|
Member
Iscritto dal: Mar 2009
Messaggi: 31
|
scusate mi sn dimenticata i log
 scusate ecco i log:
hijackthis
Quote:
Logfile of HijackThis v1.99.1
Scan saved at 22.25.29, on 19/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\AppleOSSMgr.exe
C:\WINDOWS\system32\AppleTimeSrv.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tdctxte.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\IRW.exe
C:\Programmi\Boot Camp\KbdMgr.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\reader_s.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\Documents and Settings\PC\reader_s.exe
C:\WINDOWS\system32\dwwin.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\services.exe
E:\PhoneConnectorVMC.exe
C:\Programmi\vodafone\vmclite\vmc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Prevx\prevx.exe
C:\Programmi\Prevx\prevx.exe
C:\Programmi\Mozilla Firefox 3 Beta 3\firefox.exe
C:\Documents and Settings\PC\Desktop\prog per virus vundo\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programmi\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [IRW] C:\WINDOWS\system32\IRW.exe
O4 - HKLM\..\Run: [Apple_KbdMgr] C:\Programmi\Boot Camp\KbdMgr.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [LogonStudio] "C:\Programmi\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [VeohPlugin] "C:\Programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\PC\reader_s.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\programmi\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O11 - Options group: [TABS] Tabbed Browsing
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolb...lerControl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/micr...?1208282298343
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1208282092312
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1933B4E-6953-423F-87F5-E182E6DF49DA}: NameServer = 83.224.66.134 83.224.65.134
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programmi\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Apple OS Switch Manager (AppleOSSMgr) - Unknown owner - C:\WINDOWS\system32\AppleOSSMgr.exe
O23 - Service: Servizio orario Apple (AppleTimeSrv) - Apple Inc. - C:\WINDOWS\system32\AppleTimeSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: CSIScanner - Unknown owner - C:\Programmi\Prevx\prevx.exe" /service (file missing)
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StyleXPService - Unknown owner - C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O23 - Service: tdctxte Service (tdctxte) - Unknown owner - C:\WINDOWS\system32\tdctxte.exe
|
Quote:
malware:
ComboFix 09-03-18.01 - PC 2009-03-19 19.53.38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.2028.1490 [GMT 1:00]
Eseguito da: c:\documents and settings\PC\Desktop\ComboFix.exe
AV: Sistema Antivirus NOD32 2.50 *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\PC\Impostazioni locali\Temporary Internet Files\lsn_6FBA808F-2580-48c3-8C6B-C08BBB800B8E.xml
c:\documents and settings\PC\reader_s.exe
c:\windows\file.bat
c:\windows\Install.txt
c:\windows\services.exe
c:\windows\system32\6.tmp
c:\windows\system32\7.tmp
c:\windows\system32\8.tmp
c:\windows\system32\actcontroller.exe
c:\windows\system32\C.tmp
c:\windows\system32\comsa32.sys
c:\windows\system32\D.tmp
c:\windows\system32\drivers\ntndis.sys
c:\windows\system32\drivers\protect.sys
c:\windows\system32\inf\rundll33.exe
c:\windows\system32\Lma.dll
c:\windows\system32\reader_s.exe
c:\windows\system32\rs32net.exe
c:\windows\xccwinsys.ini
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AFISICX
-------\Legacy_SOPIDKC
-------\Service_protect
-------\Service_tcpsr
((((((((((((((((((((((((( Files Creati Da 2009-02-19 al 2009-03-19 )))))))))))))))))))))))))))))))))))
.
