0.2.65.0 11.30.2006 no virus found
Kaspersky 4.0.2.24 11.30.2006 no virus found
McAfee 4907 11.29.2006 no virus found
Microsoft 1.1804 11.30.2006 no virus found
NOD32v2 1892 11.30.2006 no virus found
Norman 5.80.02 11.30.2006 no virus found
Panda 9.0.0.4 11.29.2006 no virus found
Prevx1 V2 11.30.2006 Malware
Sophos 4.11.0 11.16.2006 no virus found
TheHacker 6.0.3.126 11.29.2006 Aplicacion/PrcView(2)
UNA 1.83 11.29.2006 no virus found
VBA32 3.11.1 11.30.2006 no virus found
VirusBuster 4.3.15:9 11.30.2006 no virus found
Aditional Information
File size: 61440 bytes
MD5: fedb5342dcedcb457ca634146b9c68bc
SHA1: cf8913675a47664518f9c1d977c68915c06ed396
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PXC=cdf710576321
Complete scanning result of "few.exe", received in VirusTotal at 11.30.2006, 16:04:48 (CET).
Antivirus Version Update Result
AntiVir 7.2.0.46 11.30.2006 no virus found
Authentium 4.93.8 11.30.2006 no virus found
Avast 4.7.892.0 11.30.2006 no virus found
AVG 386 11.30.2006 no virus found
BitDefender 7.2 11.30.2006 Application.Sniffer.DaSniff
CAT-QuickHeal 8.00 11.30.2006 no virus found
ClamAV devel-20060426 11.30.2006 no virus found
DrWeb 4.33 11.30.2006 no virus found
eSafe 7.0.14.0 11.30.2006 no virus found
eTrust-InoculateIT 23.73.72 11.29.2006 no virus found
eTrust-Vet 30.3.3223 11.30.2006 no virus found
Ewido 4.0 11.30.2006 Not-A-Virus.NetTool.Win32.Sniffer.c
Fortinet 2.82.0.0 11.30.2006 HackerTool/DaSniff
F-Prot 3.16f 11.30.2006 no virus found
F-Prot4 4.2.1.29 11.30.2006 no virus found
Ikarus 0.2.65.0 11.30.2006 no virus found
Kaspersky 4.0.2.24 11.30.2006 not-a-virus:NetTool.Win32.Sniffer.c
McAfee 4907 11.29.2006 potentially unwanted program Sniff-DaSniff
Microsoft 1.1804 11.30.2006 no virus found
NOD32v2 1892 11.30.2006 no virus found
Norman 5.80.02 11.30.2006 no virus found
Panda 9.0.0.4 11.29.2006 Sniffer/Nbname
Prevx1 V2 11.30.2006 no virus found
Sophos 4.11.0 11.16.2006 no virus found
TheHacker 6.0.3.126 11.29.2006 no virus found
UNA 1.83 11.29.2006 no virus found
VBA32 3.11.1 11.30.2006 no virus found
VirusBuster 4.3.15:9 11.30.2006 no virus found
Aditional Information
File size: 90112 bytes
MD5: 9e89ff7ff914718b518bbc9dc19c8a7f
SHA1: bbf0fbe19eeff66550ff2e9abc270fa3c2fbc9eb
Complete scanning result of "kh.exe", received in VirusTotal at 11.30.2006, 16:11:02 (CET).
Antivirus Version Update Result
AntiVir 7.2.0.46 11.30.2006 no virus found
Authentium 4.93.8 11.30.2006 no virus found
Avast 4.7.892.0 11.30.2006 no virus found
AVG 386 11.30.2006 no virus found
BitDefender 7.2 11.30.2006 Win32.Worm.Gaobot.NA
CAT-QuickHeal 8.00 11.30.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 11.30.2006 no virus found
DrWeb 4.33 11.30.2006 Win32.HLLW.MyBot.based
eSafe 7.0.14.0 11.30.2006 Win32.Polipos.sus
eTrust-InoculateIT 23.73.72 11.29.2006 no virus found
eTrust-Vet 30.3.3223 11.30.2006 no virus found
Ewido 4.0 11.30.2006 no virus found
Fortinet 2.82.0.0 11.30.2006 suspicious
F-Prot 3.16f 11.30.2006 no virus found
F-Prot4 4.2.1.29 11.30.2006 no virus found
Ikarus 0.2.65.0 11.30.2006 no virus found
Kaspersky 4.0.2.24 11.30.2006 no virus found
McAfee 4907 11.29.2006 no virus found
Microsoft 1.1804 11.30.2006 no virus found
NOD32v2 1892 11.30.2006 a variant of Win32/Rbot
Norman 5.80.02 11.30.2006 no virus found
Panda 9.0.0.4 11.29.2006 W32/Gaobot.ORC.worm
Prevx1 V2 11.30.2006 Malware.Trojan.Backdoor.Gen
Sophos 4.11.0 11.16.2006 Mal/Packer
TheHacker 6.0.3.126 11.29.2006 no virus found
UNA 1.83 11.29.2006 no virus found
VBA32 3.11.1 11.30.2006 suspected of Trojan-Spy.Banker.116
VirusBuster 4.3.15:9 11.30.2006 no virus found
Aditional Information
File size: 221264 bytes
MD5: 3c07b5a78807fc959f5e2e09698173d4
SHA1: 6602c11f010c8120bf6766c2f7227bd47dcd8b69
packers: PACKMAN, SVKP
packers: Packman, SVKProtector
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PXC=e98756674915 |
|
Top |
|
 |
Smjert Dio maturo


