ho rifatto il log con combofix cmq ho notato, che il programma parte con lo scan in automatico, senza che io digiti uno e invio, in pratica avvio il programma e fa tutto lui....è normale? può darsi che è per questo che risulta incompleto?
cmq sotto inserisco il log:
ComboFix 08-06-20.4 - Administrator 2008-06-25 9.55.12.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.595 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Creati Da 2008-05-25 al 2008-06-25 )))))))))))))))))))))))))))))))))))
.
2008-06-25 09:25 . 2008-06-25 09:25 <DIR> d-------- C:\Programmi\GiPo@Utilities
2008-06-25 09:25 . 2008-06-25 09:25 <DIR> d-------- C:\Programmi\File comuni\Gibinsoft Shared
2008-06-24 20:04 . 2008-06-24 20:04 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-06-24 20:04 . 2008-06-24 20:04 <DIR> d-------- C:\Programmi\microsoft frontpage
2008-06-24 20:01 . 2008-06-24 20:04 <DIR> d-------- C:\VEXPLITE
2008-06-24 20:01 . 2008-03-17 19:23 39,808 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-06-18 11:18 . 2008-06-22 19:56 <DIR> d-------- C:\Programmi\Full Tilt Poker
2008-06-17 17:43 . 2008-06-17 17:43 <DIR> d-------- C:\Programmi\Opera
2008-06-16 14:58 . 2008-06-16 14:58 <DIR> d-------- C:\Programmi\Foxit Software
2008-06-16 14:13 . 2008-06-16 14:13 <DIR> d-------- C:\Programmi\Trend Micro
2008-06-16 10:38 . 2008-06-16 10:38 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\TuneUp Software
2008-06-16 10:38 . 2008-06-16 10:38 <DIR> d-------- C:\Documents and Settings\Administrator\Dati applicazioni\TuneUp Software
2008-06-16 10:38 . 2008-06-16 10:40 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-06-16 10:38 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-06-16 10:37 . 2008-06-16 10:40 <DIR> d-------- C:\Programmi\TuneUp Utilities 2008
2008-06-16 10:37 . 2008-06-16 10:37 <DIR> d-------- C:\Programmi\File comuni\Wise Installation Wizard
2008-06-16 00:13 . 2008-06-16 10:26 <DIR> d-------- C:\WINDOWS\system32\RegVac
2008-06-16 00:11 . 2008-06-23 16:42 <DIR> d-------- C:\Programmi\RegVac Registry Cleaner
2008-06-16 00:03 . 2008-06-16 00:09 <DIR> d-------- C:\Programmi\Error Repair Professional
2008-06-15 21:09 . 2008-06-23 15:58 <DIR> d-------- C:\Programmi\Malwarebytes' Anti-Malware
2008-06-15 21:09 . 2008-06-15 21:09 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2008-06-15 21:09 . 2008-06-15 21:09 <DIR> d-------- C:\Documents and Settings\Administrator\Dati applicazioni\Malwarebytes
2008-06-15 21:09 . 2008-06-11 15:00 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-15 21:09 . 2008-06-11 15:00 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 14:19 . 2008-06-16 14:20 <DIR> d-a------ C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-06-12 13:55 . 2008-06-12 13:55 30,946 --a------ C:\WINDOWS\system32\drivers\Partizan.sys
2008-06-12 13:55 . 2008-06-12 13:55 28,672 --a------ C:\WINDOWS\system32\Partizan.exe
2008-06-10 11:15 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2008-06-10 11:15 . 2006-12-08 12:02 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2008-06-10 11:00 . 2008-06-10 11:01 <DIR> d-------- C:\Programmi\Disk Cleaner
2008-06-10 10:36 . 2008-06-10 10:36 <DIR> d-------- C:\Programmi\VS Revo Group
2008-06-05 17:12 . 2008-06-05 17:12 <DIR> d-------- C:\WINDOWS\C6 Messenger
2008-06-05 17:12 . 2008-06-07 14:51 1,397 --a------ C:\logSeg.html
2008-06-02 22:52 . 2008-06-25 09:37 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-06-02 22:52 . 2008-06-25 09:56 9,857,824 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-02 22:52 . 2008-06-25 09:36 132,596 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-02 22:52 . 2008-06-25 09:56 124,192 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-02 22:52 . 2008-06-02 23:32 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-06-02 22:52 . 2008-06-02 23:32 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-06-02 22:52 . 2008-06-25 09:36 12,500 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-28 16:35 . 2008-05-28 16:35 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2008-05-26 20:58 . 2008-05-26 20:58 271,360 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2008-05-26 20:58 . 2008-05-26 20:58 18,048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-24 14:54 --------- d-----w C:\Programmi\Winamp
2008-06-22 16:47 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\uTorrent
2008-06-18 09:18 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-06-16 17:04 35,328 ----a-w C:\WINDOWS\system32\cygz.dll
2008-06-16 17:04 35,328 ----a-w C:\WINDOWS\cygz.dll
2008-06-16 17:04 1,126,281 ----a-w C:\WINDOWS\system32\cygwin1.dll
2008-06-16 17:04 1,126,281 ----a-w C:\WINDOWS\cygwin1.dll
2008-06-16 12:27 --------- d-----w C:\Programmi\Easy Duplicate Finder
2008-06-13 21:32 --------- d-----w C:\Programmi\eMule
2008-06-08 18:20 --------- d-----w C:\Programmi\Google
2008-06-07 23:26 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Downloaded Installations
2008-06-07 12:51 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-06-02 21:32 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-06-02 20:52 --------- d-----w C:\Programmi\Kaspersky Lab
2008-05-15 08:30 --------- d-----w C:\Programmi\capcom
2008-04-29 19:29 --------- d-----w C:\Programmi\IObit
.
(((((((((((((((((((((((((((((
snapshot@2008-06-24_12.57.12.35 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-24 07:45:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-25 07:36:35 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-25 07:25:11 55,808 ----a-r C:\WINDOWS\Installer\{E2B64929-B616-4235-B10E-D26D686296F9}\Icon8FD64119.exe
+ 2008-06-25 07:25:11 14,336 ----a-r C:\WINDOWS\Installer\{E2B64929-B616-4235-B10E-D26D686296F9}\Icon8FD641194.exe
+ 2008-06-25 07:25:11 14,336 ----a-r C:\WINDOWS\Installer\{E2B64929-B616-4235-B10E-D26D686296F9}\IconD233FA331.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"mount.exe"="C:\Programmi\GiPo@Utilities\FileUtilities.3\mount.exe" [2008-04-11 16:17 374272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-05-17 12:48 77824 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-29 16:25 7626752]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-06-29 16:25 86016]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 15:21 61952 C:\WINDOWS\system32\HdAShCut.exe]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-06-24 20:02 245760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.VP31"= vp31vfw.dll
"vidc.DIV3"= DivXc32.dll
"msacm.divxa32"= DivXa32.acm
"vidc.xvid"= xvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\explorer.exe]
Debugger="c:\windows\system32\ehpimfho.ico"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\Programmi\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Programmi\\Download Express\\dep.exe"=
"C:\\Programmi\\NetMeeting\\conf.exe"=
"C:\\Programmi\\uTorrent\\utorrent.exe"=
"C:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\Programmi\\MSN Messenger\\bak\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\Sports Interactive\\Football Manager 2008\\fm.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5762:TCP"= 5762:TCP:ppLive
"6344:UDP"= 6344:UDP:ppLive
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 19:23]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-19 15:39]
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-06-24 20:02]
R3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2005-11-13 11:50]
R3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2005-11-13 11:50]
R3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgN.sys [2005-11-13 11:50]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S2 ADSLAutoconnect;ADSLAutoconnect;"C:\Programmi\ADSL Autoconnect\ADSL Autoconnect.exe" -z []
S3 MEMSWEEP2;MEMSWEEP2;C:\WINDOWS\system32\20.tmp []
S3 PAC207;Trust WB-1200p Mini Webcam;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 12:29]
S3 Partizan;Partizan;C:\WINDOWS\system32\drivers\Partizan.sys [2008-06-12 13:55]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-16 10:40]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{073d202a-6907-11dc-a95c-001a926e3854}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contenuto della cartella 'Scheduled Tasks'
"2008-06-25 07:36:42 C:\WINDOWS\Tasks\mabfhm.job"
- c:\windows\system32\modtuntq.exe
"2008-06-25 07:36:43 C:\WINDOWS\Tasks\Verifica e correzione automatica.job"
- C:\Programmi\TuneUp Utilities 2008\OneClickStarter.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-25 09:56:36
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\C:\WINDOWS\system32\20.tmp"
.
Ora fine scansione: 2008-06-25 9.57.29
ComboFix-quarantined-files.txt 2008-06-25 07:57:17
ComboFix2.txt 2008-06-24 10:57:40
29 Directory 49,480,495,104 byte disponibili
32 Directory 49,469,456,384 byte disponibili
164