Precedente :: Successivo |
Autore |
Messaggio |
unodipalermo Eroe

Registrato: 31/10/08 01:24 Messaggi: 73
|
Inviato: 08 Mar 2009 06:57 Oggetto: Setup di programma ha installato decine di virus |
|
|
Credo di avere il pc infestato da molti virus e che xp sia compromesso...tutto ciò in seguito all' avvio di un file di setup scaricato da internet. Ho provota a risolvere il problema con Avira, facendo scansioni online e tramite il comando "sfc/scannow" ma continuo ad avere un sacco di problemi. Non so dove mettere le mani. Il sistema si blocca all' avvio....si blocca se inserisco la scheda PCMCIA o alcuni hard disk esterni, firefox mi reindirizza i siti verso siti porno e commerciali e appaiono pop up a tutto spiano. Spybot e altri programmi non funzionano più...
Questo è il log di Avira che mi ha segnalato una quarantina di infezioni, che gli ho ordinato di rimuovere...
Citazione: |
Avira AntiVir Personal
Report file date: sabato 7 marzo 2009 23:14
Scanning for 1288155 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: MARCO-DE26D929F
Version information:
BUILD.DAT : 8.2.0.337 16934 Bytes 18/11/2008 13:05:00
AVSCAN.EXE : 8.1.4.10 315649 Bytes 26/11/2008 14:41:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 13:45:09
ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 13:17:08
ANTIVIR2.VDF : 7.1.2.105 513536 Bytes 03/03/2009 21:37:01
ANTIVIR3.VDF : 7.1.2.135 157696 Bytes 07/03/2009 14:28:17
Engineversion : 8.2.0.105
AEVDF.DLL : 8.1.1.0 106868 Bytes 13/02/2009 13:17:22
AESCRIPT.DLL : 8.1.1.57 356729 Bytes 07/03/2009 14:28:22
AESCN.DLL : 8.1.1.8 127346 Bytes 07/03/2009 14:28:21
AERDL.DLL : 8.1.1.3 438645 Bytes 05/11/2008 13:45:18
AEPACK.DLL : 8.1.3.10 397686 Bytes 07/03/2009 14:28:20
AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26/02/2009 21:36:57
AEHEUR.DLL : 8.1.0.104 1634679 Bytes 07/03/2009 14:28:19
AEHELP.DLL : 8.1.2.2 119158 Bytes 26/02/2009 21:36:55
AEGEN.DLL : 8.1.1.25 336243 Bytes 07/03/2009 14:28:17
AEEMU.DLL : 8.1.0.9 393588 Bytes 05/11/2008 13:45:13
AECORE.DLL : 8.1.6.6 176501 Bytes 17/02/2009 21:36:36
AEBB.DLL : 8.1.0.3 53618 Bytes 05/11/2008 13:45:12
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 05/11/2008 13:45:11
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\programmi\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:, M:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: sabato 7 marzo 2009 23:14
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'NclBCBTSrv.exe' - '1' Module(s) have been scanned
Scan process 'NclMSBTSrv.exe' - '1' Module(s) have been scanned
Scan process 'ServiceLayer.exe' - '1' Module(s) have been scanned
Scan process '7346.tmp' - '1' Module(s) have been scanned
Module is infected -> 'C:\WINDOWS\TEMP\7346.tmp'
Scan process 'Birthday.exe' - '1' Module(s) have been scanned
Scan process 'BTTray.exe' - '1' Module(s) have been scanned
Scan process 'csrssc.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\csrssc.exe'
Scan process 'POPPeeper.exe' - '1' Module(s) have been scanned
Scan process 'PCSuite.exe' - '1' Module(s) have been scanned
Scan process 'RocketDock.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'winlognn.exe' - '1' Module(s) have been scanned
Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
Scan process 'SSMMgr.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'Monitor.exe' - '1' Module(s) have been scanned
Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
Scan process 'TFncKy.exe' - '1' Module(s) have been scanned
Scan process 'vmware-tray.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'UnlockerAssistant.exe' - '1' Module(s) have been scanned
Scan process 'cfp.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'agrsmmsg.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\Windows\lsass.exe'
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'vmware-authd.exe' - '1' Module(s) have been scanned
Scan process 'vmnetdhcp.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'vmnat.exe' - '1' Module(s) have been scanned
Scan process 'TabUserW.exe' - '1' Module(s) have been scanned
Scan process 'vmount2.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'mdm.exe' - '1' Module(s) have been scanned
Scan process 'FolderSizeSvc.exe' - '1' Module(s) have been scanned
Scan process 'cmdagent.exe' - '1' Module(s) have been scanned
Scan process 'CFSvcs.exe' - '1' Module(s) have been scanned
Scan process 'btwdins.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'acs.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Process '7346.tmp' has been terminated
Process 'csrssc.exe' has been terminated
Process 'lsass.exe' has been terminated
C:\WINDOWS\TEMP\7346.tmp
[DETECTION] Contains a recognition pattern of the (harmful) BDS/KeyStart.BC back-door program
[NOTE] The file was deleted!
