Visualizzazione dei risultati da 1 a 9 su 9

Discussione: virus e file sospetti

  1. #1

    virus e file sospetti

    Salve hò il portatile con il vista e l'antivirus avira e hò eseguito di recente la scansione completa perche il pc mi sembra più lento del solito.L'antivirus mi dice che non hò virus ma mi allarma per due virus che non è riuscito a scansionare e percui sospetti che l'ultima scansione che hò fatto prima di questa non c'erano o ce n'era uno solo.Cosa devo fare?Li devo eliminare manualmente?

    Ho fatto la scansione con hijackThis che allego per una controllatina che è questo:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21.25.02, on 25/09/2009
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16386)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\System32\s3trayp.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Free Download Manager\fdm.exe
    C:\Program Files\Ninja\ninja.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_cu...spx?TbId=60076
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Toolbar &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [HDAudDeck] "C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe" 1
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
    O4 - Startup: ninja.exe - collegamento.lnk = C:\Program Files\Ninja\ninja.exe
    O8 - Extra context menu item: Crawler Search - tbr:iemenu
    O8 - Extra context menu item: Save Flash - res://C:\Users\massimo\Desktop\Nuova cartella\Nuova cartella\Flash Saving Plugin\FlashSButton.dll/210
    O8 - Extra context menu item: Scarica con Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Scarica i video con Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
    O8 - Extra context menu item: Scarica selezionati con Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Scarica tutto con Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
    O9 - Extra 'Tools' menuitem: &Impostazioni di Google Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
    O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
    O13 - Gopher Prefix:
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Google Update Service (gupdate1c9f7145d86da67) (gupdate1c9f7145d86da67) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 7203 bytes

  2. #2
    Poi allego anche il risultato dell'antivirus he è questo:



    Avira AntiVir Personal
    Report file date: giovedì 24 settembre 2009 19:28

    Scanning for 1735135 virus strains and unwanted programs.

    Licensee : Avira AntiVir Personal - FREE Antivirus
    Serial number : 0000149996-ADJIE-0000001
    Platform : Windows Vista
    Windows version : (plain) [6.0.6000]
    Boot mode : Normally booted
    Username : SYSTEM
    Computer name : PC-MASSIMO

    Version information:
    BUILD.DAT : 9.0.0.387 17962 Bytes 24/03/2009 11:04:00
    AVSCAN.EXE : 9.0.3.3 464641 Bytes 24/02/2009 10:13:26
    AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 08:58:24
    LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 09:35:49
    LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 08:58:52
    ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 10:30:36
    ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/06/2009 12:40:20
    ANTIVIR2.VDF : 7.1.6.1 3857920 Bytes 16/09/2009 04:24:02
    ANTIVIR3.VDF : 7.1.6.18 252928 Bytes 21/09/2009 04:24:03
    Engineversion : 8.2.1.23
    AEVDF.DLL : 8.1.1.2 106867 Bytes 22/09/2009 04:24:09
    AESCRIPT.DLL : 8.1.2.33 479611 Bytes 22/09/2009 04:24:08
    AESCN.DLL : 8.1.2.5 127346 Bytes 10/09/2009 20:28:41
    AERDL.DLL : 8.1.2.4 430452 Bytes 15/07/2009 20:20:39
    AEPACK.DLL : 8.2.0.0 422261 Bytes 22/09/2009 04:24:07
    AEOFFICE.DLL : 8.1.0.38 196987 Bytes 18/06/2009 20:16:30
    AEHEUR.DLL : 8.1.0.155 1921400 Bytes 18/08/2009 15:13:22
    AEHELP.DLL : 8.1.7.0 237940 Bytes 10/09/2009 20:28:39
    AEGEN.DLL : 8.1.1.63 364916 Bytes 22/09/2009 04:24:05
    AEEMU.DLL : 8.1.0.9 393588 Bytes 09/10/2008 12:32:40
    AECORE.DLL : 8.1.8.1 184693 Bytes 22/09/2009 04:24:04
    AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 12:32:40
    AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 06:47:59
    AVPREF.DLL : 9.0.0.1 43777 Bytes 05/12/2008 08:32:15
    AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 12:34:28
    AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 08:32:09
    AVARKT.DLL : 9.0.0.1 292609 Bytes 09/02/2009 05:52:24
    AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 08:37:08
    SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 13:03:49
    SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 06:21:33
    NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 08:32:10
    RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 09/02/2009 09:45:45
    RCTEXT.DLL : 9.0.35.0 87297 Bytes 11/03/2009 13:55:12

    Configuration settings for the scan:
    Jobname.............................: Complete system scan
    Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
    Logging.............................: low
    Primary action......................: interactive
    Secondary action....................: ignore
    Scan master boot sector.............: on
    Scan boot sector....................: on
    Boot sectors........................: C:, D:,
    Process scan........................: on
    Scan registry.......................: on
    Search for rootkits.................: on
    Integrity checking of system files..: off
    Scan all files......................: All files
    Scan archives.......................: on
    Recursion depth.....................: 20
    Smart extensions....................: on
    Macro heuristic.....................: on
    File heuristic......................: medium

    Start of the scan: giovedì 24 settembre 2009 19:28

    Starting search for hidden objects.
    '70687' objects were checked, '0' hidden objects were found.

    The scan of running processes will be started
    Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
    Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'taskeng.exe' - '1' Module(s) have been scanned
    Scan process 'WirelessCard.exe' - '1' Module(s) have been scanned
    Scan process 'ninja.exe' - '1' Module(s) have been scanned
    Scan process 'fdm.exe' - '1' Module(s) have been scanned
    Scan process 'sidebar.exe' - '1' Module(s) have been scanned
    Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 's3trayp.exe' - '1' Module(s) have been scanned
    Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'dwm.exe' - '1' Module(s) have been scanned
    Scan process 'XAudio.exe' - '1' Module(s) have been scanned
    Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleCrashHandler.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have b

  3. #3
    Scan process 'XAudio.exe' - '1' Module(s) have been scanned
    Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleCrashHandler.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'sp_rsser.exe' - '1' Module(s) have been scanned
    Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
    Scan process 'audiodg.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsm.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'wininit.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    47 processes with 47 modules were scanned

    Starting master boot sector scan:

    Start scanning boot sectors:

    Starting to scan executable files (registry).
    The registry was scanned ( '32' files ).


    Starting the file scan:

    Begin scan in 'C:\'
    C:\hiberfil.sys
    [WARNING] The file could not be opened!
    [NOTE] This file is a Windows system file.
    [NOTE] This file cannot be opened for scanning.
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    [NOTE] This file is a Windows system file.
    [NOTE] This file cannot be opened for scanning.
    Begin scan in 'D:\' <DATA>


    End of the scan: giovedì 24 settembre 2009 20:35
    Used time: 1:07:03 Hour(s)

    The scan has been done completely.

    14585 Scanned directories
    224980 Files were scanned
    0 Viruses and/or unwanted programs were found
    0 Files were classified as suspicious
    0 files were deleted
    0 Viruses and unwanted programs were repaired
    0 Files were moved to quarantine
    0 Files were renamed
    2 Files cannot be scanned
    224978 Files not concerned
    2713 Archives were scanned
    2 Warnings
    2 Notes
    70687 Objects were scanned with rootkit scan
    0 Hidden objects were found


    Mi porteste spiegare se il pc ha qualsosa?Per cortesia?Grazie!


    saluti by
    massimo77mr

  4. #4
    Hò anche il report di sistemscan aggiornato che è questo:http://www.mediafire.com/?g4bjtjhzjmg

    Aspetto vostra risposta!

    saluti

  5. #5
    ?

  6. #6
    Deifobe se ci sei o anche altri per cortesia potete controllarmi il compiuter cos'ha perchè in internet è lentissimo devo aver preso qualche virus perchè hò scaricato dei programmi da emule e ora è così.Per cortesia grazie se ha qualche virus o è nel registro che devo sistemare qualcosa accetto qualsiasi risposta.Grazie!P.s.non riesco a scaricare il report ultimo su mediafire.Come faccio?Provo a caricarlo metà?

  7. #7
    Sono riuscito su filedropper che è questo: http://www.filedropper.com/report_2


    Grazie aspetto qualche risposta per cortesia.
    Saluti!............

  8. #8
    Utente di HTML.it
    Registrato dal
    Mar 2008
    Messaggi
    356
    la scansione di hijack non evidenzia problemi, c'e' solo la toolbar di crawler che non conosco e non so se possa rallentare il sistema. Io ti suggerirei di fare qualche scansione on line tipo su trend micro oppure symantec security check, fai anche una scansione con il malwarebytes, programma che ottimo che ti consiglio di scaricare ed usare spesso, www.malwarebytes.org (fai scansione completa). Se non esce nulla dopo questi controlli e' probabile che il problema sia da ricercare nella connessione alla rete.

    C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe

  9. #9
    ok grazie i programmi che mi hai detto li hò ga usati ma mi rispondono negativamente la scansione online della symantec mi havisualizzato un virus che hò adesso rimosso ma mi sembra lastesso che abbia qualcosa e l'antivirus avira mi segnala invece degli avvisi di file che non è riuscita a scansionare.Che ci sia qualcosa lì in quei files di sistema?

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved.