Ciao , la bestiaccia c'è ancora!!!!
stamattina il cmp mi sembra lento, vado a vedere gli utenti abilitati ed è ricomparso helpassistant!!!!
Incavolato nero ho fatto queste cose sperando di non avere fatto casini...
1-eliminato manualmente l'utente Helpassistant e disattivato l'accesso da remoto
2-ho scoperto in C una cartella Helpassistant backup ----> eliminata manualmente
3-ho fatto girare HelpAsst mebroot fix qui il log
C:\Documents and Settings\Agazzi\Impostazioni locali\Temporary Internet Files\Content.IE5\V7T7C8C3\HelpAsst_mebroot_fix[1].exe
14/07/2010 at 7.32.35,65
No HelpAssistant account in User list
~~ Checking for termsrv32.dll ~~
termsrv32.dll present! ~ attempting to remove
Remove on reboot: C:\WINDOWS\system32\termsrv32.dll
~~ Checking firewall ports ~~
backing up DomainProfile\GloballyOpenPorts\List registry key
closing rogue ports
HKLM\~\services\sharedaccess\parameters\firewallpo licy\domainprofile\globallyopenports\list
"65533:TCP"=-
"52344:TCP"=-
"5778:TCP"=-
"5777:TCP"=-
"3389:TCP"=-
"3115:TCP"=-
"4730:TCP"=-
"7351:TCP"=-
"7352:TCP"=-
"7114:TCP"=-
"7115:TCP"=-
"4224:TCP"=-
"6948:TCP"=-
backing up StandardProfile\GloballyOpenPorts\List registry key
closing rogue ports
HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\globallyopenports\list
"65533:TCP"=-
"52344:TCP"=-
"5777:TCP"=-
"5778:TCP"=-
"3389:TCP"=-
"3115:TCP"=-
"4730:TCP"=-
"7351:TCP"=-
"7352:TCP"=-
"7114:TCP"=-
"7115:TCP"=-
"4224:TCP"=-
"6948:TCP"=-
~~ Checking profile list ~~
HelpAssistant profile found in registry ~ backing up and removing S-1-5-21-3250203075-2804593661-1431998383-1004
~ No profile directory exists for S-1-5-21-3250203075-2804593661-1431998383-1004 ~
HelpAssistant profile found in registry ~ backing up and removing S-1-5-21-3250203075-2804593661-1431998383-1006
~ No profile directory exists for S-1-5-21-3250203075-2804593661-1431998383-1006 ~
~ All HelpAssistant profiles removed from registry ~
~~ Checking mbr ~~
user & kernel MBR OK
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on 14/07/2010 at 7.33.31,75
No HelpAssistant account in User list
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys xfilt.sys ACPI.sys hal.dll >>UNKNOWN [0x8958C78A]<<
kernel: MBR read successfully
user & kernel MBR OK
~~ Checking for termsrv32.dll ~~
termsrv32.dll present!
HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~
4-fatto girare in modalità provvisoria mbr.exe -f il log è Ok nessun codice "malato"
5-fatto girare combofix che ha evidenziato attività root kit .. qui il log
http://www.megaupload.com/?d=8IT4IKLT
6-fatto girare hijackthis qui il log
http://www.megaupload.com/?d=8R2036IC
7-fatto girare CCcleaner
Non abbandonatemi, la bestiaccia sembra rognosa e da solo non ce la posso fare.... :master:![]()
Grazie
GRY72

Rispondi quotando
