![]() |
|
#1
|
|||
|
|||
|
Hi there,
Ho notato che ho avuto un problema quando ho sentito la riproduzione di musica misteriosamente. Ho controllato e ho visto un sacco di processi in esecuzione IEXPLORE.EXE. I NAV corse, Ad-Aware, Defender e poi seguite le istruzioni che hai fornito. Grazie in anticipo per l'aiuto. Qui ci sono i log: SUPERAntiSpyware Scan Entra http://www.superantispyware.com Generata 01/19/2008 alle 08:53 AM Applicazione Versione: 3/9/1008 Core Regole Database Version: 3384 Trace Regole Database Version: 1378 Tipo di scansione: Scansione completa Totale Scan Time: 01:01:52 Memoria oggetti scanditi: 576 Memoria minacce rilevate: 0 Registro di oggetti scanditi: 7837 Registro di minacce rilevate: 0 File oggetti scanditi: 66011 File minacce rilevate: 60 Adware.Tracking Cookie C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ advertpro [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ revsci [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ cgi-bin [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@richmedia.yahoo [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ eyewonder [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ hc [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@sales.liveperson [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ html [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@www.burstnet [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@www.crackpassword [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@umkxup22.unitedme giorno [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@click.mgg01 [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ adcentriconline [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@ad1.soundpedia [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ adbrite [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@iacas.adbureau [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ indiads [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@microsoftwga.112. 2o7 [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@ads.cnn [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@ads.monster [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@server.iad.livepe rson [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@ads3.blastro [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@mailtrack.rnm [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@track.bestbuy [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ atwola [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ 85084061 [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@server.lon.livepe rson [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ PartyPoker sundeep @ [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep@ads.as4x.tmcs [2]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ XiTi [1]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ tribalfusion [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@ad.yieldman ager [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@ad.yieldman ager [3]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ adbrite [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ adecn [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@ads.128b [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@adserver.ea syad [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ apmebf [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ atdmt [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ banner [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ clicksor [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ @ doppio sistema [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ rafforzare [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ euros4click [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ fastclick [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ FindWhat [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ PartyPoker [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ pro-mercato [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ statcounter [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@stats.adbri te [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ toseeka [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@tracker.aff istats [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@www.findit-quick [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@www.goaltra ffic [2]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@www.goaltra ffic [3]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@www.goodcli CKZ [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system@www.kikclic k [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ system @ Zedo [1]. Txt C: \ Documents and Settings \ NetworkService \ Cookies \ @ Zedo sistema [3]. Txt C: \ Documents and Settings \ sundeep \ Cookies \ sundeep @ burstnet [2]. Txt # Version = 4 # OnlineScanner.ocx = 1.0.0.56 # OnlineScannerDLLA.dll = 1, 0, 0, 51 # OnlineScannerDLLW.dll = 1, 0, 0, 51 # OnlineScannerUninstaller.exe = 1, 0, 0, 49 # Vers_standard_module = 2806 (20080118) # Vers_arch_module = 1,063 (20080117) # Vers_adv_heur_module = 1,060 (20070601) # EOSSerial = 5ac60436be4e8c4d8b34206de1ddeb01 # End = finito # Remove_checked = true # Unwanted_checked = true # Utc_time = 2008-01-19 03:34:06 # Local_time = 2008-01-19 10:34:06 (-0500, Eastern Standard Time) # Paese = "Stati Uniti" OSVer = # 5/1/2600 NT Service Pack 2 Scandite = 394948 # # Trovati = 14 # Scan_time = 2493 C: \ MSInfnd.exe probabilmente una variante del trojan Win32/Hupigon (non per la pulizia - soppresso) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-34ef6dbc più infiltrazioni (soppresso) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-34ef6dbc »ZIP» BlackBox.class una variante di Java / ClassLoader trojan (errore durante la pulizia - operazione non disponibile per questo tipo di oggetto - errore durante l'eliminazione - operazione non disponibile per questo tipo di oggetto - è stata una parte del soppresso oggetto) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-34ef6dbc »ZIP» VerifierBug.class JS / IEStart.G trojan (errore durante la pulizia - operazione non disponibile per questo tipo di oggetto - errore durante l'eliminazione - operazione non disponibile per questo tipo di oggetto - è stata una parte del soppresso oggetto) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-34ef6dbc »ZIP» Dummy.class Java / NoCheat.B trojan (errore durante la pulizia - operazione non disponibile per questo tipo di oggetto - errore durante l'eliminazione - operazione non disponibile per questo tipo di oggetto - è stata una parte del soppresso oggetto) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-3f7c5e12 una variante di Java / ClassLoader trojan (soppresso) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-3f7c5e12 »ZIP» BlackBox.class una variante di Java / ClassLoader trojan (errore durante la pulizia - operazione non disponibile per questo tipo di oggetto - errore durante l'eliminazione - operazione non disponibile per questo tipo di oggetto - è stata una parte del soppresso oggetto) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-7685bc3d più infiltrazioni (soppresso) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-7685bc3d »ZIP» BlackBox.class una variante di Java / ClassLoader trojan (errore durante la pulizia - operazione non disponibile per questo tipo di oggetto - errore durante l'eliminazione - operazione non disponibile per questo tipo di oggetto - è stata una parte del soppresso oggetto) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-7685bc3d »ZIP» VerifierBug.class JS / IEStart.G trojan (errore durante la pulizia - operazione non disponibile per questo tipo di oggetto - errore durante l'eliminazione - operazione non disponibile per questo tipo di oggetto - è stata una parte del soppresso oggetto) 00000000000000000000000000000000 C: \ Documents and Settings \ NetworkService \ Dati applicazioni \ domenica \ Java \ Deployment \ cache \ 6.0 \ 58 \ 7589253a-7685bc3d »ZIP» Dummy.class Java / NoCheat.B trojan (errore durante la pulizia - operazione non disponibile per questo tipo di oggetto - errore durante l'eliminazione - operazione non disponibile per questo tipo di oggetto - è stata una parte del soppresso oggetto) 00000000000000000000000000000000 C: \ Program Files \ Common Files \ Microsoft Shared \ Msinfo \ MSInfnd.exe probabilmente una variante del trojan Win32/Hupigon (non per la pulizia - soppresso) 00000000000000000000000000000000 C: \ WINDOWS \ system32 \ _MSInfnd.exe probabilmente una variante del trojan Win32/Hupigon (non per la pulizia - soppresso) 00000000000000000000000000000000 D: \ MSInfnd.exe probabilmente una variante del trojan Win32/Hupigon (non per la pulizia - soppresso) 00000000000000000000000000000000 Logfile di Trend Micro HijackThis v2.0.2 Scan salvato a 10:55:08 AM, il 01/19/2008 Piattaforma: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Processi in esecuzione: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Windows Defender \ MsMpEng.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ Program Files \ Intel \ Wireless \ Bin \ WLKeeper.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe C: \ WINDOWS \ Explorer.EXE C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe C: \ Program Files \ Common Files \ Symantec Shared \ la CCPD-LC \ symlcsvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe C: \ WINDOWS \ system32 \ spoolsv.exe C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe C: \ Program Files \ WIDCOMM \ Bluetooth Software \ bin \ btwdins.exe C: \ WINDOWS \ system32 \ cisvc.exe C: \ Programmi \ File comuni \ Creative Labs Shared \ Service \ CreativeLicensing.exe C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkService.exe C: \ Program Files \ Common Files \ Symantec Shared \ DJSNETCN.exe C: \ Program Files \ Common Files \ LogiShrd \ LVCOMSER \ LVComSer.exe C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Yahoo! \ NAV \ navapsvc.exe C: \ Program Files \ Yahoo! \ NAV \ IWP \ NPFMntor.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ CyberLink \ Shared Files \ RichVideo.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ fxssvc.exe C: \ WINDOWS \ stsystra.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe C: \ Program Files \ Intel \ Wireless \ bin \ ZCfgSvc.exe C: \ Program Files \ Intel \ Wireless \ Bin \ ifrmewrk.exe C: \ Program Files \ Dell \ QuickSet \ quickset.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe C: \ Program Files \ Creative \ SBAudigy \ Surround Mixer \ CTSysVol.exe C: \ WINDOWS \ system32 \ Rundll32.exe C: \ Program Files \ Intel \ Wireless \ Bin \ Dot1XCfg.exe C: \ WINDOWS \ system32 \ hkcmd.exe C: \ WINDOWS \ system32 \ igfxpers.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ Program Files \ PhatNoise Music Manager \ PNAgent.exe C: \ Program Files \ Windows Defender \ MSASCui.exe C: \ DOCUME ~ 1 \ sundeep \ LOCALS ~ 1 \ Temp \ clclean.0001 C: \ WINDOWS \ system32 \ ctfmon.exe C: \ Program Files \ TheWeatherNetwork \ WeatherEye \ WeatherEye.exe C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ Program Files \ WIDCOMM \ Bluetooth Software \ BTTray.exe C: \ Program Files \ Hamachi \ hamachi.exe C: \ Program Files \ Common Files \ Symantec Shared \ Security Console \ NSCSRVCE.EXE C: \ Program Files \ Mozilla Firefox \ firefox.exe C: \ WINDOWS \ system32 \ msiexec.exe C: \ WINDOWS \ system32 \ cidaemon.exe C: \ WINDOWS \ system32 \ cidaemon.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.google.ca/ R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int Ethernet Impostazioni, ProxyOverride = *. locali O1 - Hosts: 66.98.148.65 auto.search.msn.com O1 - Hosts: 66.98.148.65 auto.search.msn.es O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ ssv.dll O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O2 - BHO: NAV Helper - (A8F38D8D-E480-4D52-B7A2-731BB6995FDD) - C: \ Program Files \ Yahoo! \ NAV \ NavShExt.dll O4 - HKLM \ .. \ Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe O4 - HKLM \ .. \ Run: [IntelZeroConfig] "C: \ Program Files \ Intel \ Wireless \ bin \ ZCfgSvc.exe" O4 - HKLM \ .. \ Run: [IntelWireless] "C: \ Program Files \ Intel \ Wireless \ Bin \ ifrmewrk.exe" / tf Intel PROSet / Wireless O4 - HKLM \ .. \ Run: [Dell QuickSet] C: \ Program Files \ Dell \ QuickSet \ quickset.exe O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [Google Desktop Search] "C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe" / startup O4 - HKLM \ .. \ Run: [CTSysVol] C: \ Program Files \ Creative \ SBAudigy \ Surround Mixer \ CTSysVol.exe / r O4 - HKLM \ .. \ Run: [MBMon] Rundll32 CTMBHA.DLL, MBMon O4 - HKLM \ .. \ Run: [UpdReg] C: \ WINDOWS \ UpdReg.EXE O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ system32 \ igfxtray.exe O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ system32 \ hkcmd.exe O4 - HKLM \ .. \ Run: [Persistence] C: \ WINDOWS \ system32 \ igfxpers.exe O4 - HKLM \ .. \ Run: [KernelFaultCheck]% systemroot% \ system32 \ dumprep 0-k O4 - HKLM \ .. \ Run: [Kernel e Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM \ .. \ Run: [PNAgent] "C: \ Program Files \ PhatNoise Music Manager \ PNAgent.exe" O4 - HKLM \ .. \ Run: [Windows Defender] "C: \ Program Files \ Windows Defender \ MSASCui.exe"-hide O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ jusched.exe" O4 - HKLM \ .. \ RunServices: [DJSNetCN] C: \ Program Files \ Common Files \ Symantec Shared \ DJSNETCN.exe O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [SetDefaultMIDI] MIDIDef.exe O4 - HKCU \ .. \ Run: [WeatherEye] C: \ Program Files \ TheWeatherNetwork \ WeatherEye \ WeatherEye.exe O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe (User 'SERVIZIO LOCALE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe (User 'Default user') O4 - Startup: Hamachi.lnk = C: \ Program Files \ Hamachi \ hamachi.exe O4 - Global Startup: Bluetooth.lnk =? O8 - Extra contesto voce di menu: E & sporta in Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ EXCEL.EXE/3000 O8 - Extra contesto voce di menu: Invia a & Bluetooth Device ... - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ btsendto_ie_ctx.htm O9 - Extra pulsante: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ ssv.dll O9 - Extra pulsante: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ REFIEBAR.DLL O9 - Extra pulsante: PartyPoker.com - (B7FE5D70-9AA2-40F1-9C6B-12A255F085E1) - C: \ Program Files \ PartyGaming \ PartyPoker \ RunApp.exe (file mancanti) O9 - Extra 'Tools' menuitem: PartyPoker.com - (B7FE5D70-9AA2-40F1-9C6B-12A255F085E1) - C: \ Program Files \ PartyGaming \ PartyPoker \ RunApp.exe (file mancanti) O9 - Extra pulsante: @ btrez.dll, -4015 - (CCA281CA-C863-46ef-9331-5C8D4460577F) - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ btsendto_ie.htm O9 - Extra 'Tools' menuitem: @ btrez.dll, -12650 - (CCA281CA-C863-46ef-9331-5C8D4460577F) - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ btsendto_ie.htm Ø10 - Rotture di accesso a Internet a causa di LSP provider 'c: \ programmi \ bonjour \ mdnsnsp.dll' mancante Ø16 - DPF: (05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8) (Office Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?linkid=58813 Ø16 - DPF: (215B8138-A3CF-44C5-803F-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) -- http://housecall65.trendmicro.com/ho...vex/hcImpl.cab Ø16 - DPF: (56762DEC-6B0D-4AB4-A8AD-989993B5D08B) (OnlineScanner Control) -- http://www.eset.eu/buxus/docs/OnlineScanner.cab Ø16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://www.update.microsoft.com/micr...?1192932319484 Ø16 - DPF: (6E32070A-766D-4EE6-879c-DC1FA91D2FC3) (MUWebControl Class) -- http://www.update.microsoft.com/micr...?1192932290562 Ø20 - AppInit_DLLs: C: \ PROGRA ~ 1 \ Google \ GOOGLE ~ 1 \ GOEC62 ~ 1.DLL Ø20 - Winlogon Notify:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ bin \ btwdins.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe O23 - Service: Creative Labs Licensing Service - Creative Labs - C: \ Programmi \ File comuni \ Creative Labs Shared \ Service \ CreativeLicensing.exe O23 - Service: Diskeeper - Diskeeper Corporation - C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkService.exe O23 - Service: Symantec Licenze Rileva connessione Internet (DJSNETCN) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ DJSNETCN.exe O23 - Service: Intel (R) PROSet / Wireless Event Log (EvtEng) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe O23 - Service: FlexNet Licensing Service - Macrovision Europe Ltd. - C: \ Program Files \ Common Files \ Macrovision Shared \ FlexNet Publisher \ FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Common Files \ InstallShield \ Driver \ 1050 \ Intel 32 \ IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: LVCOMSer - Logitech Inc. - C: \ Program Files \ Common Files \ LogiShrd \ LVCOMSER \ LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C: \ Program Files \ Common Files \ LogiShrd \ LVMVFM \ LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C: \ Program Files \ Common Files \ LogiShrd \ SrvLnch \ SrvLnch.exe O23 - Service: Msinfo Framework Service (MSInfoFrv) - Sconosciuto proprietario - C: \ Program Files \ Common Files \ Microsoft Shared \ Msinfo \ MSInfnd.exe (file mancanti) O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C: \ Program Files \ Yahoo! \ NAV \ navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C: \ Program Files \ Yahoo! \ NAV \ IWP \ NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ Security Console \ NSCSRVCE.EXE O23 - Service: Intel (R) PROSet / Wireless Registry Service (RegSrvc) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe O23 - Service: Cyberlink RichVideo Service (CRVS) (RichVideo) - Sconosciuto proprietario - C: \ Program Files \ CyberLink \ Shared Files \ RichVideo.exe O23 - Service: Intel (R) PROSet / Wireless Service (S24EventMonitor) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C: \ Program Files \ Yahoo! \ NAV \ SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ la CCPD-LC \ symlcsvc.exe O23 - Service: Intel (R) PROSet / Wireless SSO Service (WLANKEEPER) - Intel (R) Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ WLKeeper.exe -- Fine del file - 11743 bytes |
|
#2
|
|||
|
|||
|
Benvenuti a TCF.
Apri HJT e selezionare Non solo un sistema di scansione quindi un segno di spunta accanto a: O1 - Hosts: 66.98.148.65 auto.search.msn.com O1 - Hosts: 66.98.148.65 auto.search.msn.es O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O9 - Extra pulsante: PartyPoker.com - (B7FE5D70-9AA2-40F1-9C6B-12A255F085E1) - C: \ Program Files \ PartyGaming \ PartyPoker \ RunApp.exe (file mancanti) O9 - Extra 'Tools' menuitem: PartyPoker.com - (B7FE5D70-9AA2-40F1-9C6B-12A255F085E1) - C: \ Program Files \ PartyGaming \ PartyPoker \ RunApp.exe (file mancanti) Chiudere tutte le finestre tranne che per HJT e fai clic su Fix controllati. ----------
---------- Esegui una nuova scansione con HJT e posta il log dopo Spybot ha completato. |
|
#3
|
|||
|
|||
|
Ok, ecco il nuovo log:
Logfile di Trend Micro HijackThis v2.0.2 Scan salvato a 5:09:34 PM, il 01/19/2008 Piattaforma: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Processi in esecuzione: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Windows Defender \ MsMpEng.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ Program Files \ Intel \ Wireless \ Bin \ WLKeeper.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe C: \ WINDOWS \ Explorer.EXE C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe C: \ Program Files \ Common Files \ Symantec Shared \ la CCPD-LC \ symlcsvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe C: \ WINDOWS \ system32 \ spoolsv.exe C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe C: \ Program Files \ WIDCOMM \ Bluetooth Software \ bin \ btwdins.exe C: \ WINDOWS \ system32 \ cisvc.exe C: \ Programmi \ File comuni \ Creative Labs Shared \ Service \ CreativeLicensing.exe C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkService.exe C: \ Program Files \ Common Files \ Symantec Shared \ DJSNETCN.exe C: \ Program Files \ Common Files \ LogiShrd \ LVCOMSER \ LVComSer.exe C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Yahoo! \ NAV \ navapsvc.exe C: \ Program Files \ Yahoo! \ NAV \ IWP \ NPFMntor.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ CyberLink \ Shared Files \ RichVideo.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ fxssvc.exe C: \ WINDOWS \ stsystra.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe C: \ Program Files \ Intel \ Wireless \ bin \ ZCfgSvc.exe C: \ Program Files \ Intel \ Wireless \ Bin \ ifrmewrk.exe C: \ Program Files \ Dell \ QuickSet \ quickset.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe C: \ Program Files \ Intel \ Wireless \ Bin \ Dot1XCfg.exe C: \ Program Files \ Creative \ SBAudigy \ Surround Mixer \ CTSysVol.exe C: \ WINDOWS \ system32 \ Rundll32.exe C: \ WINDOWS \ system32 \ hkcmd.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ WINDOWS \ system32 \ igfxpers.exe C: \ Program Files \ PhatNoise Music Manager \ PNAgent.exe C: \ Program Files \ Windows Defender \ MSASCui.exe C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ jusched.exe C: \ WINDOWS \ system32 \ ctfmon.exe C: \ Program Files \ TheWeatherNetwork \ WeatherEye \ WeatherEye.exe C: \ DOCUME ~ 1 \ sundeep \ LOCALS ~ 1 \ Temp \ clclean.0001 C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe C: \ Program Files \ WIDCOMM \ Bluetooth Software \ BTTray.exe C: \ Program Files \ Hamachi \ hamachi.exe C: \ Program Files \ Common Files \ Symantec Shared \ Security Console \ NSCSRVCE.EXE C: \ WINDOWS \ system32 \ cidaemon.exe C: \ WINDOWS \ system32 \ cidaemon.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.google.ca/ R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int Ethernet Impostazioni, ProxyOverride = *. locali O2 - BHO: Spybot-S & D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ SpyBot ~ 1 \ SDHelper.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ ssv.dll O2 - BHO: NAV Helper - (A8F38D8D-E480-4D52-B7A2-731BB6995FDD) - C: \ Program Files \ Yahoo! \ NAV \ NavShExt.dll O4 - HKLM \ .. \ Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe O4 - HKLM \ .. \ Run: [IntelZeroConfig] "C: \ Program Files \ Intel \ Wireless \ bin \ ZCfgSvc.exe" O4 - HKLM \ .. \ Run: [IntelWireless] "C: \ Program Files \ Intel \ Wireless \ Bin \ ifrmewrk.exe" / tf Intel PROSet / Wireless O4 - HKLM \ .. \ Run: [Dell QuickSet] C: \ Program Files \ Dell \ QuickSet \ quickset.exe O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [Google Desktop Search] "C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe" / startup O4 - HKLM \ .. \ Run: [CTSysVol] C: \ Program Files \ Creative \ SBAudigy \ Surround Mixer \ CTSysVol.exe / r O4 - HKLM \ .. \ Run: [MBMon] Rundll32 CTMBHA.DLL, MBMon O4 - HKLM \ .. \ Run: [UpdReg] C: \ WINDOWS \ UpdReg.EXE O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ system32 \ igfxtray.exe O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ system32 \ hkcmd.exe O4 - HKLM \ .. \ Run: [Persistence] C: \ WINDOWS \ system32 \ igfxpers.exe O4 - HKLM \ .. \ Run: [KernelFaultCheck]% systemroot% \ system32 \ dumprep 0-k O4 - HKLM \ .. \ Run: [Kernel e Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM \ .. \ Run: [PNAgent] "C: \ Program Files \ PhatNoise Music Manager \ PNAgent.exe" O4 - HKLM \ .. \ Run: [Windows Defender] "C: \ Program Files \ Windows Defender \ MSASCui.exe"-hide O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ jusched.exe" O4 - HKLM \ .. \ RunServices: [DJSNetCN] C: \ Program Files \ Common Files \ Symantec Shared \ DJSNETCN.exe O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [SetDefaultMIDI] MIDIDef.exe O4 - HKCU \ .. \ Run: [WeatherEye] C: \ Program Files \ TheWeatherNetwork \ WeatherEye \ WeatherEye.