Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Senza una via d'uscita ? Opzioni
enzino85
Inviato: Tuesday, January 12, 2010 9:41:09 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
In un computer diverso da dove scrivo, con sistema operativo XP, mi e accaduto questo.
Qualche "cosa" mi ha fatto fuori Avira e non mi permette di installarlo di nuovo.
Non mi permette di eseguire ne Hijackthis ne Combofix e ne installare qualsiasi programma.
Non posso avviare in modalità provvisoria, perchè mi da errore a347bus.sys.
Ho qualche possibilità ?
Grazie in anticipo

Sponsor
Inviato: Tuesday, January 12, 2010 9:41:09 PM

 
panchoz
Inviato: Tuesday, January 12, 2010 9:44:29 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Bagle Think Hai installato Alcohol 120%????


Calma.
panchoz
Inviato: Tuesday, January 12, 2010 9:52:36 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Hai installato Alcohol 120%????
enzino85
Inviato: Tuesday, January 12, 2010 9:56:30 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
NON ho installato Alcohol 120%
shapiro
Inviato: Tuesday, January 12, 2010 9:59:04 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164



scarica

http://dc108.4shared.com/download/75022994/b07bff/FindyKill.exe?tsid=20090209-102651-de3379fb

Una volta installato chiudi tutte le applicazioni attive e disconnettiti dal internet, poi clicca sull'icona di FindyKill e nella finestra dos che si aprirà scrivi 2 e premi Invio. Attendi il termine della scansione e posta qui il log che trovi in C:\FindyKill.txt
panchoz
Inviato: Tuesday, January 12, 2010 10:01:37 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
enzino85 ha scritto:
NON ho installato Alcohol 120%


Scusa l'insistenza Pray


Speak to the hand
panchoz
Inviato: Tuesday, January 12, 2010 10:05:25 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Hai avuto dei problemi e ti ha seguito R16, vero?
panchoz
Inviato: Tuesday, January 12, 2010 10:12:50 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Hai installato Daemon Tool??



a347bus.sys : il driver per la gestione delle estensioni Plug&Play del BIOS ma dovrebbe trovarsi nella cartella C:\Windows\System32, legittimo.

O è un malware sotto falsa copertura...


Ciao Speak to the hand

enzino85
Inviato: Tuesday, January 12, 2010 10:17:02 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
Non va in esecuzione neppure FindKill.
Appare per un attimo una finestra e si chiude immediatamente.
shapiro
Inviato: Tuesday, January 12, 2010 10:25:13 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
scarica questo programma ed eseguilo

http://wikisend.com/download/456184/abc.exe

lancia il programma e spunta '' ELIMINAR FICHEROS AUTOMATICAMENTE''

clicca su EXPLORAR per avviare la scansione


quando avra' finito troverai il log in C:\InfoSat.txt. - copialo in blocco note e postalo nel forum
r16
Inviato: Tuesday, January 12, 2010 10:28:08 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Disistalla Combofix manualmente.
Poi scarica questa versione:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
In fase di scaricamento devi rinominarlo con un nome a caso (esempio: TOMBO-FIX.EXE)
enzino85
Inviato: Tuesday, January 12, 2010 10:49:06 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
Durante la scansione ha dato anche il seguente errore:

Accesso denegado a la carpeta:
C:\Documents and Settings\desktop\Impostazioni locali\Dati applicazioni\Microsoft\CardSpace (8210)

Questo è il log richiesto:

**********************************************************

(12-1-2010 21:29:54)
EliBagle v13.40 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 11 de Enero del 2010)

