Precedente :: Successivo |
Autore |
Messaggio |
lisa86 Mortale devoto

Registrato: 30/05/08 01:01 Messaggi: 5 Residenza: roma
|
Inviato: 30 Mag 2008 17:29 Oggetto: virus o cosa?? utilizzo avast e spybot e ho difficoltà! |
|
|
ho trovato il vostro sito girando disperata e demoralizzata su internet... spero mi possiate aiutare!!!
utilizzo avast e spybot e il sistema operativo e winXP.
nn riesco a cancellare fondamentalmente 2 cose: doubleclick e virtumunde...
ho visto su qualche atro post che chi scrive vi manda l'output del programma antivirus.... ma come si manda l'output di avast o spybot???
mi sa che sono troppo impdita...
mi aiutate uguale???
bastano quei due programmi come protezione? |
|
Top |
|
 |
lisa86 Mortale devoto

Registrato: 30/05/08 01:01 Messaggi: 5 Residenza: roma
|
Inviato: 30 Mag 2008 18:02 Oggetto: output |
|
|
Virtumonde: [SBI $42352499] Impostazioni utente (Chiave di registro, nothing done) HKEY_USERS\S-1-5-21-1903205002-2505003544-3488350123-1005\Software\Microsoft\rdfa Virtumonde: [SBI $47E741CD] Impostazioni (Chiave di registro, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws
Virtumonde.dll: [SBI $7442D4BC] Libreria (File, nothing done) C:\WINDOWS\system32\yaywVpPf.dll_old
--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2007-10-07 SDShred.exe (1.0.1.2)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-05-30 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-04-16 Includes\Adware.sbi (*)
2008-05-28 Includes\AdwareC.sbi (*)
2008-05-28 Includes\Cookies.sbi (*)
2007-12-26 Includes\Dialer.sbi (*)
2008-05-28 Includes\DialerC.sbi (*)
2008-05-28 Includes\HeavyDuty.sbi (*)
2008-05-28 Includes\Hijackers.sbi (*)
2008-05-28 Includes\HijackersC.sbi (*)
2008-04-30 Includes\Keyloggers.sbi (*)
2008-05-28 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-05-28 Includes\Malware.sbi (*)
2008-05-28 Includes\MalwareC.sbi (*)
2008-03-26 Includes\PUPS.sbi (*)
2008-05-28 Includes\PUPSC.sbi (*)
2008-05-28 Includes\Revision.sbi (*)
2008-01-09 Includes\Security.sbi (*)
2008-05-28 Includes\SecurityC.sbi (*)
2008-04-16 Includes\Spybots.sbi (*)
2008-05-28 Includes\SpybotsC.sbi (*)
2008-04-16 Includes\Spyware.sbi (*)
2008-05-28 Includes\SpywareC.sbi (*)
2007-11-06 Includes\Tracks.uti 2008-05-28 Includes\Trojans.sbi (*)
2008-05-28 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll
ecco.. penso questo sia lìoutput di spybot!
per quanto riguarda avst nn so come si faccia.... vi riporto il virus che ora ha trovato:
win32:rootkit-gen [rtk]
ma perchè se nn faccio altro che scansioni trova sempre virus nuovi??? nn lo uso per altro sto computer al momento!!!! |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 30 Mag 2008 19:04 Oggetto: |
|
|
Ciao lisa86,
Cominciamo dal più rognoso:
- Scarica VundoFix e VirtumundoBegone e salvali sul desktop.
- Avvia VundoFix
Seleziona Scan for Vundo e a scansione terminata scegli Remove Vundo.
Clicca Yes e alla richiesta di riavviare il Pc rispondi Ok.
Al riavvio dovrebbe comparire il blocco-note con dentro il log, copia e posta sul forum il contenuto.
- Ora avvia in modalità provvisoria
Avvia VirtumundoBeGone e segui le indicazioni a video.
riavvia il Pc in modalità normale e posta il log.
- Segui le istruzioni di questo topic per postare il log di combofix.
- Fai anche un nuovo log di HijackThis e mettilo qui.
|
|
Top |
|
 |
lisa86 Mortale devoto

Registrato: 30/05/08 01:01 Messaggi: 5 Residenza: roma
|
Inviato: 31 Mag 2008 01:53 Oggetto: mmmm |
|
|
sto seguendo ciò che mi hai detto... sta scansionando con il primo programma.... speriamo bene anche perchè questo gingillo nn è il mio
ok, ha appena finito la scansione e dice che nn c'erano infezioni ( ) CHE DEVO FARE???? spybot continua a troarlo.....
ma cos'è "Fai anche un nuovo log di HijackThis e mettilo qui."???? |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 31 Mag 2008 09:58 Oggetto: |
|
|
Manca il log di combofix.
Segui le istruzioni di questo topic per postare il log di hijackthis. |
|
Top |
|
 |
lisa86 Mortale devoto

Registrato: 30/05/08 01:01 Messaggi: 5 Residenza: roma
|
Inviato: 31 Mag 2008 13:15 Oggetto: il problema è un altro |
|
|
il problema è che vundofi nn trova nulla.... e di conseguenza nn fa riavvia e nn trovo il file di log! possibile?
cmq riporto la nuova scansione con spybot... sembra peggio della precedente e ui internet rallenta sempre di più e mi appaiono sempre più frequentemente finestre di SPAM... AIUTOOOOOO
ma faccio bene a dire a spybot di corregere il problema dopo che lo ha trovato?? perchè effetti positivi nn ne riscontro.... il panico...
Virtumonde: [SBI $42352499] Impostazioni utente (Chiave di registro, nothing done) HKEY_USERS\S-1-5-21-1903205002-2505003544-3488350123-1005\Software\Microsoft\rdfa
Virtumonde: [SBI $47E741CD] Impostazioni (Chiave di registro, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws
Virtumonde.dll: [SBI $7442D4BC] Libreria (File, nothing done) C:\WINDOWS\system32\jkkKeEVp.dll
Virtumonde.dll: [SBI $960C7A04] Assistente del browser (BHO) (Chiave di registro, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CED952AA-4D87-40B3-A88C-3755B527108A}
Virtumonde.dll: [SBI $960C7A04] ID di classe (Chiave di registro, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CED952AA-4D87-40B3-A88C-3755B527108A}
DoubleClick: Cookie tracciante (Internet Explorer: TOSHIBA_Satellite) (Cookie, nothing done)
AdRevolver: Cookie tracciante (Internet Explorer: TOSHIBA_Satellite) (Cookie, nothing done)
Right Media: Cookie tracciante (Internet Explorer: TOSHIBA_Satellite) (Cookie, nothing done)
AdRevolver: Cookie tracciante (Internet Explorer: TOSHIBA_Satellite) (Cookie, nothing done)
AdRevolver: Cookie tracciante (Internet Explorer: TOSHIBA_Satellite) (Cookie, nothing done)
MediaPlex: Cookie tracciante (Internet Explorer: TOSHIBA_Satellite) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2007-10-07 SDShred.exe (1.0.1.2)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-05-30 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-04-16 Includes\Adware.sbi (*)
2008-05-28 Includes\AdwareC.sbi (*)
2008-05-28 Includes\Cookies.sbi (*)
2007-12-26 Includes\Dialer.sbi (*)
2008-05-28 Includes\DialerC.sbi (*)
2008-05-28 Includes\HeavyDuty.sbi (*)
2008-05-28 Includes\Hijackers.sbi (*)
2008-05-28 Includes\HijackersC.sbi (*)
2008-04-30 Includes\Keyloggers.sbi (*)
2008-05-28 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-05-28 Includes\Malware.sbi (*)
2008-05-28 Includes\MalwareC.sbi (*)
2008-03-26 Includes\PUPS.sbi (*)
2008-05-28 Includes\PUPSC.sbi (*)
2008-05-28 Includes\Revision.sbi (*)
2008-01-09 Includes\Security.sbi (*)
2008-05-28 Includes\SecurityC.sbi (*)
2008-04-16 Includes\Spybots.sbi (*)
2008-05-28 Includes\SpybotsC.sbi (*)
2008-04-16 Includes\Spyware.sbi (*)
2008-05-28 Includes\SpywareC.sbi (*)
2007-11-06 Includes\Tracks.uti
2008-05-28 Includes\Trojans.sbi (*)
2008-05-28 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll |
|
Top |
|
 |
lisa86 Mortale devoto

Registrato: 30/05/08 01:01 Messaggi: 5 Residenza: roma
|
Inviato: 31 Mag 2008 18:31 Oggetto: forse... |
|
|
forse è queso l'output di combofix???
[05/31/2008, 2:17:59] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\TOSHIBA_Satellite\Desktop\download\VirtumundoBeGone.exe" )
[05/31/2008, 2:18:03] - Detected System Information:
[05/31/2008, 2:18:03] - Windows Version: 5.1.2600, Service Pack 2
[05/31/2008, 2:18:03] - Current Username: TOSHIBA_Satellite (Admin)
[05/31/2008, 2:18:03] - Windows is in NORMAL mode.
[05/31/2008, 2:18:03] - Searching for Browser Helper Objects:
[05/31/2008, 2:18:03] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/31/2008, 2:18:03] - BHO 2: {36F73322-468B-44D0-BF33-534D1FF394F5} ()
[05/31/2008, 2:18:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:03] - Checking for HKLM\...\Winlogon\Notify\yaywVpPf
[05/31/2008, 2:18:03] - Key not found: HKLM\...\Winlogon\Notify\yaywVpPf, continuing.
[05/31/2008, 2:18:03] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[05/31/2008, 2:18:03] - BHO 4: {54EB926D-E53F-4DA1-9595-6B4EADF80D22} ()
[05/31/2008, 2:18:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:03] - Checking for HKLM\...\Winlogon\Notify\awtuuUnL
[05/31/2008, 2:18:03] - Key not found: HKLM\...\Winlogon\Notify\awtuuUnL, continuing.
[05/31/2008, 2:18:03] - BHO 5: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[05/31/2008, 2:18:03] - BHO 6: {675131D9-916D-4500-A593-13B861E0B41E} ()
[05/31/2008, 2:18:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:03] - Checking for HKLM\...\Winlogon\Notify\tuvurqPG
[05/31/2008, 2:18:03] - Key not found: HKLM\...\Winlogon\Notify\tuvurqPG, continuing.
[05/31/2008, 2:18:03] - BHO 7: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/31/2008, 2:18:03] - BHO 8: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/31/2008, 2:18:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:03] - No filename found. Continuing.
[05/31/2008, 2:18:03] - BHO 9: {B76CF1F4-ECDC-4CA1-89F8-32403496528E} ()
[05/31/2008, 2:18:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:03] - Checking for HKLM\...\Winlogon\Notify\cbXPjGWp
[05/31/2008, 2:18:03] - Found: HKLM\...\Winlogon\Notify\cbXPjGWp - This is probably Virtumundo.
[05/31/2008, 2:18:03] - Assigning {B76CF1F4-ECDC-4CA1-89F8-32403496528E} MSEvents Object
[05/31/2008, 2:18:03] - BHO list has been changed! Starting over...
[05/31/2008, 2:18:04] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/31/2008, 2:18:04] - BHO 2: {36F73322-468B-44D0-BF33-534D1FF394F5} ()
[05/31/2008, 2:18:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:04] - Checking for HKLM\...\Winlogon\Notify\yaywVpPf
[05/31/2008, 2:18:04] - Key not found: HKLM\...\Winlogon\Notify\yaywVpPf, continuing.
[05/31/2008, 2:18:04] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[05/31/2008, 2:18:04] - BHO 4: {54EB926D-E53F-4DA1-9595-6B4EADF80D22} ()
[05/31/2008, 2:18:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:04] - Checking for HKLM\...\Winlogon\Notify\awtuuUnL
[05/31/2008, 2:18:04] - Key not found: HKLM\...\Winlogon\Notify\awtuuUnL, continuing.
[05/31/2008, 2:18:04] - BHO 5: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[05/31/2008, 2:18:04] - BHO 6: {675131D9-916D-4500-A593-13B861E0B41E} ()
[05/31/2008, 2:18:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:04] - Checking for HKLM\...\Winlogon\Notify\tuvurqPG
[05/31/2008, 2:18:04] - Key not found: HKLM\...\Winlogon\Notify\tuvurqPG, continuing.
[05/31/2008, 2:18:04] - BHO 7: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/31/2008, 2:18:04] - BHO 8: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/31/2008, 2:18:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:04] - No filename found. Continuing.
[05/31/2008, 2:18:04] - BHO 9: {B76CF1F4-ECDC-4CA1-89F8-32403496528E} (MSEvents Object)
[05/31/2008, 2:18:04] - ALERT: Found MSEvents Object!
[05/31/2008, 2:18:04] - BHO 10: {C83FC2EA-95FC-4903-8609-CE98207A7753} ()
[05/31/2008, 2:18:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:04] - Checking for HKLM\...\Winlogon\Notify\jkkKeEVp
[05/31/2008, 2:18:04] - Key not found: HKLM\...\Winlogon\Notify\jkkKeEVp, continuing.
[05/31/2008, 2:18:04] - Finished Searching Browser Helper Objects
[05/31/2008, 2:18:04] - *** Detected MSEvents Object
[05/31/2008, 2:18:04] - Trying to remove MSEvents Object...
[05/31/2008, 2:18:05] - Terminating Process: IEXPLORE.EXE
[05/31/2008, 2:18:05] - Terminating Process: RUNDLL32.EXE
[05/31/2008, 2:18:06] - Disabling Automatic Shell Restart
[05/31/2008, 2:18:06] - Terminating Process: EXPLORER.EXE
[05/31/2008, 2:18:06] - Suspending the NT Session Manager System Service
[05/31/2008, 2:18:07] - Terminating Windows NT Logon/Logoff Manager
[05/31/2008, 2:18:07] - Re-enabling Automatic Shell Restart
[05/31/2008, 2:18:07] - File to disable: C:\WINDOWS\system32\cbXPjGWp.dll
[05/31/2008, 2:18:07] - Renaming C:\WINDOWS\system32\cbXPjGWp.dll -> C:\WINDOWS\system32\cbXPjGWp.dll.vir
[05/31/2008, 2:18:07] - File successfully renamed!
[05/31/2008, 2:18:07] - Removing HKLM\...\Browser Helper Objects\{B76CF1F4-ECDC-4CA1-89F8-32403496528E}
[05/31/2008, 2:18:08] - Removing HKCR\CLSID\{B76CF1F4-ECDC-4CA1-89F8-32403496528E}
[05/31/2008, 2:18:08] - Adding Kill Bit for ActiveX for GUID: {B76CF1F4-ECDC-4CA1-89F8-32403496528E}
[05/31/2008, 2:18:08] - Deleting ATLEvents/MSEvents Registry entries
[05/31/2008, 2:18:08] - Removing HKLM\...\Winlogon\Notify\cbXPjGWp
[05/31/2008, 2:18:08] - Searching for Browser Helper Objects:
[05/31/2008, 2:18:08] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/31/2008, 2:18:08] - BHO 2: {36F73322-468B-44D0-BF33-534D1FF394F5} ()
[05/31/2008, 2:18:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:08] - Checking for HKLM\...\Winlogon\Notify\yaywVpPf
[05/31/2008, 2:18:08] - Key not found: HKLM\...\Winlogon\Notify\yaywVpPf, continuing.
[05/31/2008, 2:18:08] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[05/31/2008, 2:18:08] - BHO 4: {54EB926D-E53F-4DA1-9595-6B4EADF80D22} ()
[05/31/2008, 2:18:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:08] - Checking for HKLM\...\Winlogon\Notify\awtuuUnL
[05/31/2008, 2:18:08] - Key not found: HKLM\...\Winlogon\Notify\awtuuUnL, continuing.
[05/31/2008, 2:18:08] - BHO 5: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[05/31/2008, 2:18:08] - BHO 6: {675131D9-916D-4500-A593-13B861E0B41E} ()
[05/31/2008, 2:18:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:08] - Checking for HKLM\...\Winlogon\Notify\tuvurqPG
[05/31/2008, 2:18:08] - Key not found: HKLM\...\Winlogon\Notify\tuvurqPG, continuing.
[05/31/2008, 2:18:08] - BHO 7: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/31/2008, 2:18:08] - BHO 8: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/31/2008, 2:18:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:08] - No filename found. Continuing.
[05/31/2008, 2:18:09] - BHO 9: {C83FC2EA-95FC-4903-8609-CE98207A7753} ()
[05/31/2008, 2:18:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/31/2008, 2:18:09] - Checking for HKLM\...\Winlogon\Notify\jkkKeEVp
[05/31/2008, 2:18:09] - Key not found: HKLM\...\Winlogon\Notify\jkkKeEVp, continuing.
[05/31/2008, 2:18:09] - Finished Searching Browser Helper Objects
[05/31/2008, 2:18:09] - Finishing up...
[05/31/2008, 2:18:09] - A restart is needed.
[05/31/2008, 2:18:16] - Attempting to Restart via STOP error (Blue Screen!) |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 01 Giu 2008 14:03 Oggetto: |
|
|
Hai postato il lg di virtumondebegone.
Riproviamo:
- segui le istruzioni di questo topic per usare MBAM.
- segui le istruzioni di questo topic per postare il log di combofix.
|
|
Top |
|
 |
|
|
Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento Non puoi modificare i tuoi messaggi Non puoi cancellare i tuoi messaggi Non puoi votare nei sondaggi
|
|