ecco qua, questo è comboFix
ComboFix 09-03-25.04 - Lig 2009-03-26 23.54.17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.2047.1513 [GMT 1:00]
Eseguito da: c:\documents and settings\Marco\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\saoiy.dat
c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\saoiy.exe
c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\saoiy_nav.dat
c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\saoiy_navps.dat
c:\documents and settings\Marco\Impostazioni locali\Temporary Internet Files\sc
c:\documents and settings\Marco\Impostazioni locali\Temporary Internet Files\sc\console.html
c:\documents and settings\Marco\Impostazioni locali\Temporary Internet Files\sc\script0.html
c:\documents and settings\Marco\Impostazioni locali\Temporary Internet Files\sc\script1.html
c:\documents and settings\Marco\Impostazioni locali\Temporary Internet Files\temp1.htm
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Creati Da 2009-02-26 al 2009-03-26 )))))))))))))))))))))))))))))))))))
.
2009-03-25 20:09 . 2009-03-25 20:50 <DIR> d-------- c:\programmi\Spybot - Search & Destroy
2009-03-25 20:09 . 2009-03-25 20:25 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-03-24 19:47 . 2009-03-26 22:20 <DIR> d-------- c:\documents and settings\Marco\Tracing
2009-03-24 19:45 . 2009-03-24 19:45 <DIR> d-------- c:\programmi\Windows Live SkyDrive
2009-03-24 19:45 . 2009-03-24 19:45 <DIR> d-------- c:\programmi\Microsoft
2009-03-24 19:43 . 2009-03-24 19:43 <DIR> d-------- c:\programmi\File comuni\Windows Live
2009-03-14 02:18 . 2009-03-25 00:36 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-14 02:18 . 2009-03-14 02:18 1,409 --a------ c:\windows\QTFont.for
2009-03-01 17:21 . 2009-03-03 21:27 <DIR> d-------- c:\programmi\Crayon Physics Deluxe
2009-03-01 17:21 . 2009-03-01 17:23 <DIR> d-------- c:\documents and settings\Marco\Dati applicazioni\Crayon Physics Deluxe
2009-02-27 00:28 . 2009-02-27 00:28 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-26 23:08 --------- d-----w c:\programmi\cFosSpeed
2009-03-26 21:15 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-03-26 21:15 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2009-03-26 18:39 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\AntiVir PersonalEdition Classic
2009-03-24 18:45 --------- d-----w c:\programmi\Windows Live
2009-03-17 19:38 --------- d-----w c:\programmi\Metin2_Italiano
2009-03-07 22:36 --------- d-----w c:\programmi\DC++
2009-03-07 16:43 --------- d---a-w c:\programmi\eMule0.47a
2009-02-21 12:21 --------- d-----w c:\programmi\Microsoft Silverlight
2009-02-12 21:44 --------- d-----w c:\programmi\Messenger Plus! Live
2009-02-09 14:04 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 17:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2008-12-31 16:04 691,560 ----a-w c:\windows\system32\OGACheckControl.dll
2008-12-31 16:04 528,744 ----a-w c:\windows\system32\OGAVerify.exe
2008-12-31 16:04 502,120 ----a-w c:\windows\system32\OGAAddin.dll
2008-08-06 23:49 411,248 ----a-w c:\programmi\FLV PlayerRCSetup.exe
2008-10-22 18:29 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008102220081023\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ULiRaid"="c:\programmi\ULiRaid\ULiRaid.exe" [2005-12-29 462848]
"cFosSpeed"="c:\programmi\cFosSpeed\cFosSpeed.exe" [2005-12-01 712704]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2006-05-26 282624]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"avgnt"="c:\programmi\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 266497]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 63712]
"AliceRE_McciTrayApp"="c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\MCCITR~1.EXE" [2006-11-21 936960]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"LogitechCommunicationsManager"="c:\programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"Start WingMan Profiler"="c:\programmi\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"AdslTaskBar"="stmctrl.dll" [2003-05-20 c:\windows\system32\stmctrl.dll]
"P17Helper"="P17.dll" [2006-03-17 c:\windows\system32\P17.dll]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2008-03-02 217088]
Logitech SetPoint.lnk - c:\programmi\Logitech\SetPoint\SetPoint.exe [2006-09-26 450560]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Avvio veloce di Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Avvio veloce di Adobe Reader.lnk
backup=c:\windows\pss\Avvio veloce di Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HELPExpress.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HELPExpress.lnk
backup=c:\windows\pss\HELPExpress.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Marco^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma.lnk]
path=c:\documents and settings\Marco\Menu Avvio\Programmi\Esecuzione automatica\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a--c--- 2005-09-08 10:06 94208 c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-14 03:14 1695232 c:\programmi\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a--c--- 2004-11-02 19:24 32768 c:\programmi\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2005-11-10 12:03 36975 c:\programmi\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Azureus\\Azureus.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\eMule0.47a\\emule.exe"=
"c:\\Programmi\\rFactor\\rFactor.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Toca Race Driver 2\\RD2.exe"=
"c:\\GTR2\\GTR2.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\Documents and Settings\\Marco\\Documenti\\GTR2NAP\\GTR2.exe"=
"c:\\Programmi\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Programmi\\DC++\\DCPlusPlus.exe"=
"c:\\Programmi\\TVAnts\\Tvants.exe"=
"c:\\Programmi\\File comuni\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Programmi\\THQ\\MotoGP 2007\\motogp.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Programmi\\MiniRacingOnline\\MiniRacingOnLine.exe"=
"c:\\Programmi\\Microsoft Office\\OFFICE11\\FRONTPG.EXE"=
"c:\\Programmi\\Metin2_Italiano\\metin2.bin"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 m5288;m5288;c:\windows\system32\drivers\m5288.sys [2006-01-04 210304]
R0 ULiFilter;ULi PCIE Bridge Filter;c:\windows\system32\drivers\ULiFiltr.sys [2006-05-17 61440]
R0 ULipnp;ULi PnP Driver;c:\windows\system32\drivers\ULiPnP.sys [2006-05-17 8064]
R3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [2006-03-20 1452032]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;c:\windows\system32\drivers\ULILAN51.SYS [2006-05-17 28672]
S3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [2006-05-21 59338]
S3 TaurusUsb;ADSL Modem USB Service 1.09a;c:\windows\system32\drivers\torususb.sys [2006-05-21 527980]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - ALG
*Deregistered* - AntiVirScheduler
*Deregistered* - AntiVirService
*Deregistered* - AudioSrv
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - CCALib8
*Deregistered* - cFosSpeedS
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - HTTPFilter
*Deregistered* - ImapiService
*Deregistered* - Irmon
*Deregistered* - JavaQuickStarterService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - LVCOMSer
*Deregistered* - LVPrcSrv
*Deregistered* - LVSrvLauncher
*Deregistered* - MDM
*Deregistered* - Netman
*Deregistered* - Network WanMiniport First Position
*Deregistered* - Nla
*Deregistered* - NVSvc
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - ServiceLayer
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - UMWdf
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WmiApSrv
*Deregistered* - WmXlCore
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{14350adb-a4d0-11dd-917f-00138f8f0c45}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contenuto della cartella 'Scheduled Tasks'
2009-03-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1979792683-725345543-1003.job
- c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2008-09-02 20:55]
2009-03-26 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-03-26 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-saoiy - c:\documents and settings\marco\impostazioni locali\dati applicazioni\saoiy.exe
HKLM-Run-RTHDCPL - RTHDCPL.EXE
HKU-Default-Run-Nokia.PCSync - c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
Notify-WgaLogon - (no file)
MSConfigStartUp-DAEMON Tools-1033 - c:\programmi\D-Tools\daemon.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://virgilio.alice.it/indexbb.html
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
IE: Add to AMV Converter... - c:\programmi\MP3 Player Utilities 4.13\AMVConverter\grab.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\programmi\MP3 Player Utilities 4.13\MediaManager\grab.html
TCP: {32A885A3-5897-40A5-B353-11E34E13806E} = 208.67.222.222,208.67.220.220
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {4819DFDF-ABC4-488C-A323-919848C51175} - hxxp://portal3.rinera.com/download/RineraProxy-1.4.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-27 00:08:57
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\dwkhn]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) ) (Everyone)
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
"{DF6C93B5-1FB4-BDAD-2F0B-EE7511C45AAD}"=""
[HKEY_LOCAL_MACHINE\software\Microsoft\fiaka]
@Ace=(Denied: NO_PROPAGATE_INHERIT_ACE) ) (Everyone)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ĝ|˙˙˙˙|ù9~*]
"0140710900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2009-03-27 0.27.38
ComboFix-quarantined-files.txt 2009-03-26 23:27:14
Pre-Run: 121.131.806.720 byte disponibili
Post-Run: 121,844,740,096 byte disponibili
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
266 --- E O F --- 2009-03-21 03:35:30
E questo è A-squared
a-squared Free - Versione 4.0
Ultimo aggiornamento: 27/03/2009 0.53.08
Impostazioni scansione:
Oggetti: Memoria, Tracce, Cookies, C:\
Archivio scansioni: On
Scientifico: Off
ADS Scan: On
Scansione avviata: 27/03/2009 0.54.09
c:\documents and settings\marco\desktop\emule.lnk rilevati: Trace.File.Emule 5.0!A2
Key: HKEY_USERS\S-1-5-21-2025429265-1979792683-725345543-1003\software\kazaa rilevati: Trace.Registry.KaZaA!A2
C:\Documents and Settings\Marco\Cookies\
[email protected][2].txt rilevati: Trace.TrackingCookie.adserv!A2
C:\Documents and Settings\Marco\Cookies\lig@adtech[1].txt rilevati: Trace.TrackingCookie.adtech!A2
C:\Documents and Settings\Marco\Cookies\lig@com[1].txt rilevati: Trace.TrackingCookie.com!A2
C:\Documents and Settings\Marco\Desktop\Programmi installazione\Firmware n80\Firmware n80\crack_dongle_phoenix_2004.exe/DK2WN95.386 rilevati: Trojan.Win32.Agent!IK
C:\Documents and Settings\Marco\Documenti\Programmi installazione\Firmware n80\Firmware n80\crack_dongle_phoenix_2004.exe/DK2WN95.386 rilevati: Trojan.Win32.Agent!IK
C:\Documents and Settings\Marco\Documenti\Programmi installazione\Firmware n80\Firmware n80\Nokia Diego v3.07 + Crack.zip/DK2WN95.386 rilevati: Trojan.Win32.Agent!IK
Scansionati
Files: 379145
Tracce: 581358
Cookies: 40
Processi: 55
Rilevato
Files: 3
Tracce: 2
Cookies: 4
Processi: 0
Chiavi di registro: 0
Fine scansione: 27/03/2009 3.14.20
Tempo scansione: 2:20:11
grazie