PDA

View Full Version : Ehm...non riesco neanche a formattare!Che diavolo c'è che non va? [WINXP]


ulthuan
19-07-2008, 15:57
ciao a tutti!
premetto la mia ignoranza sul molte cose che riguardano il computer:)
Cmq sono infetto da qualcosa anzi mi sa anche piu di una!
Non riesco neanche a formattare l'hd e non so se sinceramente questo dipenda da virus o cose del genere.
Cmq ho seguito la guida alla disinfezione per infetti, quindi ecco i miei log.
Vi ringrazio per l'aiuto e confido in una vostra risposta:D
( Ho fatto del mio meglio per allegare tutti i log, spero di non averi fatto nulla di male)


1


a-squared Free - Version 3.5
Last update: 18/07/2008 17.04.17

Impostazioni scansione:

Oggetti: Memoria, Tracce, Cookies, C:\
Archivio scansioni: On
Scientifico: On
ADS Scan: On

Scansione avviata: 18/07/2008 17.04.49

[2016] C:\WINDOWS\svchost.exe rilevati: Trojan-Dropper.Win32.Agent.adn
c:\windows\svchost.exe rilevati: Trace.File.Key Spyware
c:\windows\svchost.exe rilevati: Trace.File.StartPage
Value: HKEY_USERS\S-1-5-21-725345543-562591055-2147250837-1006\software\microsoft\windows\currentversion\run --> quicktime task rilevati: Trace.Registry.CWS.QTTasks
c:\windows\svchost.exe rilevati: Trace.File.Metakodix Stealth Keylogger
C:\Documents and Settings\proprietario\Cookies\[email protected][2].txt rilevati: Trace.TrackingCookie
C:\Documents and Settings\davide\Dati applicazioni\Mozilla\Firefox\Profiles\yi7blkcr.default\cookies.txt:18 rilevati: Trace.TrackingCookie
C:\Documents and Settings\davide\Dati applicazioni\Mozilla\Firefox\Profiles\yi7blkcr.default\cookies.txt:19 rilevati: Trace.TrackingCookie
C:\bsr.exe rilevati: Trojan-Dropper.Win32.Agent.adn
C:\WINDOWS\bsr.exe rilevati: Trojan-Dropper.Win32.Agent.adn
C:\WINDOWS\svchost.exe rilevati: Trojan-Dropper.Win32.Agent.adn
C:\WINDOWS\system32\slpoov.exe rilevati: Trojan-Dropper.Win32.Agent.adn
C:\WINDOWS\system32\sploov.exe rilevati: Trojan-Dropper.Win32.Agent.adn

Scansionati

Files: 196459
Tracce: 488890
Cookies: 48
Processi: 48

Rilevato

Files: 5
Tracce: 4
Cookies: 3
Processi: 1
Chiavi registro: 0

Fine scansione: 18/07/2008 18.51.14
Tempo scansione: 1:46:25

C:\Documents and Settings\proprietario\Cookies\[email protected][2].txt In quarantena Trace.TrackingCookie
C:\Documents and Settings\davide\Dati applicazioni\Mozilla\Firefox\Profiles\yi7blkcr.default\cookies.txt:18 In quarantena Trace.TrackingCookie
C:\Documents and Settings\davide\Dati applicazioni\Mozilla\Firefox\Profiles\yi7blkcr.default\cookies.txt:19 In quarantena Trace.TrackingCookie
c:\windows\svchost.exe In quarantena Trace.File.Metakodix Stealth Keylogger
Value: HKEY_USERS\S-1-5-21-725345543-562591055-2147250837-1006\software\microsoft\windows\currentversion\run --> quicktime task In quarantena Trace.Registry.CWS.QTTasks
c:\windows\svchost.exe In quarantena Trace.File.StartPage
c:\windows\svchost.exe In quarantena Trace.File.Key Spyware
[2016] C:\WINDOWS\svchost.exe In quarantena Trojan-Dropper.Win32.Agent.adn
C:\bsr.exe In quarantena Trojan-Dropper.Win32.Agent.adn
C:\WINDOWS\bsr.exe In quarantena Trojan-Dropper.Win32.Agent.adn
C:\WINDOWS\svchost.exe In quarantena Trojan-Dropper.Win32.Agent.adn
C:\WINDOWS\system32\slpoov.exe In quarantena Trojan-Dropper.Win32.Agent.adn
C:\WINDOWS\system32\sploov.exe In quarantena Trojan-Dropper.Win32.Agent.adn

In quarantena

Files: 5
Tracce: 4
Cookies: 3


2

Scanning Report
Friday, July 18, 2008 19:52:19 - 21:03:22

Computer name: WWW-923B80A9C34
Scanning type: Scan system for malware, rootkits
Target: C:\
Result: 6 malware found
Tracking Cookie (spyware)

* System

Trojan-Spy.HTML.Fraud.gen (virus)

* C:\DOCUMENTS AND SETTINGS\PROPRIETARIO\IMPOSTAZIONI LOCALI\DATI APPLICAZIONI\MICROSOFT\WINDOWS LIVE MAIL\STORAGE FOLDERS\POSTA IN ARRIVO\220B10B5-00000072.EML (Submitted)
* C:\DOCUMENTS AND SETTINGS\PROPRIETARIO\IMPOSTAZIONI LOCALI\DATI APPLICAZIONI\MICROSOFT\WINDOWS LIVE MAIL\STORAGE FOLDERS\POSTA IN ARRIVO\4F6C4554-000000B0.EML (Submitted)
* C:\DOCUMENTS AND SETTINGS\PROPRIETARIO\IMPOSTAZIONI LOCALI\DATI APPLICAZIONI\MICROSOFT\WINDOWS LIVE MAIL\STORAGE FOLDERS\POSTA IN ARRIVO\51DB4727-00000071.EML (Submitted)

Trojan-Spy.Win32.Agent (virus)

* System

Trojan-Spy.Win32.Agent.pi (virus)

* C:\WINDOWS\AUTORUN.INF

Statistics
Scanned:

* Files: 39362
* System: 3578
* Not scanned: 9

Actions:

* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 6
* Submitted: 3

Files not scanned:

* C:\HIBERFIL.SYS
* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
* C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{0F8B64EF-0DC1-4845-9B51-814EFEA5DED2}.BIN





3

link: http://www.mediafire.com/?2kz4xxywdt2




4

link: http://www.mediafire.com/?1y1mudjknbh




5


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14.31.15, on 19/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmi\a-squared Free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\VIA\RAID\raid_tool.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Java\jre1.6.0_05\bin\jucheck.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,userinit.exe
O1 - Hosts: 89.186.66.247 L2authd.lineage2.com
O1 - Hosts: 89.186.66.247 L2testauthd.lineage2.com
O1 - Hosts: 160.128.161.153 bute2ieh.com
O1 - Hosts: 98.142.154.12 catolcwxcav.com
O1 - Hosts: 164.105.11.128 ukjp9mn2.com
O1 - Hosts: 26.61.135.9 vkipqugtsx.com
O1 - Hosts: 74.155.15.232 wvdimh98zhq.com
O1 - Hosts: 21.43.177.216 zobcslgff.com
O1 - Hosts: 217.65.130.117 fullows.com
O1 - Hosts: 7.19.148.180 thumbstring.net
O1 - Hosts: 46.227.219.28 wschooler.com
O1 - Hosts: 237.198.174.168 addwjf6zoy.com
O1 - Hosts: 42.9.237.234 itqoipyqsq.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Class - {974C3236-D34C-4EB9-B586-A0AA22A9E824} - (no file)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Easy SpyRemover] C:\Programmi\Easy SpyRemover\EasySpyRemover.exe /smart
O4 - HKLM\..\Run: [AWMON] "C:\Programmi\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [supgf] "C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\980843.exe"
O4 - HKLM\..\Run: [gdyj1.exe] C:\WINDOWS\TEMP\gdyj1.exe
O4 - HKLM\..\Run: [Bittorrent] C:\WINDOWS\bittorrent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SPYWATCH] C:\Programmi\BulletProofSoft.com\SpywareRemover\SpyWatch.exe /STARTUP
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKLM\..\Policies\Explorer\Run: [1] C:\WINDOWS\svchost.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: sploov.exe.lnk = C:\WINDOWS\system32\slpoov.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmi\VIA\RAID\raid_tool.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: SessoXXX - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\proprietario\Dati applicazioni\SessoXXX[1].exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.webmasterhelp.it
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: CSIScanner - Prevx - C:\Programmi\PrevxCSI\prevxcsi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6995 bytes



6


GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-07-19 14:50:47
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.14 ----

SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwClose [0xF84FB028]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreateKey [0xF84FAFE0]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreatePagingFile [0xF84EEB00]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwEnumerateKey [0xF84EF5DC]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwEnumerateValueKey [0xF84FB120]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenFile [0xF84EEB40]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenKey [0xF84FAFA4]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwQueryKey [0xF84EF5FC]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwQueryValueKey [0xF84FB076]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwSetSystemPowerState [0xF84FA550]

---- Devices - GMER 1.0.14 ----

Device \FileSystem\Ntfs \Ntfs 82333C58

AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \Driver\Cdrom \Device\CdRom0 820A1730
Device \FileSystem\Rdbss \Device\FsWrap 81F47458
Device \Driver\atapi \Device\Ide\IdePort0 820A1B38
Device \Driver\atapi \Device\Ide\IdePort1 820A1B38
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 820A1B38
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 820A1B38
Device \Driver\Cdrom \Device\CdRom1 820A1730
Device \Driver\Cdrom \Device\CdRom2 820A1730
Device \FileSystem\Srv \Device\LanmanServer 81D66208
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 81F3E5F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 81F3E5F0
Device \FileSystem\Npfs \Device\NamedPipe 81F67408
Device \FileSystem\Msfs \Device\Mailslot 82066200
Device \Driver\a347scsi \Device\Scsi\a347scsi1 8208BD38
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 8208BD38
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 821421D0
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 821421D0
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 821421D0
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 821421D0
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 821421D0
Device \FileSystem\Cdfs \Cdfs 81F3F8F0

---- Modules - GMER 1.0.14 ----

Module _________ F8451000-F8469000 (98304 bytes)

---- Services - GMER 1.0.14 ----

Service C:\Programmi\File comuni\System\dGs.exe (*** hidden *** ) [AUTO] NetYbu <-- ROOTKIT !!!

---- Registry - GMER 1.0.14 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej40 0x17 0x3C 0x72 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej41 0xCE 0x3C 0x72 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej42 0xCE 0x3C 0x72 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej43 0xCE 0x3C 0x72 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej44 0xCE 0x3C 0x72 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu@Type 16
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu@ImagePath "C:\Programmi\File comuni\System\dGs.exe"
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu@DisplayName NetYbu
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu@ObjectName .\pxcIuUYGKA
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu@Description Gestisce la configurazione di rete registrando e aggiornando indirizzi IP e nomi DNS.
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetYbu\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu@Type 16
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu@ImagePath "C:\Programmi\File comuni\System\dGs.exe"
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu@DisplayName NetYbu
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu@ObjectName .\pxcIuUYGKA
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu@Description Gestisce la configurazione di rete registrando e aggiornando indirizzi IP e nomi DNS.
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu\Security
Reg HKLM\SYSTEM\ControlSet002\Services\NetYbu\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}@DisplayName Alcohol 120%
Reg HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6@ProductName Alcohol 120%

---- Files - GMER 1.0.14 ----

File C:\Documents and Settings\proprietario\Impostazioni locali\Temporary Internet Files\Content.IE5\4HS7KRKR\CAQ7C9OP.0&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_java=true 1167 bytes
File C:\Documents and Settings\proprietario\Impostazioni locali\Temporary Internet Files\Content.IE5\QDCJU565\CA59ZF28.0&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_java=true 1676 bytes

---- EOF - GMER 1.0.14 ----





7

link: http://www.mediafire.com/?045b2ttr2dv

Chill-Out
19-07-2008, 17:07
Ciao e benvenuto sul forum di HWU, vediamo se possibile di recuperare questa situazione abbastanza compromessa, innazitutto confermami di aver disabilitato il ripristino configurazione sistema, fatta pulizia sia con ATF Cleaner che ADS Scanner

Procedi così:

1 -Riesegui Gmer seleziona col tasto dx mouse il servizio in rosso identificato da Gmer come Rootkit ovvero:

Service C:\Programmi\File comuni\System\dGs.exe (*** hidden *** ) [AUTO] NetYbu <-- ROOTKIT !!!


clicca su DELETE SERVICE

2 - Esegui HijackThis - clicca su Do a system scan only e metti il segno di spunta a sx delle sottoindicate voci:


