Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

virus nn rimovibile Opzioni
vinz73
Inviato: Wednesday, March 25, 2009 7:07:03 PM
Rank: Member

Iscritto dal : 3/25/2009
Posts: 12
ciao a tutti ho un problema con un virus,in pratica l'anitvirus Avast mi segnala l'installazione di Win32:Confi [Wrm] e Win32: Rootkit-gen [Rtk] nelle cartelle NetworkService.NT AUTHORITY.005 e in System32, io li cerco manualmente rimuovo il file virus ma ogni volta che mi ricollego ad internet il problema si ripresenta, premetto che della materia nn ne capisco molto,x cui volevo chiedere a voi cosa mi consigliate di fare o quale programma mi suggerite di installare per poter rimuovere questo virus, premettendo che ho Windows XP sp2, Avast come antivirus e PC Tools Firewall Plus come firewall, spero di ricevere un vostro aiuto e intanto rigranzio in anticipo tutti coloro che mi aiuteranno.
Sponsor
Inviato: Wednesday, March 25, 2009 7:07:03 PM

 
steven75
Inviato: Wednesday, March 25, 2009 7:36:56 PM
Rank: Member

Iscritto dal : 5/8/2006
Posts: 0
ciao,

fai girare combofix come spiegato qui e posta il suo log
vinz73
Inviato: Thursday, March 26, 2009 4:55:54 PM
Rank: Member

Iscritto dal : 3/25/2009
Posts: 12
ciao Steven questo è il log di combofix:

ComboFix 09-03-25.03 - vincenzo 2009-03-26 16:16:36.2 - NTFSx86
Eseguito da: c:\documents and settings\vincenzo.VINCE.000\Documenti\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090325-0] *On-access scanning disabled* (Updated)
FW: PC Tools Firewall Plus *disabled*
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NETTHROTTLE
-------\Legacy_PRTSCH
-------\Service_NetThrottle
-------\Service_prtsch


((((((((((((((((((((((((( Files Creati Da 2009-02-26 al 2009-03-26 )))))))))))))))))))))))))))))))))))
.

2009-03-25 17:58 . 2009-03-25 17:58 <DIR> d-------- c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\skypePM
2009-03-25 17:58 . 2009-03-25 17:58 56 --ah----- c:\windows\system32\ezsidmv.dat
2009-03-25 17:53 . 2009-03-25 17:55 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Skype
2009-03-18 18:50 . 2009-03-18 19:47 <DIR> d-------- c:\programmi\PhotoScape
2009-03-02 18:54 . 2009-03-02 18:54 <DIR> d-------- c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\WirePilot

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-26 15:12 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\HPAppData
2009-03-26 14:52 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2009-03-25 18:13 28,396 ----a-w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\wklnhst.dat
2009-03-25 17:30 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\Skype
2009-03-25 16:55 --------- d-----w c:\programmi\File comuni\Skype
2009-03-25 16:55 --------- d-----r c:\programmi\Skype
2009-03-25 00:59 --------- d-----w c:\programmi\PC Tools Firewall Plus
2009-03-25 00:51 95,640 ----a-w c:\windows\system32\drivers\pctplfw.sys
2009-03-25 00:51 73,840 ----a-w c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-25 00:51 130,424 ----a-w c:\windows\system32\drivers\PCTCore.sys
2009-03-11 01:27 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\SiteAdvisor
2009-03-07 01:18 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\LimeWire
2009-03-07 00:09 --------- d-----w c:\programmi\LimeWire
2009-02-15 19:25 --------- d-----w c:\programmi\MP3Gain
2009-02-14 16:57 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\gtk-2.0
2009-02-14 01:24 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\HP
2009-02-14 01:24 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\HP
2009-02-14 01:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\WEBREG
2009-02-14 00:18 --------- d-----w c:\programmi\HP
2009-02-14 00:18 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\HP Product Assistant
2009-02-14 00:15 --------- d-----w c:\programmi\Hewlett-Packard
2009-02-14 00:15 --------- d-----w c:\programmi\File comuni\HP
2009-02-14 00:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Hewlett-Packard
2009-02-13 23:50 --------- d-----w c:\programmi\HP Wireless Printer Adapter
2009-02-13 23:47 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-13 23:47 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\InstallShield
2009-02-13 23:42 --------- d-----w c:\programmi\HP Wireless Adapter
2009-02-09 11:20 --------- d-----w c:\programmi\Safari
2009-01-31 16:20 --------- d-----w c:\programmi\File comuni\PC Tools
2009-01-25 16:25 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-03-16 15:59 56,328 ----a-w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\GDIPFONTCACHEV1.DAT
2007-09-03 21:07 92,064 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmmdm.sys
2007-09-03 21:07 9,232 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmmdfl.sys
2007-09-03 21:07 79,328 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmserd.sys
2007-09-03 21:07 66,656 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmbus.sys
2007-09-03 21:07 6,208 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmcmnt.sys
2007-09-03 21:07 5,936 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmwhnt.sys
2007-09-03 21:07 4,048 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmcr.sys
2007-09-03 21:07 25,600 ----a-w c:\documents and settings\vincenzo.VINCE.000\usbsermptxp.sys
2007-09-03 21:07 22,768 ----a-w c:\documents and settings\vincenzo.VINCE.000\usbsermpt.sys
2007-01-03 15:49 635 ----a-w c:\programmi\File comuni\Cartelle condivise.lnk
2006-01-05 01:12 532,480 ----a-w c:\programmi\cwshredder.exe
2007-04-16 15:54 167,765 --sha-r c:\windows\system32\roekw.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-r 159,744 2003-10-08 03:40:00 c:\programmi\Apoint2K\bak\Apoint.exe
----a-r 159,744 2003-10-08 03:40:00 c:\programmi\Apoint2K\Apoint.exe

----a-w 335,872 2003-09-11 20:10:00 c:\programmi\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
----a-w 335,872 2003-09-11 19:10:00 c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe

----a-w 50,688 2003-06-10 16:48:58 c:\programmi\File comuni\Microsoft Shared\Works Shared\bak\WkUFind.exe
----a-w 50,688 2003-06-10 16:48:58 c:\programmi\File comuni\Microsoft Shared\Works Shared\WkUFind.exe

----a-w 65,536 2003-05-01 17:44:50 c:\programmi\File comuni\Roxio Shared\System\bak\EngUtil.exe
----a-w 65,536 2003-05-01 16:44:50 c:\programmi\File comuni\Roxio Shared\System\EngUtil.exe

----a-w 237,568 2003-09-26 08:04:16 c:\programmi\HPQ\Quick Launch Buttons\bak\EabServr.exe
----a-w 237,568 2003-09-26 07:04:16 c:\programmi\HPQ\Quick Launch Buttons\eabservr.exe

----a-w 75,520 2006-12-15 02:23:27 c:\programmi\Java\jre1.5.0_11\bin\bak\jusched.exe

------w 0 1601-01-01 00:00:00 c:\programmi\Spyware Terminator\bak\

.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"Windowe LoL Layera"="pqepwxl.exe" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programmi\Apoint2K\Apoint.exe" [2003-10-08 159744]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="c:\programmi\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"RoxioEngineUtility"="c:\programmi\File comuni\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"RoxioDragToDisc"="c:\programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-07-18 868352]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-25 136600]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2009-03-25 2652056]
"avast!"="c:\programmi\Alwil Software\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"HPWireless"="c:\programmi\HP Wireless Adapter\HPWLAN.exe" [2006-10-04 618496]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\programmi\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 c:\windows\AGRSMMSG.exe]
"ATIModeChange"="Ati2mdxx.exe" [2003-10-08 c:\windows\system32\Ati2mdxx.exe]
"Windowe LoL Layera"="pqepwxl.exe" [N/A]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
"Windowe LoL Layera"="pqepwxl.exe" [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2882:TCP"= 2882:TCP:WWW

