Salve a tutti,
sono appena entrato a far parte del vostro forum che ho conosciuto casualmente navigando alla disperata ricerca di soluzioni.
Grazie ad alcuni post letti sono riuscito a sterminare numerose "BESTIACCE" (o almeno credo).
Adesso vi chiedo cortesemente di dare un'occhiata ai log di ewido e HiJackthis:
---------------------------------------------------------
ewido anti-malware - Rapporto Scansione
---------------------------------------------------------
+ Creato il: 10.36.06, 22/02/2006
+ Report-Checksum: 4BAEE2DE
+ Risultati scansione:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{59879FA4-4790-461c-A1CC-4EC4DE4CA483} -> Adware.RXToolbar : Pulito con Backup
HKU\S-1-5-21-3646181656-590260106-813958858-500\Software\Microsoft\Windows\CurrentVersion\Ext\ Stats\{59879FA4-4790-461C-A1CC-4EC4DE4CA483} -> Adware.RXToolbar : Pulito con Backup
C:\WINDOWS\Downloaded Program Files\dialere.exe -> Trojan.Dialer.on : Pulito con Backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\dialere.exe -> Trojan.Dialer.on : Pulito con Backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\dialere.exe -> Trojan.Dialer.on : Pulito con Backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\dialere.exe -> Trojan.Dialer.on : Pulito con Backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\dialere.exe -> Trojan.Dialer.on : Pulito con Backup
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\6VE94ZUN\dialere[1].exe -> Trojan.Dialer.on : Pulito con Backup
C:\Documents and Settings\Administrator\Cookies\administrator@click bank[2].txt -> TrackingCookie.Clickbank : Pulito con Backup
C:\Documents and Settings\Administrator\Dati applicazioni\sgrunt\IE4321.exe -> Trojan.Dialer.hc : Pulito con Backup
C:\Documents and Settings\ced\Cookies\ced@doubleclick[1].txt -> TrackingCookie.Doubleclick : Pulito con Backup
C:\Documents and Settings\ced\Cookies\ced@doubleclick[3].txt -> TrackingCookie.Doubleclick : Pulito con Backup
C:\Documents and Settings\administrator.DOMINIO\Impostazioni locali\Temporary Internet Files\Content.IE5\MZXL3L74\dialere[1].exe -> Trojan.Dialer.on : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP106\A0017823.exe -> Trojan.Dialer.hh : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP106\A0017853.exe -> Trojan.Dialer.hh : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP110\A0021923.exe -> Trojan.Dialer.hh : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021932.exe -> Adware.BetterInternet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021933.dll -> Adware.Cydoor : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021938.dll -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021946.exe -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021948.dll -> Adware.BrilliantDigital : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021959.exe -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021963.dll -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021965.dll -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021966.dll -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021967.exe -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021968.dll -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021969.dll -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021971.exe -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021972.dll -> Adware.Altnet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021976.exe -> Adware.BetterInternet : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021982.dll -> Adware.RXBar : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP112\A0021983.dll -> Adware.RXBar : Pulito con Backup
C:\System Volume Information\_restore{70206334-CB21-42E7-B0CD-61D100FBBCF2}\RP117\A0022118.dll -> Adware.404Search : Pulito con Backup
::Fine Rapporto
Logfile of HijackThis v1.99.1
Scan saved at 10.51.17, on 22/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NETSUP~1\client32.exe
C:\Programmi\Symantec AntiVirus\DefWatch.exe
C:\Programmi\ewido anti-malware\ewidoctrl.exe
C:\Programmi\ewido anti-malware\ewidoguard.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\Java\j2re1.4.2_01\bin\jusched.exe
C:\Programmi\Aspire Arcade\PCMService.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\LAUNCH~1\CPLFL32.EXE
C:\Programmi\Microsoft AntiSpyware\gcasServ.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Microsoft AntiSpyware\gcasDtServ.exe
C:\Documents and Settings\Administrator\Desktop\Hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lumsa.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 192.168.4.12:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Programmi\Aspire Arcade\PCMService.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLFL32.EXE
O4 - HKLM\..\Run: [gcasServ] "C:\Programmi\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.sgrunt.biz
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: www.superspots.biz
O15 - Trusted Zone: www.xbeta69.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dominio.local
O17 - HKLM\Software\..\Telephony: DomainName = dominio.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{74DBF739-83D5-4465-857F-067E38BDFC46}: NameServer = 192.168.0.5
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dominio.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dominio.local
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BusinessC (BusinessContinuity) - Unknown owner - C:\WINDOWS\msstl.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programmi\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmi\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmi\ewido anti-malware\ewidoguard.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programmi\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programmi\Symantec AntiVirus\Rtvscan.exe
Grazie mille a tutti....siete bravissimi !