|
|
|
![]() |
|
Strumenti |
![]() |
#1 |
Junior Member
Iscritto dal: May 2006
Messaggi: 11
|
trojan-backdoor-prorat-d
Salve a tutti! Credo di aver bisogno di aiuto...
Usando Spy Sweeper, mi viene segnalato la presenza del trojan come da oggetto insieme ad altri due che potete notare nel log di Spy Sweep che allego qua sotto. Allego poi il log di hijackthis. Spero che qualcuno mi possa aiutare. Intanto ringrazio anticipatamente. Attendo fiducioso. Rha --------------------- 19.15: Common Ad Sites Shield: On 19.15: IE Tracking Cookies Shield: Removed webads cookie 19.15: IE Tracking Cookies Shield: Removed questionmarket cookie 19.15: IE Tracking Cookies Shield: Removed ru4 cookie 19.15: IE Tracking Cookies Shield: On 18.18: Removal process completed. Elapsed time 00.00.04 18.18: Quarantining All Traces: energy plugin 18.18: Quarantining All Traces: trojan-downloader-mucho-cool 18.18: Quarantining All Traces: trojan-backdoor-prorat-d 18.18: Removal process initiated 18.18: Traces Found: 10 18.18: Full Sweep has completed. Elapsed time 00.32.53 18.18: File Sweep Complete, Elapsed Time: 00.30.17 18.18: Warning: Failed to access drive O: 18.18: Warning: Failed to access drive N: 18.18: Warning: Failed to access drive M: 18.18: Warning: Failed to access drive K: 18.18: Warning: Failed to access drive H: 18.18: Warning: Failed to access drive G: 18.18: Warning: Failed to access drive E: 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\wbk6b.tmp". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\wbk67.tmp". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\wbk60.tmp". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\ca8h8p4z.9420604993136661". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\box_wht_340_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\box_grn_dbl_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\box_wht_dbl_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\box_gry_award_245x175_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\i70od9r6\arrow_tridot[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\box_wht_dbl_top[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\box_wht_dbl_bot[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\i70od9r6\box_wht_340_top[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\box_wht_340_bot[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\box_grn_dbl_top[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\box_grn_dbl_bot[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\i70od9r6\cauryvid.5727530899405873". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\footer_bg_chex[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\bot_shadow_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\box_grn_bot[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\box_grn_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\i70od9r6\top_shadow_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\box_grn_top[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\side_shadows[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\top_shadow_corners[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\hint[1].21574135101943592". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\bot_shadow_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\bot_shadow_corners[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\i70od9r6\footer_bg_chex[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\bot_shadow_corners[2].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\cartlockboxtop[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\shoppingcart_greenbackground[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\cartcallboxtop[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\top_shadow_bg[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\side_shadows[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\1kh111p7\top_shadow_corners[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\shoppingcart_cdicon[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\x2yd111w\shoppingcart-save_trans_23[1].gif". Operazione completata 18.16: Warning: Failed to open file "c:\documents and settings\gamma1\impostazioni locali\temporary internet