ComboFix 08-12-07.01 - Claudio 2008-12-08 22:55:17.2 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.78 [GMT 1:00]
Eseguito da: c:\documents and settings\Claudio\Desktop\ComboFix.exe
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Dati applicazioni\nfo
c:\documents and settings\All Users\Dati applicazioni\nfo\keys.dat
c:\documents and settings\All Users\Dati applicazioni\nfo\mon0104.dbd
c:\documents and settings\All Users\Dati applicazioni\nfo\mon0106.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon0204.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon0315.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon0412.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon0504.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon0904.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon1125.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon1204.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon1215.dbd
c:\documents and settings\All Users\Dati applicazioni\nfo\mon1909.ddx
c:\documents and settings\All Users\Dati applicazioni\nfo\mon1920.dbd
c:\documents and settings\All Users\Dati applicazioni\nfo\mon2007.dbd
c:\windows\Downloaded Program Files\EPWYKdiFe
c:\windows\Downloaded Program Files\n8lnb
c:\windows\Downloaded Program Files\rxyfvc
c:\windows\system32\ban_list.txt
c:\windows\system32\exploit.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-11-08 al 2008-12-08 )))))))))))))))))))))))))))))))))))
.
2008-12-08 20:08 . 2008-12-08 20:08 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-08 18:25 . 2008-12-08 18:25 <DIR> d-------- c:\windows\SYSTEM32\DRIVERS\Avg
2008-12-08 18:25 . 2008-12-08 18:25 <DIR> d-------- c:\programmi\AVG
2008-12-08 18:25 . 2008-12-08 18:25 <DIR> d-------- c:\documents and settings\Claudio\Dati applicazioni\AVGTOOLBAR
2008-12-08 18:25 . 2008-12-08 18:25 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\avg8
2008-12-08 18:25 . 2008-12-08 18:25 97,928 --a------ c:\windows\SYSTEM32\DRIVERS\avgldx86.sys
2008-12-08 18:25 . 2008-12-08 18:25 76,040 --a------ c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
2008-12-08 18:25 . 2008-12-08 18:25 10,520 --a------ c:\windows\SYSTEM32\avgrsstx.dll
2008-12-08 15:31 . 2008-12-08 15:31 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-12-08 15:30 . 2008-12-08 15:30 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2008-12-08 15:30 . 2008-12-08 15:30 <DIR> d-------- c:\documents and settings\Claudio\Dati applicazioni\SUPERAntiSpyware.com
2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2008-12-08 12:03 . 2008-12-08 12:04 63 --a------ c:\windows\WINHELP.BMK
2008-12-08 10:35 . 2008-12-08 10:45 40,960 --a------ c:\windows\SYSTEM32\DRIVERS\VIRAGTLT.SYS
2008-12-07 20:06 . 2008-06-19 17:24 28,544 --a------ c:\windows\SYSTEM32\DRIVERS\pavboot.sys
2008-12-07 20:05 . 2008-12-07 20:05 <DIR> d-------- c:\programmi\Panda Security
2008-12-07 13:00 . 2008-12-07 13:00 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-12-07 13:00 . 2008-12-07 13:00 <DIR> d-------- c:\documents and settings\Claudio\Dati applicazioni\Malwarebytes
2008-12-07 13:00 . 2008-12-07 13:00 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-12-07 13:00 . 2008-12-03 19:52 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-12-07 13:00 . 2008-12-03 19:52 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-12-07 11:22 . 2008-12-07 11:20 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2008-11-15 16:51 . 2008-11-15 16:51 <DIR> d--hs---- C:\FOUND.043
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 08:26 --------- d-----w c:\documents and settings\Claudio\Dati applicazioni\F-Secure
2008-11-02 08:17 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\F-Secure
2008-11-02 08:16 --------- d-----w c:\programmi\F-Secure Internet Security
2008-10-07 01:47 6,952 ----a-w c:\windows\Sysvxd.exe
2006-10-29 11:27 54 ----a-w c:\programmi\inc1.bat
2006-10-29 11:27 50 ----a-w c:\programmi\bit3.bat
2006-10-29 11:27 50 ----a-w c:\programmi\bit2.bat
2006-10-29 11:27 50 ----a-w c:\programmi\bit.bat
2006-10-29 11:27 41 ----a-w c:\programmi\sleep.bat
2005-01-01 15:11 266 --sh--w c:\programmi\desktop.ini
1999-03-10 12:53 99,840 ----a-w c:\programmi\File comuni\IRAABOUT.DLL
1998-12-08 23:53 70,144 ----a-w c:\programmi\File comuni\IRAMDMTR.DLL
1998-12-08 23:53 48,640 ----a-w c:\programmi\File comuni\IRALPTTR.DLL
1998-12-08 23:53 31,744 ----a-w c:\programmi\File comuni\IRAWEBTR.DLL
1998-12-08 23:53 186,368 ----a-w c:\programmi\File comuni\IRAREG.DLL
1998-12-08 23:53 17,920 ----a-w c:\programmi\File comuni\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TI WLAN"="c:\programmi\Wireless LAN Utility\TIWLANCu.exe" [2005-03-05 1150976]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-08 1261336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Avvio veloce di Adobe Reader.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
--------- 2004-09-24 17:22 1916928 c:\programmi\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 c:\windows\SYSTEM32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-04-01 20:04 32881 c:\programmi\Java\j2re1.4.2_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-12-07 28544]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-08 97928]
R1 SASDIFSV;SASDIFSV;\??\c:\programmi\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\programmi\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-08 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-08 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-08 76040]
R2 DLPortIO;DriverLINX Port I/O Driver;\??\c:\windows\system32\DRIVERS\DLPortIO.SYS [2005-12-15 3584]
R3 TNET1130;802.11 WLAN;c:\windows\system32\DRIVERS\TNET1130.sys [2008-09-03 438912]
S2 ousbehci;%OWC_USBEHCD.DeviceDesc%;c:\windows\system32\Drivers\ousbehci.sys [2006-12-20 29568]
S3 AR5523;NETGEAR WG111T USB2.0 Wireless Card Service;c:\windows\system32\DRIVERS\WG11TND5.sys []
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\c:\windows\system32\DNINDIS5.SYS [2006-12-19 17149]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\programmi\NOS\bin\getPlus_HelperSvc.exe [2008-10-06 33752]
S3 NtApm;Driver interfaccia NT Apm/Legacy;c:\windows\system32\DRIVERS\NtApm.sys [2005-04-01 9472]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\DRIVERS\pfc027.sys []
S3 SASENUM;SASENUM;\??\c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
.
Contenuto della cartella 'Scheduled Tasks'
2008-12-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2006-08-29 14:21]
2008-12-08 c:\windows\Tasks\iruaez.job
- c:\windows\system32\updjzlgt.exe []
.
- - - - ORFÃOS REMOVIDOS - - - -
MSConfigStartUp-jjnmra - (no file)
.
------- Supplementare di scansione -------
.
uStart Page = about:blank
mLocal Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyOverride = 127.0.0.1
TCP: {DDE8BF5D-0C67-4448-81A2-8F12751DD0B9} = 212.216.112.112,192.168.1.1
O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\fscax.dll - O16 -: {9522589E-57B9-46C5-9A77-1F1C1CCBE550}
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-08 22:59:11
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
.
Ora fine scansione: 2008-12-08 23:01:35
ComboFix-quarantined-files.txt 2008-12-08 22:01:30
Pre-Run: 18,268,520,448 byte disponibili
Post-Run: 18,258,329,600 byte disponibili
168
ecco il risultato di combofix