Ciao a tutti
sul mio computer ho 3 sistemi operativi, windows xp service pack 2, windows vista e linux fedora.
Ho Fatto una scansione su windows xp con spybot search e destroy e ho rilevato
virtumode.dll e virtumode.
Ho eliminato con lo stesso programma le infezioni e riavviato il pc.
Mi sono prima scollegato da internet e disattivato il ripristino configurazione di sistema.
Al riavvio del windows xp spybot mi cancella i file e tutto quello che riguarda virtumode.
Dopo un po il problema si ripresenta, rifaccio tutto da capo e cancello di nuovo tutto.
Alla fine esco da xp, vado su vista e faccio una scansione della partizione del windows xp con avast.
Trova il virus Cavallo di Troia Win32:VB-EIJ[trj] nel file pagefile.sys.
Cancello il file.
L'operazione riesce.
Ritorno in winodws xp e dopo un pò che lo uso ritorna dinuovo.
Eseguo Hijackthis e il log e il seguente:
Logfile of HijackThis v1.99.1
Scan saved at 20.21.04, on 25/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
E:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
E:\Programmi\Alwil Software\Avast4\ashServ.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\ATKKBService.exe
E:\WINDOWS\system32\CTsvcCDA.exe
E:\Programmi\File comuni\LightScribe\LSSrvc.exe
E:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\Programmi\CyberLink\Shared files\RichVideo.exe
E:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
E:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
E:\Programmi\Alwil Software\Avast4\ashWebSv.exe
E:\WINDOWS\system32\wscntfy.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\ASUS\AI Remote\AiRc.exe
E:\Programmi\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
E:\Programmi\Creative\Shared Files\Module Loader\DLLML.exe
E:\WINDOWS\CTHELPER.EXE
E:\WINDOWS\system32\CTXFIHLP.EXE
E:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
E:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
E:\WINDOWS\SYSTEM32\CTXFISPI.EXE
E:\Programmi\Unlocker\UnlockerAssistant.exe
E:\Program Files\ASUS\AI Remote\AiRemote.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Programmi\Creative\MediaSource5\Go\CTCMSGoU.exe
E:\Programmi\Skype\Phone\Skype.exe
E:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe
E:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
E:\Programmi\ASUS\SmartDoctor\SmartDoctor.exe
E:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
E:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
E:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
E:\Programmi\Media Key\MagicKey.exe
E:\Programmi\ASUS\ScreenDUO\AsG_Manager.exe
E:\Programmi\Media Key\OSD.EXE
E:\Programmi\Skype\Plugin Manager\skypePM.exe
E:\Programmi\ASUS\ScreenDUO\Gadgets\LaunchApplication\AsG_LaunchApplication.exe
E:\Programmi\Asus\ScreenDUO\Gadgets\Time\AsG_Time.exe
E:\Programmi\ASUS\ScreenDUO\Gadgets\VolumeControl\AsG_VolumeControl.exe
E:\Programmi\ASUS\ScreenDUO\Gadgets\HardwareMonitoring\AsG_HardwareMonitor.exe
E:\Programmi\ASUS\AASP\1.00.25\aaCenter.exe
E:\WINDOWS\system32\wuauclt.exe
F:\Programmi\Aggiornamenti_Continui\Diagnosi_Virtumonde\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {D85530E8-D39D-49D0-9F36-300D594556D2} - E:\WINDOWS\system32\khfebxx.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Ai Remote Help] "E:\Program Files\ASUS\AI Remote\AiRc.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] E:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] E:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [VolPanel] "E:\Programmi\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "E:\Programmi\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "E:\Programmi\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] E:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Ai Nap] "E:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] E:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LanguageShortcut] E:\Programmi\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "E:\Programmi\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] "E:\Programmi\Creative\MediaSource5\Go\CTCMSGoU.exe" /SCB
O4 - HKCU\..\Run: [Skype] "E:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "E:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "E:\Programmi\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ASUS SmartDoctor] E:\Programmi\ASUS\SmartDoctor\SmartDoctor.exe /start
O4 - HKCU\..\Run: [Yahoo! Pager] "E:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Media Key.lnk = E:\Programmi\Media Key\MagicKey.exe
O4 - Global Startup: ScreenDUO.lnk = ?
O8 - Extra context menu item: Scarica con il Wizard di LeechGet - file://E:\Programmi\LeechGet 2006\\Wizard.html
O8 - Extra context menu item: Scarica con LeechGet - file://E:\Programmi\LeechGet 2006\\AddUrl.html
O8 - Extra context menu item: Scarica pagina con LeechGet - file://E:\Programmi\LeechGet 2006\\Parser.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programmi\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - E:\Programmi\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: khfebxx - E:\WINDOWS\SYSTEM32\khfebxx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - E:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - E:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - E:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - E:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - E:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - E:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - E:\Programmi\CyberLink\Shared files\RichVideo.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - E:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
Il problema secondo me sono le seguenti due linee:
O2 - BHO: (no name) - {D85530E8-D39D-49D0-9F36-300D594556D2} - E:\WINDOWS\system32\khfebxx.dll
O20 - Winlogon Notify: khfebxx - E:\WINDOWS\SYSTEM32\khfebxx.dll
ho provato a selezionarle e a cancellarle, il programma mi dice che le ha cancellate ma in realtà sono sempre lì.
Ho provato a cancellare manualmente dal registro tutte le chiavi che riguardavo il file khfebxx.dll ma subito dopo
riapparivano.
Prima di usare Hijackthis ho fatto una scansione con spybot e virtumode non c'era più almeno fino a quel momento.
Ho provato a cancellare il BHO con spybot ma ha lo stesso effetto che con hijack in un primo momento scompare e
dopo un po riappare come per magia.
Qualcuno sà come risolvere il problema?
Ciao a tutti !!!