| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| marione Mortale devoto
 
  
 
 Registrato: 24/08/07 18:47
 Messaggi: 9
 
 
 | 
			
				|  Inviato: 27 Ago 2007 17:59    Oggetto: portatile in crisi? |   |  
				| 
 |  
				| uso xp pro sp2, avg 7.5 e ( da poco ) outpost. 
 Il mio portatile ( dopo il mio desktop collegato in rete ) comincia a fare cose strane, vorrei un parere. vi posto il log di hijackthis:
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 13.17.07, on 27/08/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16512)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
 C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\igfxsrvc.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe
 C:\Programmi\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
 C:\WINDOWS\system32\dla\tfswctrl.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\Programmi\HPQ\Quick Launch Buttons\EabServr.exe
 C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\Programmi\Windows Media Player\WMPNSCFG.exe
 C:\Programmi\Microsoft Office\Office\OSA.EXE
 C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
 C:\pulizia\HiJackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgilio.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar3.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
 O4 - HKLM\..\Run: [SoundMAX] C:\Programmi\Analog Devices\SoundMAX\Smax4.exe /tray
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe"
 O4 - HKLM\..\Run: [PTHOSTTR] C:\Programmi\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
 O4 - HKLM\..\Run: [UpdateManager] "C:\Programmi\File comuni\Sonic\Update Manager\sgtray.exe" /r
 O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmi\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [Cpqset] C:\Programmi\HPQ\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [WatchDog] C:\Programmi\InterVideo\DVD Check\DVDCheck.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe /waitservice
 O4 - HKLM\..\Run: [OutpostFeedBack] C:\PROGRA~1\Agnitum\OUTPOS~1.0\feedback.exe /dump:os_startup
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [WMPNSCFG] C:\Programmi\Windows Media Player\WMPNSCFG.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Avvio Office.lnk = C:\Programmi\Microsoft Office\Office\OSA.EXE
 O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: DVD Check.lnk = C:\Programmi\InterVideo\DVD Check\DVDCheck.exe
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: Ricerca rapida.lnk = C:\Programmi\Microsoft Office\Office\FINDFAST.EXE
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
 O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\PROGRA~1\Agnitum\OUTPOS~1.0\Plugins\BrowserBar\ie_bar.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{2CC28EEC-0117-4E05-AFE5-DA2658E37DCA}: NameServer = 195.130.224.18,195.130.225.129
 O17 - HKLM\System\CS1\Services\Tcpip\..\{2CC28EEC-0117-4E05-AFE5-DA2658E37DCA}: NameServer = 195.130.224.18,195.130.225.129
 O17 - HKLM\System\CS2\Services\Tcpip\..\{2CC28EEC-0117-4E05-AFE5-DA2658E37DCA}: NameServer = 195.130.224.18,195.130.225.129
 O20 - AppInit_DLLs:  C:\PROGRA~1\Agnitum\OUTPOS~1.0\wl_hook.dll
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
 O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmi\HPQ\SHARED\HPQWMI.exe
 O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
 
 --
 End of file - 8310 bytes
 
 il link all'autostart  di Gmer:
 http://www.freefilehosting.net/download/MTYxMDk=
 
 e il link al rootkit:
 http://www.freefilehosting.net/download/MTYxMTE=
 
 grazie dell'aiuto, ciao
 |  |  
		| Top |  |  
		|  |  
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 27 Ago 2007 19:47    Oggetto: |   |  
				| 
 |  
				| I logs che hai postato non evidenziano cose strane...   Facciamo un altro controllo...
 Clicca qui (tieni premuto il tasto CTRL mentre clicchi).
 Salva il file, anche sul desktop se vuoi.
 Disattiva temporaneamente il tuo antivirus.
 Avvia il file appena scaricato (sys#####)
 Assicurati che tutte le voci siano spuntate.
 clicca su Scan now
 L'operazione può durare diversi minuti... abbi pazienza
   Al termine della scansione, ti verrà aperto il blocco note. Puoi chiuderlo tranquillamente.
 Chiudi il programma e riattiva il tuo antivirus.
 Carica il file c:\suspectfile\report.txt su http://www.freefilehosting.net
 Posta qui il link che ti viene assegnato.
 |  |  
		| Top |  |  
		|  |  
		| marione Mortale devoto
 
  
 
 Registrato: 24/08/07 18:47
 Messaggi: 9
 
 
 | 
			
				|  Inviato: 27 Ago 2007 20:32    Oggetto: |   |  
				| 
 |  
				| il link al report del sys##### è: http://www.freefilehosting.net/download/MTYxNzI=
 
 Grazie ciao
 |  |  
		| Top |  |  
		|  |  
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 27 Ago 2007 20:56    Oggetto: |   |  
				| 
 |  
				| Purtroppo il log è incompleto...   Dovresti rifarlo.
 |  |  
		| Top |  |  
		|  |  
		| marione Mortale devoto
 
  
 
 Registrato: 24/08/07 18:47
 Messaggi: 9
 
 
 | 
			
				|  Inviato: 27 Ago 2007 22:12    Oggetto: |   |  
				| 
 |  
				| spero che questo sia buono: 
 http://www.freefilehosting.net/download/MTYxOTI=
 
 ciao
 |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |