PDA

View Full Version : virus Troj_smallagt


zeldavb
26-04-2005, 14:41
Al riavvio della macchina viene lanciata un'applicazione che cerca di effettuare una registrazione ad un certo sito. Durante l'esecuzione la macchina viene infettata da virus Troj_smallagt

Eseguita scansione con Microsoft AntiSpyware e stinger datato 3.01.2005 rilevati ed eliminati 104 Spyware.
Nel sistema persiste un virus che non si riesce ad eliminare denominato troj_small, questo virus ogni qual volta che si accede alla rete internet aprendo una finestra explorer fa ricomparire come pagina predefinita www.sfondissimi.net?1746 che reinfetta tutto il sistema

Sapevo che esisteva un programmino o una procedura che ti eliminava la pagina iniziale... Grazie

BravoGT83
26-04-2005, 14:45
allora serve il log di Hijackthis....

che antivirus usi?.....fai un paio di scansioni di antivirus in modalità prov. :)

zeldavb
26-04-2005, 15:01
allora serve il log di Hijackthis....

che antivirus usi?.....fai un paio di scansioni di antivirus in modalità prov. :)
L'antivirus è della trend micro (Office scan corporate edition)

Mi dava un'errore su un file denominato win.ini te lo copio:

; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1
CMC=1
CMCDLLNAME32=mapi32.dll
CMCDLLNAME=mapi.dll
MAPIX=1
MAPIXVER=1.0.0.1
OLEMessaging=1
[MCI Extensions.BAK]
asf=MPEGVideo2
asx=MPEGVideo2
ivf=MPEGVideo2
m3u=MPEGVideo2
mp2v=MPEGVideo
mp3=MPEGVideo2
mpv2=MPEGVideo
wax=MPEGVideo2
wm=MPEGVideo2
wma=MPEGVideo2
wmv=MPEGVideo2
wmx=MPEGVideo2
wvx=MPEGVideo2
wmp=MPEGVideo2
wpl=MPEGVideo
[PCDRWIN]
szCurrentCustomTest=C:\Programmi\PC-Doctor per Windows\DEFUSER.PCB
iShowStartupScreen=1
iVerticalButtonBar=1
iSaveWindowLayout=0
CurrentLanguage=14
[OLFax Ports]
OLFModem=C:\apps\Microsoft Office\Office\1040\WFXMSRVR.EXE,WFXMSRVR,WFXOUTLOOKSMTPPOP3, 60
[SciCalc]
layout=0
[MSUCE]
Advanced=0
CodePage=Unicode
Font=Arial
[MAPI 1.0 Time Zone]
Bias=ffffffc4
StandardName=ora solare Europa occidentale
StandardBias=0
StandardStart=00000A00050003000000000000000000
DaylightName=ora legale Europa occidentale
DaylightBias=ffffffc4
DaylightStart=00000300050002000000000000000000
ActiveTimeBias=ffffff88

Allego file della scansione

BravoGT83
26-04-2005, 15:16
non era quel log che m'interessava

scarica questo

http://80.237.140.193/downloads/hijackthis_199.zip

:)

poi post il log

bluepix
26-04-2005, 15:26
E si .... ci vuole il rep di Hijackthis.

Potebbe esserci il famigerato EliteToolBar :(

Ps: Ma che errore da su win.ini? Gli ha dato un'occhiata, però sembra Ok.

zeldavb
26-04-2005, 16:44
Ok perfetto ho fatto la scansione.. Il log è il seguente:

Logfile of HijackThis v1.99.1
Scan saved at 17.05.29, on 26/04/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\userinit.exe
C:\WINNT\Explorer.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteAgent] C:\OfficeScan NT\RAUAgent.exe
O4 - HKLM\..\Run: [PicoCrypto] "C:\Programmi\EUTRON\PicoDisk Crypto X\eupccrmn.exe"
O4 - HKLM\..\Run: [ZZZARDAEMON] C:\Programmi\Eutron\CryptoKit\Utils\ardaemon.exe
O4 - HKLM\..\Run: [Sxplog] C:\SxpInst\sxpstub.exe
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [CA-AMAgent] c:\programmi\ca\unicenter asset management\agents\amagent.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Programmi\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programmi\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\elitexxv32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\apps\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Data Transport Service Monitor.lnk = C:\Programmi\CA\SharedComponents\DTS\bin\dtstray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\apps\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Programmi\3M\PSNLite\PsnLite.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {878A0D61-48D2-11D3-A75D-00A0245382DE} (WebIdCli Class) - http://www.selectlavoro.com/agenziavirtuale/WEBIDENTITY/WICli.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = alteanet.it
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = alteanet.it
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = alteanet.it
O18 - Filter: text/html - {E05E4DCF-5747-41CF-A6EC-A51EA992DD7E} - C:\Documents and Settings\msalvato\Impostazioni locali\Dati applicazioni\microsoft\internet explorer\V0.26.dat
O20 - Winlogon Notify: ArCryptoKit - C:\WINNT\SYSTEM32\arcksso.dll
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Asset Management Agent (AmoAgent) - Computer Associates International, Inc. - C:\WINNT\UMCSTUB.EXE
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programmi\AVPersonal\AVGUARD.EXE
O23 - Service: ARcltsrv - Algorithmic Research Ltd. - C:\Programmi\Eutron\CryptoKit\utils\ARCLTSRV.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programmi\AVPersonal\AVWUPSRV.EXE
O23 - Service: Unicenter Message Queuing Server (CA-MessageQueuing) - Computer Associates International, Inc. - C:\PROGRA~1\CA\SHARED~1\CAM\bin\cam.exe
O23 - Service: CA-License Client (CA_LIC_CLNT) - Unknown owner - C:\WINNT\Lic98Rmt.exe
O23 - Service: CA-License Server (CA_LIC_SRVR) - Unknown owner - C:\WINNT\Lic98RmtD.exe
O23 - Service: Visual Studio Debugger Proxy Service (DbgProxy) - Unknown owner - C:\Programmi\Microsoft Visual Studio .NET 2003\Common7\Packages\Debugger\dbgproxy.exe (file missing)
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\WINNT\LogWatNT.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: Plone - Unknown owner - C:\PROGETTI\Plone103\Zope\pwi\ZopeServiceNT.exe" Plone (file missing)
O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINNT\SYSTEM32\PLSRemote.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Associates International, Inc. - C:\Programmi\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Unknown owner - C:\OfficeScan NT\tmlisten.exe
O23 - Service: DTS Browser (TNG-DOBA) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdoba.exe
O23 - Service: DTS Metrics Gatherer (TNG-DTMG) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdtmg.exe
O23 - Service: DTS Agent (TNG-DTS) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdta.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Programmi\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINNT\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINNT\system32\vmnat.exe
O23 - Service: ZEO Storage at c:\Zeo (ZEO_141467975) - Unknown owner - C:\Programmi\Zope\bin\PythonService.exe (file missing)
O23 - Service: Zope instance at c:\Progetti\Manuli (Zope_-554840605) - Unknown owner - C:\Zope-2.7.0-rc2\bin\PythonService.exe (file missing)

BravoGT83
26-04-2005, 16:50
azz che macello...

quelli dove ce scritto (file missing) alla fine togliele ;)

poi vediamo il resto

zeldavb
26-04-2005, 16:57
azz che macello...

quelli dove ce scritto (file missing) alla fine togliele ;)

poi vediamo il resto
scusa ma come faccio a rimuoverli???

