![]() |
| |||||||
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| Logfile di Trend Micro HijackThis v2.0.2 Scan saved at 12:01:37, il 9/21/2008 Piattaforma: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Processi in esecuzione: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ Csrss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ ibmpmsvc.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ WINDOWS \ system32 \ spoolsv.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Centenn.ial \ Audit \ CAgent32.exe C: \ Centenn.ial \ Audit \ xferwan.exe C: \ Program Files \ Cisco VPN Client \ cvpnd.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe C: \ WINDOWS \ system32 \ TPHDEXLG.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe c: \ _integra \ bin \ ccmagent.exe C: \ Program Files \ Lenovo \ System Update \ suservice.exe C: \ WINDOWS \ System32 \ alg.exe C: \ WINDOWS \ system32 \ calc.exe C: \ WINDOWS \ system32 \ calc.exe c: \ _integra \ bin \ shstart.exe C: \ WINDOWS \ Explorer.EXE C: \ WINDOWS \ system32 \ tp4mon.exe C: \ WINDOWS \ system32 \ igfxtray.exe C: \ WINDOWS \ system32 \ hkcmd.exe C: \ WINDOWS \ system32 \ igfxpers.exe C: \ WINDOWS \ system32 \ NWTRAY.EXE C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe C: \ Program Files \ Lenovo \ HOTKEY \ TPOSDSVC.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp.Exe C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe C: \ WINDOWS \ system32 \ TpShocks.exe C: \ Program Files \ Lenovo \ HOTKEY \ TPONSCR.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe C: \ Program Files \ Lenovo \ Zoom \ TpScrex.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ ctfmon.exe C: \ Program Files \ Yahoo! \ Messenger \ ymsgr_tray.exe C: \ WINDOWS \ system32 \ taskmgr.exe C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ WINDOWS \ system32 \ Wuauclt.exe C: \ WINDOWS \ system32 \ wbem \ wmiprvse.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe C: \ WINDOWS \ system32 \ wbem \ wmiprvse.exe F2 - REG: system.ini: UserInit = c: \ windows \ system32 \ userinit.exe, c: \ _inte gra \ bin \ shstart.exe O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: DriveLetterAccess - (5CA3D70E-1895-11CF-8E15-001234567890) - C: \ WINDOWS \ system32 \ dla \ tfswshx.dll O4 - HKLM \ .. \ Run: [TrackPointSrv] tp4mon.exe O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ system32 \ igfxtray.exe O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ system32 \ hkcmd.exe O4 - HKLM \ .. \ Run: [Persistence] C: \ WINDOWS \ system32 \ igfxpers.exe O4 - HKLM \ .. \ Run: [NWTRAY] NWTRAY.EXE O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [vptray] C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe O4 - HKLM \ .. \ Run: [TPHOTKEY] C: \ Program Files \ Lenovo \ HOTKEY \ TPOSDSVC.exe O4 - HKLM \ .. \ Run: [UpdateManager] "C: \ Program Files \ Common Files \ Sonic \ Update Manager \ sgtray.exe" / r O4 - HKLM \ .. \ Run: [dla] C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe O4 - HKLM \ .. \ Run: [EZEJMNAP] C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp.Exe O4 - HKLM \ .. \ Run: [LPManager] C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe O4 - HKLM \ .. \ Run: [TpShocks] TpShocks.exe O4 - HKLM \ .. \ Run: [TVT Scheduler Proxy] C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe" tranquilla O4 - HKUS \ S-1-5-19 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'SERVIZIO LOCALE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'Default user') O8 - Extra contesto voce di menu: E & sporta in Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ EXCEL.EXE/3000 O9 - Extra pulsante: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ REFIEBAR.DLL O9 - Extra pulsante: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' menuitem: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe Ø16 - DPF: (215B8138-A3CF-44C5-803F-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) -- http://housecall65.trendmicro.com/ho...vex/hcImpl.cab - O17 HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (B8E7B489-2160-4DE7-B592-9FD03D16CC74): Domain = keane.com O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe O23 - Service: Application Management Service (AppMgSvc) - Unknown owner - C: \ Program.exe (file missing) O23 - Service: BHCP Service (BHsrv) - Unknown owner - C: \ Program.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe O23 - Service: CentennialClientAgent - Centennial Software Limited - C: \ Centenn.ial \ Audit \ CAgent32.exe O23 - Service: CentennialIPTransferAgent - Centennial Software Limited - C: \ Centenn.ial \ Audit \ xferwan.exe O23 - Service: Servizio aggiornamento client per Novell (cusrvc) - Novell, Inc. - C: \ WINDOWS \ system32 \ cusrvc.