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-23 114768]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-01-31 159600]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-11-23 20560]
R2 HPEAPPkt;Realtek EAPPkt Protocol(HP);c:\windows\system32\drivers\HPEAPPkt.sys [2009-02-14 68864]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-01-31 73840]
R3 hpnuhst;HP NUSB Host;c:\windows\system32\drivers\hpnuhst.sys [2009-02-14 12032]
R3 HPNUHUB;HP NUSB Hub;c:\windows\system32\drivers\hpnuhub.sys [2009-02-14 39424]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-01-31 95640]
S2 zszrn;Image Security;c:\windows\system32\svchost.exe -k netsvcs [2004-05-29 14336]
S3 HPNUCMP;HP NUSB Composite;c:\windows\system32\drivers\hpnucmp.sys [2009-02-14 11648]
S3 ltwir;ltwir;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\System32\2.tmp --> c:\windows\System32\2.tmp [?]
S3 midasfr;midasfr;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
S3 RTLWUSB;Wireless Adapter;c:\windows\system32\drivers\hpl8187.sys [2009-02-14 189440]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2009-02-14 13532]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
aedturc
kkcxh
pordhuinf
zszrn
wvnwzv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aecd59d6-baf0-11dd-9629-00023f6d9a44}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

Notify-WgaLogon - (no file)


.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://it.rd.yahoo.com/customize/ycomp/defaults/su/*http://it.yahoo.com
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-26 16:24:18
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\HPQ\Default Settings\cpqset.exe????????????7?0?7?5??????? ?deB???????????????B????????

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ltwir]
"ImagePath"="\??\c:\windows\system32\01.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\System32\2.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\midasfr]
"ImagePath"="\??\c:\windows\system32\02.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv]
"ServiceDll"="c:\windows\system32\roekw.dll"
--

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zszrn]
"ServiceDll"="c:\windows\system32\roekw.dll"
.
Ora fine scansione: 2009-03-26 16:32:56
ComboFix-quarantined-files.txt 2009-03-26 15:32:42

Pre-Run: 27,836,616,704 byte disponibili
Post-Run: 27,827,015,680 byte disponibili

198
steven75
Inviato: Thursday, March 26, 2009 5:25:58 PM
Rank: Member

Iscritto dal : 5/8/2006
Posts: 0
cominciamo cosi;

apri una pagina del bloc notes e copia incolla quanto segue:

Commenta:
killall
file::
c:\windows\system32\ezsidmv.dat
c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\wklnhst.dat
c:\windows\system32\roekw.dll
c:\windows\system32\01.tmp
c:\windows\system32\02.tmp
c:\windows\system32\drivers\SjyPkt.sys
c:\windows\System32\2.tmp

registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ltwir]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\midasfr]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zszrn]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pqepwxl.exe"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"pqepwxl.exe"=-


salva la pagina nominandola obligatoriamente in CFScript.txt
a questo punto trascina il file CFScript.txt sull'icona di combofix e lascialo lavorare fino alla fine...

Poi portati nel registro di sistema (start / esegui / regedit)
Mediante le crocette + portati in questa chiave:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
Seleziona la chiave in grassetto e nella parte destra individua il valore NetSvcs
Cliccaci sopra due volte, e nella lista , cancella questi valori
-aedturc
-kkcxh
-pordhuinf
-zszrn
-wvnwzv
(solo questi mi raccomando)

Adesso scarica Avenger
http://swandog46.geekstogo.com/avenger2/download.php
Avvia con un doppio click il file "Avenger.exe"
Nella finestra "Input Script Here" incolla quanto segue:

Commenta:
files to move:
c:\programmi\Apoint2K\bak\Apoint.exe | c:\programmi\Apoint2K\Apoint.exe
c:\programmi\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe | c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\programmi\File comuni\Microsoft Shared\Works Shared\bak\WkUFind.exe | c:\programmi\File comuni\Microsoft Shared\Works Shared\WkUFind.exe
c:\programmi\File comuni\Roxio Shared\System\bak\EngUtil.exe | c:\programmi\File comuni\Roxio Shared\System\EngUtil.exe
c:\programmi\HPQ\Quick Launch Buttons\bak\EabServr.exe | c:\programmi\HPQ\Quick Launch Buttons\eabservr.exe


clicca sul tasto "Execute"
Rispondi Si all'avviso e il computer verrà riavviato
Al riavvio il tool rilascrà un log con i dettagli delle operazioni, che troverai anche in C:\ con il nome Avenger.txt
Postalo sul forum insieme ad un nuovo log combofix
vinz73
Inviato: Saturday, March 28, 2009 5:34:23 PM
Rank: Member

Iscritto dal : 3/25/2009
Posts: 12
ciao Steven ti posto i logs che mi avevi richiesto dopo aver fatto le operazioni da te descrittemi, questo è di Avenger:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File move operation "c:\programmi\Apoint2K\bak\Apoint.exe|c:\programmi\Apoint2K\Apoint.exe" completed successfully.
File move operation "c:\programmi\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe|c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" completed successfully.
File move operation "c:\programmi\File comuni\Microsoft Shared\Works Shared\bak\WkUFind.exe|c:\programmi\File comuni\Microsoft Shared\Works Shared\WkUFind.exe" completed successfully.
File move operation "c:\programmi\File comuni\Roxio Shared\System\bak\EngUtil.exe|c:\programmi\File comuni\Roxio Shared\System\EngUtil.exe" completed successfully.
File move operation "c:\programmi\HPQ\Quick Launch Buttons\bak\EabServr.exe|c:\programmi\HPQ\Quick Launch Buttons\eabservr.exe" completed successfully.

Completed script processing.

*******************

Finished! Terminate.



questo è di Combofix:

ComboFix 09-03-27.02 - vincenzo 2009-03-28 16:58:34.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.191.64 [GMT 1:00]
Eseguito da: c:\documents and settings\vincenzo.VINCE.000\Documenti\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090327-0] *On-access scanning enabled* (Updated)
FW: PC Tools Firewall Plus *disabled*
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_PCIDump


((((((((((((((((((((((((( Files Creati Da 2009-02-28 al 2009-03-28 )))))))))))))))))))))))))))))))))))
.

2009-03-25 17:58 . 2009-03-26 19:27 <DIR> d-------- c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\skypePM
2009-03-25 17:53 . 2009-03-25 17:55 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Skype
2009-03-18 18:50 . 2009-03-18 19:47 <DIR> d-------- c:\programmi\PhotoScape
2009-03-02 18:54 . 2009-03-02 18:54 <DIR> d-------- c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\WirePilot

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-28 15:42 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2009-03-27 03:01 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\HPAppData
2009-03-27 02:36 --------- d-----w c:\programmi\Apoint2K
2009-03-26 18:42 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\Skype
2009-03-25 16:55 --------- d-----w c:\programmi\File comuni\Skype
2009-03-25 16:55 --------- d-----r c:\programmi\Skype
2009-03-25 00:59 --------- d-----w c:\programmi\PC Tools Firewall Plus
2009-03-25 00:51 95,640 ----a-w c:\windows\system32\drivers\pctplfw.sys
2009-03-25 00:51 73,840 ----a-w c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-25 00:51 130,424 ----a-w c:\windows\system32\drivers\PCTCore.sys
2009-03-11 01:27 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\SiteAdvisor
2009-03-07 01:18 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\LimeWire
2009-03-07 00:09 --------- d-----w c:\programmi\LimeWire
2009-02-15 19:25 --------- d-----w c:\programmi\MP3Gain
2009-02-14 16:57 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\gtk-2.0
2009-02-14 01:24 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\HP
2009-02-14 01:24 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\HP
2009-02-14 01:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\WEBREG
2009-02-14 00:18 --------- d-----w c:\programmi\HP
2009-02-14 00:18 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\HP Product Assistant
2009-02-14 00:15 --------- d-----w c:\programmi\Hewlett-Packard
2009-02-14 00:15 --------- d-----w c:\programmi\File comuni\HP
2009-02-14 00:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Hewlett-Packard
2009-02-13 23:50 --------- d-----w c:\programmi\HP Wireless Printer Adapter
2009-02-13 23:47 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-13 23:47 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\InstallShield
2009-02-13 23:42 --------- d-----w c:\programmi\HP Wireless Adapter
2009-02-09 11:20 --------- d-----w c:\programmi\Safari
2009-01-31 16:20 --------- d-----w c:\programmi\File comuni\PC Tools
2009-01-25 16:25 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-03-16 15:59 56,328 ----a-w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\GDIPFONTCACHEV1.DAT
2007-09-03 21:07 92,064 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmmdm.sys
2007-09-03 21:07 9,232 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmmdfl.sys
2007-09-03 21:07 79,328 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmserd.sys
2007-09-03 21:07 66,656 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmbus.sys
2007-09-03 21:07 6,208 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmcmnt.sys
2007-09-03 21:07 5,936 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmwhnt.sys
2007-09-03 21:07 4,048 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmcr.sys
2007-09-03 21:07 25,600 ----a-w c:\documents and settings\vincenzo.VINCE.000\usbsermptxp.sys
2007-09-03 21:07 22,768 ----a-w c:\documents and settings\vincenzo.VINCE.000\usbsermpt.sys
2007-01-03 15:49 635 ----a-w c:\programmi\File comuni\Cartelle condivise.lnk
2006-01-05 01:12 532,480 ----a-w c:\programmi\cwshredder.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-03-28_16.52.52.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-28 15:41:28 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_7f4.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programmi\Apoint2K\Apoint.exe" [2003-10-08 159744]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="c:\programmi\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"RoxioEngineUtility"="c:\programmi\File comuni\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"RoxioDragToDisc"="c:\programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-07-18 868352]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-25 136600]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2009-03-25 2652056]
"avast!"="c:\programmi\Alwil Software\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"HPWireless"="c:\programmi\HP Wireless Adapter\HPWLAN.exe" [2006-10-04 618496]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\programmi\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 c:\windows\AGRSMMSG.exe]
"ATIModeChange"="Ati2mdxx.exe" [2003-10-08 c:\windows\system32\Ati2mdxx.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2882:TCP"= 2882:TCP:WWW

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-23 114768]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-01-31 159600]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-11-23 20560]
R2 HPEAPPkt;Realtek EAPPkt Protocol(HP);c:\windows\system32\drivers\HPEAPPkt.sys [2009-02-14 68864]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-01-31 73840]
R3 hpnuhst;HP NUSB Host;c:\windows\system32\drivers\hpnuhst.sys [2009-02-14 12032]
R3 HPNUHUB;HP NUSB Hub;c:\windows\system32\drivers\hpnuhub.sys [2009-02-14 39424]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-01-31 95640]
S3 HPNUCMP;HP NUSB Composite;c:\windows\system32\drivers\hpnucmp.sys [2009-02-14 11648]
S3 RTLWUSB;Wireless Adapter;c:\windows\system32\drivers\hpl8187.sys [2009-02-14 189440]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys --> c:\windows\System32\Drivers\SjyPkt.sys [?]

--- Altri Servizi/Drivers In Memoria ---

*Deregistered* - ALG
*Deregistered* - aswUpdSv
*Deregistered* - AudioSrv
*Deregistered* - avast! Antivirus
*Deregistered* - avast! Mail Scanner
*Deregistered* - avast! Web Scanner
*Deregistered* - Browser
*Deregistered* - btwdins
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - hpqcxs08
*Deregistered* - hpqddsvc
*Deregistered* - ImapiService
*Deregistered* - JavaQuickStarterService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MDM
*Deregistered* - Net Driver HPZ12
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - PCToolsFirewallPlus
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SoundMAX Agent Service (default)
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WMDM PMSP Service
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WudfSvc
*Deregistered* - WZCSVC

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aecd59d6-baf0-11dd-9629-00023f6d9a44}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-Windowe LoL Layera - pqepwxl.exe
HKLM-Run-Windowe LoL Layera - pqepwxl.exe
HKU-Default-Run-Windowe LoL Layera - pqepwxl.exe


.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://it.rd.yahoo.com/customize/ycomp/defaults/su/*http://it.yahoo.com
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-28 17:05:21
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\HPQ\Default Settings\cpqset.exe????????????7?0?7?5??????? ?deB???????????????B????????

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv]
"ServiceDll"="c:\windows\system32\roekw.dll"
--

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zszrn]
"ServiceDll"="c:\windows\system32\roekw.dll"
.
Ora fine scansione: 2009-03-28 17:13:07
ComboFix-quarantined-files.txt 2009-03-28 16:12:59

Pre-Run: 27,711,541,248 byte disponibili
Post-Run: 27,700,101,120 byte disponibili

224


maopapof
Inviato: Saturday, March 28, 2009 10:30:49 PM

Rank: AiutAmico

Iscritto dal : 10/31/2004
Posts: 7,185
..... se avete virus o presunti tali eliminateli in modalità provvisoria .... almeno provateci prima :O)

steven75
Inviato: Sunday, March 29, 2009 11:17:37 AM
Rank: Member

Iscritto dal : 5/8/2006
Posts: 0
ok vinz73,

ora fai cosi;

sempre con Avenger com hai fatto sopra, solo che questa volta in Input Script Here inserisci

Commenta:
files to delete:
c:\windows\System32\Drivers\SjyPkt.sys
c:\windows\system32\roekw.dll

Registry keys to delete:
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zszrn]

r16
Inviato: Sunday, March 29, 2009 12:33:52 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao steven
Scusa l'intromissione, ma vorrei chiederti una cosa.
Da un pò di tempo a questa parte, nei log di combofix compaiono queste deregistrazioni:

--- Altri Servizi/Drivers In Memoria ---

*Deregistered* - ALG
*Deregistered* - aswUpdSv
*Deregistered* - AudioSrv
*Deregistered* - avast! Antivirus
*Deregistered* - avast! Mail Scanner
*Deregistered* - avast! Web Scanner
*Deregistered* - Browser
*Deregistered* - btwdins
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc


Ne sai qualcosa al riguardo?
Non penso che funzioni quello script con Avenger.
Registry keys to delete:
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zszrn]
Scusa per il disturbo.
vinz73
Inviato: Sunday, March 29, 2009 6:49:48 PM
Rank: Member

Iscritto dal : 3/25/2009
Posts: 12
ciao Steven questi sono i log dopo aver fatto quanto da te suggerito:

Avenger:


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Mar 29 18:00:10 2009

17:59:50: Error: Invalid registry syntax in command:
"[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv]"
Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.
Skipping line. (Registry key deletion mode)
18:00:10: Error: Execution aborted by user!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Mar 29 18:01:09 2009

18:00:54: Error: Invalid registry syntax in command:
"[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv]"
Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.
Skipping line. (Registry key deletion mode)
18:00:56: Error: Invalid registry syntax in command:
"[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zszrn]"
Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.
Skipping line. (Registry key deletion mode)


//////////////////////////////////////////


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "c:\windows\System32\Drivers\SjyPkt.sys" not found!
Deletion of file "c:\windows\System32\Drivers\SjyPkt.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "c:\windows\system32\roekw.dll" not found!
Deletion of file "c:\windows\system32\roekw.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.


Combofix:


ComboFix 09-03-27.02 - vincenzo 2009-03-29 18.18.44.10 - NTFSx86
Eseguito da: c:\documents and settings\vincenzo.VINCE.000\Documenti\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090328-0] *On-access scanning disabled* (Updated)
FW: PC Tools Firewall Plus *disabled*
.

((((((((((((((((((((((((( Files Creati Da 2009-02-28 al 2009-03-29 )))))))))))))))))))))))))))))))))))
.

2009-03-29 15:32 . 2009-03-29 15:32 2,572 --a------ c:\windows\system32\PerfStringBackup.TMP
2009-03-25 18:58 . 2009-03-26 20:27 <DIR> d-------- c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\skypePM
2009-03-25 18:53 . 2009-03-25 18:55 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Skype
2009-03-18 19:50 . 2009-03-18 20:47 <DIR> d-------- c:\programmi\PhotoScape
2009-03-02 19:54 . 2009-03-02 19:54 <DIR> d-------- c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\WirePilot

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 16:07 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2009-03-29 14:14 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\HPAppData
2009-03-27 02:36 --------- d-----w c:\programmi\Apoint2K
2009-03-26 18:42 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\Skype
2009-03-25 16:55 --------- d-----w c:\programmi\File comuni\Skype
2009-03-25 16:55 --------- d-----r c:\programmi\Skype
2009-03-25 00:59 --------- d-----w c:\programmi\PC Tools Firewall Plus
2009-03-25 00:51 95,640 ----a-w c:\windows\system32\drivers\pctplfw.sys
2009-03-25 00:51 73,840 ----a-w c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-25 00:51 130,424 ----a-w c:\windows\system32\drivers\PCTCore.sys
2009-03-11 01:27 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\SiteAdvisor
2009-03-07 01:18 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\LimeWire
2009-03-07 00:09 --------- d-----w c:\programmi\LimeWire
2009-02-15 19:25 --------- d-----w c:\programmi\MP3Gain
2009-02-14 16:57 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\gtk-2.0
2009-02-14 01:24 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\HP
2009-02-14 01:24 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\HP
2009-02-14 01:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\WEBREG
2009-02-14 00:18 --------- d-----w c:\programmi\HP
2009-02-14 00:18 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\HP Product Assistant
2009-02-14 00:15 --------- d-----w c:\programmi\Hewlett-Packard
2009-02-14 00:15 --------- d-----w c:\programmi\File comuni\HP
2009-02-14 00:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Hewlett-Packard
2009-02-13 23:50 --------- d-----w c:\programmi\HP Wireless Printer Adapter
2009-02-13 23:47 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-13 23:47 --------- d-----w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\InstallShield
2009-02-13 23:42 --------- d-----w c:\programmi\HP Wireless Adapter
2009-02-09 11:20 --------- d-----w c:\programmi\Safari
2009-01-31 16:20 --------- d-----w c:\programmi\File comuni\PC Tools
2009-01-25 16:25 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-03-16 15:59 56,328 ----a-w c:\documents and settings\vincenzo.VINCE.000\Dati applicazioni\GDIPFONTCACHEV1.DAT
2007-09-03 21:07 92,064 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmmdm.sys
2007-09-03 21:07 9,232 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmmdfl.sys
2007-09-03 21:07 79,328 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmserd.sys
2007-09-03 21:07 66,656 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmbus.sys
2007-09-03 21:07 6,208 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmcmnt.sys
2007-09-03 21:07 5,936 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmwhnt.sys
2007-09-03 21:07 4,048 ----a-w c:\documents and settings\vincenzo.VINCE.000\mqdmcr.sys
2007-09-03 21:07 25,600 ----a-w c:\documents and settings\vincenzo.VINCE.000\usbsermptxp.sys
2007-09-03 21:07 22,768 ----a-w c:\documents and settings\vincenzo.VINCE.000\usbsermpt.sys
2007-01-03 15:49 635 ----a-w c:\programmi\File comuni\Cartelle condivise.lnk
2006-01-05 01:12 532,480 ----a-w c:\programmi\cwshredder.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-03-28_16.52.52.29 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2000-08-31 07:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 06:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2000-08-31 07:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 06:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2009-03-29 16:06:56 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_5c8.dat
+ 2009-03-29 16:06:06 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_63c.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programmi\Apoint2K\Apoint.exe" [2003-10-08 159744]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="c:\programmi\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"RoxioEngineUtility"="c:\programmi\File comuni\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"RoxioDragToDisc"="c:\programmi\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-07-18 868352]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-01-25 136600]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2009-03-25 2652056]
"avast!"="c:\programmi\Alwil Software\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"HPWireless"="c:\programmi\HP Wireless Adapter\HPWLAN.exe" [2006-10-04 618496]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\programmi\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 c:\windows\AGRSMMSG.exe]
"ATIModeChange"="Ati2mdxx.exe" [2003-10-08 c:\windows\system32\Ati2mdxx.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2882:TCP"= 2882:TCP:WWW

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-23 114768]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-01-31 159600]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-11-23 20560]
R2 HPEAPPkt;Realtek EAPPkt Protocol(HP);c:\windows\system32\drivers\HPEAPPkt.sys [2009-02-14 68864]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-01-31 73840]
R3 hpnuhst;HP NUSB Host;c:\windows\system32\drivers\hpnuhst.sys [2009-02-14 12032]
R3 HPNUHUB;HP NUSB Hub;c:\windows\system32\drivers\hpnuhub.sys [2009-02-14 39424]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-01-31 95640]
S3 HPNUCMP;HP NUSB Composite;c:\windows\system32\drivers\hpnucmp.sys [2009-02-14 11648]
S3 RTLWUSB;Wireless Adapter;c:\windows\system32\drivers\hpl8187.sys [2009-02-14 189440]

--- Altri Servizi/Drivers In Memoria ---

*Deregistered* - ALG
*Deregistered* - aswUpdSv
*Deregistered* - AudioSrv
*Deregistered* - avast! Antivirus
*Deregistered* - avast! Mail Scanner
*Deregistered* - avast! Web Scanner
*Deregistered* - Browser
*Deregistered* - btwdins
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - hpqcxs08
*Deregistered* - hpqddsvc
*Deregistered* - ImapiService
*Deregistered* - JavaQuickStarterService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MDM
*Deregistered* - Net Driver HPZ12
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - PCToolsFirewallPlus
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SoundMAX Agent Service (default)
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - UdfReadr_xp
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WMDM PMSP Service
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WudfPf
*Deregistered* - WudfSvc
*Deregistered* - WZCSVC

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aecd59d6-baf0-11dd-9629-00023f6d9a44}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://it.rd.yahoo.com/customize/ycomp/defaults/su/*http://it.yahoo.com
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 18:25:35
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\HPQ\Default Settings\cpqset.exe????????????7?0?7?5??P???? ?deB???????????????B????????

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv]
"ServiceDll"="c:\windows\system32\roekw.dll"
--

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zszrn]
"ServiceDll"="c:\windows\system32\roekw.dll"
.
Ora fine scansione: 2009-03-29 18.33.03
ComboFix-quarantined-files.txt 2009-03-29 16:32:48

Pre-Run: 27.689.336.832 byte disponibili
Post-Run: 27,678,359,552 byte disponibili

231




raresquare
Inviato: Sunday, March 29, 2009 8:53:04 PM

Rank: AiutAmico

Iscritto dal : 5/15/2001
Posts: 320
Scusa se m'intrometto, steven75, ma perchè non consigli, in casi come questi (un po' complicati), l'uso dei Rescue CD, che puliscono fuori-Windows? A leggere le recensioni, sarebbero molto efficaci e -- penso io, ma posso facilmente sbagliarmi -- anche più facili da usare per pulire a fondo il PC.
Lo chiedo per capire perchè il tuo metodo è migliore
(ho imparato qualcosa chiedendo, chiedendo, chiedendo).
vinz73
Inviato: Wednesday, April 01, 2009 7:10:28 PM
Rank: Member

Iscritto dal : 3/25/2009
Posts: 12
nessuno riesce più a darmi un consiglio su come risolvere il problema?
steven75
Inviato: Wednesday, April 01, 2009 7:16:07 PM
Rank: Member

Iscritto dal : 5/8/2006
Posts: 0
vinz73 ha scritto:
nessuno riesce più a darmi un consiglio su come risolvere il problema?


scusami ma sono molto preso dal lavoro e non ho molto tempo per i forum...

comunque sopra ho sbagliato lo script, in avenger devi inserire questo:

Commenta:
Registry keys to delete:
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wvnwzv
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zszrn


per il resto il log sembra pulito.... quali sono i problemi attuali?


@ raresquare: i live cd io li utilizzo solo quando il sistema non parte.... inoltre da livecd, molti malware , non essendo attivi, non vengono nemmeno scovati
vinz73
Inviato: Wednesday, April 01, 2009 7:27:22 PM
Rank: Member

Iscritto dal : 3/25/2009
Posts: 12
ciao Steven, nn preoccuparti, ti capisco bene....i problemi sono che avast continua a segnalarmi l'installazione dei file virus e poi mi succede che il pc si scollega da internet e nn riesco più a connetermi e per farlo devo riavviare il computer, cmq proverò a reinserire gli script in Avenger che mi hai postato, grazie.
steven75
Inviato: Wednesday, April 01, 2009 8:25:20 PM
Rank: Member

Iscritto dal : 5/8/2006
Posts: 0
disinstalla anche avast e installa antivir pe 9
http://dlce.antivir.com/package/wks_avira/win32/en/pecl/avira_antivir_personal_en.exe

aggiornalo e fai uno scan completo del sistema
posta il suo log

per la tua connesione , prova a far girare anche winsockxp Fix
http://www.steven.altervista.org/vecchio%20sito/files/utility.html

Per antivir se vuoi evitare le pub post aggiornamento, segui questi consigli
http://www.steven.altervista.org/files/antivir.html
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.