| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| golclaudio Semidio
 
  
 
 Registrato: 30/12/06 22:57
 Messaggi: 205
 
 
 | 
			
				|  Inviato: 28 Nov 2007 00:18    Oggetto: win32:Trojan-gen UPX |   |  
				| 
 |  
				| me lo ha segnalato avast. Lo ho eliminato (spero), ma per sicurezza se qualcuno da un occhiata al file log..... 
 
  	  | Codice: |  	  | Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23.15.04, on 27/11/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16544)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\a-squared Free\a2service.exe
 C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Programmi\Apoint2K\Apoint.exe
 C:\Programmi\TOSHIBA\E-KEY\CeEKey.exe
 C:\Programmi\TOSHIBA\TouchPad\TPTray.exe
 C:\WINDOWS\system32\ZoomingHook.exe
 C:\WINDOWS\system32\DVDRAMSV.exe
 C:\WINDOWS\system32\TCtrlIOHook.exe
 C:\WINDOWS\system32\TPSMain.exe
 C:\WINDOWS\runservice.exe
 C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 C:\Programmi\TOSHIBA\Touch and Launch\PadExe.exe
 C:\Programmi\Prevx2\PXAgent.exe
 C:\Programmi\TOSHIBA\Tvs\TvsTray.exe
 C:\WINDOWS\system32\dla\tfswctrl.exe
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
 C:\WINDOWS\system32\TPSBattM.exe
 C:\Programmi\Windows Defender\MSASCui.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\WINDOWS\System32\PAStiSvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Apoint2K\Apntex.exe
 C:\VEXPLITE\viritsvc.exe
 C:\Programmi\TOSHIBA\ConfigFree\CFSServ.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\Prevx2\PXConsole.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe
 C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
 C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\WINDOWS\system32\RAMASST.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
 C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
 C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
 C:\Programmi\TOSHIBA\ConfigFree\CFXFER.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 C:\Documents and Settings\claudio\Documenti\sicurezza\Hijackthis\HiJackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.claudio71.altervista.org/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Programmi\Windows Desktop Search\dsWebAllow.dll
 O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Dati applicazioni\Prevx\pxbho.dll
 O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint2K\Apoint.exe
 O4 - HKLM\..\Run: [CeEKEY] C:\Programmi\TOSHIBA\E-KEY\CeEKey.exe
 O4 - HKLM\..\Run: [TPNF] C:\Programmi\TOSHIBA\TouchPad\TPTray.exe
 O4 - HKLM\..\Run: [HWSetup] C:\Programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
 O4 - HKLM\..\Run: [SVPWUTIL] C:\Programmi\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
 O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
 O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
 O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
 O4 - HKLM\..\Run: [SmoothView] C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 O4 - HKLM\..\Run: [PadTouch] C:\Programmi\TOSHIBA\Touch and Launch\PadExe.exe
 O4 - HKLM\..\Run: [Tvs] C:\Programmi\TOSHIBA\Tvs\TvsTray.exe
 O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
 O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [PrevxOne] "C:\Programmi\Prevx2\PXConsole.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
 O4 - Global Startup: Bluetooth Manager.lnk = ?
 O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
 O4 - Global Startup: Windows Desktop Search.lnk = C:\Programmi\Windows Desktop Search\WindowsSearch.exe
 O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 O12 - Plugin for .UVR: C:\Programmi\Internet Explorer\Plugins\NPUPano.dll
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
 O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://www.tele2mail.com/static/apps/utils/AccountHelper.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{A4E64512-20C9-47E9-917F-D01198B735B4}: NameServer = 130.244.127.161,130.244.127.169
 O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
 O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
 O23 - Service: PREVXAgent - Prevx - C:\Programmi\Prevx2\PXAgent.exe
 O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
 O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas   www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
 
 --
 End of file - 10629 bytes
 | 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 28 Nov 2007 00:29    Oggetto: |   |  
				| 
 |  
				| Ciao golclaudio,   
 il log sembra pulito.
 
 Per sicurezza, aggiorna VirIt e fagli fare una scansione completa. Posta poi il log generato.
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| golclaudio Semidio
 
  
 
 Registrato: 30/12/06 22:57
 Messaggi: 205
 
 
 | 
			
				|  Inviato: 28 Nov 2007 01:15    Oggetto: |   |  
				| 
 |  
				| eccolo 
 
  	  | Codice: |  	  | 27/11/2007 - 23:37:49 
 [SCANSIONE DEL REGISTRO]
 OK
 
 [C:]
 MASTER BOOT RECORD: OK
 BOOT SECTOR: OK
 
 
 [D:]
 
 
 Chiavi Registro infette: 0.
 Files Infetti: 0.
 Files Sospetti: 0.
 Files Analizzati: 73710.
 Files Totali: 73710.
 Chiavi Registro rimosse: 0.
 Virus Rimossi: 0.
 | 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| golclaudio Semidio
 
  
 
 Registrato: 30/12/06 22:57
 Messaggi: 205
 
 
 | 
			
				|  Inviato: 28 Nov 2007 01:45    Oggetto: |   |  
				| 
 |  
				|  	  | Codice: |  	  | O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient | 
 
 un altro programma antispy mi da questa voce come minaccia, che ne dici?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 28 Nov 2007 02:03    Oggetto: |   |  
				| 
 |  
				| è un programma del tuo Toshiba, niente di cui preoccuparsi. |  | 
	
		| Top |  | 
	
		|  | 
	
		| golclaudio Semidio
 
  
 
 Registrato: 30/12/06 22:57
 Messaggi: 205
 
 
 | 
			
				|  Inviato: 28 Nov 2007 15:32    Oggetto: |   |  
				| 
 |  
				| ok grazie |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |