ERCOLINO ha scritto:
Hai riprovato a usare il tool in modalità provvisoria?
Usa anche ad-aware e l'antivirus
Tasto f8 all'accensione.
Poi cancella sempre in modalità provvisoria tutto il contenuto di Temp.
grazie ancora per la tua cortesia e pazienza, Ercolino.....
ho fatto come mi hai suggerito tu il tutto in modalità provvisoria. Purtroppo però il programma si è di nuovo ri-installato appena collegato alla rete, cambiando anche nome da neem1.exe a neem0.exe, sempre in Windows/Temp..
ri-incollo qui il log di HijackThis, dopo l'ennesima rimozione del programma, la ripulitura del registry editor e di msconfig....
Logfile of HijackThis v1.99.1
Scan saved at 15.05.13, on 08/12/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\luca\utility\avast\aswUpdSv.exe
C:\luca\utility\avast\ashServ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\luca\utility\avast\ashDisp.exe
C:\Programmi\TOSHIBA\TME3\Tmesbs32.exe
C:\luca\utility\avast\ashWebSv.exe
C:\luca\utility\avast\ashMaiSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Winpooch\Winpooch.exe
C:\WINDOWS\regedit.exe
C:\luca\utility\hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [avast!] C:\luca\utility\avast\ashDisp.exe
O4 - HKLM\..\Run: [Winpooch] C:\Programmi\Winpooch\Winpooch.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\luca\utility\avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\luca\utility\avast\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\luca\utility\avast\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\luca\utility\avast\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SrvCxv - Unknown owner - C:\:hOF.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Programmi\TOSHIBA\TME3\Tmesbs32.exe
un'altra informazione che sono riuscito a recuperare è il controllo tramite WinPooch dei processi che neem.exe fa (anche se non sono riuscito a vedere chi e come ri-installa il programma)...
vi incollo qui parte del log di WinPooch (mi sembra di aver messo tutto, perchè ci sono molto ripetizioni degli stessi processi), forse ci sono informazioni utili, ma io non ci capisco moltissimo :-(
- neem1.exe (3108) : File::Read (C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Connections\Pbk\rasphone.pbk) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon, ParseAutoexec) -> rejected
- neem1.exe (3108) : File::Read (c:\autoexec.bat) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, AppData) -> rejected
- neem1.exe (3108) : File::Read (C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Connections\Pbk\rasphone.pbk) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\RASModule\Data, Value) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\RASModule\Data, Value) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Afqaf, Value) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Afqaf, Value) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\RASModule\Data, Index) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\RASModule\Data, Index) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Afqaf, Index) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Afqaf, Index) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\RASModule\Data, Data) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\RASModule\Data, Data) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Afqaf, Data) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Afqaf, Data) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\RASModule\Data, Groups) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\RASModule\Data, Groups) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Afqaf, Groups) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Afqaf, Groups) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\RASModule\Data, Times) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\RASModule\Data, Times) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Afqaf, Times) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Afqaf, Times) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\RASModule\Data, Diff) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\RASModule\Data, Diff) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Afqaf, Diff) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Afqaf, Diff) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\RASModule\Data, Limit) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\RASModule\Data, Limit) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Afqaf, Limit) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Afqaf, Limit) -> rejected
- neem1.exe (3108) : File::Read (C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Connections\Pbk\rasphone.pbk) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon, ParseAutoexec) -> rejected
- neem1.exe (3108) : File::Read (c:\autoexec.bat) -> rejected
- neem1.exe (3108) : Reg::SetValue (HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, AppData) -> rejected
- neem1.exe (3108) : File::Read (C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Connections\Pbk\rasphone.pbk) -> rejected
infine c'è anche questo strano processo (C:\:hOF.exe) che parte all'avvio del PC e poi viene chiuso....è qualcosa di sistema o può avere a che fare con il dialer??
giovedÏ 7 dicembre 2006 - 18.12.37 - Pc
- services.exe (644) : Sys::KillProcess (C:\:hOF.exe) -> accepted
grazie a tutti ancora una volta...magari non riesco a fare fuori del tutto il dialer, ma almeno sto imparando molto sull'uso e protezione del PC....