PDA

View Full Version : infetto o non infetto questo è il problema!


scudnet
09-07-2010, 08:46
vista con service pack2 32bit

antivirus antivir personal e firewall di windows

caso uno:

c:\windows\system32\exitwx.exe

non rilevato da antivir e dai numerosi siti che permettono di uploadare il singolo file e lo scansionano con decine di antivirus online

solo a-squared free e poi emisoft anti-malware lo individuano come worm.win32.trafaret.a!A2 (confermato da virustotal on line) ed ora giace in quarantena

caso due:

nonostante l'unico sospetto di cui sopra effettuando hijackthis inserito dentro emisoft anti-malware mi vengono segnalati numerosi altri file eseguibili del sistema che contengono oltre alla parte sana della funzione windows anche delle cose preoccupanti.

ecco un esempio:

Name: services.exe
Good: 1
Bad: 3

Status Filename Path Description

services.exe SentryPC is a collaboration of roughly 6 years in the computer monitoring and parental control software market. Devoted to creating the best software solution possible, it created a new name to go along with its new product, SentryPC. Parents will find SentryPC as the perfect solution to monitoring, filtering, and restricting their children's computer experience thus protecting them from harmful content, child predators, and more. Businesses, schools, libraries, and others can ensure their computer users have access to only what they determine when they determine. SentryPC enables to control, restrict and monitor access and usage of PC. We can control how long and when users are allowed to use the computer, prevent the use of specific programs, block access to certain websites, restrict access to Windows functions like Control Panel and more.

services.exe XP-Tools.com is a software design and marketing corporation which was founded in November 2002 and located in 3831 Valley Center Dr. Suite 706-295 San Diego, California. It is one of the original manufacturers and vendors of its software and related products. Since its beginning it has come a long way in terms of service, products, and technology to offer us the best in tools software solutions. Its products have received major write-ups in: Time Magazine, Newsweek, Business Week, The Washington Post, ABC World News Tonight, NBC Nightly News, CNN and MSNBC. Its company mission is to provide users with quality tools software. It offers pre sale support and most post sale support to attempt to keep our customers 100% satisfied.

services.exe %systempath%\ Services.exe manages the operation of starting and stopping services.

services.exe %winpath%\winsecurity\ Email-Worm.Win32.Sober.z

infine ecco il log completo di HijackThis:

Log rimosso leggere le Regole di sezione

Chill-Out
09-07-2010, 08:53
Se desideri il controllo del log di HJT, esiste un 3D dedicato http://www.hwupgrade.it/forum/showthread.php?t=937676 diversamente:

segui esattamente nell'ordine indicato la Guida alla disinfezione (http://www.hwupgrade.it/forum/showthread.php?t=1599737) allegando tutti i log prodotti in un'unico post secondo le sottoindicate modalità, grazie per la collaborazione.

Modalità di pubblicazione dei log:

Ogni singolo log, esclusivamente in formato .txt a parte SynInspector .xml, deve essere hostato nell'ordine indicato in Guida su uno dei server remoti elencati nelle Regole di sezione (http://www.hwupgrade.it/forum/showthread.php?t=1751598).