Ecco i tre log, sembra che il Pc sia pulito , ma il mio cirillo.old(vecchio kamsoft.exe) è sempre li.Mi chiedo, sarà solo un moncone di un rootkit ormai inattivo?Intanto grazie mille!
ComboFix 08-12-07.04 - utente 2008-12-09 17.07.46.2 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.1783 [GMT 1:00]
Eseguito da: c:\documents and settings\utente\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-11-09 al 2008-12-09 )))))))))))))))))))))))))))))))))))
**********************************
log editato.. non è stato rilevato nulla
**********************************
160 --- E O F --- 2008-12-05 23:15:08
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opexxd successfully.
Script file read successfully.
Backups directory opexxd successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: file "C:\WINDOWS\system32\cirillo.exe" not found!
Deletion of file "C:\WINDOWS\system32\cirillo.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\cirillo.old" not found!
Deletion of file "C:\WINDOWS\system32\cirillo.old" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\cirillo.exe" not found!
Deletion of file "C:\WINDOWS\cirillo.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\cirillo.old" not found!
Deletion of file "C:\WINDOWS\cirillo.old" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: "C:\autorun.inf" is a folder, not a file!
Deletion of file "C:\autorun.inf" failed!
Status: 0xc00000ba (STATUS_FILE_IS_A_DIRECTORY)
--> use "Folders to delete:" instead of "Files to delete:" to delete a directory
Folder "C:\DOCUME~1\utente\IMPOST~1\Temp" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.24.25, on 09/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\cirillo.old
**********************************
log editato.. ho rimasto solo la voce infetta
**********************************
--
End of file - 5619 bytes
Modificato da prgn - 03/Marzo/2009 alle 21:09