| Precedente :: Successivo   | 
	
	
	
		| Autore | 
		Messaggio | 
	
	
		edvardmunch Comune mortale
  
 
  Registrato: 02/08/07 20:09 Messaggi: 1
 
  | 
		
			
				 Inviato: 02 Ago 2007 20:30    Oggetto: Forse ho dei Trojan! | 
				     | 
			 
			
				
  | 
			 
			
				Ciao a tutti, ho un problema con il mio portatile, quando finisce di caricare Xp, mi da due errori: CFSServ.exe e NDStray.exe, qualcuno sa spiegarmi cosa sono? Ho fatto la scansione con Norton e non ha trovato nessun virus. Non riesco più a collegarmi tramite wireless. vi allego il report di HijackThis:
 
 
Logfile of Trend Micro HijackThis v2.0.2
 
Scan saved at 19.58.42, on 02/08/2007
 
Platform: Windows XP SP2 (WinNT 5.01.2600)
 
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
 
Boot mode: Normal
 
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
 
C:\WINDOWS\system32\winlogon.exe
 
C:\WINDOWS\system32\services.exe
 
C:\WINDOWS\system32\lsass.exe
 
C:\WINDOWS\system32\Ati2evxx.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\WINDOWS\system32\ACS.exe
 
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
 
C:\WINDOWS\system32\Ati2evxx.exe
 
C:\WINDOWS\Explorer.EXE
 
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
 
C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
 
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
 
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
 
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
 
C:\WINDOWS\system32\spoolsv.exe
 
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 
C:\WINDOWS\system32\DVDRAMSV.exe
 
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
 
C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 
C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 
C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 
C:\Programmi\Toshiba\Toshiba Applet\thotkey.exe
 
C:\WINDOWS\system32\TPSMain.exe
 
C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 
C:\Programmi\TOSHIBA\PadTouch\PadExe.exe
 
C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
 
C:\WINDOWS\AGRSMMSG.exe
 
C:\Programmi\USB MEMORY BAR\diskicon.exe
 
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
 
C:\WINDOWS\system32\ctfmon.exe
 
C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 
C:\Programmi\Messenger\msmsgs.exe
 
C:\Programmi\UFDisk\UFDisk Format Tool\iFormat.exe
 
C:\WINDOWS\system32\TPSBattM.exe
 
C:\WINDOWS\system32\RAMASST.exe
 
C:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
 
C:\Programmi\Microsoft Office\Office10\msoffice.exe
 
C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
 
C:\Programmi\File comuni\Symantec Shared\NMain.exe
 
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
 
C:\DOCUME~1\CARADO~1\IMPOST~1\Temp\Rar$EX01.282\HijackThis.exe
 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
 
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmi\Canon\Easy-WebPrint\Toolband.dll
 
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
 
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
 
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 
O4 - HKLM\..\Run: [THotkey] C:\Programmi\Toshiba\Toshiba Applet\thotkey.exe
 
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
 
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
 
O4 - HKLM\..\Run: [SmoothView] C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 
O4 - HKLM\..\Run: [PadTouch] "C:\Programmi\TOSHIBA\PadTouch\PadExe.exe
 
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
 
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programmi\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
 
O4 - HKLM\..\Run: [DiskIcon] C:\Programmi\USB MEMORY BAR\diskicon.exe
 
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
 
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
 
O4 - Global Startup: iFormat.lnk = C:\Programmi\UFDisk\UFDisk Format Tool\iFormat.exe
 
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
 
O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
 
O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
 
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 
O8 - Extra context menu item: Stampa ad alta velocit? Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
 
O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\j2re1.4.2_05\bin\npjpi142_05.dll
 
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\j2re1.4.2_05\bin\npjpi142_05.dll
 
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
 
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
 
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
 
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\ccPwdSvc.exe
 
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
 
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
 
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmi\Norton Internet Security\comHost.exe
 
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
 
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 
O23 - Service: Servizio Auto-Protect di Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
 
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\SAVScan.exe
 
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
 
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
 
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
 
O23 - Service: Utilit? di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 
 
--
 
End of file - 9325 bytes
 
 Grazie a Tutti | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		Sante62 Dio maturo
  
  
  Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
  | 
		 | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		whitesquall Amministratore
  
  
  Registrato: 26/06/07 15:03 Messaggi: 8413
 
  | 
		
			
				 Inviato: 03 Ago 2007 11:02    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ho letto in internet che però dipende dalla posizione dei file inquestione... se sono in cartelle tipo Windows o Sistem32 potrebbero essere virus...         | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		ste_95 Dio maturo
  
  
  Registrato: 03/08/07 14:41 Messaggi: 1920 Residenza: Italy
  | 
		
			
				 Inviato: 03 Ago 2007 15:42    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				o potrebbero essere stati semplicemente spostati in bak, e in avvio ora i virus...
 
 
fai girare questo tool...:
 
 
link | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		bdoriano Amministratore
  
  
  Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
  | 
		
			
				 Inviato: 03 Ago 2007 19:10    Oggetto: Re: Forse ho dei Trojan! | 
				     | 
			 
			
				
  | 
			 
			
				Ciao edvardmunch,  
 
 
 	  | edvardmunch ha scritto: | 	 		  | C:\DOCUME~1\CARADO~1\IMPOST~1\Temp\Rar$EX01.282\HijackThis.exe | 	  
 
Ricordati che hijackthis va salvato in una sua cartella non temporanea e non sul desktop.  
 
 
Fai i passaggi indicati da Sante62 (il primo dei quali ti indica di far girare FindAWF).  
 
 
PS: se vuoi, puoi presentarti qui | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		 |