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\csrssc.exe
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\Windows\lsass.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '4a13f4c8.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK lib.
[NOTE] The file was deleted!
62 processes with 59 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
[WARNING] System error [21]: Periferica non pronta.
Master boot sector HD3
[INFO] No virus was found!
[WARNING] System error [21]: Periferica non pronta.
Master boot sector HD4
[INFO] No virus was found!
[WARNING] System error [21]: Periferica non pronta.
Master boot sector HD5
[INFO] No virus was found!
[WARNING] System error [21]: Periferica non pronta.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'M:\'
[INFO] No virus was found!
Starting to scan the registry.
C:\WINDOWS\system32\crypts.dll
[DETECTION] Is the TR/Dldr.JLRL Trojan
[NOTE] A backup was created as '4a2bf4f4.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK lib.
[NOTE] The file was deleted!
The registry was scanned ( '66' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\ARK3.tmp
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '49fdf4ea.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK lib.
[NOTE] The file was deleted!
C:\ARK4.tmp
[DETECTION] Is the TR/Dldr.JLRL Trojan
[NOTE] A backup was created as '49fdf4f1.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
[NOTE] Attempting to perform action using the ARK lib.
[NOTE] The file was deleted!
C:\jimi.exe
[DETECTION] Is the TR/Boaxxe.F.153 Trojan
[NOTE] A backup was created as '4a1ff510.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\sdogn.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[NOTE] A backup was created as '4a21f512.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\2417099198.exe
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '49e3f574.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\2915067948.exe
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '49e3f579.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\3263.tmp
[DETECTION] Contains a recognition pattern of the (harmful) BDS/KeyStart.BC back-door program
[NOTE] A backup was created as '49e8f572.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\4.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '4a17f56e.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\tmpEC.tmp
[DETECTION] Is the TR/Patched.CK.56 Trojan
[NOTE] A backup was created as '4a22f5b6.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\tmpF1.tmp
[DETECTION] Is the TR/Patched.CK.56 Trojan
[NOTE] A backup was created as '4a22f5b7.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temp\IXP000.TMP\坜义佄南
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '97fc4cb1.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\4TNLTGMA\4[1].ico
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '49e3f5e9.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\4TNLTGMA\dzzaaanxkx[1].htm
[DETECTION] Is the TR/Tiny.705 Trojan
[NOTE] A backup was created as '4a2cf60a.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\3[1].ico
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[NOTE] A backup was created as '49e3f5f2.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\ccsuper3[1].htm
[DETECTION] Is the TR/Boaxxe.F.153 Trojan
[NOTE] A backup was created as '4a25f5fc.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\cd[1].htm
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\cd[1].htm
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4a0df5fe.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EY3PRYVY\qmzhr[1].htm
[DETECTION] Is the TR/Tiny.705 Trojan
[NOTE] A backup was created as '498701a3.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\bxyyyyl[1].htm
[DETECTION] Is the TR/Tiny.705 Trojan
[NOTE] A backup was created as '4a2bf64c.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\ccsuper2[1].htm
[DETECTION] Is the TR/Downloader.Gen Trojan
[NOTE] A backup was created as '4a25f638.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\cd[1].htm
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\cd[1].htm
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4a0df639.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\cd[2].htm
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\cd[2].htm
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4a0df63a.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\SE6R4XM2\vrrsfssgt[1].htm
[DETECTION] Is the TR/Tiny.705 Trojan
[NOTE] A backup was created as '4a24f64d.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\725f[1].exe
[DETECTION] Contains a recognition pattern of the (harmful) BDS/KeyStart.BC back-door program
[NOTE] A backup was created as '49e7f60f.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\7[1].ico
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] A backup was created as '49e3f638.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\cclmmmzmna[1].txt
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[NOTE] A backup was created as '4a1ef642.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\ccsuper0[1].htm
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] A backup was created as '4a25f642.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\cd[1].htm
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\VOXVXNSU\cd[1].htm
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4a0df643.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\WINDOWS\system32\sdra64.exe
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\WINDOWS\Temp\862.tmp
[DETECTION] Contains a recognition pattern of the (harmful) BDS/KeyStart.BC back-door program
[NOTE] A backup was created as '49e4fe67.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\WINDOWS\Temp\EC8E9916.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] A backup was created as '49eafe75.qua' ( QUARANTINE )
[NOTE] The file was deleted!
Begin scan in 'D:\'
D:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'M:\' <P2P>
End of the scan: domenica 8 marzo 2009 00:33
Used time: 1:18:49 Hour(s)
The scan has been canceled!
13224 Scanning directories
307683 Files were scanned
36 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
33 files were deleted
0 files were repaired
31 files were moved to quarantine
0 files were renamed
3 Files cannot be scanned
307644 Files not concerned
5548 Archives were scanned
11 Warnings
33 Notes
|
Questo è il log di HijackThis...
Citazione: |
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5.52.42, on 08/03/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programmi\COMODO\Firewall\cmdagent.exe
C:\Programmi\FolderSize\FolderSizeSvc.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmi\File comuni\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Programmi\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\COMODO\Firewall\cfp.exe
C:\Programmi\Unlocker\UnlockerAssistant.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\VMware\VMware Workstation\vmware-tray.exe
C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winlognn.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\RocketDock\RocketDock.exe
C:\Programmi\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winlognn.exe
C:\Programmi\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmi\Birthday\Birthday.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Programmi\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\VMware\VMware Converter\vmware-ufad.exe
C:\Programmi\MSN Messenger\usnsvc.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\csrssc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O2 - BHO: C:\WINDOWS\system32\hs3i7jdgfd.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hs3i7jdgfd.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programmi\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Programmi\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programmi\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [vmware-tray] C:\Programmi\VMware\VMware Workstation\vmware-tray.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [Ipizutap] rundll32.exe "C:\WINDOWS\Pxubutehobekeyo.dll",e
O4 - HKCU\..\Run: [RocketDock] "C:\Programmi\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [POP Peeper] "C:\Programmi\POP Peeper\POPPeeper.exe" -min
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winlognn.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\csrssc.exe
O4 - HKLM\..\Policies\Explorer\Run: [Lsass Service] C:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\Windows\lsass.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Birthday (2).lnk = C:\Programmi\Birthday\Birthday.exe
O4 - Startup: ePrompter.lnk = C:\Programmi\ePrompter\ePrompter.exe
O4 - Global Startup: BTTray.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Scarica con Free Download Manager - file://C:\Programmi\Free Download Manager\dllink.htm
O8 - Extra context menu item: Scarica i video con Free Download Manager - file://C:\Programmi\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Scarica selezionati con Free Download Manager - file://C:\Programmi\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Scarica tutto con Free Download Manager - file://C:\Programmi\Free Download Manager\dlall.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1224551816984
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1225720626531
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-1f99dc870e63e3d3.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6E3222BA-C5E8-4075-B1AF-AA8256660EAD}: NameServer = 85.255.112.214,85.255.112.22
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.214,85.255.112.22
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.214,85.255.112.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.214,85.255.112.22
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: crypt - C:\WINDOWS\
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hs3i7jdgfd.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Servizio trasferimento intelligente in background (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: CachemanXP (CachemanXPService) - Outertech - C:\Programmi\CachemanXP\CachemanXP.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Programmi\COMODO\Firewall\cmdagent.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Programmi\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programmi\File comuni\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Programmi\WinPcap\rpcapd.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Programmi\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VMware Converter Service (ufad-p2v) - VMware, Inc. - C:\Programmi\VMware\VMware Converter\vmware-ufad.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Programmi\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Programmi\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Programmi\File comuni\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
--
End of file - 13185 bytes
|
A volte mi compare anche questo...
 |
|
Top |
|
 |
lorenaino Eroe in grazia degli dei


Registrato: 14/02/09 11:44 Messaggi: 147 Residenza: Sasso Marconi
|
Inviato: 08 Mar 2009 08:49 Oggetto: |
|
|
ciao,hai provato a fare una scansione con Malwarebytes' Anti-Malware?
http://majorgeeks.com/download.php?det=5756
se non riesci aspetta gli esperti......  |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
Inviato: 08 Mar 2009 12:03 Oggetto: |
|
|
Ciao unodipalermo
Fai queste scansioni:
- Pulisci i files temporanei con
CCleaner
- Segui le istruzioni di questo topic per rimuovere gli ADS con Hijackthis.