BravoGT83
26-04-2005, 16:58
O23 - Service: DTS Browser (TNG-DOBA) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdoba.exe
O23 - Service: DTS Metrics Gatherer (TNG-DTMG) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdtmg.exe
O23 - Service: DTS Agent (TNG-DTS) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdta.exe

O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINNT\SYSTEM32\PLSRemote.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Associates International, Inc. - C:\Programmi\CA\Unicenter Software Delivery\BIN\SDSERV.EXE

O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE

sospetti ma non so che prog. è oracle :doh:

O23 - Service: Unicenter Message Queuing Server (CA-MessageQueuing) - Computer Associates International, Inc. - C:\PROGRA~1\CA\SHARED~1\CAM\bin\cam.exe
O23 - Service: CA-License Client (CA_LIC_CLNT) - Unknown owner - C:\WINNT\Lic98Rmt.exe
O23 - Service: CA-License Server (CA_LIC_SRVR) - Unknown owner - C:\WINNT\Lic98RmtD.exe

O18 - Filter: text/html - {E05E4DCF-5747-41CF-A6EC-A51EA992DD7E} - C:\Documents and Settings\msalvato\Impostazioni locali\Dati applicazioni\microsoft\internet explorer\V0.26.dat

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = alteanet.it
O16 - DPF: {878A0D61-48D2-11D3-A75D-00A0245382DE} (WebIdCli Class) - http://www.selectlavoro.com/agenzia...NTITY/WICli.cab
molto sospetto :mbe:

mi sa che ce altro....aspettiamo blue :p

BravoGT83
26-04-2005, 16:58
scusa ma come faccio a rimuoverli???
con hijackthis :)

bluepix
26-04-2005, 17:00
Per iniziare scarica questo:

http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/EliteToolbar-Remover.shtml

e lancialo

Poi è complicatissimo il log.

Rifai lo scan con Hijackthis e, se è rimasto, fixa:

O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\elitexxv32.exe


cancella il file:

C:\winnt\system32\elitexxv32.exe

zeldavb
28-04-2005, 11:15
Per iniziare scarica questo:

http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/EliteToolbar-Remover.shtml

e lancialo

Poi è complicatissimo il log.

Rifai lo scan con Hijackthis e, se è rimasto, fixa:

O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\elitexxv32.exe


cancella il file:

C:\winnt\system32\elitexxv32.exe

Ho eseguito la scansione eliminata la stringa:
C:\winnt\system32\elitexxv32.exe

eseguito la nuova scansione con Hijackthis e il nuovo log è il seguente:

Logfile of HijackThis v1.99.1
Scan saved at 11.55.39, on 28/04/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteAgent] C:\OfficeScan NT\RAUAgent.exe
O4 - HKLM\..\Run: [PicoCrypto] "C:\Programmi\EUTRON\PicoDisk Crypto X\eupccrmn.exe"
O4 - HKLM\..\Run: [ZZZARDAEMON] C:\Programmi\Eutron\CryptoKit\Utils\ardaemon.exe
O4 - HKLM\..\Run: [Sxplog] C:\SxpInst\sxpstub.exe
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [CA-AMAgent] c:\programmi\ca\unicenter asset management\agents\amagent.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Programmi\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\apps\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Data Transport Service Monitor.lnk = C:\Programmi\CA\SharedComponents\DTS\bin\dtstray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\apps\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Programmi\3M\PSNLite\PsnLite.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {878A0D61-48D2-11D3-A75D-00A0245382DE} (WebIdCli Class) - http://www.selectlavoro.com/agenziavirtuale/WEBIDENTITY/WICli.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = alteanet.it
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = alteanet.it
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = alteanet.it
O18 - Filter: text/html - {E05E4DCF-5747-41CF-A6EC-A51EA992DD7E} - C:\Documents and Settings\msalvato\Impostazioni locali\Dati applicazioni\microsoft\internet explorer\V0.26.dat
O20 - Winlogon Notify: ArCryptoKit - C:\WINNT\SYSTEM32\arcksso.dll
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Asset Management Agent (AmoAgent) - Computer Associates International, Inc. - C:\WINNT\UMCSTUB.EXE
O23 - Service: ARcltsrv - Algorithmic Research Ltd. - C:\Programmi\Eutron\CryptoKit\utils\ARCLTSRV.EXE
O23 - Service: Unicenter Message Queuing Server (CA-MessageQueuing) - Computer Associates International, Inc. - C:\PROGRA~1\CA\SHARED~1\CAM\bin\cam.exe
O23 - Service: CA-License Client (CA_LIC_CLNT) - Unknown owner - C:\WINNT\Lic98Rmt.exe
O23 - Service: CA-License Server (CA_LIC_SRVR) - Unknown owner - C:\WINNT\Lic98RmtD.exe
O23 - Service: Visual Studio Debugger Proxy Service (DbgProxy) - Unknown owner - C:\Programmi\Microsoft Visual Studio .NET 2003\Common7\Packages\Debugger\dbgproxy.exe (file missing)
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\WINNT\LogWatNT.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: Plone - Unknown owner - C:\PROGETTI\Plone103\Zope\pwi\ZopeServiceNT.exe" Plone (file missing)
O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINNT\SYSTEM32\PLSRemote.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Associates International, Inc. - C:\Programmi\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Unknown owner - C:\OfficeScan NT\tmlisten.exe
O23 - Service: DTS Browser (TNG-DOBA) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdoba.exe
O23 - Service: DTS Metrics Gatherer (TNG-DTMG) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdtmg.exe
O23 - Service: DTS Agent (TNG-DTS) - Computer Associates International, Inc. - C:\Programmi\CA\SharedComponents\DTS\bin\tngdta.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Programmi\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINNT\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINNT\system32\vmnat.exe
O23 - Service: ZEO Storage at c:\Zeo (ZEO_141467975) - Unknown owner - C:\Programmi\Zope\bin\PythonService.exe (file missing)
O23 - Service: Zope instance at c:\Progetti\Manuli (Zope_-554840605) - Unknown owner - C:\Zope-2.7.0-rc2\bin\PythonService.exe (file missing)

Che cosa dovrei eliminare???

ercolino
28-04-2005, 11:34
Come ti hanno già detto elimina anche le righe che presentano alla fine (file missing)



Questo è abbastanza sospetto

O18 - Filter: text/html - {E05E4DCF-5747-41CF-A6EC-A51EA992DD7E} - C:\Documents and Settings\msalvato\Impostazioni locali\Dati applicazioni\microsoft\internet explorer\V0.26.dat




O23 - Service: Unicenter Message Queuing Server (CA-MessageQueuing) - Computer Associates International, Inc. - C:\PROGRA~1\CA\SHARED~1\CAM\bin\cam.exe

http://www3.ca.com/securityadvisor/pest/pest.aspx?id=71183



Poi fai una scansione anche qui:

http://it.trendmicro-europe.com/consumer/products/housecall_launch.php


poi riposta il log

bluepix
28-04-2005, 11:57
Come ti hanno già detto elimina anche le righe che presentano alla fine (file missing)



Questo è abbastanza sospetto

O18 - Filter: text/html - {E05E4DCF-5747-41CF-A6EC-A51EA992DD7E} - C:\Documents and Settings\msalvato\Impostazioni locali\Dati applicazioni\microsoft\internet explorer\V0.26.dat




O23 - Service: Unicenter Message Queuing Server (CA-MessageQueuing) - Computer Associates International, Inc. - C:\PROGRA~1\CA\SHARED~1\CAM\bin\cam.exe

http://www3.ca.com/securityadvisor/pest/pest.aspx?id=71183



Poi fai una scansione anche qui:

http://it.trendmicro-europe.com/consumer/products/housecall_launch.php


poi riposta il log


Sembra evidente che nella macchina sia installato Ca-Unicenter TNG.
cam.exe pare, vedendo questo articolo http://www.immunitysec.com/downloads/awservices.pdf ,
che faccia parte del prodotto anche se, leggendo sempre l'articolo, è un componente facilmente attaccabile.
Forse sarebbe meglio contattare l'assistenza CA per saperne di più ed ottenere le patches necessarie per il fix.

ercolino
28-04-2005, 12:04
Sicuramente ,sono d'accordo ,in effetti li da come abbastanza sospetti

zeldavb
28-04-2005, 16:00
Grazie ragazzi siete stati grandiosi problema risolto... Ora la macchina è rinata.. :D

bluepix
28-04-2005, 16:20
:yeah:

BravoGT83
28-04-2005, 21:13
Grazie ragazzi siete stati grandiosi problema risolto... Ora la macchina è rinata.. :D
:winner: :winner:

bene