il log di systemscan. piu in basso trovate anche avenger, che non ha potuto cancellare quei file, in quanto NON esistenti!!
SystemScan -
http://www.suspectfile.com - ver. 3.2.0
Running on: Windows XP PROFESSIONAL Edition, Service Pack 2 (2600.5.1)
System directory: C:\WINDOWS
Date: 02/09/2007
Time: 13.43.27
Output limited to:
-Recent files
===================== Recent files (60 days old)=====================
----- recent files in C:\
18/07/2007 23.45.18 (DIR) 0 byte 46 days old -- System Volume Information
01/08/2007 13.36.46 (DIR) 0 byte 32 days old -- btinbox
02/08/2007 20.02.38 1609801728 byte 31 days old -- pagefile.sys
26/08/2007 13.48.19 211 byte 7 days old -- boot.ini
01/09/2007 01.43.13 (DIR) 0 byte 1 days old -- WINDOWS
02/09/2007 12.09.15 (DIR) 0 byte 0 days old -- Programmi
02/09/2007 13.16.57 (DIR)1073270784 byte 0 days old -- hiberfil.sys
02/09/2007 13.29.25 126976 byte 0 days old -- zip.exe
02/09/2007 13.29.25 (DIR) 0 byte 0 days old -- Avenger
02/09/2007 13.29.25 1080 byte 0 days old -- jsuytewd.bat
02/09/2007 13.43.27 (DIR) 0 byte 0 days old -- suspectfile
----- recent files in C:\WINDOWS\
09/07/2007 22.53.42 (DIR) 0 byte 55 days old -- Help
13/07/2007 00.00.32 1109 byte 51 days old -- CDWSEAT.INI
15/07/2007 19.43.36 54 byte 49 days old -- JascCmdFile.INI
19/07/2007 15.02.33 (DIR) 0 byte 45 days old -- Fonts
01/08/2007 13.22.01 (DIR) 0 byte 32 days old -- BTFXTEMP
01/08/2007 13.24.34 (DIR) 0 byte 32 days old -- security
03/08/2007 14.34.16 (DIR) 0 byte 30 days old -- Downloaded Program Files
14/08/2007 00.37.02 0 byte 19 days old -- Sti_Trace.log
18/08/2007 11.58.49 (DIR) 0 byte 15 days old -- inf
19/08/2007 13.05.51 (DIR) 0 byte 14 days old -- Installer
26/08/2007 13.48.19 258 byte 7 days old -- system.ini
31/08/2007 21.27.34 805 byte 2 days old -- win.ini
31/08/2007 21.38.47 74752 byte 2 days old -- ST6UNST.EXE
31/08/2007 21.38.48 253952 byte 2 days old -- Setup1.exe
01/09/2007 01.43.13 54156 byte 1 days old -- QTFont.qfn
01/09/2007 01.43.13 1409 byte 1 days old -- QTFont.for
01/09/2007 13.40.20 32428 byte 1 days old -- SchedLgU.Txt
02/09/2007 11.57.34 116 byte 0 days old -- NeroDigital.ini
02/09/2007 13.06.04 155 byte 0 days old -- winamp.ini
02/09/2007 13.07.11 1778 byte 0 days old -- ModemLog_Windigo Bluetooth DUN Modem.txt
02/09/2007 13.07.33 3649 byte 0 days old -- mozver.dat
02/09/2007 13.17.03 2048 byte 0 days old -- bootstat.dat
02/09/2007 13.17.07 (DIR) 0 byte 0 days old -- Temp
02/09/2007 13.17.10 159 byte 0 days old -- wiadebug.log
02/09/2007 13.17.10 50 byte 0 days old -- wiaservc.log
02/09/2007 13.17.11 0 byte 0 days old -- 0.log
02/09/2007 13.18.40 (DIR) 0 byte 0 days old -- Internet Logs
02/09/2007 13.29.25 (DIR) 0 byte 0 days old -- system32
02/09/2007 13.32.00 11052 byte 0 days old -- WindowsUpdate.log
02/09/2007 13.39.26 (DIR) 0 byte 0 days old -- Prefetch
----- recent files in C:\WINDOWS\Downloaded Program Files\
----- recent files in C:\WINDOWS\system\
----- recent files in C:\WINDOWS\system32\
09/07/2007 22.54.16 (DIR) 0 byte 55 days old -- CatRoot
18/07/2007 23.45.18 (DIR) 0 byte 46 days old -- Restore
20/07/2007 20.31.11 216064 byte 44 days old -- FNTCACHE.DAT
03/08/2007 14.34.07 (DIR) 0 byte 30 days old -- Macromed
24/08/2007 15.30.52 (DIR) 0 byte 9 days old -- dllcache
24/08/2007 15.31.12 62286 byte 9 days old -- perfc009.dat
24/08/2007 15.31.12 994406 byte 9 days old -- PerfStringBackup.INI
24/08/2007 15.31.13 447046 byte 9 days old -- perfh010.dat
24/08/2007 15.31.13 400624 byte 9 days old -- perfh009.dat
24/08/2007 15.31.13 74296 byte 9 days old -- perfc010.dat
28/08/2007 11.00.45 2206 byte 5 days old -- wpa.dbl
29/08/2007 14.08.59 (DIR) 0 byte 4 days old -- CatRoot2
02/09/2007 13.17.13 54112 byte 0 days old -- vsconfig.xml
02/09/2007 13.29.25 (DIR) 0 byte 0 days old -- drivers
02/09/2007 13.29.25 152 byte 0 days old -- sbqcqswa.txt
----- recent files in C:\WINDOWS\system32\drivers\
01/09/2007 13.40.22 206480 byte 1 days old -- fidbox2.idx
01/09/2007 13.40.22 818276 byte 1 days old -- fidbox.idx
02/09/2007 13.14.57 60331296 byte 0 days old -- fidbox.dat
02/09/2007 13.15.17 2073376 byte 0 days old -- fidbox2.dat
02/09/2007 13.29.25 60416 byte 0 days old -- mvuqlumg.sys
----- recent files in C:\WINDOWS\temp\
28/08/2007 11.00.46 16384 byte 5 days old -- ~DFF2F.tmp
28/08/2007 19.10.04 16384 byte 5 days old -- ~DF1A3D.tmp
29/08/2007 12.35.48 16384 byte 4 days old -- ~DF1840.tmp
29/08/2007 19.45.05 16384 byte 4 days old -- ~DF1740.tmp
29/08/2007 22.18.59 16384 byte 4 days old -- ~DF18F4.tmp
30/08/2007 12.11.34 16384 byte 3 days old -- ~DF14EC.tmp
30/08/2007 20.30.18 16384 byte 3 days old -- ~DF1AAA.tmp
31/08/2007 11.45.16 16384 byte 2 days old -- ~DF1CA0.tmp
31/08/2007 19.56.29 16384 byte 2 days old -- ~DF1949.tmp
31/08/2007 19.56.31 256 byte 2 days old -- ZLT02577.TMP
31/08/2007 19.56.31 256 byte 2 days old -- ZLT01b96.TMP
31/08/2007 20.17.01 16384 byte 2 days old -- ~DF153A.tmp
01/09/2007 01.34.30 16384 byte 1 days old -- ~DF18A4.tmp
01/09/2007 11.04.51 16384 byte 1 days old -- ~DF194B.tmp
01/09/2007 11.04.53 256 byte 1 days old -- ZLT05a83.TMP
01/09/2007 11.04.53 256 byte 1 days old -- ZLT05cb4.TMP
01/09/2007 13.06.00 16384 byte 1 days old -- ~DF18A5.tmp
02/09/2007 11.15.44 16384 byte 0 days old -- ~DF1754.tmp
02/09/2007 11.15.46 256 byte 0 days old -- ZLT0332a.TMP
02/09/2007 11.15.46 256 byte 0 days old -- ZLT03680.TMP
02/09/2007 13.17.04 16384 byte 0 days old -- ~DF180A.tmp
02/09/2007 13.17.06 256 byte 0 days old -- ZLT01008.TMP
02/09/2007 13.17.07 256 byte 0 days old -- ZLT0100b.TMP
----- recent files in C:\Programmi\
10/07/2007 22.13.49 (DIR) 0 byte 54 days old -- Kaspersky Lab
13/07/2007 09.39.10 (DIR) 0 byte 51 days old -- Last.fm
13/07/2007 19.11.55 (DIR) 0 byte 51 days old -- Drive Rescue
14/07/2007 13.43.05 (DIR) 0 byte 50 days old -- pcc
14/07/2007 14.37.52 (DIR) 0 byte 50 days old -- Microsoft ActiveSync
15/07/2007 14.07.15 (DIR) 0 byte 49 days old -- PPC
19/07/2007 15.01.11 (DIR) 0 byte 45 days old -- Common Files
19/07/2007 15.01.11 (DIR) 0 byte 45 days old -- Xara
29/07/2007 15.22.14 (DIR) 0 byte 35 days old -- AWS
29/07/2007 15.22.50 (DIR) 0 byte 35 days old -- GameSpy Arcade
01/08/2007 13.23.29 (DIR) 0 byte 32 days old -- XTNDConnect Blue Manager
03/08/2007 12.58.22 (DIR) 0 byte 30 days old -- InstallShield Installation Information
03/08/2007 12.58.23 (DIR) 0 byte 30 days old -- Nokia
07/08/2007 21.12.19 (DIR) 0 byte 26 days old -- Winamp
10/08/2007 11.29.48 (DIR) 0 byte 23 days old -- Spybot - Search & Destroy
10/08/2007 21.01.14 (DIR) 0 byte 23 days old -- MSN Messenger
11/08/2007 14.33.53 (DIR) 0 byte 22 days old -- Raxco
18/08/2007 13.31.46 (DIR) 0 byte 15 days old -- SpeedFan
24/08/2007 15.30.45 (DIR) 0 byte 9 days old -- IDoser v4
30/08/2007 13.23.11 (DIR) 0 byte 3 days old -- Opera
30/08/2007 13.27.51 (DIR) 0 byte 3 days old -- Unlocker
31/08/2007 21.41.04 (DIR) 0 byte 2 days old -- Multi_Media_Italy
31/08/2007 21.42.19 (DIR) 0 byte 2 days old -- Spyware Terminator
01/09/2007 11.52.53 (DIR) 0 byte 1 days old -- Jacksms
02/09/2007 13.18.01 (DIR) 0 byte 0 days old -- Mozilla Thunderbird
02/09/2007 13.25.46 (DIR) 0 byte 0 days old -- FlashGet
----- recent files in C:\Programmi\File comuni\
10/07/2007 23.02.20 (DIR) 0 byte 54 days old -- Microsoft Shared
----- recent files in C:\Documents and Settings\Administrator\Dati applicazioni\
26/07/2007 17.06.05 (DIR) 0 byte 38 days old -- Skype
01/08/2007 13.30.10 (DIR) 0 byte 32 days old -- XTND_BTUIObjects
----- recent files in C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\
28/08/2007 19.11.47 156174 byte 5 days old -- TFR1.tmp
28/08/2007 19.11.48 55262 byte 5 days old -- TFR2.tmp
28/08/2007 19.11.48 107070 byte 5 days old -- TFR6.tmp
28/08/2007 19.11.48 22168 byte 5 days old -- TFR9.tmp
29/08/2007 12.37.10 163840 byte 4 days old -- ~DF93B2.tmp
29/08/2007 15.15.36 16384 byte 4 days old -- E5.tmp
29/08/2007 15.17.31 16384 byte 4 days old -- E6.tmp
29/08/2007 15.17.39 16384 byte 4 days old -- E7.tmp
29/08/2007 15.18.09 0 byte 4 days old -- TWAIN.LOG
29/08/2007 20.28.42 156174 byte 4 days old -- TFRA5.tmp
29/08/2007 20.28.42 107070 byte 4 days old -- TFRAA.tmp
29/08/2007 20.28.42 22168 byte 4 days old -- TFRAF.tmp
29/08/2007 20.28.42 55262 byte 4 days old -- TFRA6.tmp
29/08/2007 20.28.42 155781 byte 4 days old -- TFRA8.tmp
30/08/2007 20.59.33 163840 byte 3 days old -- ~DF481D.tmp
31/08/2007 20.04.55 0 byte 2 days old -- 07u14.tmp
31/08/2007 20.06.17 0 byte 2 days old -- ot218.tmp
31/08/2007 21.38.15 (DIR) 0 byte 2 days old -- CTJBNS
31/08/2007 21.38.31 56320 byte 2 days old -- ginst0.dll
01/09/2007 01.51.31 (DIR) 0 byte 1 days old -- File temporanei
01/09/2007 01.51.32 2 byte 1 days old -- Twain001.Mtx
01/09/2007 12.53.42 (DIR) 0 byte 1 days old -- hsperfdata_Administrator
01/09/2007 12.53.44 0 byte 1 days old -- sfe16A.tmp
02/09/2007 13.07.06 0 byte 0 days old -- jdf1B5.tmp
02/09/2007 13.07.07 0 byte 0 days old -- aug1B6.tmp
02/09/2007 13.07.33 0 byte 0 days old -- o761BF.tmp
02/09/2007 13.09.14 0 byte 0 days old -- 7rx1C1.tmp
02/09/2007 13.09.14 74 byte 0 days old -- 7rx1C1.htm
02/09/2007 13.09.17 0 byte 0 days old -- t0z1C5.tmp
02/09/2007 13.11.55 74 byte 0 days old -- x0920D.htm
02/09/2007 13.11.55 0 byte 0 days old -- x0920D.tmp
02/09/2007 13.22.45 4916 byte 0 days old -- WcesView.log
02/09/2007 13.22.48 69722 byte 0 days old -- WCESMgr.log
02/09/2007 13.22.49 26406 byte 0 days old -- WCESLog.log
02/09/2007 13.38.30 16384 byte 0 days old -- ~DF84E4.tmp
02/09/2007 13.39.26 (DIR) 0 byte 0 days old -- nsz38.tmp
02/09/2007 13.42.01 (DIR) 0 byte 0 days old -- MessengerCache
02/09/2007 13.42.33 6892 byte 0 days old -- WCESCOMM.LOG
02/09/2007 13.43.13 234 byte 0 days old -- dw.log
e avenger
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\rwjhjmev
*******************
Script file located at: \??\C:\WINDOWS\system32\sbqcqswa.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:/DOCUME~1/ADMINI~1/IMPOST~1/Temp/Rar$EX00.282/???.exe> not found!
Deletion of file C:/DOCUME~1/ADMINI~1/IMPOST~1/Temp/Rar$EX00.282/???.exe> failed!
Could not process line:
C:/DOCUME~1/ADMINI~1/IMPOST~1/Temp/Rar$EX00.282/???.exe>
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.