| Precedente :: Successivo   | 
	
	
	
		| Autore | 
		Messaggio | 
	
	
		golclaudio Semidio
  
 
  Registrato: 30/12/06 22:57 Messaggi: 205
 
  | 
		
			
				 Inviato: 02 Mag 2008 20:30    Oggetto: [RISOLTO] win32:Dialer-gen[Try] | 
				     | 
			 
			
				
  | 
			 
			
				vi posto il file log di Hijackthis per un controllo grazie
 
 
 	  | Codice: | 	 		  Logfile of Trend Micro HijackThis v2.0.2
 
Scan saved at 20.59.06, on 02/05/2008
 
Platform: Windows XP SP2 (WinNT 5.01.2600)
 
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
 
Boot mode: Normal
 
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
 
C:\WINDOWS\system32\winlogon.exe
 
C:\WINDOWS\system32\services.exe
 
C:\WINDOWS\system32\lsass.exe
 
C:\WINDOWS\system32\Ati2evxx.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\Programmi\Windows Defender\MsMpEng.exe
 
C:\WINDOWS\System32\svchost.exe
 
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 
C:\Programmi\Alwil Software\Avast4\ashServ.exe
 
C:\WINDOWS\system32\Ati2evxx.exe
 
C:\WINDOWS\Explorer.EXE
 
C:\WINDOWS\system32\spoolsv.exe
 
C:\WINDOWS\AGRSMMSG.exe
 
C:\Programmi\Apoint2K\Apoint.exe
 
C:\Programmi\TOSHIBA\E-KEY\CeEKey.exe
 
C:\Programmi\TOSHIBA\TouchPad\TPTray.exe
 
C:\WINDOWS\system32\ZoomingHook.exe
 
C:\WINDOWS\system32\TCtrlIOHook.exe
 
C:\WINDOWS\system32\TPSMain.exe
 
C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 
C:\Programmi\TOSHIBA\Touch and Launch\PadExe.exe
 
C:\Programmi\TOSHIBA\Tvs\TvsTray.exe
 
C:\WINDOWS\system32\dla\tfswctrl.exe
 
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
 
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
 
C:\Programmi\Windows Defender\MSASCui.exe
 
C:\Programmi\Apoint2K\Apntex.exe
 
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
C:\Programmi\TOSHIBA\ConfigFree\CFSServ.exe
 
C:\WINDOWS\system32\TPSBattM.exe
 
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
 
C:\Programmi\Prevx2\PXConsole.exe
 
C:\WINDOWS\system32\ctfmon.exe
 
C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
 
C:\Programmi\a-squared Free\a2service.exe
 
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 
C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
 
C:\WINDOWS\system32\DVDRAMSV.exe
 
C:\WINDOWS\runservice.exe
 
C:\Programmi\Skype\Phone\Skype.exe
 
C:\Programmi\Prevx2\PXAgent.exe
 
C:\WINDOWS\System32\PAStiSvc.exe
 
C:\WINDOWS\system32\svchost.exe
 
C:\VEXPLITE\viritsvc.exe
 
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
 
C:\Programmi\TOSHIBA\ConfigFree\CFXFER.exe
 
C:\WINDOWS\system32\RAMASST.exe
 
C:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
 
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
 
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
 
C:\Programmi\Skype\Plugin Manager\skypePM.exe
 
C:\Programmi\Windows Live\Messenger\usnsvc.exe
 
C:\Programmi\Internet Explorer\IEXPLORE.EXE
 
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
 
C:\Programmi\Toshiba\TOSHIBA Controls\TFncKy.exe
 
C:\WINDOWS\system32\igfxsrvc.exe
 
C:\Programmi\Outlook Express\msimn.exe
 
C:\Documents and Settings\claudio\Documenti\sicurezza\Hijackthis\HiJackThis.exe
 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.claudio71.altervista.org/
 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
 
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Programmi\Windows Desktop Search\dsWebAllow.dll
 
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Dati applicazioni\Prevx\pxbho.dll
 
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
 
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
 
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
 
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 
O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint2K\Apoint.exe
 
O4 - HKLM\..\Run: [CeEKEY] C:\Programmi\TOSHIBA\E-KEY\CeEKey.exe
 
O4 - HKLM\..\Run: [TPNF] C:\Programmi\TOSHIBA\TouchPad\TPTray.exe
 
O4 - HKLM\..\Run: [HWSetup] C:\Programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
 
O4 - HKLM\..\Run: [SVPWUTIL] C:\Programmi\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
 
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
 
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
 
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
 
O4 - HKLM\..\Run: [SmoothView] C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
 
O4 - HKLM\..\Run: [PadTouch] C:\Programmi\TOSHIBA\Touch and Launch\PadExe.exe
 
O4 - HKLM\..\Run: [Tvs] C:\Programmi\TOSHIBA\Tvs\TvsTray.exe
 
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
 
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
 
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
 
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmi\Windows Defender\MSASCui.exe" -hide
 
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
 
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
 
O4 - HKLM\..\Run: [PrevxOne] "C:\Programmi\Prevx2\PXConsole.exe"
 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
 
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
 
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
 
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
 
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
 
O4 - Global Startup: Bluetooth Manager.lnk = ?
 
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
 
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
 
O4 - Global Startup: Windows Desktop Search.lnk = C:\Programmi\Windows Desktop Search\WindowsSearch.exe
 
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
 
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
 
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
 
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 
O12 - Plugin for .UVR: C:\Programmi\Internet Explorer\Plugins\NPUPano.dll
 
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
 
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
 
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
 
O16 - DPF: {62BA437C-7712-48C6-9F0B-D251FA43192B} (SayaTV Control) - http://www.sayatv.com/download/SayaTV.cab
 
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://www.tele2mail.com/static/apps/utils/AccountHelper.cab
 
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
 
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
 
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
 
O23 - Service: Ad-Aware 2007 Service (aawservice) - Unknown owner - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe (file missing)
 
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
 
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
 
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
 
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
 
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
 
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
 
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
 
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
 
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
 
O23 - Service: PREVXAgent - Prevx - C:\Programmi\Prevx2\PXAgent.exe
 
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
 
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas   www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
 
 
--
 
End of file - 11364 bytes
 
 | 	  
 
 
Ho un paio di file in quarantena ma credo ci sia qualcos'altro che no va...... | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		bdoriano Amministratore
  
  
  Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
  | 
		
			
				 Inviato: 02 Mag 2008 21:20    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				VirIT è la versione trial? Per caso è già scaduta?
 
Se è già scaduta, disinstallala perché procura notevoli rallentamenti al pc.
 
 | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		golclaudio Semidio
  
 
  Registrato: 30/12/06 22:57 Messaggi: 205
 
  | 
		
			
				 Inviato: 02 Mag 2008 23:29    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				 	  | bdoriano ha scritto: | 	 		  VirIT è la versione trial? Per caso è già scaduta?
 
Se è già scaduta, disinstallala perché procura notevoli rallentamenti al pc.
 
 | 	  
 
 
ecco il log di Norman Malware Cleaner
 
NFix_2008-05-02_21-49-24.log
 
 
il log di combofix
 
ComboFix55.txt
 
 
ed il nuovo di Hijackthis
 
hijackthis529.log | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		golclaudio Semidio
  
 
  Registrato: 30/12/06 22:57 Messaggi: 205
 
  | 
		
			
				 Inviato: 04 Mag 2008 18:29    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				| uppo | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		chemicalbit Dio maturo
  
  
  Registrato: 01/04/05 18:59 Messaggi: 18597 Residenza: Milano
  | 
		
			
				 Inviato: 04 Mag 2008 19:48    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Sia Norman Mal. Cl. che Combofix hanno eliminato dei file.
 
 
Vediamo se c'è altro da eliminare
 
 
Fai una scansione con Kaspersky Virus Removal tool, come spiegato in questo messaggio
 
 
e poi posta qui un link al log
 
(log che probabilmente sarà enrome, crea un file con solo le prime parti, poi salta la lunga sezione "events", e metti le sezioni finali seguenti). | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		golclaudio Semidio
  
 
  Registrato: 30/12/06 22:57 Messaggi: 205
 
  | 
		
			
				 Inviato: 04 Mag 2008 23:34    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				ecco il log
 
 
kap.txt | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		bdoriano Amministratore
  
  
  Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
  | 
		
			
				 Inviato: 05 Mag 2008 22:25    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Kaspersky ha trovato solo l'EICAR test.
 
Combofix ha eliminato un paio di files sospetti.
 
Nel log di hijackthis non si vedono voci strane.
 
 
Che problemi riscontri? | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		golclaudio Semidio
  
 
  Registrato: 30/12/06 22:57 Messaggi: 205
 
  | 
		
			
				 Inviato: 05 Mag 2008 23:27    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				dopo questa ripulita mi pare sia tutto ok!
 
 
In caso contrario mi rifarò vivo, grazie per il momento! | 
			 
		  | 
	
	
		| Top | 
		 | 
	
	
		  | 
	
	
		 |