ti posto i log
ComboFix 08-06-05.3 - Augusto 2008-06-06 22.29.47.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1651 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Utente\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Creati Da 2008-05-06 al 2008-06-06 )))))))))))))))))))))))))))))))))))
.
2008-06-05 23:06 . 2008-06-06 22:31 165,920 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-05 23:06 . 2008-06-06 22:26 2,540 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-05 18:44 . 2008-06-05 19:15 <DIR> d-------- C:\VEXPLITE
2008-06-05 18:44 . 2008-03-17 19:23 39,808 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-06-03 23:06 . 2008-06-03 23:06 <DIR> d-------- C:\Programmi\Trend Micro
2008-06-03 22:08 . 2008-06-03 22:08 <DIR> d-------- C:\Programmi\AVG
2008-06-03 22:08 . 2008-06-03 22:08 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-15 22:50 . 2008-05-15 22:50 1,374 --a------ C:\WINDOWS\imsins.BAK
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 21:53 --------- d-----w C:\Documents and Settings\Utente\Dati applicazioni\Skype
2008-06-02 14:30 --------- d-----w C:\Documents and Settings\Utente\Dati applicazioni\skypePM
2008-06-01 17:31 --------- d-----w C:\Programmi\Java
2008-05-27 18:48 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Grisoft
2008-05-02 21:06 --------- d-----w C:\Programmi\File comuni\Skype
2008-04-26 21:40 --------- d-----w C:\Documents and Settings\Utente\Dati applicazioni\vlc
2008-04-26 21:37 --------- d-----w C:\Programmi\VideoLAN
2008-04-13 20:08 --------- d-----w C:\Programmi\SlySoft
2008-04-13 20:07 --------- d-----w C:\Programmi\Elaborate Bytes
2008-04-12 14:24 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Elaborate Bytes
2008-04-12 14:22 --------- d-----w C:\Documents and Settings\Utente\Dati applicazioni\SlySoft
2008-04-10 17:53 --------- d-----w C:\Programmi\DivX
2008-04-07 20:54 --------- d-----w C:\Programmi\Google
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 183,072 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:06 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2007-11-17 17:39 32 ----a-w C:\Documents and Settings\All Users\Dati applicazioni\ezsid.dat
2007-09-02 16:45 47,360 ------w C:\Documents and Settings\Utente\Dati applicazioni\pcouffin.sys
.
------- Sigcheck -------
2005-03-02 20:12 2060672 de16030e8209fd96eeb06d9e3d8c84a8 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2007-02-28 18:06 2063104 f89d8e24fbe047506d60b850d00bdee3 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2004-08-30 22:00 2060544 4dc3a3626b02c39aa69aae6f64bfbc2d C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-02 20:06 2060544 8f485cf9683f1220ba27d10281052fce C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 18:02 2061312 49baea1d9379df8cd897aff9f49bc9de C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2007-02-28 18:02 2061312 75c9351d7ce9ee0d6b8d54f2b06ce4f9 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 18:02 2061312 49baea1d9379df8cd897aff9f49bc9de C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
.
(((((((((((((((((((((((((((((
snapshot@2008-06-05_20.40.21,34 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-05 18:24:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-06 20:27:37 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2007-07-05 12:34:52 134,160 ----a-w C:\WINDOWS\system32\drivers\klif.sys
+ 2004-08-30 20:00:00 36,096 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\i386\isapnp.sys
+ 2004-08-30 20:00:00 95,360 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0002\DriverFiles\i386\atapi.sys
+ 2004-08-30 20:00:00 3,328 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0002\DriverFiles\i386\pciide.sys
+ 2004-08-30 20:00:00 25,088 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0002\DriverFiles\i386\pciidex.sys
+ 2004-08-03 21:59:44 95,360 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0003\DriverFiles\i386\atapi.sys
+ 2001-08-30 20:54:58 3,328 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0003\DriverFiles\i386\pciide.sys
+ 2004-08-03 21:59:42 25,088 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0003\DriverFiles\i386\pciidex.sys
+ 2004-08-30 20:00:00 57,600 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\usbhub.sys
+ 2004-08-30 20:00:00 142,976 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\usbport.sys
+ 2004-08-30 20:00:00 20,480 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\usbuhci.sys
+ 2004-08-19 15:39:30 76,800 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\usbui.dll
+ 2004-08-03 22:08:44 57,600 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0005\DriverFiles\i386\usbhub.sys
+ 2004-08-03 22:08:44 142,976 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0005\DriverFiles\i386\usbport.sys
+ 2004-08-03 22:08:38 20,480 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0005\DriverFiles\i386\usbuhci.sys
+ 2004-08-19 14:39:30 76,800 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0005\DriverFiles\i386\usbui.dll
+ 2004-08-03 22:08:44 57,600 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0006\DriverFiles\i386\usbhub.sys
+ 2004-08-03 22:08:44 142,976 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0006\DriverFiles\i386\usbport.sys
+ 2004-08-03 22:08:38 20,480 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0006\DriverFiles\i386\usbuhci.sys
+ 2004-08-19 14:39:30 76,800 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0006\DriverFiles\i386\usbui.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-30 22:00 15360]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-16 21:51 68856]
"NBJ"="C:\Programmi\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 19:25 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 06:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 06:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 06:17 118784]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 08:54 16248320 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"RemoteControl"="C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 20:42 32768]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" []
"OrderReminder"="C:\Programmi\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 18:00 98304]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-06-30 16:56 2376928]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-06-05 18:47 245760]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-30 22:00 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IETI"="C:\Programmi\Skype\Phone\IEPlugin\unins000.exe" [ ]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23100:TCP"= 23100:TCP:BitComet 23100 TCP
"23100:UDP"= 23100:UDP:BitComet 23100 UDP
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 19:23]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-03 22:08]
R2 setup_7.0.0.180_18.05.2008_22-36;setup_7.0.0.180_18.05.2008_22-36;"C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_18.05.2008_22-36.exe" -r []
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-06-05 18:47]
R3 PAC207;Trust WB-1200p Mini Webcam;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 12:29]
S1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys []
S2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-06 22:31:20
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-06-06 22.32.11
ComboFix-quarantined-files.txt 2008-06-06 20:32:05
ComboFix2.txt 2008-06-05 18:40:35
10 Directory 71,962,705,920 byte disponibili
13 Directory 71,952,474,112 byte disponibili
134 --- E O F --- 2008-05-16 22:45:27
quello di avenger
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.comPlatform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: folder "C:\WINDOWS\system32\drivers\Avg" not found!
Deletion of folder "C:\WINDOWS\system32\drivers\Avg" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: folder "C:\WINDOWS\AVG" not found!
Deletion of folder "C:\WINDOWS\AVG" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist