PDA

View Full Version : WIN32/nsanti removal



gynos
2008-02-22, 09:50
Hi

It seems I've got this virus on my pc

When I try to open a disk (internal or one of external hard drives) in My Computer window, AVG 7.5 notifies about the Win32.NSAnti virus.
I cannot unhide my hidden files and folders.

I've read previous thread on the topic but nothing helps, I need help to read my kaspersky and HJT log reports.

I'am not posting the kaspersky log report because it is too long


Logfile of HijackThis v1.99.1
Scan saved at 9.35.33, on 22/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\ATKOSD2\ATKOSD2.exe
C:\Programmi\ATK Hotkey\Hcontrol.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\ASUS\ATK Media\DMEDIA.EXE
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\ASUS\Splendid\ACMON.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Programmi\ATK Hotkey\ATKOSD.exe
C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe
C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programmi\Wireless Console 2\wcourier.exe
C:\WINDOWS\system32\ASUSTPE.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\WINDOWS\ASScrPro.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Programmi\Atheros\ACU.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmi\ATK Hotkey\KBFiltr.exe
C:\Programmi\Notebook Hardware Control\nhc.exe
C:\Programmi\ATK Hotkey\WDC.exe
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vsnpstd.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\WINDOWS\system32\svchost.exe
c:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe
c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\mioengine.exe
c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\Skype\Plugin Manager\skypePM.exe
C:\Programmi\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
D:\SETUP\FIREFO~1.WIN\FIREFOX\FIREFOX.EXE
C:\HJT\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eluniversal.com/index.shtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=69204
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programmi\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ATKOSD2] "C:\Programmi\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [ATKHOTKEY] "C:\Programmi\ATK Hotkey\Hcontrol.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATKMEDIA] C:\Programmi\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ACMON] "C:\Programmi\ASUS\Splendid\ACMON.exe"
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Programmi\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [ASUSTPE] C:\WINDOWS\system32\ASUSTPE.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\ASScrPro.exe
O4 - HKLM\..\Run: [ACU] C:\Programmi\Atheros\ACU.exe -nogui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Programmi\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [SMSTray] C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [MultiFrame] C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - Startup: CCC.lnk = ?
O4 - Startup: My Vodafone.it.lnk = C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\programmi\bonjour\mdnsnsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://gyanos.spaces.live.com/PhotoUpload/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Servizio di configurazione Atheros (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe

Could anyone help me??? thks

Blade81
2008-02-23, 18:07
Do you use usb flash memory stick? Please have it inserted so it will cleaned too.

1. Download this file -
combofix.exe (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your desktop.
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your
next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause
it to stall

gynos
2008-02-24, 12:21
Hi Thanks!

here's the combofix log



Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.1104 [GMT 1:00]


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Creati Da 2008-01-24 al 2008-02-24 )))))))))))))))))))))))))))))))))))
.

2008-02-23 11:54 . 2008-02-23 12:52 81,408 -r-hs---- C:\WINDOWS\system32\tavo0.dll
2008-02-23 10:03 . 2008-02-23 10:09 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Programmi\Malwarebytes' Anti-Malware
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Malwarebytes
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2008-02-22 01:47 . 2008-02-22 01:47 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-22 01:47 . 2008-02-22 01:47 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-02-22 01:34 . 2008-02-23 20:21 <DIR> d-------- C:\HJT
2008-02-22 01:11 . 2008-02-22 01:11 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Lavasoft
2008-02-22 01:10 . 2008-02-22 01:10 <DIR> d-------- C:\Programmi\Lavasoft
2008-02-21 23:21 . 2008-02-24 12:13 <DIR> d-------- C:\Documents and Settings\Gyanos\.housecall6.6
2008-02-21 22:46 . 2008-02-21 22:15 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-21 22:46 . 2008-02-21 22:46 2,546 --a------ C:\WINDOWS\unins000.dat
2008-02-21 22:12 . 2008-02-21 22:50 <DIR> d-------- C:\Programmi\Spybot - Search & Destroy
2008-02-21 22:12 . 2008-02-21 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-02-12 11:47 . 2008-02-13 11:29 <DIR> d-------- C:\CutePrinter
2008-02-12 11:47 . 2003-07-24 18:06 86,016 --a------ C:\WINDOWS\system32\cutemon2k.dll
2008-02-12 11:47 . 2003-06-01 15:24 40,960 --a------ C:\WINDOWS\system32\UnCutePP.exe
2008-02-11 19:19 . 2008-02-11 19:19 <DIR> d-------- C:\Programmi\File comuni\Adobe
2008-02-11 19:03 . 2008-02-11 19:03 <DIR> d-------- C:\Programmi\Windows Media Connect 2
2008-02-11 19:03 . 2006-10-04 15:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-02-11 19:03 . 2006-10-04 15:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-02-11 19:03 . 2006-03-02 14:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-02-11 19:03 . 2006-10-04 15:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-02-11 19:01 . 2008-02-11 19:01 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-11 19:01 . 2008-02-11 19:02 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-11 16:42 . 2008-02-11 16:42 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects
2008-02-11 16:42 . 2008-02-11 16:42 407,047 --a------ C:\WINDOWS\system32\mioengine.exe
2008-02-09 15:29 . 2008-02-09 15:29 <DIR> d-------- C:\Programmi\File comuni\xing shared
2008-02-09 15:28 . 2008-02-09 15:28 <DIR> d-------- C:\Programmi\Real
2008-02-09 15:28 . 2008-02-09 15:29 <DIR> d-------- C:\Programmi\File comuni\Real
2008-02-05 22:07 . 2008-02-24 11:56 <DIR> d-------- C:\Programmi\AdunanzA
2008-02-05 18:35 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-02-05 18:35 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-02-05 18:35 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-02-05 13:32 . 2008-02-05 13:32 268 --ah----- C:\sqmdata01.sqm
2008-02-05 13:32 . 2008-02-05 13:32 244 --ah----- C:\sqmnoopt01.sqm
2008-02-04 22:45 . 2008-02-04 22:45 268 --ah----- C:\sqmdata00.sqm
2008-02-04 22:45 . 2008-02-04 22:45 244 --ah----- C:\sqmnoopt00.sqm
2008-02-04 19:46 . 2008-02-05 18:46 <DIR> d-------- C:\Documents and Settings\Gyanos\Contacts
2008-02-04 19:31 . 2008-02-04 19:45 <DIR> d-------- C:\Programmi\Windows Live
2008-02-04 19:31 . 2008-02-04 19:45 <DIR> d--hsc--- C:\Programmi\File comuni\WindowsLiveInstaller
2008-02-04 19:31 . 2008-02-04 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\WLInstaller
2008-02-04 11:00 . 2002-10-16 09:18 372,736 --a------ C:\WINDOWS\system32\ISIIndexer.dll
2008-02-04 11:00 . 2002-03-06 18:56 196,608 --a------ C:\WINDOWS\system32\ISIXFiles.dll
2008-02-04 11:00 . 2008-02-17 11:20 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-02-02 15:42 . 2008-02-24 00:43 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-02 15:42 . 2008-02-02 15:42 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\iTunes
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\iPod
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\Bonjour
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Apple Computer
2008-02-02 15:40 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\QuickTime
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Programmi\File comuni\Apple
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Programmi\Apple Software Update
2008-02-02 15:40 . 2008-02-02 15:41 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Apple
2008-02-02 15:25 . 2008-02-02 15:38 <DIR> d-------- C:\Documents and Settings\Gyanos\.SunDownloadManager
2008-02-02 15:15 . 2008-02-02 15:19 <DIR> d-------- C:\j2sdk1.4.2_16
2008-02-02 15:07 . 2008-02-02 15:07 <DIR> d-------- C:\WINDOWS\Sun
2008-02-02 15:06 . 2008-02-02 15:27 <DIR> d-------- C:\Programmi\Java
2008-02-02 15:06 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-02 15:05 . 2008-02-02 15:05 <DIR> d-------- C:\Programmi\File comuni\Java
2008-02-02 14:45 . 2008-02-02 14:45 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Printer Info Cache
2008-02-02 14:45 . 2008-02-02 15:30 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Image Zone Express
2008-02-02 12:23 . 2008-02-02 12:23 <DIR> d-------- C:\Programmi\Microsoft ActiveSync
2008-02-02 12:23 . 2008-02-02 12:23 <DIR> d-------- C:\Programmi\File comuni\L&H
2008-02-02 12:05 . 2008-02-02 12:05 <DIR> d-------- C:\Programmi\TRADOS
2008-02-01 10:31 . 2008-02-01 10:31 <DIR> d-------- C:\Programmi\MSXML 4.0
2008-01-31 19:19 . 2008-01-31 19:19 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\DataCast
2008-01-31 19:19 . 2007-12-14 17:19 44,544 --------- C:\WINDOWS\system32\msxml4a.dll
2008-01-31 19:18 . 2007-08-23 21:06 110,592 --a------ C:\WINDOWS\system32\TG_DUMP0708.DLL
2008-01-31 18:34 . 2008-01-31 18:34 <DIR> d-------- C:\Programmi\MarkAny
2008-01-31 18:31 . 2008-01-31 18:31 <DIR> d-------- C:\Programmi\Samsung
2008-01-31 18:31 . 2006-03-16 08:26 397,429 --a------ C:\WINDOWS\system32\PixtreeMP4FormatWriter.ax
2008-01-31 18:31 . 2006-01-20 10:11 110,592 --a------ C:\WINDOWS\system32\tg_dump.dll
2008-01-31 18:02 . 2008-01-31 18:02 <DIR> d-------- C:\Programmi\Trust
2008-01-31 18:02 . 2008-01-31 18:02 <DIR> d-------- C:\Programmi\File comuni\snpstd
2008-01-31 18:02 . 2004-05-17 20:55 302,720 --a------ C:\WINDOWS\system32\drivers\snpstd.sys
2008-01-31 18:02 . 2004-05-10 17:37 286,720 --a------ C:\WINDOWS\vsnpstd.exe
2008-01-31 18:02 . 2004-02-16 13:59 61,440 --a------ C:\WINDOWS\system32\csnpstd.dll
2008-01-31 18:02 . 2004-05-04 20:30 53,248 --a------ C:\WINDOWS\system32\rsnpstd.dll
2008-01-31 18:02 . 2004-05-06 11:22 53,248 --a------ C:\WINDOWS\system32\dsnpstd.dll
2008-01-31 18:02 . 2002-07-03 11:44 53,248 --a------ C:\WINDOWS\amcap.exe
2008-01-31 18:02 . 2004-05-04 20:10 36,864 --a------ C:\WINDOWS\system32\vsnpstd.dll
2008-01-31 18:02 . 2004-05-04 20:07 36,864 --a------ C:\WINDOWS\system32\dsnpstd.ax
2008-01-31 18:02 . 2004-02-23 15:19 20,480 --a------ C:\WINDOWS\usnpstd.exe
2008-01-31 18:02 . 2003-01-17 17:34 15,541 --a------ C:\WINDOWS\snpstd.ini
2008-01-31 18:02 . 2003-01-17 17:35 13,023 --a------ C:\WINDOWS\snpstd.src
2008-01-31 17:12 . 2008-01-31 18:27 <DIR> d-------- C:\Programmi\C'č Posta
2008-01-31 16:18 . 2008-01-31 17:12 286,720 --a------ C:\WINDOWS\iun507.exe
2008-01-31 12:19 . 2008-01-31 12:41 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\HP
2008-01-31 12:18 . 2008-02-04 20:35 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\HPSSUPPLY
2008-01-31 12:16 . 2008-01-31 12:16 <DIR> d-------- C:\Programmi\Hewlett-Packard
2008-01-31 12:16 . 2008-01-31 12:18 <DIR> d-------- C:\Programmi\File comuni\HP
2008-01-31 12:16 . 2008-01-31 12:16 <DIR> d-------- C:\Programmi\File comuni\Hewlett-Packard
2008-01-31 12:16 . 2008-01-31 12:17 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\HP
2008-01-31 12:15 . 2008-01-31 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Hewlett-Packard
2008-01-31 12:15 . 2006-12-03 22:45 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-01-31 12:15 . 2006-12-03 22:45 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 11:02 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\Skype
2008-02-24 07:04 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\skypePM
2008-02-24 07:00 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\AVG7
2008-02-23 23:43 22,528 ----a-w C:\WINDOWS\system32\drivers\nhcDriver.sys
2008-02-04 10:00 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-02-01 09:00 --------- d-----w C:\Programmi\ASUS
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 16:19 40,960 ------w C:\WINDOWS\system32\MAMACExtract.dll
2007-12-07 00:45 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-07 00:45 668,672 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-12-07 00:45 619,008 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-12-07 00:45 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-12-07 00:45 474,624 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-12-07 00:45 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-12-07 00:45 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-12-07 00:45 3,087,360 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-07 00:45 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-12-07 00:45 1,499,648 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-12-07 00:44 96,768 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2007-12-07 00:44 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-12-07 00:44 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-07 00:44 251,904 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-12-07 00:44 205,824 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-12-07 00:44 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-12-07 00:44 151,552 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-12-07 00:44 1,056,256 ------w C:\WINDOWS\system32\dllcache\danim.dll
2007-12-07 00:44 1,024,000 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2007-12-06 10:05 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-04 18:40 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:40 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-12-02 10:34 155,995 ----a-w C:\WINDOWS\java\Packages\I975R5VN.ZIP
2007-11-28 21:34 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"StartCCC"="c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"MultiFrame"="C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe" [2007-06-21 14:07 999792]
"Skype"="C:\Programmi\Skype\Phone\Skype.exe" [2007-11-12 15:48 21760296]
"MsnMsgr"="C:\Programmi\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"SpybotSD TeaTimer"="C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="C:\Programmi\ATKOSD2\ATKOSD2.exe" [2007-07-03 10:48 7708672]
"ATKHOTKEY"="C:\Programmi\ATK Hotkey\Hcontrol.exe" [2007-07-12 10:25 225280]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 04:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
"ATKMEDIA"="C:\Programmi\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 08:27 61440]
"SynTPEnh"="C:\Programmi\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 05:02 786521]
"ACMON"="C:\Programmi\ASUS\Splendid\ACMON.exe" [2007-07-10 10:59 851968]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"RemoteControl"="C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40 155648]
"SMSERIAL"="C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 02:31 630784]
"PowerForPhone"="C:\Program Files\P4P\P4P.exe" [ ]
"Wireless Console 2"="C:\Programmi\Wireless Console 2\wcourier.exe" [2007-07-05 16:53 1040384]
"ASUSTPE"="C:\WINDOWS\system32\ASUSTPE.exe" [2007-01-16 16:13 106496]
"ASUS Camera ScreenSaver"="C:\WINDOWS\ASScrProlog.exe" [2007-10-29 14:43 37232]
"ASUS Screen Saver Protector"="C:\WINDOWS\ASScrPro.exe" [2007-10-29 14:44 33136]
"ACU"="C:\Programmi\Atheros\ACU.exe" [2007-05-03 17:42 376921]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-30 11:44 579072]
"NotebookHardwareControl"="C:\Programmi\Notebook Hardware Control\nhc.exe" [2007-05-04 01:33 2629632]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-05-10 17:37 286720]
"SMSTray"="C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 08:23 132624]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Programmi\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Programmi\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2008-02-09 15:28 185896]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-02 13:10 219136]

C:\Documents and Settings\Gyanos\Menu Avvio\Programmi\Esecuzione automatica\
CCC.lnk - C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-09-29 09:57:36 49152]
My Vodafone.it.lnk - C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio [2008-02-11 16:42:35 103615]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - C:\Programmi\Alice ti aiuta\bin\matcli.exe [2007-12-02 12:14:43 212992]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Programmi\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgw.exe"=
"C:\\Programmi\\FastWeb Login\\FastLogin.exe"=
"C:\\Programmi\\C'č Posta\\CPosta.exe"=
"C:\\Programmi\\ASUS\\ASUS Live Update\\ALU.exe"=
"C:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"C:\\Programmi\\iTunes\\iTunes.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"C:\\Programmi\\Real\\RealPlayer\\realplay.exe"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=

R2 ghaio;ghaio;C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-02 21:26]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-08-21 01:50]
R3 RTSTOR;USB Mass Stroage Device;C:\WINDOWS\system32\drivers\RTSTOR.SYS [2006-06-10 00:07]
R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-03-28 19:52]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\A5AGU.sys [2004-10-06 10:39]
S3 ATHFMWDL;D-Link predator Bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-04 06:28]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 usbstor;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-03-02 14:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{49d1b7f8-9d2c-11dc-ad13-001d60ddc7a4}]
\Shell\AutoRun\command - gqsk.bat
\Shell\explore\Command - gqsk.bat
\Shell\open\Command - gqsk.bat


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {857D4360-762B-978B-76AD-491AA719E47A} /qb
.
Contenuto della cartella 'Scheduled Tasks'
"2008-02-18 19:00:00 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Gyanos.job"
- c:\Programmi\Norton Internet Security\Norton AntiVirus\Navw32.exei/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 12:15:29
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Programmi\ASUS\Asus MultiFrame\HookTitle.dll
.
Ora fine scansione: 2008-02-24 12:15:55
ComboFix-quarantined-files.txt 2008-02-24 11:15:53
ComboFix2.txt 2008-02-23 19:17:13
ComboFix3.txt 2008-02-23 12:04:19
ComboFix4.txt 2008-02-23 11:50:37
ComboFix5.txt 2008-02-23 09:59:43
.
2008-02-13 12:34:01 --- E O F ---

Blade81
2008-02-24, 17:47
Hi


Disable Spybot's TeaTimer
Run Spybot-S&D in Advanced Mode
If it is not already set to do this, go to the Mode menu
select
Advanced Mode

On the left hand side, click on Tools
Then click on the Resident icon in the list
Uncheck
Resident TeaTimer
and OK any prompts.
Restart your computer


Start hjt, do a system scan, check (if found):
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

Close browsers and other windows. Click fix checked.

Open notepad and copy/paste the text in the quotebox below into it:



File::
C:\WINDOWS\system32\tavo0.dll

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{49d1b7f8-9d2c-11dc-ad13-001d60ddc7a4}]



Save this as
CFScript


http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif

Refering to the picture above, drag CFScript into ComboFix.exe



Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Download ATF (Atribune Temp File) CleanerŠ by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Run Kaspersky online scanner and post back its report, combofix log and a fresh hjt log.

gynos
2008-02-24, 21:40
Hi , I think the problem is not solved yet since kaspersky detects two viruses and 61 infected files. Here's the report:

KASPERSKY ONLINE SCANNER REPORT
Sunday, February 24, 2008 9:22:43 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/02/2008
Kaspersky Anti-Virus database records: 578541
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
H:\
Scan Statistics
Total number of scanned objects 79897
Number of viruses found 2
Number of infected objects 61
Number of suspicious objects 0
Duration of the scan process 01:05:31

Infected Object Name Virus Name Last Action
C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Gyanos\.housecall6.6\Quarantine\gqsk.bat.vir.bac_a14644 Infected: Worm.Win32.AutoRun.cpr skipped
C:\Documents and Settings\Gyanos\.housecall6.6\Quarantine\kavo0.dll.vir.bac_a14644 Infected: Worm.Win32.AutoRun.cpr skipped
C:\Documents and Settings\Gyanos\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\call256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\callmember256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chat256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chat512.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmember256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmsg256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmsg512.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatsync\8f\8ff392d0b80c8adb.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\index2.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\profile4096.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\sms256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user1024.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user16384.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user4096.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\voicemail256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Cronologia\History.IE5\MSHist012008022420080225\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\ATI\ACE\Log\MOM-0.log Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DF983B.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DFF60A.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DFF61B.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Gyanos\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Gyanos\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Programmi\Alice ti aiuta\log\mpbtn.log Object is locked skipped
C:\Programmi\ATK Hotkey\HControl.exe Object is locked skipped
C:\QooBox\Quarantine\C\u.exe.vir Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\QooBox\Quarantine\H\u.exe.vir Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005640.bat Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005641.inf Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005659.dll Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005667.bat Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005668.inf Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005677.exe Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005678.dll Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005738.dll Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005741.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005750.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005751.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005775.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005779.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005786.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005787.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005792.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005806.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005812.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005818.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005826.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005848.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005849.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005853.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005879.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005886.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005902.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005906.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005915.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005924.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005930.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005955.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005963.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005964.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005965.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP55\A0006310.bat Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP56\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{46B34A31-9598-4FD8-BB87-4D58C4E256C5}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\ACS.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
D:\gqsk.bat Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005642.bat Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005643.inf Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005669.bat Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005670.inf Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005744.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005781.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005794.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005820.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005855.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005889.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005908.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005917.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005932.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005957.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0006123.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP56\change.log Object is locked skipped
D:\u.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
H:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
H:\gqsk.bat Infected: Worm.Win32.AutoRun.cpr skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005752.inf Infected: Worm.Win32.AutoRun.cpr skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005857.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0006124.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP55\A0006313.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP56\change.log Object is locked skipped
Scan process completed.

gynos
2008-02-24, 21:41
HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 21:29, on 2008-02-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Programmi\ATKOSD2\ATKOSD2.exe
C:\Programmi\ATK Hotkey\Hcontrol.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\ASUS\ATK Media\DMEDIA.EXE
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\ASUS\Splendid\ACMON.exe
C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe
C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programmi\Wireless Console 2\wcourier.exe
C:\WINDOWS\system32\ASUSTPE.exe
C:\Programmi\ATK Hotkey\ATKOSD.exe
C:\WINDOWS\ASScrPro.exe
C:\Programmi\Atheros\ACU.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Programmi\Notebook Hardware Control\nhc.exe
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\vsnpstd.exe
C:\Programmi\ATK Hotkey\KBFiltr.exe
C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Programmi\ATK Hotkey\WDC.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe
c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
c:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\mioengine.exe
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
C:\Programmi\Skype\Plugin Manager\skypePM.exe
c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
D:\setup\firefox-2.0.0.11.it.win32\firefox\firefox.exe
C:\HJT\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eluniversal.com/index.shtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=69204
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programmi\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ATKOSD2] "C:\Programmi\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [ATKHOTKEY] "C:\Programmi\ATK Hotkey\Hcontrol.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATKMEDIA] C:\Programmi\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ACMON] "C:\Programmi\ASUS\Splendid\ACMON.exe"
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Programmi\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [ASUSTPE] C:\WINDOWS\system32\ASUSTPE.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\ASScrPro.exe
O4 - HKLM\..\Run: [ACU] C:\Programmi\Atheros\ACU.exe -nogui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Programmi\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [SMSTray] C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [MultiFrame] C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - Startup: CCC.lnk = ?
O4 - Startup: My Vodafone.it.lnk = C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\programmi\bonjour\mdnsnsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://gyanos.spaces.live.com/PhotoUpload/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Servizio di configurazione Atheros (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe

gynos
2008-02-24, 21:43
Combofix log:

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.1143 [GMT 1:00]


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Creati Da 2008-01-24 al 2008-02-24 )))))))))))))))))))))))))))))))))))
.

2008-02-23 10:03 . 2008-02-23 10:09 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Programmi\Malwarebytes' Anti-Malware
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Malwarebytes
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2008-02-22 01:47 . 2008-02-22 01:47 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-22 01:47 . 2008-02-22 01:47 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-02-22 01:34 . 2008-02-24 21:29 <DIR> d-------- C:\HJT
2008-02-22 01:11 . 2008-02-22 01:11 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Lavasoft
2008-02-22 01:10 . 2008-02-22 01:10 <DIR> d-------- C:\Programmi\Lavasoft
2008-02-21 23:21 . 2008-02-24 12:13 <DIR> d-------- C:\Documents and Settings\Gyanos\.housecall6.6
2008-02-21 22:46 . 2008-02-21 22:15 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-21 22:46 . 2008-02-21 22:46 2,546 --a------ C:\WINDOWS\unins000.dat
2008-02-21 22:12 . 2008-02-21 22:50 <DIR> d-------- C:\Programmi\Spybot - Search & Destroy
2008-02-21 22:12 . 2008-02-21 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-02-12 11:47 . 2008-02-13 11:29 <DIR> d-------- C:\CutePrinter
2008-02-12 11:47 . 2003-07-24 18:06 86,016 --a------ C:\WINDOWS\system32\cutemon2k.dll
2008-02-12 11:47 . 2003-06-01 15:24 40,960 --a------ C:\WINDOWS\system32\UnCutePP.exe
2008-02-11 19:19 . 2008-02-11 19:19 <DIR> d-------- C:\Programmi\File comuni\Adobe
2008-02-11 19:03 . 2008-02-11 19:03 <DIR> d-------- C:\Programmi\Windows Media Connect 2
2008-02-11 19:03 . 2006-10-04 15:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-02-11 19:03 . 2006-10-04 15:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-02-11 19:03 . 2006-03-02 14:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-02-11 19:03 . 2006-10-04 15:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-02-11 19:01 . 2008-02-11 19:01 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-11 19:01 . 2008-02-11 19:02 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-11 16:42 . 2008-02-11 16:42 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects
2008-02-11 16:42 . 2008-02-11 16:42 407,047 --a------ C:\WINDOWS\system32\mioengine.exe
2008-02-09 15:29 . 2008-02-09 15:29 <DIR> d-------- C:\Programmi\File comuni\xing shared
2008-02-09 15:28 . 2008-02-09 15:28 <DIR> d-------- C:\Programmi\Real
2008-02-09 15:28 . 2008-02-09 15:29 <DIR> d-------- C:\Programmi\File comuni\Real
2008-02-05 22:07 . 2008-02-24 16:16 <DIR> d-------- C:\Programmi\AdunanzA
2008-02-05 18:35 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-02-05 18:35 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-02-05 18:35 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-02-05 13:32 . 2008-02-05 13:32 268 --ah----- C:\sqmdata01.sqm
2008-02-05 13:32 . 2008-02-05 13:32 244 --ah----- C:\sqmnoopt01.sqm
2008-02-04 22:45 . 2008-02-04 22:45 268 --ah----- C:\sqmdata00.sqm
2008-02-04 22:45 . 2008-02-04 22:45 244 --ah----- C:\sqmnoopt00.sqm
2008-02-04 19:46 . 2008-02-05 18:46 <DIR> d-------- C:\Documents and Settings\Gyanos\Contacts
2008-02-04 19:31 . 2008-02-04 19:45 <DIR> d-------- C:\Programmi\Windows Live
2008-02-04 19:31 . 2008-02-04 19:45 <DIR> d--hsc--- C:\Programmi\File comuni\WindowsLiveInstaller
2008-02-04 19:31 . 2008-02-04 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\WLInstaller
2008-02-04 11:00 . 2002-10-16 09:18 372,736 --a------ C:\WINDOWS\system32\ISIIndexer.dll
2008-02-04 11:00 . 2002-03-06 18:56 196,608 --a------ C:\WINDOWS\system32\ISIXFiles.dll
2008-02-04 11:00 . 2008-02-17 11:20 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-02-02 15:42 . 2008-02-24 19:00 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-02 15:42 . 2008-02-02 15:42 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\iTunes
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\iPod
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\Bonjour
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Apple Computer
2008-02-02 15:40 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\QuickTime
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Programmi\File comuni\Apple
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Programmi\Apple Software Update
2008-02-02 15:40 . 2008-02-02 15:41 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Apple
2008-02-02 15:25 . 2008-02-02 15:38 <DIR> d-------- C:\Documents and Settings\Gyanos\.SunDownloadManager
2008-02-02 15:15 . 2008-02-02 15:19 <DIR> d-------- C:\j2sdk1.4.2_16
2008-02-02 15:07 . 2008-02-02 15:07 <DIR> d-------- C:\WINDOWS\Sun
2008-02-02 15:06 . 2008-02-02 15:27 <DIR> d-------- C:\Programmi\Java
2008-02-02 15:06 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-02 15:05 . 2008-02-02 15:05 <DIR> d-------- C:\Programmi\File comuni\Java
2008-02-02 14:45 . 2008-02-02 14:45 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Printer Info Cache
2008-02-02 14:45 . 2008-02-02 15:30 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Image Zone Express
2008-02-02 12:23 . 2008-02-02 12:23 <DIR> d-------- C:\Programmi\Microsoft ActiveSync
2008-02-02 12:23 . 2008-02-02 12:23 <DIR> d-------- C:\Programmi\File comuni\L&H
2008-02-02 12:05 . 2008-02-02 12:05 <DIR> d-------- C:\Programmi\TRADOS
2008-02-01 10:31 . 2008-02-01 10:31 <DIR> d-------- C:\Programmi\MSXML 4.0
2008-01-31 19:19 . 2008-01-31 19:19 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\DataCast
2008-01-31 19:19 . 2007-12-14 17:19 44,544 --------- C:\WINDOWS\system32\msxml4a.dll
2008-01-31 19:18 . 2007-08-23 21:06 110,592 --a------ C:\WINDOWS\system32\TG_DUMP0708.DLL
2008-01-31 18:34 . 2008-01-31 18:34 <DIR> d-------- C:\Programmi\MarkAny
2008-01-31 18:31 . 2008-01-31 18:31 <DIR> d-------- C:\Programmi\Samsung
2008-01-31 18:31 . 2006-03-16 08:26 397,429 --a------ C:\WINDOWS\system32\PixtreeMP4FormatWriter.ax
2008-01-31 18:31 . 2006-01-20 10:11 110,592 --a------ C:\WINDOWS\system32\tg_dump.dll
2008-01-31 18:02 . 2008-01-31 18:02 <DIR> d-------- C:\Programmi\Trust
2008-01-31 18:02 . 2008-01-31 18:02 <DIR> d-------- C:\Programmi\File comuni\snpstd
2008-01-31 18:02 . 2004-05-17 20:55 302,720 --a------ C:\WINDOWS\system32\drivers\snpstd.sys
2008-01-31 18:02 . 2004-05-10 17:37 286,720 --a------ C:\WINDOWS\vsnpstd.exe
2008-01-31 18:02 . 2004-02-16 13:59 61,440 --a------ C:\WINDOWS\system32\csnpstd.dll
2008-01-31 18:02 . 2004-05-04 20:30 53,248 --a------ C:\WINDOWS\system32\rsnpstd.dll
2008-01-31 18:02 . 2004-05-06 11:22 53,248 --a------ C:\WINDOWS\system32\dsnpstd.dll
2008-01-31 18:02 . 2002-07-03 11:44 53,248 --a------ C:\WINDOWS\amcap.exe
2008-01-31 18:02 . 2004-05-04 20:10 36,864 --a------ C:\WINDOWS\system32\vsnpstd.dll
2008-01-31 18:02 . 2004-05-04 20:07 36,864 --a------ C:\WINDOWS\system32\dsnpstd.ax
2008-01-31 18:02 . 2004-02-23 15:19 20,480 --a------ C:\WINDOWS\usnpstd.exe
2008-01-31 18:02 . 2003-01-17 17:34 15,541 --a------ C:\WINDOWS\snpstd.ini
2008-01-31 18:02 . 2003-01-17 17:35 13,023 --a------ C:\WINDOWS\snpstd.src
2008-01-31 17:12 . 2008-01-31 18:27 <DIR> d-------- C:\Programmi\C'č Posta
2008-01-31 16:18 . 2008-01-31 17:12 286,720 --a------ C:\WINDOWS\iun507.exe
2008-01-31 12:19 . 2008-01-31 12:41 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\HP
2008-01-31 12:18 . 2008-02-04 20:35 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\HPSSUPPLY
2008-01-31 12:16 . 2008-01-31 12:16 <DIR> d-------- C:\Programmi\Hewlett-Packard
2008-01-31 12:16 . 2008-01-31 12:18 <DIR> d-------- C:\Programmi\File comuni\HP
2008-01-31 12:16 . 2008-01-31 12:16 <DIR> d-------- C:\Programmi\File comuni\Hewlett-Packard
2008-01-31 12:16 . 2008-01-31 12:17 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\HP
2008-01-31 12:15 . 2008-01-31 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Hewlett-Packard
2008-01-31 12:15 . 2006-12-03 22:45 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-01-31 12:15 . 2006-12-03 22:45 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-01-31 12:14 . 2007-01-12 10:44 892,928 -ra------ C:\WINDOWS\system32\hpwtiop2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 20:32 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\Skype
2008-02-24 18:00 22,528 ----a-w C:\WINDOWS\system32\drivers\nhcDriver.sys
2008-02-24 18:00 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\skypePM
2008-02-24 07:00 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\AVG7
2008-02-04 10:00 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-02-01 09:00 --------- d-----w C:\Programmi\ASUS
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 16:19 40,960 ------w C:\WINDOWS\system32\MAMACExtract.dll
2007-12-07 00:45 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-07 00:45 668,672 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-12-07 00:45 619,008 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-12-07 00:45 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-12-07 00:45 474,624 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-12-07 00:45 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-12-07 00:45 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-12-07 00:45 3,087,360 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-07 00:45 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-12-07 00:45 1,499,648 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-12-07 00:44 96,768 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2007-12-07 00:44 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-12-07 00:44 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-07 00:44 251,904 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-12-07 00:44 205,824 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-12-07 00:44 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-12-07 00:44 151,552 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-12-07 00:44 1,056,256 ------w C:\WINDOWS\system32\dllcache\danim.dll
2007-12-07 00:44 1,024,000 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2007-12-06 10:05 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-04 18:40 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:40 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-12-02 10:34 155,995 ----a-w C:\WINDOWS\java\Packages\I975R5VN.ZIP
2007-11-28 21:34 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"StartCCC"="c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"MultiFrame"="C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe" [2007-06-21 14:07 999792]
"Skype"="C:\Programmi\Skype\Phone\Skype.exe" [2007-11-12 15:48 21760296]
"MsnMsgr"="C:\Programmi\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="C:\Programmi\ATKOSD2\ATKOSD2.exe" [2007-07-03 10:48 7708672]
"ATKHOTKEY"="C:\Programmi\ATK Hotkey\Hcontrol.exe" [2007-07-12 10:25 225280]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 04:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
"ATKMEDIA"="C:\Programmi\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 08:27 61440]
"SynTPEnh"="C:\Programmi\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 05:02 786521]
"ACMON"="C:\Programmi\ASUS\Splendid\ACMON.exe" [2007-07-10 10:59 851968]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"RemoteControl"="C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40 155648]
"SMSERIAL"="C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 02:31 630784]
"PowerForPhone"="C:\Program Files\P4P\P4P.exe" [ ]
"Wireless Console 2"="C:\Programmi\Wireless Console 2\wcourier.exe" [2007-07-05 16:53 1040384]
"ASUSTPE"="C:\WINDOWS\system32\ASUSTPE.exe" [2007-01-16 16:13 106496]
"ASUS Camera ScreenSaver"="C:\WINDOWS\ASScrProlog.exe" [2007-10-29 14:43 37232]
"ASUS Screen Saver Protector"="C:\WINDOWS\ASScrPro.exe" [2007-10-29 14:44 33136]
"ACU"="C:\Programmi\Atheros\ACU.exe" [2007-05-03 17:42 376921]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-30 11:44 579072]
"NotebookHardwareControl"="C:\Programmi\Notebook Hardware Control\nhc.exe" [2007-05-04 01:33 2629632]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-05-10 17:37 286720]
"SMSTray"="C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 08:23 132624]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Programmi\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Programmi\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2008-02-09 15:28 185896]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-02 13:10 219136]

C:\Documents and Settings\Gyanos\Menu Avvio\Programmi\Esecuzione automatica\
CCC.lnk - C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-09-29 09:57:36 49152]
My Vodafone.it.lnk - C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio [2008-02-11 16:42:35 103615]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - C:\Programmi\Alice ti aiuta\bin\matcli.exe [2007-12-02 12:14:43 212992]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Programmi\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgw.exe"=
"C:\\Programmi\\FastWeb Login\\FastLogin.exe"=
"C:\\Programmi\\C'č Posta\\CPosta.exe"=
"C:\\Programmi\\ASUS\\ASUS Live Update\\ALU.exe"=
"C:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"C:\\Programmi\\iTunes\\iTunes.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"C:\\Programmi\\Real\\RealPlayer\\realplay.exe"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=

R2 ghaio;ghaio;C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-02 21:26]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-08-21 01:50]
R3 RTSTOR;USB Mass Stroage Device;C:\WINDOWS\system32\drivers\RTSTOR.SYS [2006-06-10 00:07]
R3 usbstor;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-03-02 14:00]
R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-03-28 19:52]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\A5AGU.sys [2004-10-06 10:39]
S3 ATHFMWDL;D-Link predator Bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-04 06:28]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {857D4360-762B-978B-76AD-491AA719E47A} /qb
.
Contenuto della cartella 'Scheduled Tasks'
"2008-02-18 19:00:00 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Gyanos.job"
- c:\Programmi\Norton Internet Security\Norton AntiVirus\Navw32.exei/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 21:32:03
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Programmi\ASUS\Asus MultiFrame\HookTitle.dll
.
Ora fine scansione: 2008-02-24 21:32:27
ComboFix-quarantined-files.txt 2008-02-24 20:32:24
ComboFix2.txt 2008-02-24 18:25:48
ComboFix3.txt 2008-02-24 11:15:56
ComboFix4.txt 2008-02-23 19:17:13
ComboFix5.txt 2008-02-23 12:04:19
.
2008-02-13 12:34:01 --- E O F ---

Blade81
2008-02-24, 21:53
Hi

Most Kaspersky findings are in system restore (will be cleaned a bit later).


Open notepad and copy/paste the text in the quotebox below into it:



File::
C:\Documents and Settings\Gyanos\.housecall6.6\Quarantine\gqsk.bat.vir.bac_a14644
C:\Documents and Settings\Gyanos\.housecall6.6\Quarantine\kavo0.dll.vir.bac_a14644
D:\gqsk.bat
D:\u.exe
H:\gqsk.bat



Save this as
CFScript (overwrite previous one)


http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif

Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

gynos
2008-02-25, 10:15
HI, what do you mean by

Most Kaspersky findings are in system restore (will be cleaned a bit later).

I followed the procedure, ma the viruses still seem to be there, What can I do?

Here's the latest kaspersky report.

Monday, February 25, 2008 10:12:35 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/02/2008
Kaspersky Anti-Virus database records: 579074
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
H:\
Scan Statistics
Total number of scanned objects 79994
Number of viruses found 2
Number of infected objects 63
Number of suspicious objects 0
Duration of the scan process 01:08:01

Infected Object Name Virus Name Last Action
C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\call256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\callmember256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chat512.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmember256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmsg256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmsg512.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\index2.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\profile4096.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\sms256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user1024.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user16384.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user4096.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\voicemail256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Cronologia\History.IE5\MSHist012008022520080226\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\ATI\ACE\Log\MOM-0.log Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DFDD5A.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DFEE1F.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DFEFAD.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Gyanos\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Gyanos\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Programmi\Alice ti aiuta\log\mpbtn.log Object is locked skipped
C:\Programmi\ATK Hotkey\HControl.exe Object is locked skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gyanos\.housecall6.6\Quarantine\gqsk.bat.vir.bac_a14644.vir Infected: Worm.Win32.AutoRun.cpr skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gyanos\.housecall6.6\Quarantine\kavo0.dll.vir.bac_a14644.vir Infected: Worm.Win32.AutoRun.cpr skipped
C:\QooBox\Quarantine\C\u.exe.vir Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\QooBox\Quarantine\D\gqsk.bat.vir Infected: Worm.Win32.AutoRun.cpr skipped
C:\QooBox\Quarantine\D\u.exe.vir Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\QooBox\Quarantine\H\u.exe.vir Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005640.bat Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005641.inf Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005659.dll Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005667.bat Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005668.inf Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005677.exe Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005678.dll Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005738.dll Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005741.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005750.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005751.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005775.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005779.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005786.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005787.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005792.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005806.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005812.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005818.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005826.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005848.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005849.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005853.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005879.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005886.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005902.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005906.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005915.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005924.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005930.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005955.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005963.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005964.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005965.dll Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP55\A0006310.bat Infected: Worm.Win32.AutoRun.cpr skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP57\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\ACS.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005642.bat Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005643.inf Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005669.bat Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005670.inf Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005744.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005781.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005794.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005820.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005855.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005889.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005908.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005917.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP53\A0005932.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0005957.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0006123.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP57\A0006638.bat Infected: Worm.Win32.AutoRun.cpr skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP57\A0006639.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
D:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP57\change.log Object is locked skipped
H:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
H:\gqsk.bat Infected: Worm.Win32.AutoRun.cpr skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP51\A0005752.inf Infected: Worm.Win32.AutoRun.cpr skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP52\A0005857.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP54\A0006124.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP55\A0006313.exe Infected: Trojan-PSW.Win32.OnLineGames.rpw skipped
H:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP57\change.log Object is locked skipped
Scan process completed.

Blade81
2008-02-25, 17:01
HI, what do you mean by

Most Kaspersky findings are in system restore (will be cleaned a bit later).
I mean that system restore will be resetted after system is first cleaned :)

gynos
2008-02-25, 19:05
Hi

I'm not quite sure I understood your last post.... :red:
Do you mean it is advisable to format the computer?

Blade81
2008-02-25, 19:43
No, didn't mean that. Just follow my instructions and all those bad items in system restore will be cleaned when time is right ;)

gynos
2008-02-25, 21:48
Do you mean these instructions?

Open notepad and copy/paste the text in the quotebox below into it:

Code:

File::
C:\Documents and Settings\Gyanos\.housecall6.6\Quarantine\gqsk.bat.vir.bac_a14644
C:\Documents and Settings\Gyanos\.housecall6.6\Quarantine\kavo0.dll.vir.bac_a14644
D:\gqsk.bat
D:\u.exe
H:\gqsk.bat


Save this as
CFScript (overwrite previous one)




Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.



I did it already. so I should now wait, isn'tit?

Thanks so far! :bigthumb:

Blade81
2008-02-25, 22:02
Then post the resultant log.
I'm waiting for that ComboFix log you got after doing according to those instructions. :)

gynos
2008-02-25, 23:48
Hi,


Here is the fresh, post-procedure combofix log

ComboFix 08-02-23.2 - Gyanos 2008-02-25 23:40:54.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.1124 [GMT 1:00]
Eseguito da: C:\Documents and Settings\Gyanos\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Gyanos\Desktop\CFScript.txt
* Creato nuovo punto di ripristino

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Gyanos\.housecall6.6\Quarantine\gqsk.bat.vir.bac_a14644
C:\Documents and Settings\Gyanos\.housecall6.6\Quarantine\kavo0.dll.vir.bac_a14644
D:\gqsk.bat
D:\u.exe
H:\gqsk.bat
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

H:\gqsk.bat

.
((((((((((((((((((((((((( Files Creati Da 2008-01-25 al 2008-02-25 )))))))))))))))))))))))))))))))))))
.

2008-02-23 10:03 . 2008-02-23 10:09 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Programmi\Malwarebytes' Anti-Malware
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Malwarebytes
2008-02-22 19:59 . 2008-02-22 19:59 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2008-02-22 01:47 . 2008-02-22 01:47 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-22 01:47 . 2008-02-22 01:47 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-02-22 01:34 . 2008-02-24 21:29 <DIR> d-------- C:\HJT
2008-02-22 01:11 . 2008-02-22 01:11 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Lavasoft
2008-02-22 01:10 . 2008-02-22 01:10 <DIR> d-------- C:\Programmi\Lavasoft
2008-02-21 23:21 . 2008-02-24 12:13 <DIR> d-------- C:\Documents and Settings\Gyanos\.housecall6.6
2008-02-21 22:46 . 2008-02-21 22:15 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-21 22:46 . 2008-02-21 22:46 2,546 --a------ C:\WINDOWS\unins000.dat
2008-02-21 22:12 . 2008-02-21 22:50 <DIR> d-------- C:\Programmi\Spybot - Search & Destroy
2008-02-21 22:12 . 2008-02-21 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-02-12 11:47 . 2008-02-25 12:51 <DIR> d-------- C:\CutePrinter
2008-02-12 11:47 . 2003-07-24 18:06 86,016 --a------ C:\WINDOWS\system32\cutemon2k.dll
2008-02-12 11:47 . 2003-06-01 15:24 40,960 --a------ C:\WINDOWS\system32\UnCutePP.exe
2008-02-11 19:19 . 2008-02-11 19:19 <DIR> d-------- C:\Programmi\File comuni\Adobe
2008-02-11 19:03 . 2008-02-11 19:03 <DIR> d-------- C:\Programmi\Windows Media Connect 2
2008-02-11 19:03 . 2006-10-04 15:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-02-11 19:03 . 2006-10-04 15:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-02-11 19:03 . 2006-03-02 14:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-02-11 19:03 . 2006-10-04 15:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-02-11 19:01 . 2008-02-11 19:01 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-11 19:01 . 2008-02-11 19:02 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-11 16:42 . 2008-02-11 16:42 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects
2008-02-11 16:42 . 2008-02-11 16:42 407,047 --a------ C:\WINDOWS\system32\mioengine.exe
2008-02-09 15:29 . 2008-02-09 15:29 <DIR> d-------- C:\Programmi\File comuni\xing shared
2008-02-09 15:28 . 2008-02-09 15:28 <DIR> d-------- C:\Programmi\Real
2008-02-09 15:28 . 2008-02-09 15:29 <DIR> d-------- C:\Programmi\File comuni\Real
2008-02-05 22:07 . 2008-02-25 23:26 <DIR> d-------- C:\Programmi\AdunanzA
2008-02-05 18:35 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-02-05 18:35 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-02-05 18:35 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-02-05 13:32 . 2008-02-05 13:32 268 --ah----- C:\sqmdata01.sqm
2008-02-05 13:32 . 2008-02-05 13:32 244 --ah----- C:\sqmnoopt01.sqm
2008-02-04 22:45 . 2008-02-04 22:45 268 --ah----- C:\sqmdata00.sqm
2008-02-04 22:45 . 2008-02-04 22:45 244 --ah----- C:\sqmnoopt00.sqm
2008-02-04 19:46 . 2008-02-05 18:46 <DIR> d-------- C:\Documents and Settings\Gyanos\Contacts
2008-02-04 19:31 . 2008-02-04 19:45 <DIR> d-------- C:\Programmi\Windows Live
2008-02-04 19:31 . 2008-02-04 19:45 <DIR> d--hsc--- C:\Programmi\File comuni\WindowsLiveInstaller
2008-02-04 19:31 . 2008-02-04 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\WLInstaller
2008-02-04 11:00 . 2002-10-16 09:18 372,736 --a------ C:\WINDOWS\system32\ISIIndexer.dll
2008-02-04 11:00 . 2002-03-06 18:56 196,608 --a------ C:\WINDOWS\system32\ISIXFiles.dll
2008-02-04 11:00 . 2008-02-17 11:20 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-02-02 15:42 . 2008-02-25 08:58 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-02 15:42 . 2008-02-02 15:42 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\iTunes
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\iPod
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\Bonjour
2008-02-02 15:41 . 2008-02-02 15:41 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Apple Computer
2008-02-02 15:40 . 2008-02-02 15:41 <DIR> d-------- C:\Programmi\QuickTime
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Programmi\File comuni\Apple
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Programmi\Apple Software Update
2008-02-02 15:40 . 2008-02-02 15:41 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer
2008-02-02 15:40 . 2008-02-02 15:40 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Apple
2008-02-02 15:25 . 2008-02-02 15:38 <DIR> d-------- C:\Documents and Settings\Gyanos\.SunDownloadManager
2008-02-02 15:15 . 2008-02-02 15:19 <DIR> d-------- C:\j2sdk1.4.2_16
2008-02-02 15:07 . 2008-02-02 15:07 <DIR> d-------- C:\WINDOWS\Sun
2008-02-02 15:06 . 2008-02-02 15:27 <DIR> d-------- C:\Programmi\Java
2008-02-02 15:06 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-02 15:05 . 2008-02-02 15:05 <DIR> d-------- C:\Programmi\File comuni\Java
2008-02-02 14:45 . 2008-02-02 14:45 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Printer Info Cache
2008-02-02 14:45 . 2008-02-02 15:30 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\Image Zone Express
2008-02-02 12:23 . 2008-02-02 12:23 <DIR> d-------- C:\Programmi\Microsoft ActiveSync
2008-02-02 12:23 . 2008-02-02 12:23 <DIR> d-------- C:\Programmi\File comuni\L&H
2008-02-02 12:05 . 2008-02-02 12:05 <DIR> d-------- C:\Programmi\TRADOS
2008-02-01 10:31 . 2008-02-01 10:31 <DIR> d-------- C:\Programmi\MSXML 4.0
2008-01-31 19:19 . 2008-01-31 19:19 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\DataCast
2008-01-31 19:19 . 2007-12-14 17:19 44,544 --------- C:\WINDOWS\system32\msxml4a.dll
2008-01-31 19:18 . 2007-08-23 21:06 110,592 --a------ C:\WINDOWS\system32\TG_DUMP0708.DLL
2008-01-31 18:34 . 2008-01-31 18:34 <DIR> d-------- C:\Programmi\MarkAny
2008-01-31 18:31 . 2008-01-31 18:31 <DIR> d-------- C:\Programmi\Samsung
2008-01-31 18:31 . 2006-03-16 08:26 397,429 --a------ C:\WINDOWS\system32\PixtreeMP4FormatWriter.ax
2008-01-31 18:31 . 2006-01-20 10:11 110,592 --a------ C:\WINDOWS\system32\tg_dump.dll
2008-01-31 18:02 . 2008-01-31 18:02 <DIR> d-------- C:\Programmi\Trust
2008-01-31 18:02 . 2008-01-31 18:02 <DIR> d-------- C:\Programmi\File comuni\snpstd
2008-01-31 18:02 . 2004-05-17 20:55 302,720 --a------ C:\WINDOWS\system32\drivers\snpstd.sys
2008-01-31 18:02 . 2004-05-10 17:37 286,720 --a------ C:\WINDOWS\vsnpstd.exe
2008-01-31 18:02 . 2004-02-16 13:59 61,440 --a------ C:\WINDOWS\system32\csnpstd.dll
2008-01-31 18:02 . 2004-05-04 20:30 53,248 --a------ C:\WINDOWS\system32\rsnpstd.dll
2008-01-31 18:02 . 2004-05-06 11:22 53,248 --a------ C:\WINDOWS\system32\dsnpstd.dll
2008-01-31 18:02 . 2002-07-03 11:44 53,248 --a------ C:\WINDOWS\amcap.exe
2008-01-31 18:02 . 2004-05-04 20:10 36,864 --a------ C:\WINDOWS\system32\vsnpstd.dll
2008-01-31 18:02 . 2004-05-04 20:07 36,864 --a------ C:\WINDOWS\system32\dsnpstd.ax
2008-01-31 18:02 . 2004-02-23 15:19 20,480 --a------ C:\WINDOWS\usnpstd.exe
2008-01-31 18:02 . 2003-01-17 17:34 15,541 --a------ C:\WINDOWS\snpstd.ini
2008-01-31 18:02 . 2003-01-17 17:35 13,023 --a------ C:\WINDOWS\snpstd.src
2008-01-31 17:12 . 2008-01-31 18:27 <DIR> d-------- C:\Programmi\C'č Posta
2008-01-31 16:18 . 2008-01-31 17:12 286,720 --a------ C:\WINDOWS\iun507.exe
2008-01-31 12:19 . 2008-01-31 12:41 <DIR> d-------- C:\Documents and Settings\Gyanos\Dati applicazioni\HP
2008-01-31 12:18 . 2008-02-04 20:35 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\HPSSUPPLY
2008-01-31 12:16 . 2008-01-31 12:16 <DIR> d-------- C:\Programmi\Hewlett-Packard
2008-01-31 12:16 . 2008-01-31 12:18 <DIR> d-------- C:\Programmi\File comuni\HP
2008-01-31 12:16 . 2008-01-31 12:16 <DIR> d-------- C:\Programmi\File comuni\Hewlett-Packard
2008-01-31 12:16 . 2008-01-31 12:17 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\HP
2008-01-31 12:15 . 2008-01-31 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Hewlett-Packard
2008-01-31 12:15 . 2006-12-03 22:45 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-01-31 12:15 . 2006-12-03 22:45 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-01-31 12:14 . 2007-01-12 10:44 892,928 -ra------ C:\WINDOWS\system32\hpwtiop2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 22:09 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\Skype
2008-02-25 18:19 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\AVG7
2008-02-25 15:00 --------- d-----w C:\Documents and Settings\Gyanos\Dati applicazioni\skypePM
2008-02-25 07:59 22,528 ----a-w C:\WINDOWS\system32\drivers\nhcDriver.sys
2008-02-04 10:00 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-02-01 09:00 --------- d-----w C:\Programmi\ASUS
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 16:19 40,960 ------w C:\WINDOWS\system32\MAMACExtract.dll
2007-12-07 00:45 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-07 00:45 668,672 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-12-07 00:45 619,008 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-12-07 00:45 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-12-07 00:45 474,624 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-12-07 00:45 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-12-07 00:45 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-12-07 00:45 3,087,360 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-07 00:45 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-12-07 00:45 1,499,648 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-12-07 00:44 96,768 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2007-12-07 00:44 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-12-07 00:44 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-07 00:44 251,904 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-12-07 00:44 205,824 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-12-07 00:44 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-12-07 00:44 151,552 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-12-07 00:44 1,056,256 ------w C:\WINDOWS\system32\dllcache\danim.dll
2007-12-07 00:44 1,024,000 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2007-12-06 10:05 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-04 18:40 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:40 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-12-02 10:34 155,995 ----a-w C:\WINDOWS\java\Packages\I975R5VN.ZIP
2007-11-28 21:34 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"StartCCC"="c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"MultiFrame"="C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe" [2007-06-21 14:07 999792]
"Skype"="C:\Programmi\Skype\Phone\Skype.exe" [2007-11-12 15:48 21760296]
"MsnMsgr"="C:\Programmi\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="C:\Programmi\ATKOSD2\ATKOSD2.exe" [2007-07-03 10:48 7708672]
"ATKHOTKEY"="C:\Programmi\ATK Hotkey\Hcontrol.exe" [2007-07-12 10:25 225280]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 04:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
"ATKMEDIA"="C:\Programmi\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 08:27 61440]
"SynTPEnh"="C:\Programmi\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 05:02 786521]
"ACMON"="C:\Programmi\ASUS\Splendid\ACMON.exe" [2007-07-10 10:59 851968]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"RemoteControl"="C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40 155648]
"SMSERIAL"="C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 02:31 630784]
"PowerForPhone"="C:\Program Files\P4P\P4P.exe" [ ]
"Wireless Console 2"="C:\Programmi\Wireless Console 2\wcourier.exe" [2007-07-05 16:53 1040384]
"ASUSTPE"="C:\WINDOWS\system32\ASUSTPE.exe" [2007-01-16 16:13 106496]
"ASUS Camera ScreenSaver"="C:\WINDOWS\ASScrProlog.exe" [2007-10-29 14:43 37232]
"ASUS Screen Saver Protector"="C:\WINDOWS\ASScrPro.exe" [2007-10-29 14:44 33136]
"ACU"="C:\Programmi\Atheros\ACU.exe" [2007-05-03 17:42 376921]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-30 11:44 579072]
"NotebookHardwareControl"="C:\Programmi\Notebook Hardware Control\nhc.exe" [2007-05-04 01:33 2629632]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-05-10 17:37 286720]
"SMSTray"="C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 08:23 132624]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Programmi\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Programmi\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2008-02-09 15:28 185896]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-02 13:10 219136]

C:\Documents and Settings\Gyanos\Menu Avvio\Programmi\Esecuzione automatica\
CCC.lnk - C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-09-29 09:57:36 49152]
My Vodafone.it.lnk - C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio [2008-02-11 16:42:35 103615]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - C:\Programmi\Alice ti aiuta\bin\matcli.exe [2007-12-02 12:14:43 212992]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Programmi\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Programmi\\Grisoft\\AVG7\\avgw.exe"=
"C:\\Programmi\\FastWeb Login\\FastLogin.exe"=
"C:\\Programmi\\C'č Posta\\CPosta.exe"=
"C:\\Programmi\\ASUS\\ASUS Live Update\\ALU.exe"=
"C:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"C:\\Programmi\\iTunes\\iTunes.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"C:\\Programmi\\Real\\RealPlayer\\realplay.exe"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=

R2 ghaio;ghaio;C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-02 21:26]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-08-21 01:50]
R3 RTSTOR;USB Mass Stroage Device;C:\WINDOWS\system32\drivers\RTSTOR.SYS [2006-06-10 00:07]
R3 usbstor;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-03-02 14:00]
R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-03-28 19:52]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\A5AGU.sys [2004-10-06 10:39]
S3 ATHFMWDL;D-Link predator Bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-04 06:28]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {857D4360-762B-978B-76AD-491AA719E47A} /qb
.
Contenuto della cartella 'Scheduled Tasks'
"2008-02-25 19:00:00 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Gyanos.job"
- c:\Programmi\Norton Internet Security\Norton AntiVirus\Navw32.exei/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 23:41:56
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

? [10376]
? [53784]
? [53704]
? [54616]
? [54796]
? [27968]
scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-02-25 23:42:19
ComboFix-quarantined-files.txt 2008-02-25 22:42:17
ComboFix2.txt 2008-02-24 23:01:00
.
2008-02-13 12:34:01 --- E O F ---

Blade81
2008-02-26, 17:49
Hi

Please run Kaspersky online scanner once more and post its report & a fresh hjt log.

gynos
2008-02-26, 23:15
Hi it seems I am clean :)

Here is the hjt log

Logfile of HijackThis v1.99.1
Scan saved at 23:08, on 2008-02-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\ATKOSD2\ATKOSD2.exe
C:\Programmi\ATK Hotkey\Hcontrol.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\ASUS\ATK Media\DMEDIA.EXE
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\ASUS\Splendid\ACMON.exe
C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe
C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programmi\Wireless Console 2\wcourier.exe
C:\WINDOWS\system32\ASUSTPE.exe
C:\WINDOWS\ASScrPro.exe
C:\Programmi\Atheros\ACU.exe
C:\WINDOWS\system32\acs.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmi\Notebook Hardware Control\nhc.exe
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vsnpstd.exe
C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe
c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\ATK Hotkey\ATKOSD.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\mioengine.exe
C:\Programmi\ATK Hotkey\KBFiltr.exe
C:\Programmi\ATK Hotkey\WDC.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
c:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\Skype\Plugin Manager\skypePM.exe
C:\Programmi\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programmi\internet explorer\iexplore.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\setup\firefox-2.0.0.11.it.win32\firefox\firefox.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Programmi\Microsoft Office\OFFICE11\WINWORD.EXE
C:\HJT\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eluniversal.com/index.shtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=69204
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programmi\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ATKOSD2] "C:\Programmi\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [ATKHOTKEY] "C:\Programmi\ATK Hotkey\Hcontrol.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATKMEDIA] C:\Programmi\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ACMON] "C:\Programmi\ASUS\Splendid\ACMON.exe"
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\ASUSTek\ASUSDVD\PDVDServ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Programmi\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [ASUSTPE] C:\WINDOWS\system32\ASUSTPE.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\ASScrPro.exe
O4 - HKLM\..\Run: [ACU] C:\Programmi\Atheros\ACU.exe -nogui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Programmi\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [SMSTray] C:\Programmi\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] c:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [MultiFrame] C:\Programmi\ASUS\Asus MultiFrame\MultiFrame.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - Startup: CCC.lnk = ?
O4 - Startup: My Vodafone.it.lnk = C:\Documents and Settings\Gyanos\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\programmi\bonjour\mdnsnsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - [url]
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Servizio di configurazione Atheros (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe

...and here is the new kaspersky report

Tuesday, February 26, 2008 10:37:01 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/02/2008
Kaspersky Anti-Virus database records: 582103
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
H:\
Scan Statistics
Total number of scanned objects 72454
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 00:53:13

Infected Object Name Virus Name Last Action
C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\call256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\callmember256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chat512.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmember256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmsg256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\chatmsg512.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\index2.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\profile4096.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\sms256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user1024.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user16384.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\user4096.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Dati applicazioni\Skype\gyanos\voicemail256.dbb Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Cronologia\History.IE5\MSHist012008022620080227\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\ATI\ACE\Log\MOM-0.log Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DF588B.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DF7C05.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temp\~DF86D9.tmp Object is locked skipped
C:\Documents and Settings\Gyanos\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gyanos\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Gyanos\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Programmi\Alice ti aiuta\log\mpbtn.log Object is locked skipped
C:\Programmi\ATK Hotkey\HControl.exe Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{2275932A-1DCD-401A-8A23-B65DDD3C85EF}\RP64\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\ACS.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
Scan process completed.


As you can see it doesn't detect anything, but I don't understand why it keeps reporting the above files as infected and it says they are locked? Do you Know?
Can I consider my computer clean?

THANKS SO MUCH SO FAR!!!

Blade81
2008-02-27, 16:18
As you can see it doesn't detect anything, but I don't understand why it keeps reporting the above files as infected and it says they are locked?
Object is locked skipped message is normal.


Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis



Next we remove all used tools.

Please download OTMoveIt2 (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) and save it to desktop.

Double-click OTMoveIt2.exe.
Click the CleanUp! button.
Select Yes when the
Begin cleanup Process?
prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet, please allow it to do so.


UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

Comodo BOCLEAN (http://www.comodo.com/boclean/boclean.html) <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
Download SpywareBlaster
Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes
kill bits
in the registry, so that certain activex controls can't install.
If you don't know what activex controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)
You can download SpywareBlaster here here (http://majorgeeks.com/downloadget.php?id=2859&file=11&evp=61b0e8ad41924a03c37615f4682b4cef)
SpywareBlaster tutorial (http://www.bleepingcomputer.com/forums/tutorial49.html)

Download iespyad
It puts many bad webpages on your restricted zones list. This means that you can still view the
bad
webpages, but the webpages cannot do certain things (such as use javascripts and cookies).
If you need help understanding how it works, there is a tutorial here (http://www.bleepingcomputer.com/tutorials/tutorial53.html)
Download it here (http://www.spywarewarrior.com/uiuc/res/ie-spyad.exe)

hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this (http://www.bleepingcomputer.com/forums/tutorial60.html) webpage out.
See here (http://www.freebyte.com/antivirus/#firewalls) to choose one



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Run the spybot and adaware regularly. (Once or twice a week minimum.)
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.



Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:

gynos
2008-02-28, 13:01
Hi I am following your instructions.
Just one little thing I came up with...

I use firefox as default browser, I have updated my ie to the latest version though. Since then I cannot open links I receive in my outlook mail, ie. mozilla opens but it goes to the default homepage and not to the actual link. Do you know how to solve this? :)

gynos
2008-02-28, 13:36
Hi sorry, just ignore my last post. I manage to sort the problem out. THKs.


My system seems to be running fine so far. Though some small things I 've noticed but I think nothing to worry about.

the host file I currently have (which Avg detects as a change during scan) was inserted by spybot. Do you suggest i should download another one?

Blade81
2008-02-28, 15:20
the host file I currently have (which Avg detects as a change during scan) was inserted by spybot. Do you suggest i should download another one?
Host file inserted by spybot is good one too. It's your decision whether or not you want to replace it with MVPS hosts file :)

Blade81
2008-03-03, 22:23
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.