Pagina 1 di 2 1 2 ultimoultimo
Visualizzazione dei risultati da 1 a 10 su 18
  1. #1
    Utente di HTML.it
    Registrato dal
    Oct 2001
    Messaggi
    855

    aiuto elaborare file txt di GMER per infezione

    Ciao a tutti,

    da un po di tempo quando connetto il pc ad internet tramite modem mi apre varie finestrelle pubblicitarie

    ho fatto la scanzione con il mio antivirus ma non rivela nulla

    allora ho provato e sto provando, con una procedura molto efficace dell'utente LUCASS, che avevo fatto un'altra volta con un altro problema, utilizzando GMER ma non riesco ad elaborare i file che devo passare ad AVENGER

    questa è la procedura che ho utilizzato con GMER

    codice:
    Esegui gmer.exe
    Clicca sul Tab "Rootkit"
    Clicca su "Scan"
    finita la scansione clicca su "Copy"
    Apri il Blocco Note incolla il risultato (CTRL+V)
    Salva il file(rootkit.txt)
    
    Esegui gmer.exe
    Clicca sul Tab "Autostart"
    Spunta la casella "Show All"
    Clicca su "Scan"
    finita la scansione clicca su "Copy"
    Apri il Blocco Note incolla il risultato (CTRL+V)
    Salva il file(autostart.txt)

  2. #2
    Utente di HTML.it
    Registrato dal
    Oct 2001
    Messaggi
    855
    ROOTKIT.TXT
    codice:
    GMER 1.0.10.10122 - http://www.gmer.net
    Rootkit 2007-08-23 17:48:31
    Windows 5.1.2600 
    
    
    ---- System - GMER 1.0.10 ----
    
    SSDT  81CEF728                                                                     ZwConnectPort
    
    ---- Files - GMER 1.0.10 ----
    
    File  C:\System Volume Information\catalog.wci                                     
    File  C:\System Volume Information\tracking.log                                    
    File  C:\System Volume Information\_restore{CBA4C188-1848-4012-9CBC-833565C5319C}  
    
    ---- EOF - GMER 1.0.10 ----

  3. #3
    Utente di HTML.it
    Registrato dal
    Oct 2001
    Messaggi
    855
    AUTOSTART.TXT lo spezzetto perchè troppo lungo

    AUTOSTART.TXT
    codice:
    GMER 1.0.10.10122 - http://www.gmer.net
    Autostart 2007-08-23 17:49:26
    Windows 5.1.2600 
    
    
    HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute = autocheck autochk * /*file not found*/
    
    HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
    
    HKLM\SYSTEM\CurrentControlSet\Control\WOW@cmdline = %SystemRoot%\system32\ntvdm.exe
    
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
    @UserinitC:\WINDOWS\system32\userinit.exe, = C:\WINDOWS\system32\userinit.exe,
    @ShellExplorer.exe = Explorer.exe
    @System = 
    @UIHostlogonui.exe = logonui.exe
    
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
    crypt32chain@DLLName = crypt32.dll
    cryptnet@DLLName = cryptnet.dll
    cscdll@DLLName = cscdll.dll
    PCANotify@DLLName = PCANotify.dll
    ScCertProp@DLLName = wlnotify.dll
    Schedule@DLLName = wlnotify.dll
    sclgntfy@DLLName = sclgntfy.dll
    SensLogn@DLLName = WlNotify.dll
    termsrv@DLLName = wlnotify.dll
    wlballoon@DLLName = wlnotify.dll
    
