Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
HELP NON RIESCO AD ELIMINARE UN VIRUS
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus
Precedente :: Successivo  
Autore Messaggio
239427
Mortale devoto
Mortale devoto


Registrato: 04/10/07 12:39
Messaggi: 7

MessaggioInviato: 04 Ott 2007 12:53    Oggetto: HELP NON RIESCO AD ELIMINARE UN VIRUS Rispondi citando

UN SALUTO A TUTTO LO STAFF ED A TUTTI VOI DA UN NUOVO ISCRITTO


Chiedo un Vostro aiuto per debellare questo virus
ho provato ad eliminare la voce anche con Avanger ma rimane sempre li.
Grazie in anticipo dei consigli


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8.23.52, on 04/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Spyware Doctor\svcntaux.exe
C:\Programmi\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmon.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Spyware Doctor\SDTrayApp.exe
C:\Programmi\NETGEAR\WG111v2\WG111v2.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
C:\Programmi\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\6bef9f854d78f5c4b2e9a0259cdd4dd7\update\update.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Documents and Settings\Licciardello\Desktop\difesa sistema\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\dumprep.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {97B52B42-3798-410C-AC64-E271DB200B94} - C:\WINDOWS\system32\divxh.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: (no name) - {E8503882-230E-4012-9458-77D9277BD94B} - c:\windows\system32\btpanuij.dll
O3 - Toolbar: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Pirelli\Access Gateway USB Network\CnxTrApp.dll",AppEntry -REG "Pirelli\Access Gateway USB"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Programmi\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [SpyEmergency] "C:\Programmi\NETGATE\Spy Emergency 2007\SpyEmergency.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Programmi\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Visit &japanese keywords - res://C:\WINDOWS\DOWNLO~1\CnsMin.dll/203
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191273449671
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F5BC716E-2650-4B08-9235-C110CF95017F} (Connessione Tiscali) - http://selfcare.tiscali.it/scripts/oneclick/ConnessioneTiscali.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS1\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS3\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O20 - Winlogon Notify: mdplgzko - C:\WINDOWS\SYSTEM32\btpanuij.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9274 bytes
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 04 Ott 2007 13:24    Oggetto: Rispondi citando

Ciao 239427, Ciao

Potrebbe essere Vundo? Think

Scarica VundoFix.exe sul desktop

- Esegui VundoFix.exe
- Clicca Scan for Vundo.
- al termine della scansione, clicca Remove Vundo.
- ti chiede se vuoi eliminare i files infetti, clicca YES
- il tuo video diventerà nero durante la rimozione di Vundo.
- al termine ti chiederà di riavviare il pc, clicca OK.
- Copia qui il contenuto del log C:\vundofix.txt e un nuovo log di hijackthis.

Nota: VundoFix potrebbe non riuscire ad eliminare qualche file. In questo caso, VundoFix si avvierà automaticamente al riavvio del pc, ripeti le operazioni indicate sopra partendo da "Clicca Scan for Vundo" quando VundoFix apparirà al riavvio.

Per sicurezza, fai anche una passata con questo, avviandolo in modalità provvisoria.

PS: se vuoi, puoi presentarti qui
Top
Profilo Invia messaggio privato
239427
Mortale devoto
Mortale devoto


Registrato: 04/10/07 12:39
Messaggi: 7

MessaggioInviato: 04 Ott 2007 14:32    Oggetto: Rispondi citando

Grazie dell'aiuto.