2009-03-19 20:16 . 2009-03-19 20:18 71,680 --a------ c:\windows\system32\9.tmp
2009-03-19 20:08 . 2009-03-19 20:09 124 --a------ c:\windows\system32\5.tmp
2009-03-19 19:43 . 2009-03-19 19:43 71,680 --a------ c:\windows\system32\12.tmp
2009-03-19 19:43 . 2009-03-19 19:43 29,696 --a------ c:\windows\system32\11.tmp
2009-03-19 19:43 . 2009-03-19 19:43 124 --a------ c:\windows\system32\10.tmp
2009-03-19 19:34 . 2009-03-19 19:34 124 --a------ c:\windows\system32\B.tmp
2009-03-19 19:27 . 2009-03-19 19:31 6 --a------ c:\windows\_id.dat
2009-03-19 19:23 . 2009-03-19 19:23 124 --a------ c:\windows\system32\2.tmp
2009-03-19 18:56 . 2009-03-19 18:56 71,680 --a------ c:\windows\system32\106.tmp
2009-03-19 18:56 . 2009-03-19 18:56 124 --a------ c:\windows\system32\100.tmp
2009-03-19 18:43 . 2009-03-19 18:43 46,080 --a------ c:\windows\system32\regwiz.exe
2009-03-19 18:43 . 2009-03-19 18:43 124 --a------ c:\windows\system32\4.tmp
2009-03-19 18:38 . 2009-03-19 18:38 124 --a------ c:\windows\system32\3.tmp
2009-03-19 18:16 . 2009-03-19 18:16 71,680 --a------ c:\windows\system32\555.tmp
2009-03-19 18:16 . 2009-03-19 18:16 124 --a------ c:\windows\system32\53A.tmp
2009-03-19 18:05 . 2009-03-19 18:06 71,680 --a------ c:\windows\system32\B9.tmp
2009-03-19 18:05 . 2009-03-19 18:05 124 --a------ c:\windows\system32\A3.tmp
2009-03-19 16:58 . 2009-03-19 16:58 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-03-19 16:58 . 2009-03-19 16:58 <DIR> d-------- c:\documents and settings\PC\Dati applicazioni\Malwarebytes
2009-03-19 16:58 . 2009-03-19 16:58 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-03-19 16:58 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-19 16:58 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-18 23:50 . 2009-03-18 23:52 89,054 --a------ c:\windows\system32\1469.tmp
2009-03-18 23:50 . 2009-03-18 23:50 28,672 --a------ c:\windows\system32\145C.tmp
2009-03-18 23:50 . 2009-03-18 23:50 124 --a------ c:\windows\system32\1457.tmp
2009-03-18 23:43 . 2009-03-18 23:44 89,054 --a------ c:\windows\system32\13A1.tmp
2009-03-18 23:43 . 2009-03-18 23:43 28,672 --a------ c:\windows\system32\1396.tmp
2009-03-18 23:42 . 2009-03-18 23:43 124 --a------ c:\windows\system32\1381.tmp
2009-03-18 23:28 . 2009-03-18 23:33 89,054 --a------ c:\windows\system32\108F.tmp
2009-03-18 23:28 . 2009-03-18 23:28 28,672 --a------ c:\windows\system32\108B.tmp
2009-03-18 23:27 . 2009-03-18 23:28 124 --a------ c:\windows\system32\1088.tmp
2009-03-18 23:13 . 2009-03-18 23:14 89,054 --a------ c:\windows\system32\4EE.tmp
2009-03-18 23:12 . 2009-03-18 23:13 28,672 --a------ c:\windows\system32\4DD.tmp
2009-03-18 23:12 . 2009-03-18 23:12 124 --a------ c:\windows\system32\4D8.tmp
2009-03-18 23:10 . 2009-03-18 23:12 89,054 --a------ c:\windows\system32\416.tmp
2009-03-18 23:10 . 2009-03-18 23:10 28,672 --a------ c:\windows\system32\40E.tmp
2009-03-18 23:10 . 2009-03-19 20:16 128 --a------ c:\windows\adobe.bat
2009-03-18 23:09 . 2009-03-18 23:10 124 --a------ c:\windows\system32\3FD.tmp
2009-03-18 22:59 . 2009-03-18 22:59 182,656 --a------ c:\windows\system32\dllcache\ndis.sys
2009-03-18 22:58 . 2009-03-18 23:00 89,054 --a------ c:\windows\system32\1D8.tmp
2009-03-18 22:58 . 2009-03-18 22:58 29,696 --a------ c:\windows\system32\1B0.tmp
2009-03-18 22:58 . 2009-03-18 22:58 124 --a------ c:\windows\system32\1AA.tmp
2009-03-15 22:56 . 2009-03-15 22:56 0 --a------ c:\windows\system32\C2BF.tmp
2009-03-15 22:55 . 2009-03-15 22:56 48,734 --a------ c:\windows\system32\C251.tmp
2009-03-15 22:55 . 2009-03-15 22:55 29,696 --a------ c:\windows\system32\C242.tmp
2009-03-15 22:55 . 2009-03-15 22:55 124 --a------ c:\windows\system32\C23E.tmp
2009-03-15 21:27 . 2009-03-19 19:54 <DIR> d-------- c:\windows\system32\inf
2009-03-15 21:27 . 2009-03-14 11:23 130,235 --a------ c:\windows\system32\adx.exe
2009-03-15 21:27 . 2009-03-15 21:28 65,536 --a------ c:\windows\system32\3025.tmp
2009-03-15 21:26 . 2009-03-15 21:27 31,744 --a------ c:\windows\system32\301A.tmp
2009-03-15 21:26 . 2009-03-15 21:26 124 --a------ c:\windows\system32\3015.tmp
2009-03-15 21:15 . 2009-03-15 21:15 <DIR> d-------- c:\programmi\Nature 3D Screensaver
2009-03-15 21:15 . 2009-01-20 02:58 10,797,056 --a------ c:\windows\system32\Nature 3D Screensaver.exe
2009-03-15 21:15 . 2009-01-20 02:58 987,136 --a------ c:\windows\system32\Nature_3D_Screensaver.scr
2009-03-11 05:47 . 2009-03-11 05:47 <DIR> d-------- c:\programmi\Lighthouse Point 3D Screensaver
2009-03-11 05:47 . 2008-06-10 12:04 19,255,808 --a------ c:\windows\system32\Lighthouse Point 3D Screensaver.exe
2009-03-11 05:47 . 2008-06-09 17:26 869,888 --a------ c:\windows\system32\Lighthouse_Point_3D_Screensaver.scr
2009-03-11 03:36 . 2007-02-27 00:35 7,626 --a------ c:\windows\Koi Fish 3D Screensaver.html
2009-03-11 03:07 . 2008-12-05 07:55 144,896 --------- c:\windows\system32\dllcache\schannel.dll
2009-03-11 02:46 . 2009-03-11 02:46 <DIR> d-------- c:\programmi\Fantasy Moon 3D Screensaver
2009-03-11 02:46 . 2009-01-20 02:55 3,968,512 --a------ c:\windows\system32\Fantasy Moon 3D Screensaver.exe
2009-03-11 02:46 . 2009-01-20 02:55 984,064 --a------ c:\windows\system32\Fantasy_Moon_3D_Screensaver.scr
2009-03-11 02:32 . 2009-03-11 02:32 <DIR> d-------- c:\programmi\Nautilus 3D Screensaver
2009-03-11 02:32 . 2009-01-20 02:56 7,784,448 --a------ c:\windows\system32\Nautilus 3D Screensaver.exe
2009-03-11 02:32 . 2009-01-20 02:56 987,648 --a------ c:\windows\system32\Nautilus_3D_Screensaver.scr
2009-03-11 02:12 . 2009-03-11 02:12 <DIR> d-------- c:\programmi\Lantern 3D Screensaver
2009-03-11 02:12 . 2009-01-20 01:41 3,221,504 --a------ c:\windows\system32\Lantern 3D Screensaver.exe
2009-03-11 02:12 . 2009-01-20 02:47 457,728 --a------ c:\windows\system32\Lantern_3D_Screensaver.scr
2009-03-11 02:03 . 2009-03-11 02:03 <DIR> d-------- c:\programmi\Christmas 3D Screensaver
2009-03-11 02:03 . 2009-01-20 02:58 6,411,264 --a------ c:\windows\system32\Christmas 3D Screensaver.exe
2009-03-11 02:03 . 2009-01-20 02:58 997,376 --a------ c:\windows\system32\Christmas_3D_Screensaver.scr
2009-03-11 01:46 . 2009-03-11 01:46 <DIR> d-------- c:\programmi\Discovery 3D Screensaver
2009-03-11 01:46 . 2009-01-20 02:56 5,186,048 --a------ c:\windows\system32\Discovery 3D Screensaver.exe
2009-03-11 01:46 . 2009-01-20 02:56 984,576 --a------ c:\windows\system32\Discovery_3D_Screensaver.scr
2009-03-09 05:07 . 2009-03-09 05:07 <DIR> d-------- c:\programmi\The Lost Watch 3D Screensaver
2009-03-09 05:07 . 2009-01-20 02:59 3,154,432 --a------ c:\windows\system32\The Lost Watch 3D Screensaver.exe
2009-03-09 05:07 . 2009-01-20 02:59 993,280 --a------ c:\windows\system32\The_Lost_Watch_3D_Screensaver.scr
2009-03-09 04:22 . 2009-03-09 04:22 <DIR> d-------- c:\programmi\Fireplace 3D Screensaver
2009-03-09 04:22 . 2009-01-20 03:00 3,568,128 --a------ c:\windows\system32\Fireplace 3D Screensaver.exe
2009-03-09 04:22 . 2009-01-20 03:00 997,376 --a------ c:\windows\system32\Fireplace_3D_Screensaver.scr
2009-03-09 01:20 . 2009-03-09 01:20 <DIR> d-------- c:\windows\system32\3Planesoft
2009-03-09 01:20 . 2009-03-11 03:36 <DIR> d-------- c:\programmi\Koi Fish 3D Screensaver
2009-03-09 01:20 . 2007-02-27 06:28 9,924,608 --a------ c:\windows\system32\Koi Fish 3D Screensaver.exe
2009-03-09 01:20 . 2007-02-27 02:00 786,944 --a------ c:\windows\system32\Koi_Fish_3D_Screensaver.scr
2009-03-09 01:20 . 2009-01-20 01:33 674,816 --a------ c:\windows\system32\3Planesoft_Screensaver_Manager.scr
2009-03-09 00:52 . 2005-12-23 12:27 827,392 --a------ c:\windows\system32\Flash.ocx
2009-03-09 00:37 . 2009-03-09 00:54 114,772 --a------ C:\lma_log.html
2009-03-09 00:36 . 2009-03-09 03:39 2,909 --a------ C:\log.html
2009-03-09 00:00 . 2007-03-17 21:23 2,572 --a------ c:\windows\system32\Free Goldfish Screensaver.html
2009-03-08 23:59 . 2007-03-17 20:30 1,796,685 --a------ c:\windows\system32\Free Goldfish Screensaver.scr
2009-03-08 23:43 . 2009-03-08 23:43 <DIR> d-------- c:\programmi\Prolific Publishing, Inc
2009-03-08 23:43 . 2006-02-24 09:33 10,608,708 --a------ c:\windows\system32\Goldfish2.scr
2009-03-08 19:03 . 2009-03-08 19:03 <DIR> d-------- c:\programmi\YouTube Downloader
2009-03-08 03:42 . 2009-03-08 03:42 268 --ah----- C:\sqmdata07.sqm
2009-03-08 03:42 . 2009-03-08 03:42 244 --ah----- C:\sqmnoopt07.sqm
2009-03-08 03:40 . 2009-03-08 03:40 268 --ah----- C:\sqmdata06.sqm
2009-03-08 03:40 . 2009-03-08 03:40 244 --ah----- C:\sqmnoopt06.sqm
2009-03-08 03:07 . 2009-03-08 03:07 268 --ah----- C:\sqmdata05.sqm
2009-03-08 03:07 . 2009-03-08 03:07 244 --ah----- C:\sqmnoopt05.sqm
2009-03-08 03:03 . 2009-03-08 03:03 <DIR> d-------- c:\programmi\WinCustomize
2009-03-08 03:03 . 2000-05-17 09:52 187,392 --a------ c:\windows\system32\JPGUtils.dll
2009-03-08 03:03 . 2009-03-19 20:16 24 --a------ c:\windows\LogonStudio.ini
2009-03-07 16:17 . 2009-03-07 16:17 <DIR> d-------- c:\programmi\Stardock
2009-03-07 16:17 . 2009-03-07 16:17 <DIR> d-------- c:\programmi\File comuni\Stardock
2009-03-07 16:17 . 2009-03-07 16:33 163,712 --a------ c:\windows\system32\drivers\vidstub.sys
2009-03-07 02:15 . 2005-07-20 14:35 36,480 --a------ c:\windows\system32\drivers\P2k.sys
2009-03-07 01:38 . 2009-03-07 01:38 <DIR> d-------- C:\Program Files
2009-03-05 19:47 . 2009-03-05 19:47 2,287,616 --a------ c:\windows\system32\KERNEL.TMP
2009-03-05 19:47 . 2009-03-05 20:29 2,160,128 --a------ c:\windows\system32\kernel1.exe
2009-03-05 19:44 . 2008-04-14 03:13 219,648 --a------ c:\windows\system32\uxtheme.backup
2009-03-05 19:43 . 2009-03-05 19:43 <DIR> d-------- c:\windows\system32\Uxtheme
2009-03-05 19:38 . 2009-01-02 15:04 211 --ahs---- C:\BOOT.BKK
2009-03-05 19:37 . 2009-03-05 19:37 <DIR> d-------- c:\programmi\TGTSoft
2009-02-28 13:57 . 2008-06-17 20:01 8,490,496 --------- c:\windows\system32\dllcache\shell32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 19:19 --------- d-----w c:\programmi\Eset
2009-03-19 19:16 28,672 ----a-w c:\windows\system32\8.tmp
2009-03-19 19:09 11,450,323 ----a-w c:\windows\services.exe
2009-03-19 18:33 --------- d-----w c:\programmi\Mozilla Firefox 3 Beta 3
2009-03-18 21:59 182,656 ----a-w c:\windows\system32\drivers\ndis.sys
2009-03-08 15:18 --------- d-----w c:\documents and settings\PC\Dati applicazioni\dvdcss
2009-03-08 02:06 5,279,232 ----a-w c:\windows\system32\logonuiX.exe
2009-02-14 19:09 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\BVRP Software
2009-02-14 18:57 --------- d-----w c:\programmi\Motorola Phone Tools
2009-02-14 17:20 --------- d-----w c:\programmi\Avanquest update
2009-02-14 17:15 24,192 ----a-w c:\windows\system32\drivers\usbsermptxp.sys
2009-02-14 17:15 24,192 ----a-w c:\documents and settings\PC\usbsermptxp.sys
2009-02-14 17:15 22,768 ----a-w c:\documents and settings\PC\usbsermpt.sys
2009-02-14 17:15 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-13 23:38 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-02-13 23:35 --------- d-----w c:\programmi\File comuni\Motorola Shared
2009-02-09 14:04 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 14:04 1,846,784 ------w c:\windows\system32\dllcache\win32k.sys
2009-01-31 21:49 --------- d-----w c:\documents and settings\PC\Dati applicazioni\DivX
2009-01-25 16:27 --------- d-----w c:\programmi\DivX
2009-01-21 02:15 --------- d-----w c:\documents and settings\PC\Dati applicazioni\IcoFX
2009-01-16 20:15 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-20 22:31 826,368 ------w c:\windows\system32\dllcache\wininet.dll
2008-12-20 22:31 671,232 ------w c:\windows\system32\dllcache\mstime.dll
2008-12-20 22:31 477,696 ------w c:\windows\system32\dllcache\mshtmled.dll
2008-12-20 22:31 44,544 ------w c:\windows\system32\dllcache\pngfilt.dll
2008-12-20 22:31 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
2008-12-20 22:31 193,024 ------w c:\windows\system32\dllcache\msrating.dll
2008-12-20 22:31 105,984 ------w c:\windows\system32\dllcache\url.dll
2008-12-20 22:31 102,912 ------w c:\windows\system32\dllcache\occache.dll
2008-12-20 22:31 1,160,192 ------w c:\windows\system32\dllcache\urlmon.dll
2008-12-19 09:12 88,064 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 31,232 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
.
