Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
Setup di programma ha installato decine di virus
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus
Precedente :: Successivo  
Autore Messaggio
unodipalermo
Eroe
Eroe


Registrato: 31/10/08 01:24
Messaggi: 73

MessaggioInviato: 08 Mar 2009 06:57    Oggetto: Setup di programma ha installato decine di virus Rispondi citando

Credo di avere il pc infestato da molti virus e che xp sia compromesso...tutto ciò in seguito all' avvio di un file di setup scaricato da internet. Ho provota a risolvere il problema con Avira, facendo scansioni online e tramite il comando "sfc/scannow" ma continuo ad avere un sacco di problemi. Non so dove mettere le mani. Il sistema si blocca all' avvio....si blocca se inserisco la scheda PCMCIA o alcuni hard disk esterni, firefox mi reindirizza i siti verso siti porno e commerciali e appaiono pop up a tutto spiano. Spybot e altri programmi non funzionano più...

Questo è il log di Avira che mi ha segnalato una quarantina di infezioni, che gli ho ordinato di rimuovere...

Citazione:

Avira AntiVir Personal
Report file date: sabato 7 marzo 2009 23:14

Scanning for 1288155 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: MARCO-DE26D929F

Version information:
BUILD.DAT : 8.2.0.337 16934 Bytes 18/11/2008 13:05:00
AVSCAN.EXE : 8.1.4.10 315649 Bytes 26/11/2008 14:41:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 13:45:09
ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 13:17:08
ANTIVIR2.VDF : 7.1.2.105 513536 Bytes 03/03/2009 21:37:01
ANTIVIR3.VDF : 7.1.2.135 157696 Bytes 07/03/2009 14:28:17
Engineversion : 8.2.0.105
AEVDF.DLL : 8.1.1.0 106868 Bytes 13/02/2009 13:17:22
AESCRIPT.DLL : 8.1.1.57 356729 Bytes 07/03/2009 14:28:22
AESCN.DLL : 8.1.1.8 127346 Bytes 07/03/2009 14:28:21
AERDL.DLL : 8.1.1.3 438645 Bytes 05/11/2008 13:45:18
AEPACK.DLL : 8.1.3.10 397686 Bytes 07/03/2009 14:28:20
AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26/02/2009 21:36:57
AEHEUR.DLL : 8.1.0.104 1634679 Bytes 07/03/2009 14:28:19
AEHELP.DLL : 8.1.2.2 119158 Bytes 26/02/2009 21:36:55
AEGEN.DLL : 8.1.1.25 336243 Bytes 07/03/2009 14:28:17
AEEMU.DLL : 8.1.0.9 393588 Bytes 05/11/2008 13:45:13
AECORE.DLL : 8.1.6.6 176501 Bytes 17/02/2009 21:36:36
AEBB.DLL : 8.1.0.3 53618 Bytes 05/11/2008 13:45:12
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 05/11/2008 13:45:11
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\programmi\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:, M:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: sabato 7 marzo 2009 23:14

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'NclBCBTSrv.exe' - '1' Module(s) have been scanned
Scan process 'NclMSBTSrv.exe' - '1' Module(s) have been scanned
Scan process 'ServiceLayer.exe' - '1' Module(s) have been scanned
Scan process '7346.tmp' - '1' Module(s) have been scanned
Module is infected -> 'C:\WINDOWS\TEMP\7346.tmp'
Scan process 'Birthday.exe' - '1' Module(s) have been scanned
Scan process 'BTTray.exe' - '1' Module(s) have been scanned
Scan process 'csrssc.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\csrssc.exe'
Scan process 'POPPeeper.exe' - '1' Module(s) have been scanned
Scan process 'PCSuite.exe' - '1' Module(s) have been scanned
Scan process 'RocketDock.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'winlognn.exe' - '1' Module(s) have been scanned
Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
Scan process 'SSMMgr.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'Monitor.exe' - '1' Module(s) have been scanned
Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
Scan process 'TFncKy.exe' - '1' Module(s) have been scanned
Scan process 'vmware-tray.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'UnlockerAssistant.exe' - '1' Module(s) have been scanned
Scan process 'cfp.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'agrsmmsg.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\Windows\lsass.exe'
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'vmware-authd.exe' - '1' Module(s) have been scanned
Scan process 'vmnetdhcp.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'vmnat.exe' - '1' Module(s) have been scanned
Scan process 'TabUserW.exe' - '1' Module(s) have been scanned
Scan process 'vmount2.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'mdm.exe' - '1' Module(s) have been scanned
Scan process 'FolderSizeSvc.exe' - '1' Module(s) have been scanned
Scan process 'cmdagent.exe' - '1' Module(s) have been scanned
Scan process 'CFSvcs.exe' - '1' Module(s) have been scanned
Scan process 'btwdins.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'acs.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Process '7346.tmp' has been terminated
Process 'csrssc.exe' has been terminated
Process 'lsass.exe' has been terminated
C:\WINDOWS\TEMP\7346.tmp
[DETECTION] Contains a recognition pattern of the (harmful) BDS/KeyStart.BC back-door program
[NOTE] The file was deleted!
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\csrssc.exe
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\Windows\lsass.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '4a13f4c8.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK lib.
[NOTE] The file was deleted!

62 processes with 59 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
[WARNING] System error [21]: Periferica non pronta.
Master boot sector HD3
[INFO] No virus was found!
[WARNING] System error [21]: Periferica non pronta.
Master boot sector HD4
[INFO] No virus was found!
[WARNING] System error [21]: Periferica non pronta.
Master boot sector HD5
[INFO] No virus was found!
[WARNING] System error [21]: Periferica non pronta.

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'M:\'
[INFO] No virus was found!

Starting to scan the registry.
C:\WINDOWS\system32\crypts.dll
[DETECTION] Is the TR/Dldr.JLRL Trojan
[NOTE] A backup was created as '4a2bf4f4.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK lib.
[NOTE] The file was deleted!

The registry was scanned ( '66' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\ARK3.tmp
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '49fdf4ea.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK lib.
[NOTE] The file was deleted!
C:\ARK4.tmp
[DETECTION] Is the TR/Dldr.JLRL Trojan
[NOTE] A backup was created as '49fdf4f1.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK lib.
[NOTE] The file was deleted!
C:\jimi.exe
[DETECTION] Is the TR/Boaxxe.F.153 Trojan
[NOTE] A backup was created as '4a1ff510.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\sdogn.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[NOTE] A backup was created as '4a21f512.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\2417099198.exe
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '49e3f574.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\2915067948.exe
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '49e3f579.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\3263.tmp
[DETECTION] Contains a recognition pattern of the (harmful) BDS/KeyStart.BC back-door program
[NOTE] A backup was created as '49e8f572.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\4.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '4a17f56e.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\tmpEC.tmp
[DETECTION] Is the TR/Patched.CK.56 Trojan
[NOTE] A backup was created as '4a22f5b6.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\tmpF1.tmp
[DETECTION] Is the TR/Patched.CK.56 Trojan
[NOTE] A backup was created as '4a22f5b7.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\IXP000.TMP\坜义佄南
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '97fc4cb1.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\4TNLTGMA\4[1].ico
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '49e3f5e9.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\4TNLTGMA\dzzaaanxkx[1].htm
[DETECTION] Is the TR/Tiny.705 Trojan
[NOTE] A backup was created as '4a2cf60a.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\3[1].ico
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[NOTE] A backup was created as '49e3f5f2.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\ccsuper3[1].htm
[DETECTION] Is the TR/Boaxxe.F.153 Trojan
[NOTE] A backup was created as '4a25f5fc.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\cd[1].htm
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\cd[1].htm
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4a0df5fe.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\qmzhr[1].htm
[DETECTION] Is the TR/Tiny.705 Trojan
[NOTE] A backup was created as '498701a3.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\bxyyyyl[1].htm
[DETECTION] Is the TR/Tiny.705 Trojan
[NOTE] A backup was created as '4a2bf64c.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\ccsuper2[1].htm
[DETECTION] Is the TR/Downloader.Gen Trojan
[NOTE] A backup was created as '4a25f638.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\cd[1].htm
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\cd[1].htm
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4a0df639.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\cd[2].htm
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\cd[2].htm
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4a0df63a.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\vrrsfssgt[1].htm
[DETECTION] Is the TR/Tiny.705 Trojan
[NOTE] A backup was created as '4a24f64d.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\725f[1].exe
[DETECTION] Contains a recognition pattern of the (harmful) BDS/KeyStart.BC back-door program
[NOTE] A backup was created as '49e7f60f.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\7[1].ico
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] A backup was created as '49e3f638.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\cclmmmzmna[1].txt
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[NOTE] A backup was created as '4a1ef642.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\ccsuper0[1].htm
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] A backup was created as '4a25f642.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\cd[1].htm
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\cd[1].htm
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4a0df643.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\WINDOWS\system32\sdra64.exe
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\WINDOWS\Temp\862.tmp
[DETECTION] Contains a recognition pattern of the (harmful) BDS/KeyStart.BC back-door program
[NOTE] A backup was created as '49e4fe67.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\WINDOWS\Temp\EC8E9916.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] A backup was created as '49eafe75.qua' ( QUARANTINE )
[NOTE] The file was deleted!
Begin scan in 'D:\'
D:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'M:\' <P2P>


End of the scan: domenica 8 marzo 2009 00:33
Used time: 1:18:49 Hour(s)

The scan has been canceled!

13224 Scanning directories
307683 Files were scanned
36 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
33 files were deleted
0 files were repaired
31 files were moved to quarantine
0 files were renamed
3 Files cannot be scanned
307644 Files not concerned
5548 Archives were scanned
11 Warnings
33 Notes


Questo è il log di HijackThis...

Citazione:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5.52.42, on 08/03/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programmi\COMODO\Firewall\cmdagent.exe
C:\Programmi\FolderSize\FolderSizeSvc.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmi\File comuni\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Programmi\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\COMODO\Firewall\cfp.exe
C:\Programmi\Unlocker\UnlockerAssistant.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\VMware\VMware Workstation\vmware-tray.exe
C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winlognn.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\RocketDock\RocketDock.exe
C:\Programmi\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winlognn.exe
C:\Programmi\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmi\Birthday\Birthday.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Programmi\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\VMware\VMware Converter\vmware-ufad.exe
C:\Programmi\MSN Messenger\usnsvc.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\csrssc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O2 - BHO: C:\WINDOWS\system32\hs3i7jdgfd.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hs3i7jdgfd.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programmi\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Programmi\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programmi\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [vmware-tray] C:\Programmi\VMware\VMware Workstation\vmware-tray.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [Ipizutap] rundll32.exe "C:\WINDOWS\Pxubutehobekeyo.dll",e
O4 - HKCU\..\Run: [RocketDock] "C:\Programmi\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [POP Peeper] "C:\Programmi\POP Peeper\POPPeeper.exe" -min
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winlognn.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\csrssc.exe
O4 - HKLM\..\Policies\Explorer\Run: [Lsass Service] C:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\Windows\lsass.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Birthday (2).lnk = C:\Programmi\Birthday\Birthday.exe
O4 - Startup: ePrompter.lnk = C:\Programmi\ePrompter\ePrompter.exe
O4 - Global Startup: BTTray.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Scarica con Free Download Manager - file://C:\Programmi\Free Download Manager\dllink.htm
O8 - Extra context menu item: Scarica i video con Free Download Manager - file://C:\Programmi\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Scarica selezionati con Free Download Manager - file://C:\Programmi\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Scarica tutto con Free Download Manager - file://C:\Programmi\Free Download Manager\dlall.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1224551816984
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1225720626531
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-1f99dc870e63e3d3.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6E3222BA-C5E8-4075-B1AF-AA8256660EAD}: NameServer = 85.255.112.214,85.255.112.22
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.214,85.255.112.22
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.214,85.255.112.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.214,85.255.112.22
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: crypt - C:\WINDOWS\
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hs3i7jdgfd.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Servizio trasferimento intelligente in background (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: CachemanXP (CachemanXPService) - Outertech - C:\Programmi\CachemanXP\CachemanXP.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Programmi\COMODO\Firewall\cmdagent.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Programmi\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programmi\File comuni\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Programmi\WinPcap\rpcapd.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Programmi\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VMware Converter Service (ufad-p2v) - VMware, Inc. - C:\Programmi\VMware\VMware Converter\vmware-ufad.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Programmi\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Programmi\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Programmi\File comuni\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe

--
End of file - 13185 bytes


A volte mi compare anche questo...

