Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

[LOG:] Antivir,ComboFix,HiJackThis

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

[LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » mer nov 23, 2011 2:22 pm

Ciao a tutti mebri del forum come da titolo vi posto i vari log da esaminare!!

Antivir: Questo non e il log completo della scanzione ma una parte relativa a 2 avvisi che mi ha segnalato:

Avvio della scansione del file selezionati:

Inizia con la scansione di 'C:\'
C:\Windows\System32\sppcomapi.dll
[AVVISO] Impossibile aprire il file!
C:\Windows\winsxs\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\sppcomapi.dll
[AVVISO] Impossibile aprire il file!


Combofix:

((((((((((((((((((((((((( Files Creati Da 2011-10-23 al 2011-11-23 )))))))))))))))))))))))))))))))))))
.
.
2011-11-23 13:00 . 2011-11-23 13:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-22 15:03 . 2011-11-22 15:03 -------- d-----w- c:\program files\Common Files\McAfee
2011-11-22 15:03 . 2011-11-23 10:42 -------- d-----w- c:\program files\McAfee
2011-11-22 15:01 . 2011-10-07 03:48 6668624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6732AB53-E146-4EE6-872B-F89861A7A255}\mpengine.dll
2011-11-22 11:27 . 2011-11-22 11:31 -------- d-----w- c:\program files\SpywareBlaster
2011-11-18 16:03 . 2011-11-18 16:17 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\Ugolog
2011-11-18 16:03 . 2011-11-18 16:03 -------- d-----w- c:\program files\Ugolog
2011-11-18 15:54 . 2011-11-18 15:54 -------- d-----w- c:\program files\PaperCut Print Logger
2011-11-17 14:59 . 2011-03-13 11:37 50176 ----a-w- c:\windows\system32\drivers\dataguard.sys
2011-11-17 14:59 . 2011-11-17 15:00 -------- d-----w- c:\program files\DataGuard
2011-11-16 22:30 . 2011-11-21 16:42 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\WFDS
2011-11-16 22:30 . 2009-07-14 04:16 163840 ----a-w- c:\windows\system32\temp.001
2011-11-16 22:30 . 2009-07-14 04:15 1386496 ----a-w- c:\windows\system32\temp.002
2011-11-16 22:30 . 2009-07-14 02:43 16896 ----a-w- c:\windows\system32\temp.000
2011-11-16 22:30 . 2004-03-09 10:00 609824 ----a-w- c:\windows\system32\Comctl32.ocx
2011-11-16 22:30 . 2011-11-16 22:30 -------- d-----w- c:\program files\Prevent Restore 3
2011-11-16 22:21 . 2011-11-16 22:21 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\JPEGsnoop
2011-11-16 22:10 . 2011-11-16 22:10 -------- d-----w- c:\program files\CCleaner
2011-11-16 15:13 . 2011-11-16 15:13 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\Screaming Bee
2011-11-16 15:13 . 2011-11-16 15:13 -------- d-----w- c:\program files\Screaming Bee
2011-11-15 13:47 . 2011-11-15 14:04 -------- d-----w- c:\program files\Appnimi
2011-11-15 13:40 . 2011-11-15 13:40 -------- d-----w- c:\program files\FREE Word and Excel password recovery Wizard
2011-11-15 13:34 . 2011-11-15 13:34 -------- d-----w- c:\program files\Passware
2011-11-15 01:16 . 2011-11-15 01:16 -------- d-----w- c:\users\Dextero1.0\AppData\Local\Eraser 6
2011-11-15 00:40 . 2011-11-15 00:40 -------- d-----w- c:\program files\Eraser
2011-11-14 15:48 . 2011-11-14 15:51 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\TrueCrypt
2011-11-14 15:48 . 2011-11-14 15:48 231376 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-11-14 15:48 . 2011-11-14 15:48 -------- d-----w- c:\program files\TrueCrypt
2011-11-14 15:33 . 2011-11-16 22:33 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\PrivateEye
2011-11-14 15:33 . 2011-11-16 22:33 -------- d-----w- c:\programdata\PrivateEye
2011-11-14 14:45 . 2011-11-14 14:45 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\KeePass
2011-11-14 12:44 . 2011-11-14 14:50 -------- d-----w- c:\program files\KeePass Password Safe
2011-11-10 13:26 . 2011-10-21 21:46 185480 ----a-w- c:\windows\system32\drivers\EuFdDisk.sys
2011-11-10 13:26 . 2011-10-21 21:46 43656 ----a-w- c:\windows\system32\drivers\EUBKMON.sys
2011-11-10 13:25 . 2011-10-21 21:47 20616 ----a-w- c:\windows\system32\fbnative.exe
2011-11-10 13:14 . 2010-12-13 14:36 21464 ----a-w- c:\windows\system32\NaBootMir.exe
2011-11-10 13:14 . 2010-02-24 16:16 512 ----a-w- c:\windows\MirDetected.bin
2011-11-10 13:14 . 2011-11-10 13:14 -------- d-----w- c:\program files\Wondershare
2011-11-10 13:14 . 2010-12-13 14:37 37016 ----a-w- c:\windows\system32\drivers\FolderHK.sys
2011-11-10 13:14 . 2010-12-13 14:36 28648 ----a-w- c:\windows\system32\drivers\MirDisk.sys
2011-11-10 13:14 . 2010-12-13 14:36 33896 ----a-w- c:\windows\system32\drivers\HKDirFlt.sys
2011-11-10 01:09 . 2011-11-10 01:09 -------- d-----w- c:\users\Dextero1.0\Backups
2011-11-10 00:31 . 2011-11-10 00:31 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\Returnil
2011-11-10 00:30 . 2011-11-10 00:30 -------- d-----w- c:\programdata\Returnil
2011-11-09 12:05 . 2011-11-09 12:05 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-11-09 10:10 . 2011-10-01 04:37 708608 ----a-w- c:\program files\Common Files\System\wab32.dll
2011-11-09 10:10 . 2011-09-29 16:03 1290608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 10:10 . 2011-09-29 03:37 2341888 ----a-w- c:\windows\system32\win32k.sys
2011-11-08 16:28 . 2011-11-08 16:28 -------- d-----w- c:\program files\TVdream
2011-11-08 14:31 . 2011-11-08 14:32 -------- d-----w- c:\program files\vShare.tv plugin
2011-11-07 13:58 . 2011-11-07 13:58 -------- d-----w- c:\programdata\HP Product Assistant
2011-11-07 13:56 . 2011-11-07 13:56 -------- d-----w- c:\program files\Common Files\HP
2011-11-07 13:30 . 2011-11-07 13:30 -------- d-----w- c:\users\Dextero1.0\AppData\Roaming\HpUpdate
2011-11-06 14:21 . 2011-10-07 17:47 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-10-31 19:41 . 2011-10-31 19:41 -------- d-----w- c:\users\Dextero1.0\AppData\Local\Facebook
2011-10-26 20:34 . 2011-10-26 20:34 -------- d-----w- c:\program files\Common Files\Java
2011-10-26 12:08 . 2011-10-26 12:08 -------- d-----w- c:\program files\Veetle
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-18 12:19 . 2011-09-14 11:03 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-21 21:46 . 2010-05-14 12:17 17032 ----a-w- c:\windows\system32\drivers\eudskacs.sys
2011-10-21 21:46 . 2010-05-14 12:17 39560 ----a-w- c:\windows\system32\drivers\eubakup.sys
2011-10-07 17:47 . 2011-06-30 07:38 82400 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-10-07 17:47 . 2011-06-30 07:38 39640 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 17:47 . 2011-06-30 07:38 488208 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 17:47 . 2011-06-30 07:38 19600 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 17:47 . 2011-06-30 07:37 300200 ----a-w- c:\windows\system32\guard32.dll
2011-10-03 03:06 . 2010-05-16 12:10 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-21 00:59 . 2011-09-21 00:59 388096 ----a-r- c:\users\Dextero1.0\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-18 01:25 . 2011-09-17 14:22 409088 ----a-w- c:\windows\system32\systemcpl.dll
2011-09-18 01:25 . 2011-09-17 14:22 13824 ----a-w- c:\windows\system32\slwga.dll
2011-09-18 00:16 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-09-17 14:34 . 2011-09-17 14:34 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-09-17 14:34 . 2011-09-17 14:34 161792 ----a-w- c:\windows\system32\msls31.dll
2011-09-17 14:34 . 2011-09-17 14:34 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-09-17 14:34 . 2011-09-17 14:34 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-09-17 14:34 . 2011-09-17 14:34 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-09-17 14:34 . 2011-09-17 14:34 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-09-17 14:34 . 2011-09-17 14:34 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-09-17 14:34 . 2011-09-17 14:34 367104 ----a-w- c:\windows\system32\html.iec
2011-09-17 14:34 . 2011-09-17 14:34 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-09-17 14:34 . 2011-09-17 14:34 152064 ----a-w- c:\windows\system32\wextract.exe
2011-09-17 14:34 . 2011-09-17 14:34 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-09-17 14:34 . 2011-09-17 14:34 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-09-17 14:34 . 2011-09-17 14:34 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-09-17 14:34 . 2011-09-17 14:34 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-09-17 14:34 . 2011-09-17 14:34 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-09-17 14:34 . 2011-09-17 14:34 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-09-17 14:34 . 2011-09-17 14:34 11776 ----a-w- c:\windows\system32\mshta.exe
2011-09-17 14:34 . 2011-09-17 14:34 101888 ----a-w- c:\windows\system32\admparse.dll
2011-09-17 14:01 . 2011-09-17 14:01 53248 ----a-r- c:\users\Dextero1.0\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-09-14 11:02 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-09-01 02:35 . 2011-10-12 12:55 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-09-01 02:28 . 2011-10-12 12:55 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-09-01 02:22 . 2011-10-12 12:55 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-08-31 15:00 . 2011-09-21 00:49 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 04:26 . 2011-10-12 12:03 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-08-27 04:26 . 2011-10-12 12:03 233472 ----a-w- c:\windows\system32\oleacc.dll
2010-01-26 09:11 . 2011-09-14 14:00 444283 ----a-w- c:\program files\Common Files\WinPcapNmap.exe
2011-11-09 22:41 . 2011-09-14 12:09 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}"= "c:\program files\vShare.tv plugin\BarLcher.dll" [2011-09-22 177712]
.
[HKEY_CLASSES_ROOT\clsid\{7ac3e13b-3bca-4158-b330-f66dbb03c1b5}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher.1]
[HKEY_CLASSES_ROOT\TypeLib\{BB7256DD-EBA9-480B-8441-A00388C2BEC3}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iKill"="c:\program files\ArpanTECH\iKill\iKill.exe" [2008-12-21 73728]
"Facebook Update"="c:\users\Dextero1.0\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-10-31 137536]
"KeePass Password Safe"="c:\program files\KeePass Password Safe\KeePass.exe" [2011-10-12 1934336]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-06-25 98304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-08-18 7711264]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-09-01 281768]
"Hercules DJ Series"="c:\program files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe" [2009-10-23 509224]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 2497352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"BootNaMir"="c:\program files\Wondershare\Time Freeze\BootSP.exe" [2010-12-13 322152]
"EaseUs Watch"="c:\program files\EaseUS\Todo Backup\bin\EuWatch.exe" [2011-10-21 70792]
"EaseUs Tray"="c:\program files\EaseUS\Todo Backup\bin\TrayNotify.exe" [2011-10-21 743560]
"Eraser"="c:\progra~1\Eraser\Eraser.exe" [2011-11-05 980368]
"DataGuard"="c:\program files\DataGuard\Dataguard.exe" [2011-03-13 2208256]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
Matrix Screen Locker.lnk - c:\program files\BaroufaSoft\Matrix Screen Locker\matrix.exe [2006-1-29 539136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLUA"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoStartMenuMyGames"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0NaBootMir
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Dextero1.0^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Registrazione prodotti.lnk]
backup=c:\windows\pss\Logitech . Registrazione prodotti.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2010-06-07 16:36 4393920 ----a-w- c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2009-11-18 15:13 54576 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-08-12 10:18 205336 ----a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-09-22 23:47 4240760 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
2007-05-31 07:21 648072 ----a-w- c:\windows\WindowsMobile\wmdc.exe
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-06-10 691696]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-10-07 488208]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-10-07 39640]
R1 DataGuard AntiKeylogger Kernel Service;DataGuard AntiKeylogger Kernel Service;c:\windows\system32\drivers\dataguard.sys [2011-03-13 50176]
R1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [2011-10-21 17032]
R1 EUFDDISK;EUFDDISK;c:\windows\system32\drivers\EuFdDisk.sys [2011-10-21 185480]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-06-25 176128]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-03-30 20968]
R2 EaseUS Agent;EaseUS Agent;c:\program files\EaseUS\Todo Backup\bin\Agent.exe [2011-10-21 60552]
R2 Guard Agent;Guard Agent;c:\program files\EaseUS\Todo Backup\bin\GuardAgent.exe [2011-10-21 23176]
R2 gupdate;Servizio di Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-14 136176]
R2 HerculesDJControlMP3;Hercules DJ Control MP3;c:\program files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE [2007-11-21 17408]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [2011-08-10 94880]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-01-27 50704]
R2 PCPrintLogger;PaperCut Print Logger;c:\program files\PaperCut Print Logger\pcpl.exe PCPrintLogger [x]
R2 PrivateEyeService;PrivateEye Service; [x]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-08-19 450848]
R3 ALSysIO;ALSysIO;c:\users\Dextero1.0\AppData\Local\Temp\ALSysIO.sys [x]
R3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys [2009-10-02 127488]
R3 dc3d;MS Hardware Device Detection Driver (HID);c:\windows\system32\DRIVERS\dc3d.sys [2010-04-16 22416]
R3 EuDisk;EASEUS Disk Enumerator;c:\windows\system32\DRIVERS\EuDisk.sys [2009-12-02 123784]
R3 gupdatem;Servizio Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-14 136176]
R3 HDJMidi;DJ Control MP3 e2 MIDI;c:\windows\system32\DRIVERS\HDJMidi.sys [2009-10-02 124416]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\84D0.tmp [x]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2010-06-08 47360]
R3 portio32;portio32;c:\windows\system32\drivers\portio32.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-12-01 34384]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2010-12-01 100560]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [2011-10-21 39560]
S0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [2011-10-21 43656]
S0 HKDirFlt;Wondershare HKDirFlt;c:\windows\system32\drivers\HKDirFlt.sys [2010-12-13 33896]
S0 MirDisk;Wondershare Time Freeze;c:\windows\system32\drivers\MirDisk.sys [2010-12-13 28648]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-11-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3308655561-2943522366-3363658282-1000Core.job
- c:\users\Dextero1.0\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-31 19:41]
.
2011-11-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3308655561-2943522366-3363658282-1000UA.job
- c:\users\Dextero1.0\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-31 19:41]
.
2011-11-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-14 11:28]
.
2011-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-14 11:28]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\program files\PokerStars.IT\PokerStarsUpdate.exe
TCP: Interfaces\{154DA280-FD5B-4489-A14F-A80451998430}: NameServer = 212.216.112.112,212.216.172.62
FF - ProfilePath - c:\users\Dextero1.0\AppData\Roaming\Mozilla\Firefox\Profiles\gjks1e18.default\
FF - prefs.js: browser.search.selectedEngine - Casella di ricerca Secure
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it
FF - prefs.js: keyword.URL - hxxp://it.search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 8118
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 9050
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 8118
FF - prefs.js: network.proxy.type - 0
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\84D0.tmp"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2011-11-23 14:01:52
ComboFix-quarantined-files.txt 2011-11-23 13:01
ComboFix2.txt 2011-11-22 14:36
.
Pre-Run: 42.338.304.000 byte disponibili
Post-Run: 42.294.235.136 byte disponibili
.
- - End Of File - - EA949DCA6B4975E45E8314F76EB5B0EA


