Pensavo di essere riuscita a debellarlo invece stamattina appena acceso il computer ecco là antivirus scomparso di nuovo... stessi sintomi di prima tutto uguale (premetto che non ho ne' scaricato ne' installato nulla di nuovo)...
Ho provato con lo stesso metodo di qualche giorno fa ma niente stavolta non funziona...
Vi posto il log di combofix che mi è uscito:
ComboFix 08-10-15.08 - Administrator 2008-10-20 10.11.53.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1661 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Administrator\Desktop\roba virus\ComboFix.exe
Interruttori di comando utilizzati :: C:\Documents and Settings\Administrator\Desktop\roba virus\CFScript.txt
* Creato nuovo punto di ripristino
* Resident AV is active
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
FILE ::
C:\WINDOWS\system32\d1ae6bf2a2fdd47d259b1c5be3f614d7.sys
.
((((((((((((((((((((((((( Files Creati Da 2008-09-20 al 2008-10-20 )))))))))))))))))))))))))))))))))))
.
2008-10-20 10:07 . 2008-10-20 10:07 168 --a------ C:\log.udt
2008-10-20 10:00 . 2008-10-20 10:00 185,360 --a------ C:\WINDOWS\572E7957932142F93932B175667526BC.exe
2008-10-17 19:08 . 2008-10-17 19:37 <DIR> d-a------ C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-10-17 16:56 . 2008-10-17 16:56 313,871 --------- C:\WINDOWS\system32\e0c29e3d5df1cb4c31d8f18a6360ea11.TMP
2008-10-17 16:28 . 2008-10-17 16:43 <DIR> d-------- C:\Programmi\FindyKill
2008-10-17 15:04 . 2008-10-17 15:04 8,704 --ahsc--- C:\WINDOWS\system32\dllcache\Thumbs.db
2008-10-17 10:21 . 2008-10-17 10:21 <DIR> d-------- C:\Programmi\TeamViewer3
2008-10-17 10:21 . 2008-10-17 10:21 <DIR> d-------- C:\Documents and Settings\Administrator\Dati applicazioni\TeamViewer
2008-10-17 10:20 . 2008-10-17 10:20 <DIR> d-------- C:\Documents and Settings\Administrator\temp
2008-10-16 20:23 . 2004-08-13 18:30 45,056 --a------ C:\SDTrestore.exe
2008-10-16 20:23 . 2004-08-13 18:30 34,244 --a------ C:\SDTrestore.cpp
2008-10-16 20:23 . 2004-08-13 18:30 192 --a------ C:\compile.bat
2008-10-15 15:29 . 2008-10-15 15:29 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\GameHouse
2008-10-15 15:24 . 2008-10-15 15:24 <DIR> d-------- C:\WINDOWS\Delicious Emilys Tea Garden
2008-10-15 15:24 . 2008-10-15 19:05 <DIR> d-------- C:\Programmi\Delicious Emilys Tea Garden
2008-10-13 14:34 . 2008-10-13 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Gogii
2008-10-13 14:33 . 2008-10-13 14:33 <DIR> d-------- C:\WINDOWS\The Hidden Object Show Season 2
2008-10-13 14:33 . 2008-10-17 19:08 <DIR> d-------- C:\Programmi\The Hidden Object Show Season 2
2008-10-12 15:50 . 2008-10-12 15:50 <DIR> d-------- C:\WINDOWS\Cake Shop
2008-10-12 15:50 . 2008-10-13 14:30 <DIR> d-------- C:\Programmi\Cake Shop
2008-10-12 15:50 . 2008-10-12 15:50 <DIR> d-------- C:\Documents and Settings\Administrator\Dati applicazioni\EleFun Games
2008-10-09 17:38 . 2008-10-09 17:38 <DIR> d-------- C:\Programmi\PlayFirst
2008-09-24 01:24 . 2008-09-24 01:24 244 --ah----- C:\sqmnoopt05.sqm
2008-09-24 01:24 . 2008-09-24 01:24 244 --ah----- C:\sqmnoopt04.sqm
2008-09-24 01:24 . 2008-09-24 01:24 232 --ah----- C:\sqmdata05.sqm
2008-09-24 01:24 . 2008-09-24 01:24 232 --ah----- C:\sqmdata04.sqm
2008-09-23 22:11 . 2008-09-23 22:11 244 --ah----- C:\sqmnoopt03.sqm
2008-09-23 22:11 . 2008-09-23 22:11 232 --ah----- C:\sqmdata03.sqm
2008-09-23 22:08 . 2008-09-23 22:08 244 --ah----- C:\sqmnoopt02.sqm
2008-09-23 22:08 . 2008-09-23 22:08 232 --ah----- C:\sqmdata02.sqm
2008-09-23 21:14 . 2008-09-23 21:14 244 --ah----- C:\sqmnoopt01.sqm
2008-09-23 21:14 . 2008-09-23 21:14 232 --ah----- C:\sqmdata01.sqm
2008-09-23 21:13 . 2008-09-23 21:13 244 --ah----- C:\sqmnoopt00.sqm
2008-09-23 21:13 . 2008-09-23 21:13 232 --ah----- C:\sqmdata00.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 18:17 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-10-14 11:33 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\HPAppData
2008-10-13 12:30 --------- d-----w C:\Programmi\Farm Frenzy 2
2008-10-13 10:41 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-10-09 15:39 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\PlayFirst
2008-10-09 15:39 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\PlayFirst
2008-09-24 08:01 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-09-17 11:54 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-09-12 23:46 --------- d-----w C:\Programmi\Gravity
2008-09-09 16:37 --------- d-----w C:\Programmi\Eset
2008-09-04 10:42 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Jasc
2008-09-02 14:00 512,096 ----a-w C:\WINDOWS\system32\drivers\_mon.s00
2008-09-02 14:00 15,424 ----a-w C:\WINDOWS\system32\drivers\_od32drv.s00
2008-09-02 13:53 512,096 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-09-02 13:53 298,104 ----a-w C:\WINDOWS\system32\imon.dll
2008-09-02 13:53 15,424 ----a-w C:\WINDOWS\system32\drivers\nod32drv.sys
2008-09-02 13:05 --------- d-----w C:\Programmi\EsetOnlineScanner
2008-08-29 19:14 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-08-29 19:14 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-08-29 19:14 --------- d-----w C:\Programmi\File comuni\xing shared
2008-08-29 19:14 --------- d-----w C:\Programmi\File comuni\Real
2008-08-29 11:01 --------- d-----w C:\Programmi\Photo Story 3 for Windows
2008-08-28 12:41 --------- d-----w C:\Programmi\Pinnacle
2008-08-27 10:13 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Pinnacle VideoSpin
2008-08-27 09:05 --------- d-----w C:\Programmi\Google
2008-08-27 09:03 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\VideoSpin
2008-08-27 09:02 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Pinnacle
2008-08-27 08:51 --------- d-----w C:\Programmi\File comuni\Ulead Systems
2008-08-27 08:51 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Ulead Systems
2008-08-27 08:41 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Ulead Systems
2008-08-27 07:31 --------- d-----w C:\Programmi\Jasc Software Inc
2008-08-27 07:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\InstallShield
2008-08-27 07:29 --------- d-----w C:\Programmi\File comuni\Jasc Software Inc
2008-08-27 07:29 --------- d-----w C:\Programmi\File comuni\InstallShield
2008-08-27 07:28 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Jasc Software Inc
2008-08-25 20:42 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\FarmFrenzy2
2008-08-25 17:31 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Gamelab
2008-08-25 17:00 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Go-Go Gourmet Chef of the Year
.
((((((((((((((((((((((((((((( snapshot@2008-10-16_17.53.24.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-06-07 10:15:03 52,240 ----a-w C:\WINDOWS\system32\cunta.dll
+ 2006-04-08 10:20:46 52,240 ----a-w C:\WINDOWS\system32\cunta.dll
- 2004-06-07 10:15:14 313,871 ----a-w C:\WINDOWS\system32\fdbbcbeeefebc.dll
+ 2006-04-08 10:20:48 313,871 ----a-w C:\WINDOWS\system32\fdbbcbeeefebc.dll
- 2008-08-01 18:08:26 62,422 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-10-17 14:45:18 62,422 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-01 18:08:26 74,518 ----a-w C:\WINDOWS\system32\perfc010.dat
+ 2008-10-17 14:45:18 74,518 ----a-w C:\WINDOWS\system32\perfc010.dat
- 2008-08-01 18:08:26 400,760 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-10-17 14:45:18 400,760 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-08-01 18:08:26 447,418 ----a-w C:\WINDOWS\system32\perfh010.dat
+ 2008-10-17 14:45:18 447,418 ----a-w C:\WINDOWS\system32\perfh010.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"DAEMON Tools"="C:\Programmi\DAEMON Tools\daemon.exe" [2007-04-04 165784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Programmi\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 8466432]
"UnlockerAssistant"="C:\Programmi\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2008-03-28 413696]
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2008-08-29 185896]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2008-09-02 949376]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-14 172032]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fdbbcbeeefebc]
2006-04-08 12:20 313871 C:\WINDOWS\system32\fdbbcbeeefebc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dfaaaefdaf]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 04:14 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2007-05-15 15:55 1057328 C:\Programmi\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Programmi\File comuni\Ahead\lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-06-28 18:43 8466432 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-28 18:43 81920 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
--a------ 2007-05-15 15:55 1628208 C:\Programmi\Nero\Nero 7\InCD\NBHGui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2006-09-07 19:19 15872 C:\Programmi\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 12:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2008-04-14 04:14 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-28 18:43 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2007-04-12 11:33 16132608 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"C:\\Programmi\\iTunes\\iTunes.exe"=
"C:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 12416]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-07-12 10752]
S2 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-20 10:15:15
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\d1ae6bf2a2fdd47d259b1c5be3f614d7]
"ImagePath"="system32\d1ae6bf2a2fdd47d259b1c5be3f614d7.sys"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
PROCESSO: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\fdbbcbeeefebc.dll
-> C:\Programmi\Eset\pr_imon.dll
PROCESSO: C:\WINDOWS\system32\lsass.exe
-> C:\Programmi\Eset\pr_imon.dll
.
Ora fine scansione: 2008-10-20 10.19.05
ComboFix-quarantined-files.txt 2008-10-20 08:19:01
ComboFix2.txt 2008-10-17 14:58:54
ComboFix3.txt 2008-10-16 15:54:35
Pre-Run: 72.571.006.976 byte disponibili
Post-Run: 72,628,060,160 byte disponibili
221 --- E O F --- 2008-07-07 23:58:30
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1661 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Administrator\Desktop\roba virus\ComboFix.exe
Interruttori di comando utilizzati :: C:\Documents and Settings\Administrator\Desktop\roba virus\CFScript.txt
* Creato nuovo punto di ripristino
* Resident AV is active
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!
FILE ::
C:\WINDOWS\system32\d1ae6bf2a2fdd47d259b1c5be3f614d7.sys
.
((((((((((((((((((((((((( Files Creati Da 2008-09-20 al 2008-10-20 )))))))))))))))))))))))))))))))))))
.
2008-10-20 10:07 . 2008-10-20 10:07 168 --a------ C:\log.udt
2008-10-20 10:00 . 2008-10-20 10:00 185,360 --a------ C:\WINDOWS\572E7957932142F93932B175667526BC.exe
2008-10-17 19:08 . 2008-10-17 19:37 <DIR> d-a------ C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-10-17 16:56 . 2008-10-17 16:56 313,871 --------- C:\WINDOWS\system32\e0c29e3d5df1cb4c31d8f18a6360ea11.TMP
2008-10-17 16:28 . 2008-10-17 16:43 <DIR> d-------- C:\Programmi\FindyKill
2008-10-17 15:04 . 2008-10-17 15:04 8,704 --ahsc--- C:\WINDOWS\system32\dllcache\Thumbs.db
2008-10-17 10:21 . 2008-10-17 10:21 <DIR> d-------- C:\Programmi\TeamViewer3
2008-10-17 10:21 . 2008-10-17 10:21 <DIR> d-------- C:\Documents and Settings\Administrator\Dati applicazioni\TeamViewer
2008-10-17 10:20 . 2008-10-17 10:20 <DIR> d-------- C:\Documents and Settings\Administrator\temp
2008-10-16 20:23 . 2004-08-13 18:30 45,056 --a------ C:\SDTrestore.exe
2008-10-16 20:23 . 2004-08-13 18:30 34,244 --a------ C:\SDTrestore.cpp
2008-10-16 20:23 . 2004-08-13 18:30 192 --a------ C:\compile.bat
2008-10-15 15:29 . 2008-10-15 15:29 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\GameHouse
2008-10-15 15:24 . 2008-10-15 15:24 <DIR> d-------- C:\WINDOWS\Delicious Emilys Tea Garden
2008-10-15 15:24 . 2008-10-15 19:05 <DIR> d-------- C:\Programmi\Delicious Emilys Tea Garden
2008-10-13 14:34 . 2008-10-13 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Gogii
2008-10-13 14:33 . 2008-10-13 14:33 <DIR> d-------- C:\WINDOWS\The Hidden Object Show Season 2
2008-10-13 14:33 . 2008-10-17 19:08 <DIR> d-------- C:\Programmi\The Hidden Object Show Season 2
2008-10-12 15:50 . 2008-10-12 15:50 <DIR> d-------- C:\WINDOWS\Cake Shop
2008-10-12 15:50 . 2008-10-13 14:30 <DIR> d-------- C:\Programmi\Cake Shop
2008-10-12 15:50 . 2008-10-12 15:50 <DIR> d-------- C:\Documents and Settings\Administrator\Dati applicazioni\EleFun Games
2008-10-09 17:38 . 2008-10-09 17:38 <DIR> d-------- C:\Programmi\PlayFirst
2008-09-24 01:24 . 2008-09-24 01:24 244 --ah----- C:\sqmnoopt05.sqm
2008-09-24 01:24 . 2008-09-24 01:24 244 --ah----- C:\sqmnoopt04.sqm
2008-09-24 01:24 . 2008-09-24 01:24 232 --ah----- C:\sqmdata05.sqm
2008-09-24 01:24 . 2008-09-24 01:24 232 --ah----- C:\sqmdata04.sqm
2008-09-23 22:11 . 2008-09-23 22:11 244 --ah----- C:\sqmnoopt03.sqm
2008-09-23 22:11 . 2008-09-23 22:11 232 --ah----- C:\sqmdata03.sqm
2008-09-23 22:08 . 2008-09-23 22:08 244 --ah----- C:\sqmnoopt02.sqm
2008-09-23 22:08 . 2008-09-23 22:08 232 --ah----- C:\sqmdata02.sqm
2008-09-23 21:14 . 2008-09-23 21:14 244 --ah----- C:\sqmnoopt01.sqm
2008-09-23 21:14 . 2008-09-23 21:14 232 --ah----- C:\sqmdata01.sqm
2008-09-23 21:13 . 2008-09-23 21:13 244 --ah----- C:\sqmnoopt00.sqm
2008-09-23 21:13 . 2008-09-23 21:13 232 --ah----- C:\sqmdata00.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 18:17 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-10-14 11:33 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\HPAppData
2008-10-13 12:30 --------- d-----w C:\Programmi\Farm Frenzy 2
2008-10-13 10:41 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-10-09 15:39 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\PlayFirst
2008-10-09 15:39 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\PlayFirst
2008-09-24 08:01 --------- d--h--w C:\Programmi\InstallShield Installation Information
2008-09-17 11:54 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-09-12 23:46 --------- d-----w C:\Programmi\Gravity
2008-09-09 16:37 --------- d-----w C:\Programmi\Eset
2008-09-04 10:42 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Jasc
2008-09-02 14:00 512,096 ----a-w C:\WINDOWS\system32\drivers\_mon.s00
2008-09-02 14:00 15,424 ----a-w C:\WINDOWS\system32\drivers\_od32drv.s00
2008-09-02 13:53 512,096 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-09-02 13:53 298,104 ----a-w C:\WINDOWS\system32\imon.dll
2008-09-02 13:53 15,424 ----a-w C:\WINDOWS\system32\drivers\nod32drv.sys
2008-09-02 13:05 --------- d-----w C:\Programmi\EsetOnlineScanner
2008-08-29 19:14 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-08-29 19:14 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-08-29 19:14 --------- d-----w C:\Programmi\File comuni\xing shared
2008-08-29 19:14 --------- d-----w C:\Programmi\File comuni\Real
2008-08-29 11:01 --------- d-----w C:\Programmi\Photo Story 3 for Windows
2008-08-28 12:41 --------- d-----w C:\Programmi\Pinnacle
2008-08-27 10:13 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Pinnacle VideoSpin
2008-08-27 09:05 --------- d-----w C:\Programmi\Google
2008-08-27 09:03 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\VideoSpin
2008-08-27 09:02 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Pinnacle
2008-08-27 08:51 --------- d-----w C:\Programmi\File comuni\Ulead Systems
2008-08-27 08:51 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Ulead Systems
2008-08-27 08:41 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Ulead Systems
2008-08-27 07:31 --------- d-----w C:\Programmi\Jasc Software Inc
2008-08-27 07:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\InstallShield
2008-08-27 07:29 --------- d-----w C:\Programmi\File comuni\Jasc Software Inc
2008-08-27 07:29 --------- d-----w C:\Programmi\File comuni\InstallShield
2008-08-27 07:28 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Jasc Software Inc
2008-08-25 20:42 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\FarmFrenzy2
2008-08-25 17:31 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Gamelab
2008-08-25 17:00 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Go-Go Gourmet Chef of the Year
.
((((((((((((((((((((((((((((( snapshot@2008-10-16_17.53.24.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-06-07 10:15:03 52,240 ----a-w C:\WINDOWS\system32\cunta.dll
+ 2006-04-08 10:20:46 52,240 ----a-w C:\WINDOWS\system32\cunta.dll
- 2004-06-07 10:15:14 313,871 ----a-w C:\WINDOWS\system32\fdbbcbeeefebc.dll
+ 2006-04-08 10:20:48 313,871 ----a-w C:\WINDOWS\system32\fdbbcbeeefebc.dll
- 2008-08-01 18:08:26 62,422 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-10-17 14:45:18 62,422 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-01 18:08:26 74,518 ----a-w C:\WINDOWS\system32\perfc010.dat
+ 2008-10-17 14:45:18 74,518 ----a-w C:\WINDOWS\system32\perfc010.dat
- 2008-08-01 18:08:26 400,760 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-10-17 14:45:18 400,760 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-08-01 18:08:26 447,418 ----a-w C:\WINDOWS\system32\perfh010.dat
+ 2008-10-17 14:45:18 447,418 ----a-w C:\WINDOWS\system32\perfh010.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"DAEMON Tools"="C:\Programmi\DAEMON Tools\daemon.exe" [2007-04-04 165784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Programmi\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 8466432]
"UnlockerAssistant"="C:\Programmi\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2008-03-28 413696]
"TkBellExe"="C:\Programmi\File comuni\Real\Update_OB\realsched.exe" [2008-08-29 185896]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2008-09-02 949376]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-14 172032]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fdbbcbeeefebc]
2006-04-08 12:20 313871 C:\WINDOWS\system32\fdbbcbeeefebc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dfaaaefdaf]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 04:14 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2007-05-15 15:55 1057328 C:\Programmi\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Programmi\File comuni\Ahead\lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-06-28 18:43 8466432 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-28 18:43 81920 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
--a------ 2007-05-15 15:55 1628208 C:\Programmi\Nero\Nero 7\InCD\NBHGui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2006-09-07 19:19 15872 C:\Programmi\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 12:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2008-04-14 04:14 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-28 18:43 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2007-04-12 11:33 16132608 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"C:\\Programmi\\iTunes\\iTunes.exe"=
"C:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 12416]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-07-12 10752]
S2 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-20 10:15:15
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\d1ae6bf2a2fdd47d259b1c5be3f614d7]
"ImagePath"="system32\d1ae6bf2a2fdd47d259b1c5be3f614d7.sys"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
PROCESSO: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\fdbbcbeeefebc.dll
-> C:\Programmi\Eset\pr_imon.dll
PROCESSO: C:\WINDOWS\system32\lsass.exe
-> C:\Programmi\Eset\pr_imon.dll
.
Ora fine scansione: 2008-10-20 10.19.05
ComboFix-quarantined-files.txt 2008-10-20 08:19:01
ComboFix2.txt 2008-10-17 14:58:54
ComboFix3.txt 2008-10-16 15:54:35
Pre-Run: 72.571.006.976 byte disponibili
Post-Run: 72,628,060,160 byte disponibili
221 --- E O F --- 2008-07-07 23:58:30
Spero riusciate ad aiutarmi di nuovo
![Mi metto a piangere... [cry]](http://www.megalab.it/forum/images/smilies/crying.gif)