Torna indietro   Hardware Upgrade Forum > Networking e sicurezza > Antivirus e Sicurezza > Aiuto sono infetto! Cosa faccio?

Star Wars Zero Company è l'erede di XCOM 2
Star Wars Zero Company è l'erede di XCOM 2
Bit Reactor porta nell’universo di Star Wars una struttura tattica che richiama apertamente XCOM 2, ma la arricchisce con legami tra i personaggi, progressione ruolistica, gestione della base e un sistema di combattimento costruito attorno a tre Punti Azione e alle risorse condivise della squadra
Test ride Can-Am Origin: la moto elettrica che fa dimenticare il motore a scoppio (ma occhio all'autonomia)
Test ride Can-Am Origin: la moto elettrica che fa dimenticare il motore a scoppio (ma occhio all'autonomia)
Abbiamo provato per una settimana intera la Can-Am Origin, la Dual Sport elettrica del gruppo canadese BRP: ecco com'è andata tra città, autostrada e un primo assaggio di sterrato
Logitech G325, G305 e G316 X: il tris per chi non vuole rinunciare a nulla, spendendo poco
Logitech G325, G305 e G316 X: il tris per chi non vuole rinunciare a nulla, spendendo poco
Nelle ultime settimane abbiamo provato il mouse Logitech G305, la tastiera G316 X 98 e le cuffie G325. Si tratta del setup entry-level di Logitech che ormai, di "entry-level" ha ben poco. Tastiera e mouse offrono prestazioni di livello competitivo con quasi nessuna rinuncia e un livello di personalizzazione estremamente elevato. Le cuffie, invece, hanno mostrato qualche debolezza, ma propongono un ventaglio di funzionalità completo che consente di abbandonare completamente i cavi
Tutti gli articoli Tutte le news

Vai al Forum
Rispondi
 
Strumenti
Old 20-05-2008, 16:29   #1
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
Non sono sicura di aver risolto tutto dopo infezione di coolwebsearch

Buongiorno a tutti!
Ieri, aprendo un file che ho scaricato dopo averlo scansionato (ma nod32 non mi ha trovato nulla) ho preso coolwebsearch più vari altri virus e una quantità di spyware inimmaginabile.
Dopo aver seguito le indicazioni del forum, credo di aver risolto la maggior parte dei problemi ma ci sono delle voci nel log di hijack che non mi convincono.
Ve lo posto così magari mi sapete dire.
Mi date una mano per favore?
Sono un pò preoccupata.
Allegati
File Type: txt MIO.txt (5.3 KB, 7 visite)
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 16:41   #2
xcdegasp
Senior Member
 
L'Avatar di xcdegasp
 
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
segui la semplice procedura descritta nella Guida alla Disinfezione per Infetti, rispettando l'ordine nell'esecuzione e pubblicando tutti i log usando uno dei metodi censiti nelle Regole di Sezione.
xcdegasp è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 16:44   #3
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
si scusa, non ho specificato che ho effettuato la disinfezione così come è consigliato qui sul forum.
Ho risolto praticamente tutti i problemi tanto che spybot adaware e antivir non mi trovano più niente.
Il fatto è che, facendo analizzare il log da un sito mi sono resa conto che ci sono forse ancora delle voci sospette.
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 16:48   #4
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
ah, dimenticavo, il log è allegato come file txt.
Grazie di tutto.
In particolare, la voce di cui non sono sicura, è:
Codice:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\xwusuhzh.exe,
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 17:12   #5
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
è sicuramente da fixare, ma se tu ci allegassi i log potremmo capire qualche cosa in più...
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 17:15   #6
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28

Ma il log è sopra!
nel mio primo post!
allegato come file txt, pensavo che andasse bene!
Comunque ve lo allego in altro modo:
Codice:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18.14.51, on 20/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Sygate\SPF\smc.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\Windows Live\Messenger\msnmsgr.exe
C:\Programmi\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\eMule\emule.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Pricipale\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\xwusuhzh.exe,
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Programmi\RALINK\Common\RaUI.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - 
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207083636823
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{21B20EA9-E539-491D-B49E-81F42F62F664}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe

--
End of file - 5399 bytes
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 17:18   #7
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
i log non il log di hjt sarà anche un buon programmino ma non fa miracoli.... dal log si vede solo la voce F2 ma quello potrebbe essere il sintomo di altre infezioni.... che noi non sapremo mai se hai debellato completamente...
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 17:22   #8
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
..mi sa che mi sono persa...i log sarebbero i risultati delle scansioni con l'antivirus?
Se si posto l'ultima con antivir.
Pe ril resto grazie al cielo spybot ed adaware non trovano più niente.
Scusate l'ignoranza!
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 17:28   #9
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
ecco quello di antivir.
Dopo aver fatto la scansione di cui vi riporto sotto il log ne ho fatta un'altra e non ha trovato più niente.
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 17:30   #10
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
Codice:
Avira AntiVir Personal
Report file date: martedì 20 maggio 2008  13:57

Scanning for 1280998 virus strains and unwanted programs.

Licensed to:      Avira AntiVir PersonalEdition Classic
Serial number:    0000149996-ADJIE-0001
Platform:         Windows XP
Windows version:  (Service Pack 2)  [5.1.2600]
Boot mode:        Normally booted
Username:         SYSTEM
Computer name:    LENZIARDI

Version information:
BUILD.DAT     : 8.1.00.295      16479 Bytes  09/04/2008 16:24:00
AVSCAN.EXE    : 8.1.2.12       311553 Bytes  18/03/2008 09:02:56
AVSCAN.DLL    : 8.1.1.0         53505 Bytes  07/02/2008 08:43:37
LUKE.DLL      : 8.1.2.9        151809 Bytes  28/02/2008 08:41:23
LUKERES.DLL   : 8.1.2.1         12033 Bytes  21/02/2008 08:28:40
ANTIVIR0.VDF  : 6.40.0.0     11030528 Bytes  18/07/2007 10:33:34
ANTIVIR1.VDF  : 7.0.3.2       5447168 Bytes  07/03/2008 13:08:58
ANTIVIR2.VDF  : 7.0.4.53      1848832 Bytes  17/05/2008 11:55:45
ANTIVIR3.VDF  : 7.0.4.68        75776 Bytes  20/05/2008 11:55:46
Engineversion : 8.1.0.46  
AEVDF.DLL     : 8.1.0.5        102772 Bytes  25/02/2008 09:58:21
AESCRIPT.DLL  : 8.1.0.33       266618 Bytes  20/05/2008 11:56:00
AESCN.DLL     : 8.1.0.18       119156 Bytes  20/05/2008 11:55:58
AERDL.DLL     : 8.1.0.20       418165 Bytes  20/05/2008 11:55:57
AEPACK.DLL    : 8.1.1.5        364918 Bytes  20/05/2008 11:55:56
AEOFFICE.DLL  : 8.1.0.18       192890 Bytes  20/05/2008 11:55:54
AEHEUR.DLL    : 8.1.0.29      1253750 Bytes  20/05/2008 11:55:53
AEHELP.DLL    : 8.1.0.14       115063 Bytes  20/05/2008 11:55:49
AEGEN.DLL     : 8.1.0.21       303477 Bytes  20/05/2008 11:55:49
AEEMU.DLL     : 8.1.0.6        430451 Bytes  20/05/2008 11:55:48
AECORE.DLL    : 8.1.0.29       168311 Bytes  20/05/2008 11:55:47
AVWINLL.DLL   : 1.0.0.7         14593 Bytes  23/01/2008 17:07:53
AVPREF.DLL    : 8.0.0.1         25857 Bytes  18/02/2008 10:37:50
AVREP.DLL     : 7.0.0.1        155688 Bytes  16/04/2007 13:26:47
AVREG.DLL     : 8.0.0.0         30977 Bytes  23/01/2008 17:07:49
AVARKT.DLL    : 1.0.0.23       307457 Bytes  12/02/2008 08:29:23
AVEVTLOG.DLL  : 8.0.0.11       114945 Bytes  28/02/2008 08:31:31
SQLITE3.DLL   : 3.3.17.1       339968 Bytes  22/01/2008 17:28:02
SMTPLIB.DLL   : 1.2.0.19        28929 Bytes  23/01/2008 17:08:39
NETNT.DLL     : 8.0.0.1          7937 Bytes  25/01/2008 12:05:10
RCIMAGE.DLL   : 8.0.0.35      2371841 Bytes  10/03/2008 14:37:25
RCTEXT.DLL    : 8.0.32.0        86273 Bytes  06/03/2008 12:02:11

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\programmi\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, 
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: martedì 20 maggio 2008  13:57

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'RaUI.exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'Smc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
29 processes with 29 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
      [INFO]      No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
      [INFO]      No virus was found!

Starting to scan the registry.
The registry was scanned ( '37' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
      [WARNING]   The file could not be opened!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bd51.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll1.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bd5d.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll2.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bd65.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll3.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [WARNING]   An error has occurred and the file was not deleted. ErrorID: 26004
      [WARNING]   
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll4.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bdd5.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll5.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bdda.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bde0.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf1.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bde4.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf2.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bde8.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bdee.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch1.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bdf4.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch2.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49dfcfa5.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bdf5.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit1.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49dfcfa6.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit2.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48a1bdf7.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdf4.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdf5.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfa6.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdf7.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdf6.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfa7.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdf8.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC23.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfa8.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC24.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdf9.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC27.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfaa.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC29.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfa9.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdfa.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC30.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfab.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC31.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdfb.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC32.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfac.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC39.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdfd.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdfc.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC40.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfad.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC42.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdfe.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC43.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfae.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC44.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbdff.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC45.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cc50.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC47.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbe01.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC48.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfaf.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC49.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbde0.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfb1.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC50.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cc52.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbe03.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cc54.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbde2.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cfb3.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbde4.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbe05.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cc56.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudCgp1.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '489bbe07.qua'!
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\SmitfraudCgp2.zip
      [DETECTION] Contains suspicious code GEN/PwdZIP
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '49e5cc58.qua'!
C:\Programmi\Softwin\BitDefender8\Quarantine\xwusuhzh.exe
      [DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
      [NOTE]      The file was deleted!
C:\WINDOWS\system32\jkkHxUMG.dll
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [NOTE]      The file was deleted!
C:\WINDOWS\system32\drivers\sptd.sys
      [WARNING]   The file could not be opened!
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 17:30   #11
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
Ricapitolando, dopo aver disabilitato il ripristino di sistema, fatto la pulizia dei file inutili e cancellato gli asd con ADS Scanner, vogliamo necessariamente in ordine (altrimenti dovrai comunque rifarli):
  1. log di A-squared scansione deep aggiornato ad oggi
  2. log di F-Secure OnLine oppure di Kaspersky Virus Removal Tool scaricato oggi
  3. log di Dr.Web CureIT scaricato oggi
  4. log di ESET SysInspector
  5. log di HiJackThis
  6. log di Gmer
  7. log di PrevxCSI

spybot e ad-aware non trovano, non perchè tu sia pulita, ma perchè sono abbastanza limitati...
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 17:31   #12
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
provvedo!
Grazie!
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 18:59   #13
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
posto il log di a-squared intanto.
Se devo mandarli tutti insieme una volta effettuate tutte le scansioni fatemelo sapere.
Altrimenti mando man mano che le faccio.
Grazie di nuovo a tutti!
Allegati
File Type: txt a2scan_080520-183903.txt (3.1 KB, 4 visite)
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 19:11   #14
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
mandali tutti insieme nel prossimo post o riedita il precendente
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 21:38   #15
xcdegasp
Senior Member
 
L'Avatar di xcdegasp
 
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
non non è necessario modificare quel messaggio, raggruppa tutti i log in un unico messaggio
xcdegasp è offline   Rispondi citando il messaggio o parte di esso
Old 20-05-2008, 23:07   #16
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
Dovrei essere quasi alla fine del lavoro però ho alcuni problemi:
1 non so come salvare il log di cureit, alla fine della scansione non vedo questa possibilità
2 devo mandare anche i log dei programmi che non hanno torvato infezioni?
3 il log di kasperscy è un file di testo di 86 MEGA non riesco a capire perchè, mi è impossibile mandarlo credo (comunque non ha trovato niente)
4e' normale che per il deep scan kaspersky abbia impiegato tre ore e venti minuti?
Considerata l'ora e il fatto che non ho ancora finito, vi posto tutto domani.
Grazie a tutti in anticipo e buonanotte!
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 21-05-2008, 00:38   #17
medea1000
Junior Member
 
Iscritto dal: May 2008
Messaggi: 28
Quote:
Originariamente inviato da medea1000 Guarda i messaggi
Dovrei essere quasi alla fine del lavoro però ho alcuni problemi:
1 non so come salvare il log di cureit, alla fine della scansione non vedo questa possibilità
2 devo mandare anche i log dei programmi che non hanno torvato infezioni?
3 il log di kasperscy è un file di testo di 86 MEGA non riesco a capire perchè, mi è impossibile mandarlo credo (comunque non ha trovato niente)
4e' normale che per il deep scan kaspersky abbia impiegato tre ore e venti minuti?
Considerata l'ora e il fatto che non ho ancora finito, vi posto tutto domani.
Grazie a tutti in anticipo e buonanotte!
5 come faccio a salvare il log di prevxcsi?
Grazie!
medea1000 è offline   Rispondi citando il messaggio o parte di esso
Old 21-05-2008, 07:41   #18
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
1 Fai start -> esegui digita %USERPROFILE%\DoctorWeb (invio) il log lo trovi li
2 si
3 lo apri e copi solo la parte dei rilevamenti che ci interessa
4 si
5 A fine scansione -> click dx sull'icona di prevx a fianco dell'ora -> View the result of your last scan online -> Una volta aperto il tuo browser predefinito copia tutta la riga dell'indirizzo ed incollalo nella discussione
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 21-05-2008, 08:05   #19
Angelus88
Bannato
 
Iscritto dal: Feb 2007
Città: Palermo
Messaggi: 13587
A nessuno di voi è venuto in mente che forse l'Userinit della chiave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon va editato manualmente togliendo la parte C:\WINDOWS\system32\xwusuhzh.exe ed eliminando quindi il relativo file?

Consiglio pure di controllare Shell che deve essere solo explorer.exe e consiglio di controllare che nella chiave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options non ci sia Explorer.exe e in caso affermativo, eliminarla
Angelus88 è offline   Rispondi citando il messaggio o parte di esso
Old 21-05-2008, 08:18   #20
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
per il momento è l'unica infezione che abbiamo visto, a parte qualcosa nell'unica scansione fatta ossia quella di a-squared, stavamo solo aspettando i log, anche se effettivamente era meglio segarlo subito
wjmat è offline   Rispondi citando il messaggio o parte di esso
 Rispondi


Star Wars Zero Company è l'erede di XCOM 2 Star Wars Zero Company è l'erede di XCOM ...
Test ride Can-Am Origin: la moto elettrica che fa dimenticare il motore a scoppio (ma occhio all'autonomia) Test ride Can-Am Origin: la moto elettrica che f...
Logitech G325, G305 e G316 X: il tris per chi non vuole rinunciare a nulla, spendendo poco Logitech G325, G305 e G316 X: il tris per chi no...
Recensione POCO F9 pro: potenza da vero top di gamma, display da 185 Hz e finalmente una fotocamera da prendere sul serio Recensione POCO F9 pro: potenza da vero top di g...
Tra audio e AI: la ricetta di Qualcomm per l'agentic AI Tra audio e AI: la ricetta di Qualcomm per l'age...
ESA e ClearSpace svilupperanno un satell...
Oracle, stock option da quasi un miliard...
Starship: si è conclusa anticipat...
Un computer quantistico ha funzionato ne...
Sovranità sui dati: AWS è ...
Il nuovo nome della distro Linux mobile ...
Due ventole da 220 mm e non solo: Cooler...
Truffa telefonica via Google Ads: il bro...
Google pensiona le Gems di Gemini: cosa ...
Flight 14: incertezza per un problema a ...
C'è un problema con i robot Tesla: i dip...
Raggi gamma anomali dalla Via Lattea sve...
NIO vende il 30% della divisione scambio...
Sony brevetta un DualSense capace di acc...
Un volto per l'assistenza IA: cosa pu&og...
Chromium
GPU-Z
OCCT
LibreOffice Portable
Opera One Portable
Opera One 106
CCleaner Portable
CCleaner Standard
Cpu-Z
Driver NVIDIA GeForce 546.65 WHQL
SmartFTP
Trillian
Google Chrome Portable
Google Chrome 120
VirtualBox
Tutti gli articoli Tutte le news Tutti i download

Strumenti

Regole
Non Puoi aprire nuove discussioni
Non Puoi rispondere ai messaggi
Non Puoi allegare file
Non Puoi modificare i tuoi messaggi

Il codice vB è On
Le Faccine sono On
Il codice [IMG] è On
Il codice HTML è Off
Vai al Forum


Tutti gli orari sono GMT +1. Ora sono le: 20:27.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
Served by www3v