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C: \ Program Files \ Cisco VPN Client \ cvpnd.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe O23 - Service: Intel (R) PROSet / Wireless Event Log (EvtEng) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C: \ WINDOWS \ system32 \ ibmpmsvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: Intel (R) PROSet / Wireless Registry Service (RegSrvc) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe O23 - Service: Intel (R) PROSet / Wireless Service (S24EventMonitor) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe O23 - Service: SAVRoam (SavRoam) - symantec - C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe O23 - Service: System Update (SUService) - Lenovo Group Limited - c: \ programmi \ lenovo \ system update \ suservice.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C: \ WINDOWS \ system32 \ TPHDEXLG.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe O23 - Service: Symantec LiveState agente per Windows (WControl) - Symantec Corporation - c: \ _integra \ bin \ ccmagent.exe -- End of file - 8621 bytes |
|
#2
| |||
| |||
| Scaricare Malwarebytes' Anti-Malware (MBAM)
Ulteriori Note: Se MBAM incontra un file che è difficile da rimuovere, verrà presentato con 1 di 2 istruzioni, fare clic su OK per lasciare che sia MBAM e procedere con il processo di disinfezione, se richiesto di riavviare il computer, si prega di farlo immediatamente. |
|
#3
| |||
| |||
| Nessun malware trovato, è qui la relazione -------------------------------------------------- ---- 5/1/2600 Windows Service Pack 2 9/21/2008 6:16:07 mbam-log-2008-09-21 (18-16-07). txt Tipo di scansione: Quick Scan Scansione di oggetti: 52.621 Tempo trascorso: 4 minuti (s), 41 second (s) Processi di memoria infetti: 0 Moduli di memoria infetti: 0 Chiavi di registro infette: 0 Valori del registro infetti: 0 I dati del Registro di oggetti infetti: 0 Cartelle infette: 0 File infetti: 0 Processi di memoria infetti: (N. oggetti dannosi individuati) Moduli di memoria infetti: (N. oggetti dannosi individuati) Chiavi di registro infette: (N. oggetti dannosi individuati) Valori del registro infetti: (N. oggetti dannosi individuati) I dati del Registro di oggetti infetti: (N. oggetti dannosi individuati) Cartelle infette: (N. oggetti dannosi individuati) I file infetti: (N. oggetti dannosi individuati) |
|
#4
| |||
| |||
| Non vi è alcun mostrando malware in entrambi i log. Cosa sta succedendo esattamente? |
|
#5
| |||
| |||
| Processo IEXPLORER.EXE multiple sono spwaning nella lista dei processi. Hanno immediatamente pop up, se li uccido uno per uno. A volte sento anche alcuni suoni come una di quelle che eseguono qualsiasi finestra del browser, ma non visibile. Vi è sicuramente sbagliato, non dovrebbero esistere. |
|
#6
| |||
| |||
| Scarica ComboFix da success da uno dei link qui sotto. Assicurarsi superiore a salvare la Desktop. Link # 1 Link # 2 ** Nota: E 'importante che si è salvato direttamente sul tuo desktop Chiudere tutti i browser Web aperto. (Firefox, Internet Explorer, etc) prima di iniziare ComboFix. Temporaneamente disattivare tuo antivirus, E qualsiasi antispyware protezione in tempo reale prima eseguire una scansione. Fare clic sul pulsante questo link per visualizzare un elenco di programmi di sicurezza che dovrebbero essere disattivati e come disattivarli. Fare doppio clic su combofix.exe e segui le istruzioni. Una volta terminato ComboFix produrrà un log per voi. Posta la ComboFix log e un nuovo Log HijackThis nella prossima risposta. Importante: Non clic ComboFix della finestra, mentre è in esecuzione. Che potrebbero indurlo a stalla. Ricorda di riattivare l'antivirus e antispyware quando ComboFix protezione è completa. |
|
#7
| |||
| |||
| ComboFix Entra ----------------------- ComboFix 08-09-20.05 - 012466 2008-09-21 19:31:50.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.473 [GMT -7:00] Eseguito da: C: \ Keanetools \ ComboFix.exe * Creato un nuovo punto di ripristino AVVERTENZA-Questa macchina NON HANNO IL RECUPERO CONSOLE INSTALLED! . Altri ((((((((((((((((((((((((((((((((((((((( Deletions ))))))))) )))))))))))))))))))))))))))))))))))))))) . C: \ Documents and Settings \ LocalService \ Cookies \ system@ad.yieldmanag er [1]. Txt C: \ WINDOWS \ system32 \ x64 . ((((((((((((((((((((((((((((((((((((((( Driver / Servizi )))))))) ))))))))))))))))))))))))))))))))))))))))) . ------- \ Legacy_BHSRV ------- \ Service_BHsrv ((((((((((((((((((((((((( Files Creati dal 2008/08/22 al 2008/09/22 ))))))))))) )))))))))))))))))))) . 2008-09-21 18:09. 2008-09-21 18:10 <DIR> d -------- C: \ Program Files \ Malwarebytes 'Anti-Malware 2008-09-21 18:09. 2008-09-21 18:09 <DIR> d -------- C: \ Documents and Settings \ All Users \ Dati applicazioni \ Malwarebytes 2008-09-21 18:09. 