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe (User 'SERVIZIO LOCALE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe (User 'Default user') O4 - Startup: Hamachi.lnk = C: \ Program Files \ Hamachi \ hamachi.exe O4 - Global Startup: Bluetooth.lnk =? O8 - Extra contesto voce di menu: E & sporta in Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ EXCEL.EXE/3000 O8 - Extra contesto voce di menu: Invia a & Bluetooth Device ... - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ btsendto_ie_ctx.htm O9 - Extra pulsante: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_04 \ bin \ ssv.dll O9 - Extra pulsante: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ REFIEBAR.DLL O9 - Extra pulsante: @ btrez.dll, -4015 - (CCA281CA-C863-46ef-9331-5C8D4460577F) - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ btsendto_ie.htm O9 - Extra 'Tools' menuitem: @ btrez.dll, -12650 - (CCA281CA-C863-46ef-9331-5C8D4460577F) - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ btsendto_ie.htm O9 - Extra pulsante: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ SpyBot ~ 1 \ SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ SpyBot ~ 1 \ SDHelper.dll Ø10 - Rotture di accesso a Internet a causa di LSP provider 'c: \ programmi \ bonjour \ mdnsnsp.dll' mancante Ø16 - DPF: (05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8) (Office Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?linkid=58813 Ø16 - DPF: (215B8138-A3CF-44C5-803F-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) -- http://housecall65.trendmicro.com/ho...vex/hcImpl.cab Ø16 - DPF: (56762DEC-6B0D-4AB4-A8AD-989993B5D08B) (OnlineScanner Control) -- http://www.eset.eu/buxus/docs/OnlineScanner.cab Ø16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://www.update.microsoft.com/micr...?1192932319484 Ø16 - DPF: (6E32070A-766D-4EE6-879c-DC1FA91D2FC3) (MUWebControl Class) -- http://www.update.microsoft.com/micr...?1192932290562 Ø20 - AppInit_DLLs: C: \ PROGRA ~ 1 \ Google \ GOOGLE ~ 1 \ GOEC62 ~ 1.DLL Ø20 - Winlogon Notify:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ bin \ btwdins.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe O23 - Service: Creative Labs Licensing Service - Creative Labs - C: \ Programmi \ File comuni \ Creative Labs Shared \ Service \ CreativeLicensing.exe O23 - Service: Diskeeper - Diskeeper Corporation - C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkService.exe O23 - Service: Symantec Licenze Rileva connessione Internet (DJSNETCN) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ DJSNETCN.exe O23 - Service: Intel (R) PROSet / Wireless Event Log (EvtEng) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe O23 - Service: FlexNet Licensing Service - Macrovision Europe Ltd. - C: \ Program Files \ Common Files \ Macrovision Shared \ FlexNet Publisher \ FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Common Files \ InstallShield \ Driver \ 1050 \ Intel 32 \ IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: LVCOMSer - Logitech Inc. - C: \ Program Files \ Common Files \ LogiShrd \ LVCOMSER \ LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C: \ Program Files \ Common Files \ LogiShrd \ LVMVFM \ LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C: \ Program Files \ Common Files \ LogiShrd \ SrvLnch \ SrvLnch.exe O23 - Service: Msinfo Framework Service (MSInfoFrv) - Sconosciuto proprietario - C: \ Program Files \ Common Files \ Microsoft Shared \ Msinfo \ MSInfnd.exe (file mancanti) O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C: \ Program Files \ Yahoo! \ NAV \ navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C: \ Program Files \ Yahoo! \ NAV \ IWP \ NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ Security Console \ NSCSRVCE.EXE O23 - Service: Intel (R) PROSet / Wireless Registry Service (RegSrvc) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe O23 - Service: Cyberlink RichVideo Service (CRVS) (RichVideo) - Sconosciuto proprietario - C: \ Program Files \ CyberLink \ Shared Files \ RichVideo.exe O23 - Service: Intel (R) PROSet / Wireless Service (S24EventMonitor) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C: \ Program Files \ Yahoo! \ NAV \ SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ la CCPD-LC \ symlcsvc.exe O23 - Service: Intel (R) PROSet / Wireless SSO Service (WLANKEEPER) - Intel (R) Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ WLKeeper.exe -- Fine del file - 11469 bytes |
|
#4
|
|||
|
|||
|
Ho messo a parte delle direzioni da prima.
