Pagina 1 di 1

Aiuto ho beccato un trojan... non sono esperto di log

MessaggioInviato: dom set 18, 2005 7:09 pm
da zad
Ciao ragazzi sono nuovo e chiedo aiuto per questo problema.

Si è installato nel mio sistema XP Professional 5.1 un Trojan.Phel che mi richiedere i dati della carta di credito quando vado a fare un pagamento con Paypal. Dati che ovviamente non fornisco. Sono però bloccato.

Questo è il log che ho tirato fuori con hijack. Secondo voi cosa devo eliminare?

Grazie per l'aiuto.

Logfile of HijackThis v1.99.0
Scan saved at 10.16.38, on 18/09/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\NVATray.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\DAP\DAP.EXE
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\Programmi\Java\jre1.5.0_02\bin\jusched.exe
C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
C:\Programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Norton AntiVirus\navapsvc.exe
C:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programmi\Java\jre1.5.0_02\bin\javaw.exe
C:\Programmi\Outlook Express\msimn.exe
C:\WINDOWS\Explorer.EXE
C:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.repubblica.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O1 - Hosts: 220.65.108.3 ecom.dfckc.com
O1 - Hosts: 220.65.108.4 www.site-secure.com
O1 - Hosts: 220.65.108.5 www.cue-commerce.net
O1 - Hosts: 220.65.108.6 secure.amcore.com
O1 - Hosts: 220.65.108.7 ultrabranch.alaskausa.org
O1 - Hosts: 220.65.108.8 alaskausamortgage.account-services.com
O1 - Hosts: 220.65.108.9 www.ezcardinfo.com
O1 - Hosts: 220.65.108.10 trustreporter.alaskausatrust.com
O1 - Hosts: 220.65.108.11 etimebanker.bankofthewest.com
O1 - Hosts: 220.65.108.12 www.capcitybank.com
O1 - Hosts: 220.65.108.13 www.thecsbonline.com
O1 - Hosts: 220.65.108.14 www2.site-secure.com
O1 - Hosts: 220.65.108.15 www.netteller.com
O1 - Hosts: 220.65.108.16 www.gotomycard.com
O1 - Hosts: 220.65.108.17 onlinebanking.lasallebank.com
O1 - Hosts: 220.65.108.18 connect.skyfi.com
O1 - Hosts: 220.65.108.19 southtrustonlinebanking.com
O1 - Hosts: 220.65.108.20 www4.usbank.com
O1 - Hosts: 220.65.108.21 pcbanking.umb.com
O1 - Hosts: 220.65.108.22 online.wellsfargo.com
O1 - Hosts: 220.65.108.23 upib.unionplanters.com
O1 - Hosts: 220.65.108.24 www.paypal.com
O1 - Hosts: 220.65.108.24 paypal.com
O1 - Hosts: 220.65.108.25 signin.ebay.com
O1 - Hosts: 220.65.108.26 accountlink.placersierrabank.com
O1 - Hosts: 220.65.108.26 americaneagle.vaultsentry.com
O1 - Hosts: 220.65.108.26 banking.firsttennessee.com
O1 - Hosts: 220.65.108.26 banking.vectrabank.com
O1 - Hosts: 220.65.108.26 benefits.mbandt.com
O1 - Hosts: 220.65.108.26 businessconnex.fnbsf.com
O1 - Hosts: 220.65.108.26 cib.ibanking-services.com
O1 - Hosts: 220.65.108.26 cuolraycu.com
O1 - Hosts: 220.65.108.26 cuonline.sfcuonline.org
O1 - Hosts: 220.65.108.26 dpcuhb.org
O1 - Hosts: 220.65.108.26 ebank.factorypoint.com
O1 - Hosts: 220.65.108.26 ebanking.firstbankmi.com
O1 - Hosts: 220.65.108.26 edcomcu.vaultsentry.com
O1 - Hosts: 220.65.108.26 eds.usersonlnet.com
O1 - Hosts: 220.65.108.26 enterprise.openbank.com
O1 - Hosts: 220.65.108.26 enterprise2.openbank.com
O1 - Hosts: 220.65.108.26 estatus.loanware.com
O1 - Hosts: 220.65.108.26 eteller.greatnwfcu.com
O1 - Hosts: 220.65.108.26 fcs1.fkfcu.org
O1 - Hosts: 220.65.108.26 fhbonline.fhb.com
O1 - Hosts: 220.65.108.26 gil.usersonlnet.com
O1 - Hosts: 220.65.108.26 global1.onlinebank.com
O1 - Hosts: 220.65.108.26 gnl.usersonlnet.com
O1 - Hosts: 220.65.108.26 hb.mctfcu.org
O1 - Hosts: 220.65.108.26 hb.numericacu.com
O1 - Hosts: 220.65.108.26 hew.usersonlnet.com
O1 - Hosts: 220.65.108.26 homebank.kcpecu.org
O1 - Hosts: 220.65.108.26 homebank.oucu.org
O1 - Hosts: 220.65.108.26 homebank.pacificcascade.org
O1 - Hosts: 220.65.108.26 homebanking.dotfcu.org
O1 - Hosts: 220.65.108.26 homebanking.guardiancu.org
O1 - Hosts: 220.65.108.26 homebanking.jdccu.org
O1 - Hosts: 220.65.108.26 homebanking.national1st.org
O1 - Hosts: 220.65.108.26 homebanking.nordcu.org
O1 - Hosts: 220.65.108.26 homebanking.soopercu.org
O1 - Hosts: 220.65.108.26 ibank.pcs-sd.net
O1 - Hosts: 220.65.108.26 ibank.the1st.com
O1 - Hosts: 220.65.108.26 ibs.secure-banking.com
O1 - Hosts: 220.65.108.26 internetbanking.hvfcu.org
O1 - Hosts: 220.65.108.26 k2.secure-banking.com
O1 - Hosts: 220.65.108.26 login.prudential.com
O1 - Hosts: 220.65.108.26 mec.usersonlnet.com
O1 - Hosts: 220.65.108.26 mefcudirect.marriott.com
O1 - Hosts: 220.65.108.26 meriwestonline.meriwest.com
O1 - Hosts: 220.65.108.26 mmm1928.dulles19-verio.com
O1 - Hosts: 220.65.108.26 myonlineservices.centralbank.net
O1 - Hosts: 220.65.108.26 myvista.vistafcu.org
O1 - Hosts: 220.65.108.26 netbank.ffsb.com
O1 - Hosts: 220.65.108.26 nvbconnect.com
O1 - Hosts: 220.65.108.26 online.concordiabank.com
O1 - Hosts: 220.65.108.26 onlinebanking.bankofoklahoma.com
O1 - Hosts: 220.65.108.26 onlinebanking.entfederal.com
O1 - Hosts: 220.65.108.26 onlinebanking.huntington.com
O1 - Hosts: 220.65.108.26 pcb.peoples.com
O1 - Hosts: 220.65.108.26 pcbanc.cccpnc.com
O1 - Hosts: 220.65.108.26 pcu.kirtlandfcu.org
O1 - Hosts: 220.65.108.26 pcu.ttcu.org
O1 - Hosts: 220.65.108.26 pcuonline.philipscu.org
O1 - Hosts: 220.65.108.26 reorder.libertysite.com
O1 - Hosts: 220.65.108.26 rolb.associatedbank.com
O1 - Hosts: 220.65.108.26 s105.lanxtra.com
O1 - Hosts: 220.65.108.26 s124.lanxtra.com
O1 - Hosts: 220.65.108.26 s166.lanxtra.com
O1 - Hosts: 220.65.108.26 s56.lanxtra.com
O1 - Hosts: 220.65.108.26 secure.chemicalbankmi.com
O1 - Hosts: 220.65.108.26 secure.firstbankrichmond.com
O1 - Hosts: 220.65.108.26 secure.fnblgmt.com
O1 - Hosts: 220.65.108.26 secure.fundsxpress.com
O1 - Hosts: 220.65.108.26 secure.midamericabank.com
O1 - Hosts: 220.65.108.26 secure.tctrustco.com
O1 - Hosts: 220.65.108.26 secure.vystarcu.org
O1 - Hosts: 220.65.108.26 secure1.cyberbranch.com
O1 - Hosts: 220.65.108.26 secure7.regency.openbank.com
O1 - Hosts: 220.65.108.26 secure-tambank.com
O1 - Hosts: 220.65.108.26 server112.cey-ebanking.com
O1 - Hosts: 220.65.108.26 server20.cey-ebanking.com
O1 - Hosts: 220.65.108.26 statements-online.com
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Programmi\DAP\DAPBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Programmi\DAP\DAPIEBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NVIDIA nForce APU1 Utilities] NVATray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programmi\File comuni\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Programmi\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [iIWiper] C:\Programmi\iISystem Wiper\SystemWiper.exe m
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Avvio rapido Microsoft Office.lnk = C:\MSOffice\Office\FASTBOOT.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://c:\programmi\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\programmi\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmi\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmi\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Similar Pages - res://c:\programmi\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmi\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O12 - Plugin for .bcf: C:\Programmi\Internet Explorer\Plugins\NPBelv32.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{25EFA2F6-0EFB-4ADD-8C2C-2E60E78F4272}: NameServer = 85.37.17.55 151.99.125.1
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Programmi\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: Servizio Auto-Protect di Norton AntiVirus - Symantec Corporation - C:\Programmi\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - C:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmi\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe

Re: Aiuto ho beccato un trojan... non sono esperto di log

MessaggioInviato: dom set 18, 2005 7:40 pm
da Monkey13
zad ha scritto:O1 - Hosts: 220.65.108.3 ecom.dfckc.com
O1 - Hosts: 220.65.108.4 www.site-secure.com
O1 - Hosts: 220.65.108.5 www.cue-commerce.net
O1 - Hosts: 220.65.108.6 secure.amcore.com
O1 - Hosts: 220.65.108.7 ultrabranch.alaskausa.org
O1 - Hosts: 220.65.108.8 alaskausamortgage.account-services.com
O1 - Hosts: 220.65.108.9 www.ezcardinfo.com
O1 - Hosts: 220.65.108.10 trustreporter.alaskausatrust.com
O1 - Hosts: 220.65.108.11 etimebanker.bankofthewest.com
O1 - Hosts: 220.65.108.12 www.capcitybank.com
O1 - Hosts: 220.65.108.13 www.thecsbonline.com
O1 - Hosts: 220.65.108.14 www2.site-secure.com
O1 - Hosts: 220.65.108.15 www.netteller.com
O1 - Hosts: 220.65.108.16 www.gotomycard.com
O1 - Hosts: 220.65.108.17 onlinebanking.lasallebank.com
O1 - Hosts: 220.65.108.18 connect.skyfi.com
O1 - Hosts: 220.65.108.19 southtrustonlinebanking.com
O1 - Hosts: 220.65.108.20 www4.usbank.com
O1 - Hosts: 220.65.108.21 pcbanking.umb.com
O1 - Hosts: 220.65.108.22 online.wellsfargo.com
O1 - Hosts: 220.65.108.23 upib.unionplanters.com
O1 - Hosts: 220.65.108.24 www.paypal.com
O1 - Hosts: 220.65.108.24 paypal.com
O1 - Hosts: 220.65.108.25 signin.ebay.com
O1 - Hosts: 220.65.108.26 accountlink.placersierrabank.com
O1 - Hosts: 220.65.108.26 americaneagle.vaultsentry.com
O1 - Hosts: 220.65.108.26 banking.firsttennessee.com
O1 - Hosts: 220.65.108.26 banking.vectrabank.com
O1 - Hosts: 220.65.108.26 benefits.mbandt.com
O1 - Hosts: 220.65.108.26 businessconnex.fnbsf.com
O1 - Hosts: 220.65.108.26 cib.ibanking-services.com
O1 - Hosts: 220.65.108.26 cuolraycu.com
O1 - Hosts: 220.65.108.26 cuonline.sfcuonline.org
O1 - Hosts: 220.65.108.26 dpcuhb.org
O1 - Hosts: 220.65.108.26 ebank.factorypoint.com
O1 - Hosts: 220.65.108.26 ebanking.firstbankmi.com
O1 - Hosts: 220.65.108.26 edcomcu.vaultsentry.com
O1 - Hosts: 220.65.108.26 eds.usersonlnet.com
O1 - Hosts: 220.65.108.26 enterprise.openbank.com
O1 - Hosts: 220.65.108.26 enterprise2.openbank.com
O1 - Hosts: 220.65.108.26 estatus.loanware.com
O1 - Hosts: 220.65.108.26 eteller.greatnwfcu.com
O1 - Hosts: 220.65.108.26 fcs1.fkfcu.org
O1 - Hosts: 220.65.108.26 fhbonline.fhb.com
O1 - Hosts: 220.65.108.26 gil.usersonlnet.com
O1 - Hosts: 220.65.108.26 global1.onlinebank.com
O1 - Hosts: 220.65.108.26 gnl.usersonlnet.com
O1 - Hosts: 220.65.108.26 hb.mctfcu.org
O1 - Hosts: 220.65.108.26 hb.numericacu.com
O1 - Hosts: 220.65.108.26 hew.usersonlnet.com
O1 - Hosts: 220.65.108.26 homebank.kcpecu.org
O1 - Hosts: 220.65.108.26 homebank.oucu.org
O1 - Hosts: 220.65.108.26 homebank.pacificcascade.org
O1 - Hosts: 220.65.108.26 homebanking.dotfcu.org
O1 - Hosts: 220.65.108.26 homebanking.guardiancu.org
O1 - Hosts: 220.65.108.26 homebanking.jdccu.org
O1 - Hosts: 220.65.108.26 homebanking.national1st.org
O1 - Hosts: 220.65.108.26 homebanking.nordcu.org
O1 - Hosts: 220.65.108.26 homebanking.soopercu.org
O1 - Hosts: 220.65.108.26 ibank.pcs-sd.net
O1 - Hosts: 220.65.108.26 ibank.the1st.com
O1 - Hosts: 220.65.108.26 ibs.secure-banking.com
O1 - Hosts: 220.65.108.26 internetbanking.hvfcu.org
O1 - Hosts: 220.65.108.26 k2.secure-banking.com
O1 - Hosts: 220.65.108.26 login.prudential.com
O1 - Hosts: 220.65.108.26 mec.usersonlnet.com
O1 - Hosts: 220.65.108.26 mefcudirect.marriott.com
O1 - Hosts: 220.65.108.26 meriwestonline.meriwest.com
O1 - Hosts: 220.65.108.26 mmm1928.dulles19-verio.com
O1 - Hosts: 220.65.108.26 myonlineservices.centralbank.net
O1 - Hosts: 220.65.108.26 myvista.vistafcu.org
O1 - Hosts: 220.65.108.26 netbank.ffsb.com
O1 - Hosts: 220.65.108.26 nvbconnect.com
O1 - Hosts: 220.65.108.26 online.concordiabank.com
O1 - Hosts: 220.65.108.26 onlinebanking.bankofoklahoma.com
O1 - Hosts: 220.65.108.26 onlinebanking.entfederal.com
O1 - Hosts: 220.65.108.26 onlinebanking.huntington.com
O1 - Hosts: 220.65.108.26 pcb.peoples.com
O1 - Hosts: 220.65.108.26 pcbanc.cccpnc.com
O1 - Hosts: 220.65.108.26 pcu.kirtlandfcu.org
O1 - Hosts: 220.65.108.26 pcu.ttcu.org
O1 - Hosts: 220.65.108.26 pcuonline.philipscu.org
O1 - Hosts: 220.65.108.26 reorder.libertysite.com
O1 - Hosts: 220.65.108.26 rolb.associatedbank.com
O1 - Hosts: 220.65.108.26 s105.lanxtra.com
O1 - Hosts: 220.65.108.26 s124.lanxtra.com
O1 - Hosts: 220.65.108.26 s166.lanxtra.com
O1 - Hosts: 220.65.108.26 s56.lanxtra.com
O1 - Hosts: 220.65.108.26 secure.chemicalbankmi.com
O1 - Hosts: 220.65.108.26 secure.firstbankrichmond.com
O1 - Hosts: 220.65.108.26 secure.fnblgmt.com
O1 - Hosts: 220.65.108.26 secure.fundsxpress.com
O1 - Hosts: 220.65.108.26 secure.midamericabank.com
O1 - Hosts: 220.65.108.26 secure.tctrustco.com
O1 - Hosts: 220.65.108.26 secure.vystarcu.org
O1 - Hosts: 220.65.108.26 secure1.cyberbranch.com
O1 - Hosts: 220.65.108.26 secure7.regency.openbank.com
O1 - Hosts: 220.65.108.26 secure-tambank.com
O1 - Hosts: 220.65.108.26 server112.cey-ebanking.com
O1 - Hosts: 220.65.108.26 server20.cey-ebanking.com
O1 - Hosts: 220.65.108.26 statements-online.com


tutti questi hosts li devi eliminare... ti consiglio fra l'altro una scansione con ad-aware e nod32... per essere sicuri rimuovi prima tutti i file temporanei, recenti, cookie ecc. Magari anche una scansione con spysweeper... dovresti, come dire, Devastarlo!!! [bangbang] [weponed] [bangbang]

MessaggioInviato: lun set 19, 2005 7:24 am
da crazy.cat
Oltre a quello che ti ha detto di fare Monkey13, qui trovi le istruzioni riguardo a quel virus
http://securityresponse.symantec.com/av ... hel.a.html
controlla la presenza nel tuo pc di questi file ed eventualmente eliminali.
My.hta,uwyrl.exe,uwyrl.dll

Prova questo
http://www.MegaLab.it/2333
per la scansione dei virus

MessaggioInviato: mer set 21, 2005 12:22 am
da zad
Grazie ragazzi. Problema risolto!

Zad