| 
                 
                
                
                 
                
		 
	
		| Precedente :: Successivo   | 
	 
	
	
		| Autore | 
		Messaggio | 
	 
	
		ballack01 Eroe
  
 
  Registrato: 21/05/08 00:19 Messaggi: 60 Residenza: capriolo(bs)
  | 
		
			
				 Inviato: 16 Giu 2010 01:34    Oggetto: Dubbio mio... | 
				     | 
			 
			
				
  | 
			 
			
				salve...aprendo prima task manager windows ho trovato un programma a me sconosciuto chiamato gm4ie.exe....documentandomi su internet mi è sembrato di capire che sia un malware ma non ne sono sicuro...attendo vostro chiarimento e consigli eventuali...
 
 
Piattaforma: Win NT 5.1 (2600.Service Pack 3)
 
Microsoft Windows XP
 
Numero di serie: 84876-600-9507815-04992
 
Nome computer: OEM-RC6REE3KD71
 
BIOS: KM400  - 42302e31Phoenix - AwardBIOS v6.00PGPhoenix - AwardBIOS v6.00PG 11/04/03
 
CPU: AMD Athlon(tm) XP 2400+
 
Scheda video: VIA/S3G KM400/KN400
 
Monitor: Monitor Plug and Play
 
Memoria: 735 Mb
 
Lingua della tastiera: Italiano (Italia)
 
 
e ora il log di hijackthis:
 
 
Logfile of Trend Micro HijackThis v2.0.2
 
Scan saved at 1.25.46, on 16/06/2010
 
Platform: Windows XP SP3 (WinNT 5.01.2600)
 
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
 
Boot mode: Normal
 
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
 
C:\WINDOWS\system32\winlogon.exe
 
C:\WINDOWS\system32\services.exe
 
C:\WINDOWS\system32\lsass.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\Windows Defender\MsMpEng.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\WINDOWS\Explorer.EXE
 
C:\WINDOWS\system32\ZONELABS\vsmon.exe
 
C:\WINDOWS\system32\spoolsv.exe
 
C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe
 
C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
 
C:\WINDOWS\System32\PAStiSvc.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\Programmi\Generic\USB Card Reader Driver v1.9e3\Disk_Monitor.exe
 
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
 
C:\Programmi\ESET\ESET NOD32 Antivirus\egui.exe
 
C:\WINDOWS\system32\ctfmon.exe
 
C:\Programmi\Messenger\msmsgs.exe
 
C:\WINDOWS\system32\taskmgr.exe
 
C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
 
C:\Programmi\Windows Media Player\wmplayer.exe
 
C:\Programmi\Megaupload\Mega Manager\MegaManager.exe
 
C:\Programmi\Internet Explorer\iexplore.exe
 
C:\Programmi\Internet Explorer\iexplore.exe
 
C:\Programmi\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
 
H:\Setup\HiJackThis.exe
 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.it/
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
 
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Programmi\Megaupload\Mega Manager\MegaIEMn.dll
 
O4 - HKLM\..\Run: [Disk Monitor] C:\Programmi\Generic\USB Card Reader Driver v1.9e3\Disk_Monitor.exe
 
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
 
O4 - HKLM\..\Run: [egui] "C:\Programmi\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
 
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 
O4 - HKCU\..\Run: [GM4IE] C:\Programmi\SocialPlus\gm4ie.exe
 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
 
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{33E448CD-0EE1-4FC6-A400-5F57C8630964}: NameServer = 85.37.17.7 85.38.28.95
 
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Programmi\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
 
O23 - Service: ESET Service (ekrn) - ESET - C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe
 
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
 
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
 
O23 - Service: ServiceLayer - Nokia - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
 
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZONELABS\vsmon.exe
 
 
--
 
End of file - 5555 bytes | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		HackYourMind Mortale pio
  
 
  Registrato: 04/06/10 09:39 Messaggi: 17
 
  | 
		
			
				 Inviato: 16 Giu 2010 12:07    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Per caso usi Greasemonkey for IE ?
 
 
perchè potrebbe essere quella estensione la trovi qui: link | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		R16 Dio maturo
  
  
  Registrato: 07/03/08 22:58 Messaggi: 10129
 
  | 
		
			
				 Inviato: 16 Giu 2010 13:17    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ciao.
 
Quel file,(gm4ie.exe ) è collegato (nel tuo caso) a questo programma: SocialPlus, che a sua volta, è relazionato con Facebook.
 
link
 
link
 
Penso che, lo hai scaricato tu, visto per cosa serve. | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		 | 
	 
 
  
	 
	    
	   | 
	
Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento Non puoi modificare i tuoi messaggi Non puoi cancellare i tuoi messaggi Non puoi votare nei sondaggi
  | 
   
 
  
 
		 |