Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

R16 mi ricontrolli il log per favore.... antivirus e firewall non funzionano Opzioni
lionheart
Inviato: Tuesday, September 29, 2009 9:28:53 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
Ciao, come da titolo oggi mi si è disattivato di colpo sia il firewall che l'antivirus Brick wall Di quest'ultimo non funziona nemmeno la scansione.....

Ti posto sia il log fatto con Malwarebytes' Anti-Malware che quello con HijackThis..... Dimenticavo non mi fa andare nemmeno in modalità provvisoria......

Commenta:
Malwarebytes' Anti-Malware 1.41
Versione del database: 2870
Windows 5.1.2600 Service Pack 3

29/09/2009 21.06.16
mbam-log-2009-09-29 (21-06-16).txt

Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 171669
Tempo trascorso: 1 hour(s), 38 minute(s), 37 second(s)

Processi delle memoria infetti: 1
Moduli della memoria infetti: 0
Chiavi di registro infette: 3
Valori di registro infetti: 1
Elementi dato del registro infetti: 3
Cartelle infette: 1
File infetti: 3

Processi delle memoria infetti:
C:\Documents and Settings\G & S\Dati applicazioni\drivers\winupgro.exe (Trojan.Agent) -> Unloaded process successfully.

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_CLASSES_ROOT\Typelib\{c20ee2d6-81c3-6a08-79c5-1989da43bc19} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\111111s1ro1s1a (Worm.Bagle) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sK9Ou0s (Worm.Bagle) -> Quarantined and deleted successfully.

Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\drvsyskit (Trojan.Agent) -> Quarantined and deleted successfully.

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Cartelle infette:
C:\Documents and Settings\G & S\Dati applicazioni\drivers\downld (Worm.Bagle) -> Quarantined and deleted successfully.

File infetti:
C:\Documents and Settings\G & S\Dati applicazioni\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
C:\Documents and Settings\G & S\Dati applicazioni\drivers\11s11ro1s1a2.sys (Worm.Bagle) -> Quarantined and deleted successfully.
C:\Documents and Settings\G & S\Dati applicazioni\drivers\winupgro.exe (Trojan.Agent) -> Quarantined and deleted successfully.




Commenta:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21.18.40, on 29/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
D:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Microsoft LifeCam\MSCamS32.exe
C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
C:\Programmi\Cyberlink\Shared files\RichVideo.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
D:\Programmi\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
d:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~1.EXE
C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\Programmi\Stardock\ObjectDock\ObjectDock.exe
C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.noceraterinese.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.personalfirewall.comodo.com/uninst_survey.html?serial=3.0.25.376_E33C8A2CD88A4ed3B2BD332E72436F25
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - D:\Programmi\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmi\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - D:\Programmi\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programmi\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Programmi\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [StartupDelayer] "C:\Programmi\r2 Studios\Startup Delayer\Startup Launcher.exe"
O4 - HKLM\..\Run: [AliceRE_McciTrayApp] C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~1.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Programmi\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [drvsyskit] C:\Documents and Settings\G & S\Dati applicazioni\drivers\winupgro.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1237842482531
O17 - HKLM\System\CCS\Services\Tcpip\..\{74E9A614-E751-44CF-9A46-B15DA50780B5}: NameServer = 85.37.17.51 85.38.28.97
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE9B2EEB-6D7D-4216-AAFF-F996702F2109}: NameServer = 192.168.1.1
O23 - Service: Avira AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: Network WanMiniport First Position - Unknown owner - C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\Cyberlink\Shared files\RichVideo.exe
O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - D:\Programmi\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - d:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 8791 bytes





Sponsor
Inviato: Tuesday, September 29, 2009 9:28:53 PM

 
pidue
Inviato: Tuesday, September 29, 2009 9:31:29 PM

Rank: AiutAmico

Iscritto dal : 6/2/2005
Posts: 7,332
Hai il Bagle, una brutta bestia.



r16
Inviato: Tuesday, September 29, 2009 9:33:02 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
lionheart , tu sei il campione del forum a prenderti virus....Sick

Disattiva il ripristino configurazione di sistema, e tienilo disattivato, fino alla soluzione del problema http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121

Scarica Findykill:
http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe
installa FindyKill .
chiudi tutte le eventuali applicazioni aperte (antivirus, firewall e programmi "residenti")
disconnettiti da Internet
sconnetti, fisicamente, il modem dal computer.
avvia il tool e digita F per impostare la lingua;
clicca su 2 - Suppression des fichiers infectieux (Eliminazione dei file infetti)
al termine dell'operazione verrà rilasciato un log: salvalo sul Desktop, e postalo qui.
P.S:
Potranno esserci dei riavvii, non preoccuparti, è il programma che stà lavorando.

P.S:
Non quotare le mie risposte. (grazie)
lionheart
Inviato: Tuesday, September 29, 2009 9:34:05 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
come ho fatto a prenderlo e soprattutto come faccio a toglierlo Think
lionheart
Inviato: Tuesday, September 29, 2009 9:34:50 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
grazie....Angel
simo95
Inviato: Tuesday, September 29, 2009 9:40:36 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
lionheart ha scritto:
come ho fatto a prenderlo e soprattutto come faccio a toglierlo Think


Crack, principalmente.
lionheart
Inviato: Tuesday, September 29, 2009 9:53:00 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
ecco il log:



############################## | FindyKill V5.012 |

# User : G (Administrators) # G-2BD1F07886EB4
# Update on 20/09/2009 by Chiquitine29
# Start at: 21.41.00 | 29/09/2009
# Website : http://pagesperso-orange.fr/NosTools/index.html

# AMD Athlon(tm) XP 2600+
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : Antivirus BitDefender 12.0 [ (!) Disabled | Updated ]
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
# AV : AntiVir Desktop 9.0.1.26 [ (!) Disabled | (!) Outdated ]
# AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# FW : COMODO Firewall[ Enabled ]3.9

# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 13,92 Go (5,45 Go free) [Sistema] # NTFS
# D:\ # Disco rigido locale # 60,61 Go (9,21 Go free) [Dati] # NTFS
# E:\ # Disco CD-ROM
# F:\ # Disco CD-ROM
# G:\ # Disco CD-ROM
# H:\ # Disco rimovibile
# I:\ # Disco rimovibile

############################## | Processus actifs |

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LogonUI.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
D:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Microsoft LifeCam\MSCamS32.exe
C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
C:\Programmi\Cyberlink\Shared files\RichVideo.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
D:\Programmi\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
d:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## | C: |


################## | C:\WINDOWS |

Supprimé ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-027D44D4.pf
Supprimé ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-17681AA8.pf

################## | C:\WINDOWS\system32 |


################## | C:\WINDOWS\system32\drivers |


################## | C:\Documents and Settings\G

Supprimé ! C:\Documents and Settings\G & S\Dati applicazioni\drivers\11s11ro1s1a2.sys
Supprimé ! C:\Documents and Settings\G & S\Dati applicazioni\drivers\winupgro.exe

################## | Autres suppression ... |


################## | Temporary Internet Files |

Supprimé ! C:\DOCUME~1\G&S~1\IMPOST~1\Temp\Rar$EX01.360\crac.exe

################## | Registre / Clés infectieuses |

Supprimé ! [HKLM\SYSTEM\ControlSet001\Services\111111s1ro1s1a]
Supprimé ! [HKLM\SYSTEM\ControlSet003\Services\111111s1ro1s1a]
Supprimé ! [HKLM\SYSTEM\ControlSet001\Services\sK9Ou0s]
Supprimé ! [HKLM\SYSTEM\ControlSet003\Services\sK9Ou0s]
Supprimé ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S]
Supprimé ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S]
Supprimé ! [HKCU\Software\bisoft]
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Supprimé ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
Supprimé ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
Supprimé ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
Supprimé ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
Supprimé ! [HKLM\software\microsoft\security center] "FirewallOverride"
Supprimé ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"

################## | Etat / Services / Informations |

# Mode sans echec restauré !

# Affichage des fichiers cachés : OK

# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

################## | PEH ... |


################## | Cracks / Keygens / Serials |


################## | ! Fin du rapport # FindyKill V5.012 ! |

r16
Inviato: Tuesday, September 29, 2009 9:55:52 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Finita quella scansione, fai questa:
Scarica Elibagla:

http://www.zonavirus.com/datos/descargas/95/elibagla.asp

scorri fino a fondo pagina e, clicca su Descargar Elibagla

clicca sulla icona di Elibagla per avviare il tool

spunta la voce Eliminar ficheros automaticamente

clicca su Explorar

lascia completare la scansione di default (C:\)

al termine dell'operazione verrà rilasciato un log in Disco Locale C: dal nome InfoSat.txt
Postalo qui.

Penso e spero, che sia inutile dirti che DEVI eliminare quello che hai scaricato da E-Mule. ( Crack, Keygen, e porcherie varie.
Svuota anche il Cestino.
lionheart
Inviato: Tuesday, September 29, 2009 10:02:45 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66

(29-9-2009 19:58:32)
EliBagle v12.93 (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 28 de Septiembre del 2009)

Lista de Acciones (por Acción Directa):
Eliminada Carpeta "%AppData%\Drivers"

(29-9-2009 19:59:8)
EliBagle v12.93 (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 28 de Septiembre del 2009)

Lista de Acciones (por Exploración):
Explorando "C:\"

Nº Total de Directorios: 3857
Nº Total de Ficheros: 26069
Nº de Ficheros Analizados: 5226
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
r16
Inviato: Tuesday, September 29, 2009 10:04:26 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Disistalla: (sono corrotti)
Antivirus BitDefender
AntiVir
COMODO Firewall

Fai una pulizia con CCleaner.
Riavvia il pc.
NON NAVIGARE IN INTERNET, (penso tu stia scrivendo da un'altro pc.)
lionheart
Inviato: Tuesday, September 29, 2009 10:07:28 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
io BitDefender non c'è lo istallato, nn so perchè compaia nel log..... Purtroppo o solo questo pc quindi per forza di cose devo usare internet.....

r16
Inviato: Tuesday, September 29, 2009 10:10:00 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Puoi solo navigare sul sito di AIUTAMICI per scaricare Combofix.
Scarica Combofix

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


Salvalo sul desktop.

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.

Disinstalla combofix in questo modo: (dopo che avrò visto il log)
Start
Esegui
nella finestra di dialogo, copia ed incolla questo comando: Combofix /u e premi Invio poi cancella le cartelle in "C" di Combofix e (qoobox)
r16
Inviato: Tuesday, September 29, 2009 10:25:52 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Finita la scansione il pc dovrebbe riavviarsi, altrimenti riavvialo tu.

Poi fai:
Start\Esegui\ digita: services.msc
Si apre la pagina dei "Servizi"
Controlla se TUTTI questi "Servizi" siano avviati, e siano in Automatico:
Avvisi, Centro sicurezza PC, Aggiornamenti automatici, Connessioni di rete, Zero Configuration reti senza fili ,e Windows Firewall/ Condivisione connessione Internet (ICS).
Se ne trovi qualcuno in "Manuale, o Disabilitato, lo riporti in Automatico, ricorda di RIAVVIARE il pc.
Per avviare un servizio, clicca con il tasto destro sul servizio, Proprietà >Automatico > Ok > Avvia > Ok.

Fammi un resoconto di quello che hai fatto, e dimmi che problemi riscontri.
lionheart
Inviato: Tuesday, September 29, 2009 10:30:52 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
ecco il log di ComboFix



ComboFix 09-09-28.01 - G & S 29/09/2009 22.23.17.6.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1529 [GMT 2:00]
Eseguito da: c:\documents and settings\G & S\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {00000000-0000-0000-1200-140000FCFD7F}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000000-0012-0014-00DC-FD7F00000802}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000000-0012-0014-00EC-FD7F00000802}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000000-0012-0014-00FC-FD7F00000802}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {001300D4-0000-0000-1000-00005454927C}
AV: Antivirus BitDefender *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\G & S\Dati applicazioni\Desktopicon
c:\documents and settings\G & S\Dati applicazioni\drivers\downld
c:\documents and settings\G & S\Dati applicazioni\Microsoft\Clip Organizer\mstore10.mgc
c:\documents and settings\G & S\Dati applicazioni\Microsoft\Clip Organizer\Offic10.MGC
C:\InfoSat.txt
c:\recycler\S-1-5-21-1645522239-1580818891-1417001333-500
c:\recycler\S-1-5-21-1957994488-1979792683-1606980848-500
c:\windows\Installer\62b0c4.msi
c:\windows\jestertb.dll

.
((((((((((((((((((((((((( Files Creati Da 2009-08-28 al 2009-09-29 )))))))))))))))))))))))))))))))))))
.

2009-09-29 20:11 . 2009-09-29 20:11 -------- d--h--w- c:\documents and settings\G & S\Dati applicazioni\drivers
2009-09-29 19:37 . 2009-09-29 19:48 -------- d-----w- C:\FindyKill
2009-09-29 09:29 . 2009-09-29 09:29 71 ----a-w- c:\documents and settings\G & S\Dati applicazionidMb.dat
2009-09-29 09:28 . 2009-09-29 09:28 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\U3
2009-09-27 14:32 . 2009-09-27 14:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TVU Networks
2009-09-27 14:32 . 2009-09-27 14:32 -------- d-----w- c:\documents and settings\G & S\LocalLow
2009-09-27 14:29 . 2009-09-27 14:29 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\TVU networks
2009-09-26 10:24 . 2009-09-26 11:17 -------- d-----w- c:\documents and settings\G & S\Impostazioni locali\Dati applicazioni\JockerSoft
2009-09-26 10:23 . 2009-09-26 11:31 -------- d-----w- c:\programmi\JockerSoft
2009-09-25 22:58 . 2009-09-25 22:58 -------- d-sh--w- c:\documents and settings\G & S\PrivacIE
2009-09-25 22:53 . 2009-09-25 22:53 -------- d-sh--w- c:\documents and settings\G & S\IETldCache
2009-09-25 22:50 . 2009-09-25 22:50 -------- d-----w- c:\windows\ie8updates
2009-09-25 22:47 . 2009-09-25 22:49 -------- dc-h--w- c:\windows\ie8
2009-09-25 22:41 . 2009-08-07 08:48 100352 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-09-25 22:41 . 2009-07-03 16:55 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-25 22:40 . 2009-07-03 16:55 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-25 22:40 . 2009-07-03 16:55 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-09-25 22:40 . 2009-07-03 16:55 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2009-09-25 22:40 . 2009-07-03 16:55 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-09-24 13:02 . 2009-09-24 13:04 -------- d-----w- c:\documents and settings\G & S\.VirtualBox
2009-09-24 13:01 . 2009-09-09 18:15 115856 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-09-24 13:01 . 2009-09-09 18:15 91856 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-09-24 13:01 . 2009-09-09 18:15 41424 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-09-23 18:38 . 2009-09-27 13:26 -------- d-----w- c:\programmi\File comuni\uusee
2009-09-23 18:38 . 2009-09-27 13:25 -------- d-----w- c:\programmi\uusee
2009-09-23 18:32 . 2009-09-23 18:33 -------- d-----w- c:\programmi\SopCast
2009-09-23 12:34 . 2009-09-23 12:34 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-23 12:34 . 2009-07-15 09:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-09-23 12:34 . 2009-09-23 12:34 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-23 11:27 . 2009-09-23 11:27 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\Yahoo!
2009-09-23 11:27 . 2009-09-23 11:31 -------- d-----w- c:\programmi\Yahoo!
2009-09-22 19:17 . 2009-09-28 16:16 -------- d-----w- c:\documents and settings\G & S\Impostazioni locali\Dati applicazioni\Cyberlink
2009-09-22 19:11 . 2009-09-28 15:47 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\CyberLink
2009-09-22 19:11 . 2009-09-22 19:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CyberLink
2009-09-22 19:11 . 2009-09-22 19:11 -------- d-----w- c:\programmi\Cyberlink
2009-09-22 19:10 . 2009-09-22 19:10 -------- d-----w- c:\programmi\File comuni\CyberLink
2009-09-22 19:07 . 2009-09-22 19:07 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-09-22 18:49 . 2009-09-22 18:49 -------- d-----w- c:\documents and settings\G & S\Bluetooth Software
2009-09-22 18:47 . 2009-09-22 18:47 -------- d-----w- c:\programmi\WIDCOMM
2009-09-22 12:01 . 2009-09-26 11:48 -------- d-----w- c:\programmi\r2 Studios
2009-09-21 15:50 . 2009-09-21 15:50 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\Malwarebytes
2009-09-21 15:50 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-21 15:50 . 2009-09-21 15:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-09-21 15:50 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-21 13:04 . 2009-09-21 13:04 -------- d-----w- C:\found.000
2009-09-21 12:28 . 2009-09-21 12:28 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\TuneUp Software
2009-09-21 12:27 . 2009-09-21 12:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TuneUp Software
2009-09-21 12:23 . 2009-09-21 12:26 -------- d-----w- c:\programmi\AnVir Task Manager Free
2009-09-21 12:23 . 2009-09-21 12:26 -------- d-----w- c:\documents and settings\G & S\Impostazioni locali\Dati applicazioni\AnVir
2009-09-21 08:57 . 2009-09-21 08:58 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\GetRightToGo
2009-09-20 19:57 . 2005-05-25 05:00 90112 ------w- c:\windows\SDUnInst.exe
2009-09-20 17:33 . 2009-09-20 18:24 -------- d-----w- c:\windows\system32\NtmsData
2009-09-20 16:31 . 2009-09-20 16:31 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\JAM Software
2009-09-20 12:40 . 2009-09-20 12:40 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PPLive
2009-09-20 12:40 . 2009-09-20 12:40 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\PPLive
2009-09-20 12:33 . 2009-09-20 12:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CCTV
2009-09-17 13:19 . 2009-09-17 13:39 -------- d-----w- c:\programmi\Hard Disk Sentinel
2009-09-09 18:15 . 2009-09-09 18:15 133648 ------w- c:\windows\system32\VBoxNetFltNotify.dll
2009-09-07 11:45 . 2009-09-07 11:46 -------- d-----w- c:\windows\speech
2009-09-07 11:45 . 2009-09-07 11:45 -------- d-----w- c:\windows\Lhsp
2009-09-07 09:33 . 2009-09-07 09:33 -------- d-----w- c:\documents and settings\G & S\Impostazioni locali\Dati applicazioni\IsolatedStorage
2009-09-07 09:32 . 2009-09-07 09:32 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\SAU KP
2009-09-03 19:12 . 2009-09-03 19:12 -------- d-----w- c:\programmi\File comuni\PCSuite
2009-09-03 14:09 . 2009-09-03 22:02 -------- d-----w- c:\programmi\AudioCommander
2009-09-03 14:01 . 2009-09-03 14:01 -------- d-----w- c:\programmi\MIKSOFT
2009-09-03 13:57 . 2009-09-03 13:57 249856 ------w- c:\windows\Setup1.exe
2009-09-03 13:57 . 2009-09-03 13:57 73216 ----a-w- c:\windows\ST6UNST.EXE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-29 20:18 . 2009-03-02 14:26 -------- d-----w- c:\programmi\COMODO
2009-09-29 20:18 . 2009-03-02 13:59 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\Comodo
2009-09-29 12:47 . 2009-03-02 15:36 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\uTorrent
2009-09-26 13:34 . 2009-03-02 14:22 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-09-26 12:23 . 2009-03-02 15:31 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-09-25 22:53 . 2009-03-17 20:03 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-09-22 19:07 . 2009-08-24 15:31 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-09-22 19:07 . 2006-10-09 01:37 505128 ----a-w- c:\windows\system32\msvcp71.dll
2009-09-22 19:07 . 2006-02-03 02:30 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-09-22 14:24 . 2009-04-27 18:41 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\SolidDocuments
2009-09-21 15:40 . 2001-08-31 09:00 79910 ----a-w- c:\windows\system32\perfc010.dat
2009-09-21 15:40 . 2001-08-31 09:00 479740 ----a-w- c:\windows\system32\perfh010.dat
2009-09-21 13:51 . 2009-03-02 14:22 53896 ----a-w- c:\documents and settings\G & S\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-21 11:21 . 2009-03-20 13:05 -------- d-----w- c:\programmi\Codice Fiscale
2009-09-20 14:12 . 2009-07-28 10:10 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\Superenalotto 3000
2009-09-20 13:42 . 2009-03-02 16:56 -------- d-sh--w- c:\documents and settings\All Users\Dati applicazioni\{55A29068-F2CE-456C-9148-C869879E2357}
2009-09-14 14:55 . 2009-03-04 19:09 -------- d-----w- c:\programmi\Google
2009-09-07 09:46 . 2009-04-02 09:29 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\mIRC
2009-09-03 19:12 . 2009-06-20 13:13 -------- d-----w- c:\programmi\File comuni\Nokia
2009-09-03 19:05 . 2009-04-01 09:45 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Installations
2009-09-03 13:53 . 2009-04-01 09:57 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\Nokia
2009-08-28 13:13 . 2009-03-10 12:03 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\dvdcss
2009-08-25 16:58 . 2009-08-25 16:58 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\Thinstall
2009-08-20 11:53 . 2009-03-23 13:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-18 13:35 . 2009-08-18 13:35 -------- d-----w- c:\documents and settings\G & S\Dati applicazioni\OxyCube
2009-08-18 13:30 . 2009-08-18 13:30 -------- d-----w- c:\programmi\Oxygen Software
2009-08-07 22:32 . 2009-03-02 14:23 -------- d-----w- c:\programmi\Alice ti aiuta
2009-07-03 16:55 . 2008-04-13 17:13 915456 ----a-w- c:\windows\system32\wininet.dll
.

------- Sigcheck -------

[-] 2008-04-13 . 97CBB1689BB951AD8DEE44C9F9C44318 . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
[7] 2008-04-13 . 10AA0E13B4D20EE798E3382C9B89B3E3 . 617472 . . [5.82] . . c:\windows\VistaMizer\old\comctl32.dll
[7] 2008-04-13 . 9530E35D9033ACED20CDA2509A21073A . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
[7] 2001-08-31 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll

[-] 2009-03-01 . 1F39C7BDBA4C5F3F01C4EABF7EDBF4B3 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

[-] 2009-03-01 13:10 . EA518D0002F4338DB0E7D83370D61845 . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll

[-] 2009-03-01 . E0C98D37A349DC9688FE802F623B16F6 . 247296 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll

[-] 2009-03-01 . 948FD43022363203761659A8B27B5E94 . 2450176 . . [5.1.2600.5657] . . c:\windows\system32\ntoskrnl.exe
[-] 2009-03-01 . 0EE73494680235D59F4E57301D7AD580 . 2192896 . . [5.1.2600.5657] . . c:\windows\VistaMizer\old\ntoskrnl.exe

[-] 2008-04-13 . 3DBD6DC6D74C517D55A1B3AECA88EF48 . 588800 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[7] 2008-04-13 . FA94696C0727BD59E517C674CD6E7C72 . 579584 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\user32.dll

[-] 2008-04-13 . 6DC43081C760EEC1130D2C8C145DF375 . 549888 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[7] 2008-04-13 . 9259170D29B5A256735FCB8B80280857 . 510464 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe

[-] 2008-04-13 . 287B3020F1324E99F313C9E7FCFCCCCC . 1554944 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[7] 2008-04-13 . 70D7F99D95615C3C278367756287DB71 . 1036288 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe

[-] 2008-04-13 . 91B6AAC828F8BBE1796275424E44DFB0 . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[7] 2008-04-13 . F53CDDEF33A4C41336A782BE3D170158 . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe

[-] 2009-03-01 . 2D10EEB83EEBDCE43E9F0214057C03F2 . 2327040 . . [5.1.2600.5657] . . c:\windows\system32\ntkrnlpa.exe
[-] 2009-03-01 . C812D8551FD3B6ACDBF7EB6B18B1B992 . 2069760 . . [5.1.2600.5657] . . c:\windows\VistaMizer\old\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2005-07-07 851968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupDelayer"="c:\programmi\r2 Studios\Startup Delayer\Startup Launcher.exe" [2007-12-14 26112]
"Malwarebytes Anti-Malware (reboot)"="d:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 25088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"=c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"bgmonitor_{79662e04-7c6c-4d9f-84c7-88d8a56b10aa}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"epson stylus c42 series"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
"sunjavaupdatesched"="d:\programmi\Java\jre6\bin\jusched.exe"
"remotecontrol"=c:\windows\system32\rmctrl.exe
"QuickTime Task"=c:\windows\system32\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeExp.exe"=
"d:\\Programmi\\PoivY.com\\PoivY\\PoivY.exe"=
"c:\\Programmi\\uusee\\UUSeePlayer.exe"=

R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/09/22 21:11];d:\programmi\CyberLink\PowerDVD9\PowerDVD9\000.fcl [07/05/2009 21.05.22 87536]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [23/09/2009 14.34.14 604488]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [31/07/2009 18.35.34 8192]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [21/09/2006 11.19.04 347648]
S3 aspi;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [05/04/2009 18.17.33 16512]
S3 CrystalSysInfo;CrystalSysInfo;d:\programmi\MediaCoder\SysInfo.sys [25/09/2007 16.59.46 15152]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [20/06/2009 15.07.36 136704]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [24/09/2009 15.01.20 91856]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [13/10/2006 18.04.44 2383152]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'

2009-09-29 c:\windows\Tasks\Manutenzione in 1 clic.job
- d:\programmi\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 10:28]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.noceraterinese.com/
uInternet Connection Wizard,ShellNext = hxxp://www.personalfirewall.comodo.com/uninst_survey.html?serial=3.0.25.376_E33C8A2CD88A4ed3B2BD332E72436F25
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
TCP: {BE9B2EEB-6D7D-4216-AAFF-F996702F2109} = 192.168.1.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\G & S\Dati applicazioni\Mozilla\Firefox\Profiles\kx1lt5y4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.inter.it/aas/hp?L=it
FF - component: d:\programmi\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\G & S\Dati applicazioni\Mozilla\Firefox\Profiles\kx1lt5y4.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: d:\programmi\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: d:\programmi\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: d:\programmi\Java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: d:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.max-connections-per-server - 8
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-29 22:26
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\d:\programmi\CyberLink\PowerDVD9\PowerDVD9\000.fcl"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(1044)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'lsass.exe'(1116)
c:\windows\system32\scecli.dll
c:\windows\system32\SETUPAPI.dll
.
Ora fine scansione: 2009-09-29 22.28.07
ComboFix-quarantined-files.txt 2009-09-29 20:27

Pre-Run: 6.247.514.112 byte disponibili
Post-Run: 6.217.433.088 byte disponibili

263
lionheart
Inviato: Tuesday, September 29, 2009 10:39:08 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
avvisi ----- disabilitato

connessione di rete ------ manuale
r16
Inviato: Tuesday, September 29, 2009 10:41:28 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Segui le indicazioni: portali in Automatico.
Mi interessa sapere che problemi riscontri.

In ogni caso:
Reistalla Avira, e Comodo.

P.S:
Già che ci sei, fai anche una scansione con AVIRA.
lionheart
Inviato: Tuesday, September 29, 2009 11:32:46 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
Il problema ke ho riscontrato e ke non mi fa fare l'aggiornamento dell'archivio dell'antivirus...
r16
Inviato: Tuesday, September 29, 2009 11:41:35 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Rifai la disistallazione, e la reistallazione seguendo alla lettera questa guida.

http://www.zeusnews.it/zz_upload/PSV/Guida%20completa%20di%20%20AVIRA%20Antivir%209.pdf
Le voci indicate nella prima immagine a pagina 11 della Guida, spuntale tutte (nell'immagine non lo sono).
Ci sono anche delle istruzioni per l'Aggiornamento Manuale.
lionheart
Inviato: Wednesday, September 30, 2009 6:38:12 PM
Rank: AiutAmico

Iscritto dal : 3/26/2008
Posts: 66
il problema persiste.... non so se dipende da avira oppure è provocato dal virus
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.