ECCO IL COMBOFIX.TXT
ComboFix 08-09-22.06 - SIMONE 2008-09-24 15.46.42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1173 [GMT 2:00]
Eseguito da: C:\Documents and Settings\SIMONE\Desktop\ComboFix.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\FRANCESCO\Dati applicazioni\addon.dat
C:\Documents and Settings\LUCIA\Dati applicazioni\addon.dat
C:\Documents and Settings\MARCO\Dati applicazioni\addon.dat
C:\Documents and Settings\SIMONE\Dati applicazioni\addon.dat
C:\InfoSat.txt
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\downld\101796.exe
C:\WINDOWS\system32\drivers\downld\103859.exe
C:\WINDOWS\system32\drivers\downld\104515.exe
C:\WINDOWS\system32\drivers\downld\108687.exe
C:\WINDOWS\system32\drivers\downld\108812.exe
C:\WINDOWS\system32\drivers\downld\111390.exe
C:\WINDOWS\system32\drivers\downld\111640.exe
C:\WINDOWS\system32\drivers\downld\1131015.exe
C:\WINDOWS\system32\drivers\downld\1143328.exe
C:\WINDOWS\system32\drivers\downld\1145203.exe
C:\WINDOWS\system32\drivers\downld\115906.exe
C:\WINDOWS\system32\drivers\downld\1163406.exe
C:\WINDOWS\system32\drivers\downld\1170140.exe
C:\WINDOWS\system32\drivers\downld\1175671.exe
C:\WINDOWS\system32\drivers\downld\119218.exe
C:\WINDOWS\system32\drivers\downld\119609.exe
C:\WINDOWS\system32\drivers\downld\121562.exe
C:\WINDOWS\system32\drivers\downld\1219140.exe
C:\WINDOWS\system32\drivers\downld\1223140.exe
C:\WINDOWS\system32\drivers\downld\123171.exe
C:\WINDOWS\system32\drivers\downld\1245484.exe
C:\WINDOWS\system32\drivers\downld\1258250.exe
C:\WINDOWS\system32\drivers\downld\126000.exe
C:\WINDOWS\system32\drivers\downld\126093.exe
C:\WINDOWS\system32\drivers\downld\126734.exe
C:\WINDOWS\system32\drivers\downld\1280921.exe
C:\WINDOWS\system32\drivers\downld\128703.exe
C:\WINDOWS\system32\drivers\downld\129375.exe
C:\WINDOWS\system32\drivers\downld\131234.exe
C:\WINDOWS\system32\drivers\downld\132109.exe
C:\WINDOWS\system32\drivers\downld\133359.exe
C:\WINDOWS\system32\drivers\downld\135984.exe
C:\WINDOWS\system32\drivers\downld\138421.exe
C:\WINDOWS\system32\drivers\downld\142359.exe
C:\WINDOWS\system32\drivers\downld\147484.exe
C:\WINDOWS\system32\drivers\downld\14854125.exe
C:\WINDOWS\system32\drivers\downld\14885390.exe
C:\WINDOWS\system32\drivers\downld\14888281.exe
C:\WINDOWS\system32\drivers\downld\14910500.exe
C:\WINDOWS\system32\drivers\downld\14917156.exe
C:\WINDOWS\system32\drivers\downld\14920406.exe
C:\WINDOWS\system32\drivers\downld\14924406.exe
C:\WINDOWS\system32\drivers\downld\14961812.exe
C:\WINDOWS\system32\drivers\downld\14982375.exe
C:\WINDOWS\system32\drivers\downld\14993062.exe
C:\WINDOWS\system32\drivers\downld\15015390.exe
C:\WINDOWS\system32\drivers\downld\153031.exe
C:\WINDOWS\system32\drivers\downld\154453.exe
C:\WINDOWS\system32\drivers\downld\161234.exe
C:\WINDOWS\system32\drivers\downld\163859.exe
C:\WINDOWS\system32\drivers\downld\165562.exe
C:\WINDOWS\system32\drivers\downld\167921.exe
C:\WINDOWS\system32\drivers\downld\168156.exe
C:\WINDOWS\system32\drivers\downld\173187.exe
C:\WINDOWS\system32\drivers\downld\173234.exe
C:\WINDOWS\system32\drivers\downld\180046.exe
C:\WINDOWS\system32\drivers\downld\189609.exe
C:\WINDOWS\system32\drivers\downld\193796.exe
C:\WINDOWS\system32\drivers\downld\194140.exe
C:\WINDOWS\system32\drivers\downld\195562.exe
C:\WINDOWS\system32\drivers\downld\198125.exe
C:\WINDOWS\system32\drivers\downld\204734.exe
C:\WINDOWS\system32\drivers\downld\206250.exe
C:\WINDOWS\system32\drivers\downld\220812.exe
C:\WINDOWS\system32\drivers\downld\227312.exe
C:\WINDOWS\system32\drivers\downld\227765.exe
C:\WINDOWS\system32\drivers\downld\231359.exe
C:\WINDOWS\system32\drivers\downld\234125.exe
C:\WINDOWS\system32\drivers\downld\235328.exe
C:\WINDOWS\system32\drivers\downld\237843.exe
C:\WINDOWS\system32\drivers\downld\254296.exe
C:\WINDOWS\system32\drivers\downld\260546.exe
C:\WINDOWS\system32\drivers\downld\266312.exe
C:\WINDOWS\system32\drivers\downld\276265.exe
C:\WINDOWS\system32\drivers\downld\277250.exe
C:\WINDOWS\system32\drivers\downld\287671.exe
C:\WINDOWS\system32\drivers\downld\29427437.exe
C:\WINDOWS\system32\drivers\downld\29439531.exe
C:\WINDOWS\system32\drivers\downld\29442468.exe
C:\WINDOWS\system32\drivers\downld\29473796.exe
C:\WINDOWS\system32\drivers\downld\29481937.exe
C:\WINDOWS\system32\drivers\downld\29484906.exe
C:\WINDOWS\system32\drivers\downld\29490031.exe
C:\WINDOWS\system32\drivers\downld\29527562.exe
C:\WINDOWS\system32\drivers\downld\29605718.exe
C:\WINDOWS\system32\drivers\downld\29616156.exe
C:\WINDOWS\system32\drivers\downld\29638640.exe
C:\WINDOWS\system32\drivers\downld\303703.exe
C:\WINDOWS\system32\drivers\downld\311796.exe
C:\WINDOWS\system32\drivers\downld\6634640.exe
C:\WINDOWS\system32\drivers\downld\6637140.exe
C:\WINDOWS\system32\drivers\downld\6675250.exe
C:\WINDOWS\system32\drivers\downld\6717718.exe
C:\WINDOWS\system32\drivers\downld\6721937.exe
C:\WINDOWS\system32\drivers\downld\6740687.exe
C:\WINDOWS\system32\drivers\downld\6751640.exe
C:\WINDOWS\system32\drivers\downld\6774625.exe
C:\WINDOWS\system32\drivers\downld\704312.exe
C:\WINDOWS\system32\drivers\downld\706125.exe
C:\WINDOWS\system32\drivers\downld\738796.exe
C:\WINDOWS\system32\drivers\downld\744437.exe
C:\WINDOWS\system32\drivers\downld\782890.exe
C:\WINDOWS\system32\drivers\downld\787781.exe
C:\WINDOWS\system32\drivers\downld\808187.exe
C:\WINDOWS\system32\drivers\downld\819437.exe
C:\WINDOWS\system32\drivers\downld\843000.exe
C:\WINDOWS\system32\drivers\downld\94062.exe
C:\WINDOWS\system32\drivers\downld\94265.exe
C:\WINDOWS\system32\drivers\downld\94390.exe
C:\WINDOWS\system32\drivers\downld\95296.exe
C:\WINDOWS\system32\drivers\downld\95531.exe
C:\WINDOWS\system32\drivers\downld\97062.exe
C:\WINDOWS\system32\drivers\downld\97093.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\winsyser.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((( Files Creati Da 2008-08-24 al 2008-09-24 )))))))))))))))))))))))))))))))))))
.
2008-09-24 00:05 . 2006-11-16 18:01 <DIR> d--h----- C:\Documents and Settings\Administrator\Risorse di stampa
2008-09-24 00:05 . 2006-11-16 18:01 <DIR> d--h----- C:\Documents and Settings\Administrator\Risorse di rete
2008-09-24 00:05 . 2006-11-16 18:01 <DIR> d-------- C:\Documents and Settings\Administrator\Preferiti
2008-09-24 00:05 . 2006-11-16 17:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Modelli
2008-09-24 00:05 . 2006-11-16 18:01 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Avvio
2008-09-24 00:05 . 2008-09-24 15:49 <DIR> d--h----- C:\Documents and Settings\Administrator\Impostazioni locali
2008-09-24 00:05 . 2006-11-16 18:01 <DIR> d-------- C:\Documents and Settings\Administrator\Documenti
2008-09-24 00:05 . 2006-11-16 18:01 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dati applicazioni
2008-09-24 00:05 . 2008-09-24 00:05 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-23 21:32 . 2008-09-23 21:32 <DIR> d-------- C:\VIRUSfighter
2008-09-23 17:26 . 2008-09-23 23:57 <DIR> d-------- C:\Documents and Settings\SIMONE\.housecall6.6
2008-09-19 18:25 . 2008-09-19 18:25 <DIR> d-------- C:\Programmi\Mio Technology
2008-09-19 13:28 . 2008-09-24 15:25 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-19 13:28 . 2008-09-19 13:28 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-16 15:22 . 2004-01-10 20:56 122,880 --a------ C:\WINDOWS\system32\pdfmont.dll
2008-09-11 10:42 . 1999-12-17 11:13 86,016 --a------ C:\WINDOWS\unvise32.exe
2008-09-10 13:15 . 2008-09-10 13:15 24,576 --------- C:\WINDOWS\system32\RCDLL_Polish.dll
2008-09-04 21:51 . 2008-09-04 21:51 <DIR> d-------- C:\Documents and Settings\SIMONE\Dati applicazioni\ScummVM
2008-09-04 21:50 . 2008-09-11 12:57 <DIR> d-------- C:\Programmi\ScummVM
2008-08-30 17:18 . 2008-08-30 17:18 <DIR> d-------- C:\Programmi\Seagate
2008-08-25 14:55 . 2008-08-25 14:55 <DIR> d-------- C:\Programmi\Creative
2008-08-25 14:55 . 2008-08-25 16:42 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Creative
2008-08-25 14:55 . 2006-10-06 14:17 53,248 --------- C:\WINDOWS\Ctregrun.exe
2008-08-25 14:55 . 1999-12-13 09:01 44,032 --------- C:\WINDOWS\system32\CTSVCCDA.EXE
2008-08-25 14:55 . 1999-11-18 09:00 25,088 --------- C:\WINDOWS\system32\CTSVCCTL.EXE
2008-08-24 10:35 . 2008-08-24 10:35 <DIR> d-------- C:\Documents and Settings\LUCIA\Dati applicazioni\PC Suite
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-23 19:32 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-09-23 11:00 --------- d-----w C:\Programmi\MiTAC Research (Shanghai) Ltd
2008-09-22 18:59 --------- d-----w C:\Programmi\HDD Health
2008-09-22 16:31 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Trend Micro
2008-09-21 15:33 --------- d-----w C:\Documents and Settings\SIMONE\Dati applicazioni\foobar2000
2008-09-20 14:11 --------- d-----w C:\Documents and Settings\FRANCESCO\Dati applicazioni\foobar2000
2008-09-14 13:16 --------- d-----w C:\Documents and Settings\FRANCESCO\Dati applicazioni\Ahead
2008-09-11 08:42 --------- d-----w C:\Programmi\La Gazzetta Dello Sport
2008-08-31 21:50 --------- d-----w C:\Documents and Settings\FRANCESCO\Dati applicazioni\DNA
2008-08-31 18:27 --------- d-----w C:\Documents and Settings\SIMONE\Dati applicazioni\uTorrent
2008-08-31 06:52 --------- d-----w C:\Programmi\DNA
2008-08-30 22:58 --------- d-----w C:\Documents and Settings\SIMONE\Dati applicazioni\DNA
2008-08-30 15:17 --------- d-----w C:\Programmi\File comuni\Wise Installation Wizard
2008-08-25 13:52 --------- d-----w C:\Programmi\C6 Messenger
2008-08-25 13:50 --------- d-----w C:\Programmi\FCM
2008-08-14 20:30 --------- d-----w C:\Programmi\Alice ti aiuta
2008-08-11 18:57 --------- d-----w C:\Programmi\Vivendi Universal Games
2008-08-11 18:54 --------- d-----w C:\Programmi\MagicDisc
2008-08-09 13:26 --------- d-----w C:\Programmi\Vuze
2008-08-09 13:25 --------- d-----w C:\Documents and Settings\SIMONE\Dati applicazioni\Azureus
2008-08-07 04:53 --------- d-----w C:\Programmi\Telecom Italia
2008-08-06 11:20 --------- d-----w C:\Programmi\File comuni\InstallShield
2008-08-02 14:31 --------- d-----w C:\Programmi\MagicISO
2008-07-31 14:52 --------- d-----w C:\Programmi\PFConfig
2008-07-28 15:19 116,736 ----a-w C:\WINDOWS\system32\drivers\mcdbus.sys
2008-07-27 11:22 --------- d-----w C:\Programmi\Azureus
2008-07-27 11:17 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Azureus
2008-05-01 06:42 7,729 ----a-w C:\Documents and Settings\MARCO\antbiasu.exe
2007-02-12 17:42 94,080 ----a-w C:\Documents and Settings\SIMONE\Dati applicazioni\ezplay.sys
2007-02-12 17:42 81,920 ----a-w C:\Documents and Settings\SIMONE\Dati applicazioni\ezpinst.exe
2007-02-12 17:42 47,360 ----a-w C:\Documents and Settings\SIMONE\Dati applicazioni\pcouffin.sys
2008-05-03 18:44 500,224 --sha-r C:\WINDOWS\system32\winsyser .exe
2008-05-10 07:35 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008051020080511\index.dat
.
Code:<pre>
----a-w 155,648 2006-01-12 13:40:44 C:\Programmi\File comuni\Ahead\Lib\nerocheck .exe
----a-w 153,136 2007-03-01 13:57:24 C:\Programmi\File comuni\Nero\Lib\nerocheck .exe
----a-w 14,348 2008-04-03 19:42:41 C:\Programmi\HDD Health\hddhealth .exe
----a-w 69,632 2002-04-17 09:42:56 C:\Programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd .exe
----a-w 106,064 2007-07-14 14:39:26 C:\Programmi\National Instruments\NI-DAQ\HWConfig\nidevmon .exe
----a-w 14,348 2008-04-03 19:42:41 C:\Programmi\Nokia\Nokia PC Suite 6\LAUNCH~1 .exe
----a-w 15,360 2004-08-19 12:00:00 C:\WINDOWS\system32\ctfmon .exe
----a-w 155,648 2001-07-09 09:50:42 C:\WINDOWS\system32\NeroCheck .exe
--sha-r 500,224 2008-05-03 18:44:32 C:\WINDOWS\system32\winsyser .exe
</pre>
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"AlcoholAutomount"="C:\Programmi\Alcohol Soft\Alcohol 120\axcmd.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-02-24 5537792]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-02-24 86016]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2007-06-29 286720]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"nwiz"="nwiz.exe" [2005-02-24 C:\WINDOWS\system32\nwiz.exe]
"C-Media Mixer"="Mixer.exe" [2002-06-12 C:\WINDOWS\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\SIMONE\Menu Avvio\Programmi\Esecuzione automatica\
MagicDisc.lnk - C:\Programmi\MagicDisc\MagicDisc.exe [2008-08-11 575488]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\MSN Messenger\\msnmsger.exe"=
"C:\\Programmi\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Programmi\\BitTorrent_DNA\\dna.exe"=
"C:\\Programmi\\DNA\\btdna.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\uTorrent\\uTorrent.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\SIMONE\\Documenti\\mIRC Italiano\\mIRC.exe"=
"C:\\Programmi\\File comuni\\Ahead\\Nero Web\\SetupX.exe"=
"C:\\Programmi\\Hewlett-Packard\\hp business inkjet 1200 series\\Toolbox\\HPWNTBX.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"41987:TCP"= 41987:TCP:utorrent
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2007-11-18 162432]
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2007-11-18 12032]
R2 Network WanMiniport First Position;Network WanMiniport First Position;C:\Programmi\Telecom Italia\WanMiniport1st\srvany.exe [2003-04-18 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C5CD9787-54F4-6B5A-7054-5E50F28A8F48}]
C:\WINDOWS\crack\crack.exe s
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\SIMONE\Dati applicazioni\Mozilla\Firefox\Profiles\8ap0dm77.default\
FF -: plugin - C:\Documents and Settings\SIMONE\Documenti\firefox\plugins\npnul32.dll
FF -: plugin - C:\Programmi\DNA\plugins\npbtdna.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-24 15:51:31
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Programmi\Creative\Shared Files\CTDevSrv.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wpabaln.exe
.
**************************************************************************
.
Ora fine scansione: 2008-09-24 16:02:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-24 14:02:17
Pre-Run: 79.253.667.840 byte disponibili
Post-Run: 79,275,630,592 byte disponibili
304 --- E O F --- 2008-09-10 12:08:51
adesso scarico malwaree lancio pure quello