- Segui le istruzioni di questo topic per usare MBAM.
- Segui le istruzioni di questo topic per eseguire combofix.
- Segui le istruzioni di questo topic per postare il log di HiJackThis.
- Riferisci con un nuovo messaggio in questa discussione dell'esito: se ci sono stati problemi particolari, ecc. ecc. E riporta:
- Carica il log di MBAM su WikiSend e posta il Forum Link che ti viene assegnato.
- Carica il log di Combofix su WikiSend e posta il Forum Link che ti viene assegnato.
- Carica il log di HiJackThis su WikiSend e posta il Forum Link che ti viene assegnato.
|
|
Top |
|
 |
unodipalermo Eroe

Registrato: 31/10/08 01:24 Messaggi: 73
|
Inviato: 08 Mar 2009 21:06 Oggetto: |
|
|
MBAN:
link
combofix primo passaggio: link
combofix secondo passaggio: link
hijackthis:
link |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
Inviato: 09 Mar 2009 01:36 Oggetto: |
|
|
Apri il blocco note e mettici queste scritte:
Citazione: | Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ipizutap"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=-
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D17D3807-373F-8220-9CD2-8C1D15DB485A}\InProcServer32*]
"oabfjgephanljojebdgnjkhjafklje"=-
File::
c:\windows\Pxubutehobekeyo.dll
C:\-729293392
c:\windows\Tasks\cacheset.job
c:\windows\Tasks\hdD.job
c:\windows\Tasks\hdJ.job
c:\windows\Tasks\hdK.job
c:\windows\Tasks\hdM.job
c:\windows\Tasks\hdN.job
c:\windows\Tasks\JkDefrag.job |
Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:
Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro.
Posta i logs aggiornati di combofix e di hijackthis
scarica e installa la versione Free di SuperAntispyware:;
la configuri come è stato spiegato a un'altro utente in
questa discussione |
|
Top |
|
 |
unodipalermo Eroe

Registrato: 31/10/08 01:24 Messaggi: 73
|
Inviato: 10 Mar 2009 00:39 Oggetto: |
|
|
Allora....è successo il patatrac...
Combofix rieseguito correttamente come mi avevi detto...
Ma quando SuperAntiSpyware ha finito è successo il casino:
1)errore di windows scrittura rimandata non riuscita tutti i dati sono andati persi: il messaggio si riferiva agli hard disk esterni, infatti ho perso i i dati
2)al riavvio xp non saprei come spiegarvelo...si è resettato...tutti gli account sono andati persi (non ci sono proprio più t ranne uno che lui ha impostato di default come se avessi appena installato il sistema
CHe è successo?  |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
Inviato: 10 Mar 2009 10:37 Oggetto: |
|
|
E' successo che il sistema si è ripristinato a causa di un errore grave causato sicuramente dal virus.
C'erano delle .dll infette iniettate nei file di sistema come di solito avviene.
Mi dispiace per eventuali dati persi, ma purtroppo è da mettere nel conto quando si ha a che fare con i virus, anche se i PC non reagiscono sempre alla stessa maniere.
Intanto posta, se ancora ce l'hai, i logs di Combofix e Hijackthis e Superantispyware, altrimenti rifai la scansione con Superantispyware e HJT. |
|
Top |
|
 |
uomodeighiacci Dio minore

Registrato: 01/01/09 20:29 Messaggi: 769
|
Inviato: 10 Mar 2009 23:05 Oggetto: |
|
|
su internet trovi molti programmi free per il recupero dei dati.
Io non saprei consigliarti perchè gli unici 2 che uso nn sono adatti alla tua situazione, ma se cerchi un pò vedrai che i dati li recuperi (almeno in parte) |
|
Top |
|
 |
unodipalermo Eroe

Registrato: 31/10/08 01:24 Messaggi: 73
|
Inviato: 12 Mar 2009 18:05 Oggetto: |
|
|
Scusate, mala situazione è diventata talmente critica da essere in obbligo di formattare...grazie ugualmente per l' aiuto  |
|
Top |
|
 |
|