Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Mi date un'occhiata al log hijackthis? Opzioni
delgiud
Inviato: Friday, December 12, 2008 5:00:21 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Chiedo aiuto ai preparatissimi amici del forum. Temo di avere il pc zeppo di trojan.
Mi date un'occhiata al log? Grazie. Guido

Logfile of HijackThis v1.99.1
Scan saved at 16.54.50, on 12/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\jozfzg.exe
C:\PROGRA~1\FILECO~1\PCSuite\Services\SERVIC~1.EXE
C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\PROGRA~1\WIDCOMM\SOFTWA~1\BTSTAC~1.EXE
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Outlook Express\msimn.exe
C:\Programmi\AVG\AVG8\avgtray.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\DOTT~1.GUI\IMPOST~1\Temp\Rar$EX00.188\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [IMJPMIG8.2] msime82.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB002" /M "Stylus C46"
O4 - HKLM\..\Run: [DataLayer] C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsServer] msfun80.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [jozfzg] "c:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\jozfzg.exe" jozfzg
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download &Flash Movies - C:\Programmi\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll tiaikr.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Boonty Games - BOONTY - C:\Programmi\File comuni\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe

Sponsor
Inviato: Friday, December 12, 2008 5:00:21 PM

 
shapiro
Inviato: Friday, December 12, 2008 5:19:53 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ciao

Scarica http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe e installalo

vai in provvisoria

Lancia Navilog1 e scegli l'opzione 4, inserisci il nome jozfzge confermalo ridigitandolo quando richiesto.

Nota bene: entrambe le volte che lo digiti non devi sbagliare a scrivere il nome altrimenti dovrai ripetere tutta la procedura perchè non verrà eliminato alcun file

A questo punto il programma ripulirà il pc dai file infetti.

Quando finisce, riavvia il pc in modalità normale

Da modalità normale, svuota C:\WINDOWS\Prefetch

_____

Apri hjt, spunta queste voci e clicca su FIX CHECHED


O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe

O4 - HKCU\..\Run: [MsServer] msfun80.exe

O4 - HKCU\..\Run: [jozfzg] "c:\documents and settings\dott.guidodelgiudice\impostazioni locali\dati applicazioni\jozfzg.exe" jozfzg

O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)

O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)

O20 - AppInit_DLLs: avgrsstx.dll tiaikr.dll




_____


Analizzza questi file in rosso su virus total

C:\WINDOWS\system32\SpywareRemover.exe

C:\Programmi\File comuni\BOONTY Shared\Service\Boonty.exe


http://www.virustotal.com/it/






scarica Malwarebytes

http://www.malwarebytes.org/mbam/program/mbam-setup.exe




1) lo installi
2) lo aggiorni
3) fai una scansione scegliendo la modalità completa
4) NON eliminare le eventuali minacce che rileva
5) finita la scansione seleziona il tabellino log, apri il file di testo e postalo sul forum
delgiud
Inviato: Friday, December 12, 2008 11:35:19 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Grazie shapiro x i preziosi consigli, ma ho incontrato alcuni problemi:
1)Non ho potuto analizzare il file C:\WINDOWS\system32\SpywareRemover.exe, in quanto nella cartella indicta non è visualizzato

2)Ho scaricato Malwarebytes, ma quando cerco di eseguirlo, mi compare il messaggio di errore:
Malwarebytes' Anti-Malware\mbamext.dll
Impossibile registrare la DLL/OCX: RegSvr32 è fallito con codice di uscita 0x5

3) La scansione con Navilog1 mi indica la presenza non rimossa di una "Vundo infection", come puoi vedere dal text:

Navipromo Removal version 3.7.0 started on 12/12/2008 at 22.37.07,31

Fix running from C:\Programmi\navilog1
Actual User Account : "Administrator"

Updated on 10.12.2008 at 21h00 by IL-MAFIOSO

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) M processor 1.40GHz )
BIOS : Ver 1.00PARTTBL
USER : Administrator ( Administrator )
BOOT : Fail-safe boot

Antivirus : AVG Anti-Virus Free 8.0 (Activated)


C:\ (Local Disk) - NTFS - Total:37 Go (Free:1 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)



