r16 ha scritto:Ciao.
1)Combofix, lo salvi con un nome di fantasia (lo rinomini) solo se, con la procedura normale, non si riesce a scaricarlo.
2)Si, disabilita il Ripristino,
3)MBR.exe, ha funzionato. Nel log di Systemscan, l'MBR, è corretto.
4) Aspettiamo la scansione di Combofix, per vedere se rileva il Rootkit. (è un "rimasuglio")
Ciao r16 ecco il report di Combofix (qualcosa ha cancellato) attendo istruzioni
ComboFix 09-10-28.08 - Utente 29/10/2009 18.47.49.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.3070.2679 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
ADS - svchost.exe: deleted 88 bytes in 2 streams. ADS - ntoskrnl.exe: deleted 88 bytes in 2 streams. ((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\Drivers\waeearlvvild.sys
c:\windows\system32\Drivers\wjdmwdfdcgpj.sys
c:\windows\system32\Drivers\wxpyxuqbebcg.sys
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_waeearlvvild
-------\Legacy_wjdmwdfdcgpj
-------\Legacy_wxpyxuqbebcg
-------\Service_waeearlvvild
-------\Service_wjdmwdfdcgpj
-------\Service_wxpyxuqbebcg
((((((((((((((((((((((((( Files Creati Da 2009-09-28 al 2009-10-29 )))))))))))))))))))))))))))))))))))
.
2009-10-28 21:51 . 2009-10-28 21:51 77312 ----a-w- C:\mbr.exe
2009-10-28 21:38 . 2009-10-28 21:38 -------- d-----w- c:\documents and settings\Utente\DoctorWeb
2009-10-28 21:17 . 2009-10-28 21:21 -------- d-----w- c:\programmi\Unlocker
2009-10-28 20:34 . 2009-10-28 20:34 -------- d-----w- c:\programmi\VirusTotalUploader
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-29 18:01 . 2009-02-09 17:56 483972640 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-29 17:51 . 2009-02-09 17:56 6484088 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-28 22:33 . 2006-06-08 17:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-10-28 22:33 . 2007-06-09 09:28 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-10-28 22:22 . 2006-05-06 07:40 96256 ----a-w- c:\windows\system32\drivers\sptd0093.sys
2009-10-27 19:40 . 2009-09-26 10:09 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\vlc
2009-10-27 18:37 . 2008-08-14 14:17 -------- d-----w- c:\programmi\Java
2009-10-27 18:37 . 2001-08-31 15:00 74432 ----a-w- c:\windows\system32\perfc010.dat
2009-10-27 18:37 . 2001-08-31 15:00 447874 ----a-w- c:\windows\system32\perfh010.dat
2009-10-27 18:32 . 2008-04-16 17:29 -------- d-----w- c:\programmi\SpywareBlaster
2009-10-27 17:25 . 2006-09-05 17:26 4212 -c-ha-w- c:\windows\system32\zllictbl.dat
2009-10-09 05:35 . 2006-06-09 12:58 -------- d-----w- c:\programmi\eMule
2009-09-26 07:58 . 2009-09-26 07:53 -------- d-----w- c:\programmi\iTunes
2009-09-26 07:55 . 2006-07-02 11:22 -------- d-----w- c:\programmi\iPod
2009-09-26 07:55 . 2007-07-03 07:57 -------- d-----w- c:\programmi\File comuni\Apple
2009-09-26 07:26 . 2006-07-02 11:24 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Apple Computer
2009-09-24 08:37 . 2009-03-06 14:51 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Hamachi
2009-09-14 15:43 . 2009-09-14 15:42 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-14 15:39 . 2008-12-10 23:10 -------- d-----w- c:\programmi\QuickTime
2009-09-11 16:45 . 2009-01-23 18:51 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-09-11 07:45 . 2008-12-20 13:34 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\dvdcss
2009-09-10 17:17 . 2009-09-10 17:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-09-10 17:16 . 2009-09-10 17:16 -------- d-----w- c:\programmi\NOS
2009-09-10 12:54 . 2009-01-23 18:51 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-01-23 18:51 19160 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 16:23 . 2006-06-08 17:14 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-08-27 15:22 . 2009-08-27 15:22 13698 ----a-w- c:\windows\War3Unin.dat
2009-08-27 15:22 . 2009-08-27 15:22 2829 ----a-w- c:\windows\War3Unin.pif
2009-08-27 15:22 . 2009-08-27 15:22 126976 ----a-w- c:\windows\War3Unin.exe
2006-07-18 13:41 . 2006-06-17 17:32 1019094 -csha-r- c:\programmi\serial.tde
2008-04-29 17:39 . 2008-04-29 17:39 2 --shatr- c:\windows\winstart.bat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-16 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-16 81920]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2009-03-31 982408]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-12-04 1626112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-04-09 15360]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Reader Speed Launch.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programmi\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmi\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [06/12/2005 16.11.18 35328]
S3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe -k getPlusHelper [19/08/2004 14.39.46 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-10-28 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\programmi\Windows Live Toolbar\MSNTBUP.EXE [2006-10-10 22:25]
.
.
------- Scansione supplementare -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\programmi\Windows Live Toolbar\msntb.dll/search.htm
TCP: {C56E821E-41CB-40C6-86B7-952F2415CF8B} = 85.37.17.44,192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\hcoecvd7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: keyword.enabled - false
FF - plugin: c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\hcoecvd7.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
SafeBoot-aawservice
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-29 18:59
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1960408961-1284227242-839522115-1003\RemoteAccess\Profile\x *]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(1216)
c:\programmi\iTunes\iTunesMiniPlayer.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\it.lproj\iTunesMiniPlayerLocalized.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\programmi\Windows Media Player\wmpband.dll
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\drivers\KodakCCS.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2009-10-29 19.04.12 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-10-29 18:04
Pre-Run: 77.258.313.728 byte disponibili
Post-Run: 77.189.308.416 byte disponibili
- - End Of File - - 947EA7C1C06FCD64DEB8063361DB686D