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs = 
    
    HKLM\SYSTEM\CurrentControlSet\Services\ >>>
    Ati HotKey Poller@ = %SystemRoot%\System32\Ati2evxx.exe
    AudioSrv /*Audio Windows*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    BITS /*Servizio trasferimento intelligente in background*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    Browser /*Browser di computer*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    CryptSvc /*Servizi di crittografia*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
    Dhcp /*Client DHCP*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    dmserver /*Gestione dischi logici*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    Dnscache /*Client DNS*/@ = %SystemRoot%\System32\svchost.exe -k NetworkService
    ERSvc /*Servizio di segnalazione errori*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    Eventlog /*Registro eventi*/@ = %SystemRoot%\system32\services.exe
    helpsvc /*Guida in linea e supporto tecnico*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    IISADMIN /*Amministrazione di IIS*/@ = C:\WINDOWS\System32\inetsrv\inetinfo.exe
    lanmanserver /*Server*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    lanmanworkstation /*Workstation*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    LmHosts /*Helper NetBIOS di TCP/IP*/@ = %SystemRoot%\System32\svchost.exe -k LocalService
    Messenger /*Messenger*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    navapsvc /*Servizio Norton AntiVirus Auto-Protect*/@ = C:\Programmi\Norton AntiVirus\navapsvc.exe
    NISSERV /*Norton Internet Security Service*/@ = C:\Programmi\Norton Internet Security\NISSERV.EXE
    PlugPlay /*Plug and Play*/@ = %SystemRoot%\system32\services.exe
    PolicyAgent /*Servizi IPSEC*/@ = %SystemRoot%\System32\lsass.exe
    ProtectedStorage /*Archiviazione protetta*/@ = %SystemRoot%\system32\lsass.exe
    RemoteRegistry /*Registro di sistema remoto*/@ = %SystemRoot%\system32\svchost.exe -k LocalService
    RpcSs /*RPC (Remote Procedure Call)*/@ = %SystemRoot%\system32\svchost -k rpcss
    SamSs /*Gestione account di protezione (SAM)*/@ = %SystemRoot%\system32\lsass.exe
    SBService /*ScriptBlocking Service*/@ = C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
    Schedule /*Utilità di pianificazione*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    seclogon /*Accesso secondario*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    SENS /*Notifica eventi di sistema*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
    SharedAccess /*Firewall della connessione Internet (ICF) / Condivisione connessione Internet (ICS)*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    ShellHWDetection /*Rilevamento hardware shell*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    SMTPSVC /*Protocollo SMTP (Simple Mail Transfer Protocol)*/@ = C:\WINDOWS\System32\inetsrv\inetinfo.exe
    Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
    srservice /*Servizio Ripristino configurazione di sistema*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    SymProxySvc /*Norton Internet Security Proxy Service*/@ = C:\Programmi\Norton Internet Security\SymProxySvc.exe
    Themes /*Temi*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    TrkWks /*Manutenzione collegamenti distribuiti client*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
    UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\System32\wdfmgr.exe
    uploadmgr /*Upload Manager*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    W32Time /*Ora di Windows*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    W3SVC /*Pubblicazione sul Web*/@ = %SystemRoot%\System32\inetsrv\inetinfo.exe
    WebClient /*WebClient*/@ = %SystemRoot%\System32\svchost.exe -k LocalService
    winmgmt /*Strumentazione gestione Windows*/@ = %systemroot%\system32\svchost.exe -k netsvcs
    wuauserv /*Aggiornamenti automatici*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
    WZCSVC /*Zero Configuration reti senza fili*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
    
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
    @ATIModeChangeAti2mdxx.exe = Ati2mdxx.exe
    @CPQEASYACCC:\Programmi\Compaq\Easy Access Button Support\StartEAK.exe = C:\Programmi\Compaq\Easy Access Button Support\StartEAK.exe
    @SynTPLprC:\Programmi\Synaptics\SynTP\SynTPLpr.exe = C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
    @SynTPEnhC:\Programmi\Synaptics\SynTP\SynTPEnh.exe = C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
    @AdaptecDirectCD"C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" = "C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    @Local Servicerundll.exe /*file not found*/ = rundll.exe /*file not found*/
    @Microsoft WinUpdatesvchosts.exe /*file not found*/ = svchosts.exe /*file not found*/
    @iamappC:\Programmi\Norton Internet Security\IAMAPP.EXE = C:\Programmi\Norton Internet Security\IAMAPP.EXE
    @NAV AgentC:\PROGRA~1\NORTON~1\navapw32.exe = C:\PROGRA~1\NORTON~1\navapw32.exe
    @Symantec NetDriver MonitorC:\PROGRA~1\SYMNET~1\SNDMon.exe = C:\PROGRA~1\SYMNET~1\SNDMon.exe
    
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices >>>
    @Microsoft WinUpdatesvchosts.exe /*file not found*/ = svchosts.exe /*file not found*/
    @Local Servicerundll.exe /*file not found*/ = rundll.exe /*file not found*/
    
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
    @Microsoft WinUpdatesvchosts.exe /*file not found*/ = svchosts.exe /*file not found*/
    @Local Servicerundll.exe /*file not found*/ = rundll.exe /*file not found*/
    
    HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad >>>
    @PostBootReminder%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
    @WebCheck%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
    @SysTrayC:\WINDOWS\System32\stobject.dll = C:\WINDOWS\System32\stobject.dll
    
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler >>>
    @{438755C2-A8BA-11D1-B96B-00A0C90312E1}%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
    @{8C7461EF-2B13-11d2-BE35-3078302C2030}%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
    
    HKLM\Software\Classes\Folder\shell\open\command@ = %SystemRoot%\Explorer.exe /idlist,%I,%L
    
    HKLM\Software\Classes\Folder\shell\explore\command@ = %SystemRoot%\Explorer.exe /e,/idlist,%I,%L
    
    HKLM\Software\Classes\ >>>
    .exe@ = "%1" %*
    .com@ = "%1" %*
    .cmd@ = "%1" %*
    .bat@ = "%1" %*
    .pif@ = "%1" %*
    .scr@ = "%1" /S
    .hta@ = C:\WINDOWS\System32\mshta.exe "%1" %*

  4. #4
    Utente di HTML.it
    Registrato dal
    Oct 2001
    Messaggi
    855
    sempre AUTOSTART.TXT seconda parte

    codice:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{AEB6717E-7E19-11d0-97EE-00C04FD91972} = shell32.dll
    
    HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
    @{5a61f7a0-cde1-11cf-9113-00aa00425c62} /*IIS Shell Extension*/C:\WINDOWS\System32\inetsrv\w3ext.dll = C:\WINDOWS\System32\inetsrv\w3ext.dll
    @{5E44E225-A408-11CF-B581-008029601108} /*Adaptec DirectCD Shell Extension*/C:\PROGRA~1\Adaptec\EASYCD~1\DirectCD\Shellex.dll = C:\PROGRA~1\Adaptec\EASYCD~1\DirectCD\Shellex.dll
    @{4CCEFB41-18FA-11D3-9EF3-00A0C9E897FD} /*Componente estensione della shell di CorelDRAW*/C:\Programmi\Corel\Corel Graphics 11\DRAW\CDRVIEWER\CrlShell110.dll = C:\Programmi\Corel\Corel Graphics 11\DRAW\CDRVIEWER\CrlShell110.dll
    @CorelDRAW Shell Extension Component /*CorelDRAW Shell Extension Component*/(null) = 
    @{2206CDB2-19C1-11D1-89E0-00C04FD7A829} /*Microsoft Data Link*/C:\Programmi\File comuni\System\OLE DB\oledb32.dll = C:\Programmi\File comuni\System\OLE DB\oledb32.dll
    @{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
    @{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Cartella compressa*/%SystemRoot%\System32\zipfldr.dll = %SystemRoot%\System32\zipfldr.dll
    @{BD472F60-27FA-11cf-B8B4-444553540000} /*Compressed (zipped) Folder Right Drag Handler*/%SystemRoot%\System32\zipfldr.dll = %SystemRoot%\System32\zipfldr.dll
    @{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} /*Compressed (zipped) Folder SendTo Target*/%SystemRoot%\System32\zipfldr.dll = %SystemRoot%\System32\zipfldr.dll
    @{1D2680C9-0E2A-469d-B787-065558BC7D43} /*Fusion Cache*/C:\WINDOWS\System32\mscoree.dll = C:\WINDOWS\System32\mscoree.dll
    @{640167b4-59b0-47a6-b335-a6b3c0695aea} /*Portable Media Devices*/%SystemRoot%\System32\Audiodev.dll = %SystemRoot%\System32\Audiodev.dll
    @{cc86590a-b60a-48e6-996b-41d25ed39a1e} /*Portable Media Devices Menu*/%SystemRoot%\System32\Audiodev.dll = %SystemRoot%\System32\Audiodev.dll
    @{8DD448E6-C188-4aed-AF92-44956194EB1F} /*Windows Media Player Play as Playlist Context Menu Handler*/C:\WINDOWS\System32\wmpshell.dll = C:\WINDOWS\System32\wmpshell.dll
    @{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} /*Windows Media Player Burn Audio CD Context Menu Handler*/C:\WINDOWS\System32\wmpshell.dll = C:\WINDOWS\System32\wmpshell.dll
    @{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} /*Windows Media Player Add to Playlist Context Menu Handler*/C:\WINDOWS\System32\wmpshell.dll = C:\WINDOWS\System32\wmpshell.dll
    
    HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Cartelle Web*/ = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
    
    HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
    EditPlus@{63AFBDFB-5EF8-4791-AF79-9A3C0DE48974} = C:\Programmi\EditPlus 2\eppshell.dll
    Offline Files@{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
    Open With@{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
    Open With EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
    Symantec.Norton.Antivirus.IEContextMenu@{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Programmi\Norton AntiVirus\NavShExt.dll
    WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
    
    HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} = %SystemRoot%\system32\SHELL32.dll
    
    HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
    EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
    Offline Files@{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
    Sharing@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
    WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
    
    HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
    Symantec.Norton.Antivirus.IEContextMenu@{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Programmi\Norton AntiVirus\NavShExt.dll
    WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
    
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
    @{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx = C:\Programmi\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    @{BDF3E430-B101-42AD-A544-FADC6B084872}C:\Programmi\Norton AntiVirus\NavShExt.dll = C:\Programmi\Norton AntiVirus\NavShExt.dll
    
    HKLM\Software\Microsoft\Internet Explorer\Main >>>
    @Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
    @Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
    @Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
    
    HKCU\Software\Microsoft\Internet Explorer\Main >>>
    @Start Pagehttp://www.tecnoborsa.it/ = http://www.tecnoborsa.it/
    @Local PageC:\WINDOWS\System32\blank.htm = C:\WINDOWS\System32\blank.htm
    
    HKLM\Software\Classes\PROTOCOLS\Filter\ >>>
    application/octet-stream@CLSID = C:\WINDOWS\System32\mscoree.dll
    application/x-complus@CLSID = C:\WINDOWS\System32\mscoree.dll
    application/x-msdownload@CLSID = C:\WINDOWS\System32\mscoree.dll
    Class Install Handler@CLSID = C:\WINDOWS\system32\urlmon.dll
    deflate@CLSID = C:\WINDOWS\system32\urlmon.dll
    gzip@CLSID = C:\WINDOWS\system32\urlmon.dll
    lzdhtml@CLSID = C:\WINDOWS\system32\urlmon.dll
    text/webviewhtml@CLSID = %SystemRoot%\system32\SHELL32.dll
    
    HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
    about@CLSID = %SystemRoot%\System32\mshtml.dll
    cdl@CLSID = C:\WINDOWS\system32\urlmon.dll
    dvd@CLSID = C:\WINDOWS\System32\msvidctl.dll
    file@CLSID = C:\WINDOWS\system32\urlmon.dll
    ftp@CLSID = C:\WINDOWS\system32\urlmon.dll
    gopher@CLSID = C:\WINDOWS\system32\urlmon.dll
    http@CLSID = C:\WINDOWS\system32\urlmon.dll
    https@CLSID = C:\WINDOWS\system32\urlmon.dll
    its@CLSID = C:\WINDOWS\System32\itss.dll
    javascript@CLSID = %SystemRoot%\System32\mshtml.dll
    lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
    local@CLSID = C:\WINDOWS\system32\urlmon.dll
    mailto@CLSID = %SystemRoot%\System32\mshtml.dll
    mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
    mk@CLSID = C:\WINDOWS\system32\urlmon.dll
    ms-its@CLSID = C:\WINDOWS\System32\itss.dll
    msnim@CLSID = "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
    res@CLSID = %SystemRoot%\System32\mshtml.dll
    sysimage@CLSID = %SystemRoot%\System32\mshtml.dll
    tv@CLSID = C:\WINDOWS\System32\msvidctl.dll
    vbscript@CLSID = %SystemRoot%\System32\mshtml.dll
    vnd.ms.radio@CLSID = C:\WINDOWS\System32\msdxm.ocx
    wia@CLSID = C:\WINDOWS\System32\wiascr.dll
    
    HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters@Domain = 
    
    HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ >>>
    000000000001@LibraryPath = %SystemRoot%\System32\mswsock.dll
    000000000002@LibraryPath = %SystemRoot%\System32\winrnr.dll
    000000000003@LibraryPath = %SystemRoot%\System32\mswsock.dll
    
    HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
    000000000001@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000002@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000003@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000004@PackedCatalogItem = %SystemRoot%\system32\rsvpsp.dll
    000000000005@PackedCatalogItem = %SystemRoot%\system32\rsvpsp.dll
    000000000006@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000007@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000008@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000009@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000010@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000011@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000012@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000013@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000014@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000015@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000016@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000017@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    000000000018@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    
    HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
    