Manual Removal

Typed filename : jozfzge

Cleanning stage done in safe mode

*** Searching, making backups and deleting files ***

* Deletion in "C:\WINDOWS\system32" *


* Deletion in "C:\Documents and Settings\Administrator\impost~1\datiap~1" *



*** Deleting folders in "C:\WINDOWS" ***


*** Deleting folders in "C:\Programmi" ***


*** Deleting folders in "C:\Documents and Settings\All Users\menuav~1\progra~1" ***


*** Deleting folders in "C:\Documents and Settings\All Users\menuav~1" ***


*** Deleting folders in "c:\docume~1\alluse~1\datiap~1" ***


*** Deleting folders in "C:\Documents and Settings\Administrator\datiap~1" ***


*** Deleting folders in "C:\Documents and Settings\Administrator\impost~1\datiap~1" ***


*** Deleting folders in "C:\Documents and Settings\Administrator\menuav~1\progra~1" ***



*** Deleting files ***


*** Deleting temporary files ***

Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Administrator\impost~1\Temp done !

*** Complementary Search ***
(Search specific files)

1)Deletion with backups new Instant Access files:

2)Heuristic search and deletion with backups :


* In "C:\WINDOWS\system32" *


* In "C:\Documents and Settings\Administrator\impost~1\datiap~1" *


*** Copy Registry to Safebackup folder ***

Backing up Registry done !

*** Cleaning Registry ***

Registry cleaned


*** Certificates ***

Egroup Certificate not found !
Electronic-Group Certificate not found !
Montorgueil Certificate not found !
OOO-Favorit Certificate not found !
Sunny-Day-Design-Ltd Certificate not found !

*** Search others known folders and files ***

C:\WINDOWS\system32\twxyxyxx.ini2 found ! Possible Vundo infection, not cleaned with this tool !
C:\WINDOWS\system32\uDefNUtv.ini2 found ! Possible Vundo infection, not cleaned with this tool !
C:\WINDOWS\system32\XxEfgMoq.ini2 found ! Possible Vundo infection, not cleaned with this tool !


*** Cleaning stage complete on 12/12/2008 at 22.40.00,39 ***

shapiro
Inviato: Saturday, December 13, 2008 10:51:37 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
disinstalla e reinstalla Malwarebytes e vedi se funziona, altrimenti fai una scansione online con kaspersky

http://www.kaspersky.com/virusscanner

1. Clicca su Kaspersky Online Scanner
2. Clicca su Accept
3. Partirà un Update
4. Vai nella colonna di sinistra dov'è scritto Scan e scegli my computer
5. Al termine della scansione in fondo a destra trovi la voce View Scan Report. Cliccaci sopra e poi clicca su Save "Save Report As" e salvalo sul desktop.
Per la scansione è richiesta l'installazione del java


___

scarica Avenger da qui

http://swandog46.geekstogo.com/avenger.zip

lo installi e lo lanci

Copi e incolli nella finestra: "Input script here" il testo in rosso così come lo vedi scritto:

files to delete:
C:\WINDOWS\system32\SpywareRemover.exe


Spunta "Automatically disable any rootkits found"

clicca sul pulsante "Execute"
Il pc dovrebbe riavviarsi da solo,se così non fosse riavvialo manualmente

posta il log di avenger che trovi in c:\


Scaricati sul desktop
VundoFix.exe

http://www.atribune.org/ccount/click.php?id=4

. esegui il file VundoFix.exe
. clicca sul bottone Scan for Vundo
. finita la scansione, clicca sul bottone Remove Vundo
. alla domanda "se vuoi rimuovere i file", clicca su YES
. lo schermo dovrebbe diventare bianco, è segno che la rimozione ha avuto inizio
. finita la rimozione, ti verrà chiesto di spegnere il pc, dai l'OK
. una volta riavviato, entra in C:\ e posta il risultato del file di testo vundofix.txt ed un nuovo log di HijackThis



delgiud
Inviato: Sunday, December 14, 2008 8:54:19 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Ciao shapiro. Ho fatto quanto hai detto, ma, a quanto pare, risultati zero! Eccoti i reports:
1)scansione kasper:
Sunday, December 14, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, December 13, 2008 12:53:19
Records in database: 1457729


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area My Computer
C:\
D:\

Scan statistics
Files scanned 91378
Threat name 14
Infected objects 36
Suspicious objects 3
Duration of the scan 04:52:57

File name Threat name Threats count
C:\WINDOWS\system32\xxyywUml.dll/C:\WINDOWS\system32\xxyywUml.dll Infected: Trojan.Win32.Monder.aanc 3

C:\AUTORUN.INF Infected: Worm.Win32.AutoRun.aka 1

C:\datidel giudice\adunanza\Posta in arrivo.dbx Infected: Trojan-Downloader.HTML.Agent.ae 1

C:\datidel giudice\adunanza\Posta in arrivo.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1

C:\datidel giudice\Documenti\Backup pendrive1-3-07\mandala\OUROBOROS.jpg Infected: Trojan-Clicker.HTML.IFrame.rp 1

C:\datidel giudice\Documenti\Best NOKIA Games 2006\Mosquitos.sis Infected: Trojan.SymbOS.Mosquit.b 1

C:\datidel giudice\Documenti\Della Porta\OUROBOROS.jpg Infected: Trojan-Clicker.HTML.IFrame.rp 1

C:\datidel giudice\Documenti\Downloads\Best NOKIA Games 2006.rar Infected: Trojan.SymbOS.Mosquit.b 1

C:\datidel giudice\posta\in\You have received a postcard.eml Infected: Trojan-Downloader.HTML.Agent.ae 1

C:\datidel giudice\posta\Posta in arrivo.dbx Infected: Trojan-Downloader.HTML.Agent.ae 1

C:\datidel giudice\posta\Posta in arrivo.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\Sun\Java\Deployment\cache\6.0\11\20d7210b-330c38d2 Infected: Trojan-Downloader.Java.OpenConnection.aq 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\Sun\Java\Deployment\cache\6.0\26\508465da-1bbb896b Infected: Trojan-Downloader.Java.OpenConnection.aq 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\Sun\Java\Deployment\cache\6.0\28\1935cf9c-1aa0057a Infected: Trojan-Downloader.Java.OpenConnection.aq 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\Sun\Java\Deployment\cache\6.0\40\5c034a68-6be4ee15 Infected: Trojan-Downloader.Java.OpenConnection.aq 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\Sun\Java\Deployment\cache\6.0\42\5c0ee46a-61c8fb57 Infected: Trojan-Downloader.Java.OpenConnection.aq 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\Sun\Java\Deployment\cache\6.0\54\381fec76-463a983a Infected: Trojan-Downloader.Java.OpenConnection.aq 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Dati applicazioni\Sun\Java\Deployment\cache\6.0\6\7757bb86-71ea166c Infected: Trojan-Downloader.Java.OpenConnection.aq 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Backup pendrive1-3-07\mandala\OUROBOROS.jpg Infected: Trojan-Clicker.HTML.IFrame.rp 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Best NOKIA Games 2006\Mosquitos.sis Infected: Trojan.SymbOS.Mosquit.b 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Della Porta\OUROBOROS.jpg Infected: Trojan-Clicker.HTML.IFrame.rp 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Best NOKIA Games 2006.rar Infected: Trojan.SymbOS.Mosquit.b 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Dati applicazioni\Identities\{F62533B4-CAFB-41C7-96B1-9A4885EE9E9F}\Microsoft\Outlook Express\Posta in arrivo.dbx Infected: Trojan-Downloader.HTML.Agent.ae 1

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Dati applicazioni\Identities\{F62533B4-CAFB-41C7-96B1-9A4885EE9E9F}\Microsoft\Outlook Express\Posta in arrivo.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial\Magic Ball2 v2.1+Serial\MagicBall2.exe Infected: not-a-virus:AdWare.Win32.MegaSearch.g 1

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial\Magic Ball2 v2.1+Serial\MagicBall2.exe Infected: Trojan-Downloader.Win32.Keenval.n 1

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial\Magic Ball2 v2.1+Serial\MagicBall2.exe Infected: Trojan-Downloader.Win32.Keenval.h 1

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial\Magic Ball2 v2.1+Serial\MagicBall2.exe Infected: Trojan.Win32.Keenval.a 1

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial.rar Infected: not-a-virus:AdWare.Win32.MegaSearch.g 1

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial.rar Infected: Trojan-Downloader.Win32.Keenval.n 1

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial.rar Infected: Trojan-Downloader.Win32.Keenval.h 1

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial.rar Infected: Trojan.Win32.Keenval.a 1

C:\Programmi\eMule\Incoming\arclab MailList Controller v2.01.WinAll.Incl.[key]maker-DEViANCE.zip Infected: Trojan.Win32.Agent.acw 1

C:\Programmi\eMule\Incoming\Sendblaster.Free.Edition.1.2.18.Win_All.crracked.zip Infected: Trojan.Win32.Agent.acw 1

C:\Programmi\eMule\Incoming\Tomtom 6 Deutschland-Map-v650 updated-fixed 02-2007.zip Infected: P2P-Worm.Win32.Kapucen.b 1

C:\Programmi\eMule\Uninstall.exe Infected: not-a-virus:AdWare.Win32.Agent.hox 1

C:\WINDOWS\system32\xxyywUml.dll Infected: Trojan.Win32.Monder.aanc 1

The selected area was scanned.
2)log di avenger:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\WINDOWS\system32\SpywareRemover.exe" not found!
Deletion of file "C:\WINDOWS\system32\SpywareRemover.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

3)report di Vundofix:
VundoFix V7.0.6

Scan started at 15.31.48 13/12/2008

Listing files found while scanning....


VundoFix V7.0.6

Scan started at 15.46.31 13/12/2008

Listing files found while scanning....

No infected files were found.


VundoFix V7.0.6

Scan started at 19.27.21 14/12/2008

Listing files found while scanning....

No infected files were found.

4)log di HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 20.44.56, on 14/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\PROGRA~1\FILECO~1\PCSuite\Services\SERVIC~1.EXE
C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\WIDCOMM\SOFTWA~1\BTSTAC~1.EXE
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Outlook Express\msimn.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\DOTT~1.GUI\IMPOST~1\Temp\Rar$EX00.890\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {31B9FFFE-9006-4B3E-94E3-7C9325433ADE} - C:\WINDOWS\system32\vtUNfeDu.dll (file missing)
O2 - BHO: (no name) - {461C7FD4-E1D2-4F69-8BB9-E176DDC759CB} - C:\WINDOWS\system32\qoMgfExX.dll (file missing)
O2 - BHO: (no name) - {4B38EFD8-A182-4C55-8E25-C37EA3811D1D} - C:\WINDOWS\system32\xxyxyxwt.dll (file missing)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\xxyywUml.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {77AB59B4-55A3-4737-9FD5-B93C6430BF78} - C:\WINDOWS\system32\yevcwfsx.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [IMJPMIG8.2] msime82.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB002" /M "Stylus C46"
O4 - HKLM\..\Run: [DataLayer] C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
O4 - Global Startup: Avvio veloce di Adobe Acrobat.lnk = ?
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download &Flash Movies - C:\Programmi\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: ybpdfb.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: xxyywUml - C:\WINDOWS\SYSTEM32\xxyywUml.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Boonty Games - BOONTY - C:\Programmi\File comuni\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe

shapiro
Inviato: Sunday, December 14, 2008 9:04:50 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ciao - ti avevo detto di fare la scansione con vundofix ma va bene lo stesso

Commenta:
Ciao shapiro. Ho fatto quanto hai detto, ma, a quanto pare, risultati zero!


beh non proprio zero kaspersky ha trovato 36 infezioni

attendi che ti preparo lo script per togliere tutto e vedere la scansione di hjt


delgiud
Inviato: Monday, December 15, 2008 12:41:50 AM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Grazie. Cmq la scansione con vundofix l'ho fatta, sia in normale che in provvisoria. Ti ho postato anche il report: deve esserti sfuggito. Esito: nessuna infezione rilevata!
shapiro
Inviato: Monday, December 15, 2008 1:48:24 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
per evitare di perdere troppo tempo, vai su questo sito e fai una scansione online togliendo tutto cio' che trova

http://www.bitdefender.com/scan8/ie.html

hai parecchie infezioni e bitdefender vedrai togliera' tutto

la scansione la devi fare da internet explorer
delgiud
Inviato: Monday, December 15, 2008 5:38:29 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Ho fatto come mi hai detto ed effettivamente bitdefender mi ha eliminato tutto.... eccetto Vundo. Eccoti il report:
BitDefender Online Scanner
Scan report generated at: Mon, Dec 15, 2008 - 17:20:53
Scan path: C:\;D:\;

Statistics

Time
03:01:19

Files
519855

Folders
5813

Boot Sectors
0

Archives
52267

Packed Files
15334




Results

Identified Viruses
10

Infected Files
33

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
32




Engines Info

Virus Definitions
2352088

Engine build
AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

Scan plugins
17

Archive plugins
45

Unpack plugins
7

E-mail plugins
6

System plugins
4




Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions


Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes




Scanned File
Status

C:\datidel giudice\adunanza\Posta in arrivo.dbx=>(message 1831): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Infected with: Trojan.Downloader.HTML.Agent.AE

C:\datidel giudice\adunanza\Posta in arrivo.dbx=>(message 1831): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Disinfection failed

C:\datidel giudice\adunanza\Posta in arrivo.dbx=>(message 1831): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Deleted

C:\datidel giudice\adunanza\Posta in arrivo.dbx=>(message 1831): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)
Updated

C:\datidel giudice\adunanza\Posta in arrivo.dbx=>(message 1831): You have received a postcard
Updated

C:\datidel giudice\adunanza\Posta in arrivo.dbx
Updated

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\mobimb_internet_patch.rar=>patch.exe
Detected with: Application.Aseye.ATW

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\mobimb_internet_patch.rar=>patch.exe
Disinfection failed

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\mobimb_internet_patch.rar=>patch.exe
Deleted

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\mobimb_internet_patch.rar
Update failed

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Detected with: Application.Aseye.ATW

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Disinfection failed

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Deleted

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar
Update failed

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Detected with: Application.Aseye.ATW

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Disinfection failed

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Deleted

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar
Update failed

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack.rar=>MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Detected with: Application.Aseye.ATW

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack.rar=>MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Disinfection failed

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack.rar=>MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Deleted

C:\datidel giudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack.rar
Update failed

C:\datidel giudice\posta\in\You have received a postcard.eml=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Infected with: Trojan.Downloader.HTML.Agent.AE

C:\datidel giudice\posta\in\You have received a postcard.eml=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Disinfection failed

C:\datidel giudice\posta\in\You have received a postcard.eml=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Deleted

C:\datidel giudice\posta\in\You have received a postcard.eml=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)
Updated

C:\datidel giudice\posta\in\You have received a postcard.eml
Updated

C:\datidel giudice\posta\Posta in arrivo.dbx=>(message 1831): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Infected with: Trojan.Downloader.HTML.Agent.AE

C:\datidel giudice\posta\Posta in arrivo.dbx=>(message 1831): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Disinfection failed

C:\datidel giudice\posta\Posta in arrivo.dbx=>(message 1831): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Deleted

C:\datidel giudice\posta\Posta in arrivo.dbx=>(message 1831): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)
Updated

C:\datidel giudice\posta\Posta in arrivo.dbx=>(message 1831): You have received a postcard
Updated

C:\datidel giudice\posta\Posta in arrivo.dbx
Updated

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\mobimb_internet_patch.rar=>patch.exe
Detected with: Application.Aseye.ATW

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\mobimb_internet_patch.rar=>patch.exe
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\mobimb_internet_patch.rar=>patch.exe
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\mobimb_internet_patch.rar
Update failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Detected with: Application.Aseye.ATW

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar
Update failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Detected with: Application.Aseye.ATW

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack\MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar
Update failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack.rar=>MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Detected with: Application.Aseye.ATW

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack.rar=>MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack.rar=>MobiMB_Internet_Patch_MobiMB2.3\patch.exe
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Documenti\Downloads\Cell Phone Stuff.rar=>Cell Phone Stuff\Misc\MobiMB_v2[1].3_demo21day_crack.rar
Update failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Dati applicazioni\Identities\{F62533B4-CAFB-41C7-96B1-9A4885EE9E9F}\Microsoft\Outlook Express\Posta in arrivo.dbx=>(message 2441): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Infected with: Trojan.Downloader.HTML.Agent.AE

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Dati applicazioni\Identities\{F62533B4-CAFB-41C7-96B1-9A4885EE9E9F}\Microsoft\Outlook Express\Posta in arrivo.dbx=>(message 2441): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Dati applicazioni\Identities\{F62533B4-CAFB-41C7-96B1-9A4885EE9E9F}\Microsoft\Outlook Express\Posta in arrivo.dbx=>(message 2441): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)=>(message body)
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Dati applicazioni\Identities\{F62533B4-CAFB-41C7-96B1-9A4885EE9E9F}\Microsoft\Outlook Express\Posta in arrivo.dbx=>(message 2441): You have received a postcard=>[Subject: You have received a postcard][Date: Mon, 13 Feb 2006 10:45:43 +0200]=>(MIME part)
Updated

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Dati applicazioni\Identities\{F62533B4-CAFB-41C7-96B1-9A4885EE9E9F}\Microsoft\Outlook Express\Posta in arrivo.dbx=>(message 2441): You have received a postcard
Updated

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Dati applicazioni\Identities\{F62533B4-CAFB-41C7-96B1-9A4885EE9E9F}\Microsoft\Outlook Express\Posta in arrivo.dbx
Updated

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\4ZUNUXYH\6[1].htm
Detected with: Adware.FakeAntiVirus.L

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\4ZUNUXYH\6[1].htm
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\4ZUNUXYH\6[1].htm
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\4ZUNUXYH\fileslist[2].js
Detected with: Adware.FakeAntiVirus.L

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\4ZUNUXYH\fileslist[2].js
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\4ZUNUXYH\fileslist[2].js
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\89CDEN89\disks[1].gif
Detected with: Adware.FakeAntiVirus.K

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\89CDEN89\disks[1].gif
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\89CDEN89\warning[1].jpg
Detected with: Adware.FakeAntiVirus.K

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\89CDEN89\warning[1].jpg
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\90PDJP1J\disks[1].gif
Detected with: Adware.FakeAntiVirus.K

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\90PDJP1J\disks[1].gif
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\CPWJGZ0Z\fileslist[1].js
Detected with: Adware.FakeAntiVirus.L

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\CPWJGZ0Z\fileslist[1].js
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\CPWJGZ0Z\fileslist[1].js
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\G6QPSXIT\scanning[2].js
Detected with: Adware.FakeAntiVirus.L

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\G6QPSXIT\scanning[2].js
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\G6QPSXIT\scanning[2].js
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\K9YNMR0L\6[1].htm
Detected with: Adware.FakeAntiVirus.L

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\K9YNMR0L\6[1].htm
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\K9YNMR0L\6[1].htm
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\K9YNMR0L\scanning[2].js
Detected with: Adware.FakeAntiVirus.L

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\K9YNMR0L\scanning[2].js
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\K9YNMR0L\scanning[2].js
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\QO462UMM\fileslist[1].js
Detected with: Adware.FakeAntiVirus.L

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\QO462UMM\fileslist[1].js
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\QO462UMM\fileslist[1].js
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\UFY7EPM7\warning[1].jpg
Detected with: Adware.FakeAntiVirus.K

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\UFY7EPM7\warning[1].jpg
Deleted

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\WLYBAVOH\fileslist[2].js
Detected with: Adware.FakeAntiVirus.L

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\WLYBAVOH\fileslist[2].js
Disinfection failed

C:\Documents and Settings\Dott.GuidoDelGiudice\Impostazioni locali\Temporary Internet Files\Content.IE5\WLYBAVOH\fileslist[2].js
Deleted

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial\Magic Ball2 v2.1+Serial\MagicBall2.exe
Infected with: Trojan.Generic.196917

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial\Magic Ball2 v2.1+Serial\MagicBall2.exe
Deleted

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial.rar=>Magic Ball2 v2.1+Serial\MagicBall2.exe
Infected with: Trojan.Generic.196917

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial.rar=>Magic Ball2 v2.1+Serial\MagicBall2.exe
Deleted

