....sono riuscito a fare scansione con combofix....aspetto tue nuove
ComboFix 08-08-17.01 - Utente 2008-08-17 22.32.07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.399 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Utente\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
* Resident AV is active
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Dati applicazioni\HotbarSA
C:\Documents and Settings\All Users\Dati applicazioni\HotbarSA\HotbarSA.dat
C:\Documents and Settings\All Users\Dati applicazioni\HotbarSA\HotbarSAAbout.mht
C:\Documents and Settings\All Users\Dati applicazioni\HotbarSA\HotbarSAEULA.mht
C:\Documents and Settings\Utente\Cookies\utente@ebay[3].txt
C:\Documents and Settings\Utente\Cookies\utente@it.ebayrtm[1].txt
C:\Documents and Settings\Utente\Dati applicazioni\macromedia\Flash Player\#SharedObjects\GVP00001\iforex.com
C:\Documents and Settings\Utente\Dati applicazioni\macromedia\Flash Player\#SharedObjects\GVP00001\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Utente\Dati applicazioni\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Utente\Dati applicazioni\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\Utente\Dati applicazioni\urlredir.cfg
C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\ewgaymq.dat
C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\ewgaymq.exe
C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\ewgaymq_nav.dat
C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\ewgaymq_navps.dat
C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\oehcrsbtu.dat
C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\oehcrsbtu_nav.dat
C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\oehcrsbtu_navps.dat
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\adssite-remove.exe
C:\WINDOWS\system32\rightonadz-uninst.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-07-17 al 2008-08-17 )))))))))))))))))))))))))))))))))))
.
2008-08-16 22:09 . 2008-08-17 22:27 <DIR> d-------- C:\Programmi\Spybot - Search & Destroy
2008-08-16 22:09 . 2008-08-17 22:26 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-08-16 18:01 . 2008-08-16 18:01 <DIR> d-------- C:\Programmi\Trend Micro
2008-08-15 17:20 . 2008-08-15 20:48 126 --a------ C:\WINDOWS\PRLTP_USBdrv.ini
2008-08-14 22:25 . 2008-08-14 22:25 <DIR> d-------- C:\Programmi\Yahoo!
2008-08-14 21:38 . 2008-08-14 21:36 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-08-14 21:38 . 2008-08-14 21:36 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-08-14 21:38 . 2008-08-14 21:36 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-08-14 20:53 . 2008-08-14 21:34 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Avg8
2008-08-14 19:46 . 2008-08-14 19:46 <DIR> d-------- C:\Programmi\AVG
2008-07-25 22:23 . 2008-07-25 22:24 <DIR> d-------- C:\Programmi\File comuni\Adobe
2008-07-25 22:20 . 2008-07-26 09:43 <DIR> d-------- C:\Programmi\NOS
2008-07-25 22:20 . 2008-07-26 09:43 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\NOS
2008-07-18 20:38 . 2008-07-18 20:38 586,752 --a------ C:\WINDOWS\WLXPGSS.SCR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-17 20:32 --------- d-----w C:\Programmi\ESET
2008-08-17 16:28 --------- d-----w C:\Documents and Settings\Utente\Dati applicazioni\Skype
2008-08-17 15:31 --------- d-----w C:\Documents and Settings\Utente\Dati applicazioni\skypePM
2008-08-16 14:11 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-08-16 11:28 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-08-15 21:47 --------- d-----w C:\Documents and Settings\Utente\Dati applicazioni\LimeWire
2008-08-15 19:40 --------- d-----w C:\Programmi\LimeWire
2008-08-12 22:22 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Microsoft Help
2008-07-31 15:41 --------- d-----w C:\Documents and Settings\Utente\Dati applicazioni\EPSON
2008-07-28 19:42 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Motive
2008-07-28 13:05 --------- d---a-w C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-07-14 17:55 313,856 ----a-w C:\WINDOWS\system32\nswA7C.dll
2008-07-13 13:49 --------- d-----w C:\Programmi\Java
2008-07-11 21:47 --------- d-----w C:\Programmi\Google
2008-07-11 11:06 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-05 17:57 --------- d-----w C:\Programmi\Skype
2008-07-05 17:57 --------- d-----w C:\Programmi\File comuni\Skype
2008-07-05 17:57 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Skype
2008-06-29 11:56 --------- d-----w C:\Programmi\Sun
2008-06-29 11:55 --------- d-----w C:\Programmi\File comuni\Java
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 10:59 --------- d-----w C:\Programmi\Telecom Italia
2008-06-24 10:54 --------- d-----w C:\Programmi\Motive
2008-06-24 10:54 --------- d-----w C:\Programmi\Alice ti aiuta
2008-06-23 16:15 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:39 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-18 08:17 --------- d-----w C:\Programmi\eMule
2008-03-03 19:53 92,064 ----a-w C:\Documents and Settings\Utente\mqdmmdm.sys
2008-03-03 19:53 9,232 ----a-w C:\Documents and Settings\Utente\mqdmmdfl.sys
2008-03-03 19:53 79,328 ----a-w C:\Documents and Settings\Utente\mqdmserd.sys
2008-03-03 19:53 66,656 ----a-w C:\Documents and Settings\Utente\mqdmbus.sys
2008-03-03 19:53 6,208 ----a-w C:\Documents and Settings\Utente\mqdmcmnt.sys
2008-03-03 19:53 5,936 ----a-w C:\Documents and Settings\Utente\mqdmwhnt.sys
2008-03-03 19:53 4,048 ----a-w C:\Documents and Settings\Utente\mqdmcr.sys
2008-03-03 19:53 25,600 ----a-w C:\Documents and Settings\Utente\usbsermptxp.sys
2008-03-03 19:53 22,768 ----a-w C:\Documents and Settings\Utente\usbsermpt.sys
2007-11-17 14:32 774,144 ----a-w C:\Programmi\RngInterstitial.dll
2007-10-04 09:00 2,506,438 ----a-w C:\WINDOWS\inf\SET5F.tmp
.
Code:<pre>
----a-w 49,152 2006-02-19 01:41:10 C:\Programmi\HP\HP Software Update\hpwuschd2 .exe
----a-w 709,992 2007-04-10 21:46:52 C:\WINDOWS\vvx1000 .exe
----a-w 15,360 2004-08-19 13:39:36 C:\WINDOWS\system32\ctfmon .exe
</pre>
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 289,792 2008-01-22 00:53:21 C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\bak\oehcrsbtu.exe
----a-w 39,792 2007-10-10 18:51:55 C:\Programmi\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
----a-w 39,792 2008-01-11 20:16:38 C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
----a-w 90,112 2006-11-10 11:35:24 C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\bak\CLIStart.exe
----a-w 94,208 2005-10-28 15:25:44 C:\Programmi\File comuni\Ahead\Lib\bak\NMBgMonitor.exe
----a-w 185,632 2007-11-10 12:47:43 C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe
----a-w 68,856 2007-11-10 19:00:18 C:\Programmi\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe
----a-w 49,152 2006-02-19 01:41:10 C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 49,152 2006-02-19 00:41:10 C:\Programmi\HP\HP Software Update\hpwuSchd2.exe
----a-w 132,496 2007-07-12 03:00:36 C:\Programmi\Java\jre1.6.0_02\bin\bak\jusched.exe
----a-w 31,016 2006-10-26 23:47:42 C:\Programmi\Microsoft Office\Office12\bak\GrooveMonitor.exe
----a-w 33,648 2007-08-24 06:00:48 C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
----a-w 286,720 2007-10-19 19:16:26 C:\Programmi\QuickTime\bak\bak\qttask.exe
----a-w 286,720 2007-10-19 19:16:26 C:\Programmi\QuickTime\bak\bak\qttask.exe
----a-w 1,069,920 2007-12-06 10:58:18 C:\Programmi\Search Settings\bak\SearchSettings.exe
----a-w 15,360 2004-08-19 13:39:36 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-19 13:39:36 C:\WINDOWS\system32\ctfmon.exe
----a-w 155,648 2001-07-09 09:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{109def9a-2e87-4eda-5e3a-f1ead1c9226b}]
2008-07-14 19:55 313856 --a------ C:\WINDOWS\system32\nswA7C.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"EPSON Stylus DX7400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" [2007-04-12 08:00 182272]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:39 15360]
"ewgaymq"="c:\documents and settings\utente\impostazioni locali\dati applicazioni\ewgaymq.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LifeCam"="C:\Programmi\Microsoft LifeCam\LifeExp.exe" [2007-05-17 23:45 279912]
"AliceRE_McciTrayApp"="C:\PROGRA~1\ALICET~1\vendors\AliceRE\content\template\driven_dev\syncer\McciTrayApp.exe" [2006-11-21 16:26 936960]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"VX1000"="C:\WINDOWS\vVX1000.exe" [2007-04-10 23:46 709992]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2008-08-14 21:36 949376]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 08:49 16126464 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15:39 15360]
C:\Documents and Settings\Utente\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - C:\Programmi\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 05:45:42 101784]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - C:\Programmi\Alice ti aiuta\bin\matcli.exe [2008-06-24 12:54:01 212992]
Avvio rapido HP Photosmart Premier.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 08:56:20 73728]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
LG SyncManager.lnk - C:\Programmi\LG PC Suite\LG PC Sync\LGSyncManager.exe [2007-12-03 19:45:41 299008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\explorer.exe]
"Debugger"="c:\windows\system32\utmhemks.nls"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\eMule\\eMule.exe"=
"C:\\Programmi\\LimeWire\\LimeWire.exe"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=
R2 MSCamSvc;MSCamSvc;C:\Programmi\Microsoft LifeCam\MSCamS32.exe [2007-05-17 23:45]
R3 VX1000;VX-1000;C:\WINDOWS\system32\DRIVERS\VX1000.sys [2007-04-10 23:46]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {A75BF1D0-C7C3-CB55-EE17-3225387FD154} /qb
.
Contenuto della cartella 'Scheduled Tasks'
2007-11-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
2008-08-11 C:\WINDOWS\Tasks\OGADaily.job
- C:\WINDOWS\system32\OGAVerify.exe [2008-04-23 17:17]
2008-08-16 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- C:\Programmi\Spybot - Search & Destroy\SpybotSD.exe []
2008-08-17 C:\WINDOWS\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- C:\Programmi\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
.
- - - - ORFÃOS REMOVIDOS - - - -
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Programmi\Qualcomm\Eudora\EuShlExt.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\qf9ita22.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.msn.comFF -: plugin - C:\Programmi\Mozilla Firefox\plugins\npracplug.dll
FF -: plugin - C:\Programmi\Real\RealArcade\Plugins\Mozilla\npracplug.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-17 22:35:13
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Programmi\Eset\pr_imon.dll
.
Ora fine scansione: 2008-08-17 22:36:24
ComboFix-quarantined-files.txt 2008-08-17 20:36:11
Pre-Run: 88,919,273,472 byte disponibili
Post-Run: 89,379,909,632 byte disponibili
202 --- E O F --- 2008-08-12 22:22:42