Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

winupgro.exe come faccio ad eliminarlo? Opzioni
Ronny77
Inviato: Saturday, December 27, 2008 10:47:45 AM
Rank: Member

Iscritto dal : 3/1/2005
Posts: 15
Da due giorni ilmio portatile non va....e osservando nei processi incorsoho notato la presenza di questo winupgro.exe.
Come faccio ad eliminarlo?
Grazie per l'aiuto.
Sponsor
Inviato: Saturday, December 27, 2008 10:47:45 AM

 
shapiro
Inviato: Saturday, December 27, 2008 11:03:41 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ciao

riesci ad accedere alla provvisoria? prova e fammi sapere


scarica ► http://download.bleepingcomputer.com/sUBs/ComboFix.exe


Disattiva l'antivirus e i programmi anti-spyware
Disconnetti il pc da internet
Se hai delle icone di collegamento a programmi sul desktop, crea una cartella apposita e copiale al suo interno

Doppio click su combofix.exe e segui le istruzioni passo a passo

Quando avrà finito creerà il log C:\combofix.txt salvalo e postalo come gli altri report.

Nota bene : durante la scansione verranno creati dei file sul desktop e scompariranno le icone, potrebbe succedere che qualche programma ti chiede cosa fare per la rimozione dei drivers, in questo caso accossenti, si tratta probabilmente di drivers infetti.

Il programma creerà la cartella C:\QooBox ed all'interno della stessa verrà posizionato un backup dei files rimossi ed un file di backup del registro di windows chiamato Hiv-backup.

NON TOCCARE MOUSE E TASTIERA durante la scansione.
Ronny77
Inviato: Saturday, December 27, 2008 12:09:49 PM
Rank: Member

Iscritto dal : 3/1/2005
Posts: 15
Ciao e grazie per la celere risposta.
Ti elenco quelloche intanto ho fatto prima di leggere il tuo post.
Ho avviato Elibalgla e dopo in modalità provvisoria attraverso il comando start esegui ho fatto partire Combofix.
Ti allego intanto il report.
Una nota: al di là che dovrò reistallare i programmi antivirus etc, ho notatoche mi ha cancellato anche i drivers del wifi che non riesco a ripristinare.
Intanto grazie e attendo tue nuove.


ComboFix 08-12-26.03 - Ranieri Railz 2008-12-27 11.21.26.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.511.393 [GMT 1:00]
Eseguito da: c:\documents and settings\Ranieri Railz\desktop\abc.exe
Interruttori di comando utilizzati :: /killall
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
FW: ZoneAlarm Firewall *disabled*

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\113923.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\118971.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\119281.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\131559.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\177665.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\178566.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\178947.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\267865.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\335562.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\336473.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\336483.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\360718.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\363642.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\364924.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\366346.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\367838.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\downld\368399.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\srosa2.sys
c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers\winupgro.exe
c:\documents and settings\Ranieri Railz\Dati applicazioni\m
C:\InfoSat.txt
c:\programmi\TOSHIBA\TOSCDSPD\toscdspd.exe

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SK9OU0S
-------\Legacy_SROSA
-------\Service_sK9Ou0s


((((((((((((((((((((((((( Files Creati Da 2008-11-27 al 2008-12-27 )))))))))))))))))))))))))))))))))))
.

2008-12-26 19:29 . 2008-12-27 11:22 <DIR> d--h----- c:\documents and settings\Ranieri Railz\Dati applicazioni\drivers
2008-12-25 20:36 . 2008-12-25 20:36 <DIR> d-------- c:\windows\Sun
2008-12-22 23:21 . 2008-12-22 23:20 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-22 23:21 . 2008-12-22 23:20 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-13 00:27 . 2008-12-13 00:27 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\TEMP
2008-12-09 23:29 . 2008-12-09 23:29 118 --a------ c:\windows\system32\MRT.INI
2008-12-08 12:57 . 2008-12-08 12:57 <DIR> d-------- c:\windows\system32\it
2008-12-08 12:57 . 2008-12-08 12:57 <DIR> d-------- c:\windows\system32\bits
2008-12-08 12:57 . 2008-12-08 12:57 <DIR> d-------- c:\windows\l2schemas
2008-12-04 00:14 . 2008-12-04 00:14 3,273 --a------ c:\windows\SceneLib24.ini
2008-12-04 00:14 . 2008-12-10 22:46 672 --a------ c:\windows\3dtrack.INI
2008-12-04 00:04 . 2008-12-04 00:04 97,792 --a------ c:\windows\system32\drivers\ACEDRV05.sys
2008-12-04 00:04 . 2008-12-10 23:21 3,189 --a------ c:\windows\track.INI
2008-12-03 23:49 . 2008-12-10 23:21 <DIR> d-------- c:\programmi\WinTrack7
2008-11-30 22:51 . 2008-11-30 22:51 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2008-11-30 22:05 . 2008-11-30 22:05 <DIR> d-------- c:\documents and settings\Ranieri Railz\Dati applicazioni\SnapMail 5
2008-11-30 21:53 . 2008-11-30 21:53 <DIR> d-------- c:\programmi\Bonjour
2008-11-30 21:50 . 2008-11-30 21:50 <DIR> d-------- c:\programmi\Apple Software Update
2008-11-30 21:49 . 2008-11-30 21:49 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Apple
2008-11-29 19:43 . 2008-08-14 14:22 2,192,896 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-29 19:43 . 2008-08-14 14:22 2,148,864 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-29 19:43 . 2008-08-14 14:22 2,069,760 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-29 19:43 . 2008-08-14 14:22 2,027,520 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-29 01:18 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-11-29 01:17 . 2008-04-11 20:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-11-29 01:17 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-29 01:17 . 2008-05-01 15:34 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-11-29 01:14 . 2008-11-29 01:14 <DIR> d-------- c:\programmi\Avira
2008-11-29 01:05 . 2008-04-14 03:13 712,704 --------- c:\windows\system32\windowscodecs.dll
2008-11-29 01:05 . 2008-04-14 03:13 346,112 --------- c:\windows\system32\windowscodecsext.dll
2008-11-29 01:05 . 2008-04-14 03:13 276,992 --------- c:\windows\system32\wmphoto.dll
2008-11-29 01:05 . 2008-04-14 03:13 69,120 --------- c:\windows\system32\wlanapi.dll
2008-11-29 01:05 . 2008-04-14 03:13 53,248 --------- c:\windows\system32\tsgqec.dll
2008-11-29 01:05 . 2008-04-14 03:13 50,688 --------- c:\windows\system32\tspkg.dll
2008-11-29 01:04 . 2008-04-14 03:13 412,160 --------- c:\windows\system32\photometadatahandler.dll
2008-11-29 01:04 . 2008-04-14 03:13 293,888 --------- c:\windows\system32\qagentrt.dll
2008-11-29 01:04 . 2008-04-14 03:13 290,304 --------- c:\windows\system32\rhttpaa.dll
2008-11-29 01:04 . 2008-04-14 03:13 150,528 --------- c:\windows\system32\qagent.dll
2008-11-29 01:04 . 2008-04-14 03:13 144,896 --------- c:\windows\system32\onex.dll
2008-11-29 01:04 . 2008-04-14 03:13 76,800 --------- c:\windows\system32\qutil.dll
2008-11-29 01:04 . 2008-04-14 03:13 62,464 --------- c:\windows\system32\qcliprov.dll
2008-11-29 01:04 . 2008-04-14 03:13 61,952 --------- c:\windows\system32\rasqec.dll
2008-11-29 01:04 . 2008-04-14 03:14 32,768 --------- c:\windows\system32\setupn.exe
2008-11-29 01:04 . 2008-04-13 19:40 10,240 --------- c:\windows\system32\drivers\sffp_mmc.sys
2008-11-29 01:02 . 2008-04-14 03:13 651,264 --------- c:\windows\system32\dot3ui.dll
2008-11-29 01:01 . 2008-04-14 03:13 136,192 --------- c:\windows\system32\aaclient.dll
2008-11-29 00:12 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-11-29 00:12 . 2008-06-14 18:32 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-11-29 00:11 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-11-29 00:03 . 2008-09-15 16:24 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-26 21:58 43,100 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-26 21:58 3,788,832 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-26 17:22 --------- d-----w c:\programmi\Google
2008-12-22 22:20 --------- d-----w c:\programmi\Java
2008-12-22 22:09 --------- d-----w c:\programmi\Sicurezza
2008-12-22 21:17 --------- d-----w c:\programmi\Utility
2008-12-13 18:46 --------- d-----w c:\documents and settings\Ranieri Railz\Dati applicazioni\Lavasoft
2008-12-10 22:32 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2008-12-02 23:49 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\QuickTime
2008-11-29 00:14 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Avira
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-09-17 171448]
"eMuleAutoStart"="c:\programmi\Utility\eMule0.49b\emule.exe" [2008-08-01 5480448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-09-24 4861952]
"00THotkey"="c:\windows\System32\00THotkey.exe" [2003-05-23 14:27 253952]
"SigmaTel StacMon"="c:\programmi\SigmaTel\Driver audio di SigmaTel AC97\stacmon.exe" [2003-08-03 86073]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2003-05-30 110592]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2003-05-30 614400]
"TouchED"="c:\programmi\TOSHIBA\TouchED\TouchED.Exe" [2003-03-11 122880]
"PRONoMgr.exe"="c:\programmi\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-10 86016]
"ZoneAlarm Client"="c:\programmi\Sicurezza\Zone Labs\ZoneAlarm\zlclient.exe" [2008-12-27 919016]
"avgnt"="c:\programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-12-27 266497]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2007-09-18 98304]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-12-22 136600]
"nwiz"="nwiz.exe" [2003-09-24 c:\windows\system32\nwiz.exe]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 c:\windows\system32\000StTHK.exe]
"TFNF5"="TFNF5.exe" [2003-07-18 c:\windows\system32\TFNF5.exe]
"LTSMMSG"="LTSMMSG.exe" [2003-04-18 c:\windows\ltsmmsg.exe]
"TPSMain"="TPSMain.exe" [2003-10-02 c:\windows\system32\TPSMain.exe]
"TFncKy"="TFncKy.exe" [BU]
"NDSTray.exe"="NDSTray.exe" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2003-12-16 15:49 110592 c:\windows\system32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= usbmn2x2.dll
"midi2"= usbmn2x2.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Ranieri Railz^Menu Avvio^Programmi^Esecuzione automatica^FreePOPs.lnk]
path=c:\documents and settings\Ranieri Railz\Menu Avvio\Programmi\Esecuzione automatica\FreePOPs.lnk
backup=c:\windows\pss\FreePOPs.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 15:25 94208 c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 03:14 1695232 c:\programmi\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-09-18 22:11 98304 c:\programmi\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-09-17 20:42 171448 c:\programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Utility\\eMule0.49b\\emule.exe"=
"c:\\Programmi\\Utility\\SnapMail\\SnapMail.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

S3 USB22LDR;M-Audio USB MidiSport 2x2 Loader;c:\windows\system32\drivers\usb22ldr.sys [2007-11-10 14272]
S3 USBMN2X2;M-Audio USB MidiSport 2x2;c:\windows\system32\drivers\usbmn2x2.sys [2007-11-10 22304]
S4 Acp2w2kw;Acp2w2kw; []
.
Contenuto della cartella 'Scheduled Tasks'

2008-12-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-06-03 13:42]
.
- - - - ORFÃOS REMOVIDOS - - - -

HKCU-Run-TOSCDSPD - c:\programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
SafeBoot-sglfb.sys
SafeBoot-tga.sys
SafeBoot-wd.sys
SafeBoot-sacsvr


.
------- Supplementare di scansione -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-27 11:26:59
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

- - - - - - - > 'winlogon.exe'(944)
c:\windows\System32\LgNotify.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\S24EvMon.exe
c:\windows\system32\ZCfgSvc.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Toshiba\ConfigFree\CFSvcs.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RegSrvc.exe
c:\windows\system32\1XConfig.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\Toshiba\TOSHIBA Controls\TFncKy.exe
c:\programmi\Toshiba\ConfigFree\NDSTray.exe
c:\windows\system32\TPSBattM.exe
.
**************************************************************************
.
Ora fine scansione: 2008-12-27 11:30:34 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-12-27 10:30:31

Pre-Run: 21.535.600.640 byte disponibili
Post-Run: 21,427,605,504 byte disponibili

