| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| ballack01 Eroe
 
  
 
 Registrato: 21/05/08 00:19
 Messaggi: 60
 Residenza: capriolo(bs)
 
 | 
			
				|  Inviato: 16 Giu 2010 01:34    Oggetto: Dubbio mio... |   |  
				| 
 |  
				| salve...aprendo prima task manager windows ho trovato un programma a me sconosciuto chiamato gm4ie.exe....documentandomi su internet mi è sembrato di capire che sia un malware ma non ne sono sicuro...attendo vostro chiarimento e consigli eventuali... 
 Piattaforma: Win NT 5.1 (2600.Service Pack 3)
 Microsoft Windows XP
 Numero di serie: 84876-600-9507815-04992
 Nome computer: OEM-RC6REE3KD71
 BIOS: KM400  - 42302e31Phoenix - AwardBIOS v6.00PGPhoenix - AwardBIOS v6.00PG 11/04/03
 CPU: AMD Athlon(tm) XP 2400+
 Scheda video: VIA/S3G KM400/KN400
 Monitor: Monitor Plug and Play
 Memoria: 735 Mb
 Lingua della tastiera: Italiano (Italia)
 
 e ora il log di hijackthis:
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 1.25.46, on 16/06/2010
 Platform: Windows XP SP3 (WinNT 5.01.2600)
 MSIE: Internet Explorer v8.00 (8.00.6001.18702)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programmi\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\ZONELABS\vsmon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe
 C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
 C:\WINDOWS\System32\PAStiSvc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Generic\USB Card Reader Driver v1.9e3\Disk_Monitor.exe
 C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Programmi\ESET\ESET NOD32 Antivirus\egui.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\Messenger\msmsgs.exe
 C:\WINDOWS\system32\taskmgr.exe
 C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
 C:\Programmi\Windows Media Player\wmplayer.exe
 C:\Programmi\Megaupload\Mega Manager\MegaManager.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
 H:\Setup\HiJackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
 O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Programmi\Megaupload\Mega Manager\MegaIEMn.dll
 O4 - HKLM\..\Run: [Disk Monitor] C:\Programmi\Generic\USB Card Reader Driver v1.9e3\Disk_Monitor.exe
 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
 O4 - HKLM\..\Run: [egui] "C:\Programmi\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [GM4IE] C:\Programmi\SocialPlus\gm4ie.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
 O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{33E448CD-0EE1-4FC6-A400-5F57C8630964}: NameServer = 85.37.17.7 85.38.28.95
 O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Programmi\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
 O23 - Service: ESET Service (ekrn) - ESET - C:\Programmi\ESET\ESET NOD32 Antivirus\ekrn.exe
 O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
 O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
 O23 - Service: ServiceLayer - Nokia - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZONELABS\vsmon.exe
 
 --
 End of file - 5555 bytes
 |  |  
		| Top |  |  
		|  |  
		| HackYourMind Mortale pio
 
  
 
 Registrato: 04/06/10 09:39
 Messaggi: 17
 
 
 | 
			
				|  Inviato: 16 Giu 2010 12:07    Oggetto: |   |  
				| 
 |  
				| Per caso usi Greasemonkey for IE ? 
 perchè potrebbe essere quella estensione la trovi qui: link
 |  |  
		| Top |  |  
		|  |  
		| R16 Dio maturo
 
  
  
 Registrato: 07/03/08 22:58
 Messaggi: 10129
 
 
 | 
			
				|  Inviato: 16 Giu 2010 13:17    Oggetto: |   |  
				| 
 |  
				| Ciao. Quel file,(gm4ie.exe ) è collegato (nel tuo caso) a questo programma: SocialPlus, che a sua volta, è relazionato con Facebook.
 link
 link
 Penso che, lo hai scaricato tu, visto per cosa serve.
 |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |