ComboFix 08-08-11.01 - thething 2008-08-12 18:34:51.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.300 [GMT 2:00]
Eseguito da: C:\Documents and Settings\thething\Desktop\ComboFix.exe
[color=red][b]ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !![/b][/color]
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000011_.tmp.dll
C:\WINDOWS\system32\_000012_.tmp.dll
C:\WINDOWS\system32\appcert
C:\WINDOWS\system32\hdaqxxb.dll . . . . Eliminazione Fallita
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RJRYXSJA
-------\Service_rjryxsja
((((((((((((((((((((((((( Files Creati Da 2008-07-12 al 2008-08-12 )))))))))))))))))))))))))))))))))))
.
2008-08-10 22:59 . 2008-08-10 22:59 <DIR> d-------- C:\WINDOWS\Sun
2008-08-10 22:57 . 2008-08-10 22:57 <DIR> d-------- C:\Programmi\Java
2008-08-10 22:57 . 2005-04-13 03:48 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2008-08-10 22:56 . 2008-08-10 22:56 <DIR> d-------- C:\Programmi\File comuni\Java
2008-08-10 22:53 . 2008-08-12 14:56 <DIR> d-------- C:\Documents and Settings\Renato\.housecall6.6
2008-07-31 14:52 . 2008-07-31 14:52 <DIR> d-------- C:\Documents and Settings\Renato\Dati applicazioni\Auslogics
2008-07-31 09:45 . 2008-07-31 09:45 <DIR> d-------- C:\Programmi\AusLogics Disk Defrag
2008-07-31 09:34 . 2008-07-31 09:34 <DIR> d-------- C:\Programmi\Spybot
2008-07-31 09:34 . 2008-08-04 11:58 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-07-31 09:17 . 2008-07-31 09:17 <DIR> d-------- C:\Programmi\Ad-Aware SE Personal
2008-07-31 09:17 . 2008-07-31 09:17 <DIR> d-------- C:\Documents and Settings\Renato\Dati applicazioni\Lavasoft
2008-07-30 19:09 . 2008-07-30 19:12 <DIR> d-------- C:\Programmi\SysClean
2008-07-30 10:09 . 2008-07-30 10:09 <DIR> d-------- C:\Programmi\TrueCrypt
2008-07-30 10:09 . 2008-07-30 14:25 <DIR> d-------- C:\Documents and Settings\Renato\Dati applicazioni\TrueCrypt
2008-07-30 10:09 . 2008-07-30 10:09 235,840 --a------ C:\WINDOWS\system32\drivers\truecrypt.sys
2008-07-30 09:54 . 2008-07-30 09:54 253,952 --------- C:\WINDOWS\Setup1.exe
2008-07-30 09:54 . 2008-07-30 09:54 74,752 --a------ C:\WINDOWS\ST6UNST.EXE
2008-07-29 14:04 . 2008-08-12 12:27 <DIR> d-------- C:\Programmi\VirIt
2008-07-29 14:04 . 2008-03-17 19:23 39,808 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-07-29 13:30 . 2008-07-29 13:30 <DIR> d-------- C:\Programmi\RegSeeker
2008-07-29 12:06 . 2008-07-29 12:06 <DIR> d-------- C:\Programmi\SUPERAntiSpyware
2008-07-29 12:06 . 2008-07-29 12:06 <DIR> d-------- C:\Documents and Settings\Renato\Dati applicazioni\SUPERAntiSpyware.com
2008-07-29 12:06 . 2008-07-29 12:06 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-07-29 12:05 . 2008-07-29 12:05 <DIR> d-------- C:\Programmi\File comuni\Wise Installation Wizard
2008-07-29 10:58 . 2006-11-12 20:03 <DIR> d--h----- C:\Documents and Settings\Administrator\Risorse di stampa
2008-07-29 10:58 . 2006-11-12 20:03 <DIR> d--h----- C:\Documents and Settings\Administrator\Risorse di rete
2008-07-29 10:58 . 2006-11-12 20:03 <DIR> d-------- C:\Documents and Settings\Administrator\Preferiti
2008-07-29 10:58 . 2006-11-12 20:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Modelli
2008-07-29 10:58 . 2006-11-12 20:03 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Avvio
2008-07-29 10:58 . 2008-08-12 18:36 <DIR> d--h----- C:\Documents and Settings\Administrator\Impostazioni locali
2008-07-29 10:58 . 2006-11-12 20:03 <DIR> d-------- C:\Documents and Settings\Administrator\Documenti
2008-07-29 10:58 . 2006-11-12 20:03 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dati applicazioni
2008-07-29 10:58 . 2008-07-29 10:58 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-29 10:41 . 2008-07-29 10:43 <DIR> d-------- C:\Programmi\Unlocker
2008-07-29 10:41 . 2008-07-29 10:41 <DIR> d-------- C:\Documents and Settings\Renato\Dati applicazioni\Desktopicon
2008-07-28 12:06 . 2008-07-28 12:06 <DIR> d-------- C:\Programmi\Electronic Arts
2008-07-28 12:06 . 2005-06-24 16:24 438,272 -ra------ C:\WINDOWS\system32\vp6vfw.dll
2008-07-28 12:06 . 2004-12-10 09:06 327,680 --a------ C:\WINDOWS\system32\vp6dec.ax
2008-07-27 23:15 . 2008-07-28 10:40 <DIR> d-------- C:\Programmi\CCleaner
2008-07-27 20:53 . 2008-07-27 23:26 <DIR> d-------- C:\Programmi\Avast4
2008-07-22 18:30 . 2008-07-26 20:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-22 18:30 . 2008-07-22 18:30 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-21 18:45 . 2008-07-21 18:45 137 --a------ C:\WINDOWS\system32\MRT.INI
2008-07-21 17:05 . 2008-07-21 17:05 <DIR> d-------- C:\Documents and Settings\Angelo\Dati applicazioni\dpacvtsw
2008-07-20 21:08 . 2008-08-10 19:52 1,439 --a------ C:\Documents and Settings\All Users\Dati applicazioni\ustore.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 10:06 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-07-28 08:42 --------- d-----w C:\Programmi\MSN Messenger
2008-07-28 08:42 --------- d-----w C:\Programmi\Messenger Plus! Live
2008-07-27 18:49 --------- d-----w C:\Documents and Settings\Renato\Dati applicazioni\AVG7
2008-07-27 18:49 --------- d-----w C:\Documents and Settings\Angelo\Dati applicazioni\AVG7
2008-07-27 18:49 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\avg7
2008-07-22 18:17 --------- d-----w C:\Documents and Settings\Renato\Dati applicazioni\uTorrent
2008-07-13 11:42 --------- d-----w C:\Programmi\eMule
2008-07-11 11:52 --------- d-----w C:\Documents and Settings\Renato\Dati applicazioni\Vso
2008-07-08 08:27 --------- d-----w C:\Programmi\BitTorrent
2008-07-08 08:06 --------- d-----w C:\Programmi\uTorrent
2008-07-06 15:53 --------- d-----w C:\Documents and Settings\Renato\Dati applicazioni\BitTorrent
2008-06-30 12:28 --------- d-----w C:\Documents and Settings\NetworkService\Dati applicazioni\dpacvtsw
2008-06-30 11:31 --------- d-----w C:\Documents and Settings\Renato\Dati applicazioni\dpacvtsw
2008-06-20 17:39 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2007-06-07 13:49 81,920 ----a-w C:\Documents and Settings\Renato\Dati applicazioni\ezpinst.exe
2007-06-07 13:49 47,360 ----a-w C:\Documents and Settings\Renato\Dati applicazioni\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{156D5BC1-A014-4E75-910D-1CF6029D4FD2}]
2001-08-31 14:00 105472 --a------ c:\windows\system32\hdaqxxb.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:39 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2007-09-09 17:39 286720]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48 36975]
"GSICONEXE"="GSICON.EXE" [2001-10-16 19:35 75776 C:\WINDOWS\system32\gsicon.exe]
"DSLAGENTEXE"="dslagent.exe" [2001-10-02 10:42 16384 C:\WINDOWS\system32\dslagent.exe]
"SoundMan"="SOUNDMAN.EXE" [2002-10-16 12:24 47104 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:39 15360]
C:\Documents and Settings\Renato\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winek84.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwc05.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwd41.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Utilità di pianificazione di LiveUpdate automatico"=2 (0x2)
"usnjsvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmi\\MSN Messenger\\livecall.exe"=
"C:\\Programmi\\uTorrent\\uTorrent.exe"=
R0 lgfgnvek;lgfgnvek;C:\WINDOWS\system32\drivers\lgfgnvek.sys [2001-08-31 14:00]
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 19:23]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
R3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys [2003-03-30 22:38]
R3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys [2003-03-28 12:58]
R3 gaausb;D-Link DSL-200 USB ADSL Modem(ATM);C:\WINDOWS\system32\DRIVERS\gaausb.sys [2001-09-28 13:06]
R3 TTDec;ATI WDM Teletext Decoder (Microsoft Corporation);C:\WINDOWS\system32\DRIVERS\ATINTTXX.sys [2004-08-03 23:29]
S0 Winek84;Winek84;C:\WINDOWS\system32\Drivers\Winek84.sys []
S0 Winwd41;Winwd41;C:\WINDOWS\system32\Drivers\Winwd41.sys []
S2 gafwload;D-Link DSL-200 USB ADSL Loader;C:\WINDOWS\system32\DRIVERS\gafwload.sys [2001-09-28 13:07]
S2 viritsvclite;Virit eXplorer Lite;C:\PROGRAMMI\VIRIT\viritsvc.exe [2008-07-29 14:05]
S3 AtmElan;LAN ATM emulata;C:\WINDOWS\system32\DRIVERS\atmlane.sys [2004-08-03 23:58]
S3 AtmLane;Emulazione LAN ATM;C:\WINDOWS\system32\DRIVERS\atmlane.sys [2004-08-03 23:58]
S3 SetupNTGLM7X;SetupNTGLM7X;F:\NTGLM7X.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
rjryxsja
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cfc75f34-1815-11dd-a9fa-0050ba96ad46}]
\Shell\AutoRun\command - I:\InstallTomTomHOME.exe
.
- - - - ORFÃOS REMOVIDOS - - - -
Toolbar-ID - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.it/ig
O8 -: E&sporta in Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-12 18:36:55
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-08-12 18:38:06
ComboFix-quarantined-files.txt 2008-08-12 16:38:02
Pre-Run: 14,364,172,288 byte disponibili
Post-Run: 14,353,231,872 byte disponibili
181 --- E O F --- 2008-07-29 22:24:43