ecco il nuov report di Combofix:
ComboFix 09-10-28.08 - Utente 29/10/2009 23.25.17.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.3070.2666 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Utente\Desktop\CFScript.txt
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-09-28 al 2009-10-29 )))))))))))))))))))))))))))))))))))
.
2009-10-28 21:38 . 2009-10-28 21:38 -------- d-----w- c:\documents and settings\Utente\DoctorWeb
2009-10-28 21:17 . 2009-10-28 21:21 -------- d-----w- c:\programmi\Unlocker
2009-10-28 20:34 . 2009-10-28 20:34 -------- d-----w- c:\programmi\VirusTotalUploader
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-29 22:28 . 2009-02-09 17:56 487176736 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-29 22:17 . 2006-06-08 17:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-10-29 22:12 . 2006-06-08 17:14 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-10-29 22:02 . 2009-02-09 17:56 6506432 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-29 18:28 . 2007-06-09 09:28 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-10-28 22:22 . 2006-05-06 07:40 96256 ----a-w- c:\windows\system32\drivers\sptd0093.sys
2009-10-27 19:40 . 2009-09-26 10:09 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\vlc
2009-10-27 18:37 . 2008-08-14 14:17 -------- d-----w- c:\programmi\Java
2009-10-27 18:37 . 2001-08-31 15:00 74432 ----a-w- c:\windows\system32\perfc010.dat
2009-10-27 18:37 . 2001-08-31 15:00 447874 ----a-w- c:\windows\system32\perfh010.dat
2009-10-27 18:32 . 2008-04-16 17:29 -------- d-----w- c:\programmi\SpywareBlaster
2009-10-27 17:25 . 2006-09-05 17:26 4212 -c-ha-w- c:\windows\system32\zllictbl.dat
2009-10-09 05:35 . 2006-06-09 12:58 -------- d-----w- c:\programmi\eMule
2009-09-26 07:58 . 2009-09-26 07:53 -------- d-----w- c:\programmi\iTunes
2009-09-26 07:55 . 2006-07-02 11:22 -------- d-----w- c:\programmi\iPod
2009-09-26 07:55 . 2007-07-03 07:57 -------- d-----w- c:\programmi\File comuni\Apple
2009-09-26 07:26 . 2006-07-02 11:24 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Apple Computer
2009-09-24 08:37 . 2009-03-06 14:51 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Hamachi
2009-09-14 15:43 . 2009-09-14 15:42 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-14 15:39 . 2008-12-10 23:10 -------- d-----w- c:\programmi\QuickTime
2009-09-11 16:45 . 2009-01-23 18:51 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-09-11 07:45 . 2008-12-20 13:34 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\dvdcss
2009-09-10 17:17 . 2009-09-10 17:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-09-10 17:16 . 2009-09-10 17:16 -------- d-----w- c:\programmi\NOS
2009-09-10 12:54 . 2009-01-23 18:51 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-01-23 18:51 19160 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-08-27 15:22 . 2009-08-27 15:22 13698 ----a-w- c:\windows\War3Unin.dat
2009-08-27 15:22 . 2009-08-27 15:22 2829 ----a-w- c:\windows\War3Unin.pif
2009-08-27 15:22 . 2009-08-27 15:22 126976 ----a-w- c:\windows\War3Unin.exe
2006-07-18 13:41 . 2006-06-17 17:32 1019094 -csha-r- c:\programmi\serial.tde
2008-04-29 17:39 . 2008-04-29 17:39 2 --shatr- c:\windows\winstart.bat
.
(((((((((((((((((((((((((((((
SnapShot@2009-10-29_17.59.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-07 10:29 . 2009-10-29 20:36 41984 c:\windows\system32\ZoneLabs\zlqrtdb.dat
- 2009-02-07 10:29 . 2009-10-27 20:01 41984 c:\windows\system32\ZoneLabs\zlqrtdb.dat
+ 2009-04-08 17:31 . 2009-10-29 22:18 888760 c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2009-04-08 17:19 . 2009-10-29 18:10 14093550 c:\windows\system32\ZoneLabs\spyware.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-16 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-16 81920]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2009-03-31 982408]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-12-04 1626112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-04-09 15360]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Reader Speed Launch.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [06/12/2005 16.11.18 35328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-10-29 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\programmi\Windows Live Toolbar\MSNTBUP.EXE [2006-10-10 22:25]
.
.
------- Scansione supplementare -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\programmi\Windows Live Toolbar\msntb.dll/search.htm
TCP: {C56E821E-41CB-40C6-86B7-952F2415CF8B} = 85.37.17.44,192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\hcoecvd7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: keyword.enabled - false
FF - plugin: c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\hcoecvd7.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-29 23:28
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1960408961-1284227242-839522115-1003\RemoteAccess\Profile\x *]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2384)
c:\programmi\iTunes\iTunesMiniPlayer.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\it.lproj\iTunesMiniPlayerLocalized.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\programmi\Windows Media Player\wmpband.dll
c:\windows\system32\msi.dll
.
Ora fine scansione: 2009-10-29 23.31.02
ComboFix-quarantined-files.txt 2009-10-29 22:31
ComboFix2.txt 2009-10-29 18:04
Pre-Run: 77.161.234.432 byte disponibili
Post-Run: 77.126.836.224 byte disponibili
- - End Of File - - CBB1D6744B393E68EB662DC10422E6CB