O1 - Hosts: 160.128.161.153 bute2ieh.com
O1 - Hosts: 98.142.154.12 catolcwxcav.com
O1 - Hosts: 164.105.11.128 ukjp9mn2.com
O1 - Hosts: 26.61.135.9 vkipqugtsx.com
O1 - Hosts: 74.155.15.232 wvdimh98zhq.com
O1 - Hosts: 21.43.177.216 zobcslgff.com
O1 - Hosts: 217.65.130.117 fullows.com
O1 - Hosts: 7.19.148.180 thumbstring.net
O1 - Hosts: 46.227.219.28 wschooler.com
O1 - Hosts: 237.198.174.168 addwjf6zoy.com
O1 - Hosts: 42.9.237.234 itqoipyqsq.com
O2 - BHO: Class - {974C3236-D34C-4EB9-B586-A0AA22A9E824} - (no file)
O4 - HKLM\..\Run: [Easy SpyRemover] C:\Programmi\Easy SpyRemover\EasySpyRemover.exe /smart
O4 - HKLM\..\Run: [supgf] "C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\980843.exe"
O4 - HKLM\..\Run: [gdyj1.exe] C:\WINDOWS\TEMP\gdyj1.exe
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKLM\..\Policies\Explorer\Run: [1] C:\WINDOWS\svchost.exe
O4 - Startup: sploov.exe.lnk = C:\WINDOWS\system32\slpoov.exe
O9 - Extra button: SessoXXX - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\proprietario\Dati applicazioni\SessoXXX[1].exe (file missing)

clicca su Fix checked

3 - Scarica Avenger da qui http://swandog46.geekstogo.com/avenger2/download.php scompatta l'archivio compresso, avvia Avenger copia ed incolla il seguente script (tutto quello che è all'interno del Quote) nel box bianco

Files to delete:
C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\980843.exe
C:\WINDOWS\TEMP\gdyj1.exe
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\slpoov.exe

clicca su execute e poi su Ok al termine il Pc si dovrebbe riavviare se no riavvia tu manualmente, allega il log che trovi in C:\Avenger.txt

4 - Fai girare questo tool
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Doppio click su combofix.exe e segui le istruzioni
Allegare il log C:\combofix.txt
N.B.: Durante la scansione verranno creati alcuni file sul desktop e poi eliminati - spariranno tutte le icone del desktop - il firewall potrebbe avvisare che verranno rimossi alcuni driver (consentire)
ComboFix deve essere eseguito a macchina dedicata - disconnessi dalla rete, disabilitando momentaneamente i realtime dei software di sicurezza

Riepilogo log da allegare
Nuovo log di Gmer
Nuovo log di HijackThis
Log di Avenger
log di ComboFix

xcdegasp
19-07-2008, 18:24
qui c'è dalavoricchiare parecchio mi sa' :(

ulthuan
19-07-2008, 20:33
E rieccomi qui!
Allora ti confermo di aver disabilitato il ripristino configurazione sistema e di aver avviato ATF Cleaner e ADS scanner.
Ho fatto tutto quello che mi hai detto, l'unica cosa che mi è rimasta un pò strana è stato che quando ho provato a cancellare il file con Gmer alla fine mi ha detto impossibile trovare il file Service C:\Programmi\File comuni\System\dGs.exe (*** hidden *** ) [AUTO] NetYbu <-- ROOTKIT !!!

Però devo dire che mi sembra che nella lista non ci sia piu!

Cmq ti allego i log così mi dici com'è andata:D
Grazie di tutto sei stato davvero gentile!

1


GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-07-19 21:25:23
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.14 ----

SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwClose [0xF84FB028]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreateKey [0xF84FAFE0]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreatePagingFile [0xF84EEB00]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwEnumerateKey [0xF84EF5DC]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwEnumerateValueKey [0xF84FB120]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenFile [0xF84EEB40]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenKey [0xF84FAFA4]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwQueryKey [0xF84EF5FC]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwQueryValueKey [0xF84FB076]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwSetSystemPowerState [0xF84FA550]

---- Kernel code sections - GMER 1.0.14 ----

? Combo-Fix.sys Impossibile trovare il file specificato. !
? C:\ComboFix\catchme.sys Impossibile trovare il file specificato. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS Impossibile trovare il file specificato. !

---- Devices - GMER 1.0.14 ----

Device \FileSystem\Ntfs \Ntfs 8238D878

AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \Driver\Cdrom \Device\CdRom0 81EEF6D8
Device \FileSystem\Rdbss \Device\FsWrap 81CB9480
Device \Driver\atapi \Device\Ide\IdePort0 81EEF7E0
Device \Driver\atapi \Device\Ide\IdePort1 81EEF7E0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 81EEF7E0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 81EEF7E0
Device \Driver\Cdrom \Device\CdRom1 81EEF6D8
Device \Driver\Cdrom \Device\CdRom2 81EEF6D8
Device \FileSystem\Srv \Device\LanmanServer 81E413E0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 81E7AA08
Device \FileSystem\MRxSmb \Device\LanmanRedirector 81E7AA08
Device \FileSystem\Npfs \Device\NamedPipe 81E9C2F8
Device \FileSystem\Msfs \Device\Mailslot 82138EA8
Device \Driver\a347scsi \Device\Scsi\a347scsi1 81EBDF00
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 81EBDF00
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 81EA01A0
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 81EA01A0
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 81EA01A0
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 81EA01A0
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 81EA01A0
Device \FileSystem\Cdfs \Cdfs 82071B80

---- Modules - GMER 1.0.14 ----

Module _________ F8451000-F8469000 (98304 bytes)

---- Registry - GMER 1.0.14 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej40 0xEC 0x86 0xF8 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej41 0x35 0x86 0xF8 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej42 0x35 0x86 0xF8 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej43 0x35 0x86 0xF8 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40@ljej44 0x35 0x86 0xF8 0xCA ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}@DisplayName Alcohol 120%
Reg HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6@ProductName Alcohol 120%

---- EOF - GMER 1.0.14 ----





2


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21.25.42, on 19/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmi\a-squared Free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\VIA\RAID\raid_tool.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\WINDOWS\explorer.exe
C:\Programmi\Java\jre1.6.0_05\bin\jucheck.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmi\VIA\RAID\raid_tool.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.webmasterhelp.it
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: CSIScanner - Prevx - C:\Programmi\PrevxCSI\prevxcsi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 5636 bytes





3


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\980843.exe" not found!
Deletion of file "C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\980843.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\TEMP\gdyj1.exe" not found!
Deletion of file "C:\WINDOWS\TEMP\gdyj1.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\kavo.exe" not found!
Deletion of file "C:\WINDOWS\system32\kavo.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\svchost.exe" not found!
Deletion of file "C:\WINDOWS\svchost.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\slpoov.exe" not found!
Deletion of file "C:\WINDOWS\system32\slpoov.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.





4


ComboFix 08-07-18.5 - proprietario 2008-07-19 20.30.10.1 - NTFSx86
Eseguito da: C:\Documents and Settings\proprietario\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
C:\Documents and Settings\davide\ravmonlog
C:\Documents and Settings\proprietario\Impostazioni locali\Dati applicazioni\fpvandm.dat
C:\Documents and Settings\proprietario\Impostazioni locali\Dati applicazioni\fpvandm_nav.dat
C:\Documents and Settings\proprietario\Impostazioni locali\Dati applicazioni\fpvandm_navps.dat
C:\Documents and Settings\proprietario\ravmonlog
C:\Programmi\BulletProofSoft.com
C:\WINDOWS\clear.bat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_WINDOWS_LOG


((((((((((((((((((((((((( Files Creati Da 2008-06-19 al 2008-07-19 )))))))))))))))))))))))))))))))))))
.

2008-07-19 14:32 . 2008-07-19 18:45 250 --a------ C:\WINDOWS\gmer.ini
2008-07-19 14:30 . 2008-07-19 14:30 <DIR> d-------- C:\Programmi\Trend Micro
2008-07-18 21:09 . 2008-07-18 21:09 <DIR> d-------- C:\Documents and Settings\proprietario\DoctorWeb
2008-07-18 19:46 . 2008-07-18 19:46 <DIR> d-------- C:\fsaua.data
2008-07-18 17:01 . 2008-07-18 18:51 <DIR> d-------- C:\Programmi\a-squared Free
2008-07-18 16:43 . 2008-07-18 16:43 <DIR> d-------- C:\Programmi\Pointstone
2008-07-17 19:37 . 2008-07-17 19:37 <DIR> d-------- C:\Programmi\Microsoft Silverlight
2008-07-17 15:19 . 2008-07-17 15:19 <DIR> d-------- C:\Programmi\PrevxCSI
2008-07-17 15:19 . 2008-07-19 15:59 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\PrevxCSI
2008-07-17 15:19 . 2008-07-17 15:19 17,408 --a------ C:\WINDOWS\system32\drivers\pxark.sys
2008-07-10 17:31 . 2008-07-12 12:12 <DIR> d-------- C:\Programmi\Uniblue
2008-07-10 17:13 . 2008-07-12 12:13 <DIR> d-------- C:\Documents and Settings\proprietario\Dati applicazioni\Uniblue
2008-06-27 12:07 . 2008-06-27 12:07 <DIR> d--h----- C:\WINDOWS\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 14:02 --------- d-----w C:\Documents and Settings\davide\Dati applicazioni\AVG7
2008-07-19 14:19 --------- d-----w C:\Programmi\AdunanzA
2008-07-19 12:15 --------- d-----w C:\Documents and Settings\proprietario\Dati applicazioni\AVG7
2008-06-03 17:46 --------- d-----w C:\Programmi\LeechFTP
2007-12-28 17:35 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
2007-10-05 09:11 126,976 ----a-w C:\Documents and Settings\proprietario\(null)C89B5036.DLL
2007-07-30 14:48 299,008 ----a-w C:\Documents and Settings\proprietario\(null)D396E945.DLL
2007-07-04 18:45 113,054 ----a-w C:\Documents and Settings\proprietario\(null)DA5BB534.DLL
2007-06-02 11:52 299,008 ----a-w C:\Documents and Settings\proprietario\(null)ED9C7EC.DLL
2007-05-30 00:56 299,008 ----a-w C:\Documents and Settings\proprietario\(null)569D8CA6.DLL
2007-05-10 12:10 299,008 ----a-w C:\Documents and Settings\proprietario\(null)69386E6.DLL
2007-04-30 15:30 35,072 ----a-w C:\Documents and Settings\proprietario\Dati applicazioni\GDIPFONTCACHEV1.DAT
2007-03-17 12:50 126,976 ----a-w C:\Documents and Settings\proprietario\(null)CEC512E.DLL
2007-01-30 13:03 299,008 ----a-w C:\Documents and Settings\proprietario\(null)40DB9E0.DLL
2006-12-06 17:59 299,008 ----a-w C:\Documents and Settings\proprietario\(null)B3268B1.DLL
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:39 15360]
"SpybotSD TeaTimer"="C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
"updateMgr"="C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]
"Uniblue RegistryBooster 2"="C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-05-16 10:18 1856544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-11 13:47 7311360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-11 13:47 86016]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-17 10:34 579584]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2007-10-19 21:16 286720]
"nwiz"="nwiz.exe" [2005-11-11 13:47 1519616 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 16:39 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-29 22:16 219136]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
VIA RAID TOOL.lnk - C:\Programmi\VIA\RAID\raid_tool.exe [2006-05-04 15:23:34 565248]
WinZip Quick Pick.lnk - C:\Programmi\WinZip\WZQKPICK.EXE [2006-05-04 15:35:35 106560]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"C:\\WINDOWS\\system32\\svchost.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avginet.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\kav\\kav7.0\\english\\setup.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\LeechFTP\\Leechftp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14973:TCP"= 14973:TCP:NortonAV
"15706:TCP"= 15706:TCP:NortonAV
"13150:TCP"= 13150:TCP:NortonAV
"18873:TCP"= 18873:TCP:NortonAV

R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-07-17 15:19]
R2 CSIScanner;CSIScanner;C:\Programmi\PrevxCSI\prevxcsi.exe [2008-07-17 15:19]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - m6dqm2vd.exe
\Shell\explore\Command - m6dqm2vd.exe
\Shell\open\Command - m6dqm2vd.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\Auto\command - G:\bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8030e72d-1b69-11dd-843b-00138f2c6cd4}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bsr.exe
\Shell\´ò¿ª\command - G:\bsr.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1d8d57f-f3e6-11da-bcc7-00138f2c6cd4}]
\Shell\AutoRun\command - H:\m6dqm2vd.exe
\Shell\explore\Command - H:\m6dqm2vd.exe
\Shell\open\Command - H:\m6dqm2vd.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb92b898-3564-11dd-8484-00138f2c6cd4}]
\Shell\AutoRun\command - setup.exe
.
Contenuto della cartella 'Scheduled Tasks'
"2008-07-19 18:00:00 C:\WINDOWS\Tasks\A07F675891C4E530.job"
- c:\docume~1\propri~1\datiap~1\gpl1ac~1\IsoSeekMedia.exe
"2008-07-12 10:12:37 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Programmi\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-07-12 10:12:37 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Programmi\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-07-12 10:10:48 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Programmi\Uniblue\SpyEraser\SpyEraser.exe
.
- - - - ORFÇOS REMOVIDOS - - - -