C:\Programmi\AdunanzA\Incoming\Magic Ball2 v2.1+Serial.rar
Update failed

C:\Programmi\AdunanzA\Incoming\Xilisoft.Video.Converter.Ultimate.5.0.98.0725-=(E.D)=-SND.rar=>Xilisoft.Video.Converter.Ultimate.5.0.98.0725-=(E.D)=-SND\keYgeN\XilisoftVideoConverterltimateKeygen.exe
Infected with: Trojan.Generic.934129

C:\Programmi\AdunanzA\Incoming\Xilisoft.Video.Converter.Ultimate.5.0.98.0725-=(E.D)=-SND.rar=>Xilisoft.Video.Converter.Ultimate.5.0.98.0725-=(E.D)=-SND\keYgeN\XilisoftVideoConverterltimateKeygen.exe
Deleted

C:\Programmi\AdunanzA\Incoming\Xilisoft.Video.Converter.Ultimate.5.0.98.0725-=(E.D)=-SND.rar
Update failed

C:\Programmi\eMule\Incoming\arclab MailList Controller v2.01.WinAll.Incl.[key]maker-DEViANCE.zip=>eia-ArcLab.MailListController.v2.01-Keygenerator.exe
Infected with: Trojan.Downloader.JJOM

C:\Programmi\eMule\Incoming\arclab MailList Controller v2.01.WinAll.Incl.[key]maker-DEViANCE.zip=>eia-ArcLab.MailListController.v2.01-Keygenerator.exe
Disinfection failed

C:\Programmi\eMule\Incoming\arclab MailList Controller v2.01.WinAll.Incl.[key]maker-DEViANCE.zip=>eia-ArcLab.MailListController.v2.01-Keygenerator.exe
Deleted

C:\Programmi\eMule\Incoming\arclab MailList Controller v2.01.WinAll.Incl.[key]maker-DEViANCE.zip
Updated

C:\Programmi\eMule\Incoming\Sendblaster.Free.Edition.1.2.18.Win_All.crracked.zip=>Sendblaster.exe
Infected with: Trojan.Downloader.JJOM

C:\Programmi\eMule\Incoming\Sendblaster.Free.Edition.1.2.18.Win_All.crracked.zip=>Sendblaster.exe
Disinfection failed

C:\Programmi\eMule\Incoming\Sendblaster.Free.Edition.1.2.18.Win_All.crracked.zip=>Sendblaster.exe
Deleted

C:\Programmi\eMule\Incoming\Sendblaster.Free.Edition.1.2.18.Win_All.crracked.zip
Updated

C:\Programmi\eMule\Incoming\Tomtom 6 Deutschland-Map-v650 updated-fixed 02-2007.zip=>Setup.exe
Infected with: Win32.Worm.P2P.Puce.G

C:\Programmi\eMule\Incoming\Tomtom 6 Deutschland-Map-v650 updated-fixed 02-2007.zip=>Setup.exe
Disinfection failed

C:\Programmi\eMule\Incoming\Tomtom 6 Deutschland-Map-v650 updated-fixed 02-2007.zip=>Setup.exe
Deleted

C:\Programmi\eMule\Incoming\Tomtom 6 Deutschland-Map-v650 updated-fixed 02-2007.zip
Updated

C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP160\A0014979.INF
Infected with: Trojan.PWS.OnlineGames.RAH

C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP160\A0014979.INF
Deleted

C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP160\A0014980.exe
Infected with: Trojan.Generic.196917

C:\System Volume Information\_restore{16021E5A-EC9A-4A86-A3FE-4A6F18DD31E0}\RP160\A0014980.exe
Deleted

C:\WINDOWS\system32\xxyywUml.dll
Infected with: Trojan.Vundo.GAW

C:\WINDOWS\system32\xxyywUml.dll
Disinfection failed

C:\WINDOWS\system32\xxyywUml.dll
Delete failed



L'ultimo file è quello che non riesce ad eliminare. Ho cercato di farlo dalla cartella ma mi dice impossibile perchè in uso. Ho riprovato con Vundofix ma non me lo identifica come infetto. Intanto anche AVG free che ho attivo mi segnala continuamente la presenza di threats Vundo da eliminare. Cosa posso fare x completare l'opera?









shapiro
Inviato: Monday, December 15, 2008 5:42:35 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
prova ad analizzarlo qui â–º http://www.virustotal.com/it/

potrebbe essere un falso positivo

shapiro
Inviato: Monday, December 15, 2008 5:52:07 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
prova con vundofix e vedi se lo toglie, altrimenti passiamo alle maniere forti

scarica Vundofix sul desktop

http://www.atribune.org/ccount/click.php?id=4

lancialo metti la spunta su "Run VundoFix as a task"
riceverai un messaggio che vundofix si chiuderà e riaprirà in un minuto o meno, quando il programma si riaprirà clicca OK
clicca su "Scan for Vundo" quando ha finito di fare la scansione clicca su "Remove vundo"
clicca YES alla domanda se vuoi rimuovere i files,quindi inizierà a rimuovere le dll del vundo ,quando ha finito ti dirà che dovrà spegnere il pc clicca OK.

Riaccendi il pc e allega il file C:\vundofix.txt in un post
delgiud
Inviato: Monday, December 15, 2008 6:02:18 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
ho riprovato a scaricare vundofix, ma non trovo la casella da spuntare che mi hai indicato. La scansione continua a dare esito negativo
shapiro
Inviato: Monday, December 15, 2008 6:05:49 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
riesci a scaricare malwarebytes e farlo avviare?

http://www.malwarebytes.org/mbam/program/mbam-setup.exe

se riesci ad avviarlo abbiamo risolto
delgiud
Inviato: Monday, December 15, 2008 6:30:40 PM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Fatto! Dovrebbe essere la volta buona! Questo è il log di mbam:
Malwarebytes' Anti-Malware 1.31
Versione del database: 1501
Windows 5.1.2600 Service Pack 2

15/12/2008 18.18.24
mbam-log-2008-12-15 (18-18-24).txt

Tipo di scansione: Scansione rapida
Elementi scansionati: 52379
Tempo trascorso: 6 minute(s), 46 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 2
Chiavi di registro infette: 13
Valori di registro infetti: 1
Elementi dato del registro infetti: 1
Cartelle infette: 0
File infetti: 2

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
C:\WINDOWS\system32\yevcwfsx.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\xxyywUml.dll (Trojan.Vundo) -> Delete on reboot.

Chiavi di registro infette:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4b38efd8-a182-4c55-8e25-c37ea3811d1d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4b38efd8-a182-4c55-8e25-c37ea3811d1d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77ab59b4-55a3-4737-9fd5-b93c6430bf78} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{77ab59b4-55a3-4737-9fd5-b93c6430bf78} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77ab59b4-55a3-4737-9fd5-b93c6430bf78} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IMJPMIG8.2 (Trojan.Agent) -> Quarantined and deleted successfully.

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
C:\WINDOWS\system32\yevcwfsx.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\xxyywUml.dll (Trojan.Vundo) -> Delete on reboot.

Mille grazie Shapiro, oltre che x la competenza, xla pazienza!!
Applause Applause
shapiro
Inviato: Monday, December 15, 2008 6:35:20 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
elimina tutto quello che malwarebytes ha trovato e riferisci come va il pc

attendo tue notizie

delgiud
Inviato: Thursday, December 18, 2008 10:43:44 AM
Rank: Member

Iscritto dal : 3/27/2004
Posts: 29
Ciao shapiro. Ho aspettato un pò x vedere le cose come vanno. Pare sia tutto a posto anche se AVG mi ha segnalato una sola volta un threat di Vundo. Pensi che sia utile fare una scansione con malwarebytes anche in provvisoria?
shapiro
Inviato: Thursday, December 18, 2008 10:54:54 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
se questo ti rende piu' sereno fai la scansione di nuovo

prima di farla, disattiva il ripristino

Per disattivare il ripristino di sistema vai su :
Start/tasto destro del mouse su risorse del computer/proprietà/Ripristino configurazione del sistema/e metti la spunta su "disattiva ripristino configurazione del sistema"


Riavvia e riattiva il ripristino creando un nuovo punto

a questo punto fai la scansione e posta il risultato
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.