insane_2k
04-01-2006, 00:19
Ebbene si, è approdato nel mio PC..
Ho 3 hard disk, C (con windows e programmi base), D (programmi e giochi), E (Hd per raccogliere dati).
Curiosamente sto benedetto virus ha corrotto solo gli eseguibili dei dischi D ed E, rendendoli praticamente inutilizzabili.
Ho fatto scan approfonditi con Avast, Nod32, VirIT... qualcosa han trovato, hanno messo in quarantena miliardi di files, hanno **disinfettato** tutto, secondo loro...
Ieri formatto e reinstallo i programmi base.... oggi sto navigando tranquillamente e Nod32 mi avvisa della presenza del Tenga... ovviamente tutti gli eseguibili corrotti nuovamente...
Ora ho disattivato il ripristino di sistema, sono andato in provvisoria e ho fatto girare sia Nod che VirIT... ricerche negative.
Questo è il log di HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 0.14.28, on 04/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NVIDIA~1\Network\Apache Group\Apache2\bin\apache.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Nod32\nod32krn.exe
C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcIp.exe
C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\NVIDIA~1\Network\Apache Group\Apache2\bin\apache.exe
C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcAppFlt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Nod32\nod32kui.exe
C:\PROGRA~1\NVIDIA~1\Network\bin\nTrayFw.exe
C:\Programmi\MessengerPlus\MsgPlus.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\DAEMON Tools\daemon.exe
C:\WINDOWS\VM_STI.EXE
C:\Programmi\iPod\bin\iPodService.exe
C:\PROGRAMMI\VEXPLITE\MONLITE.EXE
C:\Programmi\Athlon64\RMClock.exe
C:\Programmi\SpeedFan\speedfan.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\The Coach\Impostazioni locali\Temp\wzb715\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Nod32\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Programmi\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [nTrayFw] C:\PROGRA~1\NVIDIA~1\Network\bin\nTrayFw.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 300NC PC Camera
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\PROGRAMMI\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [RMClock] C:\Programmi\Athlon64\RMClock.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: SpeedFan.lnk = C:\Programmi\SpeedFan\speedfan.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download Using &BitSpirit - D:\Programmi\BitSpirit\bsurl.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136222068448
O17 - HKLM\System\CCS\Services\Tcpip\..\{403AD33F-C35C-4D08-8232-D5895C1E5B63}: NameServer = 151.99.250.2,194.243.154.82
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1DF8C96-C09C-4C3E-BC4D-7365D4DD5E53}: NameServer = 85.37.17.4 151.99.125.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\PROGRA~1\NVIDIA~1\Network\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Nod32\nod32krn.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Trovo, ad ogni "attacco" del worm, un file chiamato INSTALL.EXE, in D:\, E:\, E:\Mp3
Che posso fare?? :(
Grazie!
Ho 3 hard disk, C (con windows e programmi base), D (programmi e giochi), E (Hd per raccogliere dati).
Curiosamente sto benedetto virus ha corrotto solo gli eseguibili dei dischi D ed E, rendendoli praticamente inutilizzabili.
Ho fatto scan approfonditi con Avast, Nod32, VirIT... qualcosa han trovato, hanno messo in quarantena miliardi di files, hanno **disinfettato** tutto, secondo loro...
Ieri formatto e reinstallo i programmi base.... oggi sto navigando tranquillamente e Nod32 mi avvisa della presenza del Tenga... ovviamente tutti gli eseguibili corrotti nuovamente...
Ora ho disattivato il ripristino di sistema, sono andato in provvisoria e ho fatto girare sia Nod che VirIT... ricerche negative.
Questo è il log di HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 0.14.28, on 04/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NVIDIA~1\Network\Apache Group\Apache2\bin\apache.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Nod32\nod32krn.exe
C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcIp.exe
C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\NVIDIA~1\Network\Apache Group\Apache2\bin\apache.exe
C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcAppFlt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Nod32\nod32kui.exe
C:\PROGRA~1\NVIDIA~1\Network\bin\nTrayFw.exe
C:\Programmi\MessengerPlus\MsgPlus.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\DAEMON Tools\daemon.exe
C:\WINDOWS\VM_STI.EXE
C:\Programmi\iPod\bin\iPodService.exe
C:\PROGRAMMI\VEXPLITE\MONLITE.EXE
C:\Programmi\Athlon64\RMClock.exe
C:\Programmi\SpeedFan\speedfan.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\The Coach\Impostazioni locali\Temp\wzb715\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Nod32\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Programmi\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [nTrayFw] C:\PROGRA~1\NVIDIA~1\Network\bin\nTrayFw.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 300NC PC Camera
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\PROGRAMMI\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [RMClock] C:\Programmi\Athlon64\RMClock.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: SpeedFan.lnk = C:\Programmi\SpeedFan\speedfan.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download Using &BitSpirit - D:\Programmi\BitSpirit\bsurl.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136222068448
O17 - HKLM\System\CCS\Services\Tcpip\..\{403AD33F-C35C-4D08-8232-D5895C1E5B63}: NameServer = 151.99.250.2,194.243.154.82
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1DF8C96-C09C-4C3E-BC4D-7365D4DD5E53}: NameServer = 85.37.17.4 151.99.125.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\PROGRA~1\NVIDIA~1\Network\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Nod32\nod32krn.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\Network\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Trovo, ad ogni "attacco" del worm, un file chiamato INSTALL.EXE, in D:\, E:\, E:\Mp3
Che posso fare?? :(
Grazie!