Top
Profilo Invia messaggio privato
lorenaino
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 14/02/09 11:44
Messaggi: 147
Residenza: Sasso Marconi

MessaggioInviato: 08 Mar 2009 08:49    Oggetto: Rispondi citando

ciao,hai provato a fare una scansione con Malwarebytes' Anti-Malware?

http://majorgeeks.com/download.php?det=5756

se non riesci aspetta gli esperti...... Very Happy
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 08 Mar 2009 12:03    Oggetto: Rispondi citando

Ciao unodipalermo Ciao

Fai queste scansioni:
  • Pulisci i files temporanei con
    CCleaner
  • Segui le istruzioni di questo topic per rimuovere gli ADS con Hijackthis.
  • Segui le istruzioni di questo topic per usare MBAM.
  • Segui le istruzioni di questo topic per eseguire combofix.
  • Segui le istruzioni di questo topic per postare il log di HiJackThis.
  • Riferisci con un nuovo messaggio in questa discussione dell'esito: se ci sono stati problemi particolari, ecc. ecc. E riporta:
  • Carica il log di MBAM su WikiSend e posta il Forum Link che ti viene assegnato.
  • Carica il log di Combofix su WikiSend e posta il Forum Link che ti viene assegnato.
  • Carica il log di HiJackThis su WikiSend e posta il Forum Link che ti viene assegnato.
Top
Profilo Invia messaggio privato
unodipalermo
Eroe
Eroe


Registrato: 31/10/08 01:24
Messaggi: 73

MessaggioInviato: 08 Mar 2009 21:06    Oggetto: Rispondi citando

MBAN:
link


combofix primo passaggio: link

combofix secondo passaggio: link

hijackthis:
link
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 09 Mar 2009 01:36    Oggetto: Rispondi citando

Apri il blocco note e mettici queste scritte:
Citazione:
Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ipizutap"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=-
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D17D3807-373F-8220-9CD2-8C1D15DB485A}\InProcServer32*]
"oabfjgephanljojebdgnjkhjafklje"=-

File::
c:\windows\Pxubutehobekeyo.dll
C:\-729293392
c:\windows\Tasks\cacheset.job
c:\windows\Tasks\hdD.job
c:\windows\Tasks\hdJ.job
c:\windows\Tasks\hdK.job
c:\windows\Tasks\hdM.job
c:\windows\Tasks\hdN.job
c:\windows\Tasks\JkDefrag.job

Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:

Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro. Wink
Posta i logs aggiornati di combofix e di hijackthis
scarica e installa la versione Free di SuperAntispyware:;
la configuri come è stato spiegato a un'altro utente in
questa discussione
Top
Profilo Invia messaggio privato
unodipalermo
Eroe
Eroe


Registrato: 31/10/08 01:24
Messaggi: 73

MessaggioInviato: 10 Mar 2009 00:39    Oggetto: Rispondi citando

Allora....è successo il patatrac...

Combofix rieseguito correttamente come mi avevi detto...

Ma quando SuperAntiSpyware ha finito è successo il casino:

1)errore di windows scrittura rimandata non riuscita tutti i dati sono andati persi: il messaggio si riferiva agli hard disk esterni, infatti ho perso i i dati

2)al riavvio xp non saprei come spiegarvelo...si è resettato...tutti gli account sono andati persi (non ci sono proprio più t ranne uno che lui ha impostato di default come se avessi appena installato il sistema

CHe è successo? Weeps
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 10 Mar 2009 10:37    Oggetto: Rispondi citando

E' successo che il sistema si è ripristinato a causa di un errore grave causato sicuramente dal virus.

C'erano delle .dll infette iniettate nei file di sistema come di solito avviene.

Mi dispiace per eventuali dati persi, ma purtroppo è da mettere nel conto quando si ha a che fare con i virus, anche se i PC non reagiscono sempre alla stessa maniere.

Intanto posta, se ancora ce l'hai, i logs di Combofix e Hijackthis e Superantispyware, altrimenti rifai la scansione con Superantispyware e HJT.
Top
Profilo Invia messaggio privato
uomodeighiacci
Dio minore
Dio minore


Registrato: 01/01/09 20:29
Messaggi: 769

MessaggioInviato: 10 Mar 2009 23:05    Oggetto: Rispondi citando

su internet trovi molti programmi free per il recupero dei dati.
Io non saprei consigliarti perchè gli unici 2 che uso nn sono adatti alla tua situazione, ma se cerchi un pò vedrai che i dati li recuperi (almeno in parte)
Top
Profilo Invia messaggio privato
unodipalermo
Eroe
Eroe


Registrato: 31/10/08 01:24
Messaggi: 73

MessaggioInviato: 12 Mar 2009 18:05    Oggetto: Rispondi

Scusate, mala situazione è diventata talmente critica da essere in obbligo di formattare...grazie ugualmente per l' aiuto Smile
Top
Profilo Invia messaggio privato
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus Tutti i fusi orari sono GMT + 2 ore
Pagina 1 di 1

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi