| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| ManyProbs Comune mortale
 
  
 
 Registrato: 13/06/07 09:47
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 13 Giu 2007 09:56    Oggetto: AIUTO TEMP2.EXE SERVICES.EXE |   |  
				| 
 |  
				| Sono nuovo nel forum e da poco il mio computer presente due problemi: 
 TEMP2.EXE
 Ad ogni avvio del computer appare un'errore Temp2.exe Non so xchè.
 
 Services.exe
 Questo è grave! Dopo qualche minuto dopo aver acceso il computer appare un'errore Services.exe poi dopo 1 minuto appare un'errore con un countdown di 1 minuto che, al termine, riavvia il computer.
 
 Ho fatto di tutto: Ho fatto la scansione del computr con:
 
 SpyEraser, Active virus shield, AVG anti-spyware e spyware terminator.
 Ho usato fino all'esaurimento Tue Up utilities 2007 ma i problemi continuano a esserci!
 
 Ho fatto una scansione con HijackThis, ecco i risultati:
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 9.45.39, on 13/06/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\Programmi\File comuni\InterVideo\DeviceService\DevSvc.exe
 C:\Programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 C:\WINDOWS\system32\oodag.exe
 C:\Programmi\CyberLink\Shared files\RichVideo.exe
 C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\Programmi\Spyware Terminator\sp_rsser.exe
 C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\temp1.exe
 C:\WINDOWS\system32\temp2.exe
 C:\Programmi\AOL\Active Virus Shield\avp.exe
 C:\Programmi\AOL\Active Virus Shield\avp.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Pando Networks\Pando\pando.exe
 C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 C:\Programmi\Uniblue\SpyEraser\SpyEraser.exe
 C:\WINDOWS\system32\dwwin.exe
 C:\Programmi\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: XBTP06568 - {311F9DE8-6126-4EEE-B15F-65CBB3B4F9F6} - C:\Programmi\AOL Security Toolbar\tbu168\AOL_security_toolbar.dll
 O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Programmi\Pando Networks\Pando\PandoIEPlugin.dll
 O2 - BHO: bho3 Class - {58FB2CBB-C874-45FC-A1C9-B62CC9E3BED9} - (no file)
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar3.dll
 O2 - BHO: WeeklyExecuter Class - {f015f320-ab08-11db-abbd-0800200c9a66} - (no file)
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar3.dll
 O3 - Toolbar: AOL Security Toolbar - {3BB63FD4-3C00-44D7-94A9-5DE211900DEF} - C:\Programmi\AOL Security Toolbar\tbu168\AOL_security_toolbar.dll
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_11\bin\jusched.exe"
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Programmi\Uniblue\SpyEraser\SpyEraser.exe" -m
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_11\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://zeb89.spaces.live.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{2C50E420-FAE5-4AEB-A44B-AA8FBE26D844}: Domain = 62
 O17 - HKLM\System\CCS\Services\Tcpip\..\{2C50E420-FAE5-4AEB-A44B-AA8FBE26D844}: NameServer = 62.149.128.2
 O17 - HKLM\System\CCS\Services\Tcpip\..\{5E886A4B-0ACA-4759-A4AB-8E7F915FFEB4}: NameServer = 62.149.128.2
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O20 - Winlogon Notify: jkhfc - C:\WINDOWS\system32\jkhfc.dll (file missing)
 O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
 O20 - Winlogon Notify: mljjjkh - mljjjkh.dll (file missing)
 O20 - Winlogon Notify: tuvuvtr - tuvuvtr.dll (file missing)
 O20 - Winlogon Notify: winmfu32 - winmfu32.dll (file missing)
 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Servizio stato di ASP.NET (aspnet_state) - Unknown owner - (no file)
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
 O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
 O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Programmi\AOL\Active Virus Shield\avp.exe" -r (file missing)
 O23 - Service: Capture Device Service - InterVideo Inc. - C:\Programmi\File comuni\InterVideo\DeviceService\DevSvc.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: IviRegMgr - InterVideo - C:\Programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
 O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared files\RichVideo.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 
 
 
 
 Spero qlkuno mi aiuti! GRAZIE MILLE!
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 13 Giu 2007 11:10    Oggetto: |   |  
				| 
 |  
				| ciao. certo un bel casìno....
 
 scarica questi tools:
 PerlovgaRemover
 RustbFix (una volta installato, devi riavviare il PC per far partire il tool)
 VundoFix
 
 fai lo scan con una alla volta
 metti qui tutti i risultati insieme con il log aggiornato di HJT
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ManyProbs Comune mortale
 
  
 
 Registrato: 13/06/07 09:47
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 14 Giu 2007 07:59    Oggetto: RISULTATI |   |  
				| 
 |  
				| Perlovga.Remover ha fatto una scansione che è durata 1 secondo non mostrando risultati mi ha solo detto "Done" quando l'ho aperto. 
 VundoFix non ha trovato nessun virus.
 
 RustbFix mi ha detto di riavviare il sistema, l'ho riavviata. quando ho riacceso il computer mi ha aperto due documenti di testo:
 
 
 pelog.txt:
 
 ************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************
 14/06/2007  7.50.24,12
 
 ******************* Pre-run Status of system *******************
 
 Rootkit driver xpdx is found. Starting the unload-procedure....
 
 Rustock.b-ADS attached to the System32-folder:
 No streams found.
 
 Looking for Rustock.b-files in the System32-folder:
 system32\xpdx.sys FOUND!
 attempting to delete xpdx.sys from system32-folder
 
 
 ******************* Post-run Status of system *******************
 
 Rustock.b-driver on the system: NONE!
 
 Rustock.b-ADS attached to the System32-folder:
 No System32-ADS found.
 
 Looking for Rustock.b-files in the System32-folder:
 No Rustock.b-files found in system32
 
 
 ******************************* End of Logfile ********************************
 
 
 avenger.txt:
 
 Logfile of The Avenger version 1, by Swandog46
 Running from registry key:
 \Registry\Machine\System\CurrentControlSet\Services\foaypbrl
 
 *******************
 
 Script file located at: \??\C:\WINDOWS\qlcnoqym.txt
 Script file opened successfully.
 
 Script file read successfully
 
 Backups directory opened successfully at C:\Avenger
 
 *******************
 
 Beginning to process script file:
 
 Driver xpdx unloaded successfully.
 Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.
 
 Completed script processing.
 
 *******************
 
 Finished!  Terminate.
 
 
 
 Poi ho provato a riaprire il programma e mi è aperto un'altro documento di testo, pelog.txt:
 
 ************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************
 14/06/2007  8.02.31,56
 
 No Rustock.b-rootkits found
 
 ******************************* End of Logfile ********************************
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 14 Giu 2007 11:07    Oggetto: |   |  
				| 
 |  
				| errore Services.exe dovrebbe essere eliminato...   rifai lo scan con HiJack e metti qui il log per un controllo.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ManyProbs Comune mortale
 
  
 
 Registrato: 13/06/07 09:47
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 15 Giu 2007 13:09    Oggetto: |   |  
				| 
 |  
				|  	  | Orange ha scritto: |  	  | errore Services.exe dovrebbe essere eliminato...   rifai lo scan con HiJack e metti qui il log per un controllo.
 | 
 
 
 da 2 giorni il problema non si è ripetuto, forse adesso il services.exe non mi darà + problemi.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 15 Giu 2007 15:25    Oggetto: |   |  
				| 
 |  
				| Guarda che Rustock non era l'unica infezione presente.... per questo ti avevo chiesto il log HJT.. 
 fai tu.
  |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |