Eccovi i tre log:
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\omnsojiv
*******************
Script file located at: \??\C:\japhmyra.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\System32\adsnwm.exe deleted successfully.
File C:\WINDOWS\System32\hldrrr.exe deleted successfully.
File C:\DOCUME~1\Nicola\DATIAP~1\BODYTY~1\waveblehlong.exe not found!
Deletion of file C:\DOCUME~1\Nicola\DATIAP~1\BODYTY~1\waveblehlong.exe failed!
Could not process line:
C:\DOCUME~1\Nicola\DATIAP~1\BODYTY~1\waveblehlong.exe
Status: 0xc0000034
Could not open file C:\Programmi\Logitech\iTouch\bak\iTouch.exe for move operation
File move operation C:\Programmi\Logitech\iTouch\bak\iTouch.exe|C:\Programmi\Logitech\iTouch\iTouch.exe failed!
Could not process line:
C:\Programmi\Logitech\iTouch\bak\iTouch.exe|C:\Programmi\Logitech\iTouch\iTouch.exe
Status: 0xc000003a
Could not open file C:\Programmi\Conexant\AccessRunner ADSL\bak\CnxDslTb.exe for move operation
File move operation C:\Programmi\Conexant\AccessRunner ADSL\bak\CnxDslTb.exe|C:\Programmi\Conexant\AccessRunner ADSL\CnxDslTb.exe failed!
Could not process line:
C:\Programmi\Conexant\AccessRunner ADSL\bak\CnxDslTb.exe|C:\Programmi\Conexant\AccessRunner ADSL\CnxDslTb.exe
Status: 0xc000003a
Could not open file C:\Programmi\Nokia\Nokia PC Suite 6\bak\LAUNCH~1.EXE for move operation
File move operation C:\Programmi\Nokia\Nokia PC Suite 6\bak\LAUNCH~1.EXE|C:\Programmi\Nokia\Nokia PC Suite 6\LAUNCH~1.EXE failed!
Could not process line:
C:\Programmi\Nokia\Nokia PC Suite 6\bak\LAUNCH~1.EXE|C:\Programmi\Nokia\Nokia PC Suite 6\LAUNCH~1.EXE
Status: 0xc000003a
Could not open file C:\Programmi\Trust\WB-3500T USB2 Webcam\bak\SnapTrap.exe for move operation
File move operation C:\Programmi\Trust\WB-3500T USB2 Webcam\bak\SnapTrap.exe|C:\Programmi\Trust\WB-3500T USB2 Webcam\SnapTrap.exe failed!
Could not process line:
C:\Programmi\Trust\WB-3500T USB2 Webcam\bak\SnapTrap.exe|C:\Programmi\Trust\WB-3500T USB2 Webcam\SnapTrap.exe
Status: 0xc000003a
Could not open file C:\Programmi\Logitech\MouseWare\system\bak\EM_EXEC.EXE for move operation
File move operation C:\Programmi\Logitech\MouseWare\system\bak\EM_EXEC.EXE|C:\Programmi\Logitech\MouseWare\system\EM_EXEC.EXE failed!
Could not process line:
C:\Programmi\Logitech\MouseWare\system\bak\EM_EXEC.EXE|C:\Programmi\Logitech\MouseWare\system\EM_EXEC.EXE
Status: 0xc000003a
Could not delete registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|adsnwm
Deletion of registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|adsnwm failed!
Status: 0xc0000034
Could not delete registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Vcfastmathbags
Deletion of registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Vcfastmathbags failed!
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.
Sat Jun 16 18:01:09 2007
EliBagle v10.41 (c)2007 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Renombrado a .VIR
C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
C:\DOCUMENTS AND SETTINGS\NICOLA\DATI APPLICAZIONI\HIDIRES\HIDR.EXE --> Eliminado Bagle
C:\DOCUMENTS AND SETTINGS\NICOLA\DATI APPLICAZIONI\HIDIRES\M_HOOK.SYS --> Eliminado Bagle (rootkit)
Eliminada Carpeta "%WinDir%\exefld"
Restaurada Clave: "SafeBoot\Minimal y Network"
Sat Jun 16 18:01:42 2007
EliBagle v10.41 (c)2007 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
C:\Programmi\eMule\Incoming\MSN SPY MONITOR 2007 5(1).ZIP --> Eliminado Bagle.dldr
Sat Jun 16 18:04:45 2007
EliBagle v10.41 (c)2007 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
Eliminada Carpeta "%AppData%\Hidires"
Sat Jun 16 18:04:48 2007
EliBagle v10.41 (c)2007 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
Sat Jun 16 18:05:11 2007
EliBagle v10.41 (c)2007 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
Sat Jun 16 18:05:37 2007
EliBagle v10.41 (c)2007 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
Logfile of HijackThis v1.99.1
Scan saved at 18.06.53, on 16/06/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBNE.EXE
C:\WINDOWS\System32\mioengine.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\system32\notepad.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
c:\programmi\internet explorer\iexplore.exe
C:\Documents and Settings\Nicola\Desktop\Software\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Programmi\Conexant\AccessRunner ADSL\CnxDslTb.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [STICAP] C:\Programmi\Trust\WB-3500T USB2 Webcam\SnapTrap.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmi\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [ReEXEc] C:\Documents and Settings\Nicola\Desktop\EliBaglA.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [EPSON Stylus Photo R265 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBNE.EXE /FU "C:\WINDOWS\TEMP\E_S83.tmp" /EF "HKCU"
O4 - Startup: My Vodafone.it.lnk = C:\Documents and Settings\Nicola\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Tasto di scelta rapida per l'avvio di AutoCAD.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O15 - Trusted Zone: *.whataboutadog.com
O15 - Trusted Zone: *.whataboutarabit.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/english/ka ... nicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 3208608764
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) -
http://appdirectory.messenger.msn.com/A ... gWXMSN.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F5B0C06-FF04-43A7-88D6-301CEF936A45}: NameServer = 213.205.36.70 213.205.32.70
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe