| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| Dany DJ Mortale pio
 
  
 
 Registrato: 11/06/07 23:14
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 15 Dic 2007 18:42    Oggetto: due bei virus: msdtcsw32.exe + tabletgen32.dll help me! :( |   |  
				| 
 |  
				| Ciao a tutti ragazzi, il mio Antivir ha rivelato questi due bei virus  : 
 c:\windows\msdtcsw32.exe
 tr/dldr.agent.eaa
 
 c:\windows\tabletgen32.dll
 heur/malware
 
 eccovi il log di Hijackthis:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 17.19.55, on 15/12/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 C:\PROGRA~1\Iomega\System32\AppServices.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\PROGRA~1\FILECO~1\PCSuite\DATALA~1\DATALA~1.EXE
 C:\Programmi\iTunes\iTunesHelper.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
 C:\PROGRA~1\FILECO~1\PCSuite\Services\SERVIC~1.EXE
 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
 C:\Programmi\iPod\bin\iPodService.exe
 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
 C:\WINDOWS\system32\NOTEPAD.EXE
 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
 C:\Programmi\AntiVir PersonalEdition Classic\GUARDGUI.EXE
 C:\Documents and Settings\Dany\Desktop\hijackthis_199\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
 O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\FILECO~1\PCSuite\DATALA~1\DATALA~1.EXE
 O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
 O4 - HKCU\..\Run: [ViewSonic Explorer V5.3] C:\WINDOWS\msdtcsw32.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
 O8 - Extra context menu item: &eBay Search - res://C:\Programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
 O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{BFD1C565-2569-4368-B4B6-D0D38E8959D7}: NameServer = 62.94.0.1,212.216.112.112
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 
 Grazie mille per la vostra attenzione ragazzi
 
 A presto
 
 Daniele
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 15 Dic 2007 21:30    Oggetto: |   |  
				| 
 |  
				| Ciao Dany DJ   Disattiva il ripristino di sistema e avvia il PC in modalità provvisoria
 Avvia Hijackthis e seleziona a sinistra queste righe:
 
  	  | Citazione: |  	  | O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKCU\..\Run: [ViewSonic Explorer V5.3] C:\WINDOWS\msdtcsw32.exe
 | 
 Clicca fix Checked e rispondi si.
 Se qualche voce non compare in modalità provvisoria fixala alla modalità normale.
 Riavvia il PC alla modalità normale e posta un nuovo log di HJT.
 Poi guarda questa discussione relativa a Combofix e fai la scansione del PC, caricando il risultato su www.freefilehosting.net. Per sicurezza fai passare anche Virit
 Aggiornalo mediante l'icona della parabola posta nella barra in alto e fagli fare la scansione completa del PC.
 Fai in modo che rimuova automaticamente i file infetti trovati.
 Non dimenticare di disattivare momentaneamente il tuo antivirus.
 Incolla poi quì il risultato.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Dany DJ Mortale pio
 
  
 
 Registrato: 11/06/07 23:14
 Messaggi: 19
 
 
 | 
			
				|  Inviato: 15 Dic 2007 23:18    Oggetto: |   |  
				| 
 |  
				| Ciao Sante, grazie mille per il tuo aiuto!   Prima che tu mi rispondessi, ho provato a fare una scansione antivirus in modalità provvisoria, così facendo il mio antivir ha trovato un virus che in modalità normale non trovava...che si chiama: "acledit32.dll", lo ha eliminato e al riavvio normale non c'era traccia di nessun virus. Invece quelle due voci da te consigliate di fixare non sono state eliminate. Ora ho fatto come mi hai detto ed eccoti il log:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 22.05.00, on 15/12/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\PROGRA~1\FILECO~1\PCSuite\DATALA~1\DATALA~1.EXE
 C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
 C:\Programmi\iTunes\iTunesHelper.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
 C:\PROGRA~1\FILECO~1\PCSuite\Services\SERVIC~1.EXE
 C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 C:\PROGRA~1\Iomega\System32\AppServices.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\iPod\bin\iPodService.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Documents and Settings\Dany\Desktop\hijackthis_199\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
 O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\FILECO~1\PCSuite\DATALA~1\DATALA~1.EXE
 O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
 O8 - Extra context menu item: &eBay Search - res://C:\Programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
 O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{BFD1C565-2569-4368-B4B6-D0D38E8959D7}: NameServer = 62.94.0.1,212.216.112.112
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 
 
 Io credo che ora è tutto ok....che ne dici?
 
 Grazie ancora
   
 Daniele
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 16 Dic 2007 10:09    Oggetto: |   |  
				| 
 |  
				| Si, il log di HJT sembra pulito. Hai fatto poi questo?
 
  	  | Sante62 ha scritto: |  	  | Poi guarda questa discussione relativa a Combofix e fai la scansione del PC, caricando il risultato su www.freefilehosting.net.
 
 | 
 e questo?
 
  	  | Sante62 ha scritto: |  	  | Per sicurezza fai passare anche Virit
 Aggiornalo mediante l'icona della parabola posta nella barra in alto e fagli fare la scansione completa del PC.
 Fai in modo che rimuova automaticamente i file infetti trovati.
 Non dimenticare di disattivare momentaneamente il tuo antivirus.
 Incolla poi quì il risultato.
 | 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |