############################## | FindyKill V5.006 |
# User : Elena (Administrators) # AA-5DO4D3E5JBSY
# Update on 14/08/09 by Chiquitine29
# Start at: 15.24.16 | 08/11/2009
# Website :
http://pagesperso-orange.fr/NosTools/index.html# Processore Intel Pentium III Xeon
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 298,08 Go (137,85 Go free) # NTFS
# D:\ # Disco rigido locale # 298,08 Go (278,21 Go free) [The Sims] # NTFS
# E:\ # Disco CD-ROM
# F:\ # Disco CD-ROM # 420,84 Mo (0 Mo free) [BartPE] # CDFS
# G:\ # Disco CD-ROM # 0,38 Mo (0 Mo free) [Bluebirds] # CDFS
# H:\ # Disco CD-ROM # 420,84 Mo (0 Mo free) [BartPE] # CDFS
############################## | Active Processes |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
################## | C: |
(!) Not Deleted ! G:\autorun.inf
################## | C:\WINDOWS |
Deleted ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-17681AA8.pf
################## | C:\WINDOWS\system32 |
################## | C:\WINDOWS\system32\drivers |
################## | C:\Documents and Settings\Elena\Dati applicazioni |
Deleted ! C:\Documents and Settings\Elena\Dati applicazioni\drivers\downld
Deleted ! C:\Documents and Settings\Elena\Dati applicazioni\drivers
################## | Other ... |
# Reference of comparaison Bagle MD5 :
File : C:\Qoobox\Quarantine\C\Documents and Settings\Elena\Dati applicazioni\drivers\winupgro.exe.vir
-> Crc32 : 4354b82a | Md5 : 7055eee2f4cf762b1de64d21130f41eb
################## | Temporary Internet Files |
################## | Registry / Infected keys |
Deleted ! [HKCU\Software\bisoft]
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
################## | State / Service / Information |
# Safe boot mode : OK
# Showing of hidden files : OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )
################## | PEH ... |
Corrupted : C:\MegaLabcd\MegaLabcd\plugin\Antispyware\HijackThis\files\HijackThis.exe
[Offset = 000000C4 - Value = 0x0001]
Corrupted : C:\MegaLabcd\MegaLabcd\plugin\Antispyware\spybotsd\files\blindman.exe
[Offset = 00000104 - Value = 0x0001]
Corrupted : C:\MegaLabcd\MegaLabcd\plugin\Antispyware\spybotsd\files\SpybotSD.exe
[Offset = 00000104 - Value = 0x0001]
Corrupted : C:\MegaLabcd\MegaLabcd\plugin\Antispyware\spybotsd\files\TeaTimer.exe
[Offset = 00000104 - Value = 0x0001]
Corrupted : C:\MegaLabcd\MegaLabcd\plugin\Antispyware\spybotsd\files\Update.exe
[Offset = 00000104 - Value = 0x0001]
Corrupted : C:\MegaLabcd\MegaLabcd\plugin\Antispyware\SUPERAntispyware\files\SUPERAntiSpyware.exe
[Offset = 0000012C - Value = 0x0001]
Corrupted : C:\MegaLabcd\plugin\driver\atapi_824146\files\common\update.exe
[Offset = 000000EC - Value = 0x0001]
Corrupted : C:\Programmi\MSN\MSNCoreFiles\update.exe
[Offset = 000000DC - Value = 0x0001]
Corrupted : C:\WINDOWS\$NtServicePackUninstall$\sysinfo.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : sysinfo.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\ie8updates\KB971961-IE8\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\ie8updates\KB973874-IE8\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
################## | Cracks / Keygens / Serials |
################## | End of Report # FindyKill V5.006 ! |