225 --- E O F --- 2008-12-18 22:30:52
shapiro
Inviato: Saturday, December 27, 2008 12:16:41 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
mentre controllo il log di combofix, fai una scansione con questo programma

http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

il programma potrebbe essere riconosciuto come un virus, ma non lo e'



disattiva momentaneamente l'antivirus

Doppio click sull'icona Findykill per avviare l'installazione:
Inserisci la prima spunta per accettare la licenza e prosegui > Suivant
Clicca su "Si" per destinare una cartella al programma
Clicca su Dèmarrer > Quitter per terminare l'installazione.
Cerca l'icona del programma sul desktop o in programmi ed eseguilo
Dovrai usare prima il tasto 1 (invio) per la ricerca e successivamente il tanto 2 (invio) per la pulizia.
Il report delle operazioni effettuate lo trovarai in C:\FindyKill.txt
Allega il rapporto nella tua risposta.
shapiro
Inviato: Saturday, December 27, 2008 12:55:38 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
combofix ha fatto una bella pulizia - avevi un bagle -

attento a emule soprattutto se scarichi dei programmi

attendo il report di findkill
Ronny77
Inviato: Saturday, December 27, 2008 1:01:37 PM
Rank: Member

Iscritto dal : 3/1/2005
Posts: 15
Ciao ti allego il report richiesto.



----------------- FindyKill V4.710 ------------------

* User : Ranieri Railz - RANIERI
* executed from : C:\Programmi\FindyKill
* Update on 21/12/08 par Chiquitine29
* Start at 12:55:50 the 2008-12-27
* Windows XP - Internet Explorer 7.0.5730.11


((((((((((((((( *** deleting *** ))))))))))))))))))


--------------- [ Active Processes ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

--------------- [ Infected files / folders ] ----------------


»»»» Supression files in C:


»»»» Supression files in C:\WINDOWS


»»»» Supression files in C:\WINDOWS\Prefetch


»»»» Supression files in C:\WINDOWS\system32


»»»» Supression files in C:\WINDOWS\system32\config\systemprofile\AppData\Roaming


»»»» Supression files in C:\WINDOWS\system32\drivers


»»»» Supression files in C:\Documents and Settings\Ranieri Railz\Dati applicazioni

Deleted ! - "C:\Documents and Settings\Ranieri Railz\Dati applicazioni\drivers"

»»»» Supression files in C:\DOCUME~1\RANIER~1\IMPOST~1\Temp


»»»» Supression files in C:\Documents and Settings\Ranieri Railz\Local Settings\Temporary Internet Files\Content.IE5


--------------- [ Registry / Infected keys ] ----------------

Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-1502569697-1571165634-4281287170-1006\Software\Local AppWizard-Generated Applications\install_patch
Deleted ! - HKEY_USERS\S-1-5-21-1502569697-1571165634-4281287170-1006\Software\Local AppWizard-Generated Applications\winupgro

--------------- [ States / Restarting of services ] ----------------



+- Services : [ Auto=2 / Request=3 / Disable=4 ]

Ndisuio - Type of startup = 3

EapHost - Type of startup = 2

Ip6Fw - Type of startup = 2

SharedAccess - Type of startup = 2

wuauserv - Type of startup = 2

wscsvc - Type of startup = 2


--------------- [ Cleaning removable drives ] ----------------

+- Informations :

C: - Unit… fissa


+- deleting files :


--------------- [ Registry / Mountpoint2 ] ----------------


-> Not found !


--------------- [ Searching Cracks / Keygen ] ----------------

C:\Documents and Settings\Ranieri Railz\Documenti\Software\Musica\Midtomid 1.0 Crack.zip
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Musica\Serial Number Winlive 4.7 v1.4.7.3 Cracked.exe
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Musica\WinLive Pro 4.6 + Crack
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Musica\Winlive 4.7 - 47 nuovo legge i CDG\winlive 4.7 Crack.exe
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Musica\WinLive Pro 4.6 + Crack\Winlive_Pro_4.6_build181_Crack_by_0KRam
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Musica\WinLive Pro 4.6 + Crack\wl46proit.exe
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Musica\WinLive Pro 4.6 + Crack\Winlive_Pro_4.6_build181_Crack_by_0KRam\Crack.exe
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Musica\WinLive Pro 4.6 + Crack\Winlive_Pro_4.6_build181_Crack_by_0KRam\Readme.nfo
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Utility\Camtasia Studio 4 Snagit 8 Keygen.rar
C:\Documents and Settings\Ranieri Railz\Documenti\Software\Utility\Camtasia Studio 4.0.0 Keygen Codecs (Screen Recorder).rar


---------------- ! End of report ! ------------------


shapiro
Inviato: Saturday, December 27, 2008 5:04:30 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
log pulito- anche findkill ha fatto il suo dovere

per sicurezza fai una scansione con bitdefender

http://www.bitdefender.com/scan8/ie.html

Ronny77
Inviato: Saturday, December 27, 2008 9:29:24 PM
Rank: Member

Iscritto dal : 3/1/2005
Posts: 15
Ti ringrazio molto.Ciao
shapiro
Inviato: Saturday, December 27, 2008 9:39:27 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
...uhm....veramente aspettavo il risultato di bitdefender
Ronny77
Inviato: Sunday, December 28, 2008 4:42:13 PM
Rank: Member

Iscritto dal : 3/1/2005
Posts: 15
Ti allego di seguito il risultato di bitdefender! Grazie.


//-----------------------------------------------------------------
//
// Product BitDefender Free Edition v10
// Product 10.2
//
// Created on: 28/12/2008 15:18:57
//
//-----------------------------------------------------------------


Virus Statistics

Scan path : C:\
Folders : 5304
Files : 114976
Memory processes scanned : 44
Archives : 259
Runtime packers : 6221
Identified viruses : 1
Infected files : 2
Memory processes infected : 0
Suspect files : 3
Warnings : 0
Disinfected files : 0
Deleted files : 2
Moved files : 0
I/O errors : 27
Scan time : 00:47:03
Scan speed (files/sec) : 40

Spyware Statistics

Registry keys scanned : 944
Registry keys infected : 0
Cookies scanned : 25
Cookies infected : 0
Spyware files infected : 0
Spyware threats detected : 0


Virus definitions : 2244492
Scan plugins : 12
Archive plugins : 43
Unpack plugins : 7
Mail plugins : 6
System plugins : 5

Virus scan options

Detection
[X] Scan boot sectors
[X] Memory Processes
[ ] Scan archives
[X] Scan runtime packers
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Move to quarantine
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[X] Move to quarantine
[ ] Prompt user

Virus scan options
[X] Enable warnings
[ ] Enable heuristics
[ ] Show all files in log
[X] Report file: C:\Documents and Settings\All Users\Dati applicazioni\Bitdefender\Desktop\Profiles\Logs\full_scan\1230473937.log

Spyware scan options

[X] Scan for riskware
[ ] Skip dial and applications from scan
[X] Registry keys
[X] Cookies


Summary:

C:\Qoobox\Quarantine\C\Documents and Settings\Ranieri Railz\Dati applicazioni\drivers\downld\131559.exe.vir Infected: Win32.Bagle.SUQ@mm
C:\Qoobox\Quarantine\C\Documents and Settings\Ranieri Railz\Dati applicazioni\drivers\downld\131559.exe.vir Deleted
C:\Qoobox\Quarantine\C\Documents and Settings\Ranieri Railz\Dati applicazioni\drivers\downld\267865.exe.vir Infected: Win32.Bagle.SUQ@mm
C:\Qoobox\Quarantine\C\Documents and Settings\Ranieri Railz\Dati applicazioni\drivers\downld\267865.exe.vir Deleted
shapiro
Inviato: Sunday, December 28, 2008 8:23:18 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
dovresti essere pulito da quello che dice bitdefender

posta un log per verifica

devi togliere combofix

start\esegui\Combofix /u -e premi invio(ok)

poi cancella le cartelle in C:\ (qoobox)

Ronny77
Inviato: Tuesday, December 30, 2008 5:15:16 PM
Rank: Member

Iscritto dal : 3/1/2005
Posts: 15
Ciao ecco il log richiesto.
Grazie ancora. Attendo una tua risposta positivaDancing

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:11, on 2008-12-30
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\00THotkey.exe
C:\WINDOWS\system32\TFNF5.exe
C:\Programmi\SigmaTel\Driver audio di SigmaTel AC97\stacmon.exe
C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\TPSMain.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\Programmi\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Sicurezza\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Programmi\SigmaTel\Driver audio di SigmaTel AC97\stacmon.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TouchED] C:\Programmi\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Programmi\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Sicurezza\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programmi\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Programmi\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1190052240313
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190064651259
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programmi\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7950 bytes
shapiro
Inviato: Tuesday, December 30, 2008 5:22:21 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
log pulito

se hai altre domande sono qui
Ronny77
Inviato: Tuesday, December 30, 2008 7:07:44 PM
Rank: Member

Iscritto dal : 3/1/2005
Posts: 15
Ti ringrazio molto.
Ciao
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.