katodb
19-08-2005, 16:23
Ho appena reinstallato Xp pro SP1 e al primo collegamento ho preso (almeno credo) dei trojan o worm. Come è possibile con disco pulito e zero programmi installati? E' vero che non avevo ancora fatto settaggi per proteggere di più il pc ma per tanti anni mi sono connesso senza nemmeno firewall e a volte antivirus e non ho preso mai niente, adesso...un casino.
Cmq i file sospetti credo siano ss.exe e package_adp_SIAC.exe
e mi si apre mentre sono connesso una finestra "advertisement" e una pagina di yahoo
ma questo log mi preoccupa
guardate un pò:
Logfile of HijackThis v1.99.1
Scan saved at 16.41.12, on 19/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\iexplore.exe
C:\WINDOWS\System32\li32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\wuamk032.exe
C:\WINDOWS\System32\NotifyPhoneBook.exe
C:\WINDOWS\system32\cmd.exe
C:\Documents and Settings\DARIO\Internet Optimizer\optimize.exe
C:\WINDOWS\installer_SIAC.exe
C:\WINDOWS\System32\m81uu9o9.exe
C:\Programmi\oech\ncdc.exe
C:\WINDOWS\system32\w?auboot.exe
F:\pulitori periodici\HijackThis.exe
C:\WINDOWS\System32\system.pif
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ansa.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Programmi\SurfSideKick 3\SskBho.dll
O2 - BHO: (no name) - {04C86619-E1B2-F04B-AFCB-F44404CDF9F9} - C:\WINDOWS\System32\olhksv.dll
O2 - BHO: (no name) - {31E55619-CC81-C57F-82FB-C46934FDD4C9} - C:\WINDOWS\System32\olhksv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Programmi\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [Microsoft Update] wuamk032.exe
O4 - HKLM\..\Run: [li start up] li32.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [System Update Service] system.pif
O4 - HKLM\..\Run: [Internet2 Optimizer] wkfix.exe
O4 - HKLM\..\Run: [m81uu9o9] C:\WINDOWS\System32\m81uu9o9.exe
O4 - HKLM\..\RunServices: [li start up] li32.exe
O4 - HKLM\..\RunServices: [MSN9 Startup] msn9.exe
O4 - HKLM\..\RunServices: [MS Windows Security Updater] updater.pif
O4 - HKLM\..\RunServices: [Microsoft Update] wuamk032.exe
O4 - HKLM\..\RunServices: [Internet2 Optimizer] wkfix.exe
O4 - HKLM\..\RunServices: [System Update Service] system.pif
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Programmi\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [li start up] li32.exe
O4 - HKCU\..\Run: [System Update Service] system.pif
O4 - HKCU\..\Run: [Internet2 Optimizer] wkfix.exe
O4 - HKCU\..\Run: [Eewa] C:\Programmi\oech\ncdc.exe
O4 - HKCU\..\Run: [Izcltpat] C:\WINDOWS\System32\w?auboot.exe
O4 - HKCU\..\RunServices: [li start up] li32.exe
O4 - HKCU\..\RunServices: [MS Windows Security Updater] updater.pif
O4 - HKCU\..\RunServices: [System Update Service] system.pif
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windows...b?1124390418589
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/website.ocx
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTic....cab?refid=4809
O20 - AppInit_DLLs: repairs.dll
Cmq i file sospetti credo siano ss.exe e package_adp_SIAC.exe
e mi si apre mentre sono connesso una finestra "advertisement" e una pagina di yahoo
ma questo log mi preoccupa
guardate un pò:
Logfile of HijackThis v1.99.1
Scan saved at 16.41.12, on 19/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\iexplore.exe
C:\WINDOWS\System32\li32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\wuamk032.exe
C:\WINDOWS\System32\NotifyPhoneBook.exe
C:\WINDOWS\system32\cmd.exe
C:\Documents and Settings\DARIO\Internet Optimizer\optimize.exe
C:\WINDOWS\installer_SIAC.exe
C:\WINDOWS\System32\m81uu9o9.exe
C:\Programmi\oech\ncdc.exe
C:\WINDOWS\system32\w?auboot.exe
F:\pulitori periodici\HijackThis.exe
C:\WINDOWS\System32\system.pif
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ansa.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Programmi\SurfSideKick 3\SskBho.dll
O2 - BHO: (no name) - {04C86619-E1B2-F04B-AFCB-F44404CDF9F9} - C:\WINDOWS\System32\olhksv.dll
O2 - BHO: (no name) - {31E55619-CC81-C57F-82FB-C46934FDD4C9} - C:\WINDOWS\System32\olhksv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Programmi\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [Microsoft Update] wuamk032.exe
O4 - HKLM\..\Run: [li start up] li32.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [System Update Service] system.pif
O4 - HKLM\..\Run: [Internet2 Optimizer] wkfix.exe
O4 - HKLM\..\Run: [m81uu9o9] C:\WINDOWS\System32\m81uu9o9.exe
O4 - HKLM\..\RunServices: [li start up] li32.exe
O4 - HKLM\..\RunServices: [MSN9 Startup] msn9.exe
O4 - HKLM\..\RunServices: [MS Windows Security Updater] updater.pif
O4 - HKLM\..\RunServices: [Microsoft Update] wuamk032.exe
O4 - HKLM\..\RunServices: [Internet2 Optimizer] wkfix.exe
O4 - HKLM\..\RunServices: [System Update Service] system.pif
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Programmi\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [li start up] li32.exe
O4 - HKCU\..\Run: [System Update Service] system.pif
O4 - HKCU\..\Run: [Internet2 Optimizer] wkfix.exe
O4 - HKCU\..\Run: [Eewa] C:\Programmi\oech\ncdc.exe
O4 - HKCU\..\Run: [Izcltpat] C:\WINDOWS\System32\w?auboot.exe
O4 - HKCU\..\RunServices: [li start up] li32.exe
O4 - HKCU\..\RunServices: [MS Windows Security Updater] updater.pif
O4 - HKCU\..\RunServices: [System Update Service] system.pif
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windows...b?1124390418589
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/website.ocx
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTic....cab?refid=4809
O20 - AppInit_DLLs: repairs.dll