| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| Tito Comune mortale
 
  
 
 Registrato: 07/09/08 15:44
 Messaggi: 2
 
 
 | 
			
				|  Inviato: 07 Set 2008 17:33    Oggetto: Trojan dropper Eesbin.H |   |  
				| 
 |  
				| Salve a tutti, andiamo per ordine: il mio sistema operativo è windows xp professional s.pack2, mentre il mio antivirus è l'AVG 8. Ora l'Avg mi rileva dei trojan dropper Eesbin.h ma non li riesce a rimuovere. Leggendo il forum ho fatto i passaggi suggeriti: Malwarebytes'antimalwere..combo.fix...e hijackthis..posto di seguito i vari log più il risultato di hijackthis: 1) mbam-log-2008-09-07 (13-16-02).txt
 2)ComboFix.txt
 3) Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 15.37.14, on 07/09/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 C:\WINDOWS\system32\CTsvcCDA.exe
 C:\Programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe
 C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 C:\Programmi\PDF Complete\pdfsvc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\mqsvc.exe
 C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
 C:\WINDOWS\system32\mqtgsvc.exe
 C:\PROGRA~1\AVG\AVG8\avgam.exe
 C:\PROGRA~1\AVG\AVG8\avgnsx.exe
 C:\Programmi\Analog Devices\Core\smax4pnp.exe
 C:\Programmi\PDF Complete\pdfsty.exe
 C:\Programmi\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
 C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
 C:\WINDOWS\SMINST\Scheduler.exe
 C:\Programmi\Hp\HP Software Update\HPWuSchd2.exe
 C:\Programmi\Real\RealPlayer\RealPlay.exe
 C:\Programmi\File comuni\Logitech\QCDriver2\LVCOMS.EXE
 C:\Programmi\Logitech\ImageStudio\LogiTray.exe
 C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
 C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
 C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe
 C:\PROGRA~1\AVG\AVG8\avgtray.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe
 C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
 C:\Programmi\Hewlett-Packard\Shared\HpqToaster.exe
 C:\Programmi\WIDCOMM\Bluetooth Software\BTTray.exe
 C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\explorer.exe
 C:\Programmi\AVG\AVG8\avgrsx.exe
 C:\Programmi\internet explorer\iexplore.exe
 C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 C:\Documents and Settings\Administrator\Desktop\HiJackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll
 O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmi\Microsoft Office\Office12\GrooveShellExtensions.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmi\AVG\AVG8\avgtoolbar.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
 O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Programmi\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
 O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmi\AVG\AVG8\avgtoolbar.dll
 O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
 O4 - HKLM\..\Run: [PDF Complete] "C:\Programmi\PDF Complete\pdfsty.exe"
 O4 - HKLM\..\Run: [PTHOSTTR] C:\Programmi\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
 O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
 O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
 O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
 O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
 O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
 O4 - HKLM\..\Run: [HP Software Update] c:\Programmi\Hp\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [Cpqset] C:\Programmi\Hewlett-Packard\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [WatchDog] C:\Programmi\InterVideo\DVD Check\DVDCheck.exe
 O4 - HKLM\..\Run: [RealTray] C:\Programmi\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
 O4 - HKLM\..\Run: [LVCOMS] C:\Programmi\File comuni\Logitech\QCDriver2\LVCOMS.EXE
 O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programmi\Logitech\ImageStudio\ISStart.exe
 O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programmi\Logitech\ImageStudio\LogiTray.exe
 O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
 O4 - HKLM\..\Run: [NSLauncher] C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programmi\File comuni\LightScribe\LightScribeControlPanel.exe -hidden
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - .DEFAULT User Startup: CCC.lnk = ? (User 'Default user')
 O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
 O4 - Global Startup: BTTray.lnk = ?
 O4 - Global Startup: DVD Check.lnk = C:\Programmi\InterVideo\DVD Check\DVDCheck.exe
 O4 - Global Startup: Kodak EasyShare software.lnk = C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
 O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
 O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371420.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{2BFBE958-926B-42C6-A5A0-42388FE73EFB}: NameServer = 85.37.17.51 85.38.28.97
 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmi\Microsoft Office\Office12\GrooveSystemServices.dll
 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
 O20 - AppInit_DLLs: APSHook.dll,avgrsstx.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: IviRegMgr - InterVideo - C:\Programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
 O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
 O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Programmi\PDF Complete\pdfsvc.exe
 O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Programmi\File comuni\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Programmi\File comuni\SureThing Shared\stllssvr.exe
 
 --
 End of file - 10683 bytes
 
 dopo aver fatto ciò, riattivando l'avg, in quarantena ho trovato oltre ai trojan, qsto: PUP (infezione) programma potenzialmente pericoloso hideExec.EV C:\327882R2FWJFW\hidec.exe
 Potete darmi una mano?
 vi ringrazio in anticipo...Tito
 |  |  
		| Top |  |  
		|  |  
		| baciami Semidio
 
  
  
 Registrato: 02/09/07 15:40
 Messaggi: 287
 Residenza: toscana
 
 | 
			
				|  Inviato: 07 Set 2008 19:30    Oggetto: |   |  
				| 
 |  
				| ciao tito..intanto facciamo una ripulita   
 
 Pulisci i files temporanei con ATF-Cleaner e/o CCleaner 
Segui le istruzioni di questo topic per usare MBAM. 
Segui le istruzioni di questo topic per eseguire combofix. 
Segui le istruzioni di questo topic per postare il log di HiJackThis. 
Riferisci con un nuovo messaggio in questa discussione dell'esito: se ci sono stati problemi particolari, ecc. ecc. E riporta: 
 Carica il log di MBAM su WikiSend e posta il Forum Link che ti viene assegnato. 
Carica il log di Combofix su WikiSend e posta il Forum Link che ti viene assegnato. 
Carica il log di HiJackThis su WikiSend e posta il Forum Link che ti viene assegnato.
 |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |