Torna indietro   Hardware Upgrade Forum > Networking e sicurezza > Antivirus e Sicurezza > Aiuto sono infetto! Cosa faccio?

iPhone 18 Pro: la recensione del miglior iPhone compatto di sempre
iPhone 18 Pro: la recensione del miglior iPhone compatto di sempre
Apple ha rinnovato iPhone 18 Pro soprattutto dentro: chip A20 Pro a 2 nm con memoria affiancata al SoC, camera di vapore tre volte più ampia, Dynamic Island più piccola del 25% grazie a Face ID sotto il display e fotocamera principale con diaframma variabile da f/1.48 a f/4. Lo abbiamo misurato al colorimetro e nei benchmark, usato con iOS 27 e messo alla prova in fotografia tra laghi, borghi e interni poco illuminati
Panasonic, 30 anni di Toughbook: la "Bibbia" di mille regole dietro i nuovi G3 e 34
Panasonic, 30 anni di Toughbook: la "Bibbia" di mille regole dietro i nuovi G3 e 34
A Londra, per il trentennale dei Toughbook, Panasonic ha presentato il tablet G3 e il 2-in-1 34. Con Jon Tucker, a capo dell'ingegneria europea, abbiamo parlato di ciò che non si vede: batterie, antenne, porte seriali e accorgimenti nati sul campo
realme C100x, lo smartphone economico con la batteria da 7500 mAh. La recensione
realme C100x, lo smartphone economico con la batteria da 7500 mAh. La recensione
realme C100x scommette tutto, forse troppo, sulla batteria da 7500 mAh e sulla certificazione ArmorShell per farsi notare nella fascia più economica del mercato: lo abbiamo messo alla prova per capire a chi è rivolto questo smartphone che sacrifica un po' prestazioni, display e fotocamera per offrire l'autonomia migliore possibile a un prezzo decisamente contenuto
Tutti gli articoli Tutte le news

Vai al Forum
Rispondi
 
Strumenti
Old 11-06-2008, 21:10   #1
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
Virus Blocca VirIT CCleaner e HWupgrade forum

Ciao ragazzi ci risiamo .....

vi spiego che succede :
- sistema con XP nod32 aggiornato e a-squared aggiornato -
da due giorni CCleaner non mi và più , clicco , si apre e ritorna sul desktop anche se provo a reinstallarlo . Mi insospettisco e provo a cercare sul forum le possibili cause , clicco il link e track si chiude il browser , comincio a sentire puzza di bruciato ...
- da un'altro pc vado sul forum di HWupgrade , e seguo le istruzioni per cercare di capire cosa ho ..... provo gli antivirus online consigliati ( in modalità provvisoria con rete dopo aver disabilitato ripristino config. etc .) ma niente ...

poi provo anche VirIT ( sempre in modalità provvisoria con rete ) e fine scansione mi trova due bei virus .... Trojan.Win32.Agent.BMY e Trojan.Win32.Dialer.IH .... io esulto VirIT mi conferma che sono stati rimossi .... provo CCleaner funziona provo ad andare sul forum ce la faccio ! e vai , riavvio

tutto come prima , anzi peggio ora anche VirIT non funge
e non riesco neanche a cercarlo su internet .....

ho già formattato un anno fa , questa volta vorrei provare a batterlo , aiutatemi ... non possono sempre vincere loro

ora proverò ad inserire dei log , è la prima volta quindi non sò se uscirà qualcosa .....

log di HijackThis

Codice:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18.13.09, on 10/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmi\Eset\nod32kui.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\a-squared Free\a2service.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Eset\nod32krn.exe
C:\Programs\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\VEXPLITE\viritsvc.exe
C:\WINDOWS\System32\alg.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Programmi\Corel\Corel Graphics 12\Languages\IT\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=062408 serial=DR12WRS-8796594-FHE lang=IT
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [H2O] C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
O23 - Service: CSIScanner - Prevx - C:\Programmi\PrevxCSI\prevxcsi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\mssrv32.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Programmi\Eset\nod32krn.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programs\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas   www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
O24 - Desktop Component 1: Aqua Real - 7db39a0d-580f-4be9-9195-8bfcd226f6c2

--
End of file - 5510 bytes
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 11-06-2008, 21:13   #2
xcdegasp
Senior Member
 
L'Avatar di xcdegasp
 
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
disattiva il ripristino di configurazione e segui la semplice procedura descritta in Guida alla Disinfezione per Infetti e pubblica tutti i log richiesti facendo attenzione alle Regole di Sezione, così potremmo aiutarti

nella guida è ben descritto come disabilitare il ripristino di sistema
xcdegasp è offline   Rispondi citando il messaggio o parte di esso
Old 11-06-2008, 21:45   #3
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
Scusate forse non mi sono spiegato bene ma , il ripristino di configurazione di sistema è stato disattivato , prima di tutte le operazioni

se può aiutare , quando entro in modalità provvisoria appaiono due user :

ADMIN e ADMINISTRATOR ... è normale ?

per quanto riguarda la guida ecco cosa ho fatto :

1) ADS Scanner 2.0 - niente
2) A-Squared Free v3.x deep - niente
3) F-Secure OnLine - niente
4) Dr.Web CureIT - lasciato log in ufficio
5) ESET SysInspector - log in formato XML da 1,52 mb ( come lo posto ? )
6) HiJackThis - vedi sopra
7) Gmer

Codice:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-06-10 12:07:21
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.14 ----

SSDT      spjw.sys                                                                                                                                        ZwCreateKey [0xF74B90E0]
SSDT      spjw.sys                                                                                                                                        ZwEnumerateKey [0xF74D6CA2]
SSDT      spjw.sys                                                                                                                                        ZwEnumerateValueKey [0xF74D7030]
SSDT      spjw.sys                                                                                                                                        ZwOpenKey [0xF74B90C0]
SSDT      spjw.sys                                                                                                                                        ZwQueryKey [0xF74D7108]
SSDT      spjw.sys                                                                                                                                        ZwQueryValueKey [0xF74D6F88]
SSDT      spjw.sys                                                                                                                                        ZwSetValueKey [0xF74D719A]

INT 0x62  ?                                                                                                                                               863D7BF8
INT 0x63  ?                                                                                                                                               863D7BF8
INT 0x73  ?                                                                                                                                               86244F00
INT 0x82  ?                                                                                                                                               863D7BF8
INT 0x94  ?                                                                                                                                               86244F00
INT 0xA4  ?                                                                                                                                               86244F00

---- Kernel code sections - GMER 1.0.14 ----

?         spjw.sys                                                                                                                                        Impossibile trovare il file specificato. !
.text     USBPORT.SYS!DllUnload                                                                                                                           F725262C 5 Bytes  JMP 862444E0 
.text     agmy20m1.SYS                                                                                                                                    F71B1384 1 Byte  [ 20 ]
.text     agmy20m1.SYS                                                                                                                                    F71B1386 35 Bytes  [ 00, 68, 00, 00, 00, 00, 00, ... ]
.text     agmy20m1.SYS                                                                                                                                    F71B13AA 24 Bytes  [ 00, 00, 20, 00, 00, E0, 00, ... ]
.text     agmy20m1.SYS                                                                                                                                    F71B13C4 3 Bytes  [ 00, 00, 00 ]
.text     agmy20m1.SYS                                                                                                                                    F71B13C9 1 Byte  [ 00 ]
.text     ...                                                                                                                                             

---- Kernel IAT/EAT - GMER 1.0.14 ----

IAT       \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint]                                                                              863695E0
IAT       pci.sys[ntoskrnl.exe!IoDetachDevice]                                                                                                            [F74DF6D0] spjw.sys
IAT       pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack]                                                                                               [F74E3708] spjw.sys
IAT       atapi.sys[HAL.dll!READ_PORT_UCHAR]                                                                                                              [F74BA046] spjw.sys
IAT       atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT]                                                                                                      [F74BA142] spjw.sys
IAT       atapi.sys[HAL.dll!READ_PORT_USHORT]                                                                                                             [F74BA0C4] spjw.sys
IAT       atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                                                                                     [F74BA7CE] spjw.sys
IAT       atapi.sys[HAL.dll!WRITE_PORT_UCHAR]                                                                                                             [F74BA6A4] spjw.sys
IAT       \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint]                                                                            862445E0
IAT       \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR]                                                                              [F74C5D7A] spjw.sys
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlInitUnicodeString]                                                                    DD000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!swprintf]                                                                                74000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeSetEvent]                                                                              1F000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoCreateSymbolicLink]                                                                    4B000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoGetConfigurationInformation]                                                           BD000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoDeleteSymbolicLink]                                                                    8B000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmFreeMappingAddress]                                                                    8A000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoFreeErrorLogEntry]                                                                     70000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoDisconnectInterrupt]                                                                   3E000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmUnmapIoSpace]                                                                          B5000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ObReferenceObjectByPointer]                                                              66000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IofCompleteRequest]                                                                      48000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlCompareUnicodeString]                                                                 03000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IofCallDriver]                                                                           F6000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmAllocateMappingAddress]                                                                0E000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry]                                                                 61000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoConnectInterrupt]                                                                      35000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoDetachDevice]                                                                          57000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeWaitForSingleObject]                                                                   B9000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInitializeEvent]                                                                       86000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString]                                                            C1000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlInitAnsiString]                                                                       1D000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest]                                                           9E000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoQueueWorkItem]                                                                         E1000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmMapIoSpace]                                                                            F8000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations]                                                             98000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoReportDetectedDevice]                                                                  11000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoReportResourceForDetection]                                                            69000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize]                                                             D9000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!NlsMbCodePageTag]                                                                        8E000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoRequestPowerIrp]                                                                       94000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue]                                                                9B000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection]                                                        1E000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!sprintf]                                                                                 87000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache]                                                            E9000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ObfDereferenceObject]                                                                    CE000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference]                                                            55000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoInvalidateDeviceState]                                                                 28000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwClose]                                                                                 DF000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ObReferenceObjectByHandle]                                                               8C000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwCreateDirectoryObject]                                                                 A1000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest]                                                            89000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoStartNextPowerIrp]                                                                     0D000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoCallDriver]                                                                            [BF000000] \SystemRoot\System32\drivers\dxg.sys (DirectX Graphics Driver/Microsoft Corporation)
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoCreateDevice]                                                                          E6000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension]                                                         42000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlQueryRegistryValues]                                                                  68000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwOpenKey]                                                                               41000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlFreeUnicodeString]                                                                    99000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoStartTimer]                                                                            2D000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInitializeTimer]                                                                       0F000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoInitializeTimer]                                                                       B0000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInitializeDpc]                                                                         54000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInitializeSpinLock]                                                                    BB000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoInitializeIrp]                                                                         16000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwCreateKey]                                                                             00000052
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString]                                                          00000009
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString]                                                               0000006A
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwSetValueKey]                                                                           000000D5
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInsertQueueDpc]                                                                        00000030
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel]                                                            00000036
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoStartPacket]                                                                           000000A5
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel]                                                          00000038
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest]                                                           000000BF
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoFreeMdl]                                                                               00000040
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmUnlockPages]                                                                           000000A3
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoWriteErrorLogEntry]                                                                    0000009E
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue]                                                                00000081
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping]                                                     000000F3
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmUnmapReservedMapping]                                                                  000000D7
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeSynchronizeExecution]                                                                  000000FB
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoStartNextPacket]                                                                       0000007C
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeBugCheckEx]                                                                            000000E3
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeRemoveDeviceQueue]                                                                     00000039
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeSetTimer]                                                                              00000082
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeCancelTimer]                                                                           0000009B
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!_allmul]                                                                                 0000002F
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmProbeAndLockPages]                                                                     000000FF
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!_except_handler3]                                                                        00000087
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoSetPowerState]                                                                         00000034
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey]                                                                 0000008E
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlWriteRegistryValue]                                                                   00000043
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!_aulldiv]                                                                                00000044
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!strstr]                                                                                  000000C4
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!_strupr]                                                                                 000000DE
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeQuerySystemTime]                                                                       000000E9
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoWMIRegistrationControl]                                                                000000CB
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeTickCount]                                                                             00000054
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack]                                                             0000007B
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoDeleteDevice]                                                                          00000094
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ExAllocatePoolWithTag]                                                                   00000032
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateWorkItem]                                                                      000000A6
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateIrp]                                                                           000000C2
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateMdl]                                                                           00000023
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool]                                                               0000003D
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmLockPagableDataSection]                                                                000000EE
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoGetDriverObjectExtension]                                                              0000004C
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmUnlockPagableImageSection]                                                             00000095
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ExFreePoolWithTag]                                                                       0000000B
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoFreeIrp]                                                                               00000042
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoFreeWorkItem]                                                                          000000FA
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!InitSafeBootMode]                                                                        000000C3
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlCompareMemory]                                                                        0000004E
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlCopyUnicodeString]                                                                    00000008
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!memmove]                                                                                 0000002E
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmHighestUserAddress]                                                                    000000A1
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KfAcquireSpinLock]                                                                            6C000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!READ_PORT_UCHAR]                                                                              56000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KeGetCurrentIrql]                                                                             F4000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KfRaiseIrql]                                                                                  EA000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KfLowerIrql]                                                                                  65000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!HalGetInterruptVector]                                                                        7A000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!HalTranslateBusAddress]                                                                       AE000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KeStallExecutionProcessor]                                                                    08000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KfReleaseSpinLock]                                                                            BA000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!READ_PORT_BUFFER_USHORT]                                                                      78000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!READ_PORT_USHORT]                                                                             25000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                                                     2E000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!WRITE_PORT_UCHAR]                                                                             1C000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[WMILIB.SYS!WmiSystemControl]                                                                          B4000000
IAT       \SystemRoot\System32\Drivers\agmy20m1.SYS[WMILIB.SYS!WmiCompleteRequest]                                                                        C6000000

---- Devices - GMER 1.0.14 ----

Device    \FileSystem\Ntfs \Ntfs                                                                                                                          863D61F8
Device    \FileSystem\Fastfat \FatCdrom                                                                                                                   860BB1F8
Device    \Driver\sptd \Device\189952900                                                                                                                  spjw.sys
Device    \Driver\usbuhci \Device\USBPDO-0                                                                                                                8622F1F8
Device    \Driver\dmio \Device\DmControl\DmIoDaemon                                                                                                       863671F8
Device    \Driver\dmio \Device\DmControl\DmConfig                                                                                                         863671F8
Device    \Driver\dmio \Device\DmControl\DmPnP                                                                                                            863671F8
Device    \Driver\dmio \Device\DmControl\DmInfo                                                                                                           863671F8
Device    \Driver\usbuhci \Device\USBPDO-1                                                                                                                8622F1F8
Device    \Driver\usbuhci \Device\USBPDO-2                                                                                                                8622F1F8
Device    \Driver\usbuhci \Device\USBPDO-3                                                                                                                8622F1F8
Device    \Driver\usbehci \Device\USBPDO-4                                                                                                                8623A1F8
Device    \Driver\Ftdisk \Device\HarddiskVolume1                                                                                                          863D81F8
Device    \Driver\Cdrom \Device\CdRom0                                                                                                                    8621F1F8
Device    \Driver\Cdrom \Device\CdRom1                                                                                                                    8621F1F8
Device    \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3                                                                                                     863D71F8
Device    \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3                                                                                                     prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device    \Driver\atapi \Device\Ide\IdePort0                                                                                                              863D71F8
Device    \Driver\atapi \Device\Ide\IdePort0                                                                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device    \Driver\atapi \Device\Ide\IdePort1                                                                                                              863D71F8
Device    \Driver\atapi \Device\Ide\IdePort1                                                                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device    \Driver\atapi \Device\Ide\IdePort2                                                                                                              863D71F8
Device    \Driver\atapi \Device\Ide\IdePort2                                                                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device    \Driver\atapi \Device\Ide\IdePort3                                                                                                              863D71F8
Device    \Driver\atapi \Device\Ide\IdePort3                                                                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device    \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e                                                                                                     863D71F8
Device    \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e                                                                                                     prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device    \Driver\Cdrom \Device\CdRom2                                                                                                                    8621F1F8
Device    \Driver\prohlp02 \Device\ProHlp02                                                                                                               E100F6C8
Device    \Driver\PCI_PNP9150 \Device\0000004a                                                                                                            spjw.sys
Device    \Driver\usbuhci \Device\USBFDO-0                                                                                                                8622F1F8
Device    \Driver\usbuhci \Device\USBFDO-1                                                                                                                8622F1F8
Device    \Driver\usbuhci \Device\USBFDO-2                                                                                                                8622F1F8
Device    \Driver\usbuhci \Device\USBFDO-3                                                                                                                8622F1F8
Device    \Driver\usbehci \Device\USBFDO-4                                                                                                                8623A1F8
Device    \Driver\Ftdisk \Device\FtControl                                                                                                                863D81F8
Device    \Driver\agmy20m1 \Device\Scsi\agmy20m11Port4Path0Target0Lun0                                                                                    8621E1F8
Device    \Driver\agmy20m1 \Device\Scsi\agmy20m11                                                                                                         8621E1F8
Device    \Driver\agmy20m1 \Device\Scsi\agmy20m11Port4Path0Target1Lun0                                                                                    8621E1F8
Device    \FileSystem\Fastfat \Fat                                                                                                                        860BB1F8
Device    \FileSystem\Cdfs \Cdfs                                                                                                                          860E81F8

---- Registry - GMER 1.0.14 ----

Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1                                                                                              -1880953118
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2                                                                                              881923701
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0                                                                                              3
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                                
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                             C:\Programs\Alcohol 120\
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                             0
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                          0xDC 0xC6 0xCC 0xA6 ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                                       
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                                    0x20 0x01 0x00 0x00 ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                                 0x1B 0x30 0xF1 0x02 ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                                                
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                                          0x8E 0xF8 0xFB 0x7A ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41                                                
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew                                          0xD4 0xDD 0xB6 0xE1 ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                             1
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                          0x5F 0x35 0x90 0x82 ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                                                
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                             2
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                          0x80 0x16 0x2B 0xF3 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                                    
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                                 C:\Programs\Alcohol 120\
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                                 0
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                              0xDC 0xC6 0xCC 0xA6 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                                           
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                                        0x20 0x01 0x00 0x00 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                                     0x1B 0x30 0xF1 0x02 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                                                    
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                                              0x8E 0xF8 0xFB 0x7A ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41                                                    
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew                                              0xD4 0xDD 0xB6 0xE1 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                    
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                 1
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                              0x5F 0x35 0x90 0x82 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                                                    
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                                 2
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                              0x80 0x16 0x2B 0xF3 ...
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}                                 
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@oagfmgeeemdfpmaobedmicgmkpjemp  0x64 0x61 0x64 0x70 ...
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@oakeemcdpeoooaonjjlanibkplalac  0x6A 0x61 0x64 0x70 ...
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@naaikgijmnleglpjhhfobgigbpmn    0x6A 0x61 0x66 0x70 ...

---- EOF - GMER 1.0.14 ----
8 ) PrevxCSI - niente

spero di aver messo le cose giuste , non sono protico di Gmer o HJ etc. etc.

a metto anche i log trovati nella cartella di VirIT prima che non mi funzionasse più

Codice:
[SCANSIONE DEL REGISTRO]
OK

[A:]
BOOT SECTOR: OK
 
 
[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
 
C:\WINDOWS\system32\updedvih.exe Infetto da Trojan.Win32.Agent.BMY
 * * *  RIMOSSO  * * *
C:\WINDOWS\Temp\pzxwlk.exe Infetto da Trojan.Win32.Dialer.IH
 * * *  RIMOSSO  * * *
 
[D:]
 
 
[I:]
 
 
[J:]
 
 
Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 44429.
Files Totali: 44429.
Chiavi Registro rimosse: 0.
Virus Rimossi: 2.
e 2

Codice:
VirIT Lite Monitor: Lista ultimi file creati o modificati

C:\WINDOWS

10/06/2008  13:26  0.log (0)
10/06/2008  14:01  bootstat.dat (2048)
10/06/2008  09:36  gmer.dll (884736)
10/06/2008  13:45  gmer.ini (250)
10/06/2008  09:36  gmer_uninstall.cmd (80)
10/06/2008  07:41  ModemLog_Modem standard.txt (1904)
31/05/2008  09:20  NeroDigital.ini (69)
10/06/2008  13:57  ntbtlog.txt (273134)
10/06/2008  13:20  SchedLgU.Txt (890)
10/06/2008  13:12  Sti_Trace.log (0)
09/06/2008  16:45  system.ini (253)
10/06/2008  13:26  wiadebug.log (159)
10/06/2008  13:26  wiaservc.log (50)
09/06/2008  16:45  win.ini (564)
10/06/2008  13:59  WindowsUpdate.log (6069)


C:\WINDOWS\system32

09/06/2008  14:07  wpa.dbl (2206)


C:\WINDOWS\system32\drivers

10/06/2008  09:36  gmer.sys (85969)
10/06/2008  10:32  pxark.sys (17408)


C:\DOCUME~1\Admin\IMPOST~1\Temp\

29/05/2008  17:14  control.xml (12818)
04/06/2008  17:04  femdom-005.mpg (1298436)
09/06/2008  17:02  IH110.tmp (9601)
10/06/2008  13:19  IH2B.tmp (2592)
04/06/2008  08:28  IH2DA.tmp (9744)
09/06/2008  16:52  IH41.tmp (3869)
26/05/2008  17:14  IH60DC.tmp (507991)
09/06/2008  15:46  IH719C.tmp (3869)
09/06/2008  15:51  IH7242.tmp (1161)
09/06/2008  15:52  IH726B.tmp (690)
09/06/2008  17:18  java_install_reg.log (4244)
10/06/2008  13:17  jusched.log (9570)
10/06/2008  13:53  LastScan.txt (904)
10/06/2008  13:53  restart.a2s (483)


C:\

09/06/2008  16:45  boot.ini (211)
10/06/2008  14:01  pagefile.sys (1598029824)


C:\WINDOWS\system32\dllcache



C:\WINDOWS\Temp

10/06/2008  10:36  exp103.tmp (0)
02/06/2008  10:32  exp1DDF.tmp (0)
05/06/2008  10:35  exp23C2.tmp (0)
03/06/2008  10:32  exp2CB6.tmp (0)
06/06/2008  10:35  exp4B2B.tmp (0)
07/06/2008  10:35  exp75C2.tmp (0)
08/06/2008  10:35  exp7744.tmp (0)
09/06/2008  10:35  exp7BB9.tmp (0)
01/06/2008  10:32  exp849.tmp (0)
29/05/2008  09:20  expB656.tmp (0)
04/06/2008  10:35  expD47.tmp (0)
30/05/2008  09:22  expE683.tmp (0)
31/05/2008  09:32  expFC7C.tmp (0)


C:\VEXPLITE\

10/06/2008  10:42  CLEAN.DAT (370570)
10/06/2008  10:42  DISLITE.EXE (45056)
10/06/2008  10:42  GOTGSOFT.BAT (42)
10/06/2008  10:42  GOVIRITEXPSVC.BAT (17)
10/06/2008  10:42  GOVIRSMD.BAT (17)
10/06/2008  14:02  lastfile.txt (0)
10/06/2008  10:56  listathread.txt (14492)
10/06/2008  10:42  MONLITE.EXE (245760)
10/06/2008  10:42  NAME-LT.DAT (302413)
10/06/2008  10:42  ORDINA.WRI (12496)
10/06/2008  10:42  PROCDLL.DLL (57344)
10/06/2008  13:12  reg_ecc.dat (0)
10/06/2008  10:56  REPORT.RPT (72)
10/06/2008  10:42  SCAN.DLL (290816)
10/06/2008  10:42  SCANFILE.TXT (0)
10/06/2008  14:02  Syskrn.txt (32886)
10/06/2008  10:42  TGSVCSTP.EXE (40960)
10/06/2008  10:42  VIRAGTLT.SYS (39808)
10/06/2008  10:42  VIRIT-LT.DAT (765200)
10/06/2008  10:42  VIRITEXP.CSM (4)
10/06/2008  10:42  VIRITEXP.EXE (688128)
10/06/2008  10:56  VIRITEXP.LOG (636)
10/06/2008  13:12  VIRITMON.LOG (30)
10/06/2008  10:42  VIRITSVC.EXE (57344)
10/06/2008  10:42  VIRITUPG.DLL (102400)
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 11-06-2008, 21:53   #4
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
ecco il link al log di SysInspector-PC

http://wikisend.com/download/497536/...PC-lucap78.xml

chissà se funzia ?
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 11-06-2008, 22:43   #5
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
ragan aggiungo una informazione che forse è utile

nella schermata di gmer su registry, alla voce HKEY-LOCAL-MACHINE ho trovato una cartella di nome SAM contenente sotto cartelle tutte di colore rosso ?

è una cosa normale ?

in attesa di utili consigli

distinti saluti
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 12-06-2008, 07:06   #6
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
tu carica il log secondo le modalità e copia nella discussione le voci in rosso (che di norma andrebbero eliminate)
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 12-06-2008, 11:33   #7
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
Le voci in rosso non sono nella schermata iniziale

ma dentro il registry, alla voce HKEY-LOCAL-MACHINE

comunque oggi se ce la faccio posto un log di gmer anche se penso di aver trovato un file gif sospetto in System32 che non si cancella e non si invia per lo scan online
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 12-06-2008, 12:03   #8
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
Quote:
Originariamente inviato da LuCaP78 Guarda i messaggi
ecco il link al log di SysInspector-PC

http://wikisend.com/download/497536/...PC-lucap78.xml

chissà se funzia ?
puoi rifarlo che mi da errore all'apertura
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 12-06-2008, 15:59   #9
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
allora ... ecco i log di Gmer prima posto quello dei Rootkit

Codice:
 GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-06-12 16:39:28
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.14 ----

SSDT            spni.sys                                                                                                                                        ZwCreateKey [0xF74B90E0]
SSDT            spni.sys                                                                                                                                        ZwEnumerateKey [0xF74D6CA2]
SSDT            spni.sys                                                                                                                                        ZwEnumerateValueKey [0xF74D7030]
SSDT            spni.sys                                                                                                                                        ZwOpenKey [0xF74B90C0]
SSDT            spni.sys                                                                                                                                        ZwQueryKey [0xF74D7108]
SSDT            spni.sys                                                                                                                                        ZwQueryValueKey [0xF74D6F88]
SSDT            spni.sys                                                                                                                                        ZwSetValueKey [0xF74D719A]

INT 0x62        ?                                                                                                                                               86368BF8
INT 0x63        ?                                                                                                                                               86368BF8
INT 0x82        ?                                                                                                                                               86368BF8
INT 0x94        ?                                                                                                                                               86239BF8
INT 0xA4        ?                                                                                                                                               86239BF8

---- Kernel code sections - GMER 1.0.14 ----

?               spni.sys                                                                                                                                        Impossibile trovare il file specificato. !
.text           USBPORT.SYS!DllUnload                                                                                                                           F712F62C 5 Bytes  JMP 862391D8 
.text           afy2zzfx.SYS                                                                                                                                    F7069384 1 Byte  [ 20 ]
.text           afy2zzfx.SYS                                                                                                                                    F7069386 35 Bytes  [ 00, 68, 00, 00, 00, 00, 00, ... ]
.text           afy2zzfx.SYS                                                                                                                                    F70693AA 24 Bytes  [ 00, 00, 20, 00, 00, E0, 00, ... ]
.text           afy2zzfx.SYS                                                                                                                                    F70693C4 3 Bytes  [ 00, 00, 00 ]
.text           afy2zzfx.SYS                                                                                                                                    F70693C9 1 Byte  [ 00 ]
.text           ...                                                                                                                                             

---- Kernel IAT/EAT - GMER 1.0.14 ----

IAT             \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint]                                                                              863D92D8
IAT             pci.sys[ntoskrnl.exe!IoDetachDevice]                                                                                                            [F74DF6D0] spni.sys
IAT             pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack]                                                                                               [F74E3708] spni.sys
IAT             atapi.sys[HAL.dll!READ_PORT_UCHAR]                                                                                                              [F74BA046] spni.sys
IAT             atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT]                                                                                                      [F74BA142] spni.sys
IAT             atapi.sys[HAL.dll!READ_PORT_USHORT]                                                                                                             [F74BA0C4] spni.sys
IAT             atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                                                                                     [F74BA7CE] spni.sys
IAT             atapi.sys[HAL.dll!WRITE_PORT_UCHAR]                                                                                                             [F74BA6A4] spni.sys
IAT             \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint]                                                                            862392D8
IAT             \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR]                                                                              [F74C5D7A] spni.sys
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlInitUnicodeString]                                                                    DD000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!swprintf]                                                                                74000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeSetEvent]                                                                              1F000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoCreateSymbolicLink]                                                                    4B000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoGetConfigurationInformation]                                                           BD000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoDeleteSymbolicLink]                                                                    8B000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmFreeMappingAddress]                                                                    8A000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoFreeErrorLogEntry]                                                                     70000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoDisconnectInterrupt]                                                                   3E000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmUnmapIoSpace]                                                                          B5000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ObReferenceObjectByPointer]                                                              66000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IofCompleteRequest]                                                                      48000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlCompareUnicodeString]                                                                 03000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IofCallDriver]                                                                           F6000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmAllocateMappingAddress]                                                                0E000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry]                                                                 61000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoConnectInterrupt]                                                                      35000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoDetachDevice]                                                                          57000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeWaitForSingleObject]                                                                   B9000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInitializeEvent]                                                                       86000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString]                                                            C1000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlInitAnsiString]                                                                       1D000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest]                                                           9E000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoQueueWorkItem]                                                                         E1000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmMapIoSpace]                                                                            F8000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations]                                                             98000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoReportDetectedDevice]                                                                  11000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoReportResourceForDetection]                                                            69000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize]                                                             D9000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!NlsMbCodePageTag]                                                                        8E000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoRequestPowerIrp]                                                                       94000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue]                                                                9B000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection]                                                        1E000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!sprintf]                                                                                 87000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache]                                                            E9000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ObfDereferenceObject]                                                                    CE000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference]                                                            55000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoInvalidateDeviceState]                                                                 28000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwClose]                                                                                 DF000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ObReferenceObjectByHandle]                                                               8C000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwCreateDirectoryObject]                                                                 A1000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest]                                                            89000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoStartNextPowerIrp]                                                                     0D000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoCallDriver]                                                                            [BF000000] \SystemRoot\System32\drivers\dxg.sys (DirectX Graphics Driver/Microsoft Corporation)
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoCreateDevice]                                                                          E6000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension]                                                         42000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlQueryRegistryValues]                                                                  68000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwOpenKey]                                                                               41000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlFreeUnicodeString]                                                                    99000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoStartTimer]                                                                            2D000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInitializeTimer]                                                                       0F000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoInitializeTimer]                                                                       B0000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInitializeDpc]                                                                         54000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInitializeSpinLock]                                                                    BB000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoInitializeIrp]                                                                         16000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwCreateKey]                                                                             00000052
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString]                                                          00000009
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString]                                                               0000006A
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwSetValueKey]                                                                           000000D5
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInsertQueueDpc]                                                                        00000030
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel]                                                            00000036
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoStartPacket]                                                                           000000A5
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel]                                                          00000038
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest]                                                           000000BF
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoFreeMdl]                                                                               00000040
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmUnlockPages]                                                                           000000A3
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoWriteErrorLogEntry]                                                                    0000009E
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue]                                                                00000081
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping]                                                     000000F3
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmUnmapReservedMapping]                                                                  000000D7
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeSynchronizeExecution]                                                                  000000FB
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoStartNextPacket]                                                                       0000007C
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeBugCheckEx]                                                                            000000E3
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeRemoveDeviceQueue]                                                                     00000039
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeSetTimer]                                                                              00000082
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeCancelTimer]                                                                           0000009B
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!_allmul]                                                                                 0000002F
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmProbeAndLockPages]                                                                     000000FF
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!_except_handler3]                                                                        00000087
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoSetPowerState]                                                                         00000034
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey]                                                                 0000008E
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlWriteRegistryValue]                                                                   00000043
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!_aulldiv]                                                                                00000044
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!strstr]                                                                                  000000C4
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!_strupr]                                                                                 000000DE
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeQuerySystemTime]                                                                       000000E9
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoWMIRegistrationControl]                                                                000000CB
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeTickCount]                                                                             00000054
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack]                                                             0000007B
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoDeleteDevice]                                                                          00000094
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ExAllocatePoolWithTag]                                                                   00000032
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateWorkItem]                                                                      000000A6
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateIrp]                                                                           000000C2
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateMdl]                                                                           00000023
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool]                                                               0000003D
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmLockPagableDataSection]                                                                000000EE
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoGetDriverObjectExtension]                                                              0000004C
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmUnlockPagableImageSection]                                                             00000095
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ExFreePoolWithTag]                                                                       0000000B
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoFreeIrp]                                                                               00000042
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoFreeWorkItem]                                                                          000000FA
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!InitSafeBootMode]                                                                        000000C3
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlCompareMemory]                                                                        0000004E
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlCopyUnicodeString]                                                                    00000008
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!memmove]                                                                                 0000002E
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmHighestUserAddress]                                                                    000000A1
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KfAcquireSpinLock]                                                                            6C000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!READ_PORT_UCHAR]                                                                              56000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KeGetCurrentIrql]                                                                             F4000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KfRaiseIrql]                                                                                  EA000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KfLowerIrql]                                                                                  65000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!HalGetInterruptVector]                                                                        7A000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!HalTranslateBusAddress]                                                                       AE000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KeStallExecutionProcessor]                                                                    08000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KfReleaseSpinLock]                                                                            BA000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!READ_PORT_BUFFER_USHORT]                                                                      78000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!READ_PORT_USHORT]                                                                             25000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                                                     2E000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!WRITE_PORT_UCHAR]                                                                             1C000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[WMILIB.SYS!WmiSystemControl]                                                                          B4000000
IAT             \SystemRoot\System32\Drivers\afy2zzfx.SYS[WMILIB.SYS!WmiCompleteRequest]                                                                        C6000000

---- Devices - GMER 1.0.14 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                                                          863671F8

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                                                          amon.sys (Amon monitor/Eset )

Device          \Driver\sptd \Device\1625828836                                                                                                                 spni.sys
Device          \Driver\usbuhci \Device\USBPDO-0                                                                                                                862371F8
Device          \Driver\usbuhci \Device\USBPDO-1                                                                                                                862371F8
Device          \Driver\dmio \Device\DmControl\DmIoDaemon                                                                                                       863D71F8
Device          \Driver\dmio \Device\DmControl\DmConfig                                                                                                         863D71F8
Device          \Driver\dmio \Device\DmControl\DmPnP                                                                                                            863D71F8
Device          \Driver\dmio \Device\DmControl\DmInfo                                                                                                           863D71F8
Device          \Driver\usbuhci \Device\USBPDO-2                                                                                                                862371F8
Device          \Driver\usbuhci \Device\USBPDO-3                                                                                                                862371F8
Device          \Driver\usbehci \Device\USBPDO-4                                                                                                                862361F8
Device          \Driver\prodrv06 \Device\ProDrv06                                                                                                               E15F2550
Device          \Driver\Ftdisk \Device\HarddiskVolume1                                                                                                          863691F8
Device          \Driver\Cdrom \Device\CdRom0                                                                                                                    861F6498
Device          \Driver\Cdrom \Device\CdRom1                                                                                                                    861F6498
Device          \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3                                                                                                     863681F8
Device          \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3                                                                                                     prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort0                                                                                                              863681F8
Device          \Driver\atapi \Device\Ide\IdePort0                                                                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort1                                                                                                              863681F8
Device          \Driver\atapi \Device\Ide\IdePort1                                                                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort2                                                                                                              863681F8
Device          \Driver\atapi \Device\Ide\IdePort2                                                                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort3                                                                                                              863681F8
Device          \Driver\atapi \Device\Ide\IdePort3                                                                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e                                                                                                     863681F8
Device          \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e                                                                                                     prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\Cdrom \Device\CdRom2                                                                                                                    861F6498
Device          \Driver\prohlp02 \Device\ProHlp02                                                                                                               E13F1548
Device          \Driver\PCI_PNP5086 \Device\0000004a                                                                                                            spni.sys
Device          \Driver\NetBT \Device\NetBt_Wins_Export                                                                                                         85D661F8
Device          \Driver\NetBT \Device\NetbiosSmb                                                                                                                85D661F8
Device          \Driver\NetBT \Device\NetBT_Tcpip_{BE148E8A-8250-4E6C-B1EF-DF79FE2B59B8}                                                                        85D661F8
Device          \Driver\usbuhci \Device\USBFDO-0                                                                                                                862371F8
Device          \Driver\usbuhci \Device\USBFDO-1                                                                                                                862371F8
Device          \FileSystem\MRxSmb \Device\LanmanDatagramReceiver                                                                                               85D061F8
Device          \Driver\usbuhci \Device\USBFDO-2                                                                                                                862371F8
Device          \FileSystem\MRxSmb \Device\LanmanRedirector                                                                                                     85D061F8
Device          \Driver\usbuhci \Device\USBFDO-3                                                                                                                862371F8
Device          \Driver\Ftdisk \Device\FtControl                                                                                                                863691F8
Device          \Driver\usbehci \Device\USBFDO-4                                                                                                                862361F8
Device          \Driver\afy2zzfx \Device\Scsi\afy2zzfx1Port4Path0Target0Lun0                                                                                    861F21F8
Device          \Driver\afy2zzfx \Device\Scsi\afy2zzfx1                                                                                                         861F21F8
Device          \Driver\afy2zzfx \Device\Scsi\afy2zzfx1Port4Path0Target1Lun0                                                                                    861F21F8
Device          \FileSystem\Cdfs \Cdfs                                                                                                                          85D041F8

---- Registry - GMER 1.0.14 ----

Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1                                                                                              -1880953118
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2                                                                                              881923701
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0                                                                                              3
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                                
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                             C:\Programs\Alcohol 120\
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                             0
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                          0xDC 0xC6 0xCC 0xA6 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                                       
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                                    0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                                 0x1B 0x30 0xF1 0x02 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                                                
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                                          0x8E 0xF8 0xFB 0x7A ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41                                                
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew                                          0xD4 0xDD 0xB6 0xE1 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                             1
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                          0x5F 0x35 0x90 0x82 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                                                
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                             2
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                          0x80 0x16 0x2B 0xF3 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                                    
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                                 C:\Programs\Alcohol 120\
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                                 0
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                              0xDC 0xC6 0xCC 0xA6 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                                           
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                                        0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                                     0x1B 0x30 0xF1 0x02 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                                                    
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                                              0x8E 0xF8 0xFB 0x7A ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41                                                    
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew                                              0xD4 0xDD 0xB6 0xE1 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                    
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                 1
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                              0x5F 0x35 0x90 0x82 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                                                    
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                                 2
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                              0x80 0x16 0x2B 0xF3 ...
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}                                 
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@oagfmgeeemdfpmaobedmicgmkpjemp  0x64 0x61 0x64 0x70 ...
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@oakeemcdpeoooaonjjlanibkplalac  0x6A 0x61 0x64 0x70 ...
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@naaikgijmnleglpjhhfobgigbpmn    0x6A 0x61 0x66 0x70 ...

---- EOF - GMER 1.0.14 ----
ed ecco anche quello per la voce Autostart

Codice:
 GMER 1.0.14.14536 - http://www.gmer.net
Autostart scan 2008-06-12 16:41:08
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui@DLLName = igfxdev.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
MDM@ = "C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE"
NOD32krn@ = "C:\Programmi\Eset\nod32krn.exe"
StarWindServiceAE@ = C:\Programs\Alcohol 120\StarWind\StarWindServiceAE.exe
UMWdf@ = C:\WINDOWS\system32\wdfmgr.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@CorelDRAW Graphics Suite 11bC:\Programmi\Corel\Corel Graphics 12\Languages\IT\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=062408 serial=DR12WRS-8796594-FHE lang=IT /*file not found*/ = C:\Programmi\Corel\Corel Graphics 12\Languages\IT\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=062408 serial=DR12WRS-8796594-FHE lang=IT /*file not found*/
@SunJavaUpdateSched"C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe" = "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
@SoundMAXPnPC:\Programmi\Analog Devices\Core\smax4pnp.exe = C:\Programmi\Analog Devices\Core\smax4pnp.exe
@SoundMAX"C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray = "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
@PersistenceC:\WINDOWS\system32\igfxpers.exe = C:\WINDOWS\system32\igfxpers.exe
@nod32kui"C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE = "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
@IgfxTrayC:\WINDOWS\system32\igfxtray.exe = C:\WINDOWS\system32\igfxtray.exe
@HotKeysCmdsC:\WINDOWS\system32\hkcmd.exe = C:\WINDOWS\system32\hkcmd.exe
@High Definition Audio Property Page ShortcutHDAShCut.exe = HDAShCut.exe
@H2OC:\Programmi\SyncroSoft\Pos\H2O\cledx.exe = C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
RunOnce@SpybotSnD = "C:\Programmi\Spybot - Search & Destroy\SpybotSD.exe" /autocheck

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@SpybotSD TeaTimerC:\Programmi\Spybot - Search & Destroy\TeaTimer.exe = C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe@Debugger = "c:\windows\system32\ejvcveef.gif"

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) = 
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRar\rarext.dll = C:\Programmi\WinRar\rarext.dll
@{B089FE88-FB52-11D3-BDF1-0050DA34150D} /*NOD32 Context Menu Shell Extension*/C:\Programmi\Eset\nodshex.dll = C:\Programmi\Eset\nodshex.dll
@{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} /*NeroCoverEd Live Icons*/C:\Programmi\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll = C:\Programmi\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\OFFICE11\msohev.dll = C:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft.XPS.Shell.Metadata.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft.XPS.Shell.Thumbnail.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@CorelDRAW Shell Extension Component /*CorelDRAW Shell Extension Component*/(null) = 
@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} /*Shell Extension for Malware scanning*/(null) = 

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Cover Designer@{73FCA462-9BD5-4065-A73F-A8E5F6904EF7} = C:\Programmi\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll
DaemonShellExtImage@{40966797-8FFE-46C8-9EF8-7003F33CCF0F} = 
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11D3-BDF1-0050DA34150D} = C:\Programmi\Eset\nodshex.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRar\rarext.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRar\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11D3-BDF1-0050DA34150D} = C:\Programmi\Eset\nodshex.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\PROGRA~1\SPYBOT~1\SDHelper.dll = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll = C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll

HKCU\Control Panel\[email protected] = C:\WINDOWS\system32\logon.scr

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.google.it/ = http://www.google.it/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000002@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000003@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000004@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000005@PackedCatalogItem = C:\WINDOWS\system32\imon.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011@PackedCatalogItem = C:\WINDOWS\system32\imon.dll

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica = Avvio veloce di Adobe Reader.lnk

---- EOF - GMER 1.0.14 ----
e per finire vi allego l'immagine delle cartelle rosse di GMER ....
se riesco a rimpicciolire il file
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 12-06-2008, 16:09   #10
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
ecco le cartelle in rosso in allegato

scusate la qualità ma per infilarla ho dovuto ridurla all'osso

attendo info sul da farsi

grazie in anticipo
Immagini allegate
File Type: jpg castelle rosse GMER2.jpg (20.5 KB, 9 visite)
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 12-06-2008, 16:26   #11
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
Riedita cortesemente secondo le modalità di pubblicazione dei log
Se i log o le immagini (.JPG) non superano i 24Kb allegali tramite il comodo comando Gestisci allegati nelle Opzioni aggiuntive.
Clicca su Gestisci allegati → si aprirà una finestra → Click su Sfoglia → seleziona il file da caricare → Click su Carica → sotto allegati correnti vedrai il tuo log caricato → Chiudi la finestra
Altrimenti caricali su [wikisend.com] o su [mediafire.com].
Una volta sul sito → clicca su sfoglia → seleziona il file da caricare → poi invia o upload → aspetta che venga caricato → copia tutto il contenuto a fianco della della riga "Forum link nel primo caso oppure sotto "Sharing URL" nel secondo e lo incolli nella risposta della discussione.
Le immagini più grosse salvale in JPG, essendo più leggere, e caricale su fileqube.com che permette di visualizzarle direttamente online.
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 12-06-2008, 17:04   #12
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
scusa ma l'ignoranza abbonda

link al download del log di Gmer inerente i Rootkit

http://wikisend.com/download/908710/...alwareGMER.txt

e allego il log di Gmer Autostart
Allegati
File Type: txt GmerLogAutostart.txt (8.3 KB, 1 visite)
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 12-06-2008, 17:26   #13
xcdegasp
Senior Member
 
L'Avatar di xcdegasp
 
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
rieseguiun log con sysinspectator e hijackthis pubblicandoli sempre tramite link per il download è così più comodo visionarli
xcdegasp è offline   Rispondi citando il messaggio o parte di esso
Old 13-06-2008, 09:42   #14
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
allora eccoci qua ora vi mettèro i link come dice xcdegasp

premetto che vi stò scrivendo da un thinClient collegato a uno schermo CRT di 10 anni fà penso sia un 13" , al massimo 14" la schermata è tutta deformata ..... ma questo rende il " mio " tentativo di disinfestare l'altro pc quasi " epico "

1) sysinspectator http://wikisend.com/download/522264/...80613-0948.xml

2) hijackthis http://wikisend.com/download/225048/hijackthis.log

sono pronto per la battaglia
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 13-06-2008, 17:23   #15
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
l'ho TERMINATO !!!

ma tra i vari programmi quello che mi ha " aperto gli occhi " è stato

Spybot - Search & Destroy ed ora vi allego che cosa si era infiltrato

http://wikisend.com/download/542228/trojan.jpg

http://wikisend.com/download/618958/voce registro non eliminabile.jpg

spero di esservi stato utile come cavia

grazie a tutti per l'interessamento
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 13-06-2008, 22:00   #16
xcdegasp
Senior Member
 
L'Avatar di xcdegasp
 
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
ottimo ti ha rimosso
Codice:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe@Debugger = "c:\windows\system32\ejvcveef.gif"


ad ogni modo vai al link http://secunia.com/software_inspector/ e scansiona online il tuo, al termine ti notificherà tutti i programmi critici che sono obsoleti.
nel caso della java ricordati poi di disinstallare quella attuale, per quanto riguarda acrobat reader valuta la possibilità di sostituirlo con il più veloce, leggero e performante FoxitReader

Ultima modifica di xcdegasp : 13-06-2008 alle 22:05.
xcdegasp è offline   Rispondi citando il messaggio o parte di esso
Old 14-06-2008, 09:50   #17
LuCaP78
Senior Member
 
L'Avatar di LuCaP78
 
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
Grazie xcdegasp

avevo tutto un pò vecchiotto

certo che se non ci fosse sto forum ....

grazie mille ancora , non si finisce mai di imparare

ora il PC che ho in ufficio dimostra 5 anni in meno
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT "

PIG FOREVER
LuCaP78 è offline   Rispondi citando il messaggio o parte di esso
Old 14-06-2008, 10:08   #18
wjmat
Senior Member
 
L'Avatar di wjmat
 
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
Dai un'occhiata al trattamento di prevenzione / post disinfezione, ti aiuta a verificare la configurazione di sicurezza del tuo pc, aggiornare programmi vulnerabili obsoleti ed eliminare eventuali residui inutili dei programmi utilizzati nelle guide.

In particolare IE va aggiornato quanto prima alla 7
wjmat è offline   Rispondi citando il messaggio o parte di esso
Old 14-06-2008, 23:21   #19
xcdegasp
Senior Member
 
L'Avatar di xcdegasp
 
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
benissimo
xcdegasp è offline   Rispondi citando il messaggio o parte di esso
 Rispondi


iPhone 18 Pro: la recensione del miglior iPhone compatto di sempre iPhone 18 Pro: la recensione del miglior iPhone ...
Panasonic, 30 anni di Toughbook: la "Bibbia" di mille regole dietro i nuovi G3 e 34 Panasonic, 30 anni di Toughbook: la "Bibbia...
realme C100x, lo smartphone economico con la batteria da 7500 mAh. La recensione realme C100x, lo smartphone economico con la bat...
Star Wars Zero Company è l'erede di XCOM 2 Star Wars Zero Company è l'erede di XCOM ...
Test ride Can-Am Origin: la moto elettrica che fa dimenticare il motore a scoppio (ma occhio all'autonomia) Test ride Can-Am Origin: la moto elettrica che f...
ECOVACS T90S PRO OMNI Care Kit a 699€: 4...
iPhone Duo, i problemi di produzione con...
Lenovo e FIFA, il bilancio dei Mondiali ...
La Terra vista dalla Stazione Spaziale: ...
L'IA cinese ti spiega come produrre armi...
Nuova Fire TV Stick 4K e Telecomando Fir...
Addio Visa e Mastercard? L'Europa prepar...
Allarme IA in Florida: lo stato invoca i...
Tutte le Offerte Prime anticipate: robot...
Procura di Sassari e Oxygen Forensics: i...
Duo-Man trasforma iPhone Duo in un Walkm...
Questa carta da parati produce elettrici...
Perseverance scopre su Marte rocce mai o...
Batterie allo stato solido, Gotion alza ...
Caviar presenta la Black Edition di iPho...
Chromium
GPU-Z
OCCT
LibreOffice Portable
Opera One Portable
Opera One 106
CCleaner Portable
CCleaner Standard
Cpu-Z
Driver NVIDIA GeForce 546.65 WHQL
SmartFTP
Trillian
Google Chrome Portable
Google Chrome 120
VirtualBox
Tutti gli articoli Tutte le news Tutti i download

Strumenti

Regole
Non Puoi aprire nuove discussioni
Non Puoi rispondere ai messaggi
Non Puoi allegare file
Non Puoi modificare i tuoi messaggi

Il codice vB è On
Le Faccine sono On
Il codice [IMG] è On
Il codice HTML è Off
Vai al Forum


Tutti gli orari sono GMT +1. Ora sono le: 22:20.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
Served by www3v