|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#1 |
|
Member
Iscritto dal: Nov 2005
Messaggi: 38
|
problema con avast
Ciao
cosa significano questi messaggi: Messaggio della scansione all'avvio di AVAST Protezione di rete: bloccato "DCOM Exploit" attacco da 62.211.32.100:135 TCP Controllando nella funzione Protezione di rete di AVAST trovo una serie di attacchi - vengono visualizzati gli ultimi 10. 19.01.2005 17:52:02 DCOM Exploit attack from 62.211.187.80:135 19.01.2005 17:52:49 DCOM Exploit attack from 62.211.187.80:135 19.01.2005 17:52:58 DCOM Exploit attack from 62.211.32.100:135 19.01.2005 17:54:35 DCOM Exploit attack from 62.211.221.50:135 19.01.2005 17:55:01 DCOM Exploit attack from 62.211.175.194:135 ogni dieci minuti mi escono questi messaggi da avast.............. cosa posso fare... grazie |
|
|
|
|
|
#2 |
|
Member
Iscritto dal: Nov 2005
Messaggi: 38
|
posto anche un log con hijack....
Logfile of HijackThis v1.99.1 Scan saved at 12.17.59, on 09/04/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe C:\Programmi\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Programmi\cFosSpeed\spd.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\RAMpage\RAMpage.exe C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Programmi\Alwil Software\Avast4\ashDisp.exe C:\Programmi\RealVNC\VNC4\WinVNC4.exe C:\Programmi\File comuni\Real\Update_OB\realsched.exe C:\Programmi\iTunes\iTunesHelper.exe C:\WINDOWS\SOUNDMAN.EXE C:\Programmi\cFosSpeed\cFos_Speed.exe C:\Programmi\I-Storm USB ADSL Modem\CnxDslTb.exe C:\Programmi\Messenger\msmsgs.exe C:\Programmi\MSN Messenger\msnmsgr.exe C:\Programmi\WinMX\WinMX.exe C:\Programmi\Dachshund Software\Hare\Hare.exe C:\Programmi\Alwil Software\Avast4\ashWebSv.exe C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe C:\Programmi\iPod\bin\iPodService.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\ewido anti-malware\ewidoguard.exe C:\Programmi\ewido anti-malware\ewidoctrl.exe C:\Programmi\ewido anti-malware\SecuritySuite.exe C:\Documents and Settings\Roberto\Desktop\Nuova cartella\kit velove pc\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O1 - Hosts: 205.238.40.1 winmx.com O1 - Hosts: 205.238.40.1 www.winmx.com O1 - Hosts: 205.238.40.1 err.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1305.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1305.winmx.com O1 - Hosts: 205.238.40.1 c3310.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3311.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3312.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3313.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3314.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3315.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3316.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3317.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3318.z1306.winmx.com O1 - Hosts: 82.195.155.5 c3319.z1306.winmx.com O1 - Hosts: 205.238.40.1 c3520.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3521.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3522.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3523.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3524.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3525.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3526.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3527.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3528.z1301.winmx.com O1 - Hosts: 82.195.155.5 c3529.z1301.winmx.com O1 - Hosts: 205.238.40.1 c3520.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3521.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3522.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3523.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3524.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3525.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3526.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3527.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3528.z1302.winmx.com O1 - Hosts: 82.195.155.5 c3529.z1302.winmx.com O1 - Hosts: 205.238.40.1 c3520.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3521.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3522.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3523.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3524.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3525.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3526.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3527.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3528.z1303.winmx.com O1 - Hosts: 82.195.155.5 c3529.z1303.winmx.com O1 - Hosts: 205.238.40.1 c3520.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3521.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3522.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3523.z1304.winmx.com O1 - Hosts: 205.238.40.1 c3524.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3525.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3526.z1304.winmx.com O1 - Hosts: 82.195.155.5 c3527.z1304.winmx.com O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Programmi\FlashFXP\IEFlash.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll O4 - HKLM\..\Run: [RAMpage] "C:\Programmi\RAMpage\RAMpage.exe" M=28 T=4 P="C:\Programmi\RAMpage\RAMpageConfig.exe" O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [avast!] "C:\Programmi\Alwil Software\Avast4\ashDisp.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iTunesHelper] C:\Programmi\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [cFosSpeed] C:\Programmi\cFosSpeed\cFos_Speed.exe O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Programmi\I-Storm USB ADSL Modem\CnxDslTb.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [WinMX] C:\Programmi\WinMX\WinMX.exe -m O4 - Startup: Hare.lnk = C:\Programmi\Dachshund Software\Hare\Hare.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: &Google Search - res://c:\programmi\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\programmi\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\programmi\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmi\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\programmi\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\programmi\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\MSMSGS.EXE O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {D355E971-0F61-11D2-8955-00805FFCE6FB} (siawds-full-install) - https://portal.actalis.it/CA/Environ...ll-install.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E64559F2-FA08-4A7E-85EF-8F2D715951BF}: NameServer = 193.70.152.15 193.70.152.25 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSN Messenger\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: cFosSpeed System Service (cFosSpeedS) - Unknown owner - C:\Programmi\cFosSpeed\spd.exe O23 - Service: ewido security suite control - ewido networks - C:\Programmi\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Programmi\ewido anti-malware\ewidoguard.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Programmi\RealVNC\VNC4\WinVNC4.exe" -service (file missing) |
|
|
|
|
|
#3 |
|
Senior Member
Iscritto dal: May 2005
Città: Palermo
Messaggi: 6390
|
Il log e' pulito. Ti esorto a mettere al piu' presto il SP2.
Per quanto riguarda quel messaggio di avast ti consiglio di aggiornare il sistema operativo e di usare questo tool: http://www.grc.com/dcom/ Ultima modifica di andorra24 : 09-04-2006 alle 12:32. |
|
|
|
|
|
#4 |
|
Senior Member
Iscritto dal: Sep 2005
Città: Opinions are like assholes: anybody has one...
Messaggi: 34290
|
ll log è pulito sebbene ci sia un casino di roba che mangia ram
hai sp1 meglio mettere sp2
__________________
Ну давай !! . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cina, bugiardo - stolen conto: non paghi . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . NON CERCO PIU' UN ALIMENTATORE DECENTE ----------------> LINK |
|
|
|
|
|
#5 |
|
Member
Iscritto dal: Nov 2005
Messaggi: 38
|
ok grazie
ok installerò sp2...ma ho una domanda se installo il tool....
http://www.grc.com/dcom/ che mi blocca la porta 135 ed anche altre porte...... poi potrei avere problemi ad usare winmx....... esatto.....? grazie per le info..........cortesissimi come sempre.......... |
|
|
|
|
|
#6 |
|
Senior Member
Iscritto dal: Sep 2005
Città: Opinions are like assholes: anybody has one...
Messaggi: 34290
|
non penso che winmx usi la porta 135
userà porte temporanee oltre la 1024
__________________
Ну давай !! . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cina, bugiardo - stolen conto: non paghi . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . NON CERCO PIU' UN ALIMENTATORE DECENTE ----------------> LINK |
|
|
|
|
|
#7 |
|
Senior Member
Iscritto dal: May 2005
Città: Palermo
Messaggi: 6390
|
DCOMbobulator si occupa solo della porta 135 disabilitando il DCOM.
|
|
|
|
|
|
#8 |
|
Senior Member
Iscritto dal: Sep 2005
Città: Opinions are like assholes: anybody has one...
Messaggi: 34290
|
allora metti worms doors cleaner che ne chiude anche altre
oppure safe xp ancora più completo
__________________
Ну давай !! . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cina, bugiardo - stolen conto: non paghi . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . NON CERCO PIU' UN ALIMENTATORE DECENTE ----------------> LINK |
|
|
|
|
|
#9 |
|
Member
Iscritto dal: Nov 2005
Messaggi: 38
|
x stev
ho messo il tool che mi hai detto...
wwwDC e adesso lo provo....... l'altro tool.....DCOM...non ho capito come funziona.... grazie delle info |
|
|
|
|
|
#10 |
|
Senior Member
Iscritto dal: Sep 2005
Città: Opinions are like assholes: anybody has one...
Messaggi: 34290
|
la dcom la chiudono tutti: se è solo quello che ti serve
__________________
Ну давай !! . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cina, bugiardo - stolen conto: non paghi . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . NON CERCO PIU' UN ALIMENTATORE DECENTE ----------------> LINK |
|
|
|
|
|
#11 |
|
Member
Iscritto dal: Nov 2005
Messaggi: 38
|
stev visto che il tool che ho scaricato WWDC è un demo e tra 14 giorni mi scade... ho trovato un file di registro.....che porta data 25/10/2004....
è un file ewido.reg di 201 kb...... dove lo devo installare....per la scadenza del demo.......... me lo sai psiegare... grazie |
|
|
|
|
|
#12 |
|
Senior Member
Iscritto dal: Sep 2005
Città: Opinions are like assholes: anybody has one...
Messaggi: 34290
|
worms doors cleaner un demo?????
è assolutamente free
__________________
Ну давай !! . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cina, bugiardo - stolen conto: non paghi . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . NON CERCO PIU' UN ALIMENTATORE DECENTE ----------------> LINK |
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 10:08.



















