Visualizzazione dei risultati da 1 a 4 su 4
  1. #1
    Utente di HTML.it
    Registrato dal
    Feb 2008
    Messaggi
    2

    problema con intruder-downloader

    Ciao a tutti--ho 1 problema kn il mio pc in quanto penso che c sia la presenza di 1o o + virus(presumibilmente intruder-downloader). ho dei problemi il pc x quanto riguarda la configurazione che a volte risulta alterata o cambiata( come ad esempio su internet),per quanto riguarda la velocità di risposta del pc. ( sembrerebbe strano ma mi trovo delle applicazioni mai viste)
    kaspersky 7.0 che mi detecta:
    riskware Invader Running process: H:\WINDOWS\system32\nvsvc32.exe
    detected: riskware Invader Running process: H:\WINDOWS\Explorer.EXE
    detected: riskware Invader Running process: H:\WINDOWS\SYSTEM32\winlogon.exe
    detected: riskware Invader Running process: H:\WINDOWS\system32\svchost.exe
    detected: riskware Invader Running process: H:\WINDOWS\System32\svchost.exe
    detected: riskware Invader Running process: H:\Programmi\WinRAR\WinRAR.exe
    detected: riskware Invader Running process: H:\Documents and Settings\Serv Ass\Impostazioni locali\Temp\Rar$EX00.953\kis7.0.1.321en.exe


    ed ecco il log di hijackthis:
    Logfile of HijackThis v1.99.1
    Scan saved at 1:54:18 , on 01/02/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)

    Running processes:
    H:\WINDOWS\System32\smss.exe
    H:\WINDOWS\SYSTEM32\winlogon.exe
    H:\WINDOWS\system32\services.exe
    H:\WINDOWS\system32\lsass.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\system32\LEXBCES.EXE
    H:\WINDOWS\system32\LEXPPS.EXE
    H:\WINDOWS\system32\spoolsv.exe
    H:\WINDOWS\Explorer.EXE
    H:\WINDOWS\ehome\ehtray.exe
    H:\WINDOWS\RTHDCPL.EXE
    H:\WINDOWS\system32\dla\tfswctrl.exe
    H:\Programmi\ScanSoft\OmniPageSE\opware32.exe
    H:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
    H:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
    H:\Programmi\QuickTime\qttask.exe
    H:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    H:\Programmi\SimpleCenter\bin\win\sclauncher.exe
    H:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
    H:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
    H:\Programmi\Google\GoogleToolbarNotifier\GoogleTo olbarNotifier.exe
    H:\WINDOWS\system32\ctfmon.exe
    H:\Programmi\DNA\btdna.exe
    H:\Programmi\Red Chair Software\Anapod Explorer\anamgr.exe
    H:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
    H:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    H:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
    H:\WINDOWS\eHome\ehRecvr.exe
    H:\WINDOWS\eHome\ehSched.exe
    H:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
    H:\WINDOWS\system32\nvsvc32.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\system32\ntvdm.exe
    H:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
    H:\WINDOWS\system32\dllhost.exe
    H:\WINDOWS\eHome\ehmsas.exe
    H:\WINDOWS\system32\wuauclt.exe
    H:\Programmi\Mozilla Firefox\firefox.exe
    H:\Programmi\Internet Explorer\iexplore.exe
    H:\Programmi\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.huddi.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
    R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - H:\Programmi\Share_Accelerator_MM\tbSha0.dll
    O1 - Hosts: 89.186.66.247 L2authd.lineage2.com
    O1 - Hosts: 89.186.66.247 L2testauthd.lineage2.com
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - H:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
    O2 - BHO: (no name) - {2C4C5B75-A58A-4FEF-8129-BBD7C17FEC72} - (no file)
    O2 - BHO: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - H:\Programmi\Share_Accelerator_MM\tbSha0.dll
    O2 - BHO: (no name) - {5A3F94BF-C1B1-4C04-A7A5-206C37E9576A} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - H:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {830E7C88-E6C9-4DCF-BF5B-24CD374F9B20} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - h:\programmi\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - H:\Programmi\Google\GoogleToolbarNotifier\2.0.301. 7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - H:\Programmi\Windows Live Toolbar\msntb.dll
    O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\programmi\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Virgilio Toolbar - {D3403F28-7D39-435F-A8CB-45016C29E48E} - H:\Programmi\Virgilio Toolbar\VirgilioBand.dll
    O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
    O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - H:\Programmi\Share_Accelerator_MM\tbSha0.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - H:\Programmi\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ehTray] H:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] "H:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [dla] H:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Omnipage] H:\Programmi\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [Camera Detector] H:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
    O4 - HKLM\..\Run: [DAEMON Tools] "H:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Programmi\Java\jre1.6.0_01\bin\jusched.exe "
    O4 - HKLM\..\Run: [MSKDetectorExe] H:\Programmi\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [QuickTime Task] "H:\Programmi\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NSLauncher] H:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "H:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [sclauncher] H:\Programmi\SimpleCenter\bin\win\sclauncher.exe
    O4 - HKLM\..\Run: [AVP] "H:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "H:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [msnmsgr] "H:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] H:\Programmi\Google\GoogleToolbarNotifier\GoogleTo olbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BitTorrent DNA] "H:\Programmi\DNA\btdna.exe"
    O4 - Startup: Anapod Manager.lnk = H:\Programmi\Red Chair Software\Anapod Explorer\anamgr.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = H:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: &Windows Live Search - res://H:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://H:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?dd6703e0f17c4f3a9feb5b80616d9f73
    O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://H:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?dd6703e0f17c4f3a9feb5b80616d9f73
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - H:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programmi\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - H:\Programmi\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://thelittleloserspace.spaces.li...d/MsnPUpld.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E94D1E0F-4ED7-4238-B10C-797845772CE9}: NameServer = 85.37.17.16 85.38.28.68
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - H:\Programmi\File comuni\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: klogon - H:\WINDOWS\system32\klogon.dll
    O20 - Winlogon Notify: sfc_os32 - sfc_os32.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O23 - Service: Apple Mobile Device - Apple, Inc. - H:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - H:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - H:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - H:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NBService - Nero AG - H:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - H:\Programmi\File comuni\Panda Software\PavShld\pavprsrv.exe (file missing)
    O23 - Service: ServiceLayer - Nokia. - H:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe

    vi ringrazio in anticipo =]

  2. #2
    Moderatore di Sicurezza informatica e virus L'avatar di amvinfe
    Registrato dal
    May 2002
    Messaggi
    6,739
    Scarica
    http://www.suspectfile.com/systemscan
    aprilo ed assicurati che tutte le opzioni siano spuntate, clicca su "Scan Now" al termine della scansione verrà rilasciato in C:\suspectfile un file con estensione .zip (data+ora+.zip)
    Vai su www.sendmefile.com carica il file e nella tua prossima risposta indica l'URL per poterlo scaricare.

    Ricordati d'effettuare la scansione non connesso e con l'antivirus disabilitato salvo poi riattivarlo a scansione terminata.
    ==
    Visita il mio blog SuspectFile.com
    ==

  3. #3

  4. #4
    Moderatore di Sicurezza informatica e virus L'avatar di amvinfe
    Registrato dal
    May 2002
    Messaggi
    6,739
    effettua una scansione online e posta il risultato, grazie.

    http://www.pandasoftware.com/actives..._principal.htm
    ==
    Visita il mio blog SuspectFile.com
    ==

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.