ecco il report di combofix:
ComboFix 08-12-31.01 - Sibo 2009-01-01 18.17.18.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1040.18.767.562 [GMT 1:00]
Eseguito da: J:\ComboFix.exe
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Sibo\Dati applicazioni\drivers\downld
C:\Documents
C:\InfoSat.txt
c:\programmi\Alcohol Soft\Alcohol 120\axcmd.exe
J:\InfoSat.txt
.
((((((((((((((((((((((((( Files Creati Da 2008-12-01 al 2009-01-01 )))))))))))))))))))))))))))))))))))
.
2009-01-01 18:05 . 2008-12-15 23:19 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di stampa
2009-01-01 18:05 . 2008-12-15 23:19 <DIR> d--h----- c:\documents and settings\Administrator\Risorse di rete
2009-01-01 18:05 . 2008-12-15 23:19 <DIR> d-------- c:\documents and settings\Administrator\Preferiti
2009-01-01 18:05 . 2008-12-15 22:28 <DIR> d--h----- c:\documents and settings\Administrator\Modelli
2009-01-01 18:05 . 2008-12-15 23:19 <DIR> dr------- c:\documents and settings\Administrator\Menu Avvio
2009-01-01 18:05 . 2009-01-01 18:18 <DIR> d--h----- c:\documents and settings\Administrator\Impostazioni locali
2009-01-01 18:05 . 2008-12-15 23:19 <DIR> d-------- c:\documents and settings\Administrator\Documenti
2009-01-01 18:05 . 2008-12-15 23:19 <DIR> dr-h----- c:\documents and settings\Administrator\Dati applicazioni
2009-01-01 18:05 . 2009-01-01 18:05 <DIR> d-------- c:\documents and settings\Administrator
2009-01-01 17:55 . 2009-01-01 18:17 <DIR> d--h----- c:\documents and settings\Sibo\Dati applicazioni\drivers
2009-01-01 17:53 . 2009-01-01 17:53 135,168 --a------ C:\zip.exe
2009-01-01 17:53 . 2009-01-01 17:53 19,286 --a------ C:\cleanup.exe
2009-01-01 17:53 . 2009-01-01 17:53 574 --a------ C:\cleanup.bat
2009-01-01 17:53 . 2009-01-01 17:53 0 --a------ C:\backup.reg
2009-01-01 17:02 . 2009-01-01 17:25 <DIR> d-------- c:\programmi\FindyKill
2008-12-24 19:53 . 2008-12-24 19:53 <DIR> d-------- c:\programmi\Trend Micro
2008-12-24 18:34 . 2008-12-24 18:34 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-12-24 18:34 . 2008-12-24 18:34 <DIR> d-------- c:\documents and settings\Sibo\Dati applicazioni\Malwarebytes
2008-12-24 18:34 . 2008-12-24 18:34 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-12-24 18:34 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-24 18:34 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-24 10:47 . 2008-12-24 10:47 <DIR> d-------- c:\programmi\MagicDisc
2008-12-24 10:47 . 2008-07-28 17:19 116,736 --a------ c:\windows\system32\drivers\mcdbus.sys
2008-12-24 10:40 . 2008-12-24 10:40 <DIR> d-------- c:\programmi\MagicISO
2008-12-23 18:29 . 2008-12-24 18:15 <DIR> d-------- c:\programmi\eMule
2008-12-22 21:04 . 2008-12-22 21:04 <DIR> d-------- c:\programmi\Microsoft ActiveSync
2008-12-22 21:02 . 2008-12-22 21:02 <DIR> d-------- c:\programmi\Windows Mobile Device Handbook
2008-12-20 17:58 . 2008-02-22 12:30 334,792 --a------ c:\windows\system32\_AxShlEx.dll
2008-12-20 17:45 . 2008-12-20 17:47 <DIR> d-------- c:\programmi\InstallShield Installation Information
2008-12-20 17:39 . 2008-12-20 17:47 <DIR> d-------- c:\programmi\Doom 3
2008-12-20 12:35 . 2008-12-20 12:35 <DIR> d-------- c:\programmi\File comuni\InstallShield
2008-12-20 11:51 . 2008-12-20 11:51 <DIR> d-------- c:\programmi\Alcohol Soft
2008-12-20 11:44 . 2008-12-20 11:44 716,272 --a------ c:\windows\system32\drivers\sptd.sys
2008-12-20 11:37 . 1993-07-22 23:00 210,944 --------- c:\windows\system32\Msvcrt10.dll
2008-12-20 11:36 . 2008-12-20 11:36 <DIR> d-------- c:\windows\system32\Adobe
2008-12-20 11:36 . 2001-03-15 04:55 101,200 --------- c:\windows\system32\pdfshell.dll
2008-12-20 11:36 . 2001-03-15 05:18 65,536 --------- c:\windows\system32\adistres.dll
2008-12-20 11:36 . 2001-03-15 05:18 20,584 --------- c:\windows\system32\PdfPorts.dll
2008-12-20 11:35 . 2008-12-20 11:35 <DIR> d-------- c:\documents and settings\Sibo\Dati applicazioni\InterTrust
2008-12-20 11:35 . 1998-10-29 14:45 306,688 --a------ c:\windows\IsUninst.exe
2008-12-20 11:21 . 2001-12-19 11:45 8,576 --a------ c:\windows\system32\drivers\VCdRom.sys
2008-12-20 11:19 . 2008-12-18 09:53 <DIR> d-------- c:\programmi\Virtual CD-ROM
2008-12-19 19:24 . 2008-12-19 19:24 <DIR> d-------- c:\programmi\MediaMonkey
2008-12-18 17:53 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-18 17:53 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2008-12-18 17:53 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-17 21:46 . 2008-12-17 21:46 <DIR> d-------- c:\documents and settings\Sibo\Tracing
2008-12-17 21:42 . 2008-12-17 21:42 <DIR> d-------- c:\programmi\Windows Live SkyDrive
2008-12-17 21:42 . 2008-12-17 21:42 <DIR> d-------- c:\programmi\Windows Live
2008-12-17 21:42 . 2008-12-17 21:42 <DIR> d-------- c:\programmi\Microsoft
2008-12-17 21:34 . 2008-12-17 21:34 <DIR> d-------- c:\programmi\File comuni\Windows Live
2008-12-17 21:33 . 2008-12-24 18:58 <DIR> d-------- c:\documents and settings\Sibo\Dati applicazioni\skypePM
2008-12-17 21:33 . 2008-12-17 21:33 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-12-17 21:32 . 2008-12-24 20:21 <DIR> d-------- c:\documents and settings\Sibo\Dati applicazioni\Skype
2008-12-17 21:31 . 2008-12-17 21:31 <DIR> d-------- c:\programmi\Skype
2008-12-17 21:31 . 2008-12-17 21:31 <DIR> d-------- c:\programmi\File comuni\Skype
2008-12-17 21:31 . 2008-12-17 21:31 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Skype
2008-12-17 19:26 . 2008-12-17 19:26 0 --a------ c:\windows\nsreg.dat
2008-12-17 18:51 . 2008-12-17 18:51 <DIR> d-------- c:\programmi\uTorrent
2008-12-17 18:51 . 2008-12-24 18:17 <DIR> d-------- c:\documents and settings\Sibo\Dati applicazioni\uTorrent
2008-12-16 19:28 . 2008-12-16 19:28 <DIR> d-------- c:\programmi\easy CD Extractor
2008-12-16 19:27 . 2008-12-16 19:27 <DIR> d-------- c:\documents and settings\cavalleris
2008-12-16 18:51 . 2008-10-16 21:04 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-12-16 18:51 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-12-16 18:51 . 2007-03-08 06:11 1,032,192 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-16 18:51 . 2008-10-16 21:04 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-12-16 18:51 . 2008-10-16 21:04 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-12-16 18:51 . 2008-10-16 21:04 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-12-16 18:51 . 2008-10-16 21:04 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-12-16 18:51 . 2008-10-16 21:04 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-16 18:51 . 2008-10-16 14:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-12-16 18:24 . 2008-08-14 14:22 2,192,896 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-16 18:24 . 2008-08-14 14:22 2,148,864 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-16 18:24 . 2008-08-14 14:22 2,069,760 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-16 18:24 . 2008-08-14 14:22 2,027,520 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-16 18:24 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-12-16 18:23 . 2008-08-14 11:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-12-16 18:18 . 2008-06-14 18:32 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-16 18:14 . 2008-12-20 11:36 <DIR> d-------- c:\programmi\File comuni\Adobe
