• User Newbie

    whatnew.name

    saresti gentili da controllarmi anche il mio.whatnew.nameLogfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17.55.56, on 08/12/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Programmi\Eset\nod32krn.exe
    C:\Programmi\Olivetti\ANY_WAY\olMntrService.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
    C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
    C:\Programmi\D-Link\AirPlus G\AirGCFG.exe
    C:\Programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
    C:\Programmi\Real\RealPlayer\RealPlay.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Programmi\File comuni\Logitech\QCDriver2\LVCOMS.EXE
    C:\Programmi\Logitech\ImageStudio\LogiTray.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Programmi\Olivetti\ANY_WAY\olDvcStatus.exe
    C:\Programmi\Eset\nod32kui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Programmi\MSN Messenger\MsnMsgr.Exe
    C:\Programmi\Pando Networks\Pando\Pando.exe
    C:\Programmi\DAEMON Tools\daemon.exe
    C:\WINDOWS\slrundll.exe
    C:\Programmi\MSN Messenger\usnsvc.exe
    C:\Programmi\eMule\emule.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Programmi\MSN Messenger\livecall.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Programmi\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Programmi\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://it.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://it.search.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
    O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM..\Run: [D-Link AirPlus G] C:\Programmi\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM..\Run: [ANIWZCS2Service] C:\Programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM..\Run: [RealTray] C:\Programmi\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM..\Run: [LVCOMS] C:\Programmi\File comuni\Logitech\QCDriver2\LVCOMS.EXE
    O4 - HKLM..\Run: [LogitechGalleryRepair] C:\Programmi\Logitech\ImageStudio\ISStart.exe
    O4 - HKLM..\Run: [LogitechImageStudioTray] C:\Programmi\Logitech\ImageStudio\LogiTray.exe
    O4 - HKLM..\Run: [OlStatusMon] "C:\Programmi\Olivetti\ANY_WAY\olDvcStatus.exe" dvcStatusMinimize
    O4 - HKLM..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU..\Run: [Pando] "C:\Programmi\Pando Networks\Pando\Pando.exe" /Minimized
    O4 - HKCU..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
    O4 - HKUS\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = D:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe
    O23 - Service: olMntrService - Olivetti - C:\Programmi\Olivetti\ANY_WAY\olMntrService.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O24 - Desktop Component 0: (no name) - http://thumbp1.mail.ukl.yahoo.com/tn?sid=2316905382&mid=ADgKDNkAAEUERuEZvAwldBA5BLU&partid=2&f=257&fid=Sent

    --
    End of file - 9156 bytes


  • Consiglio Direttivo

    Ciao davide3691,

    fixa con hijackthis questa chiave:

    O24 - Desktop Component 0: (no name) - http://thumbp1.mail.ukl.yahoo.com/tn?sid=2316905382&mid=ADgKDNkAAEUERuEZvAwldBA5 BLU& partid=2&f=257&fid=Sent

    Fatto questo, scarica the avenger.

    Avvia Avenger.exe e spunta l'opzione Input Script Manually. Clicca sulla lente di ingrandimento e riporta all'interno della finestra queste righe:

    Files to delete:
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exeClicca su Done, due volte sul semaforo verde e due volte su yes!
    Si dovrebbe riavviare il pc!

    Posta qui nel forum, il risultato di avenger che trovi in C:/avenger.txt! 🙂

    Infine, effettua una scansione con superantispyware.com "aggiornato"! 😉