2008-09-21 18:09 <DIR> d -------- C: \ Documents and Settings \012.466 \ Dati applicazioni \ Malwarebytes 2008-09-21 18:09. 2008/09/10 00:04 38528 - a ------ C: \ WINDOWS \ system32 \ drivers \ mbamswissarmy.sys 2008-09-21 18:09. 2008/09/10 00:03 17200 - a ------ C: \ WINDOWS \ system32 \ drivers \ mbam.sys 2008-09-21 11:07. 2008-09-21 11:07 <DIR> d -------- C: \ Program Files \ Lavasoft 2008-09-21 11:07. 2008-09-21 11:08 <DIR> d -------- C: \ Documents and Settings \ All Users \ Dati applicazioni \ Lavasoft 2008-09-21 11:06. 2008-09-21 11:06 <DIR> d -------- C: \ Programmi \ File comuni \ Wise Installation Wizard 2008-09-20 23:40. 2008-09-20 23:40 <DIR> d -------- C: \ Program Files \ Trend Micro 2008-09-19 09:03. 2008-09-19 09:08 <DIR> d -------- C: \ WINDOWS \ SxsCaPendDel 2008-09-19 00:49. 2008-09-19 00:52 <DIR> d -------- C: \ Documents and Settings \012.466 \. Housecall6.6 2008-09-19 00:27. 2008-09-19 09:04 <DIR> da ------ C: \ Documents and Settings \ All Users \ Dati applicazioni \ TEMP 2008-09-18 20:25. 2002/02/04 06:22 1230336 - a ------ C: \ WINDOWS \ system32 \ msxml4.dll 2008-09-18 20:25. 2007-09-14 05:01 922.920 --------- C: \ WINDOWS \ system32 \ ahlprun.exe 2008-09-18 20:25. 2002/02/04 06:13 82432 - a ------ C: \ WINDOWS \ system32 \ Msxml4r.dll 2008-09-18 20:25. 2002/02/04 06:13 44544 - a ------ C: \ WINDOWS \ system32 \ Msxml4a.dll 2008-09-18 20:25. 2002-02-07 18:43 9.679 - a ------ C: \ WINDOWS \ system32 \ msxml4r.cat 2008-09-18 20:25. 2002-02-07 18:43 9.675 - a ------ C: \ WINDOWS \ system32 \ msxml4.cat 2008-09-18 20:25. 2002-02-06 20:31 3.489 - a ------ C: \ WINDOWS \ system32 \ msxml4.Manifest 2008-09-18 20:25. 2002-02-06 20:31 500 - a ------ C: \ WINDOWS \ system32 \ msxml4r.Manifest 2008-09-18 20:21. 2008-09-18 20:21 <DIR> d -------- C: \ Program Files \ Common Files \ Lenovo 2008-09-18 18:27. 2008/09/21 11:54 21272 - a ------ C: \ WINDOWS \ system32 \ bynpea.key 2008-09-18 18:25. 2008/09/18 18:25 1 - a ------ C: \ WINDOWS \ system32 \004fdb9.imi 2008-09-15 14:23. 2008-09-15 14:23 332.800 --- hs ---- C: \ WINDOWS \ system32 \ _Bhsrv.msi 2008-09-15 12:15. 2008/09/18 15:57 69942 - a ------ C: \ WINDOWS \ system32 \ rrjack.key 2008-09-15 12:15. 2008/09/15 12:15 1 - a ------ C: \ WINDOWS \ system32 \0048444.imi 2008-09-13 19:27. 2008-09-13 19:27 24 - a ------ C: \ WINDOWS \ cdplayer.ini 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Real 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Programmi \ File comuni \ xing condivisa 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Common Files \ Real . (((((((((((((((((((((((((((((((((((((((( Find3M Relazione )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-09-22 02:33 --------- d ----- w C: \ Program Files \ Symantec AntiVirus 2008-09-22 02:33 --------- d ----- w C: \ Program Files \ Cisco VPN client 2008-09-21 18:56 16 - sh - r C: \ MSCIOTL.SYS 2008-09-21 18:55 8.416 ---- aw C: \ WINDOWS \ system32 \ drivers \ CDProbe.SYS 2008-09-20 19:26 430.816 - sh - w C: \ Program Files \ _MsInfo.msi 2008-09-19 03:25 --------- d - h - w C: \ Program Files \ InstallShield Installation Information 2008-09-19 03:25 --------- d ----- w C: \ Program Files \ ThinkVantage 2008-09-19 03:21 --------- d ----- w C: \ Program Files \ Lenovo . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Nota * vuoto voci & legit default voci non vengono visualizzate REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run] "ctfmon.exe" = "C: \ WINDOWS \ system32 \ ctfmon.exe" [2004-08-04 15360] "Yahoo! Pager" = "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe" [2007-08-30 4670704] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "SunJavaUpdateSched" = "C: \ WINDOWS \ system32 \ igfxtray.exe" [2007-08-15 141848] "NvCplDaemon" = "C: \ WINDOWS \ system32 \ hkcmd.exe" [2007-08-15 162328] "Persistence" = "C: \ WINDOWS \ system32 \ E igfxpers.ex" [2007-08-15 137752] "ccApp" = "C: \ Programmi \ File comuni \ Symantec Shared \ ccApp.exe" [2006-03-24 53408] "nwiz" = "C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ VPTray.exe" [2006-06-14 124656] "TPHOTKEY" = "C: \ Program Files \ Lenovo \ HOTKEY \ TPOSDSVC.exe" [2007-03-09 66176] "SunJavaUpdateSched" = "C: \ Programmi \ File comuni \ Sonic \ Update Manager \ sgtray.exe" [2003-08-18 110592] "dla" = "C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe" [2005-05-19 127037] "EZEJMNAP" = "C: \ PROGRA ~ 1 \ ThinkPad \ Utilit ~ 1 \ EzEjMnAp. Exe" [2007-04-26 243248] "LPManager" = "C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe" [2007-03-22 120368] "TVT Scheduler Proxy" = "C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe" [2008-03-04 487424] "CTFMON.EXE" = "C: \ Programmi \ File comuni \ Real \ Update_OB \ realsched.exe" [2008-09-13 185896] "TrackPointSrv" = "tp4mon.exe" [2004/08/03 C: \ WINDOWS \ system32 \ tp4mon.exe] "NWTRAY" = "NWTRAY.EXE" [2002/03/12 C: \ WINDOWS \ system32 \ nwtray.exe] "TpShocks" = "TpShocks.exe" [2007/03/29 C: \ WINDOWS \ system32 \ TpShocks.exe] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "Communicator" = "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" [2005-05-12 4167376] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entversion \ Policies \ System] "CompatibleRUPSecurity" = 1 (0x1) [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ corr rentversion \ Policies \ Explorer] "StartMenuLogoff" = 1 (0x1) [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ tpfnf2] 2006-09-06 13:37 34344 C: \ Program Files \ Lenovo \ HOTKEY \ notifyf2.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ tphotkey] 2006-12-14 08:06 28672 C: \ Program Files \ Lenovo \ HOTKEY \ tphklock.dll [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ Lsa] Pacchetti di autenticazione REG_MULTI_SZ MSV1_0 nwv1_0 [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center \ Monitoring \ SymantecAntiVirus] "DisableMonitoring" = dword: 00000001 [HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo licy \ standardprofile \ AuthorizedApplications \ List] "% windir% \ \ system32 \ \ sessmgr.exe" = "C: \ Program Files \ \ Yahoo! \ \ Messenger \ \ YahooMessenger.exe" = "C: \ Program Files \ \ Yahoo! \ \ Messenger \ \ YServer.exe" = R0 Shockprf; Shockprf; C: \ WINDOWS \ system32 \ DRIVERS \ Apsx 86.sys [2007-03-02 100656] R0 TPDIGIMN; TPDIGIMN; C: \ WINDOWS \ system32 \ DRIVERS \ M86.sys ApsH [2007-03-02 19760] R2 smefs; SMEFileSystem; C: \ WINDOWS \ system32 \ drivers \ efs.sys sm [2006-02-08 20508] R3 CdProbe; CdProbe; C: \ WINDOWS \ system32 \ DRIVERS \ e.sys cdprob [2008-09-21 8416] R3 smedrv; SMEDriver; C: \ WINDOWS \ system32 \ drivers \ v.sys smedr [2006-02-08 9516] S2 AppMgSvc; Application Management Service; C: \ Program Files \ Common Files \ Microsoft Shared \ MSINFO \ MsInfo.msi [2008-09-20 430816] S2 yraebbgi; yraebbgi; C: \ WINDOWS \ system32 \ drivers \ ea.sys bynp [] S2 yrtxzgwh; yrtxzgwh; C: \ WINDOWS \ system32 \ drivers \ ck.sys rrja [] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ svchost] wrtxzg wrtxzg REG_MULTI_SZ nraebb nraebb REG_MULTI_SZ . . ------- ------- Supplementari Scan . R0 -: HKCU-Main, Start Page = hxxp: / / www.google.com/ O8 -: E & sporta in Microsoft Excel - C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ EXCEL.EXE/3000 . ************************************************** ************************ catchme 0.3.1361 W2K/XP/Vista - rootkit / stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-21 19:35:12 5/1/2600 Windows Service Pack 2 NTFS scansione processi nascosti ... scansione entrate autostart nascoste ... scansione di file nascosti ... scansione completata con successo i file nascosti: 0 ************************************************** ************************ [HKEY_LOCAL_MACHINE \ System \ ControlSet001 \ Services \ A ppMgSvc] "ImagePath" = "C: \ Program Files \ Common Files \ Microsoft Shared \ MSINFO \ MsInfo.msi" . --------------------- DLLs Loaded Sotto i processi in esecuzione --------------------- PROCESSO: C: \ WINDOWS \ system32 \ winlogon.exe -> C: \ Program Files \ Lenovo \ HOTKEY \ tphklock.dll . ------------------------ Altri processi in esecuzione ----------------------- -- . C: \ WINDOWS \ system32 \ ibmpmsvc.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ _integra \ bin \ shstart.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ Program Files \ Lenovo \ HOTKEY \ TPONSCR.exe C: \ Program Files \ Lenovo \ ZOOM \ TpScrex.exe C: \ Program Files \ Symantec AntiVirus \ DoScan.exe C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ CENTENN.IAL \ Audit \ CAgent32.exe C: \ CENTENN.IAL \ Audit \ xferwan.exe C: \ Program Files \ Cisco VPN Client \ cvpnd.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ Yahoo! \ Messenger \ Ymsgr_tray.exe C: \ WINDOWS \ system32 \ calc.exe C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe C: \ WINDOWS \ system32 \ TPHDEXLG.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe C: \ _integra \ bin \ ccmagent.exe C: \ Program Files \ Lenovo \ System Update \ SUService.exe C: \ WINDOWS \ system32 \ wscntfy.exe C: \ ComboFix \ pv.cfexe . ************************************************** ************************ . Ora fine: 2008-09-21 19:36:58 - macchina è stato riavviato ComboFix-quarantined-files.txt 2008-09-22 02:36:54 Pre-Run: 64333811712 bytes free Post-Run: 64523264000 bytes free 175 HijackThis Entra ----------------------------------- Logfile di Trend Micro HijackThis v2.0.2 Scan saved at 7:38:41, il 9/21/2008 Piattaforma: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Processi in esecuzione: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ ibmpmsvc.