Lista de Acciones (por AcciÛn Directa):
C:\WINDOWS\WINTEMS.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\MDELK.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\BAN_LIST.TXT --> Eliminado Bagle
Por favor, envienos una muestra del fichero
C:\Muestras\WINUPGRO.EXE.Muestra EliBagle v13.40
a "virus@satinfo.es". Gracias.
C:\DOCUMENTS AND SETTINGS\DESKTOP\DATI APPLICAZIONI\DRIVERS\WINUPGRO.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\SROSA2.SYS --> Eliminado Bagle(rootkit)
C:\WINDOWS\SYSTEM32\WFSINTWQ.SYS --> Bagle(rootkit) Acceso Denegado.
C:\DOCUMENTS AND SETTINGS\DESKTOP\DATI APPLICAZIONI\M\FLEC006.EXE --> Bagle.dldr Acceso Denegado.
C:\DOCUMENTS AND SETTINGS\DESKTOP\DATI APPLICAZIONI\M\LIST.OCT --> Eliminado Bagle
C:\DOCUMENTS AND SETTINGS\DESKTOP\DATI APPLICAZIONI\DRIVERS\DOWNLD\240078.EXE --> Eliminado Bagle(drzip)
C:\DOCUMENTS AND SETTINGS\DESKTOP\DATI APPLICAZIONI\DRIVERS\DOWNLD\277156.EXE --> Eliminado Bagle
C:\DOCUMENTS AND SETTINGS\DESKTOP\DATI APPLICAZIONI\DRIVERS\DOWNLD\311484.EXE --> Eliminado Bagle.dldr
Restaurada Clave: "SafeBoot\Minimal y Network"
Reinicie para Completar la Limpieza.

(12-1-2010 21:30:33)
EliBagle v13.40 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 11 de Enero del 2010)

Lista de Acciones (por ExploraciÛn):
Explorando "C:\"

N∫ Total de Directorios: 9870
N∫ Total de Ficheros: 77389
N∫ de Ficheros Analizados: 15298
N∫ de Ficheros Infectados: 0
N∫ de Ficheros Limpiados: 0
shapiro
Inviato: Tuesday, January 12, 2010 10:55:30 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
su diverse infezioni non e' stato possibile intervenire

riprova findikyll da provvisoria, adesso potresti accedervi

eseguilo con l'opzione 2

gli altri li eliminiamo con avenger
enzino85
Inviato: Tuesday, January 12, 2010 11:47:48 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
Finalmente ho eseguito Findykill, questo è il log:

***********************************************
############################## | FindyKill V5.012 |

# User : desktop (Administrators) # FRANCO
# Update on 20/09/2009 by Chiquitine29
# Start at: 23.28.34 | 12/01/2010
# Website : http://pagesperso-orange.fr/NosTools/index.html

# Intel(R) Pentium(R) 4 CPU 3.00GHz
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
# AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 74,56 Go (36,93 Go free) [Win_XP_old] # NTFS
# D:\ # Disco rigido locale # 232,88 Go (231,67 Go free) [Work] # NTFS
# E:\ # Disco CD-ROM # 575,97 Mo (0 Mo free) [Office 2007] # CDFS
# F:\ # Disco CD-ROM
# H:\ # Disco rigido locale # 465,65 Go (372,24 Go free) [LACIE] # FAT32
# M:\ # Disco CD-ROM # 6,67 Mo (0 Mo free) [U3 System] # CDFS
# N:\ # Disco rimovibile # 7,46 Go (1,9 Go free) # FAT32

############################## | Active Processes |

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Programmi\Google\Update\GoogleUpdate.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe

################## | C: |

(!) Not Deleted ! E:\"autorun.inf"
(!) Not Deleted ! M:\"autorun.inf"
Deleted ! N:\Autorun.inf
Deleted ! N:\PortableApps\Nero\App\Nero Burning ROM\SecurDisc\Autorun.inf

################## | C:\WINDOWS |

Deleted ! C:\WINDOWS\Prefetch\277156.EXE-23059275.pf
Deleted ! C:\WINDOWS\Prefetch\311484.EXE-21A49D5D.pf
Deleted ! C:\WINDOWS\Prefetch\FLEC006.EXE-18668667.pf

