Visualizzazione dei risultati da 1 a 3 su 3

Discussione: [SpYware] problema

  1. #1
    Utente di HTML.it
    Registrato dal
    Jul 2003
    Messaggi
    185

    [SpYware] problema

    Il mio problema sono sti minkia di spyware io ho usato ad-ware
    6.0 .. ma quando li cancello tanto mi si ricreano

    ...

    il fatto è che tipo uno di questi ogni tanto compie una ricerca
    del modem ( che peraltro risulta negativa ) cercando quindi di
    connettersi ad una linea a pagamento ( presumo ) e ciò non mi va molto a genio

    questi sono i log di HijackThis; se qualcuno sa dimti qualcosa glie ne sarei grato

    bye

    Logfile of HijackThis v1.97.7
    Scan saved at 21.16.19, on 01/06/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\services\wmplayer.exe
    C:\Programmi\Ahead\InCD\InCD.exe
    C:\Programmi\File comuni\Real\Update_OB\realsched.exe
    C:\Program Files\Mikersoft\ANT\ANT.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Programmi\Messenger\msmsgs.exe
    C:\Programmi\Apache Group\Apache\Apache.exe
    C:\Programmi\Network Associates\VirusScan\Avsynmgr.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Programmi\Apache Group\Apache\Apache.exe
    C:\Programmi\Ahead\InCD\InCDsrv.exe
    C:\mysql\bin\mysqld-nt.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\OpenSSH\bin\cygrunsrv.exe
    C:\OpenSSH\usr\sbin\sshd.exe
    C:\Programmi\Network Associates\VirusScan\VsStat.exe
    C:\Programmi\Network Associates\VirusScan\Vshwin32.exe
    C:\Programmi\File comuni\Network Associates\McShield\Mcshield.exe
    C:\Programmi\Network Associates\VirusScan\Avconsol.exe
    C:\Programmi\WinMX\WinMX.exe
    C:\Programmi\Windows Media Player\wmplayer.exe
    C:\Programmi\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Standard\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    F1 - win.ini: run=C:\WINDOWS\System32\services\wmplayer.exe
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {364ED85E-B67C-409A-B339-FAE274E4FC73} - C:\WINDOWS\System32\dicbpoa.dll
    O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
    O2 - BHO: (no name) - {9056A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - c:\sysfwb\8448811387\iefwbar.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Programmi\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe /waitservice
    O4 - HKLM\..\Run: [systemdll32.dll] C:\WINDOWS\system\sysinit32.exe
    O4 - HKLM\..\Run: [ANT] C:\Program Files\Mikersoft\ANT\ANT.exe
    O4 - HKLM\..\Run: [xpsystem] C:\WINDOWS\System32\services\wmplayer.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LookAtFile] C:\Programmi\Lavalys\Look@FILE PRO\LookAtFile.exe
    O4 - HKCU\..\Run: [SpyKiller] C:\Programmi\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [xpsystem] C:\WINDOWS\System32\services\wmplayer.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
    O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
    O16 - DPF: {53AEE57C-FEF2-404C-8791-BEAFAC6FDB6A} (VacPro.italia_ver3) - http://www.advnt01.com/dialer/italia_ver3.CAB
    O16 - DPF: {9076A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - http://www.fizzlewizzle.com/installfiles/popblocker.cab
    O16 - DPF: {91BE8DAC-957E-416C-B735-E2B63CDB915B} (MyEMessengerSetup Control) - http://www.myemessenger.com/activex/...tupProject.cab
    O16 - DPF: {92F02779-6D88-4958-8AD3-83C12A16ADC7} - file://C:\WINDOWS\system32\SearchBar\zpprf1sh.exe
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...001.1421643519
    O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/SassCln.CAB
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CBEFD02B-5601-4E16-BAC1-BD166FF08608}: NameServer = 62.94.0.1

  2. #2
    Per il log di HJT non posso aiutarti, ma per evitare che le connessioni ti partano in auto, stoppa e disabilita il servzio Auto Connection Manager.

    |-- [ Sopravvissuto dell'era Grunge ] -- [Seguace del Flying Spaghetti Monster]

    Linux Registered User # 401070 - Running SuSE 10

  3. #3
    Moderatore di Sicurezza informatica e virus L'avatar di amvinfe
    Registrato dal
    May 2002
    Messaggi
    6,739
    Come prima cosa scaricati SpHjfix ti servirà pià avanti.
    Ed anche CWShredder


    Assicurati d'avere messo HJT dentro una cartella, questo per permettere allo stesso programma di creare un backup dei files che andrai ad eliminare.

    Apri HJT metti la spunta al fianco dei seguenti valori e clicca su Fix checked:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\dicbpoa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about :blank
    F1 - win.ini: run=C:\WINDOWS\System32\services\wmplayer.exe
    O2 - BHO: (no name) - {364ED85E-B67C-409A-B339-FAE274E4FC73} - C:\WINDOWS\System32\dicbpoa.dll
    O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
    O2 - BHO: (no name) - {9056A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - c:\sysfwb\8448811387\iefwbar.dll
    O4 - HKLM\..\Run: [systemdll32.dll] C:\WINDOWS\system\sysinit32.exe
    O4 - HKLM\..\Run: [xpsystem] C:\WINDOWS\System32\services\wmplayer.exe
    O4 - HKCU\..\Run: [xpsystem] C:\WINDOWS\System32\services\wmplayer.exe
    O16 - DPF: {53AEE57C-FEF2-404C-8791-BEAFAC6FDB6A} (VacPro.italia_ver3) - http://www.advnt01.com/dialer/italia_ver3.CAB
    O16 - DPF: {92F02779-6D88-4958-8AD3-83C12A16ADC7} - file://C:\WINDOWS\system32\SearchBar\zpprf1sh.exe

    Apri il programma SpHjfix e lancialo. Riavvia in modalità provvisoria è importante (!) (tasto F8 prima che il sistema operativo venga caricato). Cerca ed elimina (anche dal cestino) i seguenti files:

    C:\WINDOWS\System32\services\wmplayer.exe <=== il file Fai attenzione all'esatto percorso del file (!) questo (!) non è il file reale di WMPlayer
    c:\sysfwb \8448811387\iefwbar.dll <=== la cartella
    C:\WINDOWS\system\sysinit32.exe <=== il file
    C:\WINDOWS\system32\SearchBar \zpprf1sh.exe <=== la cartella

    Riavvia e lancia CWShredder.
    Riavvia e posta un nuovo Log di HJT

    Dimenticavo:
    il programma SpyKiller io ti consiglierei di rimuoverlo in quanto (a scriverlo sembrerebbe strano) installa spyware
    ==
    Visita il mio blog SuspectFile.com
    ==

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.