Il registro guarda bene se, come è ora il PC? |
|
#5
|
|||
|
|||
|
Il suo passato! Thanks so much for your help!
|
|
#6
|
|||
|
|||
|
Suona bene. Ho lasciato il link per il download dal post # 2 di Spybot. Vorrei suggerire di installare ed eseguire una scansione con esso. Scaricare Spybot-S & D Utilizzare le istruzioni di post # 2 per farlo correttamente.
Questo è un buon momento per cancellare il tuo sistema di punti di ripristino infetti e di creare un nuovo punto di ripristino pulito:
Check out questo post gratuitamente strumenti e suggerimenti per tenere il PC e te sicuro in futuro. Questo post ha strumenti gratuiti di consulenza e di mantenere il buon funzionamento del PC in futuro. |
|
#7
|
|||
|
|||
|
Sei stato infettato da un RAT (Remote Administration Tool). Vorrei fare una ricerca per un klog .* file e cancellarlo, dovrebbe di norma essere in entrambe le finestre o cartella system32.
RAT sono veramente popolare con script kiddies cryptors e l'uso per evitare il rilevamento e leganti AV in modo che possano impegnare la trojan per app. Quando ho scoperto che ho violato da un ratto, da scaricare warez, ho dato un'occhiata al programma di me e aveva un sacco di stronzate caratteristiche keylog, webcam viewer, password cache. SO sono le possibilità che hai sentito quando la riproduzione di musica, è stato qualcuno che manualmente tramite il file e la loro apertura. Se vi imbattete in stesse attività, come la riproduzione di musica, la password o addirittura cambiato la tua webcam accesa allora, invece di installare un sacco di inutili AV e programmi di rimozione malware crap. Controlla la tua Installed Components nel Registro di sistema. HKEY_LOCAL_MACHINE> Software> Microsoft> Active Setup> Installed Components e fai clic su ognuna delle cartelle e cercare una voce che solo ha un Stubpath punta a un file. exe in system32 o cartella di Windows. Per vedere se è questo. Exe in attivo di avvio, per navigare e eseguirlo. Se si dice che è utilizzato da un altro programma e il nome del file. Exe isnt mostrando nel vostro processo di lista, quindi viene iniettato in un altro processo, come il DEFAULT broswer (IE). Quindi è possibile utilizzare HJT per eliminare il file e riavviare su ovviamente eliminare la voce del Registro di sistema. RAT's sono gli stessi, ma un IRCBOT RAT solo ha una GUI, mi sento di raccomandare un firewall, quindi se un programma in modo casuale vuole connettersi a Internet si può negare, e comunque usare il programma. Poiché il trojan è binded per il file di installazione, il trojan estratti ed esegue quando si va a installare e provare a fare uno exteernal connessione e se si blocca poi si dispone di un trojan, ma Arnt infetti solo perché siedono in una directory facendo niente. Siamo spiacenti per il blabber, speriamo che questo vi ha dato un orizzonte più ampio per quanto riguarda le potenziali situazioni di pericolo sui ratti e IRCbots. Brad |
|
#8
|
|||
|
|||
|
Brad Hey, grazie per l'info.
Ho fatto ciò che ha detto e tutti i file. Exe a cui fa riferimento il stubpaths che ho il doppio clic non sono stati utilizzati da un altro programma. Quindi ... non significa che io sono ok? Grazie per il vostro aiuto. |
|
#9
|
|||
|
|||
|
Localhost si mente avermi dato alcuni riferimenti, come la rimozione del malware per il tuo background? Al forum di fare quello che normalmente si assiste nella rimozione del malware.
|
|
#10
|
|||
|
|||
|
Ha solo mostrare un stubpath e nient'altro? Potreste essere in cerca di un tasto sbagliato. Si dice stubpath e poi semplicemente un luogo.
|