Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Versione database: 5767
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
24/02/2011 22.05.50
mbam-log-2011-02-24 (22-05-50).txt
Tipo di scansione: Scansione veloce
Elementi esaminati: 158876
Tempo trascorso: 13 minuti, 32 secondi
Processi infetti in memoria: 1
Moduli di memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 6
Voci infette nei dati di registro: 2
Cartelle infette: 0
File infetti: 18
Processi infetti in memoria:
c:\documents and settings\Franc\dati applicazioni\microsoft\conhost.exe (Trojan.Agent) -> 1032 -> Unloaded process successfully.
Moduli di memoria infetti:
(Non sono stati rilevati elementi nocivi)
Chiavi di registro infette:
(Non sono stati rilevati elementi nocivi)
Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi on\Run\conhost (Trojan.Agent) -> Value: conhost -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Value: Load -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersio n\Run\mssend (Trojan.Agent) -> Value: mssend -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\bk (Malware.Trace) -> Value: bk -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Value: Shell -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio n\Internet Settings\ProxyServer (PUM.Bad.Proxy) -> Value: ProxyServer -> Quarantined and deleted successfully.
Voci infette nei dati di registro:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Bad: (C:\DOCUME~1\Franc\IMPOST~1\Temp\csrss.exe) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe "C:\Documents and Settings\Franc\Dati applicazioni\szqxpbmzafofkisq3hk1kfiyaixip3s2\csrss.exe") Good: (Explorer.exe) -> Quarantined and deleted successfully.
Cartelle infette:
(Non sono stati rilevati elementi nocivi)
File infetti:
c:\programmi\mozilla firefox\update.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\0.6249940967529516.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\0.6599830642522997.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\1071526.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\16.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\1F.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\2E.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\31.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\49.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\6.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\7.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\7526408.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\9.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\D.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\google.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\dati applicazioni\microsoft\conhost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\0.1521085057170598.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\documents and settings\Franc\impostazioni locali\Temp\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.