HKCU-Run-SPYWATCH - C:\Programmi\BulletProofSoft.com\SpywareRemover\SpyWatch.exe
HKLM-Run-AWMON - C:\Programmi\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
HKLM-Run-Bittorrent - C:\WINDOWS\bittorrent.exe
HKLM-Run-Cmaudio - cmicnfg.cpl


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-19 20:34:22
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmi\a-squared Free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Ora fine scansione: 2008-07-19 20:37:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-19 18:37:54

Pre-Run: 39,046,721,536 byte disponibili
Post-Run: 39,065,370,624 byte disponibili

160 --- E O F --- 2007-12-16 11:56:00

wjmat
20-07-2008, 13:50
Lancia HiJackThis → Do a system scan and save a logfile → Carica il nuovo log
_________________________________________________________________________________________
Tutte le eventuali voci O4 fixate non cancellano i programmi ma semplicemente evitano che questi partano in automatico inutilmente, rallentando l'avvio del sistema.
Di default segnalo sempre i programmi di messaggistica, ma se li ritieni strettamente necessari non fixarli.
Le eventuali voci O16 dovranno essere fixate con IE chiuso.
Eventuali voci che ti segnalo, che invece hai impostato tu o che comunque conosci e provengono da fonti sicure, lasciale se le ritieni importanti.
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE


posta anche un nuovo log log si sysinspector

hai in giro anche chiavette o dischi esterni?

ulthuan
20-07-2008, 14:50
eccomi,
ed ecco il log che mi hai chiesto!

Però non ho capito cosa devo fare con quelle stringhe...

Per quanto riguarda hd esterni e chiavette si ne ho (un hd da 500 gb e un mp3) però ancora non li ho collegati perchè so che sono infetti; posso attuare la stessa procedura di disinfezione per infetti?

Grazie ancora:)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15.43.01, on 20/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\a-squared Free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\Programmi\VIA\RAID\raid_tool.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\Programmi\Java\jre1.6.0_05\bin\jucheck.exe
C:\WINDOWS\system32\winlogon.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-21-725345543-562591055-2147250837-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'davide')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmi\VIA\RAID\raid_tool.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.webmasterhelp.it
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: CSIScanner - Prevx - C:\Programmi\PrevxCSI\prevxcsi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 5864 bytes




2

link: http://www.mediafire.com/?t0rcemttzbx

xcdegasp
20-07-2008, 16:59
Fixa:

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-21-725345543-562591055-2147250837-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'davide')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE


dopo di che dovresti aggiornare il software del tuo pc e per farlo in semplicità puoi andare al link http://secunia.com/software_inspector/ e scansionare online il pc, alla fine della scansione ti mostrerà tutti i programmi critici che sono da aggiornare.
nel caso della java ricordati che poi dovvrai disinstallare la versione 1.6.0_05 e potresti valutare la sostituzione di AcrobatReader con il più performante, legegro, veloce e sicuro foxitreader (http://www.foxitsoftware.com/pdf/rd_intro.php)

ulthuan
20-07-2008, 21:24
eccomi,
ho fixato quello che mi hai detto però non ho trovato :

O4 - HKUS\S-1-5-21-725345543-562591055-2147250837-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'davide')

questo è il log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.14.44, on 20/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmi\a-squared Free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\Programmi\VIA\RAID\raid_tool.exe
C:\Programmi\Windows Live\Messenger\msnmsgr.exe
C:\Programmi\Java\jre1.6.0_05\bin\jucheck.exe
C:\Programmi\Windows Live\Messenger\usnsvc.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmi\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.webmasterhelp.it
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: CSIScanner - Prevx - C:\Programmi\PrevxCSI\prevxcsi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 5508 bytes





adesso sono andato su quel sito e mi ha detto che ho 21 programmi da aggiornare, compreso windows però, che non posso aggiornare in quanto mi si istallerebbe AWG.

Ma gli altri programmi li devo aggiornare manualmente?
Cioè cercare l'aggiornamento da qualche parte ecc?

PS=in una risposta precedente ho chiesto se devo trattare allo stesso modo l'hd esterno e l'mp3 che so per certo essere infettati, cosa devo fare?:D

grazie ancora siete proprio gentilissimi!

wjmat
20-07-2008, 21:40
da un log di combo ci sono riferimenti ai dischi esterni... per il momento non collegarli

che sarebbe awg?? wga??

aggiorna manualmente i programmi trovati obsoleti ed in particolare IE alla 7

Chill-Out
20-07-2008, 23:50
Apri il Blocco Note copia e incolla queste righe:


Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8030e72d-1b69-11dd-843b-00138f2c6cd4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1d8d57f-f3e6-11da-bcc7-00138f2c6cd4}]

Salva il file sul Desktop come CFScript.txt

Trascina il file appena creato ovvero CFScript.txt sull'icona di ComboFix

al termine il PC si dovrebbe ravviare, eventualmente riavvia tu manualmente, allega il log che trovi in C:\ComboFix.txt

ComboFix deve essere eseguito a macchina dedicata - disconnessi dalla rete, disabilitando momentaneamente i realtime dei software di sicurezza

Questo O15 - Trusted Zone: hxxp://www.webmasterhelp.it da dove è uscito? Fixalo

Windows Genuine Advantage (WGA) è un programma creato per il sistema operativo Microsoft Windows che permette di verificare la chiave Product Key, se il tuo sistema è regolarmente licenziato non ci sono problemi

Il discorso chiavette USB, lettore MP3 lo affrontiamo poi :)

ulthuan
21-07-2008, 15:14
ciao rieccomi,
si conosco già WGA ( ho sbagliato a scriverlo) è per questo che so di non poter fare l'aggiornamento ne di win ne di IE.
Ho fatto gli aggiornamenti di tutto tranne win e IE ( per WGA ) e di winzip perchè a pagamento.

Cmq ecco il nuovo log di ComboFix:


ComboFix 08-07-18.5 - proprietario 2008-07-21 16.03.20.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.203 [GMT 2:00]
Eseguito da: C:\Documents and Settings\proprietario\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\proprietario\Desktop\CFScript.txt
* Creato nuovo punto di ripristino

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((( Files Creati Da 2008-06-21 al 2008-07-21 )))))))))))))))))))))))))))))))))))
.