################## | C:\WINDOWS\system32 |


################## | C:\WINDOWS\system32\drivers |


################## | C:\Documents and Settings\desktop\Dati applicazioni |

Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\drivers\downld
(!) Not Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\drivers\winupgro.exe
(!) Not Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\drivers
(!) Not Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\flec006.exe
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\1st Class GradeBook 9.0g.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\1st Mass Mailer v3.2 by CHiCNCREAM.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\2nd Speech Center 1.00 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\310-035 Free Test Exam Questions 10.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\32bit Email Broadcaster v07.04.29 Regged by iNFECTED.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\3D Animated Tropical Night Screensaver v1.0 by s0m.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\4D Internet Extension 6.5 for Mac (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\6Aquarium Real Life 6 1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\AbleEncryptHide Advanced 1.5.3.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Active Panel 1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Active Zune Video Converter v1.3 by tRUE.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\AD Sound Recorder v3.2 Incl Keymaker by ARN.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Add-Remove 4Good v2.0 by AmoK.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Address Organizer Deluxe v2.6 by CROSSFiRE.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Adobe creative suitte cs2 for Mac (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Adobe PageMaker PlugIn Pack for Adobe InDesign CS 1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Advanced AVI Splitter v1.26.0.23.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Advanced Outlook Password Recovery 1.34.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Aglare FLV to AVI Converter 7.1.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Altova XMLSpy Enterprise Edition v2005 SP3 German WinAll Cracked by HS.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Andrew's Plugins Volume 9 'ImageEchoes' 9.0.9.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Appointment Book v3.5.1.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Architect 9.5 for Mac.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ArGoSoft FTP Server .NET Edition v1.0.0.1.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ArGoSoft Mail Server Pro 1.8.4.7.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ASE ChartDirector for PHP v3.1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Ashampoo BrennProfi Deluxe v4.0.4 Multilingual Incl KeyGen by DiGERATi.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Ashampoo Movie Shrink And Burn v2.0 Multilingual WinALL Incl Keygen by ViRiLiTY.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Asteroids.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\AudioConverter Studio v1.61.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Baan DBSync Manager 4.2.1.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Backup Magic v1.51289.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\BarGenie v9.0.0 WinALL CRACKED by LUCiD.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Biathlon 2007 v1.0 [MULTI5] No-CD Fixed EXE.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\BrainsBreaker v4.8 build 002 by thE Cur!ouZ.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Breedworks 4.1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Brothers In Arms Retail JAVA SE Z600 by RLYEH.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Bubble Level v1.0 Retail for iPhone (3G) iPod Touch by RLYEH.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Budget Workbook v1.2.2 MacOS Regged by rG.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\BusiBudde 2.5.6.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\BWMeter v4.0.0 by CHiCNCREAM.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\CANDI 1.31.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Capella 2000.3.0a12.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\CD Catalog Expert 7.60.020426.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\CDH Zip Control 1.1 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Chips for Windows 4.6.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ChopChop Copy Sidekick v1.0 WinALL Cracked by ARN.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Cimatron IT v12.0 Final.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Cloud Garden JSAPI implementation v1.5.3.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Complete Time Tracking Professional 2.54.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Conjugaison v3.02 French.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ContactMirror for Outlook v2.1.5 WinAll Regged by cOnspiracy.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Cool Audio Magic Audio Editor Pro v10.2.4 by ViRiLiTY.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Cool Color Picker 1.10.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\CornerChaos v1.0.0 WinALL CRACKED by iNDUCT.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Courier Email Client v3.5.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Create n Distribute Screensavers (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Crysis Warhead v1.0 +5 TRAINER DX9 Updated.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Crystal Player Pro v1.76.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Curvemeister v3.0.8 Retail for Adobe Photoshop by FOSI.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Cygnus Hex Editor v1.52 by RAC.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Database Application Icons 1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Design Works 3.14 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Disk Clean Wizard v1.30 Keymaker Only And Patch by EMBRACE.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Dive Planner v1.2 Retail for iPhone (3G) iPod Touch by RLYEH.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\DockFun 4.6 X for Mac.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Documents to Go 7.0 for PalmOS (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Dr. DivX 1.0.6 build 105 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Dragon Bane v1.20 for PalmOS.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\DU Meter v3.01 build 48 Fixed.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\DVD X Copy Deluxe 6.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\DYNOMITE v1.20.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\EA Mobile Skate Retail JAVA 176x208 by RLYEH.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Easy Address Book Web Server Standard Edition 1.2 CrAcKed.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Electricfish Color Palette for Adobe After Effects v1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\EmEditor v3.26 by TNT.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\EMS Source Rescuer v1.0.0.1.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\EncryptIt 4.00 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Escape Velocity 1.0 for Pocket PC.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ETROM v1.0 [ENGLISH] No-DVD Patch.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Euro-Reisekosten 2003 3.0 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Exact Mouse v1.01 by MP2K.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\FairStars Audio Converter 1.26 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\File Securer v3.54.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Find It v3.03.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\FlexRent 1.5.2-key.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ForwardMail for System Administrators v3.90.2 WinAll Regged by FALLEN.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Freecorder v2.2 by DVT.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\FTP Cafe v1.43 WinAll Regged by cOnspiracy.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\FTP Voyager v9.0.0.6 by Twice.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Game Jackal V2.7.14.357 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Game Maker v5.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Geovid Flash to Video Encoder Pro v2.8 by EXPLOSiON.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\GoldSolution PC Auto Shutdown v3.7 by CRD.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\GoMac 1.4.2 for Mac.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\GPSy 3.0a16 for Mac.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Gravity Active Schedule ActiveX 3.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\HelpSTAR 2008 10.0.196.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\HGS-Buch-Archiv v5.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Hide Window Hotkey v1.1 WinALL REGGED by LUCiD.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\HiFi MP3 WAV Converter v1.00 by TBE.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Hkvstore ASP Net Maker v2.1.1 Incl Keymaker by ZWT.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\HTML Page Guardian 2.7.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\IBA Card Maker 1.15.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Ideal Statements 1.40.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ImTOO iPod Movie Converter v2.1.55.1104b by ViRiLiTY.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Intellience CruiseControl 1.1 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Intelligent Strategy Games 10 (1993) (Oxford Softworks) (Rev1) FULL!.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Intelore Word Password Recovery v1.0g by AGAiN.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Internet Image Hunter 1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Ippatu Hagunse 3.0J for Mac.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\IRCza 1.0.0.1 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ISecSoft Anti Keylogger Elite v2.1.0 WinALL Cracked by ARN.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\JD Design ExpPrint v3.1 by EDGE.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\JoeAlter Shave And A Haircut For Maya 7.0 v4.4v18 Linux Incl Keymaker by ARN.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Just Checking 2.06.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\LAN Supervisor 2.7.0 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Letter Chase Speed Reader v1.03.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Longtion SlideShow Pro v4.0.0.8.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Lovers Ecstasy v5.0.40 by PC.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\mac pilot 2.0.5 for Mac.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Macromedia Dreamweaver 4.0 Crack by Eminence.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Magic Notes 3.0 build 1080 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\MakeCD v2.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\MediaChance DVDLab Pro v2.23 Update Only by EDGE.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Microsoft Windows XP Key Discoverers and Finders.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Minute Timer v1.6 WinAll Cracked by CRD.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Molsoft ICMPro v3.49a Linux RPM by RECOiL.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\MotionPerfect 4.01.26.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Movian VPN for Tungsten-C.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\MovieFinder 2.0.7.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\MP3 WAV Converter v2.52 by LasH.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\MP3PowerEncoder 1.0 PowerDVD SE 3.0 PowerPacks for WinXP (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Multi Clipboard v9.80.01 WinALL Keygen Only by BRD.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Multi Desktop 2.25.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Music Organizer Deluxe 1.6.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\My Pet Store Retail for SymbianOS S60v2 JAVA N70 by RLYEH.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\My Zodiac Calendar v1.0 build 100.80.904 by AHCU.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Nice Flower Screen Saver.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\No-Limit Casino 12 Pack Retail JAVA K300 by RLYEH.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Noiseware Pro 2.0.2 build 2021.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Nomad News 1.23 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Norbyte Bloxter v1.3.3 WinAll Cracked by CRD.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\NthGrep 2.1.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Office XP and .NET Style ActiveX Menu Control 1.61.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Okoker DVD to Zune Converter v1.0 Cracked by ARN.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Omega Research Pro Suite.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\OneTap Movies Retail for iPhone (3G) iPod Touch by RLYEH.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Opera v7.54 WinALL Incl Keygen by BLiZZARD.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\PCBoost v3.1.31.2005 And Serv Auth by EMBRACE.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Pegasus Wavelet 2000 Codec 2.10.0.25 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\PenguiNet v1.21 NEW.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\PGWARE SuperRam v5.5.22.2006 by VTX.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\PHPEdit v2.4.0 Incl Keymaker by Core.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\PicBreakout v2004.06.06 Incl Keygen Applet by Lz0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Pics Organizer v1.1 WinAll Regged by EiTHeL.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\PicturePlus 6.13.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Pingotron 4.2.0 crack.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Planet Pluto 3D Screensaver v1.1 by SoS.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Plato Video Converter v3.14 WinALL Incl Keygen by ViRiLiTY.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Pocket Heroes v1.01 Russian for PocketPC by TSRh.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Poster 7.7i (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Powermarks v3.5 build 306 by TSRh.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Preliminary Practice Tree 1.1.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\PrimaSoft Movie Organizer Deluxe v2.1 by FFF.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\PySoft 2D and 3D Animator v2.2 by Bidjan.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\QuadSucker Web v2.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Quote Organizer Deluxe 2.2.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\RAV Antivirus Desktop 8.1 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Real Function Keys 1.4 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Registry Repair Pro 3.0.0.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Resco Explorer v6.15 for Pocket PC Fixed.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Retrospect Server 6 for Mac (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\RM Converter 4.06 CrAcKed.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\RRD Editor 0.5.3.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\RTW Alexander v1.9 +2 TRAINER.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Scientific Workplace v5.50 build 2953 by META-INF.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Screen Catcher 2.0.1b1 for Mac (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ScreenTime Photo Video Personal 1.05 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\SecureCRT v3.1.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ShutDown Now 4.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\SID Icon InDepth 1.2.0.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\SmartFTP v1.5.991 by TSRh.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Soaring Eagles Wallpaper 1 patch.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Sothink SWF to Video Converter v1.0 build 61103 KEYGEN by FFF.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\SPT World Tour 2003 v1.0 [ENGLISH] No-CD Fixed EXE 2.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Spy Hunter 1.20 for PalmOS (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Spytech SpyLock 4.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Steitz CMAoD v4.1.2020 Incl Keygen by SSG.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Strip Poker III (1991) (Artworx) FULL!.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Studio Necessities v1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Synapticad VeriLogger 7.0E.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\SYSTAT SYSTAT V11.0 by LND.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Tareas MSD 3.40.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\TAS Professional 7.3.build 3.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\TetrixMania v1.03.2.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\The Binary News Assistant 2.1 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\The J Maker aipblossom 2002.03.08.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\The Sims expansion pack Unleashed (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Thief - Director's Cut Gold v1.37 [GERMAN] No-CD Patch.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ThumbsUp 3.4.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\TimeOff Administrator v2.5.2.323 by diGERATi.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\TMS Smooth Controls Pack-Delphi 2005 2.7.2.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Tom Clancy's Splinter Cell Chaos Theory v1.05 + 5 TRAINER.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Total Recorder Professional Edition v4.2.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\TurboZIP Compression Suite 8.2 Build 002061227.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Ulead DVD Workshop v1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Understand for Fortran v1.4.274 HPUX Incl Keygenerator by TMG.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\USB Disk Security v5.0.0.90 by Black X.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Vehicle Log v2.2 for PalmOS.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Video2000 v1.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ViewPic 1.4.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Virtutech Simics v2.2.7 Linux AMD64 by SSG.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Vision Aerobics 4.0.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Visual Route 6.1a.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Warlords Battlecry 2 v1.02 [ENGLISH] No-CD Patch.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\WeatherXpress 1.9.6.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Windows Commander v4.54 Multilanguage Loader.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Windrop Wallpaper Manager 3.3 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\XP UserManager v5.0.5.1228.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\XSwitch 1.1.2.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Zealot Video Workshop v1.7 by SND.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Zecos ApacheConf v5.0.0.4 Cracked by ZWT.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\Zeno's Stash 1.09.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ZoneAlarm Pro v2.6.84 Full Version by Lukeg 2k.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ZoneAlarm Pro v3.0.x.zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared\ZVET 2.20 (Serial).zip
Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m\shared
(!) Not Deleted ! C:\Documents and Settings\desktop\Dati applicazioni\m

################## | Reference of comparaison Bagle MD5 : |

File : C:\Documents and Settings\desktop\Dati applicazioni\drivers\winupgro.exe
-> Crc32 : c8f36590 | Md5 : 65fa32043cf5a0686aa28206c8d1b1ac


################## | Other deleting ... |

Not Deleted ! "C:\Documents and Settings\desktop\Dati applicazioni\drivers\winupgro.exe"
-> Size : 846336 | Crc32 : c8f36590 | Md5 : 65fa32043cf5a0686aa28206c8d1b1ac

Deleted ! "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-> Size : 846336 | Crc32 : c8f36590 | Md5 : 65fa32043cf5a0686aa28206c8d1b1ac


################## | Temporary Internet Files |


################## | Registry / Infected keys |

Deleted ! [HKLM\SYSTEM\ControlSet003\Services\sK9Ou0s]
Deleted ! [HKLM\SYSTEM\CurrentControlSet\Services\srosa]
Deleted ! [HKLM\SYSTEM\ControlSet001\Services\srosa]
Deleted ! [HKLM\SYSTEM\ControlSet003\Services\srosa]
Deleted ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S]
Deleted ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Deleted ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
Deleted ! [HKCU\Software\DateTime4]
Deleted ! [HKCU\Software\MuleAppData]
Deleted ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
Deleted ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
Deleted ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
Deleted ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
Deleted ! [HKLM\software\microsoft\security center] "FirewallOverride"
Deleted ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"
Deleted ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"

################## | State / Service / Information |

# Safe boot mode : OK


# Showing of hidden files : OK

# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

################## | PEH ... |

Corrupted : C:\Programmi\ASUS\AsusUpdate\Update.exe
[Offset = 000000FC - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\avadmin.exe
[Offset = 000000FC - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\avcenter.exe
[Offset = 0000010C - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\avconfig.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
[Offset = 0000010C - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\avguard.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\avnotify.exe
[Offset = 000000F4 - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\avscan.exe
[Offset = 000000FC - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\guardgui.exe
[Offset = 000000F4 - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\licmgr.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\sched.exe
[Offset = 0000010C - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\update.exe
[Offset = 000000F4 - Value = 0x0001]

Corrupted : C:\Programmi\Avira\AntiVir Desktop\wsctool.exe
[Offset = 000000FC - Value = 0x0001]

Corrupted : C:\Programmi\Mozilla Firefox\uninstall\helper.exe
[Offset = 000000E4 - Value = 0x0001]

Corrupted : C:\Programmi\SightSpeed\update.exe
[Offset = 000000DC - Value = 0x0001]

Corrupted : C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
[Offset = 000000C4 - Value = 0x0001]

Corrupted : C:\RECYCLER\S-1-5-21-1214440339-839522115-515967899-1003\Dc328.exe
[Offset = 000000EC - Value = 0x0001]

Corrupted : C:\WINDOWS\$hf_mig$\KB915865\update\update.exe
[Offset = 000000E4 - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB923561\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB946648\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB952004\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB954459\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB954600\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB955069\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB955759\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB956390-IE7\update\update.exe
[Offset = 000000E4 - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB956391\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB956744\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB956802\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB956844\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB958644\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB958687\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB959426\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB960225\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB960715\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB960803\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB960859\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB961371\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB961503\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB968220-IE8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB969059\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB969897-IE8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB969898\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB970238\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB970430\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB971557\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB971737\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB971961-IE8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB972260-IE8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB973346\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB973354\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB973507\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB973525\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB973687\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB973815\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB973869\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB973904\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB974112\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB974392\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB974455-IE8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB974571\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB975025\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB975364-IE8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB976325-IE8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\$hf_mig$\KB976749-IE8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\ServicePackFiles\i386\sysinfo.exe
[Offset = 000000E4 - Value = 0x0001]

Attempt of repair...
Backup : sysinfo.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\SoftwareDistribution\Download\053a109b2cad7271c044d8ed5cb7b552\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\SoftwareDistribution\Download\2767f4e09963710c25dffa284d79aa62\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\SoftwareDistribution\Download\39f5becb0aac1682a49a01046dc1c251\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\SoftwareDistribution\Download\52129d100717e4891732ccd60507183a\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\SoftwareDistribution\Download\766df793175ef1796b72948a9ce269f8\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\SoftwareDistribution\Download\86c1f81528627f799c8bbc8a0c0b6b12\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\SoftwareDistribution\Download\a1fda886531a80cb0d471d4b92071890\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\SoftwareDistribution\Download\bf67a3e0872aa30d180db80f39c672bb\update\update.exe
[Offset = 000000EC - Value = 0x0001]

Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\system32\dllcache\register.exe
[Offset = 000000E4 - Value = 0x0001]

Attempt of repair...
Backup : register.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.


Corrupted : C:\WINDOWS\system32\dllcache\sysinfo.exe
[Offset = 000000E4 - Value = 0x0001]

Attempt of repair...
Backup : sysinfo.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.


Corrupted : N:\PortableApps\FirefoxPortable\App\Firefox\uninstall\helper.exe
[Offset = 000000E4 - Value = 0x0001]

Corrupted : N:\PortableApps\ThunderbirdPortable\App\Thunderbird\uninstall\helper.exe
[Offset = 000000DC - Value = 0x0001]

Corrupted : N:\PortableApps\ClamWinPortable\App\clamwin\bin\ClamTray.exe
[Offset = 000000D4 - Value = 0x0001]

Corrupted : N:\PortableApps\ClamWinPortable\App\clamwin\bin\ClamWin.exe
[Offset = 000000D4 - Value = 0x0001]

Corrupted : N:\PortableApps\ClamWinPortable\App\clamwin\bin\WClose.exe
[Offset = 000000D4 - Value = 0x0001]

Corrupted : N:\PortableApps\ClamWinPortable\App\clamwin\bin\clamscan.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : N:\PortableApps\ClamWinPortable\App\clamwin\bin\freshclam.exe
[Offset = 00000104 - Value = 0x0001]

Corrupted : N:\PortableApps\ClamWinPortable\App\clamwin\bin\sigtool.exe
[Offset = 000000F4 - Value = 0x0001]


################## | Cracks / Keygens / Serials |


################## | End of Report # FindyKill V5.012 ! |

enzino85
Inviato: Wednesday, January 13, 2010 12:18:36 AM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
Ho dimenticato che:
Combofix mi dice che non è un'applicazione di Win32 valida,
mentre Avenger continua con "errore di esecuzione".

shapiro
Inviato: Wednesday, January 13, 2010 1:11:56 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
Installa Ccleaner

http://www.aiutamici.com/software?ID=11223

durante l’installazione deseleziona l’opzione per la barra di Yahoo, lo apri, vai in Opzioni>Avanzate, togli la spunta a “Cancella file temp diwindows solo se più vecchi di 48 ore”, poi avvialo, seleziona "Analizza" ed alla fine dell'analisi premi "Avvia pulizia''


clicca su Registro, nella pagina successiva clicca Trova problemi, poi al termine dello scan clicca su Ripara selezionati , risposndi di sì alla richiesta di salvare il backup (salvalo in una cartella a piacimento) poi ripara tutti gli elementi trovati.

scarica http://www.atribune.org/ccount/click.php?id=1

non ha bisogno di installazione

Avvia ATF Cleaner.exe con un doppio click
- clicca sul menu main
- seleziona la casella Select All
- clicca sul pulsante Empty selected
- aspetta l'avviso Done Cleaning.
(se non vuoi eliminare le password togli la spunta)
(se usi opera o firefox,spunta anche le loro sezioni)


prova a lanciare nuovamente avenger - rinominalo prima del download in 123.exe

http://swandog46.geekstogo.com/avenger.zip

se te lo permette, esegui quanro descritto


Estrailo in una cartella a tua scelta
Esegui il file avenger.exe
Ora incolla queste righe nella box bianca che si è aperta:

files to delete:
C:\WINDOWS\WINTEMS.EXE
C:\WINDOWS\MDELK.EXE
C:\Muestras\WINUPGRO.EXE
C:\DOCUMENTS AND SETTINGS\DESKTOP\DATI APPLICAZIONI\DRIVERS\WINUPGRO.EXE
C:\WINDOWS\SYSTEM32\WFSINTWQ.SYS
C:\DOCUMENTS AND SETTINGS\DESKTOP\DATI APPLICAZIONI\M\FLEC006.EXE


Togli il segno di spunta dalla voce Scan for Rootkits
Premi il pulsante Execute
Rispondi di Si alle due richieste di Avenger
Adesso il tuo computer dovrebbe riavviarsi, nel caso non succedesse, riavvialo tu manualmente
Al riavvio del computer, copia e incolla qui il contenuto del blocco note che apparirà.
enzino85
Inviato: Wednesday, January 13, 2010 10:12:53 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
Per quanto riguarda Ccleaner ho effettuato pulizia ad eccezione del registro nella sezione "DLL condivise mancanti", anche perchè il programma rimane attivo poco più di 30 secondi e poi esce.

Ho effettuato la pulizia con ATF Cleaner.

Non riesco ancora a lanciare Avenger.

shapiro
Inviato: Wednesday, January 13, 2010 10:18:54 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
prova a lanciare combofix, rinominalo in 123.exe prima del download

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
(non installare la recovery console)
Lascia lavorare il programma senza interferire
Allega il rapporto C:\ComboFix.txt nella tua risposta.

non usare il pc durante la scansione, nemmeno il mouse!
enzino85
Inviato: Wednesday, January 13, 2010 10:54:24 PM

Rank: AiutAmico

Iscritto dal : 9/12/2008
Posts: 76
Quando lancio ComboFix mi parte un'installazione di windows "Aspi Update"
Cosa devo fare ?
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.