Precedente :: Successivo |
Autore |
Messaggio |
Alvin87 Mortale devoto

Registrato: 09/11/08 04:11 Messaggi: 6
|
Inviato: 09 Nov 2008 04:16 Oggetto: Problema con la connessione |
|
|
Ciao a tutti, sono nuovo del foro ed è un onore per me scrivere qui
Ma bando alle ciance...Ho un grosso problema con la connessione e perciò mi rivolgo a voi. Da diverso tempo la connessione mi casca spesso e volentieri, lasciandomi però riconnettere tranquillamente dopo 20 o 30 secondi. Il problema è che certi giorni ciò accade anche ogni 5 minuti e non ce la faccio più La cosa curiosa è che, ultimamente, dopo essermi riconnesso si disconnette immediatamente dicen protocollo ppp terminato, cosa che non so cosa vogli dire....
Che ne dite? proviamo a risolvere il problema insieme o mi tocca chiamare quelli di Libero e cazziarli?
Grazie a tutti! |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
Inviato: 09 Nov 2008 19:32 Oggetto: |
|
|
Ciao Alvin87 e benvenuto...
Vediamo se quelli di Libero c'entrano o meno.....ma non credo.
Fai queste operazioni di pulizia:
- Pulisci i files temporanei con ATF-Cleaner e/o CCleaner
- Segui le istruzioni di questo topic per usare MBAM.
- Segui le istruzioni di questo topic per eseguire combofix.
- Segui le istruzioni di questo topic per postare il log di HiJackThis.
- Riferisci con un nuovo messaggio in questa discussione dell'esito: se ci sono stati problemi particolari, ecc. ecc. E riporta:
- Carica il log di MBAM su WikiSend e posta il Forum Link che ti viene assegnato.
- Carica il log di Combofix su WikiSend e posta il Forum Link che ti viene assegnato.
- Carica il log di HiJackThis su WikiSend e posta il Forum Link che ti viene assegnato.
|
|
Top |
|
 |
Alvin87 Mortale devoto

Registrato: 09/11/08 04:11 Messaggi: 6
|
Inviato: 10 Nov 2008 01:30 Oggetto: |
|
|
OK
Grazie mille, faccio tutto o poi rispondo, spero di riuscire entro stasera, al max se ne parla per domani... |
|
Top |
|
 |
Alvin87 Mortale devoto

Registrato: 09/11/08 04:11 Messaggi: 6
|
Inviato: 10 Nov 2008 15:50 Oggetto: |
|
|
Allora, tutto fatto. Nessun particolare problema durant il processo, la cosa che mi turba è che nn ho trovato granchè coi 3 programmi, ma giudicate voi
Ah, ho avuto dei problemi con wiki e nn riesco a mettere nulla in linea, posto per ora qui i log completi, poi se magari riesco li uppo sempre su wiki e metto i link, sorry
Log di MBAM
Malwarebytes' Anti-Malware 1.30
Versione del database: 1378
Windows 5.1.2600 Service Pack 2
10/11/2008 14.30.58
mbam-log-2008-11-10 (14-30-58).txt
Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 194076
Tempo trascorso: 54 minute(s), 39 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
Log di COMBOFIX
ComboFix 08-11-09.01 - Peppalvino 2008-11-10 14:34:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.529 [GMT 1:00]
Eseguito da: d:\documents and settings\Peppalvino\Desktop\ComboFix.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\windows\Downloaded Program Files\setup.inf
d:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Creati Da 2008-10-10 al 2008-11-10 )))))))))))))))))))))))))))))))))))
.
2008-11-10 13:30 . 2008-11-10 13:30 142 --a------ d:\windows\system32\spupdsvc.inf
2008-11-10 13:29 . 2008-11-10 13:29 <DIR> d-------- d:\windows\LastGood
2008-11-10 00:26 . 2008-11-10 00:26 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Messenger Plus!
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Windows Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Messenger Plus! Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Circle Developement
2008-11-07 00:24 . 2008-11-10 00:48 <DIR> d-------- d:\programmi\Malwarebytes' Anti-Malware
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-10-22 16:28 38,496 --a------ d:\windows\system32\drivers\mbamswissarmy.sys
2008-11-07 00:24 . 2008-10-22 16:28 15,504 --a------ d:\windows\system32\drivers\mbam.sys
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\programmi\SUPERAntiSpyware
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:27 . 2008-11-06 23:27 <DIR> d-------- d:\programmi\Trend Micro
2008-11-06 23:26 . 2008-11-06 23:26 5,120 --ahs---- d:\windows\system32\Thumbs.db
2008-11-02 15:28 . 2008-11-02 15:30 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SPORE
2008-11-02 13:33 . 2008-11-02 13:33 <DIR> dr-h----- d:\documents and settings\Peppalvino\Dati applicazioni\SecuROM
2008-11-02 13:28 . 2008-11-02 13:28 <DIR> d-------- d:\programmi\Electronic Arts
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\windows\BarTr23
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\programmi\OfficePowerT
2008-10-28 20:48 . 2000-05-22 00:00 647,872 --a------ d:\windows\system32\MSComCt2.ocx
2008-10-28 20:48 . 2000-12-06 00:00 415,176 --a------ d:\windows\system32\Comct332.ocx
2008-10-28 20:48 . 1998-04-25 00:00 368,912 --a------ d:\windows\system32\vbar332.dll
2008-10-28 20:48 . 1998-08-05 00:00 150,528 --a------ d:\windows\system32\MSCmCIT.dll
2008-10-28 20:48 . 2001-03-13 14:49 140,288 --a------ d:\windows\system32\COMDLG32.OCX
2008-10-28 20:48 . 1998-06-24 00:00 137,000 --a------ d:\windows\system32\Msmapi32.ocx
2008-10-28 20:48 . 1998-08-05 00:00 63,488 --a------ d:\windows\system32\MSCc2IT.dll
2008-10-28 20:48 . 1998-08-05 00:00 33,792 --a------ d:\windows\system32\CmDlgIT.dll
2008-10-28 20:48 . 1998-08-05 00:00 28,672 --a------ d:\windows\system32\Cmct3IT.dll
2008-10-22 20:03 . 2008-11-10 13:38 <DIR> d-------- d:\windows\system32\CatRoot_bak
2008-10-22 20:02 . 2008-06-14 18:59 272,768 --------- d:\windows\system32\drivers\bthport.sys
2008-10-22 20:02 . 2008-06-14 18:59 272,768 -----c--- d:\windows\system32\dllcache\bthport.sys
2008-10-22 16:05 . 2008-10-22 16:07 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Spybot - Search & Destroy
2008-10-22 15:12 . 2008-11-09 02:49 <DIR> d-------- D:\VEXPLITE
2008-10-22 15:12 . 2008-11-05 23:02 40,960 --a------ d:\windows\system32\drivers\VIRAGTLT.SYS
2008-10-21 16:40 . 2008-10-21 16:40 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\KONAMI
2008-10-20 00:19 . 2008-10-20 00:19 <DIR> d-------- d:\programmi\Intelore
2008-10-20 00:08 . 2008-10-20 00:08 <DIR> d-------- d:\programmi\ElcomSoft
2008-10-15 23:14 . 2008-10-15 23:14 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SlySoft
2008-10-15 22:42 . 2008-10-17 17:00 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\DivX
2008-10-15 21:59 . 2008-10-15 21:59 <DIR> d-------- d:\programmi\DVDFab 5
2008-10-14 17:30 . 2008-10-14 17:30 <DIR> d-------- d:\programmi\Midway Home Entertainment
2008-10-14 17:18 . 2008-10-14 17:18 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 06:45 --------- d-----w d:\programmi\eMule Applejuice
2008-11-09 16:17 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\uTorrent
2008-11-09 13:32 --------- d-----w d:\programmi\MSN Messenger
2008-11-09 12:27 --------- d---a-w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2008-11-06 22:36 --------- d-----w d:\programmi\File comuni\Wise Installation Wizard
2008-11-02 12:26 --------- d--h--w d:\programmi\InstallShield Installation Information
2008-10-22 15:05 --------- d-----w d:\programmi\DivX
2008-10-22 15:05 --------- d-----w d:\programmi\DAP
2008-10-22 15:05 --------- d-----w d:\programmi\Alcohol Soft
2008-10-21 15:43 107,888 ----a-w d:\windows\system32\CmdLineExt.dll
2008-10-21 15:33 --------- d-----w d:\programmi\KONAMI
2008-10-15 22:24 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\DVD Shrink
2008-10-15 20:59 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Vso
2008-10-15 20:21 --------- d-----w d:\programmi\DVD Shrink
2008-09-30 21:55 --------- d-----w d:\programmi\PokerStars.NET
2008-09-30 21:54 --------- d-----w d:\programmi\Acclaim
2008-09-29 18:45 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Dev-Cpp
2008-09-28 09:06 --------- d-----w d:\programmi\Maxis
2008-09-26 23:05 --------- d-----w d:\programmi\Monte Cristo
2008-09-24 17:50 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\GetRightToGo
2008-09-22 13:14 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\SecondLife
2008-09-20 20:06 --------- d-----w d:\programmi\GiocoDigitale
2008-09-20 20:06 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\GiocoDigitale
2008-09-16 00:14 9,464 ------w d:\windows\system32\drivers\cdralw2k.sys
2008-09-16 00:14 9,336 ------w d:\windows\system32\drivers\cdr4_xp.sys
2008-09-16 00:14 524,288 ----a-w d:\windows\system32\DivXsm.exe
2008-09-16 00:14 43,528 ------w d:\windows\system32\drivers\PxHelp20.sys
2008-09-16 00:14 3,596,288 ----a-w d:\windows\system32\qt-dx331.dll
2008-09-16 00:14 129,784 ------w d:\windows\system32\pxafs.dll
2008-09-16 00:14 120,056 ------w d:\windows\system32\pxcpyi64.exe
2008-09-16 00:14 118,520 ------w d:\windows\system32\pxinsi64.exe
2008-09-16 00:12 81,920 ----a-w d:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w d:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w d:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w d:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w d:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w d:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w d:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w d:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w d:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w d:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w d:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w d:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w d:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w d:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w d:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w d:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w d:\windows\system32\DivXWMPExtType.dll
2008-09-15 15:38 1,846,016 ----a-w d:\windows\system32\win32k.sys
2008-09-11 21:35 --------- d-----w d:\programmi\SpeedSim
2008-09-10 11:34 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft
2008-09-05 22:30 952,360 ------w d:\windows\system32\SETB0.tmp
2008-09-05 22:30 267,304 ------w d:\windows\system32\SETAF.tmp
2008-08-20 05:35 662,016 ----a-w d:\windows\system32\wininet.dll
2008-08-14 13:42 2,139,648 ----a-w d:\windows\system32\ntoskrnl.exe
2008-08-14 13:42 2,019,328 ----a-w d:\windows\system32\ntkrnlpa.exe
2007-12-27 18:56 87,608 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\ezpinst.exe
2007-12-27 18:56 47,360 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\pcouffin.sys
.
Codice: | <pre>
----a-w 79,224 2007-09-06 10:06:09 d:\programmi\Alwil Software\Avast4\ashDisp .exe
----a-r 925,696 2005-05-20 09:11:06 d:\programmi\Analog Devices\Core\smax4pnp .exe
----a-w 153,136 2007-03-01 14:57:24 d:\programmi\File comuni\Nero\Lib\NeroCheck .exe
----a-w 454,144 2007-12-17 14:21:57 d:\programmi\SlySoft\AnyDVD\AnyDVD .exe
----a-w 15,360 2004-08-19 13:39:36 d:\windows\system32\ctfmon .exe
</pre> |
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MsnMsgr"="d:\programmi\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"updateMgr"="d:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Nokia.PCSync"="d:\programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="d:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-06-18 1122816]
"AnyDVD"="d:\programmi\SlySoft\AnyDVD\AnyDVDtray.exe" [N/A]
"SUPERAntiSpyware"="d:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="d:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SunJavaUpdateSched"="d:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NBKeyScan"="d:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"EPSON Stylus Photo R200 Series"="d:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE" [2003-09-11 99840]
"DownloadAccelerator"="d:\programmi\DAP\DAP.EXE" [2007-12-25 4576768]
"SoundMAXPnP"="d:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"QuickTime Task"="d:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"iTunesHelper"="d:\programmi\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"VIRIT LITE MONITOR"="d:\vexplite\MONLITE.EXE" [2008-11-08 249856]
"mirc"="c:\windows\WINCRA\mirc.exe" [N/A]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 d:\windows\system32\HdAShCut.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 d:\windows\system32\stmctrl.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
d:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - d:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
WinZip Quick Pick.lnk - d:\programmi\WinZip\WZQKPICK.EXE [2007-11-09 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 d:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\uTorrent\\utorrent.exe"=
"d:\\WINDOWS\\system32\\javaw.exe"=
"c:\\File installazione\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\DAP\\DAP.exe"=
"d:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"d:\\Programmi\\MSN Messenger\\livecall.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"d:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"d:\\Programmi\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\iTunes\\iTunes.exe"=
"d:\\Documents and Settings\\Peppalvino\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
R0 VIRAGTLT;VIRAGTLT;d:\windows\system32\drivers\VIRAGTLT.SYS [2008-11-05 40960]
R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 Stmatm;ATM/ADSL miniport;d:\windows\system32\DRIVERS\stmatm.sys [2002-09-25 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;d:\windows\system32\DRIVERS\torususb.sys [2003-01-09 527980]
S2 viritsvclite;Virit eXplorer Lite;d:\vexplite\viritsvc.exe [2008-11-08 57344]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01933866-a05c-11dd-80e5-a63d096a699a}]
\Shell\Auto\command - H:\UFO.exe
\Shell\AutoRun\command - d:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9910d7b6-9144-11dc-bd7a-fa14b2e46ed4}]
\Shell\Auto\command - H:\UFO.exe
\Shell\AutoRun\command - d:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e24cea-7cee-11dd-8070-a706b2a4527d}]
\Shell\Auto\command - UFO.exe
\Shell\AutoRun\command - d:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
2008-10-31 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.
.
------- Supplementare di scansione -------
.
FireFox -: Profile - d:\documents and settings\Peppalvino\Dati applicazioni\Mozilla\Firefox\Profiles\juhf1pjb.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://italian.eazel.com/it/index.php?rvs=hompag&d=79919291
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 14:36:17
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-11-10 14:37:59
ComboFix-quarantined-files.txt 2008-11-10 13:37:04
Pre-Run: 37,076,447,232 byte disponibili
Post-Run: 39,434,362,880 byte disponibili
222 --- E O F --- 2008-11-10 12:31:04
Log di HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14.42.51, on 10/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
D:\Programmi\Alwil Software\Avast4\ashServ.exe
D:\Programmi\Analog Devices\SoundMAX\Smax4.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
D:\Programmi\Java\jre1.6.0_07\bin\jusched.exe
D:\Programmi\Analog Devices\Core\smax4pnp.exe
D:\VEXPLITE\MONLITE.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Programmi\Nokia\Nokia PC Suite 7\PCSync2.exe
D:\Programmi\WinZip\WZQKPICK.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
D:\Programmi\PC Connectivity Solution\ServiceLayer.exe
D:\WINDOWS\system32\WgaTray.exe
D:\Programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
D:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
D:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
D:\Programmi\MSN Messenger\usnsvc.exe
D:\WINDOWS\system32\notepad.exe
D:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\explorer.exe
D:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Programmi\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NBKeyScan] "D:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [DownloadAccelerator] "D:\Programmi\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] D:\VEXPLITE\MONLITE.EXE
O4 - HKLM\..\Run: [mirc] C:\WINDOWS\WINCRA\mirc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] "D:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Nokia.PCSync] "D:\Programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "D:\Programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [AnyDVD] D:\Programmi\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = D:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Clean Traces - D:\Programmi\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - D:\Programmi\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\Programmi\DAP\dapextie2.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: InterCasino Italia - {3543D964-CE64-47E6-B730-152732DAF0E6} - http://italia.intercasino.com/ (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: InterCasino Italia - {3543D964-CE64-47E6-B730-152732DAF0E6} - http://italia.intercasino.com/ (file missing) (HKCU)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: !SASWinLogon - D:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - D:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - D:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - D:\VEXPLITE\viritsvc.exe
--
End of file - 7753 bytes
Ecco qua, che mi dite? Attendo impaziente e intanto inizio a ringraziarvi  |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
Inviato: 10 Nov 2008 16:08 Oggetto: |
|
|
Alvin87 ha scritto: | Allora, tutto fatto. Nessun particolare problema durant il processo, la cosa che mi turba è che nn ho trovato granchè coi 3 programmi, ma giudicate voi
|
Infatti, non è proprio così;
avete quasi tutti le chiavette/periferiche USB infettate;
I logs, non vanno osservati solo per ciò che eliminano, ma anche su ciò che contengono, in particolare Combofix, se guardi attentamente, c'è il famoso UFO.exe, che non è un oggetto non identificato, ma un virus vero e proprio, che si trasferisce, sui PC, e viceversa, attraverso le chiavette USB.
Dopo queste premessa, iniziamo con la pulizia.
disattiva momentaneamente il riconoscimento automatico delle periferiche USB;
serve il programma TweakUI scaricabile da questa pagina e installalo.
Una volta installato, eseguilo e procedi con questi passaggi:
Citazione: | Espandi la sezione My Computer
Espandi la sottosezione Autoplay
Spostati in Types
Togli il segno di spunta a Enable Autoplay for removable drives
Clicca su Apply
Chiudi TweakUI
PS: Con Espandi intendo: clicca sul simbolo [+] di fianco alle voci che ti ho indicato
Da questo momento tutti gli apparati USB smetteranno di avviarsi automaticamente.
Inserisci le tue chiavette e fai un check delle stesse con il tuo antivirus.
Quando sei sicuro che tutto è a posto, puoi riabilitare l'avvio automatico, rifacendo lo stesso percorso che ti ho indicato. |
Adesso crea col blocco note un file di testo mettendoci queste scritte:
Citazione: | RenV::
d:\programmi\Alwil Software\Avast4\ashDisp .exe
d:\programmi\Analog Devices\Core\smax4pnp .exe
d:\programmi\File comuni\Nero\Lib\NeroCheck .exe
d:\programmi\SlySoft\AnyDVD\AnyDVD .exe
d:\windows\system32\ctfmon .exe
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01933866-a05c-11dd-80e5-a63d096a699a}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9910d7b6-9144-11dc-bd7a-fa14b2e46ed4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e24cea-7cee-11dd-8070-a706b2a4527d}]
|
Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:
Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix.
