ComboFix 08-12-06.06 - User 2008-12-07 19:35:54.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.1559 [GMT 1:00]
Eseguito da: c:\documents and settings\User\Desktop\ComboFix.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\User\Dati applicazioni\inst.exe
c:\windows\system32\Ati2evxx.dll
.
((((((((((((((((((((((((( Files Creati Da 2008-11-07 al 2008-12-07 )))))))))))))))))))))))))))))))))))
.
2008-12-07 18:52 . 2008-12-07 18:52 <DIR> d-------- C:\VundoFix Backups
2008-12-07 16:46 . 2008-08-30 12:11 40,960 --a------ c:\windows\system32\drivers\VIRAGTLT.SYS
2008-12-07 16:45 . 2008-12-07 17:06 <DIR> d-------- C:\VEXPLITE
2008-12-06 13:32 . 2008-12-06 18:01 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-12-06 13:32 . 2008-12-06 13:32 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\Malwarebytes
2008-12-06 13:32 . 2008-12-06 13:32 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-12-06 13:32 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-06 13:32 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-05 13:39 . 2008-12-05 13:39 <DIR> d-------- c:\programmi\smartision
2008-12-05 11:39 . 2008-12-05 12:13 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-12-05 11:39 . 2008-12-05 12:13 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-12-05 11:38 . 2008-12-05 11:38 <DIR> d-------- c:\programmi\Kaspersky Lab
2008-12-05 11:38 . 2008-12-07 17:21 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2008-12-05 11:38 . 2008-12-07 19:44 9,529,888 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-12-05 11:38 . 2008-12-07 19:39 131,792 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-12-05 11:38 . 2008-12-07 19:43 23,584 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-12-05 11:38 . 2008-12-07 19:39 4,232 --ahs---- c:\windows\system32\drivers\fidbox2.idx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-06 18:51 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Kiwee Toolbar
2008-12-05 11:14 112,144 ----a-w c:\windows\system32\drivers\kl1.sys
2008-12-03 12:02 --------- d-----w c:\documents and settings\User\Dati applicazioni\Ahead
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-11 17:48 --------- d-----w c:\documents and settings\User\Dati applicazioni\Nokia Multimedia Player
2008-10-11 17:18 --------- d-----w c:\programmi\Nokia
2008-05-25 12:29 47,360 ----a-w c:\documents and settings\User\Dati applicazioni\pcouffin.sys
2005-10-06 13:17 280,576 ----a-w c:\windows\inf\WG311v3\WG311v3XP.sys
2005-10-06 13:17 280,576 ----a-w c:\windows\inf\WG311v3\WG311v3.sys
2005-03-01 09:16 212,992 ----a-w c:\windows\inf\WG311v3\CopyWHQLDriver.exe
2004-03-11 12:27 40,960 ----a-w c:\programmi\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\programmi\Kiwee Toolbar\KiweeIEToolbar.dll" [2007-10-31 296256]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3984EB67-F783-46F3-885B-FB57400006F1}]
2008-11-12 22:15 120576 --a------ c:\windows\system32\dinput8t.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61B455B1-2A98-45C7-81F3-043BFAD57AFF}]
2004-08-19 13:00 106496 --a------ c:\windows\system32\ycqvimj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
2007-10-31 16:10 296256 --a------ c:\programmi\Kiwee Toolbar\KiweeIEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\programmi\Kiwee Toolbar\KiweeIEToolbar.dll" [2007-10-31 296256]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\programmi\Kiwee Toolbar\KiweeIEToolbar.dll" [2007-10-31 296256]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"AnyDVD"="c:\programmi\SlySoft\AnyDVD\AnyDVD.exe" [2007-04-01 344421]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-23 68856]
"PcSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-03 339968]
"RemoteControl"="c:\programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"TerraTec Remote Control"="c:\programmi\TerraTec\Cinergy 400 TV\TTTVRC.exe" [2002-05-21 204800]
"NSLauncher"="c:\programmi\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 2658304]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 57344]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"spc1000"="c:\windows\vspc1000.exe" [2007-07-12 675840]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"KiweeHook"="c:\programmi\Kiwee Toolbar\kwtbaim.exe" [2007-10-31 62776]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"VIRIT LITE MONITOR"="c:\vexplite\MONLITE.EXE" [2008-12-07 249856]
"Collegamento alla pagina delle proprietà di High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
"Picasa Media Detector"="c:\programmi\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
c:\documents and settings\User\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Kodak EasyShare software.lnk - c:\programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]
NETGEAR WG311v3 Smart Wizard.lnk - c:\windows\Installer\{70014586-7BBA-4A92-A610-CDC896C48F8F}\NewShortcut1_1.exe [2007-09-11 1078]
VPro1000.lnk - c:\windows\VPro1000.exe [2007-12-09 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xzkuhibg]
2004-08-19 13:00 106496 c:\windows\system32\ycqvimj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"vidc.dvsd"= pdvcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Programmi\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
R0 utehinhp;utehinhp;c:\windows\system32\drivers\utehinhp.sys [2004-08-19 23424]
R0 VIRAGTLT;VIRAGTLT;c:\windows\system32\drivers\VIRAGTLT.SYS [2008-12-07 40960]
R2 PMJ151NM;Panasonic DVC Web Camera;c:\windows\system32\DRIVERS\PMJ151NM.sys [2008-07-24 14848]
R2 rvsport;RVS Virtual COM Port;c:\windows\system32\drivers\rvsport.sys [2002-07-22 39936]
R2 viritsvclite;Virit eXplorer Lite;c:\vexplite\viritsvc.exe [2007-10-10 57344]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2007-02-10 1258432]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-04-04 24344]
R3 TTTvTune;Cinergy 400 TV Tuner;c:\windows\system32\DRIVERS\PhTvTune.sys [2007-02-10 16128]
R3 WDMWANMP;NDIS WAN miniport;c:\windows\system32\DRIVERS\wdmwanmp.sys [2004-02-18 29312]
S3 ISDN_u;ISDN USB CAPI;c:\windows\system32\DRIVERS\ISDN_u.sys [2004-04-01 755697]
S3 MTDVC;Panasonic DVC USB-SERIAL Driver for NT Technology;c:\windows\system32\DRIVERS\mtdv2ku1.sys [2008-07-24 12590]
S3 MTDVC_ENUM;Panasonic DVC COM Driver for NT Technology;c:\windows\system32\DRIVERS\mtdv2ks1.sys [2008-07-24 11569]
S3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2007-12-09 88320]
S3 RvscomSv;RvscomSv;c:\programmi\RVS\WCOM\SYSTEM\RVSCOMSV.EXE [2002-07-22 139313]
S3 SPC1000;USB2.0 PC Camera (SPC1000);c:\windows\system32\DRIVERS\spc1000.sys [2007-12-09 3033856]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ejxcnfmp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{71e70a2e-c2af-11db-a03d-487444737531}]
\Shell\AutoRun\command - G:\setupSNK.exe
.
Contenuto della cartella 'Scheduled Tasks'
2008-12-07 c:\windows\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- c:\programmi\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORFÃOS REMOVIDOS - - - -
Toolbar-ID - (no file)
HKCU-Run-Free Download Manager - c:\programmi\Free Download Manager\fdm.exe
HKCU-Run-55gz9zh9sozn - c:\windows\system32\55gz9zh9sozn.exe
HKCU-Run-Power2GoExpress - (no file)
HKCU-Run-PowerBar - (no file)
HKLM-Run-55gz9zh9sozn - c:\windows\system32\55gz9zh9sozn.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-07 19:41:02
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PMJ151LA]
"ImagePath"="%SystemRoot%\PMJ151LA.BIN"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(1012)
c:\windows\system32\MrvGINA.dll
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1068)
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
- - - - - - - > 'Explorer.exe'(3424)
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Netgear\WG311v3\WinDomainlogon.exe
c:\windows\system32\ati2evxx.exe
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\windows\PMJ151LA.BIN
c:\programmi\RVS\WCOM\SYSTEM\RVSINST.EXE
c:\programmi\Netgear\WG311v3\WinDomainlogon.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\winhlp32.exe
c:\programmi\File comuni\PCSuite\Services\ServiceLayer.exe
c:\programmi\Netgear\WG311v3\wlancfg5.exe
c:\progra~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
.
**************************************************************************
.
Ora fine scansione: 2008-12-07 19:47:19 - macchina è stato riavviato [User]
ComboFix-quarantined-files.txt 2008-12-07 18:47:10
Pre-Run: 12,444,848,128 byte disponibili
Post-Run: 12,482,080,768 byte disponibili
189 --- E O F --- 2008-11-12 21:09:23