log di the Avenger
codice:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "C:\Programmi\Logitech\Video\CameraAssistant.exe" deleted successfully.
File "C:\Programmi\Logitech\Video\InstallHelper.exe" deleted successfully.
File "C:\Programmi\Microsoft Visual Studio\MyProjects\MAT3x3\Debug\MAT3x3.exe" deleted successfully.
File "C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" deleted successfully.
File "C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" deleted successfully.
File "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.Exe" deleted successfully.
File "C:\WINDOWS\system32\ctfmon.exe" deleted successfully.
File "C:\WINDOWS\system32\PSDrvCheck.exe" deleted successfully.
File "C:\WINXP\system32\drivers\hldrrr.exe" deleted successfully.
File "C:\WINXP\system32\wintems.exe" deleted successfully.

Error:  file "C:\WINXP\system32\drivers\hidr.exe" not found!
Deletion of file "C:\WINXP\system32\drivers\hidr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  file "C:\WINXP\system32\drivers\hidrrr.exe" not found!
Deletion of file "C:\WINXP\system32\drivers\hidrrr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist

File "C:\WINXP\system32\drivers\srosa.sys" deleted successfully.

Error:  file "C:\WINXP\system32\drivers\klif.sys" not found!
Deletion of file "C:\WINXP\system32\drivers\klif.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  file "C:\WINXP\system32\drivers\pci32.sys" not found!
Deletion of file "C:\WINXP\system32\drivers\pci32.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  file "C:\WINXP\system32\hldrrr.exe" not found!
Deletion of file "C:\WINXP\system32\hldrrr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist

File "C:\WINXP\system32\mdelk.exe" deleted successfully.
File move operation "C:\Programmi\File comuni\PCSuite\DataLayer\bak\DataLayer.exe|C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe" completed successfully.
File move operation "C:\Programmi\File comuni\Real\Update_OB\bak\evntsvc.exe|C:\Programmi\File comuni\Real\Update_OB\evntsvc.exe" completed successfully.
File move operation "C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe|C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" completed successfully.
File move operation "C:\Programmi\Logitech\Desktop Messenger\8876480\Program\bak\LogitechDesktopMessenger.exe|C:\Programmi\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" completed successfully.
File move operation "C:\Programmi\Logitech\Video\bak\CameraAssistant.exe|C:\Programmi\Logitech\Video\CameraAssistant.exe" completed successfully.
File move operation "C:\Programmi\Logitech\Video\bak\InstallHelper.exe|C:\Programmi\Logitech\Video\InstallHelper.exe" completed successfully.
File move operation "C:\Programmi\Microsoft Visual Studio\MyProjects\MAT3x3\Debug\bak\MAT3x3.exe|C:\Programmi\Microsoft Visual Studio\MyProjects\MAT3x3\Debug\MAT3x3.exe" completed successfully.
File move operation "C:\Programmi\Nokia\Nokia PC Suite 6\bak\LaunchApplication.exe|C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" completed successfully.
File move operation "C:\Programmi\Nokia\Nokia PC Suite 6\bak\PcSync2.exe|C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" completed successfully.
File move operation "C:\Programmi\Spyware Terminator\bak\SpywareTerminatorShield.exe|C:\Programmi\Spyware Terminator\SpywareTerminatorShield.Exe" completed successfully.
File move operation "C:\WINDOWS\system32\bak\ctfmon.exe|C:\WINDOWS\system32\ctfmon.exe" completed successfully.
File move operation "C:\WINDOWS\system32\bak\ElkCtrl.exe|C:\WINDOWS\system32\ElkCtrl.exe" completed successfully.
File move operation "C:\WINDOWS\system32\bak\LVCOMSX.EXE|C:\WINDOWS\system32\LVCOMSX.EXE" completed successfully.
File move operation "C:\WINDOWS\system32\bak\PSDrvCheck.exe|C:\WINDOWS\system32\PSDrvCheck.exe" completed successfully.
File move operation "C:\WINDOWS\system32\bak\srvafixe.exe|C:\WINDOWS\system32\srvafixe.exe" completed successfully.
Folder "C:\WINXP\system32\drivers\down" deleted successfully.

Error:  folder "c:\WINXP\exefld" not found!
Deletion of folder "c:\WINXP\exefld" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  folder "c:\WINXP\exefnd" not found!
Deletion of folder "c:\WINXP\exefnd" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  folder "C:\WINXP\exefqd" not found!
Deletion of folder "C:\WINXP\exefqd" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Completed script processing.

*******************

Finished!  Terminate.
Log di HiJackThis
[CODE]
Logfile of HijackThis v1.99.1
Scan saved at 19.21.58, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\csrss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
C:\Programmi\FreePOPs\freepopsservice.exe
C:\WINXP\System32\svchost.exe
C:\Programmi\FreePOPs\freepopsd.exe
C:\WINXP\System32\alg.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\wuauclt.exe
C:\WINXP\system32\NOTEPAD.EXE
C:\WINXP\system32\wuauclt.exe
C:\WINXP\RTHDCPL.EXE
C:\Programmi\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Programmi\Logitech\Video\CameraAssistant.exe
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
C:\Programmi\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\WINXP\system32\lvcomsx.exe
C:\WINXP\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\eMule\eMule.exe
C:\Programmi\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINXP\system32\svchost.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINXP\system32\NOTEPAD.EXE
C:\Programmi\OpenOffice.org 2.3\program\soffice.exe
C:\Programmi\OpenOffice.org 2.3\program\soffice.BIN
C:\Programmi\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINXP\System32\wbem\wmiprvse.exe
C:\Programmi\Mozilla Firefox 3 Beta 2\firefox.exe
C:\WINXP\System32\wbem\wmiprvse.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\SPRUNK~1\IMPOST~1\Temp\Rar$EX01.797\Hi jackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ewin91.spaces.live.com/recent/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {C2626E66-D21B-E628-C1DF-1DACCFA36ED2} - C:\Programmi\File comuni\fjOs0r.dll
O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINXP\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Programmi\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINXP\system32\PCLECoInst.dll",CheckUSBControl ler
O4 - HKLM\..\Run: [USBToolTip] "C:\Programmi\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Programmi\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programmi\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Programmi\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [RegRun WinBait] C:\WINXP\winbait.exe
O4 - HKLM\..\Run: [@RegRunOnSecure] C:\PROGRA~1\Greatis\REGRUN~1\OnSecure.exe
O4 - HKLM\..\RunServices: [runsvc] runsvc.exe
O4 - HKLM\..\RunOnce: [ReEXEc] C:\Documents and Settings\Sprunkman\Desktop\ELIBAGLA.B%D8%D8DB%D8%D 8H.EXE
O4 - HKLM\..\RunOnce: [Cleanup] C:\cleanup.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINXP\system32\ctfmon.exe
O4 - HKCU\..\Run: [drvsyskit] C:\WINXP\system32\drivers\hldrrr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Regrun2] C:\PROGRA~1\Greatis\REGRUN~1\WatchDog.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programmi\eMule\eMule.exe -AutoStart
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Programmi\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: DSLMON.lnk = C:\Programmi\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Html To Image - C:\Programmi\Html To Image\menu.htm
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A