files\content.ie5\jp8ekt4z\shoppingcart_trashcan[1].gif". Operazione completata Operation: File Access Target: Source: C:\WINNT\EXPLORER.EXE 17.56: Tamper Detection 17.49: C:\Programmi\E-nrgyPlus (ID = 2147504131) 17.49: C:\Programmi\EnergyPlugIn (ID = 2147486261) 17.49: Found Adware: energy plugin 17.48: Starting File Sweep 17.48: Warning: Failed to access drive A: 17.48: Cookie Sweep Complete, Elapsed Time: 00.00.00 17.48: Starting Cookie Sweep 17.48: Registry Sweep Complete, Elapsed Time:00.00.17 17.48: HKLM\software\microsoft\windows nt\currentversion\winlogon\ || shell (ID = 1181369) 17.48: HKLM\software\microsoft\active setup\installed components\{5y99ae78-58tt-11dw-be53-y67078979y}\ (ID = 1181364) 17.48: HKLM\software\classes\xsmx.ready2wear.1\ (ID = 1165963) 17.48: HKLM\software\classes\xsmx.ready2wear\ (ID = 1165957) 17.48: HKCR\xsmx.ready2wear\ (ID = 1165937) 17.48: HKCR\xsmx.ready2wear.1\ (ID = 1165921) 17.48: Found Trojan Horse: trojan-downloader-mucho-cool 17.47: Starting Registry Sweep 17.47: Memory Sweep Complete, Elapsed Time: 00.02.06 17.45: Starting Memory Sweep 17.45: C:\WINNT\system\sservice.exe (ID = 1181368) 17.45: HKLM\software\microsoft\active setup\installed components\{5y99ae78-58tt-11dw-be53-y67078979y}\ || stubpath (ID = 1181368) 17.45: Found Trojan Horse: trojan-backdoor-prorat-d 17.45: Sweep initiated using definitions version 734 17.45: Spy Sweeper 5.0.7.1608 started ------------ Logfile of HijackThis v1.99.1 Scan saved at 22.14.51, on 20/10/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\Explorer.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\system32\CTsvcCDA.exe C:\Programmi\iolo\System Mechanic Professional 6\IoloSGCtrl.exe C:\Programmi\Prevx1\PXAgent.exe C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINNT\system32\svchost.exe C:\VEXPLITE\viritsvc.exe C:\WINNT\services.exe C:\Programmi\Webroot\Spy Sweeper\SpySweeper.exe C:\Programmi\TRIXX\TRIXX.exe C:\Programmi\FarStone\VDPPro\VHD\RDTask.exe C:\WINNT\system32\rundll32.exe C:\VEXPLITE\MONLITE.EXE C:\Programmi\Webroot\Spy Sweeper\SpySweeperUI.exe C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe C:\WINNT\system32\MsPMSPSv.exe C:\Programmi\Webroot\Spy Sweeper\SSU.EXE C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Documents and Settings\Gamma1\Desktop\HijackThis.exe F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\system32\fservice.exe O4 - HKLM\..\Run: [TRIXX] "C:\Programmi\TRIXX\TRIXX.exe" -s O4 - HKLM\..\Run: [RAMDrive] "C:\Programmi\FarStone\VDPPro\VHD\RDTask.exe" O4 - HKLM\..\Run: [CnxTrApp] "rundll32.exe" "C:\Programmi\StarModem\StarModem USB Network\CnxTrApp.dll",AppEntry -REG "Conexant\Conexant USB Network" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE O4 - HKLM\..\Run: [SpySweeper] "C:\Programmi\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe" O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing) O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.exe O23 - Service: IAVZCKMKEYMTUX - Unknown owner - C:\DOCUME~1\Gamma1\IMPOST~1\Temp\IAVZCKMKEYMTUX.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Programmi\iolo\System Mechanic Professional 6\IoloSGCtrl.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe O23 - Service: LH - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Gamma1\IMPOST~1\Temp\LH.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Programmi\Prevx1\PXAgent.exe" -f (file missing) O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe O23 - Service: Sistema Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Programmi\Webroot\Spy Sweeper\SpySweeper.exe |
![]() |
![]() |
![]() |
#2 |
Bannato
Iscritto dal: Mar 2004
Città: Galapagos Attenzione:utente flautolente,tienilo a mente
Messaggi: 28978
|
il log di hijackthis devi farlo analizzare qui
per il resto esegui spysweeper da modalità provvisoria,dopo aver disabilitato il ripristino configurazione di sistema(riattivalo solo dopo che sei certo di aver rimosso il problema) |
![]() |
![]() |
![]() |
#3 |
Junior Member
Iscritto dal: May 2006
Messaggi: 11
|
Grazie per l'attenzione. Proverò a fare come mi consigli.
Ti faccio sapere. Grazie ancora. Rha |
![]() |
![]() |
![]() |
Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 09:25.