    C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica >>>
    Acrobat Assistant.lnk = Acrobat Assistant.lnk
    Post-it® Software Notes.lnk = Post-it® Software Notes.lnk
    
    ---- EOF - GMER 1.0.10 ----
    .. aspetto vostre notizie..
    ciao

  5. #5
    scaricati hijackthis da qui---> http://www.angololibero.it/software/...ijackthis.html
    avvialo,clicca su do a system scan and save logfile,fara una piccola scansione,uscira' un logfile con delle scritte,riporta tutto qui con un copia|incolla.

  6. #6
    Utente di HTML.it
    Registrato dal
    Oct 2001
    Messaggi
    855
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14.15.21, on 27/08/2007
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Programmi\Norton AntiVirus\navapsvc.exe
    C:\Programmi\Norton Internet Security\NISUM.EXE
    C:\Programmi\Norton Internet Security\NISSERV.EXE
    C:\Programmi\Norton Internet Security\SymProxySvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programmi\Compaq\Easy Access Button Support\StartEAK.exe
    C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
    C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
    C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Programmi\Norton Internet Security\IAMAPP.EXE
    C:\PROGRA~1\NORTON~1\navapw32.exe
    C:\Programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\Programmi\3M\PSNotes\psn.exe
    C:\Programmi\Compaq\Easy Access Button Support\CPQEADM.EXE
    C:\Compaq\EAKDRV\EAUSBKBD.EXE
    C:\PROGRA~1\3M\PSNotes\PSNGive.exe
    C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
    C:\Programmi\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\System32\mdm.exe
    C:\lavoro\programmi\programmi per pulizia linkopt\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tecnoborsa.it/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = proxya.icnet:38080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [CPQEASYACC] C:\Programmi\Compaq\Easy Access Button Support\StartEAK.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [Local Service] rundll.exe
    O4 - HKLM\..\Run: [Microsoft WinUpdate] svchosts.exe
    O4 - HKLM\..\Run: [iamapp] C:\Programmi\Norton Internet Security\IAMAPP.EXE
    O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\RunServices: [Microsoft WinUpdate] svchosts.exe
    O4 - HKLM\..\RunServices: [Local Service] rundll.exe
    O4 - HKCU\..\Run: [Microsoft WinUpdate] svchosts.exe
    O4 - HKCU\..\Run: [Local Service] rundll.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Post-it® Software Notes.lnk = C:\Programmi\3M\PSNotes\psn.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\MSMSGS.EXE
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://www.mps.it/CertEnroll/CertCo...ta/xenroll.dll
    O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://sito/gest_db_marketing/ScriptX/smsx.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9241F06A-591F-439F-B113-0683D76CF927}: NameServer = 1.70.4.12,1.70.4.59
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Programmi\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programmi\File comuni\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Servizio Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Programmi\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Programmi\Norton Internet Security\NISSERV.EXE
    O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Programmi\Norton Internet Security\NISUM.EXE
    O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\oracle\ora81\BIN\ONRSD.EXE
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
    O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\SymProxySvc.exe

    --
    End of file - 6235 bytes

  7. #7
    Utente bannato
    Registrato dal
    Jun 2007
    Messaggi
    3,899
    seleziona queste voci e vai su fix checked:

    O4 - HKLM\..\Run: [Local Service] rundll.exe
    O4 - HKLM\..\Run: [Microsoft WinUpdate] svchosts.exe
    O4 - HKLM\..\RunServices: [Microsoft WinUpdate] svchosts.exe
    O4 - HKLM\..\RunServices: [Local Service] rundll.exe
    O4 - HKCU\..\Run: [Microsoft WinUpdate] svchosts.exe
    O4 - HKCU\..\Run: [Local Service] rundll.exe

    poi fai una ricerca nel computer e dicci il percorso dei files...

  8. #8
    Utente di HTML.it
    Registrato dal
    Oct 2001
    Messaggi
    855
    sto facendo col trova file per vedere dove sono questi file

  9. #9
    Utente bannato
    Registrato dal
    Jun 2007
    Messaggi
    3,899
    va bene io aspetto...

  10. #10
    Utente di HTML.it
    Registrato dal
    Oct 2001
    Messaggi
    855
    facendo la ricerca questi due file non ci sono...


Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.