Grazie anticipate.
Ecco il log:
############################## | FindyKill V5.002 |
# User : agostino (Administrators) # AGOSTINO-62B401
# Update on 07/06/09 by Chiquitine29
# Start at: 21.07.56 | 08/06/2009
# Website :
http://pagesperso-orange.fr/NosTools/findykill.html# AMD Athlon(tm) 64 Processor 3200+
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : avast! antivirus 4.8.1335 [VPS 090607-0] 4.8.1335 [ Enabled | Updated ]
# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 49,33 Go (24,7 Go free) # NTFS
# D:\ # Disco rigido locale # 256 Go (255,17 Go free) # NTFS
# E:\ # Disco rimovibile
# F:\ # Disco rimovibile
# G:\ # Disco rigido locale # 698,63 Go (276,7 Go free) # NTFS
# I:\ # Disco CD-ROM
# J:\ # Disco CD-ROM
# L:\ # Disco rigido locale # 37,3 Go (25,71 Go free) # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LogonUI.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\CDBurnerXP\NMSAccessU.exe
C:\Programmi\rnamfler\naofsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | C: |
################## | C:\WINDOWS |
Supprimé ! C:\WINDOWS\Prefetch\1978890.EXE-09BAFA05.pf
Supprimé ! C:\WINDOWS\Prefetch\1994546.EXE-362B808A.pf
Supprimé ! C:\WINDOWS\Prefetch\2048390.EXE-12D05A4D.pf
Supprimé ! C:\WINDOWS\Prefetch\2056875.EXE-001E2567.pf
Supprimé ! C:\WINDOWS\Prefetch\2066718.EXE-37E62C47.pf
Supprimé ! C:\WINDOWS\Prefetch\2091109.EXE-0F682038.pf
Supprimé ! C:\WINDOWS\Prefetch\2112937.EXE-11E8E1B2.pf
Supprimé ! C:\WINDOWS\Prefetch\64859.EXE-02B83102.pf
Supprimé ! C:\WINDOWS\Prefetch\FLEC006.EXE-057DA145.pf
Supprimé ! C:\WINDOWS\Prefetch\MDELK.EXE-1D176F91.pf
Supprimé ! C:\WINDOWS\Prefetch\WINTEMS.EXE-2A563F9B.pf
################## | C:\WINDOWS\system32 |
Supprimé ! C:\WINDOWS\system32\ban_list.txt
Supprimé ! C:\WINDOWS\system32\mdelk.exe
Supprimé ! C:\WINDOWS\system32\wintems.exe
################## | C:\WINDOWS\system32\drivers |
Supprimé ! C:\WINDOWS\system32\drivers\down
################## | C:\Documents and Settings\agostino\Dati applicazioni |
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\drivers\111wfs1intwq.sys
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\drivers\11s11ro1s1a2.sys
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\drivers\winupgro.exe
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\m\data.oct
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\m\flec006.exe
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\m\list.oct
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\m\srvlist.oct
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\drivers\downld
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\drivers
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\m\shared
Supprimé ! C:\Documents and Settings\agostino\Dati applicazioni\m
################## | Autres ... |
# Références de comparaison Bagle MD5 :
File : C:\Documents and Settings\agostino\Dati applicazioni\drivers\winupgro.exe
-> Crc32 : f3a67fbd | Md5 : 11be43591708b05ffd6052b43d22016e
################## | Temporary Internet Files |
################## | Registre / Clés infectieuses |
Supprimé ! [HKCU\Software\bisoft]
Supprimé ! [HKCU\Software\DateTime4]
Supprimé ! [HKCU\Software\Microsoft\Windows\UI] "KEY540534"
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
Supprimé ! [HKU\S-1-5-21-1060284298-299502267-839522115-1003\Software\FFC]
Supprimé ! [HKCU\Software\Local AppWizard-Generated Applications\install_crack]
Supprimé ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
################## | Etat / Services / Informations |
# Mode sans echec restauré !
# Affichage des fichiers cachés : OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )
################## | PEH ... |
Corrupted : C:\Programmi\a-squared Free\a2service.exe
[Offset = 00000104 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashAvast.exe
[Offset = 0000011C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashChest.exe
[Offset = 0000010C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashDisp.exe
[Offset = 00000124 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashLogV.exe
[Offset = 0000010C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
[Offset = 0000010C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashPopWz.exe
[Offset = 0000011C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashQuick.exe
[Offset = 0000011C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashServ.exe
[Offset = 00000124 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashSimp2.exe
[Offset = 0000011C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashSimpl.exe
[Offset = 0000011C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashSkPcc.exe
[Offset = 00000104 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashSkPck.exe
[Offset = 00000114 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashUpd.exe
[Offset = 00000104 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
[Offset = 00000114 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\aswRegSvr.exe
[Offset = 000000D4 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
[Offset = 00000114 - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\sched.exe
[Offset = 000000FC - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\VisthLic.exe
[Offset = 0000010C - Value = 0x0001]
Corrupted : C:\Programmi\Alwil Software\Avast4\VisthUpd.exe
[Offset = 000000F4 - Value = 0x0001]
Corrupted : C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
[Offset = 000000C4 - Value = 0x0001]
################## | Cracks / Keygens / Serials |
shapiro ti prego di seguermi ed aiutarmi.