2008-07-21 15:37 . 2008-07-21 15:37 <DIR> d-------- C:\Programmi\Apple Software Update
2008-07-21 15:37 . 2008-07-21 15:37 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Apple
2008-07-21 15:33 . 2008-07-21 15:33 <DIR> d-------- C:\Programmi\File comuni\Adobe AIR
2008-07-19 14:32 . 2008-07-19 21:18 250 --a------ C:\WINDOWS\gmer.ini
2008-07-19 14:30 . 2008-07-19 14:30 <DIR> d-------- C:\Programmi\Trend Micro
2008-07-18 21:09 . 2008-07-18 21:09 <DIR> d-------- C:\Documents and Settings\proprietario\DoctorWeb
2008-07-18 19:46 . 2008-07-18 19:46 <DIR> d-------- C:\fsaua.data
2008-07-18 17:01 . 2008-07-18 18:51 <DIR> d-------- C:\Programmi\a-squared Free
2008-07-18 16:43 . 2008-07-18 16:43 <DIR> d-------- C:\Programmi\Pointstone
2008-07-17 19:37 . 2008-07-17 19:37 <DIR> d-------- C:\Programmi\Microsoft Silverlight
2008-07-17 15:19 . 2008-07-17 15:19 <DIR> d-------- C:\Programmi\PrevxCSI
2008-07-17 15:19 . 2008-07-21 15:11 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\PrevxCSI
2008-07-17 15:19 . 2008-07-17 15:19 17,408 --a------ C:\WINDOWS\system32\drivers\pxark.sys
2008-07-10 17:31 . 2008-07-12 12:12 <DIR> d-------- C:\Programmi\Uniblue
2008-07-10 17:13 . 2008-07-12 12:13 <DIR> d-------- C:\Documents and Settings\proprietario\Dati applicazioni\Uniblue
2008-06-27 12:07 . 2008-06-27 12:07 <DIR> d--h----- C:\WINDOWS\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 14:02 --------- d-----w C:\Documents and Settings\davide\Dati applicazioni\AVG7
2008-07-21 13:38 --------- d-----w C:\Programmi\QuickTime
2008-07-21 13:38 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer
2008-07-21 13:18 --------- d-----w C:\Programmi\Java
2008-07-21 13:07 --------- d-----w C:\Programmi\AdunanzA
2008-07-19 12:15 --------- d-----w C:\Documents and Settings\proprietario\Dati applicazioni\AVG7
2008-06-03 17:46 --------- d-----w C:\Programmi\LeechFTP
2007-12-28 17:35 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
2007-10-05 09:11 126,976 ----a-w C:\Documents and Settings\proprietario\(null)C89B5036.DLL
2007-07-30 14:48 299,008 ----a-w C:\Documents and Settings\proprietario\(null)D396E945.DLL
2007-07-04 18:45 113,054 ----a-w C:\Documents and Settings\proprietario\(null)DA5BB534.DLL
2007-06-02 11:52 299,008 ----a-w C:\Documents and Settings\proprietario\(null)ED9C7EC.DLL
2007-05-30 00:56 299,008 ----a-w C:\Documents and Settings\proprietario\(null)569D8CA6.DLL
2007-05-10 12:10 299,008 ----a-w C:\Documents and Settings\proprietario\(null)69386E6.DLL
2007-04-30 15:30 35,072 ----a-w C:\Documents and Settings\proprietario\Dati applicazioni\GDIPFONTCACHEV1.DAT
2007-03-17 12:50 126,976 ----a-w C:\Documents and Settings\proprietario\(null)CEC512E.DLL
2007-01-30 13:03 299,008 ----a-w C:\Documents and Settings\proprietario\(null)40DB9E0.DLL
2006-12-06 17:59 299,008 ----a-w C:\Documents and Settings\proprietario\(null)B3268B1.DLL
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.

((((((((((((((((((((((((((((( snapshot@2008-07-19_20.37.44.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-21 13:37:30 27,136 ----a-r C:\WINDOWS\Installer\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}\AppleSoftwareUpdateIco.exe
+ 2007-12-12 13:06:42 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
+ 2008-07-21 13:43:06 2,108 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{4803BEED-3BE0-4E8C-8D66-EBE06F6A8AFE}.bin
- 2008-02-22 00:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-09 23:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2008-02-22 00:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-09 23:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2008-02-22 01:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 00:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-03-25 02:32:44 218,496 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
+ 2008-07-21 13:48:57 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2007-07-30 17:18:34 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
+ 2006-12-01 20:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 20:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 20:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:39 15360]
"SpybotSD TeaTimer"="C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
"Uniblue RegistryBooster 2"="C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-05-16 10:18 1856544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-11 13:47 7311360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-11 13:47 86016]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-17 10:34 579584]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"QuickTime Task"="C:\Programmi\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"nwiz"="nwiz.exe" [2005-11-11 13:47 1519616 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 16:39 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-29 22:16 219136]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
VIA RAID TOOL.lnk - C:\Programmi\VIA\RAID\raid_tool.exe [2006-05-04 15:23:34 565248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"C:\\WINDOWS\\system32\\svchost.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avginet.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\kav\\kav7.0\\english\\setup.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\LeechFTP\\Leechftp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14973:TCP"= 14973:TCP:NortonAV
"15706:TCP"= 15706:TCP:NortonAV
"13150:TCP"= 13150:TCP:NortonAV
"18873:TCP"= 18873:TCP:NortonAV

R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-07-17 15:19]
R2 CSIScanner;CSIScanner;C:\Programmi\PrevxCSI\prevxcsi.exe [2008-07-17 15:19]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb92b898-3564-11dd-8484-00138f2c6cd4}]
\Shell\AutoRun\command - setup.exe

*Newly Created Service* - CATCHME
.
Contenuto della cartella 'Scheduled Tasks'
"2008-07-21 14:00:00 C:\WINDOWS\Tasks\A07F675891C4E530.job"
- c:\docume~1\propri~1\datiap~1\gpl1ac~1\IsoSeekMedia.exe
"2008-07-21 13:37:29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmi\Apple Software Update\SoftwareUpdate.exe
"2008-07-12 10:12:37 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Programmi\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-07-12 10:12:37 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Programmi\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-07-12 10:10:48 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Programmi\Uniblue\SpyEraser\SpyEraser.exe
.
- - - - ORFÃOS REMOVIDOS - - - -

HKCU-Run-updateMgr - C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-21 16:05:59
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-07-21 16:07:16
ComboFix-quarantined-files.txt 2008-07-21 14:06:47
ComboFix2.txt 2008-07-19 18:37:58

Pre-Run: 37,480,730,624 byte disponibili
Post-Run: 37,579,407,360 byte disponibili

141 --- E O F --- 2007-12-16 11:56:00





si si un passetto per volta:D
Chill-out sei molto gentile (anche gli altri ovviamente:D)