Non ha trovato nulla pero le connessioni si moltiplicano.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14.28.12, on 04/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Spyware Doctor\svcntaux.exe
C:\Programmi\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Licciardello\Desktop\difesa sistema\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {97B52B42-3798-410C-AC64-E271DB200B94} - C:\WINDOWS\system32\divxh.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: (no name) - {E8503882-230E-4012-9458-77D9277BD94B} - c:\windows\system32\btpanuij.dll
O3 - Toolbar: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Pirelli\Access Gateway USB Network\CnxTrApp.dll",AppEntry -REG "Pirelli\Access Gateway USB"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Programmi\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [SpyEmergency] "C:\Programmi\NETGATE\Spy Emergency 2007\SpyEmergency.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Programmi\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Visit &japanese keywords - res://C:\WINDOWS\DOWNLO~1\CnsMin.dll/203
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191273449671
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F5BC716E-2650-4B08-9235-C110CF95017F} (Connessione Tiscali) - http://selfcare.tiscali.it/scripts/oneclick/ConnessioneTiscali.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS1\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS3\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O20 - Winlogon Notify: mdplgzko - C:\WINDOWS\SYSTEM32\btpanuij.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 7682 bytes




VundoFix V6.5.9

Checking Java version...

Sun Java not detected
Scan started at 13.56.49 04/10/2007

Listing files found while scanning....

No infected files were found.






[10/04/2007, 14:26:43] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Licciardello\Desktop\VirtumundoBeGone.exe" )
[10/04/2007, 14:26:48] - Detected System Information:
[10/04/2007, 14:26:48] - Windows Version: 5.1.2600, Service Pack 2
[10/04/2007, 14:26:48] - Current Username: (Admin)
[10/04/2007, 14:26:48] - Windows is in SAFE mode with Networking.
[10/04/2007, 14:26:48] - Searching for Browser Helper Objects:
[10/04/2007, 14:26:48] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Supporto di collegamento per Adobe PDF Reader)
[10/04/2007, 14:26:48] - BHO 2: {2e6f36ce-1217-4ba1-982f-24560c0eb677} (Multi Media Italy Toolbar)
[10/04/2007, 14:26:48] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/04/2007, 14:26:48] - BHO 4: {97B52B42-3798-410C-AC64-E271DB200B94} ()
[10/04/2007, 14:26:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2007, 14:26:48] - Checking for HKLM\...\Winlogon\Notify\divxh
[10/04/2007, 14:26:48] - Key not found: HKLM\...\Winlogon\Notify\divxh, continuing.
[10/04/2007, 14:26:48] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[10/04/2007, 14:26:48] - BHO 6: {E8503882-230E-4012-9458-77D9277BD94B} ()
[10/04/2007, 14:26:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2007, 14:26:48] - Checking for HKLM\...\Winlogon\Notify\btpanuij
[10/04/2007, 14:26:48] - Key not found: HKLM\...\Winlogon\Notify\btpanuij, continuing.
[10/04/2007, 14:26:48] - Finished Searching Browser Helper Objects
[10/04/2007, 14:26:48] - Finishing up...
[10/04/2007, 14:26:48] - Nothing found! Exiting...
Top
Profilo Invia messaggio privato
Orange
Dio maturo
Dio maturo


Registrato: 18/02/07 13:20
Messaggi: 2224
Residenza: Roma

MessaggioInviato: 04 Ott 2007 14:57    Oggetto: Rispondi citando

benvenuto anche da parte mia Smile

Citazione:
Nothing found! Exiting...

Vundo è sempre più difficile da eliminare. Evil or Very Mad
proviamo qualche altro tool di rimozione automatica, prima di passare alle maniere forti.

scarica ComboFix e salvalo sul desktop
avvialo e segui le istruzioni a video.
durante la scansione non usare il PC, altrimenti c'è il rischio di blocco.
finita la scansione, il tool aprirà il blocco note con dentro il logfile. copia il suo contenuto e mettilo qui.
Top
Profilo Invia messaggio privato
239427
Mortale devoto
Mortale devoto


Registrato: 04/10/07 12:39
Messaggi: 7

MessaggioInviato: 04 Ott 2007 21:56    Oggetto: Rispondi citando

Allego il file

Grazie



ComboFix 07-10-04.6 - Licciardello 2007-10-04 21.33.19.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.360 [GMT 2:00]
Running from: C:\Documents and Settings\Licciardello\Desktop\combofix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Programmi\ShoppingReport
C:\Programmi\Starware356
C:\Programmi\Starware356\brand.bmp
C:\Programmi\Starware356\icons\star_16.ico
C:\Programmi\Starware356\Starware356Config.xml
C:\WINDOWS\system32\_000003_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\_000011_.tmp.dll
C:\WINDOWS\system32\_000013_.tmp.dll
C:\WINDOWS\system32\btpanuij.dll . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_NHVQHSNH


((((((((((((((((((((((((( Files Created from 2007-09-04 to 2007-10-04 )))))))))))))))))))))))))))))))
.

2007-10-04 21:31 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-04 20:44 <DIR> d-------- C:\VundoFix Backups
2007-10-04 07:48 <DIR> d-------- C:\Documents and Settings\NetworkService\Menu Avvio
2007-10-04 01:12 <DIR> d-------- C:\Programmi\Nero
2007-10-04 01:12 <DIR> d-------- C:\Programmi\File comuni\Ahead
2007-10-04 01:12 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Nero
2007-10-03 01:09 <DIR> d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\GlarySoft
2007-10-03 01:03 <DIR> d-------- C:\Programmi\Registry Repair
2007-10-03 00:56 <DIR> d-------- C:\Programmi\XoftSpySE
2007-10-02 23:04 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-10-02 23:04 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-10-02 23:04 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-10-02 23:04 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-10-02 23:04 <DIR> d-a------ C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2007-10-02 23:04 <DIR> d-------- C:\Programmi\Spyware Doctor
2007-10-02 23:04 <DIR> d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\PC Tools
2007-10-02 23:03 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-02 22:28 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-10-02 14:06 <DIR> d-------- C:\Programmi\MSXML 4.0
2007-10-02 13:57 <DIR> d-------- C:\Programmi\MSXML 6.0
2007-10-02 10:13 <DIR> d-------- C:\Programmi\MSBuild
2007-10-02 10:07 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-10-02 10:03 <DIR> d-------- C:\Programmi\Reference Assemblies
2007-10-02 09:58 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-10-02 09:38 <DIR> d-------- C:\Programmi\Windows Media Connect 2
2007-10-02 09:18 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-10-02 09:18 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-10-02 09:07 <DIR> d-------- C:\WINDOWS\system32\it-it
2007-10-02 08:14 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2007-10-02 08:13 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2007-10-02 00:57 82,061 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-10-02 00:57 81,549 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-10-02 00:56 4,610,848 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-02 00:56 147,232 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-10-02 00:56 <DIR> d-------- C:\Programmi\Kaspersky Lab
2007-10-02 00:56 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2007-10-02 00:52 27,904 --a------ C:\WINDOWS\system32\drivers\VIAAGP1.SYS
2007-10-01 23:51 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-10-01 23:51 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-10-01 23:13 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-10-01 22:31 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys
2007-10-01 22:28 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2007-10-01 22:28 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-10-01 22:28 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2007-10-01 22:28 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-10-01 22:05 21,035 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-10-01 22:04 <DIR> d-------- C:\Programmi\NETGEAR
2007-10-01 08:15 <DIR> d-------- C:\Programmi\RogueRemover PRO
2007-09-30 22:27 <DIR> d-------- C:\Programmi\Yahoo!
2007-09-30 22:27 <DIR> d-------- C:\Programmi\CCleaner
2007-09-29 19:45 741,632 --a------ C:\WINDOWS\system32\jwbqrlnj.dat
2007-09-29 19:45 35,584 --a------ C:\WINDOWS\system32\zekjinxf.dat
2007-09-29 19:45 34,560 --a------ C:\WINDOWS\system32\nbbvnryu.dat
2007-09-29 19:45 246,545 --a------ C:\WINDOWS\system32\libssl32.dll
2007-09-29 19:45 118,528 --a------ C:\WINDOWS\system32\jfkhchwd.dat
2007-09-29 19:45 1,188,375 --a------ C:\WINDOWS\system32\libeay32.dll
2007-09-29 19:41 5,120 C:\WINDOWS\system32\drivers\dunwjolo.dat
2007-09-29 19:41 17,664 C:\WINDOWS\system32\drivers\akiveouy.dat
2007-09-29 19:40 36,352 --a------ C:\WINDOWS\system32\atl71h.dll
2007-09-29 19:40 <DIR> d-------- C:\WINDOWS\system32\AppCert
2007-09-29 19:39 91,648 --a------ C:\WINDOWS\system32\divxh.dll
2007-09-29 19:39 81,408 --a------ C:\WINDOWS\system32\btpanuij.dll
2007-09-18 20:22 <DIR> d-------- C:\Programmi\MultiMedia Italy Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-04 21:18 60620 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-04 21:18 14828 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-04 14:20 359808 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-10-04 01:21 --------- d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\Ahead
2007-10-04 00:47 --------- d-------- C:\Programmi\Ahead
2007-10-04 00:23 --------- d-------- C:\Programmi\Multi_Media_Italy
2007-10-04 00:18 --------- d-------- C:\Programmi\Lexmark X1100 Series
2007-10-04 00:11 --------- d-------- C:\Programmi\Google
2007-10-03 23:59 --------- d-------- C:\Programmi\GESTIONE CREDITI
2007-10-03 23:49 --------- d-------- C:\Programmi\DIFX
2007-10-02 23:51 --------- d-------- C:\Programmi\PC Connectivity Solution
2007-10-01 22:09 --------- d--h----- C:\Programmi\InstallShield Installation Information
2007-10-01 08:15 2015 -r-h----- C:\WINDOWS\system32\drivers\hosts
2007-09-30 22:17 --------- d-------- C:\Documents and Settings\All Users\Dati applicazioni\Zylom
2007-09-30 14:29 --------- d-------- C:\Programmi\eMule
2007-09-01 07:48 --------- d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\Nokia Multimedia Player
2007-08-30 19:04 --------- d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\PC Suite
2007-08-30 19:04 --------- d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\Nokia
2007-08-30 18:35 --------- d-------- C:\Documents and Settings\All Users\Dati applicazioni\PC Suite
2007-08-30 18:34 --------- d-------- C:\Programmi\Nokia
2007-08-30 18:34 --------- d-------- C:\Programmi\File comuni\PCSuite
2007-08-30 18:34 --------- d-------- C:\Programmi\File comuni\Nokia
2007-08-30 18:32 --------- d-------- C:\Documents and Settings\All Users\Dati applicazioni\Installations
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97B52B42-3798-410C-AC64-E271DB200B94}]
2003-12-10 16:36 91648 --a------ C:\WINDOWS\system32\divxh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E8503882-230E-4012-9458-77D9277BD94B}]
2007-10-02 23:29 81408 --a------ c:\windows\system32\btpanuij.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"VOBRegCheck"="C:\WINDOWS\System32\VOBREGCheck.exe" [2003-01-08 16:55]
"CnxTrApp"="C:\Programmi\Pirelli\Access Gateway USB Network\CnxTrApp.dll" [2004-04-20 17:24]
"Lexmark X1100 Series"="C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 17:01]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"AVP"="C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51]
"PCSuiteTrayApplication"="C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"NeroFilterCheck"="C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpyEmergency"="C:\Programmi\NETGATE\Spy Emergency 2007\SpyEmergency.exe" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:39]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
NETGEAR WG111v2 Smart Wizard.lnk - C:\Programmi\NETGEAR\WG111v2\WG111v2.exe [2006-09-06 03:12:50]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
NETGEAR WG111v2 Smart Wizard.lnk - C:\Programmi\NETGEAR\WG111v2\WG111v2.exe [2006-09-06 03:12:50]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d97caee-a20c-11db-b2bf-000b6a860ce5}]
AutoRun\command- F:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aadd4986-6f90-11dc-88cf-000b6a860ce5}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1919d7c-7244-11dc-8990-000fb5c4f4fd}]
Auto\command- infrom.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL infrom.exe

*Newly Created Service* - NHVQHSNH
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-04 21:39:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-04 21:41:58 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-10-04 21:41
.
--- E O F ---
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 05 Ott 2007 14:03    Oggetto: Rispondi citando

Avvia AVENGER
Clicca su input script manually
Clicca sulla lente d'ingrandimento
Inserisci queste righe:
Citazione:
Files to delete:
C:\WINDOWS\system32\jwbqrlnj.dat
C:\WINDOWS\system32\zekjinxf.dat
C:\WINDOWS\system32\nbbvnryu.dat
C:\WINDOWS\system32\jfkhchwd.dat
C:\WINDOWS\system32\drivers\dunwjolo.dat
C:\WINDOWS\system32\drivers\akiveouy.dat
C:\WINDOWS\system32\atl71h.dll
C:\WINDOWS\system32\divxh.dll
C:\WINDOWS\system32\btpanuij.dll

Registry keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97B52B42-3798-410C-AC64-E271DB200B94}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8503882-230E-4012-9458-77D9277BD94B}
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\notify\mdplgzko

Clicca su Done
Clicca sul semaforo
Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
Al termine dell'operazione, posta qui il risultato e un log aggiornato di hijackthis.
Top
Profilo Invia messaggio privato
239427
Mortale devoto
Mortale devoto


Registrato: 04/10/07 12:39
Messaggi: 7

MessaggioInviato: 06 Ott 2007 00:27    Oggetto: Rispondi citando

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\mjsvtkoq

*******************

Script file located at: \??\C:\vbninyxd.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\jwbqrlnj.dat deleted successfully.
File C:\WINDOWS\system32\zekjinxf.dat deleted successfully.
File C:\WINDOWS\system32\nbbvnryu.dat deleted successfully.
File C:\WINDOWS\system32\jfkhchwd.dat deleted successfully.


Could not open file C:\WINDOWS\system32\drivers\dunwjolo.dat for deletion
Deletion of file C:\WINDOWS\system32\drivers\dunwjolo.dat failed!

Could not process line:
C:\WINDOWS\system32\drivers\dunwjolo.dat
Status: 0xc0000022



Could not open file C:\WINDOWS\system32\drivers\akiveouy.dat for deletion
Deletion of file C:\WINDOWS\system32\drivers\akiveouy.dat failed!

Could not process line:
C:\WINDOWS\system32\drivers\akiveouy.dat
Status: 0xc0000022

File C:\WINDOWS\system32\atl71h.dll deleted successfully.


Could not open file C:\WINDOWS\system32\divxh.dll for deletion
Deletion of file C:\WINDOWS\system32\divxh.dll failed!

Could not process line:
C:\WINDOWS\system32\divxh.dll
Status: 0xc0000022



Could not open file C:\WINDOWS\system32\btpanuij.dll for deletion
Deletion of file C:\WINDOWS\system32\btpanuij.dll failed!

Could not process line:
C:\WINDOWS\system32\btpanuij.dll
Status: 0xc0000022



Could not open registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97B52B42-3798-410C-AC64-E271DB200B94} for deletion
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97B52B42-3798-410C-AC64-E271DB200B94} failed!
Status: 0xc0000022



Could not open registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8503882-230E-4012-9458-77D9277BD94B} for deletion
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8503882-230E-4012-9458-77D9277BD94B} failed!
Status: 0xc0000022



Could not open registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\notify\mdplgzko for deletion
Deletion of registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\notify\mdplgzko failed!
Status: 0xc0000022


Completed script processing.

*******************

Finished! Terminate.



=============================================


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0.15.00, on 06/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\lexpps.exe
C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmon.exe
C:\Programmi\NETGEAR\WG111v2\WG111v2.exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Licciardello\Desktop\difesa sistema\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {97B52B42-3798-410C-AC64-E271DB200B94} - C:\WINDOWS\system32\divxh.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: (no name) - {E8503882-230E-4012-9458-77D9277BD94B} - c:\windows\system32\btpanuij.dll
O3 - Toolbar: Multi Media Italy Toolbar - {2e6f36ce-1217-4ba1-982f-24560c0eb677} - C:\Programmi\Multi_Media_Italy\tbMul0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Pirelli\Access Gateway USB Network\CnxTrApp.dll",AppEntry -REG "Pirelli\Access Gateway USB"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [eepgvjee] C:\mvqtjhja.bat
O4 - HKCU\..\Run: [SpyEmergency] "C:\Programmi\NETGATE\Spy Emergency 2007\SpyEmergency.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Programmi\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Visit &japanese keywords - res://C:\WINDOWS\DOWNLO~1\CnsMin.dll/203
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191273449671
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F5BC716E-2650-4B08-9235-C110CF95017F} (Connessione Tiscali) - http://selfcare.tiscali.it/scripts/oneclick/ConnessioneTiscali.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS1\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS3\Services\Tcpip\..\{01172D6E-0BED-4917-8F4A-6547E89BF5E0}: NameServer = 213.205.32.70,213.205.36.70
O23 - Service: Adobe LM Service - Unknown owner - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programmi\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programmi\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8409 bytes



Ho rifatto anche COMBOFIX


ComboFix 07-10-04.6 - Licciardello 2007-10-06 0.17.19.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.168 [GMT 2:00]
Running from: C:\Documents and Settings\Licciardello\Desktop\combofix.exe
.

((((((((((((((((((((((((( Files Created from 2007-09-05 to 2007-10-05 )))))))))))))))))))))))))))))))
.