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ WINDOWS \ system32 \ spoolsv.exe c: \ _integra \ bin \ shstart.exe C: \ WINDOWS \ system32 \ tp4mon.exe C: \ WINDOWS \ system32 \ igfxtray.exe C: \ WINDOWS \ system32 \ hkcmd.exe C: \ WINDOWS \ system32 \ igfxpers.exe C: \ WINDOWS \ system32 \ NWTRAY.EXE C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ Program Files \ Lenovo \ HOTKEY \ TPOSDSVC.exe C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp.Exe C: \ Program Files \ Lenovo \ HOTKEY \ TPONSCR.exe C: \ Program Files \ Lenovo \ Zoom \ TpScrex.exe C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe C: \ WINDOWS \ system32 \ TpShocks.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ ctfmon.exe C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ WINDOWS \ system32 \ svchost.exe C: \ Centenn.ial \ Audit \ CAgent32.exe C: \ Centenn.ial \ Audit \ xferwan.exe C: \ Program Files \ Cisco VPN Client \ cvpnd.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ Yahoo! \ Messenger \ ymsgr_tray.exe C: \ WINDOWS \ system32 \ calc.exe C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe C: \ WINDOWS \ system32 \ TPHDEXLG.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe c: \ _integra \ bin \ ccmagent.exe C: \ Program Files \ Lenovo \ System Update \ suservice.exe C: \ WINDOWS \ system32 \ wscntfy.exe C: \ WINDOWS \ system32 \ Wuauclt.exe C: \ WINDOWS \ system32 \ Wuauclt.exe C: \ WINDOWS \ Explorer.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: DriveLetterAccess - (5CA3D70E-1895-11CF-8E15-001234567890) - C: \ WINDOWS \ system32 \ dla \ tfswshx.dll O4 - HKLM \ .. \ Run: [TrackPointSrv] tp4mon.exe O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ system32 \ igfxtray.exe O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ system32 \ hkcmd.exe O4 - HKLM \ .. \ Run: [Persistence] C: \ WINDOWS \ system32 \ igfxpers.exe O4 - HKLM \ .. \ Run: [NWTRAY] NWTRAY.EXE O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [vptray] C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe O4 - HKLM \ .. \ Run: [TPHOTKEY] C: \ Program Files \ Lenovo \ HOTKEY \ TPOSDSVC.exe O4 - HKLM \ .. \ Run: [UpdateManager] "C: \ Program Files \ Common Files \ Sonic \ Update Manager \ sgtray.exe" / r O4 - HKLM \ .. \ Run: [dla] C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe O4 - HKLM \ .. \ Run: [EZEJMNAP] C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp.Exe O4 - HKLM \ .. \ Run: [LPManager] C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe O4 - HKLM \ .. \ Run: [TpShocks] TpShocks.exe O4 - HKLM \ .. \ Run: [TVT Scheduler Proxy] C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe" tranquilla O4 - HKUS \ S-1-5-19 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'SERVIZIO LOCALE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'Default user') O8 - Extra contesto voce di menu: E & sporta in Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ EXCEL.EXE/3000 O9 - Extra pulsante: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ micros ~ 2 \ Office11 \ REFIEBAR.DLL O9 - Extra pulsante: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' menuitem: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe Ø16 - DPF: (215B8138-A3CF-44C5-803F-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) -- http://housecall65.trendmicro.com/ho...vex/hcImpl.cab - O17 HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (B8E7B489-2160-4DE7-B592-9FD03D16CC74): Domain = keane.com O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (D239A412-22C2-4683-95BC-1FFAA687D0DF): NameServer = 172.21.18.101,172.21.18.102 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe O23 - Service: Application Management Service (AppMgSvc) - Unknown owner - C: \ Program.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe O23 - Service: CentennialClientAgent - Centennial Software Limited - C: \ Centenn.ial \ Audit \ CAgent32.exe O23 - Service: CentennialIPTransferAgent - Centennial Software Limited - C: \ Centenn.ial \ Audit \ xferwan.exe O23 - Service: Servizio aggiornamento client per Novell (cusrvc) - Novell, Inc. - C: \ WINDOWS \ system32 \ cusrvc.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C: \ Program Files \ Cisco VPN Client \ cvpnd.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe O23 - Service: Intel (R) PROSet / Wireless Event Log (EvtEng) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C: \ WINDOWS \ system32 \ ibmpmsvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: Intel (R) PROSet / Wireless Registry Service (RegSrvc) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe O23 - Service: Intel (R) PROSet / Wireless Service (S24EventMonitor) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe O23 - Service: SAVRoam (SavRoam) - symantec - C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe O23 - Service: System Update (SUService) - Lenovo Group Limited - c: \ programmi \ lenovo \ system update \ suservice.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C: \ WINDOWS \ system32 \ TPHDEXLG.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe O23 - Service: Symantec LiveState agente per Windows (WControl) - Symantec Corporation - c: \ _integra \ bin \ ccmagent.exe -- End of file - 8581 bytes |
|
#8
| |||
| |||
| Nota: le istruzioni qui di seguito sono stati creati appositamente per questo utente. Se non siete l'utente, NON seguire queste istruzioni in quanto potrebbero danneggiare il funzionamento del sistema Elimina i file / cartelle, come segue: 1. Vai a Inizio > Correre > Tipo Notepad.exe e fare clic su OK per aprire il Blocco note. Esso dovere essere il Blocco note, non Wordpad. 2. Copia il testo nella casella qui sotto il codice evidenziando tutto il testo e premendo Ctrl + C Codice: Killall:: Driver:: BHSRV BHsrv File:: C: \ WINDOWS \ system32 \ bynpea.key C: \ WINDOWS \ system32 \ 004fdb9.imi C: \ WINDOWS \ system32 \ _Bhsrv.msi C: \ WINDOWS \ system32 \ rrjack. chiave di C: \ WINDOWS \ system32 \ 0048444.imi C: \ WINDOWS \ system32 \ drivers \ bynpea.sys C: \ WINDOWS \ system32 \ drivers \ rrjack.sys C: \ WINDOWS \ system32 \ calc.exe 4. Quindi, fare clic su File > Salvare 5. Nome del file CFScript.txt - Salva il file sul tuo desktop 6. Quindi, trascinare il CFScript (tenere premuto il tasto sinistro del mouse mentre si trascina il file) e rilasciarlo (rilasciare il tasto sinistro del mouse) in ComboFix.exe come potete vedere nella schermata qui sotto. Importante: Eseguire questa attentamente le istruzioni! ![]() ComboFix inizierà a eseguire, basta seguire le istruzioni. Dopo il reboot (nel caso in cui si chiede di riavviare), che produrrà un log per voi. Post che log (Combofix.txt) nella prossima risposta. Nota: Non clic ComboFix della finestra, mentre è in esecuzione. Questo può causare il sistema per congelare |
|
#9
| |||
| |||
| ComboFix log dopo aver eseguito cfscript -------------------------------------------------- -------- ComboFix 08-09-20.05 - 012466 2008-09-21 22:11:45.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.598 [GMT -7:00] Eseguito da: C: \ Keanetools \ ComboFix.exe Interruttori di comando utilizzati:: C: \ Documents and Settings \012.466 \ Desktop \ CFScript.txt * Creato un nuovo punto di ripristino AVVERTENZA-Questa macchina NON HANNO IL RECUPERO CONSOLE INSTALLED! FILE:: C: \ WINDOWS \ system32 \ _Bhsrv.msi C: \ WINDOWS \ system32 \0048444.imi C: \ WINDOWS \ system32 \004fdb9.imi C: \ WINDOWS \ system32 \ bynpea.key C: \ WINDOWS \ system32 \ calc.exe C: \ WINDOWS \ system32 \ drivers \ bynpea.sys C: \ WINDOWS \ system32 \ drivers \ rrjack.sys C: \ WINDOWS \ system32 \ rrjack.key . Altri ((((((((((((((((((((((((((((((((((((((( Deletions ))))))))) )))))))))))))))))))))))))))))))))))))))) . C: \ WINDOWS \ system32 \ _Bhsrv.msi C: \ WINDOWS \ system32 \0048444.imi C: \ WINDOWS \ system32 \004fdb9.imi C: \ WINDOWS \ system32 \ bynpea.key C: \ WINDOWS \ system32 \ calc.exe C: \ WINDOWS \ system32 \ rrjack.key . ((((((((((((((((((((((((( Files Creati dal 2008/08/22 al 2008/09/22 ))))))))))) )))))))))))))))))))) . 2008-09-21 18:09. 2008-09-21 18:10 <DIR> d -------- C: \ Program Files \ Malwarebytes 'Anti-Malware 2008-09-21 18:09. 2008-09-21 18:09 <DIR> d -------- C: \ Documents and Settings \ All Users \ Dati applicazioni \ Malwarebytes 2008-09-21 18:09. 2008-09-21 18:09 <DIR> d -------- C: \ Documents and Settings \012.466 \ Dati applicazioni \ Malwarebytes 2008-09-21 18:09. 2008/09/10 00:04 38528 - a ------ C: \ WINDOWS \ system32 \ drivers \ mbamswissarmy.sys 2008-09-21 18:09. 2008/09/10 00:03 17200 - a ------ C: \ WINDOWS \ system32 \ drivers \ mbam.sys 2008-09-21 11:07. 2008-09-21 11:07 <DIR> d -------- C: \ Program Files \ Lavasoft 2008-09-21 11:07. 2008-09-21 11:08 <DIR> d -------- C: \ Documents and Settings \ All Users \ Dati applicazioni \ Lavasoft 2008-09-21 11:06. 2008-09-21 11:06 <DIR> d -------- C: \ Programmi \ File comuni \ Wise Installation Wizard 2008-09-20 23:40. 2008-09-20 23:40 <DIR> d -------- C: \ Program Files \ Trend Micro 2008-09-19 09:03. 2008-09-19 09:08 <DIR> d -------- C: \ WINDOWS \ SxsCaPendDel 2008-09-19 00:49. 2008-09-19 00:52 <DIR> d -------- C: \ Documents and Settings \012.466 \. Housecall6.6 2008-09-19 00:27. 2008-09-19 09:04 <DIR> da ------ C: \ Documents and Settings \ All Users \ Dati applicazioni \ TEMP 2008-09-18 20:25. 2002/02/04 06:22 1230336 - a ------ C: \ WINDOWS \ system32 \ msxml4.dll 2008-09-18 20:25. 2007-09-14 05:01 922.920 --------- C: \ WINDOWS \ system32 \ ahlprun.exe 2008-09-18 20:25. 2002/02/04 06:13 82432 - a ------ C: \ WINDOWS \ system32 \ Msxml4r.dll 2008-09-18 20:25. 2002/02/04 06:13 44544 - a ------ C: \ WINDOWS \ system32 \ Msxml4a.dll 2008-09-18 20:25. 2002-02-07 18:43 9.679 - a ------ C: \ WINDOWS \ system32 \ msxml4r.cat 2008-09-18 20:25. 2002-02-07 18:43 9.675 - a ------ C: \ WINDOWS \ system32 \ msxml4.cat 2008-09-18 20:25. 2002-02-06 20:31 3.489 - a ------ C: \ WINDOWS \ system32 \ msxml4.Manifest 2008-09-18 20:25. 2002-02-06 20:31 500 - a ------ C: \ WINDOWS \ system32 \ msxml4r.Manifest 2008-09-18 20:21. 2008-09-18 20:21 <DIR> d -------- C: \ Program Files \ Common Files \ Lenovo 2008-09-13 19:27. 2008-09-13 19:27 24 - a ------ C: \ WINDOWS \ cdplayer.ini 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Real 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Programmi \ File comuni \ xing condivisa 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Common Files \ Real . (((((((((((((((((((((((((((((((((((((((( Find3M Relazione )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-09-22 05:14 8.416 ---- aw C: \ WINDOWS \ system32 \ drivers \ CDProbe.SYS 2008-09-22 05:14 16 - sh - r C: \ MSCIOTL.SYS 2008-09-22 05:14 --------- d ----- w C: \ Program Files \ Symantec AntiVirus 2008-09-22 03:07 --------- d ----- w C: \ Program Files \ Cisco VPN client 2008-09-20 19:26 430.816 - sh - w C: \ Program Files \ _MsInfo.msi 2008-09-19 03:25 --------- d - h - w C: \ Program Files \ InstallShield Installation Information 2008-09-19 03:25 --------- d ----- w C: \ Program Files \ ThinkVantage 2008-09-19 03:21 --------- d ----- w C: \ Program Files \ Lenovo . ((((((((((((((((((((((((((((( Snapshot@2008-09-21_19.36.38.64 )))))))))) ))))))))))))))))))))))))))))))) . - 2008-09-21 18:59:45 71.370 ---- aw C: \ WINDOWS \ system32 \ Perfc009.dat + 2008-09-22 02:39:43 71.370 ---- aw C: \ WINDOWS \ system32 \ Perfc009.dat - 2008-09-21 18:59:45 439.832 ---- aw C: \ WINDOWS \ system32 \ Perfh009.dat + 2008-09-22 02:39:43 439.832 ---- aw C: \ WINDOWS \ system32 \ Perfh009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Nota * vuoto voci & legit default voci non vengono visualizzate REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run] "ctfmon.exe" = "C: \ WINDOWS \ system32 \ ctfmon.exe" [2004-08-04 15360] "Yahoo! Pager" = "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe" [2007-08-30 4670704] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "SunJavaUpdateSched" = "C: \ WINDOWS \ system32 \ igfxtray.exe" [2007-08-15 141848] "NvCplDaemon" = "C: \ WINDOWS \ system32 \ hkcmd.exe" [2007-08-15 162328] "Persistence" = "C: \ WINDOWS \ system32 \ E igfxpers.ex" [2007-08-15 137752] "ccApp" = "C: \ Programmi \ File comuni \ Symantec Shared \ ccApp.exe" [2006-03-24 53408] "nwiz" = "C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ VPTray.exe" [2006-06-14 124656] "TPHOTKEY" = "C: \ Program Files \ Lenovo \ HOTKEY \ TPOSDSVC.exe" [2007-03-09 66176] "SunJavaUpdateSched" = "C: \ Programmi \ File comuni \ Sonic \ Update Manager \ sgtray.exe" [2003-08-18 110592] "dla" = "C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe" [2005-05-19 127037] "EZEJMNAP" = "C: \ PROGRA ~ 1 \ ThinkPad \ Utilit ~ 1 \ EzEjMnAp. Exe" [2007-04-26 243248] "LPManager" = "C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe" [2007-03-22 120368] "TVT Scheduler Proxy" = "C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe" [2008-03-04 487424] "CTFMON.EXE" = "C: \ Programmi \ File comuni \ Real \ Update_OB \ realsched.exe" [2008-09-13 185896] "TrackPointSrv" = "tp4mon.exe" [2004/08/03 C: \ WINDOWS \ system32 \ tp4mon.exe] "NWTRAY" = "NWTRAY.EXE" [2002/03/12 C: \ WINDOWS \ system32 \ nwtray.exe] "TpShocks" = "TpShocks.exe" [2007/03/29 C: \ WINDOWS \ system32 \ TpShocks.exe] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "Communicator" = "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" [2005-05-12 4167376] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entversion \ Policies \ System] "CompatibleRUPSecurity" = 1 (0x1) [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ corr rentversion \ Policies \ Explorer] "StartMenuLogoff" = 1 (0x1) [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ tpfnf2] 2006-09-06 13:37 34344 C: \ Program Files \ Lenovo \ HOTKEY \ notifyf2.