ComboFix 10-01-25.06 - Alessandro 26/01/2010 13.40.54.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.511.244 [GMT 1:00]
Eseguito da: c:\documents and settings\Alessandro\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {FFFFFFFC-0002-0000-6008-B00D4CEE1200}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000000-0000-0000-0000-000000000000}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Alessandro\Dati applicazioni\Desktopicon
c:\documents and settings\Alessandro\Dati applicazioni\Desktopicon\config.ini
c:\documents and settings\Alessandro\Impostazioni locali\Dati applicazioni\eieyoqo_nav.dat
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\QTWMCI32.DLL
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
((((((((((((((((((((((((( Files Creati Da 2009-12-26 al 2010-01-26 )))))))))))))))))))))))))))))))))))
.
2010-01-23 14:22 . 2009-12-21 19:06 11070464 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-01-19 17:19 . 2010-01-19 17:19 -------- d--h--w- c:\windows\PIF
2010-01-12 20:29 . 2009-10-15 16:29 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-01-12 20:29 . 2009-10-15 16:29 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-01-12 18:34 . 2009-11-21 15:54 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 13:18 . 2010-01-18 14:14 -------- d-----w- c:\programmi\SokkerViewer
2010-01-08 13:18 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 13:18 . 2010-01-08 13:18 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-08 13:18 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-08 13:13 . 2010-01-08 13:13 -------- d-----w- c:\programmi\Trend Micro
2010-01-06 17:10 . 2010-01-06 17:10 -------- d-----w- c:\documents and settings\ANNA\Dati applicazioni\OpenOffice.org
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 21:01 . 2009-01-14 13:32 -------- d-----w- c:\documents and settings\Alessandro\Dati applicazioni\uTorrent
2010-01-25 18:42 . 2009-02-11 08:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2010-01-21 13:43 . 2008-11-26 14:08 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-01-18 13:34 . 2008-10-28 18:09 -------- d-----w- c:\programmi\Google
2010-01-07 19:45 . 2001-12-04 12:00 79292 ----a-w- c:\windows\system32\perfc010.dat
2010-01-07 19:45 . 2001-12-04 12:00 478808 ----a-w- c:\windows\system32\perfh010.dat
2010-01-07 19:37 . 2009-11-04 17:29 -------- d-----w- c:\documents and settings\Alessandro\Dati applicazioni\KoshyJohn.com
2009-12-21 19:06 . 2001-12-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 13:05 . 2005-12-05 17:59 79744 -c--a-w- c:\documents and settings\Alessandro\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-12-18 18:40 . 2009-12-18 18:40 -------- d-----w- c:\documents and settings\Alessandro\Dati applicazioni\OpenOffice.org
2009-12-18 18:36 . 2009-12-18 18:36 -------- d-----w- c:\programmi\JRE
2009-12-18 18:36 . 2009-12-18 18:36 -------- d-----w- c:\programmi\OpenOffice.org 3
2009-12-18 18:34 . 2009-01-13 15:15 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-18 18:34 . 2009-12-18 18:34 -------- d-----w- c:\programmi\Java
2009-12-13 13:57 . 2009-12-13 13:57 -------- d-----w- c:\programmi\SigmaTel
2009-12-13 13:57 . 2005-11-28 18:43 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-12-10 17:56 . 2009-12-01 16:08 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-01 20:23 . 2008-09-01 16:01 -------- d-----w- c:\programmi\Idoru
2009-12-01 18:19 . 2009-12-01 18:19 -------- d-----w- c:\programmi\IObit
2009-12-01 16:08 . 2009-12-01 16:08 -------- d-----w- c:\programmi\Avira
2009-12-01 16:08 . 2009-12-01 16:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-11-29 16:20 . 2009-11-29 16:20 -------- d-----w- c:\documents and settings\Alessandro\Dati applicazioni\BERNINA My Label
2009-11-21 15:54 . 2001-12-04 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-13 13:31 . 2009-11-13 13:31 49152 ----a-r- c:\windows\system32\inetwh32.dll
2009-11-13 13:31 . 2009-11-13 13:31 1044480 ----a-r- c:\windows\system32\roboex32.dll
.
------- Sigcheck -------
[-] 2009-03-23 . 90F406811EE1EEE294792D00E21CA16C . 510464 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[7] 2008-04-13 . 9259170D29B5A256735FCB8B80280857 . 510464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2005-11-28 . 1DBD3966123AC2F6ADE783F7F17F8C7F . 504832 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2009-04-01 17:16 193472 ------w- c:\programmi\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\ANNA\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.1.lnk - c:\programmi\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\combofix]
c:\combofix\CF24468.cfxxe [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX5000 Series]
2006-09-22 04:01 139264 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBVE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2002-07-17 06:45 90112 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2002-07-17 06:59 143360 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSN"=c:\programmi\MSN\MSNCoreFiles\MSN6.EXE -email
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" -autorun
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [22/01/2009 20.07.56 721904]
R2 athsgt;athsgt;c:\windows\system32\drivers\athsgt.sys [08/01/2006 20.18.39 164992]
R2 limsgt;limsgt;c:\windows\system32\drivers\limsgt.sys [08/01/2006 20.18.38 12544]
S2 gupdate1c98c21930495f0;Google Update Service (gupdate1c98c21930495f0);c:\programmi\Google\Update\GoogleUpdate.exe [11/02/2009 9.20.13 133104]
S3 iAimFP8;iAimFP8;c:\windows\system32\drivers\wADV11nt.sys [27/11/2005 19.43.23 11935]
S3 mousesystems;Windows Serial MouseSystems Mouse;c:\windows\system32\drivers\mousesys.sys [17/10/2006 18.24.14 14225]
S3 netr73;D-Link DWA-111 Wireless G USB Adapter Driver;c:\windows\system32\drivers\netr73.sys [15/11/2008 13.33.03 256000]
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-26 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-11 23:53]
2010-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-11 08:19]
2010-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-11 08:19]
2009-12-01 c:\windows\Tasks\SmartDefrag.job
- c:\programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-12-01 12:48]
2010-01-26 c:\windows\Tasks\Windows Messenger.job
- c:\progra~1\MESSEN~1\msmsgs.exe [2005-11-27 18:14]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Alessandro\Dati applicazioni\Mozilla\Firefox\Profiles\d5pc48v1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - hxxp://www.daemon-search.com/startpage
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\documents and settings\Alessandro\Dati applicazioni\Mozilla\Firefox\Profiles\d5pc48v1.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\documents and settings\Alessandro\Dati applicazioni\Mozilla\Firefox\Profiles\d5pc48v1.default\extensions\{2bae58c2-79f9-45d1-a286-81f911301c3a}\components\FFAlert.dll
FF - component: c:\documents and settings\Alessandro\Dati applicazioni\Mozilla\Firefox\Profiles\d5pc48v1.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{2BAE58C2-79F9-45D1-A286-81F911301C3A} - (no file)
WebBrowser-{DA30EFF8-CCC6-4162-A20D-67402A26A215} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-HijackThis - d:\super_pi\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-26 14:03
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync04.sys atapi.sys spor.sys >>UNKNOWN [0x82F8E938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf8732f28
\Driver\ACPI -> ACPI.sys @ 0xf858ccb8
\Driver\atapi -> sfsync04.sys @ 0xf8564a7c
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: Connessione di rete Intel(R) PRO/100 -> SendCompleteHandler -> NDIS.sys @ 0xf843ebb0
PacketIndicateHandler -> NDIS.sys @ 0xf844ba21
SendHandler -> NDIS.sys @ 0xf842987b
user & kernel MBR OK
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2392)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-26 14:13:12 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-26 13:13
Pre-Run: 21.098.024.960 byte disponibili
Post-Run: 21.306.114.048 byte disponibili
WindowsXP-KB310994-SP2-Home-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 0A9F5C95046676D8328FD928DAA2B243