ComboFix 09-01-01.01 - Erik 2009-01-02 14:01:28.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.1022.582 [GMT 1:00]
Eseguito da: c:\documents and settings\Erik\Desktop\ComboFix.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\lxnlpktf.ini
c:\windows\system32\nbncpdcu.ini
c:\windows\system32\xieptecg.ini
----- BITS: Sites possivelmente infetados -----
hxxp://childhe.com
.
((((((((((((((((((((((((( Files Creati Da 2008-12-02 al 2009-01-02 )))))))))))))))))))))))))))))))))))
.
2009-01-01 00:19 . 2009-01-01 00:19 <DIR> d-------- c:\programmi\EG
2008-12-31 22:20 . 2008-12-31 22:20 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\Screaming Bee
2008-12-31 22:19 . 2008-12-31 22:19 <DIR> d-------- c:\programmi\Screaming Bee
2008-12-31 21:08 . 2008-12-31 21:08 <DIR> d-------- c:\programmi\Doctor Alex Antispyware
2008-12-30 15:39 . 2008-12-30 15:39 <DIR> d-------- c:\programmi\Winamp Toolbar
2008-12-30 15:39 . 2008-12-30 15:39 <DIR> d-------- c:\programmi\Winamp
2008-12-30 15:39 . 2008-12-30 15:41 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\Winamp
2008-12-30 15:39 . 2008-12-30 15:39 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Winamp Toolbar
2008-12-30 15:39 . 2007-03-08 00:51 129,784 --------- c:\windows\system32\pxafs.dll
2008-12-30 15:39 . 2007-03-08 00:51 9,464 --------- c:\windows\system32\drivers\cdralw2k.sys
2008-12-30 15:39 . 2007-03-08 00:51 9,336 --------- c:\windows\system32\drivers\cdr4_xp.sys
2008-12-28 05:07 . 2008-12-28 05:07 <DIR> d-------- c:\programmi\Enigma Software Group
2008-12-28 02:20 . 2008-12-28 02:20 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-12-28 02:20 . 2008-12-28 02:20 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\Malwarebytes
2008-12-28 02:20 . 2008-12-28 02:20 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-12-28 02:20 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-28 02:20 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-27 15:46 . 2008-12-27 15:46 <DIR> d-------- C:\VundoFix Backups
2008-12-27 15:24 . 2008-12-27 15:24 <DIR> d-------- c:\programmi\Avira
2008-12-27 15:24 . 2008-12-27 15:24 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Avira
2008-12-27 13:34 . 2008-12-27 13:34 <DIR> d-------- c:\programmi\CCleaner
2008-12-27 13:17 . 2008-12-27 13:17 <DIR> d-------- c:\programmi\Trend Micro
2008-12-26 18:20 . 2008-12-27 22:41 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\Twain
2008-12-24 02:14 . 2008-12-27 14:05 2 --a------ C:\-1071718278
2008-12-24 02:08 . 2008-12-24 02:28 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\Sports Interactive
2008-12-24 02:08 . 2008-12-24 02:08 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Sports Interactive
2008-12-24 02:07 . 2007-03-12 16:42 3,495,784 --a------ c:\windows\system32\d3dx9_33.dll
2008-12-24 01:58 . 2008-12-24 01:58 <DIR> d-------- c:\windows\Logs
2008-12-23 23:09 . 2008-12-23 23:09 <DIR> d-------- c:\programmi\Team JPN
2008-12-23 22:52 . 2008-12-23 22:52 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\DAEMON Tools Pro
2008-12-23 22:51 . 2008-12-24 12:08 <DIR> d-------- c:\programmi\DAEMON Tools Toolbar
2008-12-23 22:51 . 2008-12-23 22:51 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\DAEMON Tools Lite
2008-12-23 22:50 . 2008-12-23 22:52 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\DAEMON Tools Lite
2008-12-19 22:24 . 2008-12-19 22:24 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\PY_Software
2008-12-09 19:37 . 2008-12-09 19:37 <DIR> d-------- c:\programmi\Bit Che
2008-12-09 19:37 . 2008-12-09 19:37 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\Convivea
2008-12-09 19:37 . 2004-03-09 00:00 152,848 --a------ c:\windows\system32\comdlg32.OCX
2008-12-05 17:06 . 2008-12-05 17:10 <DIR> d-------- c:\programmi\UltraISO
2008-12-05 16:53 . 2008-12-05 17:01 <DIR> d-------- c:\programmi\WinISO
2008-12-05 14:24 . 2008-12-05 14:24 <DIR> d-------- c:\documents and settings\Erik\Dati applicazioni\ImgBurn
2008-12-05 14:23 . 2008-12-05 14:23 <DIR> d-------- c:\programmi\ImgBurn
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 12:54 --------- d-----w c:\documents and settings\Erik\Dati applicazioni\DNA
2009-01-02 11:34 --------- d-----w c:\programmi\DNA
2009-01-02 11:34 --------- d-----w c:\documents and settings\Erik\Dati applicazioni\OpenOffice.org2
2008-12-31 23:25 --------- d---a-w c:\documents and settings\All Users\Dati applicazioni\TEMP
2008-12-31 23:19 --------- d--h--w c:\programmi\InstallShield Installation Information
2008-12-31 23:19 --------- d-----w c:\documents and settings\Erik\Dati applicazioni\mIRC
2008-12-31 17:34 --------- d-----w c:\programmi\mIRC
2008-12-28 02:45 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-12-28 00:14 --------- d-----w c:\programmi\Spybot - Search & Destroy
2008-12-27 14:16 --------- d-----w c:\programmi\PC Registry Cleaner
2008-12-26 17:20 --------- d-----w c:\programmi\DAEMON Tools Lite
2008-12-23 22:20 --------- d-----w c:\documents and settings\Erik\Dati applicazioni\BitTorrent
2008-12-23 21:52 --------- d-----w c:\documents and settings\Erik\Dati applicazioni\DAEMON Tools
2008-12-20 11:15 --------- d-----w c:\programmi\eMule
2008-12-05 12:15 --------- d-----w c:\programmi\Astonsoft
2008-11-30 10:58 --------- d-----w c:\programmi\R-Drive Image
2008-11-25 13:33 --------- d-----w c:\programmi\Runtime Software
2008-11-22 18:58 --------- d-----w c:\documents and settings\Erik\Dati applicazioni\DeepBurner
2008-11-22 18:53 --------- d-----w c:\programmi\CDex_150
2008-11-22 18:46 --------- d-----w c:\programmi\FinalBurner
2008-11-21 21:20 --------- d-----w c:\programmi\BitTorrent
2008-11-21 21:19 --------- d-----w c:\programmi\AskSearch
2008-11-21 21:19 --------- d-----w c:\programmi\AskBarDis
2008-11-13 20:22 --------- d-----w c:\programmi\ManyCam 2.3
2008-11-08 12:36 --------- d-----w c:\programmi\TavoliVerdi
2008-10-27 09:04 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-10 03:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w c:\windows\system32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w c:\windows\system32\D3DCompiler_40.dll
1997-01-23 06:01 24,566 ----a-w c:\documents and settings\Erik\DISKCOPY.COM
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSN Webcam Recorder"="c:\programmi\MSN Webcam Recorder\ml20gui.exe" [2007-11-27 110592]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2004-10-13 1694208]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
"ManyCam"="c:\programmi\ManyCam 2.3\ManyCam.exe" [2008-10-14 1791272]
"BitTorrent DNA"="c:\programmi\DNA\btdna.exe" [2008-12-16 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 339968]
"Cpqset"="c:\programmi\HPQ\Default Settings\cpqset.exe" [2005-02-17 233534]
"HP Software Update"="c:\programmi\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2004-10-13 278528]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-05-12 98304]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"eabconfg.cpl"="c:\programmi\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 144784]
"hpWirelessAssistant"="c:\programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 794624]
"LogitechCommunicationsManager"="c:\programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 563984]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam\Quickcam.exe" [2007-07-25 2027792]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avgnt"="c:\programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"WinampAgent"="c:\programmi\Winamp\winampa.exe" [2008-08-04 36352]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\Erik\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 2.4.lnk - c:\programmi\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Software Bluetooth\BTTray.exe [2004-12-23 569405]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\mIRC\\mirc.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"c:\\Programmi\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Programmi\\TavoliVerdi\\TVControllo.exe"=
"c:\\Programmi\\DNA\\btdna.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2008-05-12 200192]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2008-09-07 21920]
S1 73b61b89;73b61b89;c:\windows\system32\drivers\73b61b89.sys []
S1 7d3d1b83;7d3d1b83;c:\windows\system32\drivers\7d3d1b83.sys []
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2008-07-13 13352]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
2009-01-02 c:\windows\Tasks\nnaacjxd.job
- c:\windows\system32\rundll32.exe [2004-08-19 14:39]
.
.
------- Supplementare di scansione -------
.
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Erik\Dati applicazioni\Mozilla\Firefox\Profiles\3z1r2rx8.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=
FF - component: c:\documents and settings\Erik\Dati applicazioni\Mozilla\Firefox\Profiles\3z1r2rx8.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\programmi\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - plugin: c:\programmi\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF - plugin: c:\programmi\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npbittorrent.dll
ATTENTION: FIREFOX POLICES IS IN FORCE pref(dom.disable_open_during_load, false);.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-02 14:03:51
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\HPQ\Default Settings\cpqset.exe????????????1?5?8?7??????? ???B?????????????hLC????????
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(772)
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2009-01-02 14:05:38
ComboFix-quarantined-files.txt 2009-01-02 13:04:40
Pre-Run: 12,415,311,872 byte disponibili
Post-Run: 12,434,632,704 byte disponibili
210 --- E O F --- 2008-10-25 10:36:54