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ tphotkey] 2006-12-14 08:06 28672 C: \ Program Files \ Lenovo \ HOTKEY \ tphklock.dll [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ Lsa] Pacchetti di autenticazione REG_MULTI_SZ MSV1_0 nwv1_0 [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center \ Monitoring \ SymantecAntiVirus] "DisableMonitoring" = dword: 00000001 [HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo licy \ standardprofile \ AuthorizedApplications \ List] "% windir% \ \ system32 \ \ sessmgr.exe" = "C: \ Program Files \ \ Yahoo! \ \ Messenger \ \ YahooMessenger.exe" = "C: \ Program Files \ \ Yahoo! \ \ Messenger \ \ YServer.exe" = R0 Shockprf; Shockprf; C: \ WINDOWS \ system32 \ DRIVERS \ Apsx 86.sys [2007-03-02 100656] R0 TPDIGIMN; TPDIGIMN; C: \ WINDOWS \ system32 \ DRIVERS \ M86.sys ApsH [2007-03-02 19760] R2 smefs; SMEFileSystem; C: \ WINDOWS \ system32 \ drivers \ efs.sys sm [2006-02-08 20508] R3 CdProbe; CdProbe; C: \ WINDOWS \ system32 \ DRIVERS \ e.sys cdprob [2008-09-21 8416] R3 smedrv; SMEDriver; C: \ WINDOWS \ system32 \ drivers \ v.sys smedr [2006-02-08 9516] S2 AppMgSvc; Application Management Service; C: \ Program Files \ Common Files \ Microsoft Shared \ MSINFO \ MsInfo.msi [2008-09-20 430816] S2 yraebbgi; yraebbgi; C: \ WINDOWS \ system32 \ drivers \ ea.sys bynp [] S2 yrtxzgwh; yrtxzgwh; C: \ WINDOWS \ system32 \ drivers \ ck.sys rrja [] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ svchost] wrtxzg wrtxzg REG_MULTI_SZ nraebb nraebb REG_MULTI_SZ . ************************************************** ************************ catchme 0.3.1361 W2K/XP/Vista - rootkit / stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-21 22:16:04 5/1/2600 Windows Service Pack 2 NTFS scansione processi nascosti ... scansione entrate autostart nascoste ... scansione di file nascosti ... C: \ WINDOWS \ system32 \ calc.exe scansione completata con successo i file nascosti: 1 ************************************************** ************************ [HKEY_LOCAL_MACHINE \ System \ ControlSet001 \ Services \ A ppMgSvc] "ImagePath" = "C: \ Program Files \ Common Files \ Microsoft Shared \ MSINFO \ MsInfo.msi" . --------------------- DLLs Loaded Sotto i processi in esecuzione --------------------- PROCESSO: C: \ WINDOWS \ system32 \ winlogon.exe -> C: \ Program Files \ Lenovo \ HOTKEY \ tphklock.dll . ------------------------ Altri processi in esecuzione ----------------------- -- . C: \ WINDOWS \ system32 \ ibmpmsvc.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ CENTENN.IAL \ Audit \ CAgent32.exe C: \ CENTENN.IAL \ Audit \ xferwan.exe C: \ Program Files \ Cisco VPN Client \ cvpnd.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe C: \ WINDOWS \ system32 \ TPHDEXLG.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe C: \ _integra \ bin \ ccmagent.exe C: \ Program Files \ Lenovo \ System Update \ SUService.exe C: \ _integra \ bin \ shstart.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ Program Files \ Lenovo \ HOTKEY \ TPONSCR.exe C: \ Program Files \ Lenovo \ ZOOM \ TpScrex.exe C: \ Program Files \ Symantec AntiVirus \ DoScan.exe C: \ Program Files \ Yahoo! \ Messenger \ Ymsgr_tray.exe C: \ ComboFix \ pv.cfexe . ************************************************** ************************ . Ora fine: 2008-09-21 22:17:28 - macchina è stato riavviato ComboFix-quarantined-files.txt 2008-09-22 05:17:23 ComboFix2.txt 2008-09-22 02:36:59 Pre-Run: 64509464576 bytes free Post-Run: 64505421824 bytes free 181 |
|
#10
| |||
| |||
| Scaricare OTMoveIt2 da Oldtimere salvarlo sul Desktop. Nota: Se si esegue su Vista, fai clic destro e scegliere il OTMoveIt2.exe Esegui come amministratore. 1. Fare doppio clic su OTMoveIt2.exe per eseguirlo. 2. Copia le righe nel codebox seguito. Codice: [Explorer kill] C: \ WINDOWS \ system32 \ calc.exe HKEY_LOCAL_MACHINE \ System \ ControlSet001 \ Services \ AppMgSvc EmptyTemp [start explorer] 4. Fare clic sul pulsante rosso Moveit! pulsante. 5. Copia tutto nella finestra dei risultati (sotto la barra verde) e incollalo nella tua prossima risposta. 6. Chiudere OTMoveIt2 Nota: Se un file o una cartella non possono essere spostati immediatamente è possibile che venga richiesto di riavviare il computer al fine di completare il processo di muoversi. Se ha chiesto di riavviare, scegliere Sì. In caso contrario, comunque il riavvio. |
![]() |
|
| Segnalibri |
Threads simili | ||||
| Filo | Thread Starter | Forum | Risposte | Ultimo Post |
| Rimuovere il virus iexplore.exe / log hijack | xalice15x | Virus, Spyware e sicurezza | 16 | 12 nov 2008 19:43 |
| IEXPLORER.EXE virus - please help me! | Giant Panda | Virus, Spyware e sicurezza | 2 | 6 Ott 2008 14:55 |
| Sono sempre i virus per il mio bone.exe IEXPLORER | damandg | Virus, Spyware e sicurezza | 12 | 14 lug 2008 14:31 |
| IEXPLORER.EXE virus | iuboy2006 | Virus, Spyware e sicurezza | 9 | 26 Mar 2008 08:12 |
| Avssytemcare popup virus e simili - (include dirottare questo) | shifty | Virus, Spyware e sicurezza | 23 | 2007 Sep 4. 16:15 |
| Thread Tools | |
| |