Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
dialer internet connection
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus
Precedente :: Successivo  
Autore Messaggio
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 24 Apr 2008 09:26    Oggetto: Rispondi citando

Sembra tutto ok. Smile
Se non riscontri più problemi, puoi riattivare il ripristino di sistema.

In caso non ci fossero ulteriori novità, tra una settimana spostiamo l'intero thread tra i casi risolti. Wink
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 24 Apr 2008 12:21    Oggetto: grazie Rispondi citando

ti ringrazio ancora dell'aiuto fornito.
Very Happy
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 25 Apr 2008 08:17    Oggetto: replay Rispondi citando

ciao, purtroppo dopo un giorno il problema si è ripresentato ma già appena acceso il pc senza essermi ancora connesso ho notato ke nella cartella C:\WINDOWS\Prefetch erano presenti i file, con cui si presenta il problema tipo nerocheck, smaz4pnp, itouch, jusched, con la data e l'ora dell'accensione del pc, appunto di poki minuti fa, e ke prima ke mi collegassi è apparso il tentativo di connessione e da li ho capito ke si era ripresentato il problema ke puntualmente si è verificato, disconnettendomi, appena collegato alla rete.
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 25 Apr 2008 14:13    Oggetto: Rispondi citando

Per la cartella prefetch non ci sono problemi, viene creata in automatico da Windows e serve ad avviare più velocemente le applicazioni.

Per il resto, tagliamo la testa al toro... fai questa scansione con SystemScan e posta il log su FreeFileHosting come indicato qui.
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 25 Apr 2008 15:25    Oggetto: log systemscan Rispondi citando

ecco il log della scansione con systemscan:
25_04_2008_15_18_report.zip
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 25 Apr 2008 16:00    Oggetto: Rispondi citando

  • Avvia FindAWF e seleziona l'opzione 2:

  • Ti si apre un file di testo
  • Spostati sotto l'ultima riga del file di testo e inserisci le seguenti righe:
    Codice:
    "C:\Programmi\Analog Devices\SoundMAX\bak\smax4pnp.exe"
    "C:\Programmi\Java\jre1.5.0_05\bin\bak\jusched.exe"
    "C:\Programmi\Logitech\iTouch\bak\itouch.exe"
    "C:\WINDOWS\system32\bak\nerocheck.exe"
    "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb05.exe"

  • Chiudi il file di testo e conferma il salvataggio delle modifiche
  • Al termine dell'operazione ti viene aperto un nuovo log con l'esito finale
  • Incollalo nella tua prossima risposta insieme a un log aggiornato di combofix

Dopo, dovremo capire da dove salta fuori. Think
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 25 Apr 2008 16:18    Oggetto: log findawf e combofix Rispondi citando

ecco i 2 log aggiornati di findawf e combofix:

Find AWF report by noahdfear ©2006
Version 1.40
Option 2 run successfully



bak folders found
~~~~~~~~~~~

Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\WINDOWS\EHOME\BAK

17/08/2005 23.40 64.512 ehtray.exe
1 File 64.512 byte
2 Directory 54.518.538.240 byte disponibili
Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\WINDOWS\SYSTEM32\BAK

07/09/2004 14.00 15.360 ctfmon.exe
09/07/2001 12.50 155.648 NeroCheck.exe
2 File 171.008 byte
2 Directory 54.518.538.240 byte disponibili
Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\PROGRA~1\ANALOG~1\SOUNDMAX\BAK

23/09/2004 14.41 860.160 Smax4.exe
14/10/2004 11.11 1.388.544 SMax4PNP.exe
2 File 2.248.704 byte
2 Directory 54.518.534.144 byte disponibili
Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\PROGRA~1\LOGITECH\ITOUCH\BAK

01/12/2003 12.38 892.928 iTouch.exe
1 File 892.928 byte
2 Directory 54.518.534.144 byte disponibili
Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\PROGRA~1\NOKIA\NOKIAS~1\BAK

07/09/2007 15.44 3.100.672 NSLauncher.exe
1 File 3.100.672 byte
2 Directory 54.518.534.144 byte disponibili
Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK

10/10/2007 20.51 39.792 Reader_sl.exe
1 File 39.792 byte
2 Directory 54.518.534.144 byte disponibili
Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK

26/08/2005 19.14 36.975 jusched.exe
1 File 36.975 byte
2 Directory 54.518.534.144 byte disponibili
Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\PROGRA~1\ADOBE\PHOTOS~1\3.0\APPS\BAK

07/07/2005 18.41 57.344 apdproxy.exe
1 File 57.344 byte
2 Directory 54.518.534.144 byte disponibili
Il volume nell'unit? C non ha etichetta.
Numero di serie del volume: 247A-1CD2

Directory di C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK

21/06/2002 12.28 188.416 hpztsb05.exe
1 File 188.416 byte
2 Directory 54.518.534.144 byte disponibili


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

59392 10 Aug 2004 "C:\WINDOWS\$NtUninstallKB900325$\ehtray.exe"
64512 17 Aug 2005 "C:\WINDOWS\ehome\ehtray.exe"
64512 17 Aug 2005 "C:\WINDOWS\ehome\bak\ehtray.exe"
15360 7 Sep 2004 "C:\WINDOWS\system32\ctfmon.exe"
15360 7 Sep 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
155648 9 Jul 2001 "C:\WINDOWS\system32\nerocheck .exe"
155648 9 Jul 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
860160 23 Sep 2004 "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe"
860160 23 Sep 2004 "C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe"
1388544 14 Oct 2004 "C:\Programmi\Analog Devices\SoundMAX\smax4pnp.exe"
1388544 14 Oct 2004 "C:\Programmi\Analog Devices\SoundMAX\bak\SMax4PNP.exe"
892928 1 Dec 2003 "C:\Programmi\Logitech\iTouch\itouch.exe"
892928 1 Dec 2003 "C:\Programmi\Logitech\iTouch\bak\iTouch.exe"
3100672 7 Sep 2007 "C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe"
327680 22 Dec 2007 "C:\WINDOWS\Installer\{A8C856AD-63CD-4613-AA29-E6C85607EA06}\NSLauncher2_8C75ED63874746D18905B6C4AF1D7A30.exe"
3100672 7 Sep 2007 "C:\Programmi\Nokia\Nokia Software Launcher\bak\NSLauncher.exe"
39792 10 Oct 2007 "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
39792 10 Oct 2007 "C:\Programmi\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
36975 26 Aug 2005 "C:\Programmi\Java\jre1.5.0_05\bin\jusched.exe"
36975 26 Aug 2005 "C:\Programmi\Java\jre1.5.0_05\bin\bak\jusched.exe"
57344 7 Jul 2005 "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
57344 7 Jul 2005 "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe"
188416 21 Jun 2002 "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe"
188416 21 Jun 2002 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb05.exe"


end of report

ComboFix 08-04-24.1 - Angelo 2008-04-25 16.13.16.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.653 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Angelo\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Creati Da 2008-03-25 al 2008-04-25 )))))))))))))))))))))))))))))))))))
.

2008-04-25 16:11 . 2001-07-09 12:50 155,648 --a------ C:\WINDOWS\system32\nerocheck.exe
2008-04-23 22:43 . 2008-04-23 22:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-23 22:43 . 2008-04-23 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-04-23 22:16 . 2008-04-23 22:40 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-04-23 21:04 . 2008-04-23 21:04 <DIR> d-------- C:\Programmi\CCleaner
2008-04-23 16:19 . 2008-04-25 16:13 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-21 21:36 . 2005-08-17 23:40 64,512 --a--c--- C:\WINDOWS\system32\dllcache\ehtray.exe
2008-04-21 21:28 . 2008-04-21 21:28 6,144 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-04-16 13:15 . 2008-04-16 13:15 <DIR> d-------- C:\Programmi\File comuni\Skype
2008-04-16 13:14 . 2008-04-16 13:14 <DIR> d-------- C:\Documents and Settings\LocalService\Dati applicazioni\AVG7
2008-04-02 13:08 . 2008-04-02 13:08 <DIR> d-------- C:\Documents and Settings\Angelo\Dati applicazioni\skypePM
2008-04-02 13:08 . 2008-04-02 13:08 32 --a------ C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
2008-03-31 23:25 . 2008-03-31 23:25 831,488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 23:25 . 2008-03-31 23:25 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 23:25 . 2008-03-31 23:25 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2008-03-31 23:25 . 2008-03-31 23:25 161,096 --a--c--- C:\WINDOWS\system32\DivXCodecVersionChecker.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-25 14:01 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\Skype
2008-04-24 19:22 --------- d-----w C:\Programmi\eMule
2008-04-23 14:40 --------- d-----w C:\Programmi\C6 Messenger
2008-04-22 18:44 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\SopCast
2008-04-17 11:08 --------- d-----w C:\Programmi\DivX
2008-04-16 11:15 --------- d-----w C:\Programmi\SopCast
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-20 08:06 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:50 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:33 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:31 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-12 08:54 737,280 -c--a-w C:\WINDOWS\iun6002.exe
2007-12-28 11:30 69,176 ----a-w C:\Documents and Settings\Angelo\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
Codice:
<pre>
----a-w         1,388,544 2004-10-14 09:11:10  C:\Programmi\Analog Devices\SoundMAX\smax4pnp .exe
----a-w            36,975 2005-08-26 17:14:44  C:\Programmi\Java\jre1.5.0_05\bin\jusched .exe
----a-w           892,928 2003-12-01 10:38:16  C:\Programmi\Logitech\iTouch\itouch .exe
----a-w            64,512 2005-08-17 21:40:06  C:\WINDOWS\ehome\ehtray .exe
----a-w            15,360 2004-09-07 12:00:00  C:\WINDOWS\system32\ctfmon .exe
----a-w           155,648 2001-07-09 10:50:42  C:\WINDOWS\system32\nerocheck .exe
----a-w           188,416 2002-06-21 10:28:47  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05 .exe
</pre>



((((((((((((((((((((((((((((( snapshot@2008-04-23_16.21.18,31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-23 20:16:28 45,056 ----a-w C:\WINDOWS\BDOSCAN8\avxdisk.dll
+ 2008-04-23 20:16:28 10,240 ----a-w C:\WINDOWS\BDOSCAN8\avxs.dll
+ 2008-04-23 20:16:28 27,136 ----a-w C:\WINDOWS\BDOSCAN8\avxt.dll
+ 2008-04-23 20:16:30 181,760 ----a-w C:\WINDOWS\BDOSCAN8\bdcore.dll
+ 2008-01-09 13:01:48 118,784 ----a-w C:\WINDOWS\BDOSCAN8\bdupd.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\BDOSCAN8\ipsupd.dll
+ 2008-04-23 20:16:30 142,848 ----a-w C:\WINDOWS\BDOSCAN8\libfn.dll
+ 2008-04-23 20:16:28 86,016 ----a-w C:\WINDOWS\BDOSCAN8\librtvr.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
- 2008-04-23 12:34:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-25 13:07:23 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-01-09 13:01:48 118,784 ----a-w C:\WINDOWS\Downloaded Program Files\bdupd.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\Downloaded Program Files\ipsupd.dll
+ 2005-05-24 10:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 13:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 13:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2002-06-21 10:28:47 188,416 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 57,344 2005-07-07 16:41:54 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
----a-w 57,344 2005-07-07 16:41:54 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe

-c--a-w 860,160 2004-09-23 12:41:54 C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe
----a-w 860,160 2004-09-23 12:41:54 C:\Programmi\Analog Devices\SoundMAX\Smax4.exe

-c--a-w 1,388,544 2004-10-14 09:11:10 C:\Programmi\Analog Devices\SoundMAX\bak\SMax4PNP.exe
----a-w 1,388,544 2004-10-14 09:11:10 C:\Programmi\Analog Devices\SoundMAX\smax4pnp.exe

-c--a-w 36,975 2005-08-26 17:14:44 C:\Programmi\Java\jre1.5.0_05\bin\bak\jusched.exe
----a-w 36,975 2005-08-26 17:14:44 C:\Programmi\Java\jre1.5.0_05\bin\jusched.exe

-c--a-w 892,928 2003-12-01 10:38:16 C:\Programmi\Logitech\iTouch\bak\iTouch.exe
----a-w 892,928 2003-12-01 10:38:16 C:\Programmi\Logitech\iTouch\itouch.exe

----a-w 3,100,672 2007-09-07 13:44:30 C:\Programmi\Nokia\Nokia Software Launcher\bak\NSLauncher.exe
----a-w 3,100,672 2007-09-07 13:44:30 C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe

-c--a-w 64,512 2005-08-17 21:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 64,512 2005-08-17 21:40:06 C:\WINDOWS\ehome\ehtray.exe

----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe

-c--a-w 155,648 2001-07-09 10:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
----a-w 155,648 2001-07-09 10:50:42 C:\WINDOWS\system32\nerocheck.exe

-c--a-w 188,416 2002-06-21 10:28:47 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb05.exe
----a-w 188,416 2002-06-21 10:28:47 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-17 23:40 64512]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-26 19:14 36975]
"SoundMAXPnP"="C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 11:11 1388544]
"SoundMAX"="C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 14:41 860160]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-05 12:31 7323648]
"nwiz"="nwiz.exe" [2006-01-05 12:31 1519616 C:\WINDOWS\system32\nwiz.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 13:01 151552 C:\WINDOWS\system32\stmctrl.dll]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-06-21 12:28 188416]
"zBrowser Launcher"="C:\Programmi\Logitech\iTouch\iTouch.exe" [2003-12-01 12:38 892928]
"Adobe Photo Downloader"="C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 18:41 57344]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"NSLauncher"="C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 15:44 3100672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 14:00 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IETI"="C:\Programmi\Skype\Phone\IEPlugin\unins000.exe" [ ]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmi\\MSN Messenger\\livecall.exe"=
"C:\\Programmi\\C6 Messenger\\plugin\\fsmodule\\C6FileSharing.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\Programmi\\C6 Messenger\\c6Messenger.exe"=
"C:\\Documents and Settings\\Angelo\\Dati applicazioni\\SopCast\\adv\\SopAdver.exe"=
"C:\\Programmi\\SopCast\\SopCast.exe"=
"C:\\Programmi\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=

R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-01-24 17:45]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2002-09-25 08:37]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;C:\WINDOWS\system32\DRIVERS\torususb.sys [2003-01-09 16:21]
R3 usbstor;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-09-07 14:00]
R3 X10Hid;X10 Hid Device;C:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 11:45]
S1 as6eio;as6eio;C:\WINDOWS\system32\drivers\as6eio.sys []

*Newly Created Service* - MBR
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-25 16:14:03
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-04-25 16.14.43
ComboFix-quarantined-files.txt 2008-04-25 14:14:34
ComboFix2.txt 2008-04-23 14:21:39

9 Directory 54,466,920,448 byte disponibili
12 Directory 54,521,434,112 byte disponibili

188 --- E O F --- 2008-04-16 11:19:22
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 25 Apr 2008 16:56    Oggetto: Rispondi citando

  1. Azzera la domain zone.
    Avvia FindAWF e scegli l'opzione 4:


    Descrizione di questa funzione:
    ● verrà mostrato un messaggio di avviso
    digitare 1, e premere Enter
    ● dopo il reset della domain zones, il programma tornerà al menu principale.
    digitare E e, quindi, premere invio per uscire
    Nota: Se si fossero aggiunti, manualmente, Siti in zone protette, dovranno essere, nuovamente, inseriti.

  2. Crea un file di testo con le seguenti istruzioni:
    Codice:
    RenV::
    C:\Programmi\Analog Devices\SoundMAX\smax4pnp .exe
    C:\Programmi\Java\jre1.5.0_05\bin\jusched .exe
    C:\Programmi\Logitech\iTouch\itouch .exe
    C:\WINDOWS\ehome\ehtray .exe
    C:\WINDOWS\system32\ctfmon .exe
    C:\WINDOWS\system32\nerocheck .exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05 .exe

    Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:

    Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro. Wink
    Posta il log aggiornato di combofix

  3. usa KASPERSKY VIRUS REMOVAL TOOL: clicca qui per il download
    Compatibilita: Windows XP
    scarica la versione del tool più aggiornata rispetto alla data e ora di pubblicazione

    Installa KASPERSKY VIRUS REMOVAL TOOL:
    verrà creata una apposta cartella sul Desktop
    all?interno della cartella è presente la classica icona (una K) di Kaspersky
    clicca sull?icona per lanciare il tool
    imposta le aree che intendi scansionare (Startup Objects e Disk boot sector sono impostate di default)
    al termine della scansione sarà possibile rimuovere e/o mettere in quarantena i file infetti rilevati
    salva il log che verrà rilasciato
    Nota 1: Il tool è incompatibile se si hanno già prodotti Kaspersky installati
    Nota 2: non possiede una funzione di aggiornamento automatico delle firme


    Al termine, carica il log generato su FreeFileHosting come indicato qui.
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 25 Apr 2008 18:28    Oggetto: log combofix e kaspersky Rispondi citando

ecco i 2 log di combofix:

ComboFix 08-04-24.1 - Angelo 2008-04-25 17.03.09.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.673 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Angelo\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Angelo\Desktop\CFScript.txt
* Creato nuovo punto di ripristino

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Creati Da 2008-03-25 al 2008-04-25 )))))))))))))))))))))))))))))))))))
.

2008-04-23 22:43 . 2008-04-23 22:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-23 22:43 . 2008-04-23 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-04-23 22:16 . 2008-04-23 22:40 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-04-23 21:04 . 2008-04-23 21:04 <DIR> d-------- C:\Programmi\CCleaner
2008-04-23 16:19 . 2008-04-25 16:13 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-21 21:36 . 2005-08-17 23:40 64,512 --a--c--- C:\WINDOWS\system32\dllcache\ehtray.exe
2008-04-21 21:28 . 2008-04-21 21:28 6,144 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-04-16 13:15 . 2008-04-16 13:15 <DIR> d-------- C:\Programmi\File comuni\Skype
2008-04-16 13:14 . 2008-04-16 13:14 <DIR> d-------- C:\Documents and Settings\LocalService\Dati applicazioni\AVG7
2008-04-02 13:08 . 2008-04-02 13:08 <DIR> d-------- C:\Documents and Settings\Angelo\Dati applicazioni\skypePM
2008-04-02 13:08 . 2008-04-02 13:08 32 --a------ C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
2008-03-31 23:25 . 2008-03-31 23:25 831,488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 23:25 . 2008-03-31 23:25 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 23:25 . 2008-03-31 23:25 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2008-03-31 23:25 . 2008-03-31 23:25 161,096 --a--c--- C:\WINDOWS\system32\DivXCodecVersionChecker.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-25 14:58 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\Skype
2008-04-24 19:22 --------- d-----w C:\Programmi\eMule
2008-04-23 14:40 --------- d-----w C:\Programmi\C6 Messenger
2008-04-22 18:44 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\SopCast
2008-04-17 11:08 --------- d-----w C:\Programmi\DivX
2008-04-16 11:15 --------- d-----w C:\Programmi\SopCast
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-20 08:06 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:50 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:33 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:31 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-12 08:54 737,280 -c--a-w C:\WINDOWS\iun6002.exe
2007-12-28 11:30 69,176 ----a-w C:\Documents and Settings\Angelo\Dati applicazioni\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-04-23_16.21.18,31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-23 20:16:28 45,056 ----a-w C:\WINDOWS\BDOSCAN8\avxdisk.dll
+ 2008-04-23 20:16:28 10,240 ----a-w C:\WINDOWS\BDOSCAN8\avxs.dll
+ 2008-04-23 20:16:28 27,136 ----a-w C:\WINDOWS\BDOSCAN8\avxt.dll
+ 2008-04-23 20:16:30 181,760 ----a-w C:\WINDOWS\BDOSCAN8\bdcore.dll
+ 2008-01-09 13:01:48 118,784 ----a-w C:\WINDOWS\BDOSCAN8\bdupd.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\BDOSCAN8\ipsupd.dll
+ 2008-04-23 20:16:30 142,848 ----a-w C:\WINDOWS\BDOSCAN8\libfn.dll
+ 2008-04-23 20:16:28 86,016 ----a-w C:\WINDOWS\BDOSCAN8\librtvr.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
- 2008-04-23 12:34:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-25 13:07:23 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-01-09 13:01:48 118,784 ----a-w C:\WINDOWS\Downloaded Program Files\bdupd.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\Downloaded Program Files\ipsupd.dll
+ 2005-05-24 10:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 13:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 13:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2001-07-09 10:50:42 155,648 ----a-w C:\WINDOWS\system32\nerocheck.exe
+ 2002-06-21 10:28:47 188,416 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 57,344 2005-07-07 16:41:54 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
----a-w 57,344 2005-07-07 16:41:54 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe

-c--a-w 860,160 2004-09-23 12:41:54 C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe
----a-w 860,160 2004-09-23 12:41:54 C:\Programmi\Analog Devices\SoundMAX\Smax4.exe

-c--a-w 1,388,544 2004-10-14 09:11:10 C:\Programmi\Analog Devices\SoundMAX\bak\SMax4PNP.exe
----a-w 1,388,544 2004-10-14 09:11:10 C:\Programmi\Analog Devices\SoundMAX\smax4pnp.exe

-c--a-w 36,975 2005-08-26 17:14:44 C:\Programmi\Java\jre1.5.0_05\bin\bak\jusched.exe
----a-w 36,975 2005-08-26 17:14:44 C:\Programmi\Java\jre1.5.0_05\bin\jusched.exe

-c--a-w 892,928 2003-12-01 10:38:16 C:\Programmi\Logitech\iTouch\bak\iTouch.exe
----a-w 892,928 2003-12-01 10:38:16 C:\Programmi\Logitech\iTouch\itouch.exe

----a-w 3,100,672 2007-09-07 13:44:30 C:\Programmi\Nokia\Nokia Software Launcher\bak\NSLauncher.exe
----a-w 3,100,672 2007-09-07 13:44:30 C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe

-c--a-w 64,512 2005-08-17 21:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 64,512 2005-08-17 21:40:06 C:\WINDOWS\ehome\ehtray.exe

----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe

-c--a-w 155,648 2001-07-09 10:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
----a-w 155,648 2001-07-09 10:50:42 C:\WINDOWS\system32\nerocheck.exe

-c--a-w 188,416 2002-06-21 10:28:47 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb05.exe
----a-w 188,416 2002-06-21 10:28:47 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-17 23:40 64512]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-26 19:14 36975]
"SoundMAXPnP"="C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 11:11 1388544]
"SoundMAX"="C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 14:41 860160]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-05 12:31 7323648]
"nwiz"="nwiz.exe" [2006-01-05 12:31 1519616 C:\WINDOWS\system32\nwiz.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 13:01 151552 C:\WINDOWS\system32\stmctrl.dll]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-06-21 12:28 188416]
"zBrowser Launcher"="C:\Programmi\Logitech\iTouch\iTouch.exe" [2003-12-01 12:38 892928]
"Adobe Photo Downloader"="C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 18:41 57344]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"NSLauncher"="C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 15:44 3100672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 14:00 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IETI"="C:\Programmi\Skype\Phone\IEPlugin\unins000.exe" [ ]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmi\\MSN Messenger\\livecall.exe"=
"C:\\Programmi\\C6 Messenger\\plugin\\fsmodule\\C6FileSharing.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\Programmi\\C6 Messenger\\c6Messenger.exe"=
"C:\\Documents and Settings\\Angelo\\Dati applicazioni\\SopCast\\adv\\SopAdver.exe"=
"C:\\Programmi\\SopCast\\SopCast.exe"=
"C:\\Programmi\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=

R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-01-24 17:45]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2002-09-25 08:37]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;C:\WINDOWS\system32\DRIVERS\torususb.sys [2003-01-09 16:21]
R3 usbstor;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-09-07 14:00]
R3 X10Hid;X10 Hid Device;C:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 11:45]
S1 as6eio;as6eio;C:\WINDOWS\system32\drivers\as6eio.sys []

*Newly Created Service* - CATCHME
*Newly Created Service* - MBR
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-25 17:03:50
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-04-25 17.04.25
ComboFix-quarantined-files.txt 2008-04-25 15:04:14
ComboFix2.txt 2008-04-25 14:14:44
ComboFix3.txt 2008-04-23 14:21:39

9 Directory 54,480,297,984 byte disponibili
12 Directory 54,498,885,632 byte disponibili

182 --- E O F --- 2008-04-16 11:19:22

e quello di kaspersky :

kaspersky10.txt
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 26 Apr 2008 09:40    Oggetto: Rispondi citando

I logs sembrano puliti.

Giusto per sicurezza, prova a rieseguire la scansione di Kaspersky dalla modalità provvisoria.
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 26 Apr 2008 10:53    Oggetto: Rispondi citando

ecco il log della scansione in modalità provvisoria di kaspersky , precisando ke ho fatto la stessa selezionando le prime 4 voci del programma, xkè selezionandole tutte sarebbe durata più di 2 ore e ke se mi dici di rifarla tutta al completo provvedo:

edit by bdoriano: log eliminato perché incompleto. I logs vanno caricati su FreeFileHosting come indicato qui.

PS: ho fatto taglia e cuci del log che hai postato in 3 messaggi e ho salvato il risultato su freefilehosting: Kaspeskylog.zip
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 26 Apr 2008 11:47    Oggetto: Rispondi citando

Il log spezzato sembra pulito.
Anche le voci dei risultato finale non evidenziano ulteriori infezioni.

Assicurati di avere tutti gli aggiornamenti del tuo antivirus e di Microsoft Windows & Java.

Sarei dell'idea di proporti di cambiare antivirus... (che, per inciso, non ricordo quale sia). Wink
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 26 Apr 2008 12:21    Oggetto: Rispondi citando

al momento nn ho nessuno antivirus ma preciso ke avevo prima avg e poi antivir (avira) ma il problema si è presentato proprio quando avevo antivir e quindi poi fra tentativi e pulizie varie l'ho cancellato ma il problema è rimasto cmq. magari se mi indiki tu qualke buon antivirus

per quanto riguarda gli aggiornamenti farò al più presto quelli rikiesti ma ho notato ke nella cartella di windows dove avvengono tutti gli aggiornamenti, ke da quando ho fatto le varie scansioni e pulizie con i programmi ke mi hai detto nn è rimasto nessun file di aggiornamento ke puntualmente mi venivano kiesti di scaricare e aggiornare.
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 27 Apr 2008 07:51    Oggetto: Rispondi citando

Per quanto riguarda gli antivirus gratuiti, puoi guardare qui (Antivir mi dicono sia migliore di AVG, l'unica cosa che non mi piace è l'apparizione di una finestra pubblicitaria all'avvio del pc).
Non ho ancora avuto occasione di testare le nuove versioni di entrambi gli antivirus indicati. Razz

Ovviamente, è consigliata anche l'installazione di un buon firewall (io ti consiglio OnlineArmor o Comodo) e di un buon antispyware con protezione in tempo reale (real-time protection).
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 27 Apr 2008 11:33    Oggetto: Rispondi citando

ringranziandoti ancora per l'aiuto fornito ti informo ke ho installato un antivirus (antivir), un firewall (comodo) e un antispymare (avg), sperando di aver risolto definitivamente il problema. ciao
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 01 Mag 2008 21:20    Oggetto: Rispondi citando

purtroppo dopo 4 giorni tranquilli è riapparso internet collection disconnettendomi all'improvviso e tentando di collegarsi a quella creata. premetto ke ho installato solo antivir xkè installando anke avg e online armor ( firewall) andava un po' in conflitto qualkosa e risultava difficoltoso aprire programmi ke già avevo installati. inoltre ho fatto varie volte la scansione senza problemi con kaspersky rimasto installato dai precedenti tentativi di risoluzione del problema.
Top
Profilo Invia messaggio privato
chemicalbit
Dio maturo
Dio maturo


Registrato: 01/04/05 18:59
Messaggi: 18597
Residenza: Milano

MessaggioInviato: 01 Mag 2008 21:43    Oggetto: Rispondi citando

Per il conflitto tra i vari software di sicurezza: antivir è anche firewall?

Quanto a KASPERSKY VIRUS REMOVAL TOOL se l'avevi prelevato il 25 aprile, sicuramente ci sono versioni più aggiornate (ne escono più versioni ogni giorno).
Il programma non ha una funzione di aggiornamento, per cui occorre prelevare la nuova versione, disinstallare quella vecchia (lancia il programma uninst000.exe -o qualcosa di simile- che trovi nella cartella di KASPERSKY che il programma ti ha creato sul desktop ) e installare la nuova versione.


Con che altri programmi hai fatto scansioni?


Esegui HijackThis e Combofix e posta i loro log.
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 01 Mag 2008 22:25    Oggetto: Rispondi citando

allora antivir nn è firewall, ke io sappia. le scansioni sono state fatte solo con antivir e kaspersky , ke tra l'altro nn riesco a disinstallare ed infine ecco i 2 log rikiesti:
ComboFix 08-04-24.1 - Angelo 2008-05-01 22.18.13.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.679 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Angelo\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Creati Da 2008-04-01 al 2008-05-01 )))))))))))))))))))))))))))))))))))
.