Registrato: 01/04/06 18:19 Messaggi: 1619 Residenza: Perso nella rete
|
Inviato: 30 Nov 2006 18:16 Oggetto: |
|
|
Sono indubbiamente dei Malware (Norton non è un gran antivirus, tutt'altro... usalo finchè non ti scade ma poi cambialo con qualcosa di free che è molto meglio, guarda qui)
Scaricati HijackThis, decomprimilo in una cartella tutta sua non temporanea (mettilo ad esempio in C:\HijackThis)
Avvialo, premi Do a system scan and save a log file, ti si apre una finestra di notepad con il risultato, copialo e postalo qua. |
|
Top |
|
 |
capitanjack Mortale adepto


Registrato: 30/11/06 06:00 Messaggi: 35 Residenza: Palermo
|
Inviato: 30 Nov 2006 18:49 Oggetto: |
|
|
Logfile of HijackThis v1.99.1
Scan saved at 17.48.48, on 30/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\cisvc.exe
C:\Programmi\Norton AntiVirus\navapsvc.exe
C:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmi\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Programmi\Outlook Express\msimn.exe
C:\Programmi\Windows Media Player\wmplayer.exe
C:\Programmi\AdunanzA\eMule_AdnzA.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [WiFix service] miwucgf.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AWMON] "C:\Programmi\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [OpwareSE2] "C:\Programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [msennger] C:\WINDOWS\System32\xcvnm\kasber.exe
O4 - HKLM\..\RunServices: [Managment Service] taskmgrc.exe
O4 - HKLM\..\RunServices: [WiFix service] miwucgf.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\MSMSGS.EXE" /background
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1164092892390
O16 - DPF: {7142BA01-8BDF-11CF-9E23-0000E8A37440} (Surround Video Control Object) - http://www.sagraf.com/plugin/download/svideo.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Programmi\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmi\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 |
|
Top |
|
 |
Smjert Dio maturo


Registrato: 01/04/06 18:19 Messaggi: 1619 Residenza: Perso nella rete
|
Inviato: 30 Nov 2006 19:39 Oggetto: |
|
|
Avvia HijackThis, premi Do a system scan only, spunta queste voci e poi premi FixChecked:
Citazione: |
O4 - HKLM\..\Run: [WiFix service] miwucgf.exe
O4 - HKLM\..\Run: [msennger] C:\WINDOWS\System32\xcvnm\kasber.exe
O4 - HKLM\..\RunServices: [Managment Service] taskmgrc.exe
O4 - HKLM\..\RunServices: [WiFix service] miwucgf.exe |
Riavvia il pc in Modalità Provvisoria (quando ti fa il calcolo della memoria, ti segna gli hd collegati ecc premi continuamente F8 finchè non appare un menu, da lì scegli con le freccie la modalità)
Citazione: | Usa la ricerca di Windows e trova questi file: miwucgf.exe, taskmgrc.exe
(ricordati di attivare la ricerca nelle cartelle e nei file nascosti andando
in "Altre opzioni avanzate" e spuntando la voce
"Cerca nei file e nelle cartelle nascosti"). |
Se li trovi li cancelli
Cancella poi questa cartella C:\WINDOWS\System32\xcvnm |
|
Top |
|
 |
|