############################## | FindyKill V5.043 |
# User : utente (Administrators) # UTENTE-F5ED1DD0
# Update on 12/05/2010 by El Desaparecido
# Start at: 20.27.24 | 15/05/2010
# Website :
http://pagesperso-orange.fr/NosTools/index.html# Contact :
FindyKill.Contact@gmail.com# Intel(R) Pentium(R) 4 CPU 2.40GHz
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
# AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 38,28 Go (18,77 Go free) # NTFS
# D:\ # Disco CD-ROM # 293,1 Mo (0 Mo free) [CM0102_REL] # CDFS
# F:\ # Disco rigido locale # 232,88 Go (6,1 Go free) [Volume] # NTFS
############################## | Infected processes stopped |
"C:\Documents and Settings\utente\Dati applicazioni\drivers\winupgro.exe" (1616)
"C:\WINDOWS\wintems.exe" (1668)
"C:\Documents and Settings\utente\Dati applicazioni\m\flec006.exe" (3164)
"C:\Documents and Settings\utente\Dati applicazioni\hidires\flec003.exe" -run (3392)
################## | Infected File |
C:\infosat.txt
C:\Muestras
D:\autorun.inf
F:\autorun.inf
C:\WINDOWS\ban_list.txt
C:\WINDOWS\mdelk.exe
C:\WINDOWS\wintems.exe
C:\WINDOWS\system32\srosa2.sys
C:\WINDOWS\system32\wfsintwq.sys
C:\Documents and Settings\utente\Dati applicazioni\drivers
C:\Documents and Settings\utente\Dati applicazioni\drivers\downld
C:\Documents and Settings\utente\Dati applicazioni\drivers\winupgro.exe
C:\Documents and Settings\utente\Dati applicazioni\hidires
C:\Documents and Settings\utente\Dati applicazioni\hidires\config
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\cancelled.met
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\clients.met
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\cryptkey.dat
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\emfriends.met
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\known.met
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\known2_64.met
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\preferences.ini
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\server.met
C:\Documents and Settings\utente\Dati applicazioni\hidires\config\statistics.ini
C:\Documents and Settings\utente\Dati applicazioni\hidires\downloads.txt
C:\Documents and Settings\utente\Dati applicazioni\hidires\file.exe
C:\Documents and Settings\utente\Dati applicazioni\hidires\flec003.exe
C:\Documents and Settings\utente\Dati applicazioni\hidires\flec005.exe
C:\Documents and Settings\utente\Dati applicazioni\hidires\Incoming
C:\Documents and Settings\utente\Dati applicazioni\hidires\lang
C:\Documents and Settings\utente\Dati applicazioni\hidires\names.txt
C:\Documents and Settings\utente\Dati applicazioni\hidires\server.txt
C:\Documents and Settings\utente\Dati applicazioni\hidires\skins
C:\Documents and Settings\utente\Dati applicazioni\hidires\Temp
C:\Documents and Settings\utente\Dati applicazioni\hidires\WDIR
C:\Documents and Settings\utente\Dati applicazioni\hidires\webserver
C:\Documents and Settings\utente\Dati applicazioni\m
C:\Documents and Settings\utente\Dati applicazioni\m\data.oct
C:\Documents and Settings\utente\Dati applicazioni\m\flec006.exe
C:\Documents and Settings\utente\Dati applicazioni\m\list.oct
C:\Documents and Settings\utente\Dati applicazioni\m\srvlist.oct
C:\Documents and Settings\utente\Dati applicazioni\m\shared
################## | Registry |
[HKLM\SYSTEM\CurrentControlSet\Services\sK9Ou0s]
[HKLM\SYSTEM\ControlSet001\Services\sK9Ou0s]
[HKLM\SYSTEM\ControlSet002\Services\sK9Ou0s]
[HKLM\SYSTEM\CurrentControlSet\Services\srosa]
[HKLM\SYSTEM\ControlSet001\Services\srosa]
[HKLM\SYSTEM\ControlSet002\Services\srosa]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]
[HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S]
[HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
[HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
[HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
[HKLM\software\microsoft\shared tools\msconfig\startupreg\flec003.exe]
[HKCU\Software\bisoft]
[HKCU\Software\DateTime4]
[HKCU\Software\MuleAppData]
[HKCU\Software\WS4001]
[HKCR\ed2k]
[HKCU\Software\Classes\ed2k]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "flec003.exe"
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Run] "flec003.exe"
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\bisoft]
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\DateTime4]
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\MuleAppData]
[HKCU\Software\Local AppWizard-Generated Applications\patch]
[HKCU\Software\Local AppWizard-Generated Applications\winupgro]
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\Local AppWizard-Generated Applications\patch]
[HKU\S-1-5-21-789336058-1060284298-1202660629-1003\Software\Local AppWizard-Generated Applications\winupgro]
################## | State |
# Showing of hidden files : OK
Missing key : HKLM\...\SafeBoot | Safe boot mode disabled !
# (!) Ndisuio -> Start = 4 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
# (!) Ip6Fw -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) wuauserv -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )
################## | End of Report # FindyKill V5.043 ! |