Analysis

Toshiba Satellite P100


Intel Core 2 T7200 @ 2.00 Ghz


RAM 1 GB


System: Microsoft windows XP Media Center Edition Versione 2002 Service Pack 2


Problem: Eksplorasi.exe


Hjackyhis log:


Logfile of Trend Micro HijackThis v2.0.2


Scan saved at 20.44.54, on 23/05/2008


Platform: Windows XP SP2 (WinNT 5.01.2600)


MSIE: Internet Explorer v7.00 (7.00.6000.16640)


Boot mode: Normal


Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\System32\svchost.exe


C:\Programmi\Intel\Wireless\Bin\EvtEng.exe


C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe


C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe


C:\WINDOWS\system32\spoolsv.exe


C:\WINDOWS\Explorer.exe


C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe


C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe


C:\Programmi\Cisco Systems\VPN Client\cvpnd.exe


C:\WINDOWS\system32\DVDRAMSV.exe


C:\WINDOWS\eHome\ehRecvr.exe


C:\WINDOWS\eHome\ehSched.exe


C:\PROGRA~1\AVG\AVG8\avgrsx.exe


C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe


C:\Programmi\Microsoft LifeCam\MSCamS32.exe


C:\WINDOWS\system32\nvsvc32.exe


C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe


C:\WINDOWS\system32\svchost.exe


C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe


C:\Programmi\File comuni\Softwin\BitDefender Communicator\xcommsvr.exe


C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe


C:\Programmi\File comuni\Softwin\BitDefender Update Service\livesrv.exe


C:\WINDOWS\ehome\ehtray.exe


C:\Programmi\Synaptics\SynTP\SynTPEnh.exe


C:\Programmi\Toshiba\Windows Utilities\Hotkey.exe


C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe


C:\WINDOWS\System32\DLA\DLACTRLW.EXE


C:\Programmi\Synaptics\SynTP\Toshiba.exe


C:\Programmi\Intel\Wireless\bin\ZCfgSvc.exe


C:\Programmi\Intel\Wireless\Bin\ifrmewrk.exe


C:\Programmi\File comuni\Real\Update_OB\realsched.exe


C:\Programmi\Softwin\BitDefender10\bdagent.exe


C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe


C:\WINDOWS\vVX6000.exe


C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe


C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe


C:\Programmi\iTunes\iTunesHelper.exe


C:\WINDOWS\system32\ctfmon.exe


C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe


C:\Programmi\Softwin\BitDefender10\vsserv.exe


C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe


C:\Programmi\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe


C:\Programmi\Logitech\SetPoint\SetPoint.exe


C:\WINDOWS\system32\dllhost.exe


C:\WINDOWS\system32\RAMASST.exe


C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe


C:\Programmi\iPod\bin\iPodService.exe


C:\WINDOWS\eHome\ehmsas.exe


C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe


C:\Programmi\File comuni\Logishrd\KHAL2\KHALMNPR.EXE


C:\WINDOWS\system32\igfxsrvc.exe


C:\Programmi\Windows Live\Messenger\msnmsgr.exe


C:\Programmi\Windows Live\Messenger\usnsvc.exe


C:\Programmi\Internet Explorer\IEXPLORE.EXE


C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe


C:\Programmi\Trend Micro\HijackThis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.it/


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.hadiko.de/


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.hadiko.de:3128


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti


R3 - URLSearchHook: Coolstreaming Tool-Bar v1.0 Toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCool.dll


F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"


O1 - Hosts: <!doctype html public "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">


O1 - Hosts: <html><head><title>Yahoo! - 503 Service Temporarily Unavailable</title><style>


O1 - Hosts: /* nn4 hide */


O1 - Hosts: /*/*/


O1 - Hosts: body {font:small/1.2em arial,helvetica,clean,sans-serif;font:x-small;text-align:center;}table {font-size:inherit;font:x-small;}


O1 - Hosts: html>body {font:83%/1.2em arial,helvetica,clean,sans-serif;}input {font-size:100%;vertical-align:middle;}p, form {margin:0;padding:0;}


O1 - Hosts: p {padding-bottom:6px;margin-bottom:10px;}#doc {width:48.5em;margin:0 auto;border:1px solid #fff;text-align:center;}#ygma {text-align:right;margin-bottom:53px}


O1 - Hosts: h1 {font-size:135%;text-align:center;margin:0 0 15px;}legend {display:none;}fieldset {border:0 solid #fff;padding:.8em 0 .8em 4.5em;}


O1 - Hosts: form {position:relative;background:#eee;margin-bottom:15px;border:1px solid #ccc;border-width:1px 0;}


O1 - Hosts: form span {position:absolute;left:70%;top:.8em;}form a {font:78%/1.2em arial;display:block;padding-left:.8em;white-space:nowrap;background: url(http://us.i1.yimg.com/us.yimg.com/i/s/bullet.gif) no-repeat left center;}


O1 - Hosts: form .sep {display:none;}.more {text-align:center;}#ft {padding-top:10px;border-top:1px solid #999;}#ft p {text-align:center;font:78% arial;}


O1 - Hosts: /* end nn4 hide */


O1 - Hosts: </style></head>


O1 - Hosts: <body><div id="doc">


O1 - Hosts: <div id="ygma"><a href="http://us.rd.yahoo.com/503/*http://www.yahoo.com"><img


O1 - Hosts: src=http://us.i1.yimg.com/us.yimg.com/i/yahoo.gif


O1 - Hosts: width=147 height=31 border=0 alt="Yahoo!"></a><div><a


O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://www.yahoo.com">Yahoo!</a>'>http://us.rd.yahoo.com/503/*http://www.yahoo.com">Yahoo!</a>


O1 - Hosts: - <a href="http://us.rd.yahoo.com/503/*http://help.yahoo.com">Help</a></div></div>


O1 - Hosts: <div id="bd"><h1>Sorry, Service Temporarily Unavailable.</h1>


O1 - Hosts: The server is temporarily unable to service your


O1 - Hosts: request due to maintenance downtime or capacity


O1 - Hosts: problems. Please try again later.


O1 - Hosts: <P>Additionally, a 503 Service Temporarily Unavailable


O1 - Hosts: error was encountered while trying to use an ErrorDocument to handle the request.


O1 - Hosts: <p>Please check the URL for proper spelling and capitalization. If


O1 - Hosts: you're having trouble locating a destination on Yahoo!, try visiting the


O1 - Hosts: <strong><a


O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://www.yahoo.com">Yahoo! home


O1 - Hosts: page</a></strong> or look through a list of <strong><a


O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://docs.yahoo.com/docs/family/more/">Yahoo!'s


O1 - Hosts: online services</a></strong>. Also, you may find what you're looking for


O1 - Hosts: if you try searching below.</p>


O1 - Hosts: <form name="s1" action="http://us.rd.yahoo.com/503/*-http://search.yahoo.com/search"><fieldset>


O1 - Hosts: <legend><label for="s1p">Search the Web</label></legend>


O1 - Hosts: <input type="text" size=30 name="p" id="s1p" title="enter search terms here">


O1 - Hosts: <input type="submit" value="Search">


O1 - Hosts: <span><a href="http://us.rd.yahoo.com/503/*http://search.yahoo.com/search/options?p=">advanced search</a> <span class=sep>|</span> <a href="http://us.rd.yahoo.com/503/*http://buzz.yahoo.com">most popular</a></span>


O1 - Hosts: </fieldset></form>


O1 - Hosts: <p class="more">Please try <strong><a


O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://help.yahoo.com">Yahoo!


O1 - Hosts: Help Central</a></strong> if you need more assistance.</p>


O1 - Hosts: </div><div id="ft"><p>Copyright © 2008 Yahoo! Inc.


O1 - Hosts: All rights reserved. <a


O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://privacy.yahoo.com">Privacy


O1 - Hosts: Policy</a> - <a


O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://docs.yahoo.com/info/terms/">Terms


O1 - Hosts: of Service</a></p></div>


O1 - Hosts: </div></body></html>


O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll


O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL


O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL


O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll


O2 - BHO: Coolstreaming Tool-Bar v1.0 Toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCool.dll


O3 - Toolbar: Coolstreaming Tool-Bar v1.0 Toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCool.dll


O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe


O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe


O4 - HKLM\..\Run: [synTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe


O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Programmi\Toshiba\Windows Utilities\Hotkey.exe" /lang IT


O4 - HKLM\..\Run: [smoothView] C:\Programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe


O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE


O4 - HKLM\..\Run: [intelZeroConfig] "C:\Programmi\Intel\Wireless\bin\ZCfgSvc.exe"


O4 - HKLM\..\Run: [intelWireless] "C:\Programmi\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless


O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot


O4 - HKLM\..\Run: [bDAgent] "C:\Programmi\Softwin\BitDefender10\bdagent.exe"


O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALICET~1\SMARTB~1\MotiveSB.exe


O4 - HKLM\..\Run: [LifeCam] "C:\Programmi\Microsoft LifeCam\LifeExp.exe"


O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe


O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"


O4 - HKLM\..\Run: [bDMCon] "C:\Programmi\Softwin\BitDefender10\bdmcon.exe" /reg


O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime


O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"


O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet


O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE


O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"


O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit


O4 - HKLM\..\Run: [Automatico EPSON Stylus CX6600 Series su WST-001] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P48 "Automatico EPSON Stylus CX6600 Series su WST-001" /O19 "\\WST-001\Stampante" /M "Stylus CX6600"


O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE


O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe


O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe


O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe


O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\Federico Illengo\Impostazioni locali\Dati applicazioni\smss.exe"


O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')


O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')


O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')


O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe


O4 - Global Startup: Bluetooth Manager.lnk = ?


O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmi\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe


O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmi\Logitech\SetPoint\SetPoint.exe


O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE


O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe


O4 - Global Startup: VPN Client.lnk = C:\Programmi\Cisco Systems\VPN Client\vpngui.exe


O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000


O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_04\bin\npjpi150_04.dll


O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_04\bin\npjpi150_04.dll


O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll


O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll


O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll


O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll


O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL


O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe


O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe


O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone...EngineQuery.dll


O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.pixdiscount.it/clients/uploader_v2.2.0.6.cab


O17 - HKLM\System\CCS\Services\Tcpip\..\{98D2F3AE-7852-4158-91F9-9BFD14E3EDAE}: NameServer = 172.20.32.1,172.20.63.254


O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = hadiko.de


O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = hadiko.de


O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmi\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll


O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL


O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll


O20 - AppInit_DLLs: avgrsstx.dll


O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe


O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe


O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe


O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe


O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe


O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe


O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmi\Cisco Systems\VPN Client\cvpnd.exe


O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe


O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe


O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe


O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe


O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmi\File comuni\Logishrd\Bluetooth\LBTServ.exe


O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Programmi\File comuni\Softwin\BitDefender Update Service\livesrv.exe


O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe


O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe


O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Programmi\Softwin\BitDefender10\vsserv.exe


O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe


O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Programmi\File comuni\Softwin\BitDefender Communicator\xcommsvr.exe


--


End of file - 17977 bytes

Comments

  • Can someone say to me what I must delete?

  • rootkit
    rootkit ✭✭✭
    edited May 2008

    Pack this files into a archive with the password infected an attach it here or upload it on a server an leave here the link !


    C:\WINDOWS\eksplorasi.exe


    C:\Documents and Settings\Federico Illengo\Impostazioni locali\Dati applicazioni\smss.exe


    After this reboot in safe mode and delete them manually !


    Then, back in normal, check and press Fix checked for:



    F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"


    O1 - Hosts:


    O1 - Hosts: Yahoo! - 503 Service Temporarily Unavailable


    O1 - Hosts: /* nn4 hide */


    O1 - Hosts: /*/*/


    O1 - Hosts: body {font:small/1.2em arial,helvetica,clean,sans-serif;font:x-small;text-align:center;}table {font-size:inherit;font:x-small;}


    O1 - Hosts: html>body {font:83%/1.2em arial,helvetica,clean,sans-serif;}input {font-size:100%;vertical-align:middle;}p, form {margin:0;padding:0;}


    O1 - Hosts: p {padding-bottom:6px;margin-bottom:10px;}#doc {width:48.5em;margin:0 auto;border:1px solid #fff;text-align:center;}#ygma {text-align:right;margin-bottom:53px}


    O1 - Hosts: h1 {font-size:135%;text-align:center;margin:0 0 15px;}legend {display:none;}fieldset {border:0 solid #fff;padding:.8em 0 .8em 4.5em;}


    O1 - Hosts: form {position:relative;background:#eee;margin-bottom:15px;border:1px solid #ccc;border-width:1px 0;}


    O1 - Hosts: form span {position:absolute;left:70%;top:.8em;}form a {font:78%/1.2em arial;display:block;padding-left:.8em;white-space:nowrap;background: url(http://us.i1.yimg.com/us.yimg.com/i/s/bullet.gif) no-repeat left center;}


    O1 - Hosts: form .sep {display:none;}.more {text-align:center;}#ft {padding-top:10px;border-top:1px solid #999;}#ft p {text-align:center;font:78% arial;}


    O1 - Hosts: /* end nn4 hide */


    O1 - Hosts:


    O1 - Hosts:


    O1 - Hosts:


    O1 - Hosts: src=http://us.i1.yimg.com/us.yimg.com/i/yahoo.gif


    O1 - Hosts: width=147 height=31 border=0 alt="Yahoo!">


    O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://www.yahoo.com">Yahoo!


    O1 - Hosts: - Help


    O1 - Hosts: Sorry, Service Temporarily Unavailable.


    O1 - Hosts: The server is temporarily unable to service your


    O1 - Hosts: request due to maintenance downtime or capacity


    O1 - Hosts: problems. Please try again later.


    O1 - Hosts: Additionally, a 503 Service Temporarily Unavailable


    O1 - Hosts: error was encountered while trying to use an ErrorDocument to handle the request.


    O1 - Hosts: Please check the URL for proper spelling and capitalization. If


    O1 - Hosts: you're having trouble locating a destination on Yahoo!, try visiting the


    O1 - Hosts:


    O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://www.yahoo.com">Yahoo! home


    O1 - Hosts: page or look through a list of


    O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://docs.yahoo.com/docs/family/more/">Yahoo !'s


    O1 - Hosts: online services. Also, you may find what you're looking for


    O1 - Hosts: if you try searching below.


    O1 - Hosts:


    O1 - Hosts: Search the Web


    O1 - Hosts:


    O1 - Hosts:


    O1 - Hosts: advanced search | most popular


    O1 - Hosts:


    O1 - Hosts: Please try


    O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://help.yahoo.com">Yahoo!


    O1 - Hosts: Help Central if you need more assistance.


    O1 - Hosts: Copyright © 2008 Yahoo! Inc.


    O1 - Hosts: All rights reserved.


    O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://privacy.yahoo.com">Privacy


    O1 - Hosts: Policy -


    O1 - Hosts: href="http://us.rd.yahoo.com/503/*http://docs.yahoo.com/info/terms/">Terms


    O1 - Hosts: of Service


    O1 - Hosts:


    O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\Federico Illengo\Impostazioni locali\Dati applicazioni\smss.exe"


    After this, post another HijackThis log !

  • rootkit
    rootkit ✭✭✭

    Thank you for the sample !


    The Virus Researchers from BitDefender Labs will take a look ;)

  • I've tried this ......but the file is still on my computer...he comes back every time I reboot...

  • rootkit
    rootkit ✭✭✭

    What version of Bitdefender do you have ?!

  • j4p
    j4p
    edited June 2008

    Bitdefender v10


    Sorry..


    BitDefender Plus v10


    Is there an updated version? Can I download it with my license?


    Can you help me??


    crysty2k5's EDIT: posts merged

  • rootkit
    rootkit ✭✭✭

    Download Bitdefender 11 (Bitdefender Antivirus 2008) and use your license ;)

  • Correction: since the AV Plus series has been dropped from development, users of the AV Plus versions can upgrade to BitDefender Internet Security 2008 (the licenses for AV Plus work for IS versions in the 2008 series, not for BitDefender Antivirus).


    Cris.