----------------- FindyKill V4.712 ------------------
* User: LuPo - ICE
* Executed from : C:\Programmi\FindyKill
* Update on 14/01/09 by Chiquitine29
* Start at 18:00:42 the 15/01/2009
* Windows XP - Internet Explorer 7.0.5730.13
((((((((((((((((( *** Searching *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\sched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avesvc.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avmailc.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avguard.exe
C:\WINDOWS\services.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe
C:\Documents and Settings\LuPo\Desktop\HiJackThis.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
--------------- [ Infected files / folders ] ----------------
»»»» Presence Files in C:
»»»» Presence Files in C:\WINDOWS
»»»» Presence Files in C:\WINDOWS\Prefetch
Found ! - C:\WINDOWS\prefetch\1.EXE-123305E2.pf
»»»» Presence Files in C:\WINDOWS\system32
»»»» Presence Files in C:\WINDOWS\system32\drivers
»»»» Presence Files in C:\Documents and Settings\LuPo\Dati applicazioni
»»»» Presence Files in C:\DOCUME~1\LuPo\IMPOST~1\Temp
--------------- [ Registry / Startup ] ----------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
Sidebar=C:\Programmi\Windows Sidebar\sidebar.exe /autoRun
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
Win32 SDK=C:\WINDOWS\system32\lzadovaje.exe
C-Media Mixer=Mixer.exe /startup
avgnt="C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
services=C:\WINDOWS\services.exe
[HKEY_CURRENT_USER\software\local appwizard-generated applications\Mixer]
--------------- [ Registry / Infected keys ] ----------------
--------------- [ States / Services ] ----------------
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
EapHost - Type of startup = 3
Ip6Fw - Type of startup = 3
/!\ SharedAccess - Type of startup = 4
wuauserv - Type of startup = 2
/!\ wscsvc - Type of startup = 4
--------------- [ Searching in removable drives ] ----------------
+- Informations :
C: - Unit… fissa
D: - Unit… CD-ROM
E: - Unit… rimovibile
+- Contents of autorun : C:\autorun.inf
[AutoRun]
open=unlducgit.exe
shellexecute=unlducgit.exe
shell\Auto\command=unlducgit.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkfk1
+- Contents of autorun : D:\autorun.inf
[autorun]
open = setup.exe
icon = Autorun.ico
+- Contents of autorun : E:\autorun.inf
[AutoRun]
open=unlducgit.exe
shellexecute=unlducgit.exe
shell\Auto\command=unlducgit.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkfk1
+- Presence of files :
Found ! [15/01/2009 17.11][--ah-----] - C:\autorun.inf
Found ! [01/11/2008 00.52][-r-h-----] - D:\autorun.inf
Found ! [15/01/2009 17.11][--ah-----] - E:\autorun.inf
--------------- [ Registry / Mountpoint2 ] ----------------
-> Not found !
------------------- ! End of report ! --------------------
* User: LuPo - ICE
* Executed from : C:\Programmi\FindyKill
* Update on 14/01/09 by Chiquitine29
* Start at 18:00:42 the 15/01/2009
* Windows XP - Internet Explorer 7.0.5730.13
((((((((((((((((( *** Searching *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\sched.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avesvc.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avmailc.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avguard.exe
C:\WINDOWS\services.exe
C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe
C:\Documents and Settings\LuPo\Desktop\HiJackThis.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
--------------- [ Infected files / folders ] ----------------
»»»» Presence Files in C:
»»»» Presence Files in C:\WINDOWS
»»»» Presence Files in C:\WINDOWS\Prefetch
Found ! - C:\WINDOWS\prefetch\1.EXE-123305E2.pf
»»»» Presence Files in C:\WINDOWS\system32
»»»» Presence Files in C:\WINDOWS\system32\drivers
»»»» Presence Files in C:\Documents and Settings\LuPo\Dati applicazioni
»»»» Presence Files in C:\DOCUME~1\LuPo\IMPOST~1\Temp
--------------- [ Registry / Startup ] ----------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
Sidebar=C:\Programmi\Windows Sidebar\sidebar.exe /autoRun
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
Win32 SDK=C:\WINDOWS\system32\lzadovaje.exe
C-Media Mixer=Mixer.exe /startup
avgnt="C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
services=C:\WINDOWS\services.exe
[HKEY_CURRENT_USER\software\local appwizard-generated applications\Mixer]
--------------- [ Registry / Infected keys ] ----------------
--------------- [ States / Services ] ----------------
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
EapHost - Type of startup = 3
Ip6Fw - Type of startup = 3
/!\ SharedAccess - Type of startup = 4
wuauserv - Type of startup = 2
/!\ wscsvc - Type of startup = 4
--------------- [ Searching in removable drives ] ----------------
+- Informations :
C: - Unit… fissa
D: - Unit… CD-ROM
E: - Unit… rimovibile
+- Contents of autorun : C:\autorun.inf
[AutoRun]
open=unlducgit.exe
shellexecute=unlducgit.exe
shell\Auto\command=unlducgit.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkfk1
+- Contents of autorun : D:\autorun.inf
[autorun]
open = setup.exe
icon = Autorun.ico
+- Contents of autorun : E:\autorun.inf
[AutoRun]
open=unlducgit.exe
shellexecute=unlducgit.exe
shell\Auto\command=unlducgit.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkfk1
+- Presence of files :
Found ! [15/01/2009 17.11][--ah-----] - C:\autorun.inf
Found ! [01/11/2008 00.52][-r-h-----] - D:\autorun.inf
Found ! [15/01/2009 17.11][--ah-----] - E:\autorun.inf
--------------- [ Registry / Mountpoint2 ] ----------------
-> Not found !
------------------- ! End of report ! --------------------
Questo è il log di findykill... tra questo log e quello di prima di hijackthis cosa trovate.?