2008-12-16 18:11 . 2008-12-16 18:58 <DIR> d-------- c:\programmi\NOS
2008-12-16 18:11 . 2008-12-16 18:58 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\NOS
2008-12-16 07:23 . 2008-12-16 18:51 <DIR> d-------- c:\windows\system32\it-it
2008-12-16 07:23 . 2008-12-16 07:23 <DIR> d-------- c:\windows\system32\it
2008-12-16 07:23 . 2008-12-16 07:23 <DIR> d-------- c:\windows\system32\bits
2008-12-16 07:23 . 2008-12-16 07:23 <DIR> d-------- c:\windows\l2schemas
2008-12-16 07:20 . 2008-12-16 07:23 <DIR> d-------- c:\windows\ServicePackFiles
2008-12-16 07:14 . 2008-12-16 07:14 <DIR> d-------- c:\windows\EHome
2008-12-16 00:22 . 2004-08-19 15:23 327,168 --------- c:\windows\system32\drivers\ati2mtaa.sys
2008-12-15 23:57 . 2008-04-13 19:45 172,416 --a------ c:\windows\system32\drivers\kmixer.sys
2008-12-15 23:57 . 2008-04-13 17:39 142,592 --a------ c:\windows\system32\drivers\aec.sys
2008-12-15 23:57 . 2008-04-13 20:17 83,072 --a------ c:\windows\system32\drivers\wdmaud.sys
2008-12-15 23:57 . 2008-04-13 20:15 60,800 --a------ c:\windows\system32\drivers\sysaudio.sys
2008-12-15 23:57 . 2008-04-13 19:45 56,576 --a------ c:\windows\system32\drivers\swmidi.sys
2008-12-15 23:57 . 2008-04-13 19:45 52,864 --a------ c:\windows\system32\drivers\dmusic.sys
2008-12-15 23:57 . 2008-04-13 19:45 6,272 --a------ c:\windows\system32\drivers\splitter.sys
2008-12-15 23:57 . 2008-04-13 19:45 2,944 --a------ c:\windows\system32\drivers\drmkaud.sys
2008-12-15 23:56 . 2004-11-01 04:19 163,712 --a------ c:\windows\system32\drivers\vinyl97.sys
2008-12-15 23:56 . 2008-04-13 20:19 146,048 --a------ c:\windows\system32\drivers\portcls.sys
2008-12-15 23:56 . 2008-04-13 19:45 60,160 --a------ c:\windows\system32\drivers\drmk.sys
2008-12-15 23:48 . 2008-12-24 18:56 4,124,704 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-12-15 23:48 . 2008-12-24 18:56 54,632 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-12-15 23:46 . 2008-12-15 23:56 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-12-15 23:46 . 2008-10-30 14:10 117,120 --a------ c:\windows\system32\drivers\Rtnicxp.sys
2008-12-15 23:46 . 2008-07-16 22:35 9,728 --a------ c:\windows\system32\RtNicProp32.dll
2008-12-15 23:37 . 2008-07-09 09:05 54,672 --a------ c:\windows\system32\vsutil_loc0410.dll
2008-12-15 23:37 . 2008-07-09 09:05 42,384 --a------ c:\windows\zllsputility_loc0410.dll
2008-12-15 23:37 . 2008-07-09 09:05 21,904 --a------ c:\windows\system32\imsinstall_loc0410.dll
2008-12-15 23:37 . 2008-07-09 09:05 17,808 --a------ c:\windows\system32\imslsp_install_loc0410.dll
2008-12-15 23:36 . 2008-12-15 23:36 <DIR> d-------- c:\programmi\Zone Labs
2008-12-15 23:36 . 2008-12-15 23:36 <DIR> d-------- c:\programmi\Innovative Solutions
2008-12-15 23:30 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2008-12-15 23:30 . 2003-03-18 20:14 499,712 --a------ c:\windows\system32\MSVCP71.dll
2008-12-15 23:30 . 2003-02-21 04:42 348,160 --a------ c:\windows\system32\MSVCR71.dll
2008-12-15 23:23 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFCBA.tmp
2008-12-15 23:23 . 2003-03-18 20:14 499,712 --a------ c:\windows\system32\MSVB8.tmp
2008-12-15 23:23 . 2003-02-21 04:42 348,160 --a------ c:\windows\system32\MSVB9.tmp
2008-12-15 23:19 . 2008-12-15 23:19 <DIR> d--h----- c:\documents and settings\Default User\Risorse di stampa
2008-12-15 23:19 . 2008-12-15 23:19 <DIR> d--h----- c:\documents and settings\Default User\Risorse di rete
2008-12-15 23:19 . 2008-12-15 23:19 <DIR> d-------- c:\documents and settings\Default User\Preferiti
2008-12-15 23:19 . 2008-12-15 22:28 <DIR> d--h----- c:\documents and settings\Default User\Modelli
2008-12-15 23:19 . 2008-12-15 23:19 <DIR> dr------- c:\documents and settings\Default User\Menu Avvio
2008-12-15 23:19 . 2008-12-15 23:19 <DIR> dr-h----- c:\documents and settings\Default User\Impostazioni locali
2008-12-15 23:19 . 2008-12-15 23:19 <DIR> d-------- c:\documents and settings\Default User\Documenti
2008-12-15 23:19 . 2008-12-15 23:19 <DIR> d-------- c:\documents and settings\All Users\Preferiti
2008-12-15 23:19 . 2008-12-15 23:19 <DIR> d--h----- c:\documents and settings\All Users\Modelli
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-15 21:51 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\MailFrontier
2008-12-15 21:41 --------- d-----w c:\programmi\Alwil Software
2008-12-15 21:33 --------- d-----w c:\programmi\microsoft frontpage
2008-12-15 21:31 --------- d-----w c:\programmi\Servizi in linea
2008-12-02 21:37 49,480 ----a-w c:\windows\system32\sirenacm.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:04 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\programmi\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\programmi\Alwil Software\Avast4\ashDisp.exe" [2009-01-01 81000]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2009-01-01 919016]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Sibo\Menu Avvio\Programmi\Esecuzione automatica\
MagicDisc.lnk - c:\programmi\MagicDisc\MagicDisc.exe [2008-12-24 575488]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Acrobat Assistant.lnk - c:\programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2008-12-20 49254]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Sibo\\Desktop\\utorrent.exe"=
"c:\programmi\Microsoft ActiveSync\rapimgr.exe"= c:\programmi\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programmi\Microsoft ActiveSync\wcescomm.exe"= c:\programmi\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programmi\Microsoft ActiveSync\WCESMgr.exe"= c:\programmi\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 vcdrom;Virtual CD-ROM Device Driver;\??\c:\windows\system32\drivers\VCdRom.sys [2008-12-20 8576]
S1 aswSP;avast! Self Protection; []
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys []
*Newly Created Service* - PROCEXP90
.
- - - - ORFÃOS REMOVIDOS - - - -
HKCU-Run-AlcoholAutomount - c:\programmi\Alcohol Soft\Alcohol 120\axcmd.exe
.
------- Supplementare di scansione -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Sibo\Dati applicazioni\Mozilla\Firefox\Profiles\a5nykxps.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.bidda.it
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-01 18:18:31
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2009-01-01 18.20.16
ComboFix-quarantined-files.txt 2009-01-01 17:19:03
Pre-Run: 34.162.823.168 byte disponibili
Post-Run: 34,169,065,472 byte disponibili
229 --- E O F --- 2008-12-19 17:20:07