2007-10-04 20:44 <DIR> d-------- C:\VundoFix Backups
2007-10-04 07:48 <DIR> d-------- C:\Documents and Settings\NetworkService\Menu Avvio
2007-10-04 01:12 <DIR> d-------- C:\Programmi\Nero
2007-10-04 01:12 <DIR> d-------- C:\Programmi\File comuni\Ahead
2007-10-04 01:12 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Nero
2007-10-03 01:09 <DIR> d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\GlarySoft
2007-10-03 01:03 <DIR> d-------- C:\Programmi\Registry Repair
2007-10-03 00:56 <DIR> d-------- C:\Programmi\XoftSpySE
2007-10-02 23:04 <DIR> d-a------ C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2007-10-02 23:04 <DIR> d-------- C:\Programmi\Spyware Doctor
2007-10-02 23:04 <DIR> d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\PC Tools
2007-10-02 14:06 <DIR> d-------- C:\Programmi\MSXML 4.0
2007-10-02 13:57 <DIR> d-------- C:\Programmi\MSXML 6.0
2007-10-02 10:13 <DIR> d-------- C:\Programmi\MSBuild
2007-10-02 10:03 <DIR> d-------- C:\Programmi\Reference Assemblies
2007-10-02 09:38 <DIR> d-------- C:\Programmi\Windows Media Connect 2
2007-10-02 00:56 <DIR> d-------- C:\Programmi\Kaspersky Lab
2007-10-02 00:56 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2007-10-01 22:04 <DIR> d-------- C:\Programmi\NETGEAR
2007-10-01 08:15 <DIR> d-------- C:\Programmi\RogueRemover PRO
2007-09-30 22:27 <DIR> d-------- C:\Programmi\Yahoo!
2007-09-30 22:27 <DIR> d-------- C:\Programmi\CCleaner
2007-09-18 20:22 <DIR> d-------- C:\Programmi\MultiMedia Italy Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-06 00:17 148768 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-10-06 00:10 60788 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-06 00:10 4610848 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-06 00:10 14900 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-04 14:20 359808 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-10-04 01:21 --------- d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\Ahead
2007-10-04 00:47 --------- d-------- C:\Programmi\Ahead
2007-10-04 00:23 --------- d-------- C:\Programmi\Multi_Media_Italy
2007-10-04 00:18 --------- d-------- C:\Programmi\Lexmark X1100 Series
2007-10-04 00:11 --------- d-------- C:\Programmi\Google
2007-10-03 23:59 --------- d-------- C:\Programmi\GESTIONE CREDITI
2007-10-03 23:49 --------- d-------- C:\Programmi\DIFX
2007-10-02 23:51 --------- d-------- C:\Programmi\PC Connectivity Solution
2007-10-02 23:29 81408 --a------ C:\WINDOWS\system32\btpanuij.dll
2007-10-02 07:42 82061 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-10-02 07:42 81549 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-10-01 22:09 --------- d--h----- C:\Programmi\InstallShield Installation Information
2007-10-01 22:05 21035 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-10-01 08:15 2015 -r-h----- C:\WINDOWS\system32\drivers\hosts
2007-09-30 22:17 --------- d-------- C:\Documents and Settings\All Users\Dati applicazioni\Zylom
2007-09-30 14:29 --------- d-------- C:\Programmi\eMule
2007-09-29 19:45 246545 --a------ C:\WINDOWS\system32\libssl32.dll
2007-09-29 19:45 1188375 --a------ C:\WINDOWS\system32\libeay32.dll
2007-09-27 13:43 79688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-09-27 13:43 62280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-09-27 13:43 41288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-09-27 13:43 29000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-09-01 07:48 --------- d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\Nokia Multimedia Player
2007-08-30 19:04 --------- d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\PC Suite
2007-08-30 19:04 --------- d-------- C:\Documents and Settings\Licciardello\Dati applicazioni\Nokia
2007-08-30 18:35 --------- d-------- C:\Documents and Settings\All Users\Dati applicazioni\PC Suite
2007-08-30 18:34 --------- d-------- C:\Programmi\Nokia
2007-08-30 18:34 --------- d-------- C:\Programmi\File comuni\PCSuite
2007-08-30 18:34 --------- d-------- C:\Programmi\File comuni\Nokia
2007-08-30 18:32 --------- d-------- C:\Documents and Settings\All Users\Dati applicazioni\Installations
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
C:\WINDOWS\system32\drivers\dunwjolo.dat
C:\WINDOWS\system32\drivers\akiveouy.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97B52B42-3798-410C-AC64-E271DB200B94}]
2003-12-10 16:36 91648 --a------ C:\WINDOWS\system32\divxh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E8503882-230E-4012-9458-77D9277BD94B}]
2007-10-02 23:29 81408 --a------ c:\windows\system32\btpanuij.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"VOBRegCheck"="C:\WINDOWS\System32\VOBREGCheck.exe" [2003-01-08 16:55]
"CnxTrApp"="C:\Programmi\Pirelli\Access Gateway USB Network\CnxTrApp.dll" [2004-04-20 17:24]
"Lexmark X1100 Series"="C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 17:01]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"AVP"="C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51]
"PCSuiteTrayApplication"="C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"NeroFilterCheck"="C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
"eepgvjee"="C:\mvqtjhja.bat" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpyEmergency"="C:\Programmi\NETGATE\Spy Emergency 2007\SpyEmergency.exe" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:39]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
NETGEAR WG111v2 Smart Wizard.lnk - C:\Programmi\NETGEAR\WG111v2\WG111v2.exe [2006-09-06 03:12:50]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
NETGEAR WG111v2 Smart Wizard.lnk - C:\Programmi\NETGEAR\WG111v2\WG111v2.exe [2006-09-06 03:12:50]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R0 orzsfzos;orzsfzos;C:\WINDOWS\system32\drivers\akiveouy.dat
R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys
S0 elwbtcbl;elwbtcbl;C:\WINDOWS\system32\drivers\chmpbqnl.sys
S2 nhvqhsnh; archiviazione di massa USBSupport;C:\WINDOWS\System32\svchost.exe -k netsvcs
S4 Boonty Games;Boonty Games;"C:\Programmi\File comuni\BOONTY Shared\Service\Boonty.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d97caee-a20c-11db-b2bf-000b6a860ce5}]
AutoRun\command- F:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aadd4986-6f90-11dc-88cf-000b6a860ce5}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1919d7c-7244-11dc-8990-000fb5c4f4fd}]
Auto\command- infrom.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL infrom.exe

.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-06 00:20:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-06 0.22.20
C:\ComboFix-quarantined-files.txt ... 2007-10-06 00:22
C:\ComboFix2.txt ... 2007-10-04 21:41
.
--- E O F ---
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 06 Ott 2007 09:46    Oggetto: Rispondi citando

Purtroppo, non è servito! Evil or Very Mad
Mi sa che c'è un'infezione multipla, andiamo sul pesante... Twisted Evil
Fai questa Scansione con SystemScan e posta i logs su FreeFileHosting come indicato qui.
Top
Profilo Invia messaggio privato
239427
Mortale devoto
Mortale devoto


Registrato: 04/10/07 12:39
Messaggi: 7

MessaggioInviato: 06 Ott 2007 14:40    Oggetto: Rispondi citando

Fatto

Grazie sempre

link
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 06 Ott 2007 18:36    Oggetto: Rispondi citando

Apri il notepad, e copia/incolla questo codice
Codice:
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e3ec35a-72b3-11dc-8996-efe6fd47fa59}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aadd4986-6f90-11dc-88cf-000b6a860ce5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1919d7c-7244-11dc-8990-000fb5c4f4fd}]



poi salva il file col nome di fix.reg in C:\ (IMPORTANTE!)

Avvia AVENGER
Clicca su input script manually
Clicca sulla lente d'ingrandimento
Inserisci queste righe:
Citazione:
drivers to unload:
orzsfzos

Files to delete:
C:\WINDOWS\ppptiymx.txt
C:\WINDOWS\system32\drivers\akiveouy.dat
C:\WINDOWS\system32\btpanuij.dll.bak
C:\WINDOWS\system32\btpanuij.dll
C:\WINDOWS\system32\drivers\dunwjolo.dat
C:\WINDOWS\system32\drivers\atpc^xrd.sys
C:\WINDOWS\system32\drivers\chmpbqnl.sys
C:\WINDOWS\system32\drivers\sbsgiaia.sys

registry keys to delete:
HKLM\system\currentcontrolset\services\elwbtcbl
HKLM\system\currentcontrolset\services\Msiptlxnrnhs
HKLM\system\currentcontrolset\services\nhvqhsnh
HKLM\system\currentcontrolset\services\npkakqor
HKLM\system\currentcontrolset\services\orzsfzos
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97B52B42-3798-410C-AC64-E271DB200B94}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8503882-230E-4012-9458-77D9277BD94B}

Programs to launch on reboot:
C:\fix.reg

Clicca su Done
Clicca sul semaforo
Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
Al termine dell'operazione, posta qui il risultato.

Poi, scarica VirIt, installalo, aggiornalo (importante) e fai lo scan completo.

Spero di non aver tralasciato niente! Phew
Top
Profilo Invia messaggio privato
239427
Mortale devoto
Mortale devoto


Registrato: 04/10/07 12:39
Messaggi: 7

MessaggioInviato: 06 Ott 2007 22:31    Oggetto: Rispondi citando

Niente da fare sono sempre LI

Grazie dell'aiuto ma rinuncio ho formattato .......

GRAZIE
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 07 Ott 2007 17:26    Oggetto: Rispondi

Peccato. Sad
Sarebbe stato interessante capire come funzionava e se si poteva debellare senza formattare.
Immagino che tu non abbia più neanche i logs dei programmi. Sarebbe interessante vedere come ha reagito al tentativo di eliminazione. Think
Top
Profilo Invia messaggio privato
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus Tutti i fusi orari sono GMT + 2 ore
Pagina 1 di 1

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi