| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| anninats Comune mortale
 
  
 
 Registrato: 05/02/08 11:55
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 05 Feb 2008 12:10    Oggetto: Dialer trojan 2026  :-( |   |  
				| 
 |  
				| Ciao a tutti! Siete la mia ultima speranza.. non riesco a cancellare sto trojan..
 dunque, spesso mi viene un avviso di Norton che rileva un file nei Temporary Internet Files, un certo 2026.exe o 2026[1].exe pero' non riesce a cancellarlo, semplicemente non lo esegue.
 Nel registro di sistema nella cartella di Internet Explorer ho trovato strane voci: netvision.exe, 2026.exe  e le ho cancellate ma continuano a venire sti avvisi di Norton..
 tra l'altro se uso Internet Explorer mi si blocca tutto e infatti sono collegata con Firefox adesso...
 ho provato a fare la scansione con SuperAntiSpyware ma non mi trova nulla.
 
 ps:ho un Windows Me (e' il pc di mia mamma ahime'!)
 
 vi posto il log di hijack:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 11.01.32, on 05/02/2008
 Platform: Windows ME (Win9x 4.90.3000)
 MSIE: Internet Explorer v5.50 (5.50.4134.0100)
 
 Running processes:
 C:\WINDOWS\SYSTEM\KERNEL32.DLL
 C:\WINDOWS\SYSTEM\MSGSRV32.EXE
 C:\WINDOWS\SYSTEM\MPREXE.EXE
 C:\WINDOWS\SYSTEM\MSTASK.EXE
 C:\WINDOWS\CARPSERV.EXE
 C:\WINDOWS\SYSTEM\mmtask.tsk
 C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
 C:\WINDOWS\EXPLORER.EXE
 C:\WINDOWS\SYSTEM\CMMPU.EXE
 C:\WINDOWS\TASKMON.EXE
 C:\WINDOWS\SYSTEM\SYSTRAY.EXE
 C:\WINDOWS\SYSTEM\WMIEXE.EXE
 C:\PROGRAMMI\PCI AUDIO APPLICATIONS\MIXER.EXE
 C:\PROGRAMMI\NORTON ANTIVIRUS\NAVAPW32.EXE
 C:\PROGRAMMI\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
 C:\PROGRAMMI\INTERNET EXPLORER\IEXPLORE.EXE
 C:\PROGRAMMI\INTERNET EXPLORER\IEXPLORE.EXE
 C:\WINDOWS\WUAUCLT.EXE
 C:\PROGRAMMI\MOZILLA FIREFOX\FIREFOX.EXE
 C:\WINDOWS\NOTEPAD.EXE
 C:\PROGRAMMI\H\HIJACKTH.EXE
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.libero.it
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.it
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 F1 - win.ini: run=C:\WINDOWS\SYSTEM\cmmpu.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMI\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
 O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
 O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
 O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
 O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
 O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
 O4 - HKLM\..\Run: [C-Media Mixer] C:\Programmi\PCI Audio Applications\Mixer.exe /startup
 O4 - HKLM\..\Run: [CARPService] carpserv.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
 O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
 O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
 O4 - HKLM\..\Run: [idmsnn] Wscript C:\WINDOWS\LICENSEMSE.VBS /B
 O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
 O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
 O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
 O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
 O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAMMI\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
 O4 - Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
 O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAMMI\SUPERANTISPYWARE\SASWINLO.DLL
 
 Annalisa [/b]
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| ste_95 Dio maturo
 
  
  
 Registrato: 03/08/07 14:41
 Messaggi: 1920
 Residenza: Italy
 
 | 
			
				|  Inviato: 05 Feb 2008 15:57    Oggetto: |   |  
				| 
 |  
				| Il log di hijackthis che hai postato è tagliato. |  | 
	
		| Top |  | 
	
		|  | 
	
		| anninats Comune mortale
 
  
 
 Registrato: 05/02/08 11:55
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 05 Feb 2008 17:28    Oggetto: |   |  
				| 
 |  
				| Logfile of HijackThis v1.99.1 Scan saved at 16.44.44, on 05/02/2008
 Platform: Windows ME (Win9x 4.90.3000)
 MSIE: Internet Explorer v5.50 (5.50.4134.0100)
 
 Running processes:
 C:\WINDOWS\SYSTEM\KERNEL32.DLL
 C:\WINDOWS\SYSTEM\MSGSRV32.EXE
 C:\WINDOWS\SYSTEM\MPREXE.EXE
 C:\WINDOWS\SYSTEM\MSTASK.EXE
 C:\WINDOWS\CARPSERV.EXE
 C:\WINDOWS\SYSTEM\mmtask.tsk
 C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
 C:\WINDOWS\EXPLORER.EXE
 C:\WINDOWS\SYSTEM\CMMPU.EXE
 C:\WINDOWS\TASKMON.EXE
 C:\WINDOWS\SYSTEM\SYSTRAY.EXE
 C:\WINDOWS\SYSTEM\WMIEXE.EXE
 C:\PROGRAMMI\PCI AUDIO APPLICATIONS\MIXER.EXE
 C:\PROGRAMMI\NORTON ANTIVIRUS\NAVAPW32.EXE
 C:\PROGRAMMI\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
 C:\WINDOWS\WUAUCLT.EXE
 C:\PROGRAMMI\MOZILLA FIREFOX\FIREFOX.EXE
 C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
 C:\WINDOWS\SYSTEM\SPOOL32.EXE
 C:\WINDOWS\REGEDIT.EXE
 C:\PROGRAMMI\H\HIJACKTH.EXE
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.libero.it
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.it
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 F1 - win.ini: run=C:\WINDOWS\SYSTEM\cmmpu.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMI\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
 O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
 O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
 O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
 O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
 O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
 O4 - HKLM\..\Run: [C-Media Mixer] C:\Programmi\PCI Audio Applications\Mixer.exe /startup
 O4 - HKLM\..\Run: [CARPService] carpserv.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
 O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
 O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
 O4 - HKLM\..\Run: [idmsnn] Wscript C:\WINDOWS\LICENSEMSE.VBS /B
 O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
 O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
 O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
 O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
 O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAMMI\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
 O4 - Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
 O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAMMI\SUPERANTISPYWARE\SASWINLO.DLL
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| anninats Comune mortale
 
  
 
 Registrato: 05/02/08 11:55
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 05 Feb 2008 18:21    Oggetto: |   |  
				| 
 |  
				| Ciao, innanzitutto grazie ... poi ho provato a fare quello che hai detto ma.. sul mio pc nelle proprieta non c'e' disattiva ecc.. il norman non mi si apre e in modalita' provvoria non mi funzia il mouse quindi e' tutto un casino con la tastiera.. il cureit non mi ha segnalato nessun virus in modalita' normale..
 
 pero' nel registro del sistema ho un sacco di file strani:
 sotto Local mashine/system/current control set/session manager
 
 e poi in task manager quando apro il pc mi vengono 2 iexplore anche se non ho aperto Internet Explorer...
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |