Dopo tanti errori e un riavvio perche mi diceva combo ha rilevato un rootkik e quindi il pc deve essere riavviato, ho in mano un log da parte di combo e ora lo posto, R16 tocca a te...
ComboFix 09-11-11.02 - dario 12/11/2009 0.20.55.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.766.543 [GMT 1:00]
Eseguito da: c:\documents and settings\dario\desktop\Combo-Fix.exe
Opzioni usate :: /KillAll
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-6C25-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
La copia infetta di c:\windows\system32\drivers\atapi.sys è stata trovata e disinfettata
ipristinata copia da - Kitty ate it :p
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((( Files Creati Da 2009-10-11 al 2009-11-11 )))))))))))))))))))))))))))))))))))
.
2009-11-11 00:53 . 2009-11-11 00:53 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\Malwarebytes
2009-11-11 00:53 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-11 00:53 . 2009-11-11 00:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-11-11 00:53 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-11 00:36 . 2009-11-11 00:36 -------- d-----w- c:\programmi\Yahoo!
2009-11-11 00:35 . 2009-11-11 00:36 -------- d-----w- c:\programmi\CCleaner
2009-11-10 20:10 . 2009-11-10 20:10 -------- d-----w- c:\programmi\Trend Micro
2009-11-08 22:00 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-11-08 22:00 . 2009-02-13 11:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-11-08 22:00 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-11-08 22:00 . 2009-11-08 22:00 -------- d-----w- c:\programmi\Avira
2009-11-08 22:00 . 2009-11-08 22:00 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2009-11-08 11:07 . 2008-10-16 13:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-11-08 11:07 . 2008-10-16 13:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-11-08 09:18 . 2009-11-08 10:12 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\GlarySoft
2009-11-07 22:38 . 2009-11-07 22:38 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\Uniblue
2009-11-07 21:10 . 2009-11-07 21:10 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\Foxit
2009-11-07 20:55 . 2009-11-07 21:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-11-07 20:55 . 2009-09-23 15:37 34112 ----a-w- c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-07 20:55 . 2009-09-23 15:37 32448 ----a-w- c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-07 20:55 . 2009-09-23 15:37 22352 ----a-w- c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-07 16:49 . 2009-11-07 17:05 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\QuickScan
2009-11-07 16:48 . 2009-10-29 14:39 679936 ----a-w- c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2009-11-07 16:48 . 2009-10-29 14:39 614400 ----a-w- c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2009-11-05 13:44 . 2009-11-05 13:44 -------- d-----w- c:\documents and settings\HelpAssistant\WINDOWS
2009-11-05 13:44 . 2009-11-05 13:44 -------- d-----w- c:\documents and settings\HelpAssistant\UserData
2009-11-05 13:44 . 2009-11-05 13:44 -------- d-----w- c:\documents and settings\HelpAssistant\Tracing
2009-11-05 13:44 . 2009-11-05 13:44 -------- d-----w- c:\documents and settings\HelpAssistant\LocalLow
2009-11-05 13:44 . 2009-11-05 13:44 -------- d-----w- c:\documents and settings\HelpAssistant\Incomplete
2009-11-05 13:39 . 2009-11-05 13:39 -------- d-----w- c:\documents and settings\HelpAssistant\dwhelper
2009-11-05 13:20 . 2009-11-05 13:20 -------- d-----w- c:\documents and settings\HelpAssistant\Contacts
2009-10-26 21:10 . 2009-10-26 21:13 4100096 ----a-w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge\PowerSoccer\PowerSoccer.exe
2009-10-18 15:38 . 2009-10-18 15:39 917504 ----a-w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge\PowerSoccer\TVE3.dll
2009-10-18 15:36 . 2009-10-18 15:36 253952 ----a-w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge\PowerSoccer\OpenAL32.dll
2009-10-18 15:36 . 2009-10-18 15:36 676464 ----a-w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge\PowerSoccer\DFEngine.dll
2009-10-18 15:33 . 2009-10-18 15:33 656088 ----a-w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge\loader8.dll
2009-10-18 15:33 . 2009-10-18 15:36 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge
2009-10-18 15:33 . 2009-10-18 15:33 -------- d-----w- c:\documents and settings\dario\Impostazioni locali\Dati applicazioni\PowerChallenge
2009-10-18 01:01 . 2009-10-18 01:01 152576 ----a-w- c:\documents and settings\dario\Dati applicazioni\Sun\Java\jre1.6.0_16\lzma.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-08 10:13 . 2007-11-26 20:05 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\uTorrent
2009-11-08 10:13 . 2007-04-11 14:08 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\BitTorrent
2009-11-08 10:08 . 2007-03-17 15:06 -------- d-----w- c:\programmi\Servizi in linea
2009-11-07 22:00 . 2007-03-17 16:54 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-11-07 20:29 . 2007-03-17 17:41 -------- d-----w- c:\programmi\File comuni\Adobe
2009-11-03 20:05 . 2007-03-19 22:22 -------- d-----w- c:\programmi\Mozilla Thunderbird
2009-10-26 09:57 . 2001-08-31 10:00 76970 ----a-w- c:\windows\system32\perfc010.dat
2009-10-26 09:57 . 2001-08-31 10:00 454368 ----a-w- c:\windows\system32\perfh010.dat
2009-10-23 14:28 . 2009-05-30 12:32 -------- d-----w- c:\documents and settings\dario\Dati applicazioni\xVideoServiceThief
2009-10-18 01:03 . 2007-03-26 20:27 -------- d-----w- c:\programmi\Java
2009-10-05 10:25 . 2007-03-18 00:04 64952 ----a-w- c:\documents and settings\dario\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-05 10:24 . 2009-10-05 10:16 -------- d-----w- c:\programmi\Windows Live
2009-10-05 10:24 . 2007-03-26 17:55 -------- d-----w- c:\programmi\Windows Live Toolbar
2009-10-05 10:23 . 2009-10-05 10:23 -------- d-----w- c:\programmi\Microsoft Sync Framework
2009-10-05 10:22 . 2007-03-26 17:53 -------- d-----w- c:\programmi\MSN Messenger
2009-10-05 10:17 . 2009-10-05 10:17 -------- d-----w- c:\programmi\Microsoft
2009-10-05 10:17 . 2009-10-05 10:17 -------- d-----w- c:\programmi\Windows Live SkyDrive
2009-10-05 10:10 . 2009-10-05 10:10 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-09-21 08:50 . 2009-09-21 08:50 656088 ----a-w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge\loader.dll
2009-09-21 08:50 . 2009-09-21 08:50 266968 ----a-w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge\axpowerloader.dll
2009-09-21 08:50 . 2009-09-21 08:50 217816 ----a-w- c:\documents and settings\dario\Dati applicazioni\PowerChallenge\nppowerloader.dll
2009-09-17 15:54 . 2009-09-18 18:17 2491192 ----a-w- c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
2009-08-27 11:37 . 2009-08-27 11:37 152576 ----a-w- c:\documents and settings\dario\Dati applicazioni\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-16 18:04 . 2009-08-16 18:01 5519752 ----a-w- c:\documents and settings\dario\Dati applicazioni\TVU Networks\TVU AutoUpgrade\TVUPlayer2.4.7.2.exe
2009-11-11 21:42 . 2009-11-09 21:18 67688 ----a-w- c:\programmi\mozilla firefox\components\jar50.dll
2009-11-11 21:42 . 2009-11-09 21:18 54368 ----a-w- c:\programmi\mozilla firefox\components\jsd3250.dll
2009-11-11 21:42 . 2009-11-09 21:18 34944 ----a-w- c:\programmi\mozilla firefox\components\myspell.dll
2009-11-11 21:43 . 2009-11-09 21:19 46712 ----a-w- c:\programmi\mozilla firefox\components\spellchk.dll
2009-11-11 21:43 . 2009-11-09 21:19 172136 ----a-w- c:\programmi\mozilla firefox\components\xpinstal.dll
2009-01-27 01:34 . 2009-01-27 01:34 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"EzPrint"="c:\programmi\Lexmark 3400 Series\ezprint.exe" [2006-02-07 98304]
"FaxCenterServer"="c:\programmi\Lexmark Fax Solutions\fm3032.exe" [2006-02-02 290816]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-05 5406720]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes Anti-Malware (reboot)"="d:\programmi1\Antivirus\malwarebytes\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\H:\0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"lxcy_device"=3 (0x3)
"STI Simulator"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Giochi\\Empire earth\\Empire Earth.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"d:\\Programmi1\\Emule 0.47\\eMule\\emule.exe"=
"d:\\Giochi\\Empire Earth 1.5\\EE-AOC.exe"=
"d:\\Giochi\\aeo2\\age2_x1\\Age2_x1.exe"=
"d:\\Programmi1\\Bearshare\\BearShare.exe"=
"c:\\Documents and Settings\\dario\\Application Data\\PowerChallenge\\PowerFootball\\PowerFootball.exe"=
"c:\\Documents and Settings\\dario\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"d:\\Programmi1\\BitTorrent\\bittorrent.exe"=
"d:\\Giochi\\Rise of Nation\\thrones.exe"=
"d:\\Giochi\\Rise of Nation\\rise.exe"=
"d:\\Programmi1\\TV internet\\Partite Gratis\\TVAnts\\Tvants.exe"=
"d:\\Programmi1\\TV internet\\SopCast\\SopCast.exe"=
"d:\\Programmi1\\TV internet\\SopCast\\adv\\SopAdver.exe"=
"d:\\Programmi1\\TV internet\\PPlive\\PPLive.exe"=
"d:\\Programmi1\\TV internet\\PPStream\\PPStream\\PPStream.exe"=
"d:\\Programmi1\\TV internet\\TVU player\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"d:\\Programmi1\\Vlc\\vlc.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\dario\\Dati applicazioni\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:emule1
"4672:UDP"= 4672:UDP:emule2
"16243:TCP"= 16243:TCP:BitComet 16243 TCP
"16243:UDP"= 16243:UDP:BitComet 16243 UDP
"4662:UDP"= 4662:UDP:BitComet 4662 UDP
"10222:TCP"= 10222:TCP:BitComet 10222 TCP
"10222:UDP"= 10222:UDP:BitComet 10222 UDP
"3389:TCP"= 3389:TCP:Remote Desktop
R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [08/11/2009 23.00.31 22360]
R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [08/11/2009 23.00.30 45416]
S3 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service --> c:\windows\system32\lxcycoms.exe -service [?]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.sys [24/02/2005 12.29.14 162176]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-11 c:\windows\Tasks\GlaryInitialize.job
- d:\programmi1\Glary Utilities\initialize.exe [2009-11-08 18:27]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
IE: Add to AMV Converter... - d:\programmi1\mpe akai\AMVConverter\grab.html
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - d:\programmi1\mpe akai\MediaManager\grab.html
FF - ProfilePath - c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\programmi\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\programmi\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - plugin: c:\docume~1\dario\DATIAP~1\POWERC~1\nppowerloader.dll
FF - plugin: c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\dario\Dati applicazioni\Mozilla\Firefox\Profiles\nlkw1gy0.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\programmi1\Divx\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: d:\programmi1\Divx\DivX Web Player\npdivx32.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-12 00:54
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x822F8B00]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\ACPI -> 0x822f8b00
\Driver\atapi -> 0x82e753b8
NDIS: Intel(R) PRO/Wireless 2200BG Network Connection -> SendCompleteHandler -> 0x82335200
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x0BA4CF80
malicious code @ sector 0x0BA4CF83 !
PE file found in sector at 0x0BA4CF99 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-299502267-1659004503-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Æ*)* \OpenWithList]
@Class="Shell"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2956)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\System32\nvsvc32.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2009-11-11 1.22.48 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-11-12 00:21
Pre-Run: 38.464.094.208 byte disponibili
Post-Run: 38.344.663.040 byte disponibili
- - End Of File - - BA1A607B5A092343D700BAA7569E37FE