Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Problema malware sul mio pc: Rogue Residue Opzioni
pavelceko
Inviato: Tuesday, April 07, 2009 12:25:43 PM
Rank: Newbie

Iscritto dal : 4/7/2009
Posts: 0
Salve dopo aver fatto la scansione con Malwarebytes questo che segue è il file log che si autoproduce.
Come faccio ad eliminare difinitivamente quella che mi indica come una chiave di registro infetta.
Premetto che ho provato fin ora eliminando il malware sia in modalità normale e provvisoria dopo la scansione, ma il problema persiste.

Grazie

Malwarebytes' Anti-Malware 1.36
Versione del database: 1947
Windows 5.1.2600 Service Pack 2

07/04/2009 11.55.50
mbam-log-2009-04-07 (11-55-50).txt

Tipo di scansione: Scansione rapida
Elementi scansionati: 72309
Tempo trascorso: 8 minute(s), 20 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 1
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)
Sponsor
Inviato: Tuesday, April 07, 2009 12:25:43 PM

 
r16
Inviato: Tuesday, April 07, 2009 12:30:10 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Vuoi dire che Malwarebytes, ad ogni scansione continua a trovarti quella chiave?
Posta un log di HJT.
pavelceko
Inviato: Tuesday, April 07, 2009 12:30:20 PM
Rank: Newbie

Iscritto dal : 4/7/2009
Posts: 0
Spero vi sia utile anche il file log con Hjt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12.28.32, on 07/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Elantech\ktp.exe
C:\Programmi\Arcade\PCMService.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\acer\epm\epm-dm.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\Acer\eRecovery\Monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\Pompeo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
C:\documents and settings\pompeo\impostazioni locali\dati applicazioni\ucigw.exe
C:\Acer\eManager\anbmServ.exe
C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Windows Live\Contacts\wlcomm.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {78875F5C-A685-4405-8DC5-D48DC65452B0} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmi\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Programmi\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [KTPWare] C:\Programmi\Elantech\ktp.exe
O4 - HKLM\..\Run: [PCMService] "C:\Programmi\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Programmi\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Pompeo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ucigw] "c:\documents and settings\pompeo\impostazioni locali\dati applicazioni\ucigw.exe" ucigw
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Programmi\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Impostazioni di Google Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Programmi\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c9a754d8962ae) (gupdate1c9a754d8962ae) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Programmi\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 8448 bytes
pavelceko
Inviato: Tuesday, April 07, 2009 12:31:40 PM
Rank: Newbie

Iscritto dal : 4/7/2009
Posts: 0
r16 ha scritto:
Ciao.
Vuoi dire che Malwarebytes, ad ogni scansione continua a trovarti quella chiave?
Posta un log di HJT.


Ho postato il log Hjt, ma come ripeto ho eliminato dopo scnsione e ancora mi si aprono finestre non volute..
r16
Inviato: Tuesday, April 07, 2009 12:34:00 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
COMBOFIX
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,e dopo aver scaricato COMBOFIX, chiudi la connessione.

Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Salvalo sul desktop.
Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.

Disinstalla combofix in questo modo: (dopo che avrò visto il log)
Start
Esegui
nella finestra di dialogo, copia ed incolla questo comando: Combofix /u e premi Invio poi cancella le cartelle in "C" di combofix (qoobox)

Fai una scansione con Malwarebytes, e posta il log.
Riferisci se il problema è risolto.
pavelceko
Inviato: Tuesday, April 07, 2009 12:46:30 PM
Rank: Newbie

Iscritto dal : 4/7/2009
Posts: 0
r16 ha scritto:
COMBOFIX
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,e dopo aver scaricato COMBOFIX, chiudi la connessione.

Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Salvalo sul desktop.
Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.

Disinstalla combofix in questo modo: (dopo che avrò visto il log)
Start
Esegui
nella finestra di dialogo, copia ed incolla questo comando: Combofix /u e premi Invio poi cancella le cartelle in "C" di combofix (qoobox)

Fai una scansione con Malwarebytes, e posta il log.
Riferisci se il problema è risolto.



Ecco:

ComboFix 09-04-04.01 - Pompeo 2009-04-07 12.40.24.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.1023.570 [GMT 2:00]
Eseguito da: c:\documents and settings\Pompeo\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Pompeo\Impostazioni locali\Dati applicazioni\ucigw.dat
c:\documents and settings\Pompeo\Impostazioni locali\Dati applicazioni\ucigw.exe
c:\documents and settings\Pompeo\Impostazioni locali\Dati applicazioni\ucigw_nav.dat
c:\documents and settings\Pompeo\Impostazioni locali\Dati applicazioni\ucigw_navps.dat
c:\windows\system32\drivers\npf.sys
c:\windows\system32\packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_NPF


((((((((((((((((((((((((( Files Creati Da 2009-03-07 al 2009-04-07 )))))))))))))))))))))))))))))))))))
.

2009-04-07 12:27 . 2009-04-07 12:27 <DIR> d-------- c:\programmi\Trend Micro
2009-04-07 11:08 . 2009-04-07 11:08 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-04-07 11:08 . 2009-04-07 11:08 <DIR> d-------- c:\documents and settings\Pompeo\Dati applicazioni\Malwarebytes
2009-04-07 11:08 . 2009-04-07 11:08 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-04-07 11:08 . 2009-04-06 15:32 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-07 11:08 . 2009-04-06 15:32 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-04-06 17:15 . 2004-08-19 15:39 159,232 --a------ c:\windows\system32\ptpusd.dll
2009-04-06 17:15 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-04-06 17:15 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\dllcache\usbscan.sys
2009-04-06 17:15 . 2001-08-30 23:07 5,632 --a------ c:\windows\system32\ptpusb.dll
2009-03-31 11:02 . 2009-03-31 11:02 <DIR> d--hs---- C:\FOUND.000
2009-03-23 15:06 . 2009-03-23 15:06 <DIR> d-------- c:\programmi\Windows Media Connect 2
2009-03-22 13:18 . 2009-03-22 13:18 <DIR> d-------- c:\documents and settings\NetworkService\Dati applicazioniPDFcreator
2009-03-20 16:45 . 2009-03-20 16:45 <DIR> d-------- c:\windows\Governor of Poker
2009-03-20 16:45 . 2009-03-20 16:45 <DIR> d-------- c:\programmi\Governor of Poker
2009-03-20 14:02 . 2009-03-20 14:02 <DIR> d-------- C:\AbaEnglishCourse
2009-03-18 17:08 . 2009-03-18 17:08 <DIR> d-------- c:\documents and settings\Pompeo\Dati applicazioni\Delicious IE Extension
2009-03-18 12:31 . 2009-03-18 12:31 <DIR> d-------- c:\programmi\NOS
2009-03-18 12:31 . 2009-03-18 12:31 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-03-17 14:29 . 2009-03-17 14:29 <DIR> d-------- c:\programmi\Microsoft Silverlight
2009-03-16 23:48 . 2009-03-16 23:48 <DIR> d-------- c:\programmi\MSXML 4.0
2009-03-16 12:46 . 2009-03-16 12:46 0 --a------ c:\windows\nsreg.dat
2009-03-16 12:35 . 2009-03-16 12:35 <DIR> d-------- c:\programmi\MSBuild
2009-03-16 12:30 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-03-16 12:30 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-03-16 12:30 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-03-16 12:27 . 2009-03-16 12:27 <DIR> d-------- c:\programmi\Microsoft Works
2009-03-16 12:26 . 2009-03-16 12:26 <DIR> d-------- c:\windows\SHELLNEW
2009-03-16 12:26 . 2009-03-16 12:26 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-03-16 12:25 . 2009-03-16 12:25 <DIR> dr-h----- C:\MSOCache
2009-03-16 12:12 . 2009-03-16 12:12 <DIR> d-------- c:\programmi\File comuni\Adobe
2009-03-16 12:12 . 2009-03-16 12:12 <DIR> d-------- c:\documents and settings\Pompeo\Dati applicazioni\AdobeUM
2009-03-16 11:38 . 2009-03-16 11:38 <DIR> d-------- c:\programmi\Avira
2009-03-16 11:38 . 2009-03-16 11:38 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-03-16 11:17 . 2009-03-16 11:17 <DIR> d-------- c:\documents and settings\Pompeo\Tracing
2009-03-16 11:16 . 2009-03-16 11:16 <DIR> d-------- c:\programmi\Windows Live SkyDrive
2009-03-16 11:16 . 2009-03-16 11:16 <DIR> d-------- c:\programmi\Windows Live
2009-03-16 11:16 . 2009-03-16 11:16 <DIR> d-------- c:\programmi\Microsoft
2009-03-16 11:07 . 2009-03-16 11:07 <DIR> d-------- c:\programmi\File comuni\Windows Live
2009-03-16 10:57 . 2009-03-16 10:57 <DIR> d-------- c:\windows\system32\CatRoot_bak
2009-03-16 10:55 . 2008-10-24 12:10 453,632 --------- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-16 10:55 . 2008-06-14 18:59 272,768 --------- c:\windows\system32\dllcache\bthport.sys
2009-03-16 10:54 . 2008-08-14 14:43 2,184,064 --------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-16 10:54 . 2008-08-14 14:42 2,139,648 --------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-16 10:54 . 2008-08-14 14:42 2,061,440 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-16 10:54 . 2008-08-14 14:42 2,019,328 --------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-16 10:53 . 2009-03-16 10:53 <DIR> d--h----- c:\windows\$hf_mig$
2009-03-16 10:53 . 2009-03-16 10:53 <DIR> d---s---- c:\documents and settings\Pompeo\UserData
2009-03-16 10:48 . 2009-03-16 10:48 <DIR> d-------- c:\programmi\Google
2009-03-16 00:09 . 2009-03-16 00:09 <DIR> d-------- c:\programmi\VideoLAN
2009-03-16 00:09 . 2009-03-16 00:09 <DIR> d-------- c:\documents and settings\Pompeo\Dati applicazioni\vlc
2009-03-16 00:08 . 2009-03-16 00:08 <DIR> d-------- c:\programmi\vanBasco's Karaoke Player
2009-03-15 23:58 . 2009-03-15 23:58 <DIR> d-------- c:\programmi\PDFCreator
2009-03-15 23:58 . 2009-03-15 23:58 <DIR> d-------- c:\documents and settings\Pompeo\Dati applicazioni\PDFCreator
2009-03-15 23:51 . 2009-03-15 23:51 <DIR> d-------- c:\programmi\File comuni\Skype
2009-03-15 23:51 . 2009-03-15 23:51 <DIR> d-------- c:\documents and settings\Pompeo\Dati applicazioni\Skype
2009-03-15 23:51 . 2009-03-15 23:51 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Skype
2009-03-15 23:50 . 2009-03-15 23:50 <DIR> d-------- c:\programmi\Skype
2009-03-15 23:43 . 2009-03-15 23:43 <DIR> d-------- c:\windows\system32\LogFiles
2009-03-15 23:42 . 2009-03-15 23:42 <DIR> d-------- c:\windows\system32\drivers\umdf
2009-03-15 23:42 . 2007-07-27 09:41 26,488 --a------ c:\windows\system32\spupdsvc.exe
2009-03-15 23:27 . 2004-08-19 05:00 26,496 --a------ c:\windows\system32\dllcache\usbstor.sys
2009-03-15 22:48 . 2009-03-15 22:48 <DIR> d-------- c:\documents and settings\NetworkService\Menu Avvio
2009-03-15 21:43 . 2009-04-07 12:43 0 --------- c:\windows\system32\eRLog.ini
2009-03-15 21:42 . 2009-03-15 21:42 <DIR> d-------- c:\windows\Downloaded Installations
2009-03-15 21:42 . 2005-06-30 16:58 7,296 --a------ c:\windows\system32\drivers\osaio.sys
2009-03-15 21:42 . 2005-01-14 15:57 4,010 --a------ c:\windows\system32\drivers\osanbm.sys
2009-03-15 21:42 . 2009-03-15 21:43 88 --a------ c:\windows\GridV.UNI
2009-03-15 21:39 . 2009-03-15 21:39 <DIR> d-------- c:\programmi\acer
2009-03-15 21:39 . 2005-06-20 10:52 253,952 --a------ c:\windows\system32\Uninstall_eRecovery.exe
2009-03-15 21:38 . 2009-03-15 21:38 <DIR> d-------- c:\documents and settings\Pompeo\Bluetooth Software
2009-03-15 21:36 . 2009-03-15 21:36 <DIR> d-------- c:\programmi\WIDCOMM
2009-03-15 21:33 . 2009-03-15 21:33 <DIR> d-------- c:\programmi\Launch Manager
2009-03-15 21:33 . 2004-12-10 11:49 147,456 --a------ c:\windows\UNINST32.EXE
2009-03-15 21:33 . 2004-12-08 14:10 16,896 --a------ c:\windows\system32\drivers\DKbFltr.SYS
2009-03-15 21:33 . 2004-12-09 12:04 5,120 --a------ c:\windows\system32\FILTRCOI.DLL
2009-03-15 21:33 . 2009-03-15 21:33 79 --a------ c:\windows\LManager.UNI
2009-03-15 21:32 . 2004-11-10 11:06 13 --a------ c:\windows\system32\drivers\verfile.tic
2009-03-15 21:31 . 2009-03-15 21:31 <DIR> d-------- c:\programmi\WinPCap
2009-03-15 21:31 . 2009-03-15 21:31 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Intel
2009-03-15 21:31 . 2009-03-15 21:31 17,119 --a------ c:\windows\system32\drivers\AegisP.sys
2009-03-15 21:30 . 2009-03-15 21:30 <DIR> d-------- C:\Acer
2009-03-15 21:30 . 2004-09-01 23:57 221,258 --a------ c:\windows\system32\Epm-Po.dll
2009-03-15 21:30 . 2005-04-07 18:08 78,208 --a------ c:\windows\system32\drivers\epm-shd.sys
2009-03-15 21:30 . 2004-07-19 13:10 4,096 --a------ c:\windows\system32\drivers\epm-psd.sys
2009-03-15 21:29 . 2009-03-15 21:29 <DIR> d-------- c:\programmi\ATI Technologies
2009-03-15 21:29 . 2005-05-25 19:06 <DIR> d--h----- c:\documents and settings\Pompeo\Risorse di stampa
2009-03-15 21:29 . 2005-05-25 19:06 <DIR> d--h----- c:\documents and settings\Pompeo\Risorse di rete
2009-03-15 21:29 . 2009-03-15 21:30 <DIR> dr------- c:\documents and settings\Pompeo\Preferiti
2009-03-15 21:29 . 2005-05-25 19:06 <DIR> d--h----- c:\documents and settings\Pompeo\Modelli
2009-03-15 21:29 . 2005-05-25 19:06 <DIR> dr------- c:\documents and settings\Pompeo\Menu Avvio
2009-03-15 21:29 . 2005-05-25 19:06 <DIR> d--h----- c:\documents and settings\Pompeo\Impostazioni locali
2009-03-15 21:29 . 2009-03-15 21:30 <DIR> dr------- c:\documents and settings\Pompeo\Documenti
2009-03-15 21:29 . 2005-05-25 19:06 <DIR> dr-h----- c:\documents and settings\Pompeo\Dati applicazioni
2009-03-15 21:29 . 2004-06-14 11:48 3,318,626 --a------ c:\windows\as_1280x800.swf
2009-03-15 21:28 . 2009-03-15 21:29 <DIR> d-------- c:\documents and settings\Pompeo
2009-03-15 21:24 . 2001-08-30 20:41 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-03-15 21:24 . 2004-08-19 05:00 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2009-03-15 21:24 . 2009-03-15 21:24 8,192 --a------ c:\windows\REGLOCS.OLD

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 19:35 6,144 ----a-w c:\windows\system32\drivers\NTIDrvr.sys
2009-02-09 13:56 1,846,272 ----a-w c:\windows\system32\win32k.sys
2009-02-09 13:56 1,846,272 ----a-w c:\windows\system32\dllcache\win32k.sys
2009-02-06 16:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2007-02-09 25388584]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-16 39408]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Google Update"="c:\documents and settings\Pompeo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-03-16 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-03-22 126976]
"KTPWare"="c:\programmi\Elantech\ktp.exe" [2005-01-29 253952]
"PCMService"="c:\programmi\Arcade\PCMService.exe" [2005-03-09 49152]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-12 339968]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-08-11 200704]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-15 2893824]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2005-04-28 544768]
"eRecoveryService"="c:\programmi\Acer\eRecovery\Monitor.exe" [2005-06-29 352256]
"avgnt"="c:\programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 c:\windows\system32\bthprops.cpl]
"SoundMan"="SOUNDMAN.EXE" [2005-03-24 c:\windows\soundman.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Software Bluetooth\BTTray.exe [2005-08-16 577597]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Ares\\Ares.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2009-03-15 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2009-03-15 78208]
R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2009-03-15 7296]
R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2009-03-15 4010]
R3 Ktp;Elantech Touchpad;c:\windows\system32\drivers\Ktp.sys [2005-05-25 25984]
S2 gupdate1c9a754d8962ae;Google Update Service (gupdate1c9a754d8962ae);c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-17 133104]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{83a0e1ee-11b0-11de-aebe-000fb093f9c5}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL usbdrv.exe
.
Contenuto della cartella 'Scheduled Tasks'

2009-04-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4173389063-3791883740-1275237321-1005.job
- c:\documents and settings\Pompeo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-03-16 12:37]

2009-04-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-03-17 23:59]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-ucigw - c:\documents and settings\pompeo\impostazioni locali\dati applicazioni\ucigw.exe
HKLM-Run-IgfxTray - c:\windows\system32\igfxtray.exe


.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Pompeo\Dati applicazioni\Mozilla\Firefox\Profiles\td5wakxr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - component: c:\programmi\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: c:\documents and settings\Pompeo\Impostazioni locali\Dati applicazioni\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\programmi\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-07 12:43:26
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\SYSTEM32\ATI2EVXX.EXE
c:\programmi\INTEL\WIRELESS\BIN\EVTENG.EXE
c:\programmi\INTEL\WIRELESS\BIN\S24EVMON.EXE
c:\windows\SYSTEM32\ATI2EVXX.EXE
c:\programmi\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE
c:\windows\SYSTEM32\RUNDLL32.EXE
c:\acer\EMANAGER\ANBMSERV.EXE
c:\programmi\LAUNCH MANAGER\LMANAGER.EXE
c:\programmi\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE
c:\programmi\WIDCOMM\SOFTWARE BLUETOOTH\BIN\BTWDINS.EXE
c:\programmi\INTEL\WIRELESS\BIN\REGSRVC.EXE
c:\programmi\Skype\Plugin Manager\SkypePM.exe
.
**************************************************************************
.
Ora fine scansione: 2009-04-07 12:44:55 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-04-07 10:44:54

Pre-Run: 27.661.271.040 byte disponibili
Post-Run: 28,089,548,800 byte disponibili

242 --- E O F --- 2009-03-24 14:13:16
r16
Inviato: Tuesday, April 07, 2009 1:19:07 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Fai queste semplici operazioni di pulizia:
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
Poi:
Start\Esegui\copia e incolla la stringa %temp% clicca su Ok, svuota la cartella temp. (non eliminare la cartella)
Poi:
Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO
Le infezioni sono state eliminate, non dovrebbe più verificarsi il problema.
Ciao.
pavelceko
Inviato: Tuesday, April 07, 2009 1:55:13 PM
Rank: Newbie

Iscritto dal : 4/7/2009
Posts: 0
r16 ha scritto:
Fai queste semplici operazioni di pulizia:
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223
Poi:
Start\Esegui\copia e incolla la stringa %temp% clicca su Ok, svuota la cartella temp. (non eliminare la cartella)
Poi:
Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)
SVUOTA IL CESTINO
Le infezioni sono state eliminate, non dovrebbe più verificarsi il problema.
Ciao.


Ti ringrazio per la consulenza. Ho fatto tutto ciò che mi hai detto e spero abbia risolto il mio problema.

Ancora grazie.

Saluti
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.