ciao r16,ti aspettavo con ansia
nel task quel processo per fortuna non c'è
Ho scaricato combofix(è normale che gira in DOS?) questo è il log:
ComboFix 08-09-15.01 - k&k 2008-09-15 21.06.28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.1573 [GMT 2:00]
Eseguito da: C:\Documents and Settings\k&k\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((( Files Creati Da 2008-08-15 al 2008-09-15 )))))))))))))))))))))))))))))))))))
.
2008-09-15 14:50 . 2008-09-15 15:08 <DIR> d-------- C:\Programmi\DMW Client 3
2008-09-15 14:13 . 2008-09-15 15:05 <DIR> d-------- C:\Programmi\GameSpy Arcade
2008-09-15 14:12 . 2008-09-15 14:12 <DIR> d-------- C:\Programmi\EA GAMES
2008-09-15 14:07 . 2008-09-15 14:07 <DIR> d-------- C:\Programmi\Alcohol Soft
2008-09-15 14:06 . 2008-09-15 14:06 639,224 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-09-15 03:00 . 2008-09-15 03:00 <DIR> d-------- C:\Programmi\MSXML 4.0
2008-09-15 03:00 . 2008-09-15 03:02 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-09-15 01:58 . 2008-09-15 01:58 <DIR> d-------- C:\Programmi\Malwarebytes' Anti-Malware
2008-09-15 01:58 . 2008-09-15 01:58 <DIR> d-------- C:\Documents and Settings\k&k\Dati applicazioni\Malwarebytes
2008-09-15 01:58 . 2008-09-15 01:58 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2008-09-15 01:58 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-15 01:58 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-15 01:15 . 2008-09-15 01:15 <DIR> d-------- C:\Programmi\Trend Micro
2008-09-15 00:38 . 2008-09-15 00:45 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-09-15 00:38 . 2008-09-15 00:45 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-09-15 00:37 . 2008-09-15 00:37 <DIR> d-------- C:\Programmi\Kaspersky Lab
2008-09-15 00:37 . 2008-09-15 16:52 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-09-15 00:37 . 2008-09-15 21:08 1,035,808 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-15 00:37 . 2008-09-15 21:08 221,216 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-15 00:37 . 2008-09-15 21:08 9,172 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-15 00:37 . 2008-09-15 21:08 1,836 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-15 00:24 . 2008-09-15 00:24 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2008-09-14 18:37 . 2008-09-14 18:37 <DIR> d-------- C:\Programmi\File comuni\InstallShield
2008-09-14 18:37 . 2008-09-14 18:37 <DIR> d-------- C:\DriveKey
2008-09-14 17:20 . 2008-09-14 17:20 <DIR> d-------- C:\Programmi\UltraISO
2008-09-14 17:20 . 2008-09-14 17:20 <DIR> d-------- C:\Programmi\File comuni\EZB Systems
2008-09-14 17:06 . 2008-09-14 17:06 <DIR> d-------- C:\Documents and Settings\k&k\Dati applicazioni\Nero
2008-09-14 17:05 . 2008-09-14 17:06 <DIR> d-------- C:\Programmi\File comuni\Nero
2008-09-14 17:05 . 2008-09-14 17:05 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Nero
2008-09-14 17:02 . 2008-09-14 17:02 <DIR> d-------- C:\Programmi\Nero
2008-09-14 16:41 . 2008-09-14 16:41 <DIR> d-------- C:\Programmi\WinISO
2008-09-14 15:12 . 2008-09-14 15:12 <DIR> d-------- C:\Programmi\VideoLAN
2008-09-14 15:12 . 2008-09-14 15:12 <DIR> d-------- C:\Documents and Settings\k&k\Dati applicazioni\vlc
2008-09-14 13:30 . 2008-09-14 13:31 <DIR> d-------- C:\Documents and Settings\k&k\Dati applicazioni\DeepBurner
2008-09-14 13:29 . 2008-09-14 13:42 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-14 12:12 . 2008-09-14 23:28 <DIR> d--h----- C:\$AVG8.VAULT$
2008-09-14 11:29 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-09-14 11:29 . 2008-06-14 19:59 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-14 01:56 . 2008-09-15 03:02 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-09-14 01:56 . 2005-02-25 05:35 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-09-14 01:20 . 2008-09-15 17:02 <DIR> d-------- C:\Documents and Settings\k&k\Dati applicazioni\LimeWire
2008-09-14 01:17 . 2008-09-14 01:17 <DIR> d-------- C:\WINDOWS\Sun
2008-09-14 01:16 . 2008-09-14 01:16 <DIR> d-------- C:\Programmi\Java
2008-09-14 01:16 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-14 01:15 . 2008-09-14 01:15 <DIR> d-------- C:\Programmi\File comuni\Java
2008-09-14 01:11 . 2008-09-14 01:12 <DIR> d-------- C:\Programmi\LimeWire
2008-09-14 00:48 . 2007-11-22 16:00 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
2008-09-14 00:22 . 2008-09-14 00:22 <DIR> d-------- C:\Programmi\AbiSuite2
2008-09-14 00:22 . 2008-09-14 00:22 <DIR> d-------- C:\Documents and Settings\k&k\AbiSuite
2008-09-14 00:15 . 2008-09-14 00:15 <DIR> d-------- C:\Programmi\Astonsoft
2008-09-13 23:53 . 2008-09-13 23:53 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-13 23:18 . 2008-09-13 23:18 <DIR> d---s---- C:\Documents and Settings\k&k\UserData
2008-09-13 21:09 . 2008-09-13 21:09 <DIR> d-------- C:\Programmi\TVUPlayer
2008-09-13 21:09 . 2008-09-13 21:09 <DIR> d-------- C:\Documents and Settings\k&k\LocalLow
2008-09-13 21:09 . 2008-09-13 21:09 <DIR> d-------- C:\Documents and Settings\k&k\Dati applicazioni\TVU Networks
2008-09-13 21:09 . 2008-09-13 21:09 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\TVU Networks
2008-09-13 21:08 . 2008-09-14 20:59 <DIR> d-------- C:\Programmi\TVAnts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 12:56 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-09-14 22:22 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\avg8
2008-09-13 18:41 --------- d-----w C:\Programmi\Veoh Networks
2008-09-13 18:40 --------- d-----w C:\Programmi\File comuni\Adobe
2008-09-13 18:14 --------- d-----w C:\Programmi\CCleaner
2008-09-13 16:38 --------- d-----w C:\Programmi\microsoft frontpage
2008-09-13 16:37 --------- d-----w C:\Programmi\Servizi in linea
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:38 662,016 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:39 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"Veoh"="C:\Programmi\Veoh Networks\Veoh\VeohClient.exe" [2008-08-28 3660848]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-07 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-07 81920]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroFilterCheck"="C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"DmwClient"="C:\Programmi\DMW Client 3\dmwclient.exe" [2008-09-15 337408]
"AVP"="C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-25 C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2007-10-11 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Programmi\\LimeWire\\LimeWire.exe"=
"C:\\Programmi\\TVAnts\\Tvants.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\autorun.exe
.
- - - - ORFÇOS REMOVIDOS - - - -
HKLM-Run-BearShare - C:\Programmi\BearShare\BearShare.exe
HKLM-Run-in3 - C:\Documents and Settings\k&k\Impostazioni locali\Temp\.tt18.tmp.exe
HKLM-Run-nwiz - nwiz.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\k&k\Dati applicazioni\Mozilla\Firefox\Profiles\afuzzc8g.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.google.itFF -: plugin - C:\Programmi\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-15 21:09:21
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Ora fine scansione: 2008-09-15 21:10:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-15 19:10:52
Pre-Run: 309,431,562,240 byte disponibili
Post-Run: 310,571,466,752 byte disponibili
157 --- E O F --- 2008-09-15 01:02:29