Fatto.
############################## | FindyKill V5.043 |
# User : Michele (Administrators) # XXX-0DEBD40D8BC
# Update on 12/05/2010 by El Desaparecido
# Start at: 21.24.49 | 01/06/2010
# Website :
http://pagesperso-orange.fr/NosTools/index.html# Contact :
FindyKill.Contact@gmail.com# Processore Intel Celeron
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# A:\ # Disco floppy, 3,5 pollici
# C:\ # Disco rigido locale # 14,32 Go (4,28 Go free) # NTFS
# D:\ # Disco rigido locale # 4,76 Go (3,82 Go free) # FAT32
# E:\ # Disco CD-ROM
# F:\ # Disco CD-ROM
# H:\ # Disco rimovibile # 7,46 Go (350,88 Mo free) [USB DISK] # FAT32
################## | Infected File |
Deleted ! C:\WINDOWS\ban_list.txt
Deleted ! C:\WINDOWS\mdelk.exe
Deleted ! C:\WINDOWS\wintems.exe
Deleted ! C:\WINDOWS\system32\srosa2.sys
Deleted ! C:\WINDOWS\system32\wfsintwq.sys
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\drivers\downld
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\drivers\winupgro.exe
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\drivers
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\downloads.bak
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\downloads.txt
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\AC_BootstrapIPs.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\AC_SearchStrings.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\AC_ServerMetURLs.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\cancelled.met
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\clients.met
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\clients.met.bak
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\cryptkey.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\emfriends.met
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\key_index.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\known.met
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\known2_64.met
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\load_index.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\nodes.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\preferences.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\preferences.ini
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\preferencesKad.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\server.met
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\server_met.old
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\shareddir.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\src_index.dat
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\statistics.ini
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config\StoredSearches.met
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\config
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\file.exe
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\flec003.exe
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\flec005.exe
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\Incoming
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\lang
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\names.txt
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\server.txt
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\skins
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\Temp
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\WDIR
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires\webserver
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\hidires
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\m\data.oct
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\m\flec006.exe
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\m\list.oct
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\m\shared
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\m\srvlist.oct
Deleted ! C:\Documents and Settings\Michele\Dati applicazioni\m
################## | Reference of comparaison Bagle MD5 : |
File : C:\Documents and Settings\Michele\Dati applicazioni\drivers\winupgro.exe
-> Crc32 : be0a8c83 | Md5 : 8d38731ae954896cb40d1823a3cf44a2
################## | MD5 ... |
################## | CRC32 ... |
################## | Registry |
Deleted ! [HKLM\SYSTEM\ControlSet002\Services\srosa]
Deleted ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Deleted ! [HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
Deleted ! [HKCU\Software\bisoft]
Deleted ! [HKCU\Software\DateTime4]
Deleted ! [HKCU\Software\MuleAppData]
Deleted ! [HKCU\Software\WS4001]
Deleted ! [HKCR\ed2k]
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "flec003.exe"
Deleted ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
################## | State |
# Safe boot mode restored !
# Showing of hidden files : OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )
################## | Corrupted Files |
Corrupted : C:\Programmi\Mozilla Firefox\uninstall\helper.exe
[Offset = 000000E4 - Value = 0x0001]
Corrupted : C:\RECYCLER\S-1-5-21-1757981266-1060284298-1202660629-1003\Dc3.exe
[Offset = 00000204 - Value = 0x0001]
Corrupted : C:\RECYCLER\S-1-5-21-1757981266-1060284298-1202660629-1003\Dc5.exe
[Offset = 000000EC - Value = 0x0001]
Corrupted : C:\WINDOWS\$hf_mig$\KB898461\update\update.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB915865\update\update.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB923561\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB925720\update\update.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB938127-v2-IE7\update\update.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB946648\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB950762\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB961118\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB978037\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\$hf_mig$\KB978542\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\SoftwareDistribution\Download\0c26e47e07a4c6331f0b4ccdac130608\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\SoftwareDistribution\Download\5d489f496e4e9f3aa0ab2184f06a9537\update\update.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\SoftwareDistribution\Download\77e8dbcf65004c9a12c04290c88df4c5\update\update.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\SoftwareDistribution\Download\be9e26e54f7a2d73396715001d0e1e17\update\update.exe
[Offset = 000000EC - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000EC - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\SoftwareDistribution\Download\e10c6cff30da6e8f03631d1b72af3dba\update\update.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : update.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
Corrupted : C:\WINDOWS\system32\dllcache\register.exe
[Offset = 000000E4 - Value = 0x0001]
Attempt of repair...
Backup : register.exe.REN
[Offset = 000000E4 - New value = 0x4C01]
File repaired successfully.
################## | Upload |
Please send the file : C:\FindyKill_Upload_Me_XXX-0DEBD40D8BC.zip :
http://chiquitine.changelog.fr/Sample/Upload.php Thank you for your contribution .
################## | End of Report # FindyKill V5.043 ! |