2008-04-29 01:23 . 2008-04-29 01:23 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\nView_Profiles
2008-04-27 11:56 . 2008-04-27 11:56 <DIR> d-------- C:\Programmi\Tall Emu
2008-04-27 11:34 . 2008-04-27 11:34 <DIR> d-------- C:\Programmi\Avira
2008-04-27 11:34 . 2008-04-27 11:34 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Avira
2008-04-26 12:41 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-25 17:12 . 2008-05-01 22:20 3,074,080 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-25 17:12 . 2008-05-01 22:05 38,780 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-23 22:43 . 2008-04-23 22:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-23 22:43 . 2008-05-01 22:06 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-04-23 22:16 . 2008-04-23 22:40 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-04-23 21:04 . 2008-04-23 21:04 <DIR> d-------- C:\Programmi\CCleaner
2008-04-23 16:19 . 2008-04-25 16:13 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-21 21:36 . 2005-08-17 23:40 64,512 --a--c--- C:\WINDOWS\system32\dllcache\ehtray.exe
2008-04-21 21:28 . 2008-04-21 21:28 6,144 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-04-16 13:15 . 2008-04-16 13:15 <DIR> d-------- C:\Programmi\File comuni\Skype
2008-04-16 13:14 . 2008-04-16 13:14 <DIR> d-------- C:\Documents and Settings\LocalService\Dati applicazioni\AVG7
2008-04-02 13:08 . 2008-04-02 13:08 <DIR> d-------- C:\Documents and Settings\Angelo\Dati applicazioni\skypePM
2008-04-02 13:08 . 2008-04-02 13:08 32 --a------ C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-01 20:07 14,348 ----a-w C:\WINDOWS\system32\nerocheck.exe
2008-05-01 16:53 --------- d-----w C:\Programmi\eMule
2008-05-01 00:35 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\Skype
2008-04-27 12:25 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\Lavasoft
2008-04-26 10:41 --------- d-----w C:\Programmi\Java
2008-04-23 14:40 --------- d-----w C:\Programmi\C6 Messenger
2008-04-22 18:44 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\SopCast
2008-04-17 11:08 --------- d-----w C:\Programmi\DivX
2008-04-16 11:15 --------- d-----w C:\Programmi\SopCast
2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-03-31 21:25 161,096 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-20 08:06 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:50 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:33 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:31 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-12 08:54 737,280 -c--a-w C:\WINDOWS\iun6002.exe
2007-12-28 11:30 69,176 ----a-w C:\Documents and Settings\Angelo\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
Codice:
<pre>
----a-w         1,388,544 2004-10-14 09:11:10  C:\Programmi\Analog Devices\SoundMAX\smax4pnp .exe
----a-w           892,928 2003-12-01 10:38:16  C:\Programmi\Logitech\iTouch\itouch .exe
----a-w            64,512 2005-08-17 21:40:06  C:\WINDOWS\ehome\ehtray .exe
----a-w            15,360 2004-09-07 12:00:00  C:\WINDOWS\system32\ctfmon .exe
----a-w           155,648 2001-07-09 10:50:42  C:\WINDOWS\system32\nerocheck .exe
----a-w           188,416 2002-06-21 10:28:47  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05 .exe
</pre>



((((((((((((((((((((((((((((( snapshot@2008-04-23_16.21.18,31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-23 20:16:28 45,056 ----a-w C:\WINDOWS\BDOSCAN8\avxdisk.dll
+ 2008-04-23 20:16:28 10,240 ----a-w C:\WINDOWS\BDOSCAN8\avxs.dll
+ 2008-04-23 20:16:28 27,136 ----a-w C:\WINDOWS\BDOSCAN8\avxt.dll
+ 2008-04-23 20:16:30 181,760 ----a-w C:\WINDOWS\BDOSCAN8\bdcore.dll
+ 2008-01-09 13:01:48 118,784 ----a-w C:\WINDOWS\BDOSCAN8\bdupd.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\BDOSCAN8\ipsupd.dll
+ 2008-04-23 20:16:30 142,848 ----a-w C:\WINDOWS\BDOSCAN8\libfn.dll
+ 2008-04-23 20:16:28 86,016 ----a-w C:\WINDOWS\BDOSCAN8\librtvr.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
- 2008-04-23 12:34:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-01 20:06:11 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-01-09 13:01:48 118,784 ----a-w C:\WINDOWS\Downloaded Program Files\bdupd.dll
+ 2008-01-09 13:01:48 53,248 ----a-w C:\WINDOWS\Downloaded Program Files\ipsupd.dll
+ 2007-08-09 11:04:11 40,768 ----a-w C:\WINDOWS\system32\drivers\avgntdd.sys
+ 2007-07-18 12:22:19 21,312 ----a-w C:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2008-04-27 09:37:13 79,424 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-07-05 12:34:52 134,160 ----a-w C:\WINDOWS\system32\drivers\klif.sys
+ 2007-03-01 08:34:36 28,352 ----a-w C:\WINDOWS\system32\drivers\ssmdrv.sys
- 2005-08-26 14:55:46 49,248 -c--a-w C:\WINDOWS\system32\java.exe
+ 2008-02-21 23:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2005-08-26 14:55:58 49,250 -c--a-w C:\WINDOWS\system32\javaw.exe
+ 2008-02-21 23:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2005-08-26 17:14:46 127,078 -c--a-w C:\WINDOWS\system32\javaws.exe
+ 2008-02-22 00:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2005-05-24 10:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 13:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 13:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-05-01 20:07:22 14,348 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 57,344 2005-07-07 16:41:54 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
----a-w 57,344 2005-07-07 16:41:54 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe

-c--a-w 860,160 2004-09-23 12:41:54 C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe
----a-w 860,160 2004-09-23 12:41:54 C:\Programmi\Analog Devices\SoundMAX\Smax4.exe

-c--a-w 1,388,544 2004-10-14 09:11:10 C:\Programmi\Analog Devices\SoundMAX\bak\SMax4PNP.exe
----a-w 14,348 2008-05-01 19:08:13 C:\Programmi\Analog Devices\SoundMAX\smax4pnp.exe

-c--a-w 36,975 2005-08-26 17:14:44 C:\Programmi\Java\jre1.5.0_05\bin\bak\jusched.exe
----a-w 36,975 2005-08-26 17:14:44 C:\Programmi\Java\jre1.5.0_05\bin\jusched.exe

-c--a-w 892,928 2003-12-01 10:38:16 C:\Programmi\Logitech\iTouch\bak\iTouch.exe
----a-w 14,348 2008-05-01 20:07:23 C:\Programmi\Logitech\iTouch\itouch.exe

----a-w 3,100,672 2007-09-07 13:44:30 C:\Programmi\Nokia\Nokia Software Launcher\bak\NSLauncher.exe
----a-w 3,100,672 2007-09-07 13:44:30 C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe

-c--a-w 64,512 2005-08-17 21:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 64,512 2005-08-17 21:40:06 C:\WINDOWS\ehome\ehtray.exe

----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe

-c--a-w 155,648 2001-07-09 10:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
----a-w 14,348 2008-05-01 20:07:24 C:\WINDOWS\system32\nerocheck.exe

-c--a-w 188,416 2002-06-21 10:28:47 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb05.exe
----a-w 14,348 2008-05-01 20:07:22 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-17 23:40 64512]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SoundMAXPnP"="C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe" [2008-05-01 21:08 14348]
"SoundMAX"="C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 14:41 860160]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-05 12:31 7323648]
"nwiz"="nwiz.exe" [2006-01-05 12:31 1519616 C:\WINDOWS\system32\nwiz.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 13:01 151552 C:\WINDOWS\system32\stmctrl.dll]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2008-05-01 22:07 14348]
"zBrowser Launcher"="C:\Programmi\Logitech\iTouch\iTouch.exe" [2008-05-01 22:07 14348]
"Adobe Photo Downloader"="C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 18:41 57344]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2008-05-01 22:07 14348]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"NSLauncher"="C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 15:44 3100672]
"AVP"="C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_25.04.2008_18-23.exe" [2007-10-12 16:29 212992]
"avgnt"="C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-27 11:37 262401]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 14:00 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IETI"="C:\Programmi\Skype\Phone\IEPlugin\unins000.exe" [ ]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmi\\MSN Messenger\\livecall.exe"=
"C:\\Programmi\\C6 Messenger\\plugin\\fsmodule\\C6FileSharing.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\Programmi\\C6 Messenger\\c6Messenger.exe"=
"C:\\Documents and Settings\\Angelo\\Dati applicazioni\\SopCast\\adv\\SopAdver.exe"=
"C:\\Programmi\\SopCast\\SopCast.exe"=
"C:\\Programmi\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=

R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-01-24 17:45]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2002-09-25 08:37]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;C:\WINDOWS\system32\DRIVERS\torususb.sys [2003-01-09 16:21]
R3 usbstor;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-09-07 14:00]
R3 X10Hid;X10 Hid Device;C:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 11:45]
S1 as6eio;as6eio;C:\WINDOWS\system32\drivers\as6eio.sys []
S2 setup_7.0.0.180_25.04.2008_18-23;setup_7.0.0.180_25.04.2008_18-23;"C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_25.04.2008_18-23.exe" -r []

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-01 22:20:09
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-05-01 22.20.58
ComboFix-quarantined-files.txt 2008-05-01 20:20:55
ComboFix2.txt 2008-04-25 15:04:25
ComboFix3.txt 2008-04-25 14:14:44
ComboFix4.txt 2008-04-23 14:21:39

9 Directory 53,075,443,712 byte disponibili
11 Directory 53,144,424,448 byte disponibili

212 --- E O F --- 2008-04-16 11:19:22


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.24.00, on 01/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Programmi\Analog Devices\SoundMAX\SMax4PNP .exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05 .exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Programmi\internet explorer\iexplore.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\Angelo\IMPOST~1\Temp\Rar$EX00.531\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 205.238.40.53 winmx-com.winmxgroup.com winmx-com-v30.winmxgroup.com
O1 - Hosts: 205.238.40.1 test0.winmxgroup.net test4.winmxgroup.net
O1 - Hosts: 205.238.40.2 test1.winmxgroup.net test5.winmxgroup.net
O1 - Hosts: 82.43.224.20 test2.winmxgroup.net test6.winmxgroup.net
O1 - Hosts: 82.204.21.111 test3.winmxgroup.net
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmi\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [AVP] "C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_25.04.2008_18-23.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Programmi\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Programmi\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Programmi\Yahoo!\Messenger\yhexbmesit.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Programmi\Yahoo!\Messenger\yhexbmesit.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=19588
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0835856-69A6-4A63-91D9-0B77E1D78023}: NameServer = 85.37.17.49 85.38.28.91
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: setup_7.0.0.180_25.04.2008_18-23 - Kaspersky Lab - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_25.04.2008_18-23.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

--
End of file - 8198 bytes
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 02 Mag 2008 20:28    Oggetto: Rispondi citando

Per disinstallare Kaspersky, procedi così:
  • clicca sull?icona per lanciare il tool
  • nella finestra principale, in basso, clicca sulla voce Complete Virus Protection
  • verrà visualizzato un messaggio: clicca su Ok
  • chiudi la pagina web che verrà aperta
  • nel messaggio successivo, clicca su SI per avviare la disinstallazione
  • al termine, verrà richiesto di riavviare il P.C.

Crea un file di testo con le seguenti istruzioni:
Codice:
RenV::
C:\Programmi\Analog Devices\SoundMAX\smax4pnp .exe
C:\Programmi\Logitech\iTouch\itouch .exe
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\nerocheck .exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05 .exe

Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:

Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro. Wink
Posta il log aggiornato di combofix.
Top
Profilo Invia messaggio privato
nikman
Eroe in grazia degli dei
Eroe in grazia degli dei


Registrato: 22/04/08 15:54
Messaggi: 158

MessaggioInviato: 02 Mag 2008 21:02    Oggetto: Rispondi

per quanto riguarda kaspersky l'avevo disinstallato in modalità provvisoria invece eccoti il log di combofix:

ComboFix 08-04-24.1 - Angelo 2008-05-02 20.57.06.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.687 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Angelo\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Angelo\Desktop\CFScript.txt
* Creato nuovo punto di ripristino

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Creati Da 2008-04-02 al 2008-05-02 )))))))))))))))))))))))))))))))))))
.

2008-04-29 01:23 . 2008-04-29 01:23 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\nView_Profiles
2008-04-27 11:34 . 2008-04-27 11:34 <DIR> d-------- C:\Programmi\Avira
2008-04-27 11:34 . 2008-04-27 11:34 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Avira
2008-04-26 12:41 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-25 17:12 . 2008-05-01 22:28 3,100,704 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-25 17:12 . 2008-05-01 22:28 39,500 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-23 22:43 . 2008-04-23 22:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-23 22:43 . 2008-05-01 22:06 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-04-23 22:16 . 2008-04-23 22:40 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-04-23 21:04 . 2008-04-23 21:04 <DIR> d-------- C:\Programmi\CCleaner
2008-04-23 16:19 . 2008-04-25 16:13 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-21 21:36 . 2005-08-17 23:40 64,512 --a--c--- C:\WINDOWS\system32\dllcache\ehtray.exe
2008-04-21 21:28 . 2008-04-21 21:28 6,144 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-04-16 13:15 . 2008-04-16 13:15 <DIR> d-------- C:\Programmi\File comuni\Skype
2008-04-16 13:14 . 2008-04-16 13:14 <DIR> d-------- C:\Documents and Settings\LocalService\Dati applicazioni\AVG7
2008-04-02 13:08 . 2008-04-02 13:08 <DIR> d-------- C:\Documents and Settings\Angelo\Dati applicazioni\skypePM
2008-04-02 13:08 . 2008-04-02 13:08 32 --a------ C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-02 14:08 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\Skype
2008-05-01 16:53 --------- d-----w C:\Programmi\eMule
2008-04-27 12:25 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\Lavasoft
2008-04-26 10:41 --------- d-----w C:\Programmi\Java
2008-04-23 14:40 --------- d-----w C:\Programmi\C6 Messenger
2008-04-22 18:44 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\SopCast
2008-04-17 11:08 --------- d-----w C:\Programmi\DivX
2008-04-16 11:15 --------- d-----w C:\Programmi\SopCast
2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-03-31 21:25 161,096 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-20 08:06 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:50 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:33 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:31 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-12 08:54 737,280 -c--a-w C:\WINDOWS\iun6002.exe
2007-12-28 11:30 69,176 ----a-w C:\Documents and Settings\Angelo\Dati applicazioni\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot_2008-05-01_22.20.37,95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-01 20:06:11 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-02 18:46:57 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-01 20:07:24 14,348 ----a-w C:\WINDOWS\system32\nerocheck.exe
+ 2001-07-09 10:50:42 155,648 ----a-w C:\WINDOWS\system32\nerocheck.exe
- 2008-05-01 20:07:22 14,348 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
+ 2002-06-21 10:28:47 188,416 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 57,344 2005-07-07 16:41:54 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
----a-w 57,344 2005-07-07 16:41:54 C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe

-c--a-w 860,160 2004-09-23 12:41:54 C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe
----a-w 860,160 2004-09-23 12:41:54 C:\Programmi\Analog Devices\SoundMAX\Smax4.exe

-c--a-w 1,388,544 2004-10-14 09:11:10 C:\Programmi\Analog Devices\SoundMAX\bak\SMax4PNP.exe
----a-w 1,388,544 2004-10-14 09:11:10 C:\Programmi\Analog Devices\SoundMAX\smax4pnp.exe

-c--a-w 36,975 2005-08-26 17:14:44 C:\Programmi\Java\jre1.5.0_05\bin\bak\jusched.exe
----a-w 36,975 2005-08-26 17:14:44 C:\Programmi\Java\jre1.5.0_05\bin\jusched.exe

-c--a-w 892,928 2003-12-01 10:38:16 C:\Programmi\Logitech\iTouch\bak\iTouch.exe
----a-w 892,928 2003-12-01 10:38:16 C:\Programmi\Logitech\iTouch\itouch.exe

----a-w 3,100,672 2007-09-07 13:44:30 C:\Programmi\Nokia\Nokia Software Launcher\bak\NSLauncher.exe
----a-w 3,100,672 2007-09-07 13:44:30 C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe

-c--a-w 64,512 2005-08-17 21:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 64,512 2005-08-17 21:40:06 C:\WINDOWS\ehome\ehtray.exe

----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe

-c--a-w 155,648 2001-07-09 10:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
----a-w 155,648 2001-07-09 10:50:42 C:\WINDOWS\system32\nerocheck.exe

-c--a-w 188,416 2002-06-21 10:28:47 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb05.exe
----a-w 188,416 2002-06-21 10:28:47 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-17 23:40 64512]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SoundMAXPnP"="C:\Programmi\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 11:11 1388544]
"SoundMAX"="C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 14:41 860160]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-05 12:31 7323648]
"nwiz"="nwiz.exe" [2006-01-05 12:31 1519616 C:\WINDOWS\system32\nwiz.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 13:01 151552 C:\WINDOWS\system32\stmctrl.dll]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-06-21 12:28 188416]
"zBrowser Launcher"="C:\Programmi\Logitech\iTouch\iTouch.exe" [2003-12-01 12:38 892928]
"Adobe Photo Downloader"="C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 18:41 57344]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"NSLauncher"="C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 15:44 3100672]
"avgnt"="C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-27 11:37 262401]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 14:00 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IETI"="C:\Programmi\Skype\Phone\IEPlugin\unins000.exe" [ ]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmi\\MSN Messenger\\livecall.exe"=
"C:\\Programmi\\C6 Messenger\\plugin\\fsmodule\\C6FileSharing.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\Programmi\\C6 Messenger\\c6Messenger.exe"=
"C:\\Documents and Settings\\Angelo\\Dati applicazioni\\SopCast\\adv\\SopAdver.exe"=
"C:\\Programmi\\SopCast\\SopCast.exe"=
"C:\\Programmi\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=

R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-01-24 17:45]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2002-09-25 08:37]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;C:\WINDOWS\system32\DRIVERS\torususb.sys [2003-01-09 16:21]
R3 usbstor;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-09-07 14:00]
R3 X10Hid;X10 Hid Device;C:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 11:45]
S1 as6eio;as6eio;C:\WINDOWS\system32\drivers\as6eio.sys []

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-02 20:58:31
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-05-02 20.59.10
ComboFix-quarantined-files.txt 2008-05-02 18:59:03
ComboFix2.txt 2008-05-01 20:20:59
ComboFix3.txt 2008-04-25 15:04:25
ComboFix4.txt 2008-04-25 14:14:44
ComboFix5.txt 2008-04-23 14:21:39

9 Directory 53,098,209,280 byte disponibili
11 Directory 53,169,360,896 byte disponibili

179 --- E O F --- 2008-04-16 11:19:22
Top
Profilo Invia messaggio privato
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus Tutti i fusi orari sono GMT + 2 ore
Vai a Precedente  1, 2, 3, 4  Successivo
Pagina 2 di 4

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi