Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

controllo log

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

controllo log

Messaggioda ivan92 » dom feb 22, 2009 8:00 pm

potreste controllarmi il log?..gli antivirus non mi segnalano virus ma confido in voi...ho la connessione ad internet parecchio lenta

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20.02.48, on 22/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Program Files\Hp\Digital Imaging\bin\HpqSRmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Utente\Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://it.search.yahoo.com/search?fr=mcafee&p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{035A7A39-03E6-4522-9147-59CAF8CF44C6}: NameServer = 85.37.17.6 85.38.28.89
O17 - HKLM\System\CS1\Services\Tcpip\..\{035A7A39-03E6-4522-9147-59CAF8CF44C6}: NameServer = 85.37.17.6 85.38.28.89
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: APSHook.dll
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

--
End of file - 12226 bytes
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)

Re: controllo log

Messaggioda stevens » dom feb 22, 2009 8:28 pm

ciao

Avvia hijackthis, con tutte le applicazioni chiuse, premi su Do a system scan only , spunta ed elimina (fix checked) le seguenti righe:

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://it.search.yahoo.com/search?fr=mcafee&p=%s

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe



appena finita questa operazione Scarica ed installa MalwareBytes: clicca qui per il download

http://www.malwarebytes.org/mbam/program/mbam-setup.exe
esegui una scansione completa del sistema e, una volta terminata la scansione, allega il log che verrà rilasciato
Avatar utente
stevens
Bronze Member
Bronze Member
 
Messaggi: 678
Iscritto il: mer feb 18, 2009 1:39 pm

Re: controllo log

Messaggioda ivan92 » lun feb 23, 2009 9:29 am

non riesco ad eliminare gli ultimi due oggetti che mi hai detto....mi dice di chiudere tutte le finestre di internet explorer anche se non ce ne sono di aperte...poi adesso l'antivirus mi dice che non è aggiornato e non si vuole aggiornare.
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)


Re: controllo log

Messaggioda stevens » lun feb 23, 2009 9:34 am

prova ad eliminare(fixare) gli elementi da modalita' provvisoria

per accedere alla modalità provvisoria: all'avvio del pc, prima che inizi a caricare Windows, premi ripetutamente F8. Uscirà la finestra del menu Opzioni avanzate di Windows => scegli modalità provvisoria (usa il tasto freccia)
Avatar utente
stevens
Bronze Member
Bronze Member
 
Messaggi: 678
Iscritto il: mer feb 18, 2009 1:39 pm

Re: controllo log

Messaggioda Martina Stella » lun feb 23, 2009 2:59 pm

Devi fixare:
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://it.search.yahoo.com/search?fr=mcafee&p=%s
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe ( questo è un componente spyware)

se la connessione è lenta potrebbe essere dovuta da errori di registro troppi file temporanei: scarica ADVANCED SYSTEM CARE [brindisi]
http://www.vampirediaries-love.net/
Avatar utente
Martina Stella
Senior Member
Senior Member
 
Messaggi: 354
Iscritto il: ven gen 16, 2009 3:02 pm
Località: Treviso, Veneto

Re: controllo log

Messaggioda ivan92 » lun feb 23, 2009 4:57 pm

ok ho eliminato i file e fatto la scansione con malwarebites che non ho rilevato niente
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)

Re: controllo log

Messaggioda stevens » lun feb 23, 2009 5:20 pm

avresti dovuto postare il log di malwarebytes

prova a fare u po' di pulizie

Scarica ed installa CCleaner: clicca qui per il download

http://www.filehippo.com/download_ccleaner/

Una volta installato configuralo in questo modo:
lancia il programma, nel menu di sinistra portati alla voce Opzioni e nella finestra successiva clicca su:
Impostazioni, e spunta la voce Cancellazione sicura (lenta)
poi clicca su:
Avanzate, togli la spunta alla voce Cancella solo file più vecchi di 48 ore
alla voce Pulizia, nella sezione Avanzate spunta le voci Vecchi dati Prefetch e Disinstallatori aggiornamenti di WinUpdate
nel menu a sinistra, clicca sulla voce Pulizia
clicca su tasto Avvia pulizia per eseguire la scansione
finita la scansione, sempre nel menu a sinistra, clicca sulla voce Registro e spunta tutte le voci comprese nella sezione meno la voce estensioni file non usate
clicca sul tasto Trova problemi ed avvia una scansione
al termine della scansione clicca sulla voce Ripara selezionati e prosegui con la riparazione (questo ultimo passaggio ripetilo più volte, fino a quando non verranno rilevati più problemi da correggere)
Accetta quando ti dice se vuoi un back-up del registro e conservalo


Scarica Lop S&D | http://eric.71.mespages.googlepages.com/LopSD.exe
con tutte le applicazioni chiuse e disconnesso
doppio click su LopSD
scegli la lingua E (invio)
1 (ricerca) invio

al termine dello scan riavvia LopSD
questa volta scegli l'opzione 2 (invio)

allega il report C:\LopR.txt insieme ad un nuovo log di hijackthis
Avatar utente
stevens
Bronze Member
Bronze Member
 
Messaggi: 678
Iscritto il: mer feb 18, 2009 1:39 pm

Re: controllo log

Messaggioda crazy.cat » lun feb 23, 2009 7:12 pm

Comincia a buttare via Windows schifender e il mattone spyware doctor, li sostituisci con spyware terminator per il controllo in tempo reale e malwarebytes per pulizie occasionali.

Programmi che possono essere rimossi senza problemi e che allegeriscono il pc.
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Re: controllo log

Messaggioda ivan92 » mar feb 24, 2009 11:13 am

ecco i due file di lop s&d prima quella della ricerca poi l'altro

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Home Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz )
BIOS : Ver 1.00PARTTBL
USER : Utente ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:221 Go (Free:26 Go)
D:\ (Local Disk) - NTFS - Total:11 Go (Free:7 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 24/02/2009|11.01 )

[ UAC => 1 ]

--------------------\\ Listing folders in Local

[14/11/2008|19.59] C:\Users\Utente\AppData\Local\Activision
[03/09/2008|15.33] C:\Users\Utente\AppData\Local\Adobe
[03/09/2008|12.41] C:\Users\Utente\AppData\Local\Ahead
[04/09/2008|10.07] C:\Users\Utente\AppData\Local\ashampoo
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\AtStart.txt
[21/12/2008|16.15] C:\Users\Utente\AppData\Local\CamSpace
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Cronologia
[01/09/2008|10.13] C:\Users\Utente\AppData\Local\d3d9caps.dat
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Dati applicazioni
[23/02/2009|17.02] C:\Users\Utente\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[09/10/2008|13.11] C:\Users\Utente\AppData\Local\Downloaded Installations
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\DSwitch.txt
[21/12/2008|16.30] C:\Users\Utente\AppData\Local\FnF4.txt
[15/02/2009|10.17] C:\Users\Utente\AppData\Local\GDIPFONTCACHEV1.DAT
[14/02/2009|19.56] C:\Users\Utente\AppData\Local\GMail Drive
[07/02/2009|20.03] C:\Users\Utente\AppData\Local\Google
[05/09/2008|14.04] C:\Users\Utente\AppData\Local\HP
[23/02/2009|22.49] C:\Users\Utente\AppData\Local\IconCache.db
[03/09/2008|09.31] C:\Users\Utente\AppData\Local\IsolatedStorage
[03/09/2008|13.54] C:\Users\Utente\AppData\Local\Lingoes
[14/01/2009|19.52] C:\Users\Utente\AppData\Local\Microsoft
[12/09/2008|14.00] C:\Users\Utente\AppData\Local\Microsoft Games
[08/12/2008|10.19] C:\Users\Utente\AppData\Local\Microsoft Help
[02/09/2008|08.55] C:\Users\Utente\AppData\Local\Mozilla
[05/09/2008|14.11] C:\Users\Utente\AppData\Local\OLYMPUS
[02/02/2009|19.15] C:\Users\Utente\AppData\Local\Opera
[27/11/2008|15.27] C:\Users\Utente\AppData\Local\PunkBuster
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\QSwitch.txt
[23/02/2009|16.55] C:\Users\Utente\AppData\Local\QuickPlay
[15/01/2009|19.20] C:\Users\Utente\AppData\Local\Rockstar Games
[03/09/2008|07.47] C:\Users\Utente\AppData\Local\Scansoft
[22/12/2008|17.06] C:\Users\Utente\AppData\Local\TechSmith
[24/02/2009|11.00] C:\Users\Utente\AppData\Local\Temp
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Temporary Internet Files
[14/12/2008|11.29] C:\Users\Utente\AppData\Local\Temporary Projects
[04/09/2008|09.30] C:\Users\Utente\AppData\Local\VirtualStore
[8|File] C:\Users\Utente\AppData\Local\byte
[30|Directory] C:\Users\Utente\AppData\Local\byte disponibili

--------------------\\ Scheduled Tasks located in C:\Windows\Tasks

[04/09/2008 09.43][--a------] C:\Windows\tasks\McDefragTask.job
[04/09/2008 09.43][--a------] C:\Windows\tasks\McQcTask.job
[24/02/2009 09.30][--ah-----] C:\Windows\tasks\SA.DAT
[23/02/2009 22.49][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing Folders in C:\ProgramData

[07/11/2008|14.40] C:\ProgramData\Adobe
[02/09/2008|10.22] C:\ProgramData\Apple Computer
[04/09/2008|10.07] C:\ProgramData\ashampoo
[02/09/2008|12.13] C:\ProgramData\CanonBJ
[03/09/2008|09.23] C:\ProgramData\CyberLink
[01/09/2008|09.59] C:\ProgramData\Dati applicazioni
[01/09/2008|09.59] C:\ProgramData\Desktop
[01/09/2008|09.59] C:\ProgramData\Documenti
[05/09/2008|15.28] C:\ProgramData\Downloaded Installations
[09/10/2008|13.12] C:\ProgramData\Electronic Arts
[06/02/2009|15.33] C:\ProgramData\Extensions
[01/09/2008|10.19] C:\ProgramData\Google
[23/02/2009|11.34] C:\ProgramData\Google Updater
[20/07/2007|12.35] C:\ProgramData\Hewlett-Packard
[05/09/2008|14.02] C:\ProgramData\HP
[05/09/2008|14.04] C:\ProgramData\hpzinstall.log
[20/07/2007|11.44] C:\ProgramData\InstallShield
[04/09/2008|09.25] C:\ProgramData\LUUnInstall.LiveUpdate
[31/10/2008|16.06] C:\ProgramData\Malwarebytes
[04/09/2008|09.30] C:\ProgramData\McAfee
[01/09/2008|09.59] C:\ProgramData\Menu Avvio
[03/09/2008|07.47] C:\ProgramData\Messenger Plus!
[22/02/2009|16.14] C:\ProgramData\Microsoft
[08/12/2008|10.09] C:\ProgramData\Microsoft Help
[01/09/2008|09.59] C:\ProgramData\Modelli
[21/12/2008|15.49] C:\ProgramData\NVIDIA
[24/02/2009|09.31] C:\ProgramData\nvModes.001
[15/02/2009|19.08] C:\ProgramData\nvModes.dat
[01/09/2008|09.59] C:\ProgramData\Preferiti
[16/01/2009|20.14] C:\ProgramData\Roxio
[02/09/2008|12.18] C:\ProgramData\ScanSoft
[03/09/2008|17.52] C:\ProgramData\SiteAdvisor
[09/09/2008|12.45] C:\ProgramData\Sonic
[04/09/2008|09.25] C:\ProgramData\Symantec
[24/12/2008|09.29] C:\ProgramData\TechSmith
[22/02/2009|18.15] C:\ProgramData\TEMP
[09/09/2008|13.19] C:\ProgramData\Ubisoft
[08/09/2008|12.17] C:\ProgramData\VistaCodecs
[29/09/2008|16.34] C:\ProgramData\WindowsSearch
[02/09/2008|11.54] C:\ProgramData\WLInstaller
[4|File] C:\ProgramData\byte
[38|Directory] C:\ProgramData\byte disponibili

--------------------\\ Listing Folders in C:\Program Files

[14/11/2008|15.44] C:\Program Files\Activision
[07/11/2008|14.39] C:\Program Files\Adobe
[15/02/2009|19.10] C:\Program Files\AGEIA Technologies
[30/01/2009|16.26] C:\Program Files\AmitySource
[02/09/2008|12.15] C:\Program Files\ArcSoft
[04/09/2008|10.06] C:\Program Files\Ashampoo
[01/09/2008|10.08] C:\Program Files\Bioscrypt
[18/01/2009|10.53] C:\Program Files\Bit Che
[30/11/2008|15.18] C:\Program Files\CamSpace
[02/09/2008|12.21] C:\Program Files\Canon
[02/09/2008|12.09] C:\Program Files\CanonBJ
[23/02/2009|22.31] C:\Program Files\CCleaner
[30/12/2008|16.30] C:\Program Files\Common Files
[03/09/2008|10.21] C:\Program Files\DAEMON Tools Lite
[02/09/2008|14.40] C:\Program Files\DivX
[15/02/2009|19.12] C:\Program Files\EA Games
[14/01/2009|15.43] C:\Program Files\Electronic Arts
[12/12/2008|18.20] C:\Program Files\Enigma Software Group
[01/09/2008|09.59] C:\Program Files\File comuni [C:\Program Files\Common Files]
[31/01/2009|14.30] C:\Program Files\FileZilla FTP Client
[01/09/2008|10.08] C:\Program Files\Fingerprint Sensor
[12/12/2008|14.48] C:\Program Files\FLV Player
[09/10/2008|15.02] C:\Program Files\Game_Maker7
[20/01/2009|16.29] C:\Program Files\GeoGebra
[30/12/2008|17.59] C:\Program Files\Gimp-2.0
[02/09/2008|09.12] C:\Program Files\Google
[23/12/2008|16.10] C:\Program Files\Hedgewars 0.9.7
[20/07/2007|12.32] C:\Program Files\Hewlett-Packard
[23/02/2009|13.03] C:\Program Files\Hp
[20/07/2007|12.22] C:\Program Files\HPQ
[23/02/2009|13.03] C:\Program Files\InstallShield Installation Information
[06/09/2008|13.22] C:\Program Files\Internet Explorer
[13/09/2008|09.57] C:\Program Files\Java
[14/02/2009|17.17] C:\Program Files\JRE
[22/02/2009|22.33] C:\Program Files\Malwarebytes' Anti-Malware
[22/02/2009|13.44] C:\Program Files\McAfee
[04/09/2008|09.27] C:\Program Files\McAfee.com
[10/02/2009|17.23] C:\Program Files\Messenger Plus! Live
[30/12/2008|16.35] C:\Program Files\Microsoft
[02/11/2006|13.37] C:\Program Files\Microsoft Games
[14/01/2009|19.52] C:\Program Files\Microsoft Games for Windows - LIVE
[20/07/2007|12.04] C:\Program Files\Microsoft Office
[08/12/2008|10.05] C:\Program Files\Microsoft SDKs
[22/10/2008|12.56] C:\Program Files\Microsoft Silverlight
[08/12/2008|10.10] C:\Program Files\Microsoft SQL Server
[22/02/2009|16.10] C:\Program Files\Microsoft SQL Server Compact Edition
[22/02/2009|16.14] C:\Program Files\Microsoft Sync Framework
[08/12/2008|10.10] C:\Program Files\Microsoft Synchronization Services
[08/12/2008|10.10] C:\Program Files\Microsoft Visual Studio 9.0
[10/09/2008|21.35] C:\Program Files\Microsoft Works
[08/12/2008|10.06] C:\Program Files\Microsoft.NET
[20/07/2007|11.22] C:\Program Files\Motorola
[06/09/2008|13.23] C:\Program Files\Movie Maker
[05/02/2009|17.47] C:\Program Files\Mozilla Firefox
[02/11/2006|13.37] C:\Program Files\MSBuild
[01/09/2008|10.44] C:\Program Files\MSXML 4.0
[03/09/2008|13.03] C:\Program Files\Nero
[07/11/2008|14.49] C:\Program Files\Notepad++
[02/09/2008|10.21] C:\Program Files\OLYMPUS
[19/10/2008|12.17] C:\Program Files\OpenOffice.org 2.4
[14/02/2009|17.17] C:\Program Files\OpenOffice.org 3
[02/02/2009|19.15] C:\Program Files\Opera
[27/11/2008|17.24] C:\Program Files\PC Wizard 2008
[18/01/2009|10.57] C:\Program Files\PDFCreator
[02/09/2008|10.23] C:\Program Files\QuickTime
[20/07/2007|12.20] C:\Program Files\Realtek
[07/02/2009|23.06] C:\Program Files\Recuva
[02/11/2006|13.37] C:\Program Files\Reference Assemblies
[14/01/2009|15.49] C:\Program Files\Rockstar Games
[20/07/2007|11.51] C:\Program Files\Roxio
[02/09/2008|12.18] C:\Program Files\ScanSoft
[20/07/2007|12.19] C:\Program Files\Servizi in linea
[04/09/2008|09.29] C:\Program Files\SiteAdvisor
[22/02/2009|17.45] C:\Program Files\Spyware Doctor
[28/09/2008|13.30] C:\Program Files\Symantec
[20/07/2007|11.28] C:\Program Files\Synaptics
[18/01/2009|09.36] C:\Program Files\Techland
[22/12/2008|16.46] C:\Program Files\TechSmith
[16/12/2008|18.28] C:\Program Files\Tint
[04/02/2009|16.56] C:\Program Files\TutoreDattilo
[12/02/2009|15.25] C:\Program Files\TuxMath
[28/10/2008|14.58] C:\Program Files\Ubisoft
[02/11/2006|14.01] C:\Program Files\Uninstall Information
[02/09/2008|14.35] C:\Program Files\uTorrent
[21/12/2008|10.41] C:\Program Files\VideoLAN
[08/09/2008|12.18] C:\Program Files\VistaCodecPack
[06/09/2008|13.23] C:\Program Files\Windows Calendar
[06/09/2008|13.22] C:\Program Files\Windows Collaboration
[06/09/2008|13.22] C:\Program Files\Windows Defender
[06/09/2008|13.22] C:\Program Files\Windows Journal
[22/02/2009|16.15] C:\Program Files\Windows Live
[08/10/2008|14.56] C:\Program Files\Windows Live Safety Center
[30/12/2008|16.34] C:\Program Files\Windows Live SkyDrive
[11/02/2009|21.24] C:\Program Files\Windows Mail
[06/09/2008|13.22] C:\Program Files\Windows Media Player
[01/09/2008|09.59] C:\Program Files\Windows NT
[06/09/2008|13.22] C:\Program Files\Windows Photo Gallery
[06/09/2008|13.23] C:\Program Files\Windows Sidebar
[02/09/2008|14.46] C:\Program Files\WinRAR
[07/02/2009|20.20] C:\Program Files\xchat
[11/09/2008|18.25] C:\Program Files\Yahoo!
[20/01/2009|16.29] C:\Program Files\Zero G Registry
[0|File] C:\Program Files\byte
[104|Directory] C:\Program Files\byte disponibili

--------------------\\ Listing Folders in C:\Program Files\Common Files

[07/11/2008|14.40] C:\Program Files\Common Files\Adobe
[05/09/2008|14.02] C:\Program Files\Common Files\HP
[20/07/2007|12.19] C:\Program Files\Common Files\InstallShield
[20/07/2007|12.35] C:\Program Files\Common Files\Java
[20/07/2007|12.22] C:\Program Files\Common Files\LightScribe
[04/09/2008|09.27] C:\Program Files\Common Files\McAfee
[22/02/2009|16.05] C:\Program Files\Common Files\microsoft shared
[02/09/2008|10.28] C:\Program Files\Common Files\muvee Technologies
[02/09/2008|14.40] C:\Program Files\Common Files\PX Storage Engine
[20/07/2007|11.50] C:\Program Files\Common Files\Roxio Shared
[02/09/2008|12.18] C:\Program Files\Common Files\ScanSoft Shared
[02/11/2006|12.18] C:\Program Files\Common Files\Services
[20/07/2007|11.51] C:\Program Files\Common Files\Sonic Shared
[02/11/2006|12.18] C:\Program Files\Common Files\SpeechEngines
[20/07/2007|11.51] C:\Program Files\Common Files\SureThing Shared
[04/09/2008|09.26] C:\Program Files\Common Files\Symantec Shared
[06/09/2008|13.22] C:\Program Files\Common Files\System
[22/12/2008|16.46] C:\Program Files\Common Files\TechSmith Shared
[30/12/2008|16.30] C:\Program Files\Common Files\Windows Live
[02/09/2008|11.58] C:\Program Files\Common Files\WindowsLiveInstaller
[15/02/2009|19.10] C:\Program Files\Common Files\Wise Installation Wizard
[0|File] C:\Program Files\Common Files\byte
[23|Directory] C:\Program Files\Common Files\byte disponibili

--------------------\\ Process

( 79 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-24 11:01:46
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 7

--------------------\\ Searching for other infections

--------------------\\ Cracks & Keygens ..

C:\Users\Utente\AppData\Roaming\uTorrent\Ashampoo.Burning.Studio.8.v8.03.Bilingual.+.Keygen.[CrAsH].rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Brothers.in.Arms.Hells.Highway.CRACK.ONLY-RELOADED.rar.1.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Brothers.in.Arms.Hells.Highway.CRACK.ONLY-RELOADED.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio 5.1 - With Keygen.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio 5.1 - With Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Crysis.Warhead.Crack-TDM.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Far Cry 2 CRACK & Patch.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Far Cry 2 Crack.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA IV Crack NoCD working.exe.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.Only.READNFO-0x0008.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.1.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.2.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.Securom.Bypass.Launcher.UBER-PROPER-FeD0R.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Keygen_Far-Cry.2-Version_2008-Razor1911.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Mirror's Edge no-cd Crack + KeyGen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need for Speed Undercover Keygen Only.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need for Speed Undercover Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need.For.Speed.Undercover.Crack.and.Keygen.Only-RELOADED.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Rainbow Six Vegas 2 - 1.03 Crack - CALIBER.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\RAZOR1911 [WEB SEED] FAR CRY 2 CRACK - REAL 100% FULLY WORKING.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore - CRACKFIX-RELOADED - [Demonoid.com].torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore RELOADED - crack only.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore-keygen.torrent
C:\Users\Utente\Downloads\Camtasia Studio Keygen
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen
C:\Users\Utente\Downloads\Camtasia Studio Keygen\Camtasia Studio 6 Keygen.exe
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen\Mirror's Edge KeyGen.exe
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen\MirrorsEdge.exe


[F:4][D:1]-> C:\Users\Utente\AppData\Local\Temp
[F:4][D:1]-> C:\Users\Utente\AppData\Roaming\MICROS~1\Windows\Cookies
[F:106][D:12]-> C:\Users\Utente\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:32][D:2]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 24/02/2009|11.03 - Option : [1]

il secondo

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Home Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz )
BIOS : Ver 1.00PARTTBL
USER : Utente ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:221 Go (Free:26 Go)
D:\ (Local Disk) - NTFS - Total:11 Go (Free:7 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 24/02/2009|11.04 )

[ UAC => 1 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

-
[ Hosts file ] .. Restored!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in Local

[14/11/2008|19.59] C:\Users\Utente\AppData\Local\Activision
[03/09/2008|15.33] C:\Users\Utente\AppData\Local\Adobe
[03/09/2008|12.41] C:\Users\Utente\AppData\Local\Ahead
[04/09/2008|10.07] C:\Users\Utente\AppData\Local\ashampoo
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\AtStart.txt
[21/12/2008|16.15] C:\Users\Utente\AppData\Local\CamSpace
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Cronologia
[01/09/2008|10.13] C:\Users\Utente\AppData\Local\d3d9caps.dat
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Dati applicazioni
[23/02/2009|17.02] C:\Users\Utente\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[09/10/2008|13.11] C:\Users\Utente\AppData\Local\Downloaded Installations
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\DSwitch.txt
[21/12/2008|16.30] C:\Users\Utente\AppData\Local\FnF4.txt
[15/02/2009|10.17] C:\Users\Utente\AppData\Local\GDIPFONTCACHEV1.DAT
[14/02/2009|19.56] C:\Users\Utente\AppData\Local\GMail Drive
[07/02/2009|20.03] C:\Users\Utente\AppData\Local\Google
[05/09/2008|14.04] C:\Users\Utente\AppData\Local\HP
[23/02/2009|22.49] C:\Users\Utente\AppData\Local\IconCache.db
[03/09/2008|09.31] C:\Users\Utente\AppData\Local\IsolatedStorage
[03/09/2008|13.54] C:\Users\Utente\AppData\Local\Lingoes
[14/01/2009|19.52] C:\Users\Utente\AppData\Local\Microsoft
[12/09/2008|14.00] C:\Users\Utente\AppData\Local\Microsoft Games
[08/12/2008|10.19] C:\Users\Utente\AppData\Local\Microsoft Help
[02/09/2008|08.55] C:\Users\Utente\AppData\Local\Mozilla
[05/09/2008|14.11] C:\Users\Utente\AppData\Local\OLYMPUS
[02/02/2009|19.15] C:\Users\Utente\AppData\Local\Opera
[27/11/2008|15.27] C:\Users\Utente\AppData\Local\PunkBuster
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\QSwitch.txt
[23/02/2009|16.55] C:\Users\Utente\AppData\Local\QuickPlay
[15/01/2009|19.20] C:\Users\Utente\AppData\Local\Rockstar Games
[03/09/2008|07.47] C:\Users\Utente\AppData\Local\Scansoft
[22/12/2008|17.06] C:\Users\Utente\AppData\Local\TechSmith
[24/02/2009|11.04] C:\Users\Utente\AppData\Local\Temp
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Temporary Internet Files
[14/12/2008|11.29] C:\Users\Utente\AppData\Local\Temporary Projects
[04/09/2008|09.30] C:\Users\Utente\AppData\Local\VirtualStore
[8|File] C:\Users\Utente\AppData\Local\byte
[30|Directory] C:\Users\Utente\AppData\Local\byte disponibili

--------------------\\ Scheduled Tasks located in C:\Windows\Tasks

[04/09/2008 09.43][--a------] C:\Windows\tasks\McDefragTask.job
[04/09/2008 09.43][--a------] C:\Windows\tasks\McQcTask.job
[24/02/2009 09.30][--ah-----] C:\Windows\tasks\SA.DAT
[23/02/2009 22.49][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing Folders in C:\ProgramData

[07/11/2008|14.40] C:\ProgramData\Adobe
[02/09/2008|10.22] C:\ProgramData\Apple Computer
[04/09/2008|10.07] C:\ProgramData\ashampoo
[02/09/2008|12.13] C:\ProgramData\CanonBJ
[03/09/2008|09.23] C:\ProgramData\CyberLink
[01/09/2008|09.59] C:\ProgramData\Dati applicazioni
[01/09/2008|09.59] C:\ProgramData\Desktop
[01/09/2008|09.59] C:\ProgramData\Documenti
[05/09/2008|15.28] C:\ProgramData\Downloaded Installations
[09/10/2008|13.12] C:\ProgramData\Electronic Arts
[06/02/2009|15.33] C:\ProgramData\Extensions
[01/09/2008|10.19] C:\ProgramData\Google
[23/02/2009|11.34] C:\ProgramData\Google Updater
[20/07/2007|12.35] C:\ProgramData\Hewlett-Packard
[05/09/2008|14.02] C:\ProgramData\HP
[05/09/2008|14.04] C:\ProgramData\hpzinstall.log
[20/07/2007|11.44] C:\ProgramData\InstallShield
[04/09/2008|09.25] C:\ProgramData\LUUnInstall.LiveUpdate
[31/10/2008|16.06] C:\ProgramData\Malwarebytes
[04/09/2008|09.30] C:\ProgramData\McAfee
[01/09/2008|09.59] C:\ProgramData\Menu Avvio
[03/09/2008|07.47] C:\ProgramData\Messenger Plus!
[22/02/2009|16.14] C:\ProgramData\Microsoft
[08/12/2008|10.09] C:\ProgramData\Microsoft Help
[01/09/2008|09.59] C:\ProgramData\Modelli
[21/12/2008|15.49] C:\ProgramData\NVIDIA
[24/02/2009|09.31] C:\ProgramData\nvModes.001
[15/02/2009|19.08] C:\ProgramData\nvModes.dat
[01/09/2008|09.59] C:\ProgramData\Preferiti
[16/01/2009|20.14] C:\ProgramData\Roxio
[02/09/2008|12.18] C:\ProgramData\ScanSoft
[03/09/2008|17.52] C:\ProgramData\SiteAdvisor
[09/09/2008|12.45] C:\ProgramData\Sonic
[04/09/2008|09.25] C:\ProgramData\Symantec
[24/12/2008|09.29] C:\ProgramData\TechSmith
[22/02/2009|18.15] C:\ProgramData\TEMP
[09/09/2008|13.19] C:\ProgramData\Ubisoft
[08/09/2008|12.17] C:\ProgramData\VistaCodecs
[29/09/2008|16.34] C:\ProgramData\WindowsSearch
[02/09/2008|11.54] C:\ProgramData\WLInstaller
[4|File] C:\ProgramData\byte
[38|Directory] C:\ProgramData\byte disponibili

--------------------\\ Listing Folders in C:\Program Files

[14/11/2008|15.44] C:\Program Files\Activision
[07/11/2008|14.39] C:\Program Files\Adobe
[15/02/2009|19.10] C:\Program Files\AGEIA Technologies
[30/01/2009|16.26] C:\Program Files\AmitySource
[02/09/2008|12.15] C:\Program Files\ArcSoft
[04/09/2008|10.06] C:\Program Files\Ashampoo
[01/09/2008|10.08] C:\Program Files\Bioscrypt
[18/01/2009|10.53] C:\Program Files\Bit Che
[30/11/2008|15.18] C:\Program Files\CamSpace
[02/09/2008|12.21] C:\Program Files\Canon
[02/09/2008|12.09] C:\Program Files\CanonBJ
[23/02/2009|22.31] C:\Program Files\CCleaner
[30/12/2008|16.30] C:\Program Files\Common Files
[03/09/2008|10.21] C:\Program Files\DAEMON Tools Lite
[02/09/2008|14.40] C:\Program Files\DivX
[15/02/2009|19.12] C:\Program Files\EA Games
[14/01/2009|15.43] C:\Program Files\Electronic Arts
[12/12/2008|18.20] C:\Program Files\Enigma Software Group
[01/09/2008|09.59] C:\Program Files\File comuni [C:\Program Files\Common Files]
[31/01/2009|14.30] C:\Program Files\FileZilla FTP Client
[01/09/2008|10.08] C:\Program Files\Fingerprint Sensor
[12/12/2008|14.48] C:\Program Files\FLV Player
[09/10/2008|15.02] C:\Program Files\Game_Maker7
[20/01/2009|16.29] C:\Program Files\GeoGebra
[30/12/2008|17.59] C:\Program Files\Gimp-2.0
[02/09/2008|09.12] C:\Program Files\Google
[23/12/2008|16.10] C:\Program Files\Hedgewars 0.9.7
[20/07/2007|12.32] C:\Program Files\Hewlett-Packard
[23/02/2009|13.03] C:\Program Files\Hp
[20/07/2007|12.22] C:\Program Files\HPQ
[23/02/2009|13.03] C:\Program Files\InstallShield Installation Information
[06/09/2008|13.22] C:\Program Files\Internet Explorer
[13/09/2008|09.57] C:\Program Files\Java
[14/02/2009|17.17] C:\Program Files\JRE
[22/02/2009|22.33] C:\Program Files\Malwarebytes' Anti-Malware
[22/02/2009|13.44] C:\Program Files\McAfee
[04/09/2008|09.27] C:\Program Files\McAfee.com
[10/02/2009|17.23] C:\Program Files\Messenger Plus! Live
[30/12/2008|16.35] C:\Program Files\Microsoft
[02/11/2006|13.37] C:\Program Files\Microsoft Games
[14/01/2009|19.52] C:\Program Files\Microsoft Games for Windows - LIVE
[20/07/2007|12.04] C:\Program Files\Microsoft Office
[08/12/2008|10.05] C:\Program Files\Microsoft SDKs
[22/10/2008|12.56] C:\Program Files\Microsoft Silverlight
[08/12/2008|10.10] C:\Program Files\Microsoft SQL Server
[22/02/2009|16.10] C:\Program Files\Microsoft SQL Server Compact Edition
[22/02/2009|16.14] C:\Program Files\Microsoft Sync Framework
[08/12/2008|10.10] C:\Program Files\Microsoft Synchronization Services
[08/12/2008|10.10] C:\Program Files\Microsoft Visual Studio 9.0
[10/09/2008|21.35] C:\Program Files\Microsoft Works
[08/12/2008|10.06] C:\Program Files\Microsoft.NET
[20/07/2007|11.22] C:\Program Files\Motorola
[06/09/2008|13.23] C:\Program Files\Movie Maker
[05/02/2009|17.47] C:\Program Files\Mozilla Firefox
[02/11/2006|13.37] C:\Program Files\MSBuild
[01/09/2008|10.44] C:\Program Files\MSXML 4.0
[03/09/2008|13.03] C:\Program Files\Nero
[07/11/2008|14.49] C:\Program Files\Notepad++
[02/09/2008|10.21] C:\Program Files\OLYMPUS
[19/10/2008|12.17] C:\Program Files\OpenOffice.org 2.4
[14/02/2009|17.17] C:\Program Files\OpenOffice.org 3
[02/02/2009|19.15] C:\Program Files\Opera
[27/11/2008|17.24] C:\Program Files\PC Wizard 2008
[18/01/2009|10.57] C:\Program Files\PDFCreator
[02/09/2008|10.23] C:\Program Files\QuickTime
[20/07/2007|12.20] C:\Program Files\Realtek
[07/02/2009|23.06] C:\Program Files\Recuva
[02/11/2006|13.37] C:\Program Files\Reference Assemblies
[14/01/2009|15.49] C:\Program Files\Rockstar Games
[20/07/2007|11.51] C:\Program Files\Roxio
[02/09/2008|12.18] C:\Program Files\ScanSoft
[20/07/2007|12.19] C:\Program Files\Servizi in linea
[04/09/2008|09.29] C:\Program Files\SiteAdvisor
[22/02/2009|17.45] C:\Program Files\Spyware Doctor
[28/09/2008|13.30] C:\Program Files\Symantec
[20/07/2007|11.28] C:\Program Files\Synaptics
[18/01/2009|09.36] C:\Program Files\Techland
[22/12/2008|16.46] C:\Program Files\TechSmith
[16/12/2008|18.28] C:\Program Files\Tint
[04/02/2009|16.56] C:\Program Files\TutoreDattilo
[12/02/2009|15.25] C:\Program Files\TuxMath
[28/10/2008|14.58] C:\Program Files\Ubisoft
[02/11/2006|14.01] C:\Program Files\Uninstall Information
[02/09/2008|14.35] C:\Program Files\uTorrent
[21/12/2008|10.41] C:\Program Files\VideoLAN
[08/09/2008|12.18] C:\Program Files\VistaCodecPack
[06/09/2008|13.23] C:\Program Files\Windows Calendar
[06/09/2008|13.22] C:\Program Files\Windows Collaboration
[06/09/2008|13.22] C:\Program Files\Windows Defender
[06/09/2008|13.22] C:\Program Files\Windows Journal
[22/02/2009|16.15] C:\Program Files\Windows Live
[08/10/2008|14.56] C:\Program Files\Windows Live Safety Center
[30/12/2008|16.34] C:\Program Files\Windows Live SkyDrive
[11/02/2009|21.24] C:\Program Files\Windows Mail
[06/09/2008|13.22] C:\Program Files\Windows Media Player
[01/09/2008|09.59] C:\Program Files\Windows NT
[06/09/2008|13.22] C:\Program Files\Windows Photo Gallery
[06/09/2008|13.23] C:\Program Files\Windows Sidebar
[02/09/2008|14.46] C:\Program Files\WinRAR
[07/02/2009|20.20] C:\Program Files\xchat
[11/09/2008|18.25] C:\Program Files\Yahoo!
[20/01/2009|16.29] C:\Program Files\Zero G Registry
[0|File] C:\Program Files\byte
[104|Directory] C:\Program Files\byte disponibili

--------------------\\ Listing Folders in C:\Program Files\Common Files

[07/11/2008|14.40] C:\Program Files\Common Files\Adobe
[05/09/2008|14.02] C:\Program Files\Common Files\HP
[20/07/2007|12.19] C:\Program Files\Common Files\InstallShield
[20/07/2007|12.35] C:\Program Files\Common Files\Java
[20/07/2007|12.22] C:\Program Files\Common Files\LightScribe
[04/09/2008|09.27] C:\Program Files\Common Files\McAfee
[22/02/2009|16.05] C:\Program Files\Common Files\microsoft shared
[02/09/2008|10.28] C:\Program Files\Common Files\muvee Technologies
[02/09/2008|14.40] C:\Program Files\Common Files\PX Storage Engine
[20/07/2007|11.50] C:\Program Files\Common Files\Roxio Shared
[02/09/2008|12.18] C:\Program Files\Common Files\ScanSoft Shared
[02/11/2006|12.18] C:\Program Files\Common Files\Services
[20/07/2007|11.51] C:\Program Files\Common Files\Sonic Shared
[02/11/2006|12.18] C:\Program Files\Common Files\SpeechEngines
[20/07/2007|11.51] C:\Program Files\Common Files\SureThing Shared
[04/09/2008|09.26] C:\Program Files\Common Files\Symantec Shared
[06/09/2008|13.22] C:\Program Files\Common Files\System
[22/12/2008|16.46] C:\Program Files\Common Files\TechSmith Shared
[30/12/2008|16.30] C:\Program Files\Common Files\Windows Live
[02/09/2008|11.58] C:\Program Files\Common Files\WindowsLiveInstaller
[15/02/2009|19.10] C:\Program Files\Common Files\Wise Installation Wizard
[0|File] C:\Program Files\Common Files\byte
[23|Directory] C:\Program Files\Common Files\byte disponibili

--------------------\\ Process

( 81 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-24 11:04:41
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 7

--------------------\\ Searching for other infections

--------------------\\ Cracks & Keygens ..

C:\Users\Utente\AppData\Roaming\uTorrent\Ashampoo.Burning.Studio.8.v8.03.Bilingual.+.Keygen.[CrAsH].rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Brothers.in.Arms.Hells.Highway.CRACK.ONLY-RELOADED.rar.1.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Brothers.in.Arms.Hells.Highway.CRACK.ONLY-RELOADED.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio 5.1 - With Keygen.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio 5.1 - With Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Crysis.Warhead.Crack-TDM.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Far Cry 2 CRACK & Patch.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Far Cry 2 Crack.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA IV Crack NoCD working.exe.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.Only.READNFO-0x0008.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.1.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.2.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.Securom.Bypass.Launcher.UBER-PROPER-FeD0R.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Keygen_Far-Cry.2-Version_2008-Razor1911.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Mirror's Edge no-cd Crack + KeyGen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need for Speed Undercover Keygen Only.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need for Speed Undercover Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need.For.Speed.Undercover.Crack.and.Keygen.Only-RELOADED.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Rainbow Six Vegas 2 - 1.03 Crack - CALIBER.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\RAZOR1911 [WEB SEED] FAR CRY 2 CRACK - REAL 100% FULLY WORKING.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore - CRACKFIX-RELOADED - [Demonoid.com].torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore RELOADED - crack only.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore-keygen.torrent
C:\Users\Utente\Downloads\Camtasia Studio Keygen
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen
C:\Users\Utente\Downloads\Camtasia Studio Keygen\Camtasia Studio 6 Keygen.exe
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen\Mirror's Edge KeyGen.exe
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen\MirrorsEdge.exe


[F:4][D:1]-> C:\Users\Utente\AppData\Local\Temp
[F:4][D:1]-> C:\Users\Utente\AppData\Roaming\MICROS~1\Windows\Cookies
[F:106][D:12]-> C:\Users\Utente\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:32][D:2]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 24/02/2009|11.03 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 24/02/2009|11.06 - Option : [2]

e il log di hijack this

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Home Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz )
BIOS : Ver 1.00PARTTBL
USER : Utente ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:221 Go (Free:26 Go)
D:\ (Local Disk) - NTFS - Total:11 Go (Free:7 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 24/02/2009|11.04 )

[ UAC => 1 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

-
[ Hosts file ] .. Restored!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in Local

[14/11/2008|19.59] C:\Users\Utente\AppData\Local\Activision
[03/09/2008|15.33] C:\Users\Utente\AppData\Local\Adobe
[03/09/2008|12.41] C:\Users\Utente\AppData\Local\Ahead
[04/09/2008|10.07] C:\Users\Utente\AppData\Local\ashampoo
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\AtStart.txt
[21/12/2008|16.15] C:\Users\Utente\AppData\Local\CamSpace
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Cronologia
[01/09/2008|10.13] C:\Users\Utente\AppData\Local\d3d9caps.dat
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Dati applicazioni
[23/02/2009|17.02] C:\Users\Utente\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[09/10/2008|13.11] C:\Users\Utente\AppData\Local\Downloaded Installations
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\DSwitch.txt
[21/12/2008|16.30] C:\Users\Utente\AppData\Local\FnF4.txt
[15/02/2009|10.17] C:\Users\Utente\AppData\Local\GDIPFONTCACHEV1.DAT
[14/02/2009|19.56] C:\Users\Utente\AppData\Local\GMail Drive
[07/02/2009|20.03] C:\Users\Utente\AppData\Local\Google
[05/09/2008|14.04] C:\Users\Utente\AppData\Local\HP
[23/02/2009|22.49] C:\Users\Utente\AppData\Local\IconCache.db
[03/09/2008|09.31] C:\Users\Utente\AppData\Local\IsolatedStorage
[03/09/2008|13.54] C:\Users\Utente\AppData\Local\Lingoes
[14/01/2009|19.52] C:\Users\Utente\AppData\Local\Microsoft
[12/09/2008|14.00] C:\Users\Utente\AppData\Local\Microsoft Games
[08/12/2008|10.19] C:\Users\Utente\AppData\Local\Microsoft Help
[02/09/2008|08.55] C:\Users\Utente\AppData\Local\Mozilla
[05/09/2008|14.11] C:\Users\Utente\AppData\Local\OLYMPUS
[02/02/2009|19.15] C:\Users\Utente\AppData\Local\Opera
[27/11/2008|15.27] C:\Users\Utente\AppData\Local\PunkBuster
[01/09/2008|10.10] C:\Users\Utente\AppData\Local\QSwitch.txt
[23/02/2009|16.55] C:\Users\Utente\AppData\Local\QuickPlay
[15/01/2009|19.20] C:\Users\Utente\AppData\Local\Rockstar Games
[03/09/2008|07.47] C:\Users\Utente\AppData\Local\Scansoft
[22/12/2008|17.06] C:\Users\Utente\AppData\Local\TechSmith
[24/02/2009|11.04] C:\Users\Utente\AppData\Local\Temp
[01/09/2008|10.01] C:\Users\Utente\AppData\Local\Temporary Internet Files
[14/12/2008|11.29] C:\Users\Utente\AppData\Local\Temporary Projects
[04/09/2008|09.30] C:\Users\Utente\AppData\Local\VirtualStore
[8|File] C:\Users\Utente\AppData\Local\byte
[30|Directory] C:\Users\Utente\AppData\Local\byte disponibili

--------------------\\ Scheduled Tasks located in C:\Windows\Tasks

[04/09/2008 09.43][--a------] C:\Windows\tasks\McDefragTask.job
[04/09/2008 09.43][--a------] C:\Windows\tasks\McQcTask.job
[24/02/2009 09.30][--ah-----] C:\Windows\tasks\SA.DAT
[23/02/2009 22.49][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing Folders in C:\ProgramData

[07/11/2008|14.40] C:\ProgramData\Adobe
[02/09/2008|10.22] C:\ProgramData\Apple Computer
[04/09/2008|10.07] C:\ProgramData\ashampoo
[02/09/2008|12.13] C:\ProgramData\CanonBJ
[03/09/2008|09.23] C:\ProgramData\CyberLink
[01/09/2008|09.59] C:\ProgramData\Dati applicazioni
[01/09/2008|09.59] C:\ProgramData\Desktop
[01/09/2008|09.59] C:\ProgramData\Documenti
[05/09/2008|15.28] C:\ProgramData\Downloaded Installations
[09/10/2008|13.12] C:\ProgramData\Electronic Arts
[06/02/2009|15.33] C:\ProgramData\Extensions
[01/09/2008|10.19] C:\ProgramData\Google
[23/02/2009|11.34] C:\ProgramData\Google Updater
[20/07/2007|12.35] C:\ProgramData\Hewlett-Packard
[05/09/2008|14.02] C:\ProgramData\HP
[05/09/2008|14.04] C:\ProgramData\hpzinstall.log
[20/07/2007|11.44] C:\ProgramData\InstallShield
[04/09/2008|09.25] C:\ProgramData\LUUnInstall.LiveUpdate
[31/10/2008|16.06] C:\ProgramData\Malwarebytes
[04/09/2008|09.30] C:\ProgramData\McAfee
[01/09/2008|09.59] C:\ProgramData\Menu Avvio
[03/09/2008|07.47] C:\ProgramData\Messenger Plus!
[22/02/2009|16.14] C:\ProgramData\Microsoft
[08/12/2008|10.09] C:\ProgramData\Microsoft Help
[01/09/2008|09.59] C:\ProgramData\Modelli
[21/12/2008|15.49] C:\ProgramData\NVIDIA
[24/02/2009|09.31] C:\ProgramData\nvModes.001
[15/02/2009|19.08] C:\ProgramData\nvModes.dat
[01/09/2008|09.59] C:\ProgramData\Preferiti
[16/01/2009|20.14] C:\ProgramData\Roxio
[02/09/2008|12.18] C:\ProgramData\ScanSoft
[03/09/2008|17.52] C:\ProgramData\SiteAdvisor
[09/09/2008|12.45] C:\ProgramData\Sonic
[04/09/2008|09.25] C:\ProgramData\Symantec
[24/12/2008|09.29] C:\ProgramData\TechSmith
[22/02/2009|18.15] C:\ProgramData\TEMP
[09/09/2008|13.19] C:\ProgramData\Ubisoft
[08/09/2008|12.17] C:\ProgramData\VistaCodecs
[29/09/2008|16.34] C:\ProgramData\WindowsSearch
[02/09/2008|11.54] C:\ProgramData\WLInstaller
[4|File] C:\ProgramData\byte
[38|Directory] C:\ProgramData\byte disponibili

--------------------\\ Listing Folders in C:\Program Files

[14/11/2008|15.44] C:\Program Files\Activision
[07/11/2008|14.39] C:\Program Files\Adobe
[15/02/2009|19.10] C:\Program Files\AGEIA Technologies
[30/01/2009|16.26] C:\Program Files\AmitySource
[02/09/2008|12.15] C:\Program Files\ArcSoft
[04/09/2008|10.06] C:\Program Files\Ashampoo
[01/09/2008|10.08] C:\Program Files\Bioscrypt
[18/01/2009|10.53] C:\Program Files\Bit Che
[30/11/2008|15.18] C:\Program Files\CamSpace
[02/09/2008|12.21] C:\Program Files\Canon
[02/09/2008|12.09] C:\Program Files\CanonBJ
[23/02/2009|22.31] C:\Program Files\CCleaner
[30/12/2008|16.30] C:\Program Files\Common Files
[03/09/2008|10.21] C:\Program Files\DAEMON Tools Lite
[02/09/2008|14.40] C:\Program Files\DivX
[15/02/2009|19.12] C:\Program Files\EA Games
[14/01/2009|15.43] C:\Program Files\Electronic Arts
[12/12/2008|18.20] C:\Program Files\Enigma Software Group
[01/09/2008|09.59] C:\Program Files\File comuni [C:\Program Files\Common Files]
[31/01/2009|14.30] C:\Program Files\FileZilla FTP Client
[01/09/2008|10.08] C:\Program Files\Fingerprint Sensor
[12/12/2008|14.48] C:\Program Files\FLV Player
[09/10/2008|15.02] C:\Program Files\Game_Maker7
[20/01/2009|16.29] C:\Program Files\GeoGebra
[30/12/2008|17.59] C:\Program Files\Gimp-2.0
[02/09/2008|09.12] C:\Program Files\Google
[23/12/2008|16.10] C:\Program Files\Hedgewars 0.9.7
[20/07/2007|12.32] C:\Program Files\Hewlett-Packard
[23/02/2009|13.03] C:\Program Files\Hp
[20/07/2007|12.22] C:\Program Files\HPQ
[23/02/2009|13.03] C:\Program Files\InstallShield Installation Information
[06/09/2008|13.22] C:\Program Files\Internet Explorer
[13/09/2008|09.57] C:\Program Files\Java
[14/02/2009|17.17] C:\Program Files\JRE
[22/02/2009|22.33] C:\Program Files\Malwarebytes' Anti-Malware
[22/02/2009|13.44] C:\Program Files\McAfee
[04/09/2008|09.27] C:\Program Files\McAfee.com
[10/02/2009|17.23] C:\Program Files\Messenger Plus! Live
[30/12/2008|16.35] C:\Program Files\Microsoft
[02/11/2006|13.37] C:\Program Files\Microsoft Games
[14/01/2009|19.52] C:\Program Files\Microsoft Games for Windows - LIVE
[20/07/2007|12.04] C:\Program Files\Microsoft Office
[08/12/2008|10.05] C:\Program Files\Microsoft SDKs
[22/10/2008|12.56] C:\Program Files\Microsoft Silverlight
[08/12/2008|10.10] C:\Program Files\Microsoft SQL Server
[22/02/2009|16.10] C:\Program Files\Microsoft SQL Server Compact Edition
[22/02/2009|16.14] C:\Program Files\Microsoft Sync Framework
[08/12/2008|10.10] C:\Program Files\Microsoft Synchronization Services
[08/12/2008|10.10] C:\Program Files\Microsoft Visual Studio 9.0
[10/09/2008|21.35] C:\Program Files\Microsoft Works
[08/12/2008|10.06] C:\Program Files\Microsoft.NET
[20/07/2007|11.22] C:\Program Files\Motorola
[06/09/2008|13.23] C:\Program Files\Movie Maker
[05/02/2009|17.47] C:\Program Files\Mozilla Firefox
[02/11/2006|13.37] C:\Program Files\MSBuild
[01/09/2008|10.44] C:\Program Files\MSXML 4.0
[03/09/2008|13.03] C:\Program Files\Nero
[07/11/2008|14.49] C:\Program Files\Notepad++
[02/09/2008|10.21] C:\Program Files\OLYMPUS
[19/10/2008|12.17] C:\Program Files\OpenOffice.org 2.4
[14/02/2009|17.17] C:\Program Files\OpenOffice.org 3
[02/02/2009|19.15] C:\Program Files\Opera
[27/11/2008|17.24] C:\Program Files\PC Wizard 2008
[18/01/2009|10.57] C:\Program Files\PDFCreator
[02/09/2008|10.23] C:\Program Files\QuickTime
[20/07/2007|12.20] C:\Program Files\Realtek
[07/02/2009|23.06] C:\Program Files\Recuva
[02/11/2006|13.37] C:\Program Files\Reference Assemblies
[14/01/2009|15.49] C:\Program Files\Rockstar Games
[20/07/2007|11.51] C:\Program Files\Roxio
[02/09/2008|12.18] C:\Program Files\ScanSoft
[20/07/2007|12.19] C:\Program Files\Servizi in linea
[04/09/2008|09.29] C:\Program Files\SiteAdvisor
[22/02/2009|17.45] C:\Program Files\Spyware Doctor
[28/09/2008|13.30] C:\Program Files\Symantec
[20/07/2007|11.28] C:\Program Files\Synaptics
[18/01/2009|09.36] C:\Program Files\Techland
[22/12/2008|16.46] C:\Program Files\TechSmith
[16/12/2008|18.28] C:\Program Files\Tint
[04/02/2009|16.56] C:\Program Files\TutoreDattilo
[12/02/2009|15.25] C:\Program Files\TuxMath
[28/10/2008|14.58] C:\Program Files\Ubisoft
[02/11/2006|14.01] C:\Program Files\Uninstall Information
[02/09/2008|14.35] C:\Program Files\uTorrent
[21/12/2008|10.41] C:\Program Files\VideoLAN
[08/09/2008|12.18] C:\Program Files\VistaCodecPack
[06/09/2008|13.23] C:\Program Files\Windows Calendar
[06/09/2008|13.22] C:\Program Files\Windows Collaboration
[06/09/2008|13.22] C:\Program Files\Windows Defender
[06/09/2008|13.22] C:\Program Files\Windows Journal
[22/02/2009|16.15] C:\Program Files\Windows Live
[08/10/2008|14.56] C:\Program Files\Windows Live Safety Center
[30/12/2008|16.34] C:\Program Files\Windows Live SkyDrive
[11/02/2009|21.24] C:\Program Files\Windows Mail
[06/09/2008|13.22] C:\Program Files\Windows Media Player
[01/09/2008|09.59] C:\Program Files\Windows NT
[06/09/2008|13.22] C:\Program Files\Windows Photo Gallery
[06/09/2008|13.23] C:\Program Files\Windows Sidebar
[02/09/2008|14.46] C:\Program Files\WinRAR
[07/02/2009|20.20] C:\Program Files\xchat
[11/09/2008|18.25] C:\Program Files\Yahoo!
[20/01/2009|16.29] C:\Program Files\Zero G Registry
[0|File] C:\Program Files\byte
[104|Directory] C:\Program Files\byte disponibili

--------------------\\ Listing Folders in C:\Program Files\Common Files

[07/11/2008|14.40] C:\Program Files\Common Files\Adobe
[05/09/2008|14.02] C:\Program Files\Common Files\HP
[20/07/2007|12.19] C:\Program Files\Common Files\InstallShield
[20/07/2007|12.35] C:\Program Files\Common Files\Java
[20/07/2007|12.22] C:\Program Files\Common Files\LightScribe
[04/09/2008|09.27] C:\Program Files\Common Files\McAfee
[22/02/2009|16.05] C:\Program Files\Common Files\microsoft shared
[02/09/2008|10.28] C:\Program Files\Common Files\muvee Technologies
[02/09/2008|14.40] C:\Program Files\Common Files\PX Storage Engine
[20/07/2007|11.50] C:\Program Files\Common Files\Roxio Shared
[02/09/2008|12.18] C:\Program Files\Common Files\ScanSoft Shared
[02/11/2006|12.18] C:\Program Files\Common Files\Services
[20/07/2007|11.51] C:\Program Files\Common Files\Sonic Shared
[02/11/2006|12.18] C:\Program Files\Common Files\SpeechEngines
[20/07/2007|11.51] C:\Program Files\Common Files\SureThing Shared
[04/09/2008|09.26] C:\Program Files\Common Files\Symantec Shared
[06/09/2008|13.22] C:\Program Files\Common Files\System
[22/12/2008|16.46] C:\Program Files\Common Files\TechSmith Shared
[30/12/2008|16.30] C:\Program Files\Common Files\Windows Live
[02/09/2008|11.58] C:\Program Files\Common Files\WindowsLiveInstaller
[15/02/2009|19.10] C:\Program Files\Common Files\Wise Installation Wizard
[0|File] C:\Program Files\Common Files\byte
[23|Directory] C:\Program Files\Common Files\byte disponibili

--------------------\\ Process

( 81 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-24 11:04:41
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 7

--------------------\\ Searching for other infections

--------------------\\ Cracks & Keygens ..

C:\Users\Utente\AppData\Roaming\uTorrent\Ashampoo.Burning.Studio.8.v8.03.Bilingual.+.Keygen.[CrAsH].rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Brothers.in.Arms.Hells.Highway.CRACK.ONLY-RELOADED.rar.1.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Brothers.in.Arms.Hells.Highway.CRACK.ONLY-RELOADED.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio 5.1 - With Keygen.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio 5.1 - With Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Crysis.Warhead.Crack-TDM.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Far Cry 2 CRACK & Patch.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Far Cry 2 Crack.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA IV Crack NoCD working.exe.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.Only.READNFO-0x0008.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.1.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.2.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.Securom.Bypass.Launcher.UBER-PROPER-FeD0R.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Keygen_Far-Cry.2-Version_2008-Razor1911.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Mirror's Edge no-cd Crack + KeyGen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need for Speed Undercover Keygen Only.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need for Speed Undercover Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need.For.Speed.Undercover.Crack.and.Keygen.Only-RELOADED.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Rainbow Six Vegas 2 - 1.03 Crack - CALIBER.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\RAZOR1911 [WEB SEED] FAR CRY 2 CRACK - REAL 100% FULLY WORKING.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore - CRACKFIX-RELOADED - [Demonoid.com].torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore RELOADED - crack only.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore-keygen.torrent
C:\Users\Utente\Downloads\Camtasia Studio Keygen
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen
C:\Users\Utente\Downloads\Camtasia Studio Keygen\Camtasia Studio 6 Keygen.exe
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen\Mirror's Edge KeyGen.exe
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen\MirrorsEdge.exe


[F:4][D:1]-> C:\Users\Utente\AppData\Local\Temp
[F:4][D:1]-> C:\Users\Utente\AppData\Roaming\MICROS~1\Windows\Cookies
[F:106][D:12]-> C:\Users\Utente\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:32][D:2]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 24/02/2009|11.03 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 24/02/2009|11.06 - Option : [2]

ecco...scusate per la lentezza.
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)

Re: controllo log

Messaggioda stevens » mar feb 24, 2009 1:18 pm

scarica http://www.ilsoftware.it/dl.asp?id=1005

fai una scansione completa del sistema ed elimina cio' che trova appena finito posta il report che rilascia
Avatar utente
stevens
Bronze Member
Bronze Member
 
Messaggi: 678
Iscritto il: mer feb 18, 2009 1:39 pm

Re: controllo log

Messaggioda [Claudio] » mar feb 24, 2009 2:04 pm

ivan92 ha scritto: --------------------\\ Searching for other infections
--------------------\\ Cracks & Keygens ..

C:\Users\Utente\AppData\Roaming\uTorrent\Ashampoo.Burning.Studio.8.v8.03.Bilingual.+.Keygen.[CrAsH].rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Brothers.in.Arms.Hells.Highway.CRACK.ONLY-RELOADED.rar.1.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Brothers.in.Arms.Hells.Highway.CRACK.ONLY-RELOADED.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio 5.1 - With Keygen.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio 5.1 - With Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Camtasia Studio Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Crysis.Warhead.Crack-TDM.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Far Cry 2 CRACK & Patch.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Far Cry 2 Crack.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA IV Crack NoCD working.exe.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.Only.READNFO-0x0008.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.1.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.2.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\GTA.IV.Crack.Securom.Bypass.Launcher.UBER-PROPER-FeD0R.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Keygen_Far-Cry.2-Version_2008-Razor1911.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Mirror's Edge no-cd Crack + KeyGen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need for Speed Undercover Keygen Only.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need for Speed Undercover Keygen.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Need.For.Speed.Undercover.Crack.and.Keygen.Only-RELOADED.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Rainbow Six Vegas 2 - 1.03 Crack - CALIBER.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\RAZOR1911 [WEB SEED] FAR CRY 2 CRACK - REAL 100% FULLY WORKING.rar.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore - CRACKFIX-RELOADED - [Demonoid.com].torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore RELOADED - crack only.torrent
C:\Users\Utente\AppData\Roaming\uTorrent\Spore-keygen.torrent
C:\Users\Utente\Downloads\Camtasia Studio Keygen
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen
C:\Users\Utente\Downloads\Camtasia Studio Keygen\Camtasia Studio 6 Keygen.exe
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen\Mirror's Edge KeyGen.exe
C:\Users\Utente\Downloads\Mirror's Edge no-cd Crack + KeyGen\MirrorsEdge.exe

Crack e keygen ....... pessime abitudini Ivan.
E con le pessime abitudini il meno che ti può capitare è quello di infettare continuamente il computer.
Allega un log di Hijackthis per piacere.
Avatar utente
[Claudio]
Senior Member
Senior Member
 
Messaggi: 307
Iscritto il: ven feb 06, 2009 11:16 pm

Re: controllo log

Messaggioda stevens » mar feb 24, 2009 2:28 pm

Crack e keygen ....... pessime abitudini Ivan.
E con le pessime abitudini il meno che ti può capitare è quello di infettare continuamente il computer.
Allega un log di Hijackthis per piacere.


claudio cerchiamo di seguire una scaletta altrimenti l'utente si confonde - ha dei rootkit nel pc
Avatar utente
stevens
Bronze Member
Bronze Member
 
Messaggi: 678
Iscritto il: mer feb 18, 2009 1:39 pm

Re: controllo log

Messaggioda stevens » mar feb 24, 2009 3:27 pm

ivan 92 dopo che avrai fatto la scansione del pc con il programma che ti ho indicato

http://www.ilsoftware.it/dl.asp?id=1005

vai sul sito di kaspersky ===> http://www.kaspersky.com/virusscanner

clicca su "kaspersky online scanner"
clicca su "accept"
--- verrà eseguito il download dei componenti necessari alla scansione
quando è terminato clicca su "my computer" (finestra a sinistra)
avvia la scansione
--- da questo punto in poi, puoi anche disconnettere il pc da internet
quando finisce la scansione, salva e posta il rapporto.
Avatar utente
stevens
Bronze Member
Bronze Member
 
Messaggi: 678
Iscritto il: mer feb 18, 2009 1:39 pm

Re: controllo log

Messaggioda ivan92 » mar feb 24, 2009 4:45 pm

questo è quello che ha trovato avg

Path: C:\Windows\System32\Drivers\asbo1zmf.SYS Description: Hidden driver file
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)

Re: controllo log

Messaggioda stevens » mar feb 24, 2009 5:16 pm

usa anche questo ====> http://download.html.it/software/getit/3742/gmer/

Dopo averlo scompattato, lo avvii, selezioni "Rootkit"
Clicca su "Scan"
Attendi la fine della scansione e clicca su "Copy"
Apri il block notes di windows, clicca su modifica e seleziona incolla, salvi il file di testo.

Poi fai una scansione con GMer dalla posizione Autostart, con le stesse procedure del precedente. Incolli il log generato nel suddetto file di block notes e posta il report nel forum


Quando hai finito, fai la scansione online con kaspersky che ti ho indicato nel post precedente
Avatar utente
stevens
Bronze Member
Bronze Member
 
Messaggi: 678
Iscritto il: mer feb 18, 2009 1:39 pm

Re: controllo log

Messaggioda ivan92 » mar feb 24, 2009 5:55 pm

a proposito di scansione online è da circa 2 ore che sta aggiornando il database e sono solo a metà...e la connessione si è rallentata tantissimo...è normale
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)

Re: controllo log

Messaggioda ivan92 » mar feb 24, 2009 8:30 pm

ecco la scansione con kaspersky

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, February 24, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, February 24, 2009 16:30:35
Records in database: 1839529
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - Folder:


Scan statistics:
Files scanned: 177162
Threat name: 2
Infected objects: 1
Suspicious objects: 1
Duration of the scan: 02:19:05


File name / Threat name / Threats count
C:\Users\Utente\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\McAfee Anti efc\314A1A28-00000037.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Users\Utente\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1d1a8ca8-4b058f1c Infected: Trojan-Downloader.Java.OpenConnection.aq 1

The selected area was scanned.
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)

Re: controllo log

Messaggioda [Claudio] » mer feb 25, 2009 10:53 am

Ivan, prosegui in questo modo per favore:

svuota la cache di Java visto che è infetta:
Start
Pannello di controllo
clicca sull'icona Java e verrà aperto il Pannello di controllo di Java
seleziona la scheda Cache e clicca su Cancella
verrà visualizzata una finestra di dialogo di conferma: clicca su SI per confermare, poi su APPLICA

Poi, prosegui in questo modo:

Disattiva il Ripristino configurazione di sistema, procedendo in questa maniera:
Start
tasto destro del mouse sull'icona Risorse del Computer
seleziona la voce Proprietà
apri la scheda Ripristino configurazione di sistema
spunta la voce Disattiva Ripristino configurazione di sistema
conferma, la modifica, con Applica e, poi OK

svuota del suo contenuto la cartella Prefetch procedendo in questa maniera:
Start
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno

Poi scarica ed installa Kaspersky Virus Removal tool: clicca qui per il download (gli scanner online sono inutili se rilevano infezioni ma non danno modo di rimuoverle):
al termine della installazione verrà mostrata la schermata principale del tool
disattiva, temporaneamente, il tuo antivirus
seleziona la partizione da scansionare e clicca su Scan per avviare la scansione
terminata la scansione, in caso di rilevazione di infezioni, clicca su Neutralize all
si apriranno dei popup dove potrai scegliere se cancellare o disinfettare l'oggetto: metti la spunta su Apply to all e clicca su Quarantine
per salvare il Report che verrà rilasciato, clicca sul tasto Reports - salvalo ed allegalo
Terminate tutte le operazioni, chiudi il programma che si autodisinstallerà.

Allega anche un log di Hijackthis, per piacere.
Avatar utente
[Claudio]
Senior Member
Senior Member
 
Messaggi: 307
Iscritto il: ven feb 06, 2009 11:16 pm

Re: controllo log

Messaggioda ivan92 » mer feb 25, 2009 11:39 am

ecco il log di gmer...devo diverderlo in 2 pezzi altrimnenti non mi sta.

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2009-02-25 11:32:48
Windows 6.0.6001 Service Pack 1


---- System - GMER 1.0.13 ----

Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateProcess
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateProcessEx
Code \SystemRoot\system32\drivers\mfehidk.sys ZwMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys ZwNotifyChangeKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys ZwOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys ZwProtectVirtualMemory
Code \SystemRoot\system32\drivers\mfehidk.sys ZwReplaceKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwRestoreKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwSetContextThread
Code \SystemRoot\system32\drivers\mfehidk.sys ZwSetInformationProcess
Code \SystemRoot\system32\drivers\mfehidk.sys ZwTerminateProcess
Code \SystemRoot\system32\drivers\mfehidk.sys ZwUnmapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys ZwYieldExecution
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateUserProcess
Code \SystemRoot\system32\drivers\mfehidk.sys NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys NtSetInformationProcess

---- Kernel code sections - GMER 1.0.13 ----

.text ntkrnlpa.exe!ZwYieldExecution 81E2D18C 5 Bytes JMP 8CD3A48C \SystemRoot\system32\drivers\mfehidk.sys
.text ntkrnlpa.exe!ZwQueryLicenseValue + D11 81E5DB59 1 Byte [ 06 ]
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 81FC717C 5 Bytes JMP 8CD3A4E3 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwCreateUserProcess 81FCEDCA 5 Bytes JMP 8CD3A426 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwTerminateProcess 81FE8F80 5 Bytes JMP 8CD3A4CF \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!NtOpenThread 820081DC 5 Bytes JMP 8CD3A3E8 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!NtOpenProcess 82017B18 5 Bytes JMP 8CD3A3D4 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!NtMapViewOfSection 8202A74E 7 Bytes JMP 8CD3A4A0 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 8202ADA5 5 Bytes JMP 8CD3A4B6 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!NtCreateFile 8202CFB6 5 Bytes JMP 8CD3A462 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!NtSetInformationProcess 8203A674 5 Bytes JMP 8CD3A43A \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 8203C8CE 7 Bytes JMP 8CD3A476 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwRestoreKey 8205B452 5 Bytes JMP 8CD3A4F7 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwReplaceKey 8205C49E 5 Bytes JMP 8CD3A50B \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwCreateProcess 8209A1C1 5 Bytes JMP 8CD3A3FC \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwCreateProcessEx 8209A20C 7 Bytes JMP 8CD3A410 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntkrnlpa.exe!ZwSetContextThread 8209ACCB 5 Bytes JMP 8CD3A44E \SystemRoot\system32\drivers\mfehidk.sys
? System32\Drivers\spjp.sys Impossibile trovare il file specificato.
.text USBPORT.SYS!DllUnload 87FC546F 5 Bytes JMP 862721D8
.text arokya7l.SYS 8C987000 22 Bytes [ 26, 62, 1C, 82, 10, 61, 1C, ... ]
.text arokya7l.SYS 8C987017 159 Bytes [ 00, 32, 87, 99, 82, 3D, 85, ... ]
.text arokya7l.SYS 8C9870B7 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text arokya7l.SYS 8C9870CE 80 Bytes [ 00, 00, 26, 00, 00, 00, E0, ... ]
.text arokya7l.SYS 8C98711F 194 Bytes [ 7E, 38, 40, 39, 82, 3B, C4, ... ]
.text ...

---- User code sections - GMER 1.0.13 ----

.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[592] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[592] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
.text C:\Windows\system32\services.exe[700] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 0038008C
.text C:\Windows\system32\services.exe[700] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 00380F46
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 00380EF5
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 00380F06
.text C:\Windows\system32\services.exe[700] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 0038006A
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 00380FDE
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 00380F90
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 00380FB2
.text C:\Windows\system32\services.exe[700] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 00380F75
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 00380FA1
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 00380FCD
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 0038007B
.text C:\Windows\system32\services.exe[700] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 00380EE4
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 00380014
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 00380FEF
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 00380025
.text C:\Windows\system32\services.exe[700] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 00380F21
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 00370051
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 00370036
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 00370000
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 00370FAF
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 00370F94
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 0037001B
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 00370FE5
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 00370FCA
.text C:\Windows\system32\services.exe[700] WS2_32.dll!socket 773736D1 5 Bytes JMP 0039000A
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 001000E4
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 001000C9
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 001000F5
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 00100F5E
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 00100F94
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 00100FB9
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 00100062
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 00100036
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 00100093
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 00100047
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 00100025
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 001000AE
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 00100F39
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 00100FE5
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 00100000
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 00100FD4
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 00100F83
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 000F0080
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 000F005B
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 000F0FEF
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 000F0FD4
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 000F0091
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 000F0025
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 000F0014
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 000F004A
.text C:\Windows\system32\lsass.exe[712] WS2_32.dll!socket 773736D1 5 Bytes JMP 00840000
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 0059009F
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 0059008E
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 00590F12
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 00590F23
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 00590F7E
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 00590025
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 00590058
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 00590FAF
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 00590F63
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 00590047
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 00590036
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 00590073
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 005900CE
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 00590FD4
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 00590FEF
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 0059000A
.text C:\Windows\system32\svchost.exe[812] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 00590F3E
.text C:\Windows\system32\svchost.exe[812] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 00100025
.text C:\Windows\system32\svchost.exe[812] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 00100F9E
.text C:\Windows\system32\svchost.exe[812] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 00100FEF
.text C:\Windows\system32\svchost.exe[812] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 00100F8D
.text C:\Windows\system32\svchost.exe[812] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 00100F5E
.text C:\Windows\system32\svchost.exe[812] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 0010000A
.text C:\Windows\system32\svchost.exe[812] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 00100FD4
.text C:\Windows\system32\svchost.exe[812] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 00100FB9
.text C:\Windows\system32\svchost.exe[812] WS2_32.dll!socket 773736D1 5 Bytes JMP 005A000A
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 006E0089
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 006E0F39
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 006E00AE
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 006E0F17
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 006E0F80
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 006E0FD1
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 006E004E
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 006E0FAC
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 006E0F65
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 006E0F91
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 006E003D
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 006E0F4A
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 006E0EFC
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 006E001B
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 006E0000
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 006E002C
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 006E0F28
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 006D005B
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 006D002C
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 006D0000
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 006D0FAF
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 006D006C
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 006D0FDB
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 006D0011
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 006D0FCA
.text C:\Windows\system32\svchost.exe[864] WS2_32.dll!socket
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)

Re: controllo log

Messaggioda ivan92 » mer feb 25, 2009 11:42 am

l'altro pezzo

.text C:\Windows\System32\svchost.exe[912] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 02920F34
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 02920084
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 029200BA
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 0292009F
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 02920F88
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 0292002C
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 02920FA5
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 02920FC0
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 02920F6D
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 02920062
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 0292003D
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 02920073
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 02920F08
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 02920FEF
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 0292000A
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 0292001B
.text C:\Windows\System32\svchost.exe[912] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 02920F23
.text C:\Windows\System32\svchost.exe[912] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 02910FAF
.text C:\Windows\System32\svchost.exe[912] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 02910036
.text C:\Windows\System32\svchost.exe[912] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 02910000
.text C:\Windows\System32\svchost.exe[912] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 02910047
.text C:\Windows\System32\svchost.exe[912] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 02910F9E
.text C:\Windows\System32\svchost.exe[912] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 02910FE5
.text C:\Windows\System32\svchost.exe[912] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 02910011
.text C:\Windows\System32\svchost.exe[912] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 02910FD4
.text C:\Windows\System32\svchost.exe[912] WS2_32.dll!socket 773736D1 5 Bytes JMP 0293000A
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 00A20F48
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 00A20F59
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 00A20F12
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 00A20F37
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 00A20073
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 00A20FC0
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 00A20062
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 00A20047
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 00A20084
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 00A20FA5
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 00A20036
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 00A20F74
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 00A20F01
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 00A20011
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 00A20000
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 00A20FD1
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 00A200A9
.text C:\Windows\system32\svchost.exe[968] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 00A10F8D
.text C:\Windows\system32\svchost.exe[968] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 00A10FA8
.text C:\Windows\system32\svchost.exe[968] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 00A10FE5
.text C:\Windows\system32\svchost.exe[968] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 00A1002F
.text C:\Windows\system32\svchost.exe[968] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 00A10F7C
.text C:\Windows\system32\svchost.exe[968] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 00A10FC3
.text C:\Windows\system32\svchost.exe[968] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 00A10FD4
.text C:\Windows\system32\svchost.exe[968] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 00A10014
.text C:\Windows\system32\svchost.exe[968] WS2_32.dll!socket 773736D1 5 Bytes JMP 00A70000
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 00750F48
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 0075008E
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 00750F2D
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 007500BA
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 00750062
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 00750036
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 00750F88
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 00750047
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 00750073
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 00750FA5
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 00750FC0
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 00750F63
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 00750F1C
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 00750011
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 00750000
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 00750FDB
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 0075009F
.text C:\Windows\System32\svchost.exe[1076] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 00740F8D
.text C:\Windows\System32\svchost.exe[1076] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 00740FAF
.text C:\Windows\System32\svchost.exe[1076] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 00740FEF
.text C:\Windows\System32\svchost.exe[1076] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 00740F9E
.text C:\Windows\System32\svchost.exe[1076] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 00740F7C
.text C:\Windows\System32\svchost.exe[1076] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 0074000A
.text C:\Windows\System32\svchost.exe[1076] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 00740FD4
.text C:\Windows\System32\svchost.exe[1076] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 00740025
.text C:\Windows\System32\svchost.exe[1076] WS2_32.dll!socket 773736D1 5 Bytes JMP 00760FEF
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 010A0F1E
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 010A0F39
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 010A0EE1
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 010A0EF2
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 010A0042
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 010A001B
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 010A0F68
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 010A0F94
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 010A005D
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 010A0F83
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 010A0FAF
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 010A006E
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 010A0EC6
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 010A0FD4
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 010A0FE5
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 010A000A
.text C:\Windows\System32\svchost.exe[1104] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 010A0F0D
.text C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 01050051
.text C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 0105002F
.text C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 01050FEF
.text C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 01050040
.text C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 01050062
.text C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 01050FC3
.text C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 01050FD4
.text C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 01050014
.text C:\Windows\System32\svchost.exe[1104] WS2_32.dll!socket 773736D1 5 Bytes JMP 010B0FEF
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 01010F26
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 01010F41
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 010100A2
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 0101007D
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 01010047
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 01010011
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 01010036
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 01010F94
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 01010F5C
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 01010F83
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 01010FA5
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 0101006C
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 010100BD
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 01010FE5
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 01010000
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 01010FCA
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 01010F0B
.text C:\Windows\system32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 0100004A
.text C:\Windows\system32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 0100002F
.text C:\Windows\system32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 01000FEF
.text C:\Windows\system32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 01000FA8
.text C:\Windows\system32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 0100005B
.text C:\Windows\system32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 01000014
.text C:\Windows\system32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 01000FDE
.text C:\Windows\system32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExW 7689F09D 5 Bytes JMP 01000FC3
.text C:\Windows\system32\svchost.exe[1116] WS2_32.dll!socket 773736D1 5 Bytes JMP 010E0FE5
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!GetStartupInfoW 76C01929 5 Bytes JMP 000B007D
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!GetStartupInfoA 76C019C9 5 Bytes JMP 000B0F37
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!CreateProcessW 76C01C01 5 Bytes JMP 000B0F1C
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!CreateProcessA 76C01C36 5 Bytes JMP 000B00A9
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!VirtualProtect 76C01DD1 5 Bytes JMP 000B004E
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!CreateNamedPipeW 76C05C44 5 Bytes JMP 000B0FC0
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!LoadLibraryExW 76C230C3 5 Bytes JMP 000B003D
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!LoadLibraryW 76C2361F 5 Bytes JMP 000B002C
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!VirtualProtectEx 76C28D7E 5 Bytes JMP 000B0F59
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!LoadLibraryExA 76C29469 5 Bytes JMP 000B0F8A
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!LoadLibraryA 76C29491 5 Bytes JMP 000B0FA5
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!CreatePipe 76C30284 5 Bytes JMP 000B0F48
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!GetProcAddress 76C4B8B6 5 Bytes JMP 000B0F0B
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!CreateFileW 76C4CC4E 5 Bytes JMP 000B0FE5
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!CreateFileA 76C4CF71 5 Bytes JMP 000B0000
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!CreateNamedPipeA 76C941F6 5 Bytes JMP 000B001B
.text C:\Windows\system32\svchost.exe[1252] kernel32.dll!WinExec 76C953E7 5 Bytes JMP 000B008E
.text C:\Windows\system32\svchost.exe[1252] ADVAPI32.dll!RegCreateKeyExA 7687B5E7 5 Bytes JMP 000A0F80
.text C:\Windows\system32\svchost.exe[1252] ADVAPI32.dll!RegCreateKeyA 7687B8AE 5 Bytes JMP 000A0FAF
.text C:\Windows\system32\svchost.exe[1252] ADVAPI32.dll!RegOpenKeyA 76880BF5 5 Bytes JMP 000A0000
.text C:\Windows\system32\svchost.exe[1252] ADVAPI32.dll!RegCreateKeyW 7688B83D 5 Bytes JMP 000A002C
.text C:\Windows\system32\svchost.exe[1252] ADVAPI32.dll!RegCreateKeyExW 7688BCE1 5 Bytes JMP 000A0F6F
.text C:\Windows\system32\svchost.exe[1252] ADVAPI32.dll!RegOpenKeyExA 7688D4E8 5 Bytes JMP 000A0FDB
.text C:\Windows\system32\svchost.exe[1252] ADVAPI32.dll!RegOpenKeyW 76893CB0 5 Bytes JMP 000A0011
.text C:\Windows\system32\svchost.exe[1252] ADVAPI32.dll!RegOpenKeyExW
Avatar utente
ivan92
Senior Member
Senior Member
 
Messaggi: 285
Iscritto il: mer gen 09, 2008 4:48 pm
Località: orsago( tv)

Prossimo

Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 11 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising