Ecco il report:
############################## | FindyKill V5.020 |
# User : Massimo (Administrators) # TRAVERSA-C9CBCB
# Update on 26/11/2009 by Chiquitine29
# Start at: 16.33.50 | 06/12/2009
# Website :
http://pagesperso-orange.fr/NosTools/index.html# Contact :
FindyKill.Contact@gmail.com# Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
# Microsoft Windows XP Home Edition (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : AntiMalware 1.0 [ Enabled | (!) Outdated ]
# AV : Kaspersky Anti-Virus 8.0.0.506 [ (!) Disabled | Updated ]
# AV : Microsoft Security Essentials 2.0.6212.0 [ Enabled | Updated ]
# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 232,88 Go (28,03 Go free) # NTFS
# D:\ # Disco CD-ROM
# E:\ # Disco CD-ROM
############################## | Active Processes |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Programmi\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
C:\Programmi\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\PSIService.exe
C:\Programmi\Macrium\Reflect\ReflectService.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## | C: |
################## | C:\WINDOWS |
################## | C:\WINDOWS\system32 |
################## | C:\WINDOWS\system32\drivers |
################## | C:\Documents and Settings\Massimo\Dati applicazioni |
################## | Other deleting ... |
################## | Temporary Internet Files |
################## | Registry / Infected keys |
Deleted ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_111111s1ro1s1a]
Deleted ! [HKCU\Software\MuleAppData]
Deleted ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
Deleted ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
Deleted ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
Deleted ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
Deleted ! [HKLM\software\microsoft\security center] "FirewallOverride"
Deleted ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"
Deleted ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
################## | State / Service / Information |
# Safe boot mode : OK
# Showing of hidden files : OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# (!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )
################## | PEH ... |
Corrupted : C:\Documents and Settings\Massimo\Documenti\avenger\avenger.exe
[Offset = 00000084 - Value = 0x0001]
Corrupted : C:\Programmi\Netlog Music Tool\Uninstaller.exe
[Offset = 000000FC - Value = 0x0001]
Corrupted : C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
[Offset = 000000C4 - Value = 0x0001]
Corrupted : C:\WINDOWS\SoftwareDistribution\Download\a46c5627aadf6da0508c6a0af418b47a\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
################## | Cracks / Keygens / Serials |
"C:\Documents and Settings\Massimo\Desktop\Incoming\BitTorrent\GIOCHI FINITI\Bannershop GIF Animator 5.1.2.0\Keygen\BannerShopGIFAnimatorKeygen.exe"
23/11/2009 21.21 |Size 157696 |Crc32 1c3b2bc6 |Md5 188f8ea345254698e7c321621972b879
"C:\Documents and Settings\Massimo\Desktop\Incoming\BitTorrent\GIOCHI FINITI\Incomedia.WebSite.X5.v8.0.0.11.Multilingual.Incl.Keymaker-CORE [iMMUNE]\Incomedia.WebSite.X5.v8.0.0.11.Multilingual.Incl\keygen.exe"
13/09/2009 16.12 |Size 115712 |Crc32 e6e27cb1 |Md5 2636801a85d56cf5c8ed6d3d08827571
"C:\Documents and Settings\Massimo\Desktop\Incoming\BitTorrent\GIOCHI FINITI\PROGRAMMI X CHIARA\Nuova cartella\RegCure 1.5.0.0 + Crack\RegCure 1.5.0.0 + Crack\CRACK\RegCure.exe"
02/08/2007 08.20 |Size 11511104 |Crc32 846ef081 |Md5 a65e2440b06a8805ea2bfd9a215cbe45
"C:\Documents and Settings\Massimo\Desktop\Incoming\BitTorrent\GIOCHI FINITI\PROGRAMMI X CHIARA\WinRar 3.90 ITA + CRACK\WRar390it.exe"
07/10/2009 05.53 |Size 1446446 |Crc32 cc14fdbd |Md5 1b7d23b650bbbf68f09fb208a8620790
"C:\Documents and Settings\Massimo\Desktop\Incoming\BitTorrent\GIOCHI FINITI\[PC ~ Multi5] Borderlands\Crack\Borderlands.exe"
02/11/2009 06.55 |Size 29255315 |Crc32 2e4299fe |Md5 b86557202e28d7cf63134af663ba2095
"C:\Documents and Settings\Massimo\Desktop\Incoming\MODIFICARE film con 2 AUDIO\Virtualdub Italiano\Virtualdub Italiano\Virtualdub Italiano\Varie\[CODEC] DivX.Pro.5.0.5.+.Keygen.By.HoddiX\DivXPro505Bundle.exe"
28/04/2003 01.36 |Size 4050944 |Crc32 f75bf56e |Md5 6adbd7c2ef9ca84befdfb9dd4ea8c275
"C:\Documents and Settings\Massimo\Desktop\Incoming\MODIFICARE film con 2 AUDIO\Virtualdub Italiano\Virtualdub Italiano\Virtualdub Italiano\[CODEC] DivX.Pro.5.0.5.+.Keygen.By.HoddiX\DivXPro505Bundle.exe"
28/04/2003 01.36 |Size 4050944 |Crc32 f75bf56e |Md5 6adbd7c2ef9ca84befdfb9dd4ea8c275
################## | End of Report # FindyKill V5.020 ! |