ciao ragazzi.. ho appena finito di fare in modalità provvisoria la pulizia e subito dopo sono tornato in modalità normale.. questo è il log:
SDFix: Version 1.207 Run by Sly on 23/07/2008 at 09.16
Microsoft Windows XP [Versione 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default Desktop Wallpaper
Restoring Default ScreenSaver value
Restoring Default Schedule Service Path
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\SYSTEM32\PHCP4A~1.BMP - Deleted
C:\WINDOWS\SYSTEM32\BLPHCP~1.SCR - Deleted
C:\Documents and Settings\LocalService\svchost.exe - Deleted
C:\Documents and Settings\Sly\Menu Avvio\Programmi\Esecuzione automatica\userinit.exe - Deleted
C:\Documents and Settings\Sly\svchost.exe - Deleted
C:\WINDOWS\system32\drivers\services.exe - Deleted
C:\WINDOWS\system32\ntos.exe - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll.cla - Deleted
C:\WINDOWS\system32\wsnpoem\video.dll - Deleted
C:\Documents and Settings\LocalService\Dati applicazioni\wsnpoem\audio.dll - Deleted
C:\Documents and Settings\NetworkService\Dati applicazioni\wsnpoem\audio.dll - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-23 09:24:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\000ee7601210]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000ee7601210]
"001d6eaac61b"=hex:e2,aa,08,42,5b,9f,1f,0a,db,45,ef,ba,ce,1d,f0,f2
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000ee7601210]
"001d6eaac61b"=hex:e2,aa,08,42,5b,9f,1f,0a,db,45,ef,ba,ce,1d,f0,f2
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\system32\\rasphone.exe"="C:\\WINDOWS\\system32\\rasphone.exe:*:Disabled:rasphone"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Programmi\\Outlook Express\\msimn.exe"="C:\\Programmi\\Outlook Express\\msimn.exe:*:Enabled:Outlook Express"
"C:\\Programmi\\File comuni\\Symantec Shared\\NMain.exe"="C:\\Programmi\\File comuni\\Symantec Shared\\NMain.exe:*:Enabled:NMain"
"C:\\Programmi\\iTunes\\iTunes.exe"="C:\\Programmi\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Programmi\\eMule\\emule.exe"="C:\\Programmi\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Programmi\\Kazaa\\kazaa.exe"="C:\\Programmi\\Kazaa\\kazaa.exe:*:Enabled:Kazaa Media Desktop"
"C:\\Programmi\\Messenger\\msmsgs.exe"="C:\\Programmi\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Programmi\\Yahoo!\\Messenger\\YServer.exe"="C:\\Programmi\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Programmi\\CyberLink\\PowerCinema\\PowerCinema.exe"="C:\\Programmi\\CyberLink\\PowerCinema\\PowerCinema.exe:*:Enabled:PowerCinema"
"C:\\Programmi\\File comuni\\Synacast\\SynaLive\\PE.exe"="C:\\Programmi\\File comuni\\Synacast\\SynaLive\\PE.exe:*:Enabled:SynacastPE"
"C:\\Programmi\\Sop Cast\\SopCast.exe"="C:\\Programmi\\Sop Cast\\SopCast.exe:*:Enabled:SoP Client"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Modulo di esecuzione DLL come applicazioni"
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"="C:\\Programmi\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Programmi\\MSN Messenger\\livecall.exe"="C:\\Programmi\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Programmi\\Grisoft\\AVG Free\\avginet.exe"="C:\\Programmi\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Programmi\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Programmi\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"="C:\\Programmi\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Programmi\\MSN Messenger\\livecall.exe"="C:\\Programmi\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 22 May 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 11 Dec 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 21 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\90a71d9643d3d7bd061e3a88ad5dd8b1\BIT3.tmp"
Thu 8 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\df3d775e7b42b8dc342b507906f4e30c\BIT3.tmp"
Finished!Ho notato che mi sono usciti di nuovo le linguette dei sfondi e dei screensaver quando clicco proprietà sul desktop, ora faccio anche la seconda operazione riguardante combofix? Se si sempre in modalità provvisoria?