Ciao R16 ecco il log. di combofix
ComboFix 09-06-20.04 - standard 21/06/2009 12.49.41.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.767.381 [GMT 2:00]
Eseguito da: e:\documents and settings\standard\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat
e:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat
C:\InfoSat.txt
----- BITS: Possibili siti infetti -----
hxxp://sunmicro.ht.rd.llnw.net
.
((((((((((((((((((((((((( Files Creati Da 2009-05-21 al 2009-06-21 )))))))))))))))))))))))))))))))))))
.
2009-06-17 17:10 . 2009-06-21 09:22 -------- d-----w- E:\FindyKill
2009-06-16 20:35 . 2009-05-26 11:20 40160 ----a-w- e:\windows\system32\drivers\mbamswissarmy.sys
2009-06-16 20:35 . 2009-06-16 20:35 -------- d-----w- e:\programmi\Malwarebytes' Anti-Malware
2009-06-16 20:35 . 2009-05-26 11:19 19096 ----a-w- e:\windows\system32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 10:56 . 2009-04-21 16:46 -------- d-----w- e:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-06-21 10:53 . 2009-04-21 16:46 4716 --sha-w- e:\windows\system32\drivers\fidbox2.idx
2009-06-21 10:53 . 2009-04-21 16:46 450592 --sha-w- e:\windows\system32\drivers\fidbox2.dat
2009-06-21 10:53 . 2009-04-21 16:46 3515936 --sha-w- e:\windows\system32\drivers\fidbox.dat
2009-06-21 10:53 . 2009-04-21 16:46 30644 --sha-w- e:\windows\system32\drivers\fidbox.idx
2009-06-21 10:44 . 2007-07-07 10:18 -------- d-----w- e:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-06-21 09:18 . 2009-01-15 23:22 -------- d---a-w- e:\documents and settings\All Users\Dati applicazioni\TEMP
2009-06-21 09:18 . 2009-01-15 23:21 -------- d-----w- e:\programmi\SpywareBlaster
2009-06-17 17:31 . 2001-08-31 15:00 64156 ----a-w- e:\windows\system32\perfc010.dat
2009-06-17 17:31 . 2001-08-31 15:00 428288 ----a-w- e:\windows\system32\perfh010.dat
2009-06-10 22:38 . 2008-10-24 13:56 -------- d-----w- e:\documents and settings\standard\Dati applicazioni\uTorrent
2009-05-20 13:59 . 2009-04-21 16:47 94643 ----a-w- e:\windows\system32\drivers\klick.dat
2009-05-20 13:59 . 2009-04-21 16:47 105395 ----a-w- e:\windows\system32\drivers\klin.dat
2009-05-16 06:48 . 2007-10-14 14:42 -------- d-----w- e:\documents and settings\standard\Dati applicazioni\Vso
2009-05-07 15:32 . 2004-08-19 13:39 347648 ----a-w- e:\windows\system32\localspl.dll
2009-04-29 04:33 . 2004-08-19 13:39 669184 ----a-w- e:\windows\system32\wininet.dll
2009-04-29 04:33 . 2004-08-19 13:39 81920 ----a-w- e:\windows\system32\ieencode.dll
2009-04-21 16:56 . 2008-01-29 16:29 33808 ----a-w- e:\windows\system32\drivers\klbg.sys
2009-04-19 19:47 . 2004-08-19 13:31 1847168 ----a-w- e:\windows\system32\win32k.sys
2009-04-15 14:52 . 2004-08-19 13:39 585216 ----a-w- e:\windows\system32\rpcrt4.dll
2008-02-18 23:07 . 2008-02-18 23:08 9119744 ----a-w- e:\programmi\Trust CP-2300 Webcam.msi
2008-02-18 23:07 . 2008-02-18 23:08 44544 ----a-w- e:\programmi\1040.MST
2008-02-18 23:07 . 2008-02-18 23:08 5186 ----a-w- e:\programmi\
0x0410.ini
2004-10-01 13:00 . 2007-04-18 08:18 40960 ----a-w- e:\programmi\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="e:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="e:\programmi\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"CTSyncU.exe"="e:\programmi\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-28 700416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="e:\programmi\VIA\RAID\raid_tool.exe" [2005-04-28 589824]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"NeroFilterCheck"="e:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"PAC7311_Monitor"="e:\windows\PixArt\PAC7311\Monitor.exe" [2006-11-03 319488]
"WinPatrol"="e:\programmi\BillP Studios\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"SunJavaUpdateSched"="e:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"EverioService"="e:\programmi\CyberLink\PCM4Everio\EverioService.exe" [2008-04-03 151552]
"AVP"="e:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-04-21 201992]
"nwiz"="nwiz.exe" - e:\windows\system32\nwiz.exe [2007-12-05 1626112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
e:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - e:\programmi\D-Link\Bluetooth Software\BTTray.exe [2006-4-12 643133]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0pgdfgsvc E 1
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="e:\programmi\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\Programmi\\Messenger\\msmsgs.exe"=
"e:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"e:\\Programmi\\MSN Messenger\\livecall.exe"=
"e:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"e:\\Programmi\\eMule\\emule.exe"=
"e:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\italian\\setup.exe"=
"e:\\Programmi\\Malwarebytes' Anti-Malware\\mbam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"38260:TCP"= 38260:TCP:*:Disabled:bittorrent
"48870:TCP"= 48870:TCP:*:Disabled:utorrent
R0 klbg;Kaspersky Lab Boot Guard Driver;e:\windows\system32\drivers\klbg.sys [29/01/2008 18.29.38 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;e:\windows\system32\drivers\klim5.sys [25/03/2008 20.07.10 24592]
R3 PAC7311;Trust CP-2300 Webcam;e:\windows\system32\drivers\PA707UCM.SYS [14/03/2007 11.57.56 449024]
S3 AIDA32Driver;AIDA32Driver;\??\e:\programmi\AIDA32 - Enterprise System Information\aida32.sys --> e:\programmi\AIDA32 - Enterprise System Information\aida32.sys [?]
S3 cpuz;cpuz;\??\e:\docume~1\standard\IMPOST~1\Temp\cpuz.sys --> e:\docume~1\standard\IMPOST~1\Temp\cpuz.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
2009-05-08 e:\windows\Tasks\AppleSoftwareUpdate.job
- e:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-01-10 13:42]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - e:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Invia a periferica &Bluetooth... - e:\programmi\D-Link\Bluetooth Software\btsendto_ie_ctx.htm
LSP: e:\windows\system32\imon.dll
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-21 12:56
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RaidTool = e:\programmi\VIA\RAID\raid_tool.exe??\??
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1388)
e:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1468)
e:\windows\system32\imon.dll
- - - - - - - > 'explorer.exe'(504)
e:\programmi\BillP Studios\WinPatrol\PATROLPRO.DLL
e:\progra~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
e:\programmi\File comuni\Microsoft Shared\Web Components\10\1040\OWCI10.DLL
e:\progra~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
e:\programmi\File comuni\Microsoft Shared\Web Components\11\1040\OWCI11.DLL
e:\windows\system32\imon.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
e:\programmi\D-Link\Bluetooth Software\bin\btwdins.exe
e:\windows\system32\CTSVCCDA.EXE
e:\programmi\FolderSize\FolderSizeSvc.exe
e:\programmi\Java\jre6\bin\jqs.exe
e:\programmi\File comuni\LightScribe\LSSrvc.exe
e:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
e:\windows\system32\nvsvc32.exe
e:\windows\system32\wdfmgr.exe
e:\windows\system32\wscntfy.exe
e:\windows\system32\rundll32.exe
.
**************************************************************************
.
Ora fine scansione: 2009-06-21 13.00.04 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-06-21 11:00
Pre-Run: 9.134.260.224 byte disponibili
Post-Run: 9.072.050.176 byte disponibili
167 --- E O F --- 2009-06-10 17:22