ciao a tutti, spero davvero in un aiuto. Ho molti dei sintomi del linkoptimizer.
ho eseguito la guida di p2p (
http://www.p2pforum.it/forum/showthread.php?t=115737), sia quella di suspectfile (
http://www.suspectfile.com/forum/viewtopic.php?t=156).
adesso ho eseguito le istruzioni di pc-facile in questo topic.
I file qui nominati che dovrei eliminare non li ho nemmeno io. in compenso in due dei cinque profili del mio XP nella cartella TEMP c'è un file .exe che non posso cancellare. lo posso rinominare ma non cancellare.
in c:\programmi avevo la cartella "linkoptimizer" e l'ho eliminata.
In c:\documents and settings avevo un utente dal nome "wIc" (che certamente non ho creato io) e l'ho eliminato.
Virit ogni volta che lo lancio mi trova due chiavi di registro infette e le elimina.
In piu' spesso zonealarm mi rileva un programma che tenta di accedere alla rete e lo blocco. Tale programma ha sempre nomi diversi e questi nomi sono sempre composti da quadratini, simboli di euro e dollaro e lettere accentate.
Ho lanciato PREVX e appena clicco su scan mi dice che non ha trovato nessun componente del trojan.gromozon nel mio pc. faccio proseguire ugualmente la scansione completa (dopo il riavvio) e mi dice che il mio sistema non è infetto ed e' sanissimo.
Ho cancellato con Cclean tutti i cookies, i temp, i tempor.int.files di tutti gli utenti.
adesso ho lanciato anche gmer e questi sono i risultati.
PS: tutto cio' che ho fatto e che ho qui descritto l'ho fatto da SAFE MODE in modo da non avere interferenze di programmi che partono all'avvio come AVG asntivirus, Spybot e ZoneAlarm.
se qualcuno ha qualsiasi suggerimento lo ringrazio sin da ora.
GMER 1.0.11.11390 -
http://www.gmer.net
Rootkit 2006-10-13 09:31:10
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.11 ----
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
---- Devices - GMER 1.0.11 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 86F98EB0
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 86F98EB0
---- EOF - GMER 1.0.11 ----
GMER 1.0.11.11390 -
http://www.gmer.net
Autostart 2006-10-13 09:33:55
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = c:\windows\system32\userinit.exe,,c:\windows\svchost.exe,"c:\windows\wifiset.exe",
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@DLLName = Ati2evxx.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Ati HotKey Poller@ = %SystemRoot%\system32\Ati2evxx.exe
ATI Smart /*ATI Smart*/@ = C:\WINDOWS\system32\ati2sgag.exe
Avg7Alrt /*AVG7 Alert Manager Server*/@ = C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
Avg7UpdSvc /*AVG7 Update Service*/@ = C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
CiSvc /*Servizio di indicizzazione*/@ = C:\WINDOWS\system32\cisvc.exe
Fax /*Fax*/@ = %systemroot%\system32\fxssvc.exe
IISADMIN /*Amministrazione di IIS*/@ = C:\WINDOWS\system32\inetsrv\inetinfo.exe
MDM /*Machine Debug Manager*/@ = "C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE"
MSFtpsvc /*Pubblicazione FTP*/@ = %SystemRoot%\system32\inetsrv\inetinfo.exe
SimpTcp /*Servizi semplici TCP/IP*/@ = %SystemRoot%\system32\tcpsvcs.exe
SLService /*SmartLinkService*/@ = slmdmsr.exe
SMTPSVC /*Protocollo SMTP (Simple Mail Transfer Protocol)*/@ = C:\WINDOWS\system32\inetsrv\inetinfo.exe
SNMP /*Servizio SNMP*/@ = %SystemRoot%\System32\snmp.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
StarWindService /*StarWind iSCSI Service*/@ = d:\Programmin\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\system32\wdfmgr.exe
UserAccess7 /*SecuROM User Access Service (V7)*/@ = C:\WINDOWS\system32\UAService7.exe
vsmon /*TrueVector Internet Monitor*/@ = C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service
W3SVC /*Pubblicazione sul Web*/@ = %SystemRoot%\system32\inetsrv\inetinfo.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SoundManSOUNDMAN.EXE = SOUNDMAN.EXE
@ATIPTA"C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" = "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
@NVIDIA nTune"C:\Programmi\NVIDIA Corporation\nTune\\nTune.exe" clear = "C:\Programmi\NVIDIA Corporation\nTune\\nTune.exe" clear
@ASUS ProbeC:\Program Files\ASUS\Asus Probe\AsusProb.exe = C:\Program Files\ASUS\Asus Probe\AsusProb.exe
@AVG7_CCC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
@AVG7_EMCC:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
@SunJavaUpdateSchedC:\Programmi\Java\jre1.5.0_06\bin\jusched.exe = C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
@MediaKeyC:\PROGRA~1\INTERN~2\MEDIAKEY.EXE = C:\PROGRA~1\INTERN~2\MEDIAKEY.EXE
@Zone Labs Client"D:\Programmin\Zone Labs\ZoneAlarm\zlclient.exe" = "D:\Programmin\Zone Labs\ZoneAlarm\zlclient.exe"
@MSConfigC:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
@VIRIT LITE MONITORD:\PROGRAMMIN\VEXPLITE\MONLITE.EXE = D:\PROGRAMMIN\VEXPLITE\MONLITE.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run@wifiset = "c:\windows\wifiset.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run@CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@UPnPMonitor = C:\WINDOWS\system32\upnpui.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{5a61f7a0-cde1-11cf-9113-00aa00425c62} /*IIS Shell Extension*/C:\WINDOWS\system32\inetsrv\w3ext.dll = C:\WINDOWS\system32\inetsrv\w3ext.dll
@{e57ce731-33e8-4c51-8354-bb4de9d215d1} /*Periferiche Plug and Play universali*/C:\WINDOWS\system32\upnpui.dll = C:\WINDOWS\system32\upnpui.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\OFFICE11\msohev.dll = C:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG7 Shell Extension*/C:\Programmi\Grisoft\AVG Free\avgse.dll = C:\Programmi\Grisoft\AVG Free\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG7 Find Extension*/C:\Programmi\Grisoft\AVG Free\avgse.dll = C:\Programmi\Grisoft\AVG Free\avgse.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/D:\Programmin\WinRar\rarext.dll = D:\Programmin\WinRar\rarext.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/D:\Programmin\iTunes\iTunesMiniPlayer.dll = D:\Programmin\iTunes\iTunesMiniPlayer.dll
@{792F0537-F929-4eb7-AC1D-FB6334C71550} /*LG Phone*/D:\PROGRA~1\LGPCSU~1\LGPHON~1\Phone.dll = D:\PROGRA~1\LGPCSU~1\LGPHON~1\Phone.dll
@{ABC70703-32AF-11d4-90C4-D483A70F4825} /*CMenuExtender*/D:\Programmin\iColorFolder\CMExt.dll = D:\Programmin\iColorFolder\CMExt.dll
@{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} /*PhoneBrowser*/D:\Programmin\Nokia\Nokia PC Suite 6\PhoneBrowser.dll = D:\Programmin\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/d:\PROGRA~1\ALCOHO~1\ALCOHO~1\axshlex.dll = d:\PROGRA~1\ALCOHO~1\ALCOHO~1\axshlex.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Programmi\Grisoft\AVG Free\avgse.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = D:\Programmin\WinRar\rarext.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
CMenuExtender@{ABC70703-32AF-11d4-90C4-D483A70F4825} = D:\Programmin\iColorFolder\CMExt.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = D:\Programmin\WinRar\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Programmi\Grisoft\AVG Free\avgse.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = D:\Programmin\WinRar\rarext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\system32\sstext3d.scr
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start
Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pageabout:blank = about:blank
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = C:\WINDOWS\system32\wiascr.dll
C:\Documents and Settings\Administrator\Menu Avvio\Programmi\Esecuzione automatica = Spybot - Search & Destroy.lnk
---- EOF - GMER 1.0.11 ----