Visualizzazione dei risultati da 1 a 3 su 3
  1. #1

    errore scvhost.exe - possibile virus

    mi date un occhio al log


    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 21.37.56, on 22/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\windows\system32\svchost.exe
    C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Programmi\IVT Corporation\BlueSoleil\BTNtService.exe
    C:\WINDOWS\system32\ckrlpbuu.exe
    C:\Programmi\Eset\nod32krn.exe
    C:\WINDOWS\system32\UStorSrv.exe
    C:\Programmi\Eset\nod32kui.exe
    C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
    C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\smtsvc.exe
    C:\Programmi\BestsellerAntivirus\pgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe
    C:\Programmi\MSN Messenger\usnsvc.exe
    C:\Programmi\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\explorer.exe
    C:\Programmi\Outlook Express\msimn.exe
    C:\Programmi\Internet Explorer\iexplore.exe
    C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\star\Impostazioni locali\Temporary Internet Files\Content.IE5\KH2RCL6J\HiJackThis_v2[1].exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ig?hl=it
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {24172C33-4329-4A75-9136-51682C3710A3} - C:\WINDOWS\system32\qopop.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: {e7e01a31-d077-03e8-d554-a6e7b187c8e9} - {9e8c781b-7e6a-455d-8e30-770d13a10e7e} - C:\WINDOWS\system32\cwqfaqkn.dll
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\qkfvenpm.dll
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\qkfvenpm.dll
    O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programmi\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [nod32kui] C:\Programmi\Eset\nod32kui.exe /WAITSERVICE
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe "
    O4 - HKLM\..\Run: [System Terminal Storage] smtsvc.exe
    O4 - HKLM\..\Run: [NI.UGA6P_0001_N122M2210] "C:\DOCUME~1\star\IMPOST~1\Temp\exjegpqb.exe"
    O4 - HKLM\..\Run: [BestsellerAntivirus] C:\Programmi\BestsellerAntivirus\pgs.exe
    O4 - HKLM\..\Run: [88ab7380] rundll32.exe "C:\WINDOWS\system32\btoymidc.dll",b
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
    O4 - Global Startup: BlueSoleil.lnk = C:\Programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1194718013817
    O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0099C7E.dat
    O20 - Winlogon Notify: qkfvenpm - C:\WINDOWS\SYSTEM32\qkfvenpm.dll
    O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programmi\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: DomainService - - C:\WINDOWS\system32\ckrlpbuu.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Programmi\Eset\nod32krn.exe
    O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe

    --
    End of file - 5864 bytes

  2. #2
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    scarica CCleaner, Avenger, combofix, Vundofix, Fixvundo e Superantispyware (installa e aggiorna programma)

    Disattiva il ripristino configurazione di sistema (start - pannello di controllo - sistema - ripristino configurazione di sistema - spunta "disattiva ripristino configuraz. di sistema")

    Ripulisci temp/cookie e registro con CCleaner (la prima volta che lo esegui vai su "opzioni" => "avanzate" => togli la spunta su "cancella file in Windows Temp solo se piu vecchi di 48 ore" e quindi ripulisci.)

    fixa con hjt
    O2 - BHO: (no name) - {24172C33-4329-4A75-9136-51682C3710A3} - C:\WINDOWS\system32\qopop.dll
    O2 - BHO: {e7e01a31-d077-03e8-d554-a6e7b187c8e9} - {9e8c781b-7e6a-455d-8e30-770d13a10e7e} - C:\WINDOWS\system32\cwqfaqkn.dll
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\qkfvenpm.dll
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\qkfvenpm.dll
    O4 - HKLM\..\Run: [NI.UGA6P_0001_N122M2210] "C:\DOCUME~1\star\IMPOST~1\Temp\exjegpqb.exe"
    O4 - HKLM\..\Run: [88ab7380] rundll32.exe "C:\WINDOWS\system32\btoymidc.dll",b
    O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0099C7E.dat
    O20 - Winlogon Notify: qkfvenpm - C:\WINDOWS\SYSTEM32\qkfvenpm.dll
    O23 - Service: DomainService - - C:\WINDOWS\system32\ckrlpbuu.exe


    Esegui avenger, seleziona l'opzione "Input Script Manually" e clicca sulla lente d'ingrandimento.
    All'interno della finestra "Wiew/edit script", nel box bianco, copia/incolla:
    files to delete:
    C:\WINDOWS\system32\qopop.dll
    C:\WINDOWS\system32\cwqfaqkn.dll
    C:\WINDOWS\system32\qkfvenpm.dll
    C:\DOCUME~1\star\IMPOST~1\Temp\exjegpqb.exe
    C:\WINDOWS\system32\btoymidc.dll
    C:\WINDOWS\system32\__c0099C7E.dat
    C:\WINDOWS\system32\ckrlpbuu.exe

    Registry values to replace with dummy:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
    Clicca sul pulsante "Done", poi sul semaforo verde, rispondi 2 volte Yes.
    Il pc dovrebbe riavviarsi da solo, altrimenti riavvialo tu.
    Posta il report rilasciato.

    Esegui le scansioni con Vundofix, FixVundo, SUPERAntiSpyware e combofix.

    Posta i risultati di Combofix e un nuovo log di hjt.
    Evita di eseguire la procedura in modo spezzettato perchè il Vundo si riproduce (sono presenti dei file-copia).

  3. #3
    ok,

    grazie ora provo e ti dico

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.