Chill-Out
23-07-2008, 21:34
Apri il Blocco Note copia e incolla queste righe:


[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb92b898-3564-11dd-8484-00138f2c6cd4}]
\Shell\AutoRun\command - setup.exe

Salva il file sul Desktop come CFScript.txt

Trascina il file appena creato ovvero CFScript.txt sull'icona di ComboFix

al termine il PC si dovrebbe ravviare, eventualmente riavvia tu manualmente, allega il log che trovi in C:\ComboFix.txt

ComboFix deve essere eseguito a macchina dedicata - disconnessi dalla rete, disabilitando momentaneamente i realtime dei software di sicurezza

Per quanto concerne il discorso chiavette USB, lettore MP3 etc...devi disabilitare la riproduzione automatica quindi:

Start → Esegui → digita gpedit.msc (invio) → Configurazione computer → Modelli amministrativi → Sistema → Nella finestra di destra scendi e doppio click su Disattiva riproduzione automatica → Seleziona Attivata → Nella tendina che si accende scegli Tutte le unità → OK

dimmi se desideri formattare i supporti removibili o disinfettarli, ciao.

ulthuan
25-07-2008, 17:06
eccomi,
ed ecco il log di combofix


ComboFix 08-07-18.5 - proprietario 2008-07-25 17.50.40.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.214 [GMT 2:00]
Eseguito da: C:\Documents and Settings\proprietario\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\proprietario\Desktop\CFScript.txt
* Creato nuovo punto di ripristino

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((( Files Creati Da 2008-06-25 al 2008-07-25 )))))))))))))))))))))))))))))))))))
.

2008-07-21 15:37 . 2008-07-21 15:37 <DIR> d-------- C:\Programmi\Apple Software Update
2008-07-21 15:37 . 2008-07-21 15:37 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Apple
2008-07-21 15:33 . 2008-07-21 15:33 <DIR> d-------- C:\Programmi\File comuni\Adobe AIR
2008-07-19 14:32 . 2008-07-19 21:18 250 --a------ C:\WINDOWS\gmer.ini
2008-07-19 14:30 . 2008-07-19 14:30 <DIR> d-------- C:\Programmi\Trend Micro
2008-07-18 21:09 . 2008-07-18 21:09 <DIR> d-------- C:\Documents and Settings\proprietario\DoctorWeb
2008-07-18 19:46 . 2008-07-18 19:46 <DIR> d-------- C:\fsaua.data
2008-07-18 17:01 . 2008-07-18 18:51 <DIR> d-------- C:\Programmi\a-squared Free
2008-07-18 16:43 . 2008-07-18 16:43 <DIR> d-------- C:\Programmi\Pointstone
2008-07-17 19:37 . 2008-07-17 19:37 <DIR> d-------- C:\Programmi\Microsoft Silverlight
2008-07-17 15:19 . 2008-07-17 15:19 <DIR> d-------- C:\Programmi\PrevxCSI
2008-07-17 15:19 . 2008-07-25 15:00 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\PrevxCSI
2008-07-17 15:19 . 2008-07-17 15:19 17,408 --a------ C:\WINDOWS\system32\drivers\pxark.sys
2008-07-10 17:31 . 2008-07-12 12:12 <DIR> d-------- C:\Programmi\Uniblue
2008-07-10 17:13 . 2008-07-12 12:13 <DIR> d-------- C:\Documents and Settings\proprietario\Dati applicazioni\Uniblue
2008-06-27 12:07 . 2008-06-27 12:07 <DIR> d--h----- C:\WINDOWS\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 14:02 --------- d-----w C:\Documents and Settings\davide\Dati applicazioni\AVG7
2008-07-25 13:39 --------- d-----w C:\Documents and Settings\proprietario\Dati applicazioni\AVG7
2008-07-24 22:16 --------- d-----w C:\Programmi\AdunanzA
2008-07-21 13:38 --------- d-----w C:\Programmi\QuickTime
2008-07-21 13:38 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer
2008-07-21 13:18 --------- d-----w C:\Programmi\Java
2008-06-03 17:46 --------- d-----w C:\Programmi\LeechFTP
2007-12-28 17:35 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
2007-10-05 09:11 126,976 ----a-w C:\Documents and Settings\proprietario\(null)C89B5036.DLL
2007-07-30 14:48 299,008 ----a-w C:\Documents and Settings\proprietario\(null)D396E945.DLL
2007-07-04 18:45 113,054 ----a-w C:\Documents and Settings\proprietario\(null)DA5BB534.DLL
2007-06-02 11:52 299,008 ----a-w C:\Documents and Settings\proprietario\(null)ED9C7EC.DLL
2007-05-30 00:56 299,008 ----a-w C:\Documents and Settings\proprietario\(null)569D8CA6.DLL
2007-05-10 12:10 299,008 ----a-w C:\Documents and Settings\proprietario\(null)69386E6.DLL
2007-04-30 15:30 35,072 ----a-w C:\Documents and Settings\proprietario\Dati applicazioni\GDIPFONTCACHEV1.DAT
2007-03-17 12:50 126,976 ----a-w C:\Documents and Settings\proprietario\(null)CEC512E.DLL
2007-01-30 13:03 299,008 ----a-w C:\Documents and Settings\proprietario\(null)40DB9E0.DLL
2006-12-06 17:59 299,008 ----a-w C:\Documents and Settings\proprietario\(null)B3268B1.DLL
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.

((((((((((((((((((((((((((((( snapshot@2008-07-19_20.37.44.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-21 13:37:30 27,136 ----a-r C:\WINDOWS\Installer\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}\AppleSoftwareUpdateIco.exe
+ 2007-12-12 13:06:42 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
- 2008-02-22 00:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-09 23:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2008-02-22 00:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-09 23:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2008-02-22 01:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 00:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-03-25 02:32:44 218,496 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
+ 2008-07-21 13:48:57 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2007-07-30 17:18:34 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
+ 2006-12-01 20:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 20:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 20:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:39 15360]
"SpybotSD TeaTimer"="C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
"Uniblue RegistryBooster 2"="C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-05-16 10:18 1856544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-11 13:47 7311360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-11 13:47 86016]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-17 10:34 579584]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"QuickTime Task"="C:\Programmi\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"nwiz"="nwiz.exe" [2005-11-11 13:47 1519616 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 16:39 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-29 22:16 219136]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
VIA RAID TOOL.lnk - C:\Programmi\VIA\RAID\raid_tool.exe [2006-05-04 15:23:34 565248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"C:\\WINDOWS\\system32\\svchost.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avginet.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\kav\\kav7.0\\english\\setup.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\LeechFTP\\Leechftp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14973:TCP"= 14973:TCP:NortonAV
"15706:TCP"= 15706:TCP:NortonAV
"13150:TCP"= 13150:TCP:NortonAV
"18873:TCP"= 18873:TCP:NortonAV

R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-07-17 15:19]
R2 CSIScanner;CSIScanner;C:\Programmi\PrevxCSI\prevxcsi.exe [2008-07-17 15:19]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb92b898-3564-11dd-8484-00138f2c6cd4}]
\Shell\AutoRun\command - setup.exe
.
Contenuto della cartella 'Scheduled Tasks'
"2008-07-25 15:00:00 C:\WINDOWS\Tasks\A07F675891C4E530.job"
- c:\docume~1\propri~1\datiap~1\gpl1ac~1\IsoSeekMedia.exe
"2008-07-21 13:37:29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmi\Apple Software Update\SoftwareUpdate.exe
"2008-07-12 10:12:37 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Programmi\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-07-12 10:12:37 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Programmi\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-07-12 10:10:48 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Programmi\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-25 17:53:32
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-07-25 17:54:56
ComboFix-quarantined-files.txt 2008-07-25 15:54:27
ComboFix2.txt 2008-07-21 14:07:17
ComboFix3.txt 2008-07-19 18:37:58

Pre-Run: 41,637,150,720 byte disponibili
Post-Run: 41,986,125,824 byte disponibili

138 --- E O F --- 2007-12-16 11:56:00




Ma alla fine di tutto questo...come sto messo?un pò meglio spero:D

Per quanto riguarda l'hd esterno e l'mp3 meglio se li disinfetto, perchè avevo spostato tutto li sopra per formattare, però poi non ci sono riuscito quindi non vorrei perdere qualcosa di importante che neanche ricordoXD

grazie ciao ciao

wjmat
25-07-2008, 18:16
nella strina di prima mancava registry:: di conseguenza la stringa nel registro è rimasta
rifallo con quello che ti segnalo qui sotto
registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb92b898-3564-11dd-8484-00138f2c6cd4}]
\Shell\AutoRun\command - setup.exe


sarebbe meglio che tu caricassi tutti i log secondo le modalità (http://www.hwupgrade.it/forum/showthread.php?t=1779308)

Chill-Out
25-07-2008, 18:19
nella strina di prima mancava registry:: di conseguenza la stringa nel registro è rimasta
rifallo con quello che ti segnalo qui sotto
registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb92b898-3564-11dd-8484-00138f2c6cd4}]
\Shell\AutoRun\command - setup.exe


sarebbe meglio che tu caricassi tutti i log secondo le modalità (http://www.hwupgrade.it/forum/showthread.php?t=1779308)

Giusto :stordita: chiedo venia ma qui manca - :D in definitiva deve essere così:

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb92b898-3564-11dd-8484-00138f2c6cd4}]

wjmat
25-07-2008, 18:22
senza il - non la cancella... non ci avevo fatto caso :doh: :D

ulthuan
02-08-2008, 16:38
eccomi un pò in ritardo questa volta, sono stato 4 giorni fuori!
allora ecco il log di combofix, e anche nella modalità esatta ;)

ciau ciau

wjmat
02-08-2008, 18:29
se ti sembra di essere a posto (dai log vedo questo, ma potrebbe esserci altro)
dai un'occhiata al trattamento di prevenzione / post disinfezione (http://www.hwupgrade.it/forum/showthread.php?t=1726383), ti aiuta a verificare la configurazione di sicurezza del tuo pc, aggiornare programmi vulnerabili obsoleti ed eliminare eventuali residui inutili dei programmi utilizzati nelle guide

ulthuan
04-08-2008, 14:24
indubbiamente mi sembra di stare molto meglio!!!
Cmq volevo chiedervi se AVG è un buon antivirus o me ne consigliate un altro, e con calma cosa devo fare con l'hd esterno che è infetto anche lui;)
grazie ancora siete stati magnifici!!!

Gle89
04-08-2008, 18:02
Cmq volevo chiedervi se AVG è un buon antivirus o me ne consigliate un altro

Ti consigliamo l'ottimo e migliore ANTIVIR PERSONAL EDITION FREE: clicca qui per il download (http://www.free-av.com/down/windows/antivir_workstation_win7u_en_h.exe)
● una volta installato, scarica gli aggiornamenti e poi, esegui una scansione completa del sistema.
qui trovi la Guida di configurazione per Antivir (http://www.hwupgrade.it/forum/showthread.php?t=1514684) pubblicata da Juninho, ed altre cose importanti ed interessanti in relazione ad Antivir.


, e con calma cosa devo fare con l'hd esterno che è infetto anche lui;)


HD esterno è infetto dal solito virus? "sintomi"?

ulthuan
04-08-2008, 22:47
gracias per l'antivirus:D

l'hd dovrebbe essere infetto da autorun.inf o ravmonlog qualcosa del genere, cmq è un virus che avevo anche nell'hd interno, in quanto si trasferisci tra i due!
I sintomi sono che quando tento di aprirlo (non da esplora risorse) mi apre la finestra "apri con", come se fosse un programma sconosciuto! (questo è quello più evidente:D)

ciau ciau

xcdegasp
04-08-2008, 23:22
con avira non sarai più infetto :)

ulthuan
11-08-2008, 17:54
rieccomi qui a rompere:D
devo dire che va proprio meglio da quando mi avete aiutato!
A questo punto volevo cominciare a disinfettare l'hd esterno se possibile...quando volete io sono pronto:D
E visto che ci sono un'altra domandina, secondo voi dovrei aumentare la memoria ram che ora ho a 512 fino a 1 GB?
grazie ciau ciau

Chill-Out
11-08-2008, 18:01
rieccomi qui a rompere:D
devo dire che va proprio meglio da quando mi avete aiutato!
A questo punto volevo cominciare a disinfettare l'hd esterno se possibile...quando volete io sono pronto:D
E visto che ci sono un'altra domandina, secondo voi dovrei aumentare la memoria ram che ora ho a 512 fino a 1 GB?
grazie ciau ciau

Se hai disabilitato la riproduzione automatica come indicato qui http://www.hwupgrade.it/forum/showpost.php?p=23448243&postcount=12

procedi alla disinfezione dell'Hd esterno dapprima dando una passata con Avira, successivamente con A-Squared Free e CureIt (per quanto riguarda CureIt lo devi riscaricare in quanto sono passati diversi giorni e le definizioni sono state aggiornate)

Aumentare la Ram male non fà :)