r16 ha scritto:Ciao lauraz
No,non credo che hai il Blaster,avresti il log devastato (oltre il pc).
Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti.
Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exeSalvalo sul
desktop.
Doppio click su combofix.exe (comparirà una videata.)
Digita
1, premi
Invio e segui le indicazioni.
Al termine, verrà creato un file log chiamato C:\ComboFix.txt.
Postalo qui.
Durante l'operazione di scansione è importante non usare il PC e attendere pazientemente la fine delle operazioni.
Posta un nuovo log di HijackThis .
Sempre qui.
ComboFix non funziona in modalità provvisoria Ecco il file log di Combofix ( cavolo mi ha eliminato un sacco di cose!!!!!) :
ComboFix 08-06-16.5 - Massimo 2008-06-18 22.27.29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.1553 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Massimo\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Massimo\Dati applicazioni\addon.dat
C:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\aauoid_nav.dat
C:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\aauoid_navps.dat
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\Log\2007 Nov 08 - 11_22_59 PM_843.log
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\Log\2007 Nov 08 - 11_23_04 PM_515.log
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\rs.dat
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\Settings\CustomScan.stg
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\Settings\IgnoreList.stg
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\Settings\ScanInfo.stg
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\Settings\ScanResults.stg
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\Settings\SelectedFolders.stg
C:\Documents and Settings\Utente\Dati applicazioni\AntiSpywareBot\Settings\Settings.stg
C:\Documents and Settings\Utente\Dati applicazioni\m
C:\Documents and Settings\Utente\Dati applicazioni\m\list.oct
C:\Documents and Settings\Utente\Dati applicazioni\m\shared
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\3D Galaxy
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Acceleration Pack 2.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Adwords & Keywords 2.00 [Cracked].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Aimg2PDF 1.1 [Patch].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Air Warrior III v3.10 patch.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\All Image 1.3.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Allok MP3 WAV Converter 1.1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Altdo Convert MP3 Master 2.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Anetto Password Saver 3.1 [KeyGen].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\AprCalc 4.0 Serial.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\ASP Express Standard 4.1.5 Key+Serial.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\AVI Splitter 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\AVS DV to DVD 1.2.1.97 Serial.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\BasinFlow May 2005.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Battlefield 1942 Night of Nights map 2.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\BeamYourScreen 2.0.7.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\BitHack 0.95 Alpha.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\CHAOS Generator 2.4.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Chilibase for Outlook 1.5.4.138.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Coalesys HTTP Client 1.0.93.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Cool EasyCard For Valentine's day 2.55 Patch.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\CrazyWarp 2.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\DactyloMagic Pro 2007 9.0.0 (With Crack).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\DailyPim 4.06 Patch.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Data Scripter 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\DBSmart 1.6.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Dicom 4.0.74.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Direct MP3 Recorder 1.0 [Patch].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Diskeeper Server Standard Edition 11.0.703t Serial.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Diskimager 1.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\DiskLister 5.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Do Not Call List Solution Safe Caller 1.3 Key+Serial.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\DocClear Pro 3.1.0.0 Crack.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Easy HR Caps Lock 1.28.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\EZ Backup IE and Outlook Express Basic 4.7 (Cracked).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Fantastic Flame Screensaver 5.15.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\FantasyTV Player Professional 2.70.2.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Flawless Complexion 5.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Funny Faces ScreenSaver 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\GetPDF Form Filler 2.00 Key.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\GetRight Pro 6c.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Global Surfari Notifier 1.0.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Globex Pro 3.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\GP 500 demo.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Hangman 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Happy Aqua-R Ticker Menu 1.30.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Hide Folder Now 3.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Hitman Codename 47 Patch (UK).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Homemade Lip Gloss 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Hot Jingle Player 1.0 (Patch).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\InspireModels.com Wallpaper Set 2 2.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Instant Messenger Dating 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\IP-Checker 1.21.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\IP2Location IP-COUNTRY-REGION-CITY Database May 2007.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\iZotope Vinyl for Winamp 2 1.0 (Patch).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\JustCursors 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\KABcam 3.0.4.2.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Kaspersky.Antivirus.Personal.v6.0.1.411.Final.con.keyfiles.incluidos.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Kate Moss Sex-E Screensaver 3.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Linear Barcode Console 1.3 [Key+Serial].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\LingoWare Portuguese (Brazilian).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Lost Widget 2.2.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\MacBonferroni 1.00.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\MailOMatic 1.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Max Payne 2 The Fall of Max Payne Deep Blue mod 3.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Microsoft Virtual Server 2005 Enterprise R2 SP1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\MirrorJNDI 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\MonitorTest 2.2.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\MoodLogic 2.71.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Mp3 Recording Applet SDK 1.2.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\MsgAgent 0.37b.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\MusicWonk 3.2 [Cracked].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\MySpeed Server Professional 7.2a.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\myTasks 1.5.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\News Central Lite 1.0.17976.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\NiceClock 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Nod32_2.51.12_XP-2k3-x64_SLO.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\On-Screen Keyboard Magic 1.0.0.27 (Patch).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\ParsCafe Radio 1.0.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Photoshop Updater 7.0.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Picture of the Day 1.3.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\PostgreSQL Import Multiple Text Files Software 7.0 [KeyGen].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Power Launch 2 2.00 [Patch].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Pumpkin Jack Screensaver 3.11.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Quantrix WinTool 1.11.0114.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Quark ALAP ShadowCaster 3.2.3 [Key].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\QuickSync 3.0FC2.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Rain Cast 2.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Recite French Words 3.1 (Key+Serial).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\RememberNotes 1.03.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Robin Hood The Legend of Sherwood patch 1.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\RSI Reminder 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\RSS To Speech 1.1 (Key).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Sophie's Cards for Windows 5.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\SOS Banner 1.1 (Key+Serial).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Sothink DVD Ripper 1.3 Build 70119 With Crack.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\SourceMonitor 2.3.6.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\SpywareStriker 9.3.0.10 [Patch].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\SQL Help Builder 2.03 [Cracked].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\StyleName Widget 1.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\StylePad 1.4.2.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Super MP3 Recorder 3.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Superbowl XLI Countdown 1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\SuperPower 1.30 to 1.40 patch.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\SVGDeveloper 1.0.5.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Tab Transcriber 3.05.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\TExcelDSNCreator 1.002 (Cracked).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Timer Cafe Lan House Manager 3.9.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\TrayList 2006.04.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Trooper 2.04.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Unreal Tournament 2004 DOM Mayan Ruins Map.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\VirtualCamera 0.8.5 build 1125.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Water Illusion Screensaver 3.60.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\WAV MP3 Converter 1.30.2 [Key+Serial].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Web ImageGrabber 2.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\WebcastMaker 1.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Word2html Pro 1.7 [With Crack].zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\WorkManager 2.0.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\WorldTime 1.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\Xlight FTP Server 2.24.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\XMPlay 3.4.2.1.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\XT Typing Tutor 1.0.2 With Crack.zip
C:\Documents and Settings\Utente\Dati applicazioni\m\shared\ZipZag 1.80 (KeyGen).zip
C:\Documents and Settings\Utente\Dati applicazioni\m\srvlist.oct
C:\WINDOWS\explorer.exe.tmp
C:\WINDOWS\system32\drivers\retx2.sys
C:\WINDOWS\system32\fnhoje
C:\WINDOWS\system32\Oleopri20051.dll
C:\WINDOWS\system32\sysmwwod.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3550P
-------\Legacy_RUNTIME
-------\Service_asc3550p
-------\Service_fnhoje
-------\Service_retx2
((((((((((((((((((((((((( Files Creati Da 2008-05-18 al 2008-06-18 )))))))))))))))))))))))))))))))))))
.
2008-06-18 16:51 . 2008-06-18 16:52 <DIR> d-------- C:\Programmi\Netlog Video Tool
2008-06-17 15:42 . 2008-06-17 15:42 <DIR> d-------- C:\Programmi\City Interactive
2008-06-17 15:33 . 2008-06-17 15:33 <DIR> d-------- C:\Converted Videos
2008-06-17 15:33 . 2005-08-27 03:38 1,435,272 --a------ C:\WINDOWS\system32\Flash.ocx
2008-06-15 22:21 . 2008-06-15 22:23 <DIR> d-------- C:\WINDOWS\system32\oodag
2008-06-15 22:21 . 2008-06-15 22:21 0 --a------ C:\WINDOWS\oodcnt.INI
2008-06-15 16:02 . 2008-06-15 16:02 <DIR> d-------- C:\Programmi\Microsoft Games
2008-06-14 17:37 . 2008-06-14 17:37 <DIR> d-------- C:\Programmi\Netlog
2008-06-09 21:23 . 2008-06-09 21:23 <DIR> d-------- C:\WINDOWS\speech
2008-06-09 21:23 . 2008-06-15 15:21 <DIR> d-------- C:\Programmi\Acclaim Entertainment
2008-06-09 13:55 . 2008-06-09 13:56 <DIR> d-------- C:\Programmi\Spamihilator
2008-06-08 14:52 . 2008-06-08 14:52 <DIR> d-------- C:\Documents and Settings\Massimo\Dati applicazioni\Motive
2008-06-08 14:50 . 2008-06-08 15:55 <DIR> d-------- C:\WINDOWS\Motive
2008-06-08 14:50 . 2008-06-08 14:50 <DIR> d-------- C:\Programmi\File comuni\Motive
2008-06-08 14:50 . 2008-06-08 14:50 <DIR> d-------- C:\Programmi\Common Files
2008-06-08 14:42 . 2008-06-08 15:56 <DIR> d-------- C:\Programmi\Alice ti aiuta
2008-05-30 22:06 . 2008-05-30 22:06 <DIR> d-------- C:\WINDOWS\system32\Epson
2008-05-26 18:52 . 2008-05-26 18:52 <DIR> d-------- C:\Programmi\JoWood
2008-05-26 18:06 . 2008-05-26 18:06 <DIR> d-------- C:\Programmi\Flagship Studios
2008-05-18 11:28 . 2008-05-18 11:28 <DIR> d-------- C:\Documents and Settings\Massimo\Dati applicazioni\PlayFirst
2008-05-18 11:28 . 2008-05-18 11:28 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dati applicazioni\PlayFirst
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-18 20:26 --------- d-----w C:\Documents and Settings\Massimo\Dati applicazioni\Spamihilator
2008-06-18 17:57 --------- d-----w C:\Programmi\eMule
2008-06-18 07:24 --------- d-----w C:\Documents and Settings\Massimo\Dati applicazioni\AVG7
2008-06-15 20:16 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dati applicazioni\Spybot - Search & Destroy
2008-06-15 18:00 --------- d-----w C:\Documents and Settings\Massimo\Dati applicazioni\Microsoft Games
2008-06-15 14:32 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-06-15 13:02 --------- d-----w C:\Programmi\Eidos
2008-06-08 12:50 --------- d-----w C:\Programmi\Telecom Italia
2008-05-31 06:24 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dati applicazioni\UDL
2008-05-31 06:22 --------- d-----w C:\Programmi\epson
2008-05-28 20:05 --------- d-----w C:\Programmi\SpeedFan
2008-05-26 16:28 --------- d-----w C:\Programmi\Ubisoft
2008-05-19 19:47 --------- d-----w C:\Programmi\MagicISO
2008-05-18 09:09 --------- d-----w C:\Programmi\Electronic Arts
2008-05-18 08:37 --------- d-----w C:\Programmi\File comuni\Wise Installation Wizard
2008-05-18 08:25 --------- d-----w C:\Programmi\Google
2008-05-17 07:48 --------- d-----w C:\Programmi\GameShadow
2008-05-12 16:01 --------- d-----w C:\Programmi\Ludonic
2008-05-11 21:33 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dati applicazioni\DVD Shrink
2008-05-09 19:08 --------- d-----w C:\Documents and Settings\Massimo\Dati applicazioni\DeepBurner
2008-05-09 19:03 --------- d-----w C:\Programmi\SlySoft
2008-05-02 06:45 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dati applicazioni\avg7
2008-05-01 15:35 --------- d-----w C:\Documents and Settings\LocalService.NT AUTHORITY\Dati applicazioni\AVG7
2008-05-01 15:35 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dati applicazioni\Grisoft
2008-04-25 12:02 --------- d-----w C:\Programmi\THQ
2008-04-19 19:40 --------- d-----w C:\Programmi\Wanadoo Edition
2008-04-19 18:00 --------- d-----w C:\Documents and Settings\Massimo\Dati applicazioni\Ubisoft
2008-04-19 18:00 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dati applicazioni\Ubisoft
2008-04-19 16:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dati applicazioni\WLInstaller
2008-03-24 13:11 215,144 ----a-w C:\WINDOWS\patchw32.dll
2008-02-04 20:52 176 ----a-w C:\Documents and Settings\Massimo\preved.bat
2008-02-01 22:16 1 ----a-w C:\Documents and Settings\Massimo\SI.bin
2007-12-23 15:53 22,328 ----a-w C:\Documents and Settings\Massimo\Dati applicazioni\PnkBstrK.sys
2007-08-10 21:09 14 ----a-w C:\Documents and Settings\Utente\getfile.dat
2007-07-19 19:50 87,608 ----a-w C:\Documents and Settings\Utente\Dati applicazioni\ezpinst.exe
2007-07-19 19:50 47,360 ----a-w C:\Documents and Settings\Utente\Dati applicazioni\pcouffin.sys
2007-01-03 19:37 1 ----a-w C:\Documents and Settings\Utente\SI.bin
2006-07-18 13:41 1,019,094 --sha-r C:\Programmi\serial.tde
2006-05-28 16:46 397,306 --sha-r C:\Programmi\wunauclt.zip
2006-05-28 16:46 397,306 --sha-r C:\Programmi\wunauclt.tbe
2006-05-28 13:45 115,459 --sha-r C:\Programmi\andame.zip
2006-05-28 13:45 115,459 --sha-r C:\Programmi\andame.tde
2008-01-30 20:56 0 --sha-w C:\WINDOWS\crack\klog.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"ISUSPM"="C:\Programmi\File comuni\InstallShield\UpdateService\isuspm.exe" [2006-09-10 23:56 218032]
"NBJ"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Programmi\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 17:59 143360]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"Gainward"="C:\Programmi\Vtune\TBPanel.exe" [2006-09-13 11:16 2154496]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 15:43 7630848]
"nwiz"="nwiz.exe" [2006-08-11 15:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 13:01 151552 C:\WINDOWS\system32\stmctrl.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 08:54 16248320 C:\WINDOWS\RTHDCPL.EXE]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 15:43 86016]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 17:40 155648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-05-02 08:48 579584]
"Spamihilator"="C:\Programmi\Spamihilator\spamihilator.exe" [2008-01-06 13:20 1003520]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-05-01 17:35 219136]
C:\Documents and Settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Reader Synchronizer.lnk - C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 01:01:50 734872]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 02:48:20 40048]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Yie85.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Programmi\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Programmi\\Internet Explorer\\IEXPLORE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\Spamihilator\\dccproc.exe"=
"C:\\Programmi\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"C:\\Programmi\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"C:\\Programmi\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Programmi\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"C:\\Programmi\\Microsoft Games\\Gears of War\\Binaries\\WarGame-G4WLive.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3263:TCP"= 3263:TCP:@xpsp2res.dll,-22005
"4042:TCP"= 4042:TCP:@xpsp2res.dll,-22005
"11801:TCP"= 11801:TCP:@xpsp2res.dll,-22005
"23476:TCP"= 23476:TCP:@xpsp2res.dll,-22005
R2 Network WanMiniport First Position;Network WanMiniport First Position;C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe [2003-04-18 18:06]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2002-09-25 08:37]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;C:\WINDOWS\system32\DRIVERS\torususb.sys [2003-01-09 16:21]
S1 fak32;fak32;C:\WINDOWS\system32\drivers\fak32.sys []
S1 retx2;retx2;C:\WINDOWS\system32\drivers\retx2.sys []
S2 BackWeb Client - 7681197;F-Secure BackWeb;C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 18:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 18:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 18:59]
S4 fnhoje;fnhoje;C:\WINDOWS\system32\fnhoje []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a50d4ab7-ae10-11dc-b53e-00138fd227ed}]
\Shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C5CD9787-54F4-6B5A-7054-5E50F28A8F48}]
C:\WINDOWS\crack\crack.exe s
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-18 22:31:53
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\btstack]
"ImagePath"="\??\C:\WINDOWS\system32\btstack.ibs"
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\ellowtab]
"ImagePath"="\??\C:\WINDOWS\system32\ellowtab.txt"
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\fnhoje]
"ImagePath"="\??\C:\WINDOWS\system32\fnhoje"
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Programmi\Intel\Intel Matrix Storage Manager\IAANTmon.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Ora fine scansione: 2008-06-18 22:36:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-18 20:36:32
22 Directory 134,881,267,712 byte disponibili
26 Directory 135,693,189,120 byte disponibili
337 --- E O F --- 2008-02-13 12:14:35
Ecco il Log di HijackThis :
Logfile of HijackThis v1.99.1
Scan saved at 22.41.40, on 18/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Programmi\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Programmi\Vtune\TBPanel.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmi\Spamihilator\spamihilator.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Programmi\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Gainward] C:\Programmi\Vtune\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Spamihilator] "C:\Programmi\Spamihilator\spamihilator.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Programmi\File comuni\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cabO16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://static.slide.com/uploader/SlideImageUploader.cabO16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) -
http://esupport.epson-europe.com/selftest/it/Prg/ESTPTest.cabO16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) -
http://chiaraesara.spaces.live.com/PhotoUpload/MsnPUpld.cabO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{45E7E1DC-2B16-4346-B3FA-A523E10025BA}: NameServer = 85.37.17.41 85.38.28.83
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programmi\Windows Live\Mail\mailcomm.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE (file missing)
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programmi\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: Network WanMiniport First Position - Unknown owner - C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe