| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| noizy83 Comune mortale
 
  
 
 Registrato: 17/06/07 14:12
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 17 Giu 2007 15:53    Oggetto: Malware: Video ActiveX Object |   |  
				| 
 |  
				| Salve a tutti, sono giorni che sono alle prese con un virus, un malware, non ho ben capito, so soltanto che mi crea diversi problemi e che vorrei eliminarlo definitivamente. Preciso che nè avast, nè AdAware, nè Spy Doctor hanno risolto il problema.
 Vi sottopongo il log file ottenuto con Hijackthis nella speranza che possiate fare qualosa.
 Grazie.
 
 Logfile of HijackThis v1.99.1
 Scan saved at 4.16.14, on 17/06/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16473)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 C:\Programmi\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Spyware Doctor\svcntaux.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Video ActiveX Access\iesmn.exe
 C:\WINDOWS\system32\sistray.EXE
 C:\Programmi\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
 C:\Program Files\Logitech\iTouch\iTouch.exe
 C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 C:\Programmi\Java\jre1.5.0_04\bin\jusched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Winamp\winampa.exe
 C:\Programmi\Picasa2\PicasaMediaDetector.exe
 C:\WINDOWS\system32\Ma10Pan.Exe
 C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
 C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
 C:\Programmi\DAEMON Tools\daemon.exe
 C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
 C:\Programmi\Lexmark 3300 Series\lxccmon.exe
 C:\WINDOWS\FixCamera.exe
 C:\WINDOWS\tsnpstd3.exe
 C:\WINDOWS\vsnpstd3.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Programmi\Spyware Doctor\SDTrayApp.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\MSN Messenger\msnmsgr.exe
 C:\Programmi\MySpace\IM\MySpaceIM.exe
 C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 C:\Programmi\Google\Google Updater\GoogleUpdater.exe
 C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\system32\lxcccoms.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Yahoo!\Messenger\ymsgr_tray.exe
 C:\Programmi\Spyware Doctor\swdsvc.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
 C:\Programmi\Mozilla Firefox\firefox.exe
 C:\Programmi\WinAce\WinAce.exe
 C:\DOCUME~1\User\IMPOST~1\Temp\~AceTemp\hijackthis\HijackThis.exe
 
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:80
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;192.168.1.1
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: (no name) - {A1176E34-1792-4D69-9B53-B430C475C177} - C:\WINDOWS\system32\tlntsvrq.dll (file missing)
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
 O2 - BHO: (no name) - {B8C5186E-EC37-4889-9C2E-F73649FFB7BB} - C:\Programmi\Video ActiveX Access\iesplg.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
 O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
 O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
 O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programmi\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
 O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
 O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
 O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
 O4 - HKLM\..\Run: [EPSON Stylus C46 Series (Copia 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P33 "EPSON Stylus C46 Series (Copia 1)" /O6 "USB001" /M "Stylus C46"
 O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_04\bin\jusched.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
 O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmi\Picasa2\PicasaMediaDetector.exe
 O4 - HKLM\..\Run: [Ma10Pan] Ma10Pan.Exe
 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programmi\File comuni\Roxio Shared\System\EngUtil.exe"
 O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
 O4 - HKLM\..\Run: [H2O] C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
 O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
 O4 - HKLM\..\Run: [LXCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
 O4 - HKLM\..\Run: [lxccmon.exe] "C:\Programmi\Lexmark 3300 Series\lxccmon.exe"
 O4 - HKLM\..\Run: [FaxCenterServer] "C:\Programmi\Lexmark Fax Solutions\fm3032.exe" /s
 O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
 O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
 O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programmi\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
 O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [SDTray] "C:\Programmi\Spyware Doctor\SDTrayApp.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Programmi\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe" -quiet
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [MySpaceIM] C:\Programmi\MySpace\IM\MySpaceIM.exe
 O4 - Startup: ubisoft register.lnk = C:\Programmi\Ubi Soft\Register\schedule.exe
 O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
 O4 - Global Startup: Google Updater.lnk = C:\Programmi\Google\Google Updater\GoogleUpdater.exe
 O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesit.dll
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesit.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O11 - Options group: [INTERNATIONAL] International*
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
 O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
 O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{6F03C3B6-664D-4EE5-95C0-6B04A260D1AA}: NameServer = 85.37.17.17 85.38.28.72
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Programmi\FileZilla Server\FileZilla Server.exe (file missing)
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
 O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
 O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Unknown owner - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (file missing)
 O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Unknown owner - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
 |  |  
		| Top |  |  
		|  |  
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 18 Giu 2007 07:54    Oggetto: |   |  
				| 
 |  
				| Ciao noizy83,   
 Avvia il pc in modalità provvisoria.
 Avvia HijackThis
 clicca su do a system scan only
 metti il segno di spunta a queste voci:
 
  	  | Citazione: |  	  | O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {A1176E34-1792-4D69-9B53-B430C475C177} - C:\WINDOWS\system32\tlntsvrq.dll (file missing)
 O2 - BHO: (no name) - {B8C5186E-EC37-4889-9C2E-F73649FFB7BB} - C:\Programmi\Video ActiveX Access\iesplg.dll
 O4 - HKLM\..\Run: [Ma10Pan] Ma10Pan.Exe
 O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Inst all3.0/Installer.exe
 | 
 clicca su fix checked
 Riavvia il pc, rifai il log di hijackthis e ripostalo.
 
 2° passaggio:
 scarica questo.
 Avvialo
 Scegli 1 e conferma con invio
 Viene creato un log (C:\rapport.txt), posta anche quello.
 
 questo cos'è?
 
  	  | Citazione: |  	  | O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Programmi\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200 | 
 Se serve a patchare il limite delle connessioni con XP SP2, esistono altri sistemi che non necessitano di caricare programmi all'avvio.
 
 PS: se vuoi, puoi presentarti qui
 |  |  
		| Top |  |  
		|  |  
		| noizy83 Comune mortale
 
  
 
 Registrato: 17/06/07 14:12
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 18 Giu 2007 19:27    Oggetto: |   |  
				| 
 |  
				| Salve bdoriano, purtroppo al momento sono fuori casa per motivi di studio, ma entro giovedì ti saprò dare risposte su cosa ho trovato.
 Intanto grazie per l'aiuto.
 |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |