Malwarebytes' Anti-Malware 1.30
Versione del database: 1397
Windows 5.1.2600 Service Pack 3
14/11/2008 13.41.14
mbam-log-2008-11-14 (13-41-14).txt
Tipo di scansione: Scansione completa (C:\|D:\|E:\|)
Elementi scansionati: 133525
Tempo trascorso: 1 hour(s), 1 minute(s), 17 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 5
Cartelle infette: 1
File infetti: 3
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System (Rootkit.DNSChanger.H) -> Data: kdkph.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip\Parameters\Interfaces\{4cbaa140-11b7-4d01-af45-09dfad8edc6f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.102;85.255.112.168 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\T cpip\Parameters\Interfaces\{4cbaa140-11b7-4d01-af45-09dfad8edc6f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.102;85.255.112.168 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\T cpip\Parameters\Interfaces\{4cbaa140-11b7-4d01-af45-09dfad8edc6f}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.102;85.255.112.168 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\T cpip\Parameters\Interfaces\{4cbaa140-11b7-4d01-af45-09dfad8edc6f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.102;85.255.112.168 -> Quarantined and deleted successfully.
Cartelle infette:
C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.
File infetti:
C:\WINDOWS\system32\kdkph.exe (Rootkit.DNSChanger.H) -> Delete on reboot.
C:\resycled\boot.com (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Programmi\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.