PcPrimiPassi.it - informatica facile per tutti, home page
PcPrimiPassi.it - informatica facile per tutti, home page



Infezioni informatiche e Sicurezza informatica in generale

 PcPrimiPassi.it FORUMSICUREZZA INFORMATICAInfezioni informatiche e Sicurezza informatica in generale


Icona di Messaggio

Topic: Aiuto: adware/navipromo e panda

Altre pagine della discussione:




Crismon
Apprendista Apprendista
Crismon
Apprendista Apprendista
Crismon
Apprendista
Apprendista

Avatar


Iscritto dal : 10/Febbraio/2006
Da: Italy
Status: Offline
Posts: 374
Riporta il testo di: Crismon Rispondibullet Topic: Post n° 48.787 - Postato: 10/Febbraio/2006 alle 13:58


Ciao Ragazzi,

ho riscontrato un problema con panda antivirus e nn riesco a venirne a capo!!

Ad ogni avvio di windows mi si apre la finestra di panda con questo avviso:

Adware neutralized!

Adware name: Adware/navipromo

Location: c:\windows\system32\msclock32.dll

Mi connetto e mi dice:

Network virus blocked!

Virus name: exploit/RPC-DCOM

Faccio la scansione di tutto il pc

e sotto la voce SYSTEM compare

2 infetti

1 disinfettato che: c:\windows\system32\txclkbh_navps.dat

e anche questo succede a ogni riavvio e ogni scansione!

Il file txclkbh.exe è caricato nel task manager

questo è il rapporto di fine scansione:

%s incident report
Filter selected:Virus detected, Suspicious file, Dangerous file, Script execution, Phone connection, Connection attempt, Port scan attack, Denial of service attack, Spoofing, Attacking IP address blocked, Enabled, Disabled, Update, Scan started, Scan complete, Date: All
INCIDENT        & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;     NOTIFIED BY         & ; ;nbs p;         & ; ;nbs p; DATE-TIME        &am p;am p;nb sp;    RESULT                 ADDITIONAL INFORMATION        & amp; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbsp;         
------------------------------------------------------------ ------------------------------------------------------------ ------------------------------------------------------------ ------------------------------------------------------------ ------------------------------------------------------------ ------------------------------------------------------------ -------------
Scan complete        & ; ;nbs p;         & ; ;nbs p;          On-demand antivirus scan        02/10/06 10:32:52        & ; ;nbs p;         & ; ;nbs p;        Scan:         & amp; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbsp;         
Adware detected: adware/navipromo       &a mp;a mp;n bsp; On-demand antivirus scan        02/10/06 10:13:36     Disinfected        & amp; amp; nbsp;  Path: C:\WINDOWS\SYSTEM32\txclkbh_navps.dat     ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;     
Scan started          ; ; ;           ; ; ;           ; ; ; On-demand antivirus scan        02/10/06 10:12:18        & ; ;nbs p;         & ; ;nbs p;        Scan:         & amp; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbsp;        
Adware detected: adware/navipromo       &a mp;a mp;n bsp; On-demand antivirus scan        02/10/06 10:09:44     Disinfected        & amp; amp; nbsp;  Path: C:\WINDOWS\SYSTEM32\txclkbh_navps.dat     ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;     
Scan started          ; ; ;           ; ; ;           ; ; ; On-demand antivirus scan        02/10/06 10:08:22        & ; ;nbs p;         & ; ;nbs p;        Scan:         & amp; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbsp;        
Adware detected: adware/navipromo       &a mp;a mp;n bsp; On-demand antivirus scan        02/10/06 09:59:13     Disinfected        & amp; amp; nbsp;  Path: C:\WINDOWS\SYSTEM32\txclkbh_navps.dat     ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;     
Scan started          ; ; ;           ; ; ;           ; ; ; On-demand antivirus scan        02/10/06 09:57:42        & ; ;nbs p;         & ; ;nbs p;        Scan:         & amp; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbsp;        
Virus detected: Exploit/RPC-DCOM       &a mp;a mp;n bsp;  Antivirus protection        &a mp;a mp;n bsp;   02/10/06 09:56:45     Blocked          ; ; ;      Path:         & amp; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbsp; 
Adware detected: Adware/NaviPromo       &a mp;a mp;n bsp; Antivirus protection        &a mp;a mp;n bsp;   02/10/06 09:51:45     Disinfected        & amp; amp; nbsp;  Path: c:\windows\system32\msclock32.dll    &am p;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb sp;
Scan complete        & ; ;nbs p;         & ; ;nbs p;          On-demand antivirus scan        02/10/06 09:28:43        & ; ;nbs p;         & ; ;nbs p;        Scan:         & amp; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbsp;         
Adware detected: adware/navipromo       &a mp;a mp;n bsp; On-demand antivirus scan        02/10/06 09:28:40     Disinfected        & amp; amp; nbsp;  Path: C:\WINDOWS\SYSTEM32\txclkbh_navps.dat     ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;           ; ; ;     
Scan started          ; ; ;           ; ; ;           ; ; ; On-demand antivirus scan        02/10/06 09:27:06        & ; ;nbs p;         & ; ;nbs p;        Scan:         & amp; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbs p;         & ; amp; nbsp;        
Update                                       Update system                    02/10/06 09:27:01     Correct          ; ; ;      New virus signatures: 46         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;         & ; ;nbs p;       
Adware detected: Adware/NaviPromo       &a mp;a mp;n bsp; Antivirus protection        &a mp;a mp;n bsp;   02/10/06 09:17:36     Disinfected        & amp; amp; nbsp;  Path: c:\windows\system32\msclock32.dll    &am p;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb sp;
Adware detected: Adware/NaviPromo       &a mp;a mp;n bsp; Antivirus protection        &a mp;a mp;n bsp;   02/09/06 15:55:14     Disinfected        & amp; amp; nbsp;  Path: c:\windows\system32\msclock32.dll    &am p;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb s p;         & ;am p;nb sp;
Scan complete        & ; ;nbs p;         & ; ;nbs p;          On-demand

Sarei lieto se qualcuno mi aiutasse a risolvere il problema!

 



Modificato da Crismon il 2006/Febbraio/10 alle 10:42



lucas
Esperto Esperto
lucas
Esperto Esperto
lucas
Esperto
Esperto

Avatar

Security Advisor

Iscritto dal : 14/Aprile/2005
Da: Italy
Status: Offline
Posts: 6.715
Riporta il testo di: lucas Rispondibullet Topic: Post n° 48.790 - Postato: 10/Febbraio/2006 alle 14:55


ciao procurari 6 floppy vuoti appena formattati una volta che li hai apri panda,clicca su servizi>scegli dischi di ripristino
segui le istruzioni a schermo per la creazione dei floppy,quando hai fatto tutto vieni qui che ti spiego come fare per far partire panda da boot altrimenti difficilmente riuscirai ciao

Aspetta hai la possibilità di installare la console di ripristino?cioè hai il cd originale di installazione?se si dai una letta a questo articolo che lo eliminiamo dalla console
http://www.pcprimipassi.it/psoftware/psoftware.asp?ID=158


Modificato da lucas


Crismon
Apprendista Apprendista
Crismon
Apprendista Apprendista
Crismon
Apprendista
Apprendista

Avatar


Iscritto dal : 10/Febbraio/2006
Da: Italy
Status: Offline
Posts: 374
Riporta il testo di: Crismon Rispondibullet Topic: Post n° 48.792 - Postato: 10/Febbraio/2006 alle 15:08


Ciao Luca,

Innanzitutto grazie x l'interessamento!

Il problema è che il mio pc nn dispone di floppy...e nn ho nemmeno il cd!|

Come faccio?



Modificato da Crismon



lucas
Esperto Esperto
lucas
Esperto Esperto
lucas
Esperto
Esperto

Avatar

Security Advisor

Iscritto dal : 14/Aprile/2005
Da: Italy
Status: Offline
Posts: 6.715
Riporta il testo di: lucas Rispondibullet Topic: Post n° 48.793 - Postato: 10/Febbraio/2006 alle 15:18


Ok nessun problema,hai un portatile per caso?
Avvia il pc in modalità provvisoria con prompt dei comandi
Dovresti avere una schermata dos,dove lampeggia il cursore digita:

cd C:\WINDOWS\SYSTEM32  (nota che dopo cd c'è uno spazio)
Invio
del txclkbh_navps.dat (nota che dopo del c'è uno spazio)
Invio

cd C:\WINDOWS\SYSTEM32 (nota che dopo cd c'è uno spazio)
Invio
del
msclock32.dll (nota che dopo del c'è uno spazio)
Invio

Riavvia il pc,questa volta scegli solo modalità provvisoria
Avvia panda nota che ti potrebbe dire che panda non si avvia,quando ricevi quel messaggio riaprilo nuovamente e lancia una scansione completa,fammi sapere ciao


Modificato da lucas


Crismon
Apprendista Apprendista
Crismon
Apprendista Apprendista
Crismon
Apprendista
Apprendista

Avatar


Iscritto dal : 10/Febbraio/2006
Da: Italy
Status: Offline
Posts: 374
Riporta il testo di: Crismon Rispondibullet Topic: Post n° 48.795 - Postato: 10/Febbraio/2006 alle 15:43


Ho fatto tutto quello che mi hai detto:

x quanto riguarda panda mi si apre laschermata del menu di avvio ma nn mi fa la scansione

I file a parte msclock32.dll li avevo cancellati compreso txclkbh.exe!

msclock32.dll nn me lo trova e nn riuscivo nemmeno priva a individuarlo!

al successivo riavvio mi dice come succedeva in precedenza:(sempre panda) "a network virus has tried get into your computer. this attack has been bloched"




lucas
Esperto Esperto
lucas
Esperto Esperto
lucas
Esperto
Esperto

Avatar

Security Advisor

Iscritto dal : 14/Aprile/2005
Da: Italy
Status: Offline
Posts: 6.715
Riporta il testo di: lucas Rispondibullet Topic: Post n° 48.796 - Postato: 10/Febbraio/2006 alle 15:48


si devi attendere per la scansione ci usa farlo
quel messaggio è leggittimo tranquilla,aggiorna il sistema tramite windows update,puoi disattivare l'opzione adesso non so che versione hai,leggi questa guida per postare il log di Hijackthis evidentemente ci sono altri problemi che vediamo di risolvere ciao

Modificato da lucas


Crismon
Apprendista Apprendista
Crismon
Apprendista Apprendista
Crismon
Apprendista
Apprendista

Avatar


Iscritto dal : 10/Febbraio/2006
Da: Italy
Status: Offline
Posts: 374
Riporta il testo di: Crismon Rispondibullet Topic: Post n° 48.797 - Postato: 10/Febbraio/2006 alle 15:52


Io continuo a ringraziarti nel frattempo...

ecco il log

Logfile of HijackThis v1.99.1
Scan saved at 15.51.11, on 10/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\TPSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\PavFnSvr.exe
C:\Programmi\File comuni\Panda Software\PavShld\pavprsrv.exe
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\pavsrv51.exe
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\AVENGINE.EXE
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\AntiSpam\pskmssvc.exe
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\FIREWALL\PNMSRV.EXE
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\apvxdwin.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmi\FlyNet\CnxDslTb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\SRVLOAD.EXE
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\WebProxy.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\IFACE.EXE
C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\PAVJOBS.EXE
C:\Programmi\WinRAR\WinRAR.exe
C:\Documents and Settings\CrIsMoN\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Programmi\FlyNet\CnxDslTb.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\Inicio.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {54579C3D-A58D-4623-B5B5-465552BDA45B} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1 072_ASPIV4_XP.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x 86/client/wuweb_site.cab?1131209734671
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en /x86/client/muweb_site.cab?1139247915890
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (Damage Cleanup Server Control) - http://213.158.72.33/housecall/xscan53.cab
O16 - DPF: {8B3B8135-9DAA-40E7-8941-962795F9C1CB} - http://scripts.downloadv3.com/binaries/IA/syswbsvc32_EN_XP.c ab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloade r.cab
O16 - DPF: {C2481ED1-9896-4D49-AE90-69858DFDE446} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1 073_XP.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EFB23983-5803-4914-ADA3-C0EA2CFBDC37} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1 072_XP.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5C2ACD1-15C4-4617-8D1C-1 3179B67839B}: NameServer = 85.37.17.57 85.38.28.80
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software - C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Programmi\File comuni\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - PANDA SOFTWARE - C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\AntiSpam\pskmssvc.exe
O23 - Service: Panda Network Manager (PNMSRV) - Panda Software - C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\FIREWALL\PNMSRV.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software - C:\Programmi\Panda Software\Panda Platinum 2006 Internet Security\TPSrv.exe

 




Crismon
Apprendista Apprendista
Crismon
Apprendista Apprendista
Crismon
Apprendista
Apprendista

Avatar


Iscritto dal : 10/Febbraio/2006
Da: Italy
Status: Offline
Posts: 374
Riporta il testo di: Crismon Rispondibullet Topic: Post n° 48.799 - Postato: 10/Febbraio/2006 alle 15:59


volevo anche aggiungere che durante la scansione con panda in modalità normale mi rileva un'infezione sotto system!



lucas
Esperto Esperto
lucas
Esperto Esperto
lucas
Esperto
Esperto

Avatar

Security Advisor

Iscritto dal : 14/Aprile/2005
Da: Italy
Status: Offline
Posts: 6.715
Riporta il testo di: lucas Rispondibullet Topic: Post n° 48.800 - Postato: 10/Febbraio/2006 alle 16:01


Il log non presenta problemi

Apri Hijackthis,clicca sul 2° pulsante,metti le spunte nelle caselle che corrispondono a queste stringhe

O16 - DPF: {54579C3D-A58D-4623-B5B5-465552BDA45B} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCES S_1 072_ASPIV4_XP.cab

O16 - DPF: {8B3B8135-9DAA-40E7-8941-962795F9C1CB} - http://scripts.downloadv3.com/binaries/IA/syswbsvc32_EN_XP.c ab

O16 - DPF: {C2481ED1-9896-4D49-AE90-69858DFDE446} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1 073_XP.cab

O16 - DPF: {EFB23983-5803-4914-ADA3-C0EA2CFBDC37} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1 072_XP.cab

Clicca su "Fix Checked" per eliminarle

Hai il l'antivirus in inglese?comunque prova in questo modo adesso l'ultima versione non l'ho presente
comunque c'è un opzione di non avviso di attacchi alla rete gli attacchi vengono bloccati ma tu non viene avvisata ciao


Modificato da lucas


Crismon
Apprendista Apprendista
Crismon
Apprendista Apprendista
Crismon
Apprendista
Apprendista

Avatar


Iscritto dal : 10/Febbraio/2006
Da: Italy
Status: Offline
Posts: 374
Riporta il testo di: Crismon Rispondibullet Topic: Post n° 48.801 - Postato: 10/Febbraio/2006 alle 16:06


ok per l'avviso so come fare!

mi spieghi brevemente che cosa abbiamo cancellato?

Poi pensi che nod32 sia valido?

Grazie ancora Lucas, spero di nn aver + problemi ora!




Altre pagine della discussione:






Vai al Forum
Non puoi postare nuovi topic in questo forum
Non puoi rispondere ai topic in questo forum
Non puoi cancellare i tuoi post in questo forum
Non puoi modificare i tuoi post in questo forum
Non puoi creare sondaggi in questo forum
Non puoi votare i sondaggi in questo forum

Bulletin Board Software by Web Wiz Forums version PcPrimiPassi
Copyright ©2001-2006 Web Wiz Guide

Questa pagina è stata generata in 0,055 secondi.

Sostienici

Versione 5.7 Sviluppata da Stefano Ravagni