HiJackThis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:09:16, on 23/11/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: VShareToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Hercules DJ Series] C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe /boot
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [BootNaMir] C:\Program Files\Wondershare\Time Freeze\BootSP.exe
O4 - HKLM\..\Run: [EaseUs Watch] "C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe"
O4 - HKLM\..\Run: [EaseUs Tray] "C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe"
O4 - HKLM\..\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart
O4 - HKLM\..\Run: [DataGuard] C:\Program Files\DataGuard\Dataguard.exe r
O4 - HKCU\..\Run: [iKill] "C:\Program Files\ArpanTECH\iKill\iKill.exe" -s
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Dextero1.0\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [KeePass Password Safe] "C:\Program Files\KeePass Password Safe\KeePass.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Matrix Screen Locker.lnk = C:\Program Files\BaroufaSoft\Matrix Screen Locker\matrix.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: PokerStars.it - {C4046502-6524-4d87-896C-878F57D1FF07} - C:\Program Files\PokerStars.IT\PokerStarsUpdate.exe
O9 - Extra button: Visualizza o nasconde HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{154DA280-FD5B-4489-A14F-A80451998430}: NameServer = 212.216.112.112,212.216.172.62
O17 - HKLM\System\CS1\Services\Tcpip\..\{154DA280-FD5B-4489-A14F-A80451998430}: NameServer = 212.216.112.112,212.216.172.62
O17 - HKLM\System\CS2\Services\Tcpip\..\{154DA280-FD5B-4489-A14F-A80451998430}: NameServer = 212.216.112.112,212.216.172.62
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\System32\guard32.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: EaseUS Agent - CHENGDU YIWO Tech Development Co., Ltd - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
O23 - Service: Guard Agent - CHENGDU YIWO Tech Development Co., Ltd - C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe
O23 - Service: Servizio di Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Hercules DJ Control MP3 (HerculesDJControlMP3) - Unknown owner - C:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: PaperCut Print Logger (PCPrintLogger) - PaperCut Software International Pty Ltd - C:\Program Files\PaperCut Print Logger\pcpl.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

--
End of file - 8878 bytes


Attendo Vosta Risposta ;) Grazie.
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda hashcat » mer nov 23, 2011 2:56 pm

Noti particolare problemi?
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » mer nov 23, 2011 3:12 pm

Rallentamenti non ne ho....spyware penso nemmeno...!!I log sono Puliti??O hai trovato qualcosa??

Per quanto riguarda I Rootkit mi consigli di fare una scansione con GMER?:)
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am


Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda hashcat » mer nov 23, 2011 3:24 pm

Non postare i log troncandoli.

Analizzandoli velocemente non ho notato particolari anomali eccetto le seguenti:

Questa ed altre voci di registro:

Codice: Seleziona tutto
HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher.1

Che si riferiscono all'adware Ezshopper/ActivShopper.

Questo servizio (probabilmente malevolo):

Codice: Seleziona tutto
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\84D0.tmp

Anche se il file in questione è mancante.

Riposta i log completi, spiegando in dettaglio le anomalie che riscontri sul tuo computer.

Per rimuovere l'adware afare un po' di pulizia scarica Malwarebytes, aggiornalo, fai una scansione completa. Al termine della scansione rimuovi tutte le minacce rilevate e posta qui il relativo log.

Scarica Hitman Pro, installalo ed esegui una scansione completa (richiede una connessione ad internet permanente), non rimuovere nessuna delle minacce indicate ma salva il log.

Le impostazioni di Hitman Pro devono essere le seguenti:
Immagine

Per salvare il log fai così:
Immagine

[^] [^]
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » mer nov 23, 2011 4:57 pm

Metto in aggiunta i Log Di Malwarebytes Anti-Malware e Hitman Pro:

Malwarebytes:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Versione database: 8223

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421

23/11/2011 16:37:05
mbam-log-2011-11-23 (16-36-39).txt

Tipo di scansione: Scansione completa (C:\|D:\|E:\|F:\|I:\|Y:\|)
Elementi esaminati: 277185
Tempo impiegato: 27 minuti, 31 secondi

Processi infetti in memoria: 0
Moduli di memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Voci infette nei dati di registro: 0
Cartelle infette: 0
File infetti: 17

Processi infetti in memoria:
(Non sono stati rilevati elementi nocivi)

Moduli di memoria infetti:
(Non sono stati rilevati elementi nocivi)

Chiavi di registro infette:
(Non sono stati rilevati elementi nocivi)

Valori di registro infetti:
(Non sono stati rilevati elementi nocivi)

Voci infette nei dati di registro:
(Non sono stati rilevati elementi nocivi)

Cartelle infette:
(Non sono stati rilevati elementi nocivi)

File infetti:
i:\programmi\utility htc\htc p3300\rom windows mobile 6\start_uspl.exe (Trojan.Agent) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software detective\Browser\iehv.exe (PUP.HistoryTool) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\astlog.exe (HackTool.Asterisk) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\chromepass.exe (PUP.ChromePasswordTool) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\dialupass.exe (PUP.Dialupass) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\iepv.exe (PUP.PSW.Passview) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\mailpv.exe (PUP.MailPassView) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\mspass.exe (PUP.PSW.MessenPass) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\netpass.exe (PUP.NetworkPasswordTool) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\operapassview.exe (PUP.OperaPasswordTool) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\passwordfox.exe (PUP.PSW.PassFox) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\pspv.exe (PUP.Passview) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\pstpassword.exe (PUP.MailPassView) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\rdpv.exe (Password.Tool) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\sniffpass.exe (PUP.PswdSniffer) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\webbrowserpassview.exe (PUP.PassView) -> No action taken.
i:\programmi\WINDOWS\software sicurezza\software password\password recovery\wirelesskeyview.exe (PUP.WirelessKeyView) -> No action taken.


Hitman Pro:

<?xml version="1.0"?>
-<Log filesProcessed="11620" timeSpentInSecs="107" date="2011-11-23T16:44:33" version="3.5.9.131" scan="Normal" computer="DEXTERO10-PC">-<Item status="Deleted" score="0.0" type="Repair"><File path="C:\Users\Dextero1.0\AppData\Local\Google\Chrome\User Data\Default\Cookies:cocacola2.solution.weborama.fr"/></Item>-<Item status="Deleted" score="0.0" type="Repair"><File path="C:\Users\Dextero1.0\AppData\Local\Google\Chrome\User Data\Default\Cookies:weborama.fr"/></Item></Log>


P.S Di segni di Malware non ne noto nel Computer...Pero prima di effettuare un immagine di sistema vorrei essere sicuro di avere un sistema PULITO

Grazie.
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda hashcat » mer nov 23, 2011 9:48 pm

Credo che l'unica cosa da pulire sia ActivShopper. Ci pensermo domani [^]
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » gio nov 24, 2011 1:43 pm

Ciao HASH :).....Pronto per l'eliminazione di Activ-Shopper....Quale programma tra i log che ti ho postato la rilevato giusto per informazione!!

L'unica scansione che mi manca è contro i Rootkit quale programma mi consigli di usare??
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda hashcat » gio nov 24, 2011 3:34 pm

DennioLab ha scritto:Ciao HASH :).....Pronto per l'eliminazione di Activ-Shopper....Quale programma tra i log che ti ho postato la rilevato giusto per informazione!!
Dal log di Combofix anche se quello che hai postato tu è troncato.
Prima di eseguire la pulizia di ActivShopper o la scansione anti-rootkit disabilita temporaneamente il Defense+ e la Sandbox di Comodo.
Per rimuovere ActivShopper scarica Ad-Remover, installalo, clicca su Clean, attendi fino al termine della pulizia. Una volta terminata la pulizia verrà richiesto di riavviare, riavvia.
Posta qui il log che si trova in C:\
DennioLab ha scritto:L'unica scansione che mi manca è contro i Rootkit quale programma mi consigli di usare??

Sembra che tu abbia già utilizzato Sophos Anti-Rootkit.
Sinceramente io non vedo la necessità di fare una scansione per rootkit. Se vuoi comunque portarla a termine utilizza GMER e/o rootrepeal.

GMER deve essere settato in questo modo:

Immagine

Infine ti suggerisco di rimuovere DataGuard AntiKeylogger, perché le funzioni di Anti-Keylogger sono già svolte da Comodo e potrebbero esserci delle incompatibilità tra i due programmi.
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » gio nov 24, 2011 4:53 pm

Ok Grazie del Consiglio....

Ti postero i Log di Gmer e Ad-Remover appena ho tempo ;)
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » gio nov 24, 2011 6:05 pm

Ecco i LOG:

Ad-Remove:

======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 =======

Updated by TeamXscript on 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
website: http://www.teamxscript.org

C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 17:02:16 on 24/11/2011, Normal boot

Microsoft Windows 7 Ultimate Service Pack 1 (X86)
Dextero1.0@DEXTERO10-PC (To Be Filled By O.E.M. To Be Filled By O.E.M.)

============== ACTION(S) ==============


Folder deleted: C:\Program Files\Ask.com
Folder deleted: C:\Users\Dextero1.0\AppData\LocalLow\AskToolbar

(!) -- Temporary files deleted.


Key deleted: HKLM\Software\Classes\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key deleted: HKLM\Software\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key deleted: HKLM\Software\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key deleted: HKLM\Software\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}
Key deleted: HKLM\Software\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}
Key deleted: HKCU\Software\Ask.com
Key deleted: HKCU\Software\AppDataLow\AskToolbarInfo
Key deleted: HKCU\Software\AppDataLow\Software\AskToolbar
Key deleted: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}


============== ADDITIONNAL SCAN ==============

**** Mozilla Firefox Version [8.0 (it)] ****

Plugins\npvsharetvplg.dll (vShare.tv )
HKLM_MozillaPlugins\@mcafee.com/SAFFPlugin (x)
HKLM_MozillaPlugins\Adobe Reader (x)
HKCU_MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin (x)
Searchplugins\bing.xml ( hxxp://www.bing.com/search&#41;
Searchplugins\eBay-it.xml (hxxp://rover.ebay.com/rover/1/724-51951-19398-1/4)
Searchplugins\hoepli.xml (hxxp://dizionari.hoepli.it/Dizionario_Italiano/cerca.aspx?idD=1&amp;utm_source=mozilla-firefox&amp;query={searchTerms})
Searchplugins\McSiteAdvisor.xml ( hxxp://it.search.yahoo.com/search&#41;
Searchplugins\wikipedia-it.xml (hxxp://it.wikipedia.org/wiki/Speciale:Ricerca)
Searchplugins\yahoo-it.xml (hxxp://it.search.yahoo.com/search)
Components\browsercomps.dll (Mozilla Foundation)
HKLM_Extensions|smartwebprinting@hp.com - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
HKLM_Extensions|{4ED1F68A-5463-4931-9384-8FFF5ED91D92} - C:\Program Files\McAfee\SiteAdvisor
HKCU_Extensions|smartwebprinting@hp.com - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

-- C:\Users\Dextero1.0\AppData\Roaming\Mozilla\FireFox\Profiles\gjks1e18.default --
Prefs.js - browser.download.dir, C:\\Users\\Dextero1.0\\Desktop
Prefs.js - browser.search.defaultenginename, Hotspot Shield Private Search
Prefs.js - browser.search.selectedEngine, Casella di ricerca Secure
Prefs.js - browser.startup.homepage, hxxp://www.google.it
Prefs.js - browser.startup.homepage_override.buildID, 20111104165243
Prefs.js - browser.startup.homepage_override.mstone, rv:8.0
Prefs.js - keyword.URL, hxxp://it.search.yahoo.com/search?fr=mcafee&p=
Prefs.js - privacy.popups.showBrowserMessage, false

========================================

**** Internet Explorer Version [9.0.8112.16421] ****

HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_URLSearchHooks|{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - "McAfee SiteAdvisor Toolbar" (c:\progra~1\mcafee\sitead~1\mcieplg.dll)
HKCU_SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} - "?" (?)
HKCU_SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54} - "Private Search" (hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms})
HKLM_Toolbar|{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (x)
HKLM_Toolbar|{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} (c:\progra~1\mcafee\sitead~1\mcieplg.dll)
HKCU_ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA} - C:\Users\Dextero1.0\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited)
HKLM_ElevationPolicy\{02073B90-44EE-47B1-9633-732376A8A3C8} - C:\Program Files\Veetle\Player\VeetleNet.exe (?)
HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\System32\wpcer.exe (x)
HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\System32\winfxdocobj.exe (x)
HKLM_ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA} - C:\Users\Dextero1.0\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited)
HKLM_ElevationPolicy\{6052BF20-EA23-4A04-B3C1-A20EFE01A95A} - C:\Program Files\Veetle\Player\vtl_hfs.exe (?)
HKLM_ElevationPolicy\{680FA47E-AB59-46BE-B594-7358726E108B} - C:\Program Files\Veetle\Player\player.exe (?)
HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{DAABE21E-DB8C-49b8-9511-9E6547ECBC5F} - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
HKLM_ElevationPolicy\{E8BC6C2B-DD90-4397-96EB-2AAF0E48ABE6} - C:\Program Files\Veetle\Player\vtl_hfax.exe (?)
HKLM_Extensions\{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - "@C:\Windows\WindowsMobile\INetRepl.dll,-222" (C:\Windows\WindowsMobile\INetRepl.dll,210)
HKLM_Extensions\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - "?" (?)
HKLM_Extensions\{C4046502-6524-4d87-896C-878F57D1FF07} - "PokerStars.it" (?)
BHO\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} - "McAfee SiteAdvisor BHO" (c:\progra~1\mcafee\sitead~1\mcieplg.dll)

========================================

C:\Program Files\Ad-Remover\Quarantine: 9 File(s)
C:\Program Files\Ad-Remover\Backup: 13 File(s)

C:\Ad-Report-CLEAN[1].txt - 24/11/2011 17:02:36 (6773 Byte(s))

End at: 17:03:38, 24/11/2011

============== E.O.F ==============


P.S Mi piacerebbe essere autonomo su queste cose...e imparare a capire i LOG dei programmi!!

Il Log di Gmer contiene troppi caratteri e non posso metterlo nel post...comunque ha termine scansione non mi ha lasciato nessun avviso e nessuna riga segnalata in Rosso.

Intato Grazie Hash del Supporto ;)
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda hashcat » gio nov 24, 2011 10:39 pm

Ad-Remover ha rimosso la Ask toolbar ed ulteriori rimasugli.

Per completare la pulizia devi creare il file fix.reg:

Codice: Seleziona tutto
Windows Registry Editor Version 5.00

[-HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher]

[-HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher.1]

[-HKEY_CLASSES_ROOT\TypeLib\{BB7256DD-EBA9-480B-8441-A00388C2BEC3}]


Apri il Blocco Note e salva questo script come fix.reg selezionando l'opzione Salva Come: Tutti i file.

Inoltre vorrei analizzare un log di DDS:

  1. Scarica DDS da qui
  2. Disabilita Comodo
  3. Eseguilo
  4. Al termine della scansione verranno aperte due finestre del Blocco Note
    Una chiamata dds.txt e un'altra attach.txt
  5. Devi salvare i due log ed includere entrambi nel tuo prossimo messaggio.
  6. Se i log dovessere eccedere il numero di caratteri consentito in un messaggio caricali su paste2.org

Infine ti suggerisco di effettuare una scansione completa con Emsisoft Rescue, se vengono rilevate minacce metti tutto in quarantena.
Domani analizzeró il log di DDS, se sarà pulito abbiamo finito.
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » gio nov 24, 2011 11:11 pm

Non ho capito il primo passaggio devo aprire il blocco note e incollarci questo:?

Windows Registry Editor Version 5.00

[-HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher]

[-HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher.1]

[-HKEY_CLASSES_ROOT\TypeLib\{BB7256DD-EBA9-480B-8441-A00388C2BEC3}]

E salvarlo come fix.reg e poi lo devo eseguire??

Per il Log di DDs te le potero domani tutti e 2!!

P.S Dove hai imparato a capire i LOG dei programmi??Mi piacerebbe imparare a capirli!!

Grazie :)
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda hashcat » ven nov 25, 2011 2:03 pm

Devi creare il file Fix.reg come indicato ed eseguirlo.

P.S.: Per l’interprtazione dei log leggi il mio messaggio privato.
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » ven nov 25, 2011 3:22 pm

Questi sono i Log di DDS....domani ti postero anche quello di Emisoft Emergency Kit...

DDS.txt:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by Dextero1.0 at 15:10:15 on 2011-11-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.39.1040.18.1791.833 [GMT 1:00]
.
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe
C:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE
C:\Windows\system32\svchost.exe -k hpdevmgmt
c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\rundll32.exe
C:\Program Files\PaperCut Print Logger\pcpl.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Process Lasso\processgovernor.exe
I:\Programmi\WINDOWS\Software Test HardWare\Controllo Temperature\CoreTemp32\Core Temp.exe
C:\Program Files\Process Lasso\processlasso.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\EASEUS\Todo Backup\bin\EuWatch.exe
C:\Program Files\EASEUS\Todo Backup\bin\TrayNotify.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\ArpanTECH\iKill\iKill.exe
C:\Program Files\KeePass Password Safe\KeePass.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\BaroufaSoft\Matrix Screen Locker\matrix.exe
I:\Programmi\WINDOWS\Software Utility\NoSleepHD v1.0\NoSleepHD v1.0.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\explorer.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title =
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No File
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [iKill] "c:\program files\arpantech\ikill\iKill.exe" -s
uRun: [Facebook Update] "c:\users\dextero1.0\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [KeePass Password Safe] "c:\program files\keepass password safe\KeePass.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Hercules DJ Series] c:\program files\hercules\audio\dj console series\HDJSeriesCPL.exe /boot
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [BootNaMir] c:\program files\wondershare\time freeze\BootSP.exe
mRun: [EaseUs Watch] "c:\program files\easeus\todo backup\bin\EuWatch.exe"
mRun: [EaseUs Tray] "c:\program files\easeus\todo backup\bin\TrayNotify.exe"
mRun: [Eraser] "c:\progra~1\eraser\Eraser.exe" --atRestart
StartupFolder: c:\users\dextero1.0\appdata\roaming\micros~1\windows\startm~1\programs\startup\noslee~1.lnk - i:\programmi\windows\software utility\nosleephd v1.0\NoSleepHD v1.0.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\matrix~1.lnk - c:\program files\baroufasoft\matrix screen locker\matrix.exe
uPolicies-explorer: NoChangeAnimation = 0 (0x0)
uPolicies-explorer: NoDFSTab = 0 (0x0)
uPolicies-explorer: NoFileAssociate = 0 (0x0)
uPolicies-explorer: NoStartMenuMyGames = 0 (0x0)
uPolicies-explorer: NoCommonGroups = 0 (0x0)
uPolicies-explorer: NoSimpleStartMenu = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&sporta in Microsoft Excel - c:\progra~1\mif5ba~1\office14\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~1\mif5ba~1\office14\ONBttnIE.dll/105
IE: {C4046502-6524-4d87-896C-878F57D1FF07} - c:\program files\pokerstars.it\PokerStarsUpdate.exe
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: Interfaces\{154DA280-FD5B-4489-A14F-A80451998430} : NameServer = 212.216.112.112,212.216.172.62
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: c:\windows\system32\guard32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\dextero1.0\appdata\roaming\mozilla\firefox\profiles\gjks1e18.default\
FF - prefs.js: browser.search.selectedEngine - Casella di ricerca Secure
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it
FF - prefs.js: keyword.URL - hxxp://it.search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 8118
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 9050
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 8118
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npvsharetvplg.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\dextero1.0\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\users\dextero1.0\appdata\roaming\mozilla\firefox\profiles\gjks1e18.default\extensions\{1bc9ba34-1eed-42ca-a505-6d2f1a935bbb}\plugins\npietab2.dll
.
============= SERVICES / DRIVERS ===============
.
R0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [2010-5-14 39560]
R0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [2011-11-10 43656]
R0 HKDirFlt;Wondershare HKDirFlt;c:\windows\system32\drivers\HKDirFlt.sys [2011-11-10 33896]
R0 MirDisk;Wondershare Time Freeze;c:\windows\system32\drivers\MirDisk.sys [2011-11-10 28648]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-5-14 11608]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-6-30 488208]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-6-30 39640]
R1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [2010-5-14 17032]
R1 EUFDDISK;EUFDDISK;c:\windows\system32\drivers\EuFdDisk.sys [2011-11-10 185480]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-6-25 176128]
R2 AntiVirScheduler;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-5-14 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-5-14 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-5-14 66616]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-5-15 20968]
R2 EaseUS Agent;EaseUS Agent;c:\program files\easeus\todo backup\bin\Agent.exe [2011-11-10 60552]
R2 Guard Agent;Guard Agent;c:\program files\easeus\todo backup\bin\GuardAgent.exe [2011-11-10 23176]
R2 HerculesDJControlMP3;Hercules DJ Control MP3;c:\program files\hercules\audio\dj console series\HerculesDJControlMP3.EXE [2011-9-14 17408]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\mcsacore.exe [2011-11-22 94880]
R2 PCPrintLogger;PaperCut Print Logger;c:\program files\papercut print logger\pcpl.exe [2011-11-18 430080]
R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848]
R3 Bulk;HDJBulk;c:\windows\system32\drivers\HDJBulk.sys [2011-9-14 127488]
R3 HDJMidi;DJ Control MP3 e2 MIDI;c:\windows\system32\drivers\HDJMidi.sys [2011-9-14 124416]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-12-1 34384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Servizio di Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-14 136176]
S2 PrivateEyeService;PrivateEye Service; [x]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 EuDisk;EASEUS Disk Enumerator;c:\windows\system32\drivers\EuDisk.sys [2010-5-14 123784]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-11-21 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Servizio Google Update (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-14 136176]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-9-17 15872]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-9-17 52224]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2011-11-25 10:22:12 6668624 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{11e07f1f-db84-4396-ae58-3168948cc8da}\mpengine.dll
2011-11-25 10:22:12 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{11e07f1f-db84-4396-ae58-3168948cc8da}\offreg.dll
2011-11-24 16:01:59 -------- d-----w- c:\program files\Ad-Remover
2011-11-23 15:44:33 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-23 14:42:49 -------- d-----w- c:\programdata\Hitman Pro
2011-11-23 13:01:12 -------- d-sh--w- C:\$RECYCLE.BIN
2011-11-22 15:03:25 -------- d-----w- c:\program files\common files\McAfee
2011-11-22 15:03:21 -------- d-----w- c:\program files\McAfee
2011-11-22 14:27:23 98816 ----a-w- c:\windows\sed.exe
2011-11-22 14:27:23 518144 ----a-w- c:\windows\SWREG.exe
2011-11-22 14:27:23 256000 ----a-w- c:\windows\PEV.exe
2011-11-22 14:27:23 208896 ----a-w- c:\windows\MBR.exe
2011-11-22 11:27:24 -------- d-----w- c:\program files\SpywareBlaster
2011-11-18 16:03:33 -------- d-----w- c:\users\dextero1.0\appdata\roaming\Ugolog
2011-11-18 16:03:28 -------- d-----w- c:\program files\Ugolog
2011-11-18 15:54:41 -------- d-----w- c:\program files\PaperCut Print Logger
2011-11-16 22:30:46 -------- d-----w- c:\users\dextero1.0\appdata\roaming\WFDS
2011-11-16 22:30:45 609824 ----a-w- c:\windows\system32\Comctl32.ocx
2011-11-16 22:30:45 16896 ----a-w- c:\windows\system32\temp.000
2011-11-16 22:30:45 163840 ----a-w- c:\windows\system32\temp.001
2011-11-16 22:30:45 1386496 ----a-w- c:\windows\system32\temp.002
2011-11-16 22:30:44 -------- d-----w- c:\program files\Prevent Restore 3
2011-11-16 22:21:39 -------- d-----w- c:\users\dextero1.0\appdata\roaming\JPEGsnoop
2011-11-16 22:10:51 -------- d-----w- c:\program files\CCleaner
2011-11-16 15:13:50 -------- d-----w- c:\users\dextero1.0\appdata\roaming\Screaming Bee
2011-11-16 15:13:22 -------- d-----w- c:\program files\Screaming Bee
2011-11-15 13:47:19 -------- d-----w- c:\program files\Appnimi
2011-11-15 13:40:09 -------- d-----w- c:\program files\FREE Word and Excel password recovery Wizard
2011-11-15 13:34:02 -------- d-----w- c:\program files\Passware
2011-11-15 01:16:27 -------- d-----w- c:\users\dextero1.0\appdata\local\Eraser 6
2011-11-15 00:40:08 -------- d-----w- c:\program files\Eraser
2011-11-14 15:48:56 -------- d-----w- c:\users\dextero1.0\appdata\roaming\TrueCrypt
2011-11-14 15:48:23 231376 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-11-14 15:48:15 -------- d-----w- c:\program files\TrueCrypt
2011-11-14 15:33:38 -------- d-----w- c:\users\dextero1.0\appdata\roaming\PrivateEye
2011-11-14 15:33:33 -------- d-----w- c:\programdata\PrivateEye
2011-11-14 14:45:53 -------- d-----w- c:\users\dextero1.0\appdata\roaming\KeePass
2011-11-14 12:44:06 -------- d-----w- c:\program files\KeePass Password Safe
2011-11-10 13:26:37 185480 ----a-w- c:\windows\system32\drivers\EuFdDisk.sys
2011-11-10 13:26:32 43656 ----a-w- c:\windows\system32\drivers\EUBKMON.sys
2011-11-10 13:25:26 20616 ----a-w- c:\windows\system32\fbnative.exe
2011-11-10 13:14:29 21464 ----a-w- c:\windows\system32\NaBootMir.exe
2011-11-10 13:14:22 512 ----a-w- c:\windows\MirDetected.bin
2011-11-10 13:14:21 37016 ----a-w- c:\windows\system32\drivers\FolderHK.sys
2011-11-10 13:14:21 33896 ----a-w- c:\windows\system32\drivers\HKDirFlt.sys
2011-11-10 13:14:21 28648 ----a-w- c:\windows\system32\drivers\MirDisk.sys
2011-11-10 13:14:21 -------- d-----w- c:\program files\Wondershare
2011-11-10 01:09:54 -------- d-----w- c:\users\dextero1.0\Backups
2011-11-10 00:31:55 -------- d-----w- c:\users\dextero1.0\appdata\roaming\Returnil
2011-11-10 00:30:49 -------- d-----w- c:\programdata\Returnil
2011-11-09 12:05:29 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-11-09 10:10:47 708608 ----a-w- c:\program files\common files\system\wab32.dll
2011-11-09 10:10:45 1290608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 10:10:43 2341888 ----a-w- c:\windows\system32\win32k.sys
2011-11-08 16:28:47 -------- d-----w- c:\program files\TVdream
2011-11-08 14:31:51 -------- d-----w- c:\program files\vShare.tv plugin
2011-11-07 13:56:13 -------- d-----w- c:\program files\common files\HP
2011-11-07 13:30:45 -------- d-----w- c:\users\dextero1.0\appdata\roaming\HpUpdate
2011-11-06 14:21:08 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-10-31 19:41:44 -------- d-----w- c:\users\dextero1.0\appdata\local\Facebook
.
==================== Find3M ====================
.
2011-11-18 12:19:14 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-21 21:46:48 17032 ----a-w- c:\windows\system32\drivers\eudskacs.sys
2011-10-21 21:46:46 39560 ----a-w- c:\windows\system32\drivers\eubakup.sys
2011-10-07 17:47:52 39640 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 17:47:51 488208 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 17:47:50 19600 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 17:47:10 300200 ----a-w- c:\windows\system32\guard32.dll
2011-10-03 03:06:03 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-18 01:25:52 409088 ----a-w- c:\windows\system32\systemcpl.dll
2011-09-18 01:25:52 13824 ----a-w- c:\windows\system32\slwga.dll
2011-09-18 00:16:08 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-09-01 02:35:59 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-08-31 15:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-26 09:11:08 444283 ----a-w- c:\program files\common files\WinPcapNmap.exe
.
============= FINISH: 15:11:29,06 ===============


Attach.txt

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume2
Install Date: 14/05/2010 13:40:16
System Uptime: 25/11/2011 11:17:51 (4 hours ago)
.
Motherboard: ASRock | | M3A785GM-LE/128M
Processor: AMD Sempron(tm) 140 Processor | CPUSocket | 2700/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 59 GiB total, 38,999 GiB free.
D: is FIXED (NTFS) - 192 GiB total, 170,976 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 10 GiB total, 9,06 GiB free.
G: is CDROM ()
I: is FIXED (NTFS) - 699 GiB total, 483,969 GiB free.
Y: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_81681849&REV_03\4&FD190B8&0&0028
Manufacturer: Realtek
Name: Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20) #2
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_81681849&REV_03\4&FD190B8&0&0028
Service: RTL8167
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
7-Zip 9.15 beta
abgx360 v1.0.4
Ad-Remover
Adobe Flash Player 11 Plugin
Adobe Reader 9.4.6 - Italiano
Aggiornamento driver Centro gestione dispositivi Windows Mobile
AnyDVD
Apple Application Support
Apple Software Update
Asterisk Key 10.0
ATI Catalyst Install Manager
µTorrent
Auslogics Disk Defrag
Avira AntiVir Personal - Free Antivirus
AVS DVD Player version 2.4
AVS4YOU Software Navigator 1.2
BufferChm
CameraHelperMsi
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
CDBurnerXP
Centro gestione dispositivi Windows Mobile
CheckDrive
CloneDVD 5.0.1.6
COMODO Internet Security
Copy
CPUID CPU-Z 1.54
D3DX10
Destinations
DeviceDiscovery
DJ_AIO_06_F2400_SW_Min
DriverMax 5
DVD Shrink 3.2
EaseUS Todo Backup Free 3.5
Eraser 6.0.9.2343
erLT
ERUNT 1.1j
Eusing Free Registry Cleaner
F2400
Facebook Video Calling 1.0.0.8953
FREE Word and Excel password recovery Wizard version 2.0.6
GIMP 2.6.8
Google Chrome
Google Earth Plug-in
Google Update Helper
GPBaseService2
Hercules DJ Products Series drivers
HiJackThis
HP Customer Participation Program 13.0
HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6
HP Imaging Device Functions 13.0
HP Print Projects 1.0
HP Smart Web Printing 4.5
HP Solution Center 13.0
HP Update
HP USB Disk Storage Format Tool
HPPhotoGadget
hpPrintProjects
HPProductAssistant
HPSSupply
hpWLPGInstaller
iKill
ImageShack Uploader 2.2.0
ImgBurn
Index.dat Analyzer v2.5
Java Auto Updater
Java(TM) 6 Update 29
JDownloader
Junk Mail filter update
K-Lite Codec Pack 6.9.0 (Full)
KeePass Password Safe 1.21
LimeWire 5.5.8
Logitech Vid HD
LWS Facebook
LWS Gallery
LWS Help_main
LWS Launcher
LWS Motion Detection
LWS Pictures And Video
LWS Twitter
LWS Video Mask Maker
LWS VideoEffects
LWS Webcam Software
LWS WLM Plugin
LWS YouTube Plugin
Malwarebytes' Anti-Malware versione 1.51.2.1300
MarketResearch
Matrix Screen Locker
McAfee SiteAdvisor
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MorphVOX Junior
Mozilla Firefox 8.0 (x86 it)
Mozilla Thunderbird (3.1.16)
MRU-Blaster v1.5 (Database 3/28/2004)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NTREGOPT 1.1j
OpenOffice.org 3.2
PaperCut Print Logger 1.7
PokerStars.it
Prevent Restore 3.17
Process Lasso
QuickTime
Raccolta foto di Windows Live
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Recuva
RefreshPC
Revo Uninstaller 1.93
Scan
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Shop for HP Supplies
Skype Toolbars
Skype™ 5.0
SmartWebPrinting
Software della webcam Logitech
SolutionCenter
SpywareBlaster 4.4
Status
Toolbox
TrayApp
TrueCrypt
TVdream
Ugolog
Uniblue ProcessScanner
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
VDownloader 3.6.943
Veetle TV
VirtualDJ PRO Full
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
vShare.tv plugin 1.3
WebReg
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player Firefox Plugin
WinPcap 4.1.1
WinRAR archiver
Wondershare Time Freeze
Yahoo! Toolbar
.
==== End Of File ===========================
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda DennioLab » ven nov 25, 2011 8:20 pm

Log di Emisoft Emergency Kit:

a-squared Free - Versione 1.0
Ultimo aggiornamento: 25/11/2011 15:19:44

Impostazioni scansione:

Tipo scansione: Completa
Oggetti: Memoria, Tracce, Cookies, C:\, D:\, F:\, I:\
Archivio scansioni: On
Euristica: Off
Scansione ADS: On

Scansione avviata: 25/11/2011 17:34:30

c:\program files\Passware rilevati: Trace.Directory.BackupKey!A2
c:\users\dextero1.0\appdata\roaming\microsoft\windows\start menu\programs\Passware rilevati: Trace.Directory.Messenger Key!A2
c:\program files\Passware\pk.chm rilevati: Trace.File.Messenger Key!A2
Value: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\portio\Enum --> Count rilevati: Trace.Registry.FreeMP3Player 2.2!A2
Value: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\portio\Enum --> NextInstance rilevati: Trace.Registry.FreeMP3Player 2.2!A2
Value: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\portio\Enum --> Count rilevati: Trace.Registry.FreeMP3Player 2.2!A2
Value: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\portio\Enum --> NextInstance rilevati: Trace.Registry.FreeMP3Player 2.2!A2
C:\Program Files\Passware\ariskkey.exe rilevati: Trojan.Win32.Ariskkey!A2
C:\Program Files\TVdream\TVdream Player.exe rilevati: Win32.SuspectCrc!IK
C:\Windows\Installer\ba6851.msi/_BFD72F8247824761913C6BB12430E68C rilevati: Win32.SuspectCrc!IK
I:\Programmi\WINDOWS\Software Manutenzione PC\apt\apt.exe rilevati: Riskware.Win32.APT!A2
I:\Programmi\WINDOWS\Software Manutenzione PC\refreshpcinstall.exe rilevati: Trojan.Win32.Toolbar.Zugo.AMN!A2
I:\Programmi\WINDOWS\Software Multimedia\TVdream-Setup.rar/_BFD72F8247824761913C6BB12430E68C rilevati: Win32.SuspectCrc!IK
I:\Programmi\WINDOWS\Software Multimedia\TVdream-Setup.rar/_FC6A9800EFE143AA89FA905D2685A5EA rilevati: Win32.SuspectCrc!IK
I:\Programmi\WINDOWS\Software Multimedia\TVdream.msi/_BFD72F8247824761913C6BB12430E68C rilevati: Win32.SuspectCrc!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Detective\Browser\mzcv.exe rilevati: Riskware.PSWTool.Win32.NetPass.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\astlog.exe rilevati: Riskware.PSWTool.Win32.Asterisk.c!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\BulletsPassView.exe rilevati: Riskware.PSWTool.Win64.ShowPassword.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\ChromePass.exe rilevati: Riskware.PSWTool.Win32.NetPas!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\iepv.exe rilevati: Riskware.PWTool.IEPassView!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\mailpv.exe rilevati: Riskware.PSWTool.Win32.MailPassView!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\mspass.exe rilevati: Riskware.Win32.MPass.A!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\netpass.exe rilevati: Riskware.PSWTool.Win32.NetPass!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\OperaPassView.exe rilevati: Riskware.PSWTool.OperaPassView!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\PasswordFox.exe rilevati: Riskware.PSWTool.Passwordfox!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\pspv.exe rilevati: Riskware.PSWTool.Win32.PassView.b!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\PstPassword.exe rilevati: Riskware.PSWTool.Win32.PassViewer!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\rdpv.exe rilevati: Riskware.PSWTool.Win32.IEPassView.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\SniffPass.exe rilevati: HackTool.Win32.Sniffer.Agent.aa!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\VNCPassView.exe rilevati: Riskware.PSWTool.Win32.VNCPwdump.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\WebBrowserPassView.exe rilevati: Riskware.Win32.WebBrowserPassView.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\WirelessKeyView.exe rilevati: possible-Threat.Hacktool.WKView!IK

Scansionati

File: 467809
Tracce: 401794
Cookies: 0
Processi: 18

Rilevato

File: 37
Tracce: 7
Cookies: 0
Processi: 0
Chiavi di Registro: 0

Fine scansione: 25/11/2011 19:01:33
Tempo scansione: 1:27:03

I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\WirelessKeyView.exe In quarantena possible-Threat.Hacktool.WKView!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\WebBrowserPassView.exe In quarantena Riskware.Win32.WebBrowserPassView.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\VNCPassView.exe In quarantena Riskware.PSWTool.Win32.VNCPwdump.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\SniffPass.exe In quarantena HackTool.Win32.Sniffer.Agent.aa!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\rdpv.exe In quarantena Riskware.PSWTool.Win32.IEPassView.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\PstPassword.exe In quarantena Riskware.PSWTool.Win32.PassViewer!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\pspv.exe In quarantena Riskware.PSWTool.Win32.PassView.b!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\PasswordFox.exe In quarantena Riskware.PSWTool.Passwordfox!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\OperaPassView.exe In quarantena Riskware.PSWTool.OperaPassView!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\netpass.exe In quarantena Riskware.PSWTool.Win32.NetPass!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\mspass.exe In quarantena Riskware.Win32.MPass.A!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\mailpv.exe In quarantena Riskware.PSWTool.Win32.MailPassView!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\iepv.exe In quarantena Riskware.PWTool.IEPassView!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\ChromePass.exe In quarantena Riskware.PSWTool.Win32.NetPas!IK
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\BulletsPassView.exe In quarantena Riskware.PSWTool.Win64.ShowPassword.AMN!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Password\Password Recovery\astlog.exe In quarantena Riskware.PSWTool.Win32.Asterisk.c!A2
I:\Programmi\WINDOWS\Software Sicurezza\Software Detective\Browser\mzcv.exe In quarantena Riskware.PSWTool.Win32.NetPass.AMN!A2
I:\Programmi\WINDOWS\Software Manutenzione PC\refreshpcinstall.exe In quarantena Trojan.Win32.Toolbar.Zugo.AMN!A2
I:\Programmi\WINDOWS\Software Manutenzione PC\apt\apt.exe In quarantena Riskware.Win32.APT!A2
I:\Programmi\WINDOWS\Crack!Win7\CW.zip/CW.eXe In quarantena HackTool.Win32.Wpakill!IK
C:\Program Files\TVdream\TVdream Player.exe In quarantena Win32.SuspectCrc!IK
C:\Windows\Installer\ba6851.msi/_BFD72F8247824761913C6BB12430E68C In quarantena Win32.SuspectCrc!IK
I:\Programmi\WINDOWS\Software Multimedia\TVdream-Setup.rar/_BFD72F8247824761913C6BB12430E68C In quarantena Win32.SuspectCrc!IK
I:\Programmi\WINDOWS\Software Multimedia\TVdream-Setup.rar/_FC6A9800EFE143AA89FA905D2685A5EA In quarantena Win32.SuspectCrc!IK
I:\Programmi\WINDOWS\Software Multimedia\TVdream.msi/_BFD72F8247824761913C6BB12430E68C In quarantena Win32.SuspectCrc!IK
C:\Program Files\Passware\ariskkey.exe In quarantena Trojan.Win32.Ariskkey!A2
Value: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\portio\Enum --> Count In quarantena Trace.Registry.FreeMP3Player 2.2!A2
Value: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\portio\Enum --> NextInstance In quarantena Trace.Registry.FreeMP3Player 2.2!A2
Value: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\portio\Enum --> Count In quarantena Trace.Registry.FreeMP3Player 2.2!A2
Value: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\portio\Enum --> NextInstance In quarantena Trace.Registry.FreeMP3Player 2.2!A2
c:\program files\Passware\pk.chm In quarantena Trace.File.Messenger Key!A2
c:\users\dextero1.0\appdata\roaming\microsoft\windows\start menu\programs\Passware In quarantena Trace.Directory.Messenger Key!A2
c:\program files\Passware In quarantena Trace.Directory.BackupKey!A2

In quarantena

File: 37
Tracce: 7
Cookies: 0


Qualcosa ho ripristina perche programmi che uso tipo TVdream Player...il resto lo eliminato!!
Avatar utente
DennioLab
Aficionado
Aficionado
 
Messaggi: 33
Iscritto il: gio dic 16, 2010 9:35 am

Re: [LOG:] Antivir,ComboFix,HiJackThis

Messaggioda hashcat » dom nov 27, 2011 6:02 pm

A questo punto direi che sei a posto.

Ci sono molti strumenti per il recupero password nella partizione I:\ ma credo che li abbia scaricati tu intenzionalmente.
Se non fosse così elimina la cartella e il suo contenuto (dove si trovano gli strumenti) con questo script [^]
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 4 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising