Inanzitutto grazie per l'attenzione shapiro. Ti posto come da te richiesto i log dei due programmi.
Come credevo malwarebytes mi ha confermato alcune file infetti come fopinope.dll. Ma come lui tanti altri....
Secondo te è il caso di fixare da hijackthis i file infetti che mi indica malwarebytes oppure operare in altro modo?
GRAZIE Matteo
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Mobile AMD Sempron(tm) Processor 3000+ )
BIOS : Ver 1.00PARTTBL
USER : Matteo ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 081210-0] 4.8.1296 (Activated)
Firewall : ZoneAlarm Pro Firewall 7.0.362.000 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:67 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( 10/12/2008|23.28 )
--------------------\\ Listing folders in DATIAP~1
[22/11/2008|14.57] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Adobe
[22/11/2008|15.15] C:\DOCUME~1\ALLUSE~1\DATIAP~1\InstallShield
[04/12/2008|19.13] C:\DOCUME~1\ALLUSE~1\DATIAP~1\Microsoft
[04/12/2008|19.00] C:\DOCUME~1\ALLUSE~1\DATIAP~1\WLInstaller
[0|File] C:\DOCUME~1\ALLUSE~1\DATIAP~1\byte
[6|Directory] C:\DOCUME~1\ALLUSE~1\DATIAP~1\byte disponibili
[21/11/2008|19.46] C:\DOCUME~1\DEFAUL~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\DEFAUL~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\DEFAUL~1\DATIAP~1\byte disponibili
[21/11/2008|19.46] C:\DOCUME~1\LOCALS~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\LOCALS~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\LOCALS~1\DATIAP~1\byte disponibili
[29/11/2008|14.38] C:\DOCUME~1\marco\DATIAP~1\Adobe
[28/11/2008|17.42] C:\DOCUME~1\marco\DATIAP~1\AdobeUM
[21/11/2008|19.55] C:\DOCUME~1\marco\DATIAP~1\Identities
[23/11/2008|11.04] C:\DOCUME~1\marco\DATIAP~1\InterVideo
[27/11/2008|16.34] C:\DOCUME~1\marco\DATIAP~1\Leadertech
[22/11/2008|15.27] C:\DOCUME~1\marco\DATIAP~1\Macromedia
[04/12/2008|19.15] C:\DOCUME~1\marco\DATIAP~1\Microsoft
[27/11/2008|16.34] C:\DOCUME~1\marco\DATIAP~1\Sonic
[04/12/2008|18.43] C:\DOCUME~1\marco\DATIAP~1\Sun
[0|File] C:\DOCUME~1\marco\DATIAP~1\byte
[11|Directory] C:\DOCUME~1\marco\DATIAP~1\byte disponibili
[29/11/2008|12.50] C:\DOCUME~1\marco_2\DATIAP~1\Adobe
[23/11/2008|17.36] C:\DOCUME~1\marco_2\DATIAP~1\Identities
[25/11/2008|16.23] C:\DOCUME~1\marco_2\DATIAP~1\InterVideo
[23/11/2008|17.38] C:\DOCUME~1\marco_2\DATIAP~1\Macromedia
[25/11/2008|16.23] C:\DOCUME~1\marco_2\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\marco_2\DATIAP~1\byte
[7|Directory] C:\DOCUME~1\marco_2\DATIAP~1\byte disponibili
[03/12/2008|12.16] C:\DOCUME~1\Matteo\DATIAP~1\Adobe
[03/12/2008|12.16] C:\DOCUME~1\Matteo\DATIAP~1\AdobeUM
[02/12/2008|10.57] C:\DOCUME~1\Matteo\DATIAP~1\Identities
[02/12/2008|11.04] C:\DOCUME~1\Matteo\DATIAP~1\Macromedia
[10/12/2008|16.50] C:\DOCUME~1\Matteo\DATIAP~1\Microsoft
[10/12/2008|16.24] C:\DOCUME~1\Matteo\DATIAP~1\Mozilla
[05/12/2008|10.42] C:\DOCUME~1\Matteo\DATIAP~1\Sun
[0|File] C:\DOCUME~1\Matteo\DATIAP~1\byte
[9|Directory] C:\DOCUME~1\Matteo\DATIAP~1\byte disponibili
[21/11/2008|19.46] C:\DOCUME~1\NETWOR~1\DATIAP~1\Microsoft
[0|File] C:\DOCUME~1\NETWOR~1\DATIAP~1\byte
[3|Directory] C:\DOCUME~1\NETWOR~1\DATIAP~1\byte disponibili
--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[10/12/2008 23.06][--ah-----] C:\WINDOWS\tasks\SA.DAT
[19/08/2004 14.00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing Folders in C:\Programmi
[22/11/2008|14.57] C:\Programmi\Adobe
[22/11/2008|15.32] C:\Programmi\Alwil Software
[22/11/2008|14.48] C:\Programmi\AMD
[22/11/2008|14.52] C:\Programmi\ATI Technologies
[21/11/2008|19.42] C:\Programmi\ComPlus Applications
[22/11/2008|14.50] C:\Programmi\CONEXANT
[29/11/2008|12.42] C:\Programmi\Duolabs
[04/12/2008|18.50] C:\Programmi\File comuni
[29/11/2008|12.47] C:\Programmi\FLV Player
[22/11/2008|15.03] C:\Programmi\Hewlett-Packard
[22/11/2008|15.03] C:\Programmi\Hp
[22/11/2008|15.17] C:\Programmi\HPQ
[22/11/2008|15.17] C:\Programmi\InstallShield Installation Information
[22/11/2008|15.09] C:\Programmi\Internet Explorer
[22/11/2008|14.59] C:\Programmi\InterVideo
[22/11/2008|15.16] C:\Programmi\Java
[04/12/2008|19.01] C:\Programmi\Messenger
[21/11/2008|19.46] C:\Programmi\microsoft frontpage
[04/12/2008|18.55] C:\Programmi\Microsoft SQL Server Compact Edition
[21/11/2008|19.43] C:\Programmi\Movie Maker
[10/12/2008|23.21] C:\Programmi\Mozilla Firefox
[21/11/2008|19.41] C:\Programmi\MSN Gaming Zone
[21/11/2008|19.43] C:\Programmi\NetMeeting
[21/11/2008|19.43] C:\Programmi\Outlook Express
[21/11/2008|19.44] C:\Programmi\Servizi in linea
[22/11/2008|15.13] C:\Programmi\Sonic
[22/11/2008|14.51] C:\Programmi\Synaptics
[10/12/2008|18.05] C:\Programmi\Trend Micro
[21/11/2008|19.55] C:\Programmi\Uninstall Information
[04/12/2008|19.17] C:\Programmi\Windows Live
[22/11/2008|15.18] C:\Programmi\Windows Media Player
[21/11/2008|19.41] C:\Programmi\Windows NT
[21/11/2008|19.44] C:\Programmi\WindowsUpdate
[10/12/2008|16.56] C:\Programmi\WinRAR
[21/11/2008|19.46] C:\Programmi\xerox
[10/12/2008|16.49] C:\Programmi\Zone Labs
[0|File] C:\Programmi\byte
[38|Directory] C:\Programmi\byte disponibili
--------------------\\ Listing Folders in C:\Programmi\File comuni
[28/11/2008|17.39] C:\Programmi\File comuni\Adobe
[22/11/2008|15.15] C:\Programmi\File comuni\InstallShield
[22/11/2008|15.15] C:\Programmi\File comuni\Java
[04/12/2008|19.13] C:\Programmi\File comuni\Microsoft Shared
[21/11/2008|19.43] C:\Programmi\File comuni\MSSoap
[21/11/2008|20.10] C:\Programmi\File comuni\ODBC
[21/11/2008|19.43] C:\Programmi\File comuni\Services
[22/11/2008|15.13] C:\Programmi\File comuni\Sonic Shared
[21/11/2008|20.10] C:\Programmi\File comuni\SpeechEngines
[22/11/2008|15.13] C:\Programmi\File comuni\SureThing Shared
[21/11/2008|19.43] C:\Programmi\File comuni\System
[22/11/2008|15.13] C:\Programmi\File comuni\TiVo Shared
[04/12/2008|18.54] C:\Programmi\File comuni\WindowsLiveInstaller
[0|File] C:\Programmi\File comuni\byte
[15|Directory] C:\Programmi\File comuni\byte disponibili
--------------------\\ Process
( 39 Processes )
... OK !
--------------------\\ Searching with S_Lop
No Lop folder found !
--------------------\\ Searching for Lop Files - Folders
No Lop folder found !
--------------------\\ Searching within the Registry
..... OK !
--------------------\\ Checking the Hosts file
Hosts file CLEAN
--------------------\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net Rootkit scan 2008-12-10 23:46:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Searching for other infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Matteo\Desktop\WinRAR.v3.51+ crack.zip
C:\DOCUME~1\Matteo\Desktop\Zone Alarm Pro 6.5.737+crack.rar
C:\DOCUME~1\Matteo\Recent\Zone Alarm Pro 6.5.737+crack.lnk
[F:1196][D:29]-> C:\DOCUME~1\Matteo\IMPOST~1\Temp
[F:13][D:0]-> C:\DOCUME~1\Matteo\Cookies
[F:332][D:4]-> C:\DOCUME~1\Matteo\IMPOST~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 11/12/2008| 0.16 - Option : [1]
--------------------\\ Scan completed at 0.16.18
Malwarebytes' Anti-Malware 1.31
Versione del database: 1483
Windows 5.1.2600 Service Pack 2
11/12/2008 0.04.54
mbam-log-2008-12-11 (00-04-49).txt
Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 74398
Tempo trascorso: 31 minute(s), 12 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 5
Chiavi di registro infette: 6
Valori di registro infetti: 5
Elementi dato del registro infetti: 7
Cartelle infette: 0
File infetti: 48
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
C:\WINDOWS\system32\torazovi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\numisufe.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\sohojire.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\tuhinibo.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\vewalimu.dll (Trojan.BHO) -> No action taken.
Chiavi di registro infette:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2cbe5d54-cd11-4b49-94ae-2e2f2ab7c264} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2cbe5d54-cd11-4b49-94ae-2e2f2ab7c264} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2cbe5d54-cd11-4b49-94ae-2e2f2ab7c264} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\b0576559 (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nikayevudu (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmb36456c5 (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> No action taken.
Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\sohojire.dll -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\sohojire.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\sohojire.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\tuhinibo.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\tuhinibo.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\vewalimu.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\vewalimu.dll -> No action taken.
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
C:\WINDOWS\system32\hisakite.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\etikasih.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\jahanane.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\enanahaj.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\ruludoji.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\ijodulur.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\titodopu.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\upodotit.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\torazovi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\ivozarot.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vusuputu.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\utupusuv.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\zidoyowi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\iwoyodiz.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\numisufe.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\tuhinibo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\fopinope.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\sohojire.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\vewalimu.dll (Trojan.BHO) -> No action taken.
C:\Documents and Settings\marco_2\Impostazioni locali\Temp\winmgnnX2qp7gi.exe (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\marco_2\Impostazioni locali\Temp\winuNnOQ.exe (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\marco_2\Impostazioni locali\Temporary Internet Files\Content.IE5\09M3CL6Z\cntr[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\marco_2\Impostazioni locali\Temporary Internet Files\Content.IE5\6V5IFA75\cntr[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\marco_2\Impostazioni locali\Temporary Internet Files\Content.IE5\6V5IFA75\cntr[2] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Matteo\Impostazioni locali\Temp\winb5616Ghl.exe (Trojan.Vundo) -> No action taken.
C:\RECYCLER\S-1-5-21-1220945662-113007714-682003330-1007\Dc4.EXE (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP37\A0004046.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP37\A0004047.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP37\A0004048.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP37\A0004139.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP38\A0005354.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP38\A0005355.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP38\A0011350.dll (Trojan.Vundo.H) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP38\A0011351.dll (Trojan.Vundo.H) -> No action taken.
C:\System Volume Information\_restore{5025CBEF-ECCF-48CF-A983-5E292352B100}\RP38\A0011352.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\mohafilu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\nefilepu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\vewalimu.dll.tmp (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\nuruhola.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\lulakodu.dll.tmp (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\madubiha.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\migitiho.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\pedisasa.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tuzatazo.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\kosuyapu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\yizesoko.dll.tmp (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\zorotahi.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\~.exe (Trojan.Vundo) -> No action taken.