------- Sigcheck -------
2004-08-03 22:14 182912 1df7f42665c94b825322fae71721130d c:\windows\$NtServicePackUninstall$\ndis.sys
2008-04-13 20:20 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2009-03-18 22:59 213120 1df7f42665c94b825322fae71721130d c:\windows\system32\dllcache\ndis.sys
2009-03-18 22:59 213120 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys
2008-04-14 03:14 1053696 3cd39b831634125d5eda40cf0a254e1d c:\windows\explorer.exe
2007-06-13 14:10 1053184 151c2d5593d0d5a8c09c7d81498bb69d c:\windows\$NtServicePackUninstall$\explorer.exe
2007-01-03 11:48 1053184 659589b8ac5bb6f73fe1c46b3237a9c5 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-14 03:14 1054208 32ff41161f21d101abb0b7a9eca44791 c:\windows\ServicePackFiles\i386\explorer.exe
2004-08-19 14:39 33280 04ad9ce4d65e69680f91a4e46ae1cb2f c:\windows\$NtServicePackUninstall$\ctfmon.exe
2008-04-14 03:14 32768 f2eba1deaf00e86d8d9fdf57cce04fb7 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 03:14 32768 fc9b3db086af31c2b755a994bced8693 c:\windows\system32\ctfmon.exe
2004-08-19 14:39 42496 58834eeb7440b3faa443bec1b827c8dd c:\windows\$NtServicePackUninstall$\userinit.exe
2008-04-14 03:14 44032 37850666bd5d40ee902d49be5279fd56 c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 03:14 44032 05b951fc3ffafd295ee27d24fe80bde3 c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 32768]
"ISUSPM"="c:\documents and settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"VeohPlugin"="c:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-11-03 3522296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-15 8527872]
"IRW"="c:\windows\system32\IRW.exe" [2008-02-08 167936]
"Apple_KbdMgr"="c:\programmi\Boot Camp\KbdMgr.exe" [2008-02-08 423216]
"nod32kui"="c:\programmi\Eset\nod32kui.exe" [2008-04-15 937984]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-08 81920]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2008-11-04 434176]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"BootSkin Startup Jobs"="c:\progra~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 290816]
"LogonStudio"="c:\programmi\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"nwiz"="nwiz.exe" [2008-04-15 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-15 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 32768]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-12-20 c:\windows\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0lexx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0wgxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3fmxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5ibxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5lexx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5pyxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6jsxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@="Driver Group"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"FirewallDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Programmi\\Reallusion\\CrazyTalk for Skype\\CT4Skype.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R2 AppleOSSMgr;Apple OS Switch Manager;c:\windows\system32\AppleOSSMgr.exe [2008-02-08 132400]
R2 AppleTimeSrv;Servizio orario Apple;c:\windows\system32\AppleTimeSrv.exe [2008-02-08 99632]
R2 KeyAgent;KeyAgent;c:\windows\system32\drivers\KeyAgent.sys [2008-02-08 5504]
R2 MacHALDriver;Mac HAL;c:\windows\system32\drivers\MacHALDriver.sys [2008-02-08 6528]
R2 tdctxte;tdctxte Service;c:\windows\system32\tdctxte.exe [2001-08-31 187392]
R3 applemtm;Apple Multitouch Mouse;c:\windows\system32\drivers\applemtm.sys [2008-03-06 10496]
R3 applemtp;Apple Multitouch;c:\windows\system32\drivers\applemtp.sys [2008-03-06 15616]
R3 IRRemoteFlt;IR Receiver Filter Driver;c:\windows\system32\drivers\IRFilter.sys [2008-03-06 16512]
R3 KeyMagic;USB Keyboard HID Filter;c:\windows\system32\drivers\KeyMagic.sys [2008-03-06 19968]
S0 ati0lexx;ati0lexx;c:\windows\system32\Drivers\ati0lexx.sys --> c:\windows\system32\Drivers\ati0lexx.sys [?]
S0 ati0wgxx;ati0wgxx;c:\windows\system32\Drivers\ati0wgxx.sys --> c:\windows\system32\Drivers\ati0wgxx.sys [?]
S0 ati3fmxx;ati3fmxx;c:\windows\system32\Drivers\ati3fmxx.sys --> c:\windows\system32\Drivers\ati3fmxx.sys [?]
S0 ati5ibxx;ati5ibxx;c:\windows\system32\Drivers\ati5ibxx.sys --> c:\windows\system32\Drivers\ati5ibxx.sys [?]
S0 ati5lexx;ati5lexx;c:\windows\system32\Drivers\ati5lexx.sys --> c:\windows\system32\Drivers\ati5lexx.sys [?]
S0 ati5pyxx;ati5pyxx;c:\windows\system32\Drivers\ati5pyxx.sys --> c:\windows\system32\Drivers\ati5pyxx.sys [?]
S0 ati6jsxx;ati6jsxx;c:\windows\system32\Drivers\ati6jsxx.sys --> c:\windows\system32\Drivers\ati6jsxx.sys [?]
S0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys --> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d44c2c6a-0a50-11dd-82c4-001ec2899937}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d44c2c6b-0a50-11dd-82c4-001ec2899937}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
.
Contenuto della cartella 'Scheduled Tasks'
2008-11-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-19 c:\windows\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- c:\programmi\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
HKCU-Run-reader_s - c:\documents and settings\PC\reader_s.exe
HKCU-Run-services - c:\windows\services.exe
HKLM-Run-trioService - c:\programmi\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe
HKLM-Run-reader_s - c:\windows\System32\reader_s.exe
HKLM-Run-services - c:\windows\services.exe
HKU-Default-Run-rs32net - c:\windows\System32\rs32net.exe
HKU-Default-Run-reader_s - c:\documents and settings\PC\reader_s.exe
HKU-Default-Run-services - c:\windows\services.exe
HKLM-Explorer_Run-services - c:\windows\services.exe
HKCU-Explorer_Run-services - c:\windows\services.exe
HKU-Default-Explorer_Run-services - c:\windows\services.exe
MSConfigStartUp-eMuleAutoStart - c:\programmi\eMule\emule.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://it.msn.com
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\programmi\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\PC\Dati applicazioni\Mozilla\Firefox\Profiles\rfatvrkq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=it-IT&FORM=MICI05&q=
FF - component: c:\programmi\Mozilla Firefox 3 Beta 3\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\programmi\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\programmi\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-19 20:20:45
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwOpenFile
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(984)
c:\programmi\Bonjour\mdnsNSP.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Eset\nod32krn.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\qoobox\Quarantine\C\WINDOWS\system32\reader_s.exe.virpen
c:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2009-03-19 20:22:36 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-03-19 19:22:32
Pre-Run: 14.422.736.896 byte disponibili
Post-Run: 14,500,573,184 byte disponibili
359 --- E O F --- 2009-03-15 22:09:20
|
Ultima modifica di Chill-Out : 19-03-2009 alle 21:58.
|