Prova poi a pulire le periferiche USB usando il tool Perlovga Removal Tool |
|
Top |
|
 |
Alvin87 Mortale devoto

Registrato: 09/11/08 04:11 Messaggi: 6
|
Inviato: 10 Nov 2008 16:33 Oggetto: |
|
|
Ecco il log, preciso che nn sapevo che riavviasse il pc e purtroppo avevo in esecuzione automatica messenger e antivir che però ho chiuso immediatamente, nn credo abbiano dato problemi....
ComboFix 08-11-09.04 - Peppalvino 2008-11-10 15.20.35.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.517 [GMT 1:00]
Eseguito da: d:\documents and settings\Peppalvino\Desktop\ComboFix.exe
Interruttori di comando utilizzati :: d:\documents and settings\Peppalvino\Desktop\CFScript.txt.txt
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.
((((((((((((((((((((((((( Files Creati Da 2008-10-10 al 2008-11-10 )))))))))))))))))))))))))))))))))))
.
2008-11-10 15:14 . 2003-06-25 16:05 266,360 --a------ d:\windows\system32\TweakUI.exe
2008-11-10 15:14 . 2002-06-21 15:09 160,217 --a------ d:\windows\system32\PowerToysLicense.rtf
2008-11-10 00:26 . 2008-11-10 00:26 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Messenger Plus!
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Windows Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Messenger Plus! Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Circle Developement
2008-11-07 00:24 . 2008-11-10 00:48 <DIR> d-------- d:\programmi\Malwarebytes' Anti-Malware
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-10-22 16:28 38,496 --a------ d:\windows\system32\drivers\mbamswissarmy.sys
2008-11-07 00:24 . 2008-10-22 16:28 15,504 --a------ d:\windows\system32\drivers\mbam.sys
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\programmi\SUPERAntiSpyware
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:27 . 2008-11-06 23:27 <DIR> d-------- d:\programmi\Trend Micro
2008-11-06 23:26 . 2008-11-06 23:26 5,120 --ahs---- d:\windows\system32\Thumbs.db
2008-11-02 15:28 . 2008-11-02 15:30 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SPORE
2008-11-02 13:33 . 2008-11-02 13:33 <DIR> dr-h----- d:\documents and settings\Peppalvino\Dati applicazioni\SecuROM
2008-11-02 13:28 . 2008-11-02 13:28 <DIR> d-------- d:\programmi\Electronic Arts
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\windows\BarTr23
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\programmi\OfficePowerT
2008-10-28 20:48 . 2000-05-22 00:00 647,872 --a------ d:\windows\system32\MSComCt2.ocx
2008-10-28 20:48 . 2000-12-06 00:00 415,176 --a------ d:\windows\system32\Comct332.ocx
2008-10-28 20:48 . 1998-04-25 00:00 368,912 --a------ d:\windows\system32\vbar332.dll
2008-10-28 20:48 . 1998-08-05 00:00 150,528 --a------ d:\windows\system32\MSCmCIT.dll
2008-10-28 20:48 . 2001-03-13 14:49 140,288 --a------ d:\windows\system32\COMDLG32.OCX
2008-10-28 20:48 . 1998-06-24 00:00 137,000 --a------ d:\windows\system32\Msmapi32.ocx
2008-10-28 20:48 . 1998-08-05 00:00 63,488 --a------ d:\windows\system32\MSCc2IT.dll
2008-10-28 20:48 . 1998-08-05 00:00 33,792 --a------ d:\windows\system32\CmDlgIT.dll
2008-10-28 20:48 . 1998-08-05 00:00 28,672 --a------ d:\windows\system32\Cmct3IT.dll
2008-10-22 20:03 . 2008-11-10 15:04 <DIR> d-------- d:\windows\system32\CatRoot_bak
2008-10-22 20:02 . 2008-06-14 18:59 272,768 --------- d:\windows\system32\drivers\bthport.sys
2008-10-22 20:02 . 2008-06-14 18:59 272,768 -----c--- d:\windows\system32\dllcache\bthport.sys
2008-10-22 16:05 . 2008-10-22 16:07 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Spybot - Search & Destroy
2008-10-22 15:12 . 2008-11-09 02:49 <DIR> d-------- D:\VEXPLITE
2008-10-22 15:12 . 2008-11-05 23:02 40,960 --a------ d:\windows\system32\drivers\VIRAGTLT.SYS
2008-10-21 16:40 . 2008-10-21 16:40 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\KONAMI
2008-10-20 00:19 . 2008-10-20 00:19 <DIR> d-------- d:\programmi\Intelore
2008-10-20 00:08 . 2008-10-20 00:08 <DIR> d-------- d:\programmi\ElcomSoft
2008-10-15 23:14 . 2008-10-15 23:14 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SlySoft
2008-10-15 22:42 . 2008-10-17 17:00 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\DivX
2008-10-15 21:59 . 2008-10-15 21:59 <DIR> d-------- d:\programmi\DVDFab 5
2008-10-14 17:30 . 2008-10-14 17:30 <DIR> d-------- d:\programmi\Midway Home Entertainment
2008-10-14 17:18 . 2008-10-14 17:18 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 06:45 --------- d-----w d:\programmi\eMule Applejuice
2008-11-09 16:17 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\uTorrent
2008-11-09 13:32 --------- d-----w d:\programmi\MSN Messenger
2008-11-09 12:27 --------- d---a-w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2008-11-06 22:36 --------- d-----w d:\programmi\File comuni\Wise Installation Wizard
2008-11-02 12:26 --------- d--h--w d:\programmi\InstallShield Installation Information
2008-10-22 15:05 --------- d-----w d:\programmi\DivX
2008-10-22 15:05 --------- d-----w d:\programmi\DAP
2008-10-22 15:05 --------- d-----w d:\programmi\Alcohol Soft
2008-10-21 15:33 --------- d-----w d:\programmi\KONAMI
2008-10-15 22:24 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\DVD Shrink
2008-10-15 20:59 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Vso
2008-10-15 20:21 --------- d-----w d:\programmi\DVD Shrink
2008-09-30 21:55 --------- d-----w d:\programmi\PokerStars.NET
2008-09-30 21:54 --------- d-----w d:\programmi\Acclaim
2008-09-29 18:45 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Dev-Cpp
2008-09-28 09:06 --------- d-----w d:\programmi\Maxis
2008-09-26 23:05 --------- d-----w d:\programmi\Monte Cristo
2008-09-24 17:50 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\GetRightToGo
2008-09-22 13:14 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\SecondLife
2008-09-20 20:06 --------- d-----w d:\programmi\GiocoDigitale
2008-09-20 20:06 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\GiocoDigitale
2008-09-16 00:14 9,464 ------w d:\windows\system32\drivers\cdralw2k.sys
2008-09-16 00:14 9,336 ------w d:\windows\system32\drivers\cdr4_xp.sys
2008-09-16 00:14 43,528 ------w d:\windows\system32\drivers\PxHelp20.sys
2008-09-11 21:35 --------- d-----w d:\programmi\SpeedSim
2008-09-10 11:34 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft
2007-12-27 18:56 87,608 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\ezpinst.exe
2007-12-27 18:56 47,360 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\pcouffin.sys
.
Codice: | <pre>
----a-w 79,224 2007-09-06 10:06:09 d:\programmi\Alwil Software\Avast4\ashDisp .exe
----a-r 925,696 2005-05-20 09:11:06 d:\programmi\Analog Devices\Core\smax4pnp .exe
</pre> |
((((((((((((((((((((((((((((( snapshot@2008-11-10_14.36.47.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-03 20:32:22 231,552 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ac97ali.sys
- 2004-08-03 20:32:32 84,480 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ac97via.sys
- 2004-08-03 20:32:24 10,880 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\admjoy.sys
- 2004-08-03 20:31:20 36,224 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\an983.sys
- 2004-08-03 20:29:30 56,623 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1btxx.sys
- 2004-08-03 20:29:30 11,615 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1mdxx.sys
- 2004-08-03 20:29:30 12,047 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1pdxx.sys
- 2004-08-03 20:29:32 30,671 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1raxx.sys
- 2004-08-03 20:29:32 63,663 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1rvxx.sys
- 2004-08-03 20:29:32 26,367 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1snxx.sys
- 2004-08-03 20:29:32 21,343 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1ttxx.sys
- 2004-08-03 20:29:32 36,463 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1tuxx.sys
- 2004-08-03 20:29:32 29,455 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1xbxx.sys
- 2004-08-03 20:29:32 34,735 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati1xsxx.sys
- 2004-08-19 13:23:38 327,168 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati2mtaa.sys
- 2004-08-19 13:23:40 701,440 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ati2mtag.sys
- 2004-08-03 20:29:28 57,856 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinbtxx.sys
- 2004-08-03 20:29:30 13,824 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinmdxx.sys
- 2004-08-03 20:29:30 14,336 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinpdxx.sys
- 2004-08-03 20:29:30 52,224 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinraxx.sys
- 2004-08-03 20:29:32 104,960 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinrvxx.sys
- 2004-08-03 20:29:32 28,672 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinsnxx.sys
- 2004-08-03 20:29:32 13,824 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinttxx.sys
- 2004-08-03 20:29:32 73,216 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atintuxx.sys
- 2004-08-03 20:29:32 31,744 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinxbxx.sys
- 2004-08-03 20:29:32 63,488 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\atinxsxx.sys
- 2004-08-03 20:32:26 48,640 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\cwrwdm.sys
- 2004-08-19 13:22:30 121,344 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\epcl5res.dll
- 2004-08-03 20:32:28 137,088 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\essm2e.sys
- 2004-08-03 20:31:24 34,173 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\forehe.sys
- 2004-08-03 20:41:48 220,032 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\hsfbs2s2.sys
- 2004-08-03 20:41:50 685,056 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\hsfcxts2.sys
- 2004-08-03 20:41:56 1,041,536 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\hsfdpsp2.sys
- 2004-08-03 20:29:38 161,020 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\i81xnt5.sys
- 2008-04-13 17:13:42 424,448 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\licdll.dll
- 2004-08-19 13:31:46 607,292 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ltmdmnt.sys
- 2004-08-19 13:31:48 422,272 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ltmdmntt.sys
- 2004-08-03 20:39:32 20,864 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\lwadihid.sys
- 2004-08-03 20:41:56 11,868 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\mdmxsdk.sys
- 2004-08-03 20:41:40 126,686 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\mtlmnt5.sys
- 2004-08-03 20:41:38 1,309,184 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\mtlstrm.sys
- 2004-08-03 20:29:38 452,736 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\mtxparhm.sys
- 2004-08-19 13:33:24 132,695 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\netwlan5.sys
- 2006-12-30 17:27:08 4,569 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\new\secupd.dat
- 2004-08-03 20:41:40 180,360 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\ntmtlfax.sys
- 2004-08-03 20:29:56 1,897,408 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\nv4_mini.sys
- 2004-08-03 20:31:24 29,502 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\pca200e.sys
- 2004-08-03 20:06:18 169,984 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\pcx500.sys
- 2004-08-03 20:41:40 13,776 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\recagent.sys
- 2004-08-03 20:31:34 20,992 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\rtl8139.sys
- 2004-08-03 20:29:52 166,912 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\s3gnbm.sys
- 2008-04-13 17:13:50 1,001,472 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\setupapi.dll
- 2004-08-03 20:31:36 32,768 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\sisnic.sys
- 2004-08-03 20:31:42 63,547 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\sla30nd5.sys
- 2004-08-03 20:41:42 129,535 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\slnt7554.sys
- 2004-08-03 20:41:44 404,990 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\slntamr.sys
- 2004-08-03 20:41:46 95,424 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\slnthal.sys
- 2004-08-03 20:41:46 13,240 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\slwdmsup.sys
- 2008-04-13 17:13:52 438,272 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spcompat.dll
- 2007-08-10 06:20:24 18,808 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spmsg.dll
- 2008-04-13 17:14:22 11,264 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spnpinst.exe
- 2007-08-10 06:20:24 33,656 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\sprecovr.exe
- 2007-08-10 06:20:24 233,848 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spuninst.exe
- 2007-08-10 06:20:26 26,488 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\spupdsvc.exe
- 2008-04-13 17:14:08 8,192 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\fixccs.exe
- 2008-04-13 17:14:16 6,656 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\nv4prep.exe
- 2008-04-13 17:13:50 1,001,472 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\setupapi.dll
- 2008-04-13 17:13:52 438,272 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\spcompat.dll
- 2007-08-10 06:20:24 26,488 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\spcustom.dll
- 2008-04-13 17:14:22 11,264 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\spnpinst.exe
- 2007-08-10 06:20:26 763,768 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\update.exe
- 2007-08-10 06:20:34 402,296 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\update\updspapi.dll
- 2004-08-19 13:28:22 32,384 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\usb101et.sys
- 2004-08-03 20:29:38 12,415 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv01nt.sys
- 2004-08-03 20:29:38 12,127 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv02nt.sys
- 2004-08-03 20:29:38 11,775 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv05nt.sys
- 2004-08-03 20:29:40 11,807 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv07nt.sys
- 2004-08-03 20:29:40 11,295 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv08nt.sys
- 2004-08-03 20:29:42 11,871 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv09nt.sys
- 2004-08-03 20:29:42 11,935 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wadv11nt.sys
- 2004-08-03 20:29:42 29,311 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv01nt.sys
- 2004-08-03 20:29:44 19,551 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv02nt.sys
- 2004-08-03 20:29:44 33,599 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv04nt.sys
- 2004-08-03 20:29:46 22,271 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv06nt.sys
- 2004-08-03 20:29:46 25,471 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\watv10nt.sys
- 2004-08-03 20:29:46 23,615 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wch7xxnt.sys
- 2004-08-03 20:31:28 154,624 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wlluc48.sys
- 2004-08-03 20:29:48 12,063 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wsiintxx.sys
- 2004-08-03 20:29:50 19,455 ----a-w d:\windows\SoftwareDistribution\Download\fc8deab818fa7e7ffabfc43e34347907\wvchntxx.sys
- 2007-04-10 13:00:54 236,928 ------w d:\windows\system32\WgaLogon.dll
+ 2008-09-05 22:30:52 267,304 ----a-w d:\windows\system32\WgaLogon.dll
- 2007-04-10 13:01:38 337,280 ------w d:\windows\system32\WgaTray.exe
+ 2008-09-05 22:30:06 952,360 ----a-w d:\windows\system32\WgaTray.exe
+ 2008-11-10 14:23:54 16,384 ----atw d:\windows\Temp\Perflib_Perfdata_4e4.dat
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MsnMsgr"="d:\programmi\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"updateMgr"="d:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Nokia.PCSync"="d:\programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="d:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-06-18 1122816]
"AnyDVD"="d:\programmi\SlySoft\AnyDVD\AnyDVDtray.exe" [N/A]
"SUPERAntiSpyware"="d:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="d:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NBKeyScan"="d:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"EPSON Stylus Photo R200 Series"="d:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE" [2003-09-11 99840]
"DownloadAccelerator"="d:\programmi\DAP\DAP.EXE" [2007-12-25 4576768]
"SoundMAXPnP"="d:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"QuickTime Task"="d:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"iTunesHelper"="d:\programmi\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"VIRIT LITE MONITOR"="d:\vexplite\MONLITE.EXE" [2008-11-08 249856]
"mirc"="c:\windows\WINCRA\mirc.exe" [N/A]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 d:\windows\system32\HdAShCut.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 d:\windows\system32\stmctrl.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
d:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - d:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
WinZip Quick Pick.lnk - d:\programmi\WinZip\WZQKPICK.EXE [2007-11-09 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 d:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\uTorrent\\utorrent.exe"=
"d:\\WINDOWS\\system32\\javaw.exe"=
"c:\\File installazione\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\DAP\\DAP.exe"=
"d:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"d:\\Programmi\\MSN Messenger\\livecall.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"d:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"d:\\Programmi\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\iTunes\\iTunes.exe"=
"d:\\Documents and Settings\\Peppalvino\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
R0 VIRAGTLT;VIRAGTLT;d:\windows\system32\drivers\VIRAGTLT.SYS [2008-11-05 40960]
R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 viritsvclite;Virit eXplorer Lite;d:\vexplite\viritsvc.exe [2008-11-08 57344]
R3 Stmatm;ATM/ADSL miniport;d:\windows\system32\DRIVERS\stmatm.sys [2002-09-25 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;d:\windows\system32\DRIVERS\torususb.sys [2003-01-09 527980]
.
Contenuto della cartella 'Scheduled Tasks'
2008-10-31 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 15:24:37
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
d:\windows\system32\ati2evxx.exe
d:\windows\system32\ati2evxx.exe
d:\programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
d:\programmi\Alwil Software\Avast4\aswUpdSv.exe
d:\programmi\Alwil Software\Avast4\ashServ.exe
d:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\programmi\Nero\Nero8\Nero BackItUp\NBService.exe
d:\windows\system32\wdfmgr.exe
d:\programmi\Alwil Software\Avast4\ashMaiSv.exe
d:\programmi\Alwil Software\Avast4\ashWebSv.exe
d:\windows\system32\WgaTray.exe
d:\windows\system32\rundll32.exe
d:\programmi\iPod\bin\iPodService.exe
d:\programmi\PC Connectivity Solution\ServiceLayer.exe
d:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
d:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
d:\programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
.
**************************************************************************
.
Ora fine scansione: 2008-11-10 15:30:32 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-11-10 14:30:28
ComboFix2.txt 2008-11-10 13:38:00
Pre-Run: 39.596.707.840 byte disponibili
Post-Run: 39,595,253,760 byte disponibili
292 --- E O F --- 2008-11-10 12:31:04 |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
Inviato: 10 Nov 2008 16:44 Oggetto: |
|
|
Gran parte dell'operazione è riuscita;
devi rifare l'operazione con questi file, e tieni l'antivirus disattivato:
Citazione: | RenV::
d:\programmi\Alwil Software\Avast4\ashDisp .exe
d:\programmi\Analog Devices\Core\smax4pnp .exe |
Inoltre, ho visto che hai due antivirus, così non ha protezione perchè vanno in conflitto; ho visto che possiedi Virit, quindi disinstalla Avast;
quì la discussione su come procedere; oppure installa Avira Antivir, se decidi di non tenere VirIT. |
|
Top |
|
 |
Alvin87 Mortale devoto

Registrato: 09/11/08 04:11 Messaggi: 6
|
Inviato: 10 Nov 2008 17:03 Oggetto: |
|
|
Ennesimo log, grazie per la pazienza e per la disponibilità...
ComboFix 08-11-09.04 - Peppalvino 2008-11-10 15:52:15.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.645 [GMT 1:00]
Eseguito da: d:\documents and settings\Peppalvino\Desktop\ComboFix.exe
Interruttori di comando utilizzati :: d:\documents and settings\Peppalvino\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
.
((((((((((((((((((((((((( Files Creati Da 2008-10-10 al 2008-11-10 )))))))))))))))))))))))))))))))))))
.
2008-11-10 15:14 . 2003-06-25 16:05 266,360 --a------ d:\windows\system32\TweakUI.exe
2008-11-10 15:14 . 2002-06-21 15:09 160,217 --a------ d:\windows\system32\PowerToysLicense.rtf
2008-11-10 00:26 . 2008-11-10 00:26 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Messenger Plus!
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Windows Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Messenger Plus! Live
2008-11-09 14:32 . 2008-11-09 14:32 <DIR> d-------- d:\programmi\Circle Developement
2008-11-07 00:24 . 2008-11-10 00:48 <DIR> d-------- d:\programmi\Malwarebytes' Anti-Malware
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-11-07 00:24 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes
2008-11-07 00:24 . 2008-10-22 16:28 38,496 --a------ d:\windows\system32\drivers\mbamswissarmy.sys
2008-11-07 00:24 . 2008-10-22 16:28 15,504 --a------ d:\windows\system32\drivers\mbam.sys
2008-11-06 23:36 . 2008-11-10 15:47 <DIR> d-------- d:\programmi\SUPERAntiSpyware
2008-11-06 23:36 . 2008-11-10 15:47 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:36 . 2008-11-06 23:36 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SUPERAntiSpyware.com
2008-11-06 23:27 . 2008-11-06 23:27 <DIR> d-------- d:\programmi\Trend Micro
2008-11-06 23:26 . 2008-11-06 23:26 5,120 --ahs---- d:\windows\system32\Thumbs.db
2008-11-02 15:28 . 2008-11-02 15:30 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\SPORE
2008-11-02 13:33 . 2008-11-02 13:33 <DIR> dr-h----- d:\documents and settings\Peppalvino\Dati applicazioni\SecuROM
2008-11-02 13:28 . 2008-11-02 13:28 <DIR> d-------- d:\programmi\Electronic Arts
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\windows\BarTr23
2008-10-28 20:48 . 2008-10-28 20:49 <DIR> d-------- d:\programmi\OfficePowerT
2008-10-28 20:48 . 2000-05-22 00:00 647,872 --a------ d:\windows\system32\MSComCt2.ocx
2008-10-28 20:48 . 2000-12-06 00:00 415,176 --a------ d:\windows\system32\Comct332.ocx
2008-10-28 20:48 . 1998-04-25 00:00 368,912 --a------ d:\windows\system32\vbar332.dll
2008-10-28 20:48 . 1998-08-05 00:00 150,528 --a------ d:\windows\system32\MSCmCIT.dll
2008-10-28 20:48 . 2001-03-13 14:49 140,288 --a------ d:\windows\system32\COMDLG32.OCX
2008-10-28 20:48 . 1998-06-24 00:00 137,000 --a------ d:\windows\system32\Msmapi32.ocx
2008-10-28 20:48 . 1998-08-05 00:00 63,488 --a------ d:\windows\system32\MSCc2IT.dll
2008-10-28 20:48 . 1998-08-05 00:00 33,792 --a------ d:\windows\system32\CmDlgIT.dll
2008-10-28 20:48 . 1998-08-05 00:00 28,672 --a------ d:\windows\system32\Cmct3IT.dll
2008-10-22 20:03 . 2008-11-10 15:04 <DIR> d-------- d:\windows\system32\CatRoot_bak
2008-10-22 20:02 . 2008-06-14 18:59 272,768 --------- d:\windows\system32\drivers\bthport.sys
2008-10-22 20:02 . 2008-06-14 18:59 272,768 -----c--- d:\windows\system32\dllcache\bthport.sys
2008-10-22 16:05 . 2008-10-22 16:07 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\Spybot - Search & Destroy
2008-10-22 15:12 . 2008-11-10 15:55 <DIR> d-------- D:\VEXPLITE
2008-10-22 15:12 . 2008-11-05 23:02 40,960 --a------ d:\windows\system32\drivers\VIRAGTLT.SYS
2008-10-21 16:40 . 2008-10-21 16:40 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\KONAMI
2008-10-20 00:19 . 2008-10-20 00:19 <DIR> d-------- d:\programmi\Intelore
2008-10-20 00:08 . 2008-10-20 00:08 <DIR> d-------- d:\programmi\ElcomSoft
2008-10-15 23:14 . 2008-10-15 23:14 <DIR> d-------- d:\documents and settings\All Users.WINDOWS\Dati applicazioni\SlySoft
2008-10-15 22:42 . 2008-10-17 17:00 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\DivX
2008-10-15 21:59 . 2008-10-15 21:59 <DIR> d-------- d:\programmi\DVDFab 5
2008-10-14 17:30 . 2008-10-14 17:30 <DIR> d-------- d:\programmi\Midway Home Entertainment
2008-10-14 17:18 . 2008-10-14 17:18 <DIR> d-------- d:\documents and settings\Peppalvino\Dati applicazioni\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 14:51 --------- d-----w d:\programmi\eMule Applejuice
2008-11-10 14:47 --------- d-----w d:\programmi\File comuni\Wise Installation Wizard
2008-11-10 14:26 --------- d---a-w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\TEMP
2008-11-09 16:17 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\uTorrent
2008-11-09 13:32 --------- d-----w d:\programmi\MSN Messenger
2008-11-02 12:26 --------- d--h--w d:\programmi\InstallShield Installation Information
2008-10-22 15:05 --------- d-----w d:\programmi\DivX
2008-10-22 15:05 --------- d-----w d:\programmi\DAP
2008-10-22 15:05 --------- d-----w d:\programmi\Alcohol Soft
2008-10-21 15:33 --------- d-----w d:\programmi\KONAMI
2008-10-15 22:24 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\DVD Shrink
2008-10-15 20:59 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Vso
2008-10-15 20:21 --------- d-----w d:\programmi\DVD Shrink
2008-09-30 21:55 --------- d-----w d:\programmi\PokerStars.NET
2008-09-30 21:54 --------- d-----w d:\programmi\Acclaim
2008-09-29 18:45 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\Dev-Cpp
2008-09-28 09:06 --------- d-----w d:\programmi\Maxis
2008-09-26 23:05 --------- d-----w d:\programmi\Monte Cristo
2008-09-24 17:50 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\GetRightToGo
2008-09-22 13:14 --------- d-----w d:\documents and settings\Peppalvino\Dati applicazioni\SecondLife
2008-09-20 20:06 --------- d-----w d:\programmi\GiocoDigitale
2008-09-20 20:06 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\GiocoDigitale
2008-09-16 00:14 9,464 ------w d:\windows\system32\drivers\cdralw2k.sys
2008-09-16 00:14 9,336 ------w d:\windows\system32\drivers\cdr4_xp.sys
2008-09-16 00:14 43,528 ------w d:\windows\system32\drivers\PxHelp20.sys
2008-09-11 21:35 --------- d-----w d:\programmi\SpeedSim
2008-09-10 11:34 --------- d-----w d:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft
2007-12-27 18:56 87,608 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\ezpinst.exe
2007-12-27 18:56 47,360 ----a-w d:\documents and settings\Peppalvino\Dati applicazioni\pcouffin.sys
.
Codice: | <pre>
----a-w 79,224 2007-09-06 10:06:09 d:\programmi\Alwil Software\Avast4\ashDisp .exe
----a-r 925,696 2005-05-20 09:11:06 d:\programmi\Analog Devices\Core\smax4pnp .exe
</pre> |
((((((((((((((((((((((((((((( snapshot_2008-11-10_15.30.10.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-10 14:55:21 16,384 ----atw d:\windows\Temp\Perflib_Perfdata_4ec.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MsnMsgr"="d:\programmi\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"updateMgr"="d:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Nokia.PCSync"="d:\programmi\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="d:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-06-18 1122816]
"AnyDVD"="d:\programmi\SlySoft\AnyDVD\AnyDVDtray.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="d:\programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NBKeyScan"="d:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"EPSON Stylus Photo R200 Series"="d:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE" [2003-09-11 99840]
"DownloadAccelerator"="d:\programmi\DAP\DAP.EXE" [2007-12-25 4576768]
"SoundMAXPnP"="d:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"QuickTime Task"="d:\programmi\QuickTime\qttask.exe" [2008-01-31 385024]
"iTunesHelper"="d:\programmi\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"mirc"="c:\windows\WINCRA\mirc.exe" [N/A]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 d:\windows\system32\HdAShCut.exe]
"AdslTaskBar"="stmctrl.dll" [2003-01-22 d:\windows\system32\stmctrl.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
d:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - d:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
WinZip Quick Pick.lnk - d:\programmi\WinZip\WZQKPICK.EXE [2007-11-09 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\uTorrent\\utorrent.exe"=
"d:\\WINDOWS\\system32\\javaw.exe"=
"c:\\File installazione\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\DAP\\DAP.exe"=
"d:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"d:\\Programmi\\MSN Messenger\\livecall.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"d:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"d:\\Programmi\\eMule Applejuice\\emule.exe"=
"d:\\Programmi\\iTunes\\iTunes.exe"=
"d:\\Documents and Settings\\Peppalvino\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"d:\\Programmi\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 Stmatm;ATM/ADSL miniport;d:\windows\system32\DRIVERS\stmatm.sys [2002-09-25 59338]
R3 TaurusUsb;ADSL Modem USB Service 1.09a;d:\windows\system32\DRIVERS\torususb.sys [2003-01-09 527980]
.
Contenuto della cartella 'Scheduled Tasks'
2008-10-31 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 15:56:55
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
d:\windows\system32\ati2evxx.exe
d:\windows\system32\ati2evxx.exe
d:\programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
d:\programmi\Alwil Software\Avast4\aswUpdSv.exe
d:\programmi\Alwil Software\Avast4\ashServ.exe
d:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\programmi\Nero\Nero8\Nero BackItUp\NBService.exe
d:\windows\system32\wdfmgr.exe
d:\programmi\Alwil Software\Avast4\ashMaiSv.exe
d:\programmi\Alwil Software\Avast4\ashWebSv.exe
d:\windows\system32\WgaTray.exe
d:\windows\system32\rundll32.exe
d:\programmi\iPod\bin\iPodService.exe
d:\programmi\PC Connectivity Solution\ServiceLayer.exe
d:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
d:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
d:\programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
.
**************************************************************************
.
Ora fine scansione: 2008-11-10 16:02:03 - macchina è stato riavviato [Peppalvino]
ComboFix-quarantined-files.txt 2008-11-10 15:01:59
ComboFix2.txt 2008-11-10 14:30:33
ComboFix3.txt 2008-11-10 13:38:00
Pre-Run: 39,534,006,272 byte disponibili
Post-Run: 39,536,656,384 byte disponibili
190 --- E O F --- 2008-11-10 12:31:04 |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
|
Top |
|
 |
Alvin87 Mortale devoto

Registrato: 09/11/08 04:11 Messaggi: 6
|
Inviato: 12 Nov 2008 02:17 Oggetto: |
|
|
Ehm...Mi dice che il topic cercato nn esiste
Cmq se può interessare il problema è scomparso e lo posso confermare, ho avuto il PC connesso per 26 ore
Sante sei il mio nuovo Dio 8) |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
Inviato: 12 Nov 2008 10:39 Oggetto: |
|
|
OK, però ti consiglio di scaricare e fare la scasnione con KASPERSKY VIRUS REMOVAL TOOL: clicca qui per il download
Compatibilita: Windows XP
scarica la versione del tool più aggiornata rispetto alla data ed ora di pubblicazione
Installa KASPERSKY VIRUS REMOVAL TOOL:
verrà creata una apposta cartella sul Desktop
all?interno della cartella è presente la classica icona (una K) di Kaspersky
clicca sull?icona per lanciare il tool
imposta le aree che intendi scansionare (Startup Objects e Disk boot sector sono impostate di default)
al termine della scansione sarà possibile rimuovere e/o mettere in quarantena i file infetti rilevati
salva il log che verrà rilasciato
Nota 1: Il tool è incompatibile se si hanno già prodotti Kaspersky installati
Nota 2: non possiede una funzione di aggiornamento automatico delle firme.
Perchè ancora c'è qualcosa che non è stata sistemata...e cioè Avast "corrotto". |
|
Top |
|
 |
|
|
Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento Non puoi modificare i tuoi messaggi Non puoi cancellare i tuoi messaggi Non puoi votare nei sondaggi
|
|