ComboFix 08-12-12.05 - 2008-12-14 17:15:31.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.502.159 [GMT 1:00]
Eseguito da: c:\documents and settings\mionome\Desktop\ComboFixza.exe (l' ho rinominato io combo come suggerito in un post)
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat
C:\kmd.exe
c:\windows\system32\NavLogon.dll
c:\windows\system32\tphklock.dll
.
((((((((((((((((((((((((( Files Creati Da 2008-11-14 al 2008-12-14 )))))))))))))))))))))))))))))))))))
.
2008-12-12 20:36 . 2008-12-12 20:36 142,096 --a------ c:\windows\system32\drivers\tmcomm.sys
2008-12-12 20:35 . 2008-12-12 20:36 <DIR> d-------- c:\programmi\RootkitBuster2.2.1014
2008-12-12 19:57 . 2008-12-12 19:57 981,274 --a------ c:\programmi\RootkitBuster2.2.1014.zip
2008-12-11 22:49 . 2008-12-11 22:49 <DIR> d-------- c:\programmi\Dial-a-fix-v0.60.0.24
2008-12-11 12:31 . 2008-12-11 12:31 <DIR> d-------- C:\Desktop
2008-12-10 22:40 . 2008-12-10 22:40 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-12-10 22:40 . 2008-12-10 22:40 <DIR> d-------- c:\documents and settings\mionome\Dati applicazioni\Malwarebytes
2008-12-10 22:40 . 2008-12-10 22:40 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-12-10 22:40 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-10 22:40 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-10 21:44 . 2008-12-11 11:37 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2008-12-10 21:44 . 2008-12-10 21:44 <DIR> d-------- c:\documents and settings\mionome\Dati applicazioni\SUPERAntiSpyware.com
2008-12-10 21:44 . 2008-12-10 21:44 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-12-10 20:10 . 2008-12-10 20:10 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2008-12-10 20:09 . 2008-12-10 20:09 5,780,000 --a------ c:\programmi\SUPERAntiSpyware.exe
2008-12-09 22:12 . 2008-12-09 22:12 <DIR> d-------- c:\programmi\Panda Security
2008-12-09 22:12 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2008-12-09 10:51 . 2008-12-09 10:52 <DIR> d-------- c:\programmi\CCleaner
2008-12-08 20:06 . 2008-12-08 20:06 <DIR> d-------- c:\programmi\Trend Micro
2008-12-08 19:25 . 2008-12-08 19:25 335,992 --a------ c:\programmi\Dial-a-fix-v0.60.0.24.zip
2008-12-08 18:50 . 2008-12-08 18:50 812,344 --a------ c:\programmi\HJTInstall.exe
2008-12-06 18:15 . 2008-12-06 18:15 <DIR> d--hs---- c:\windows\ftpcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-14 16:17 19,470,368 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-14 15:59 228,452 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-14 15:58 --------- d-----w c:\programmi\Eraser
2008-12-14 14:39 5,427 ----a-w c:\windows\system32\EGATHDRV.SYS
2008-12-08 13:50 --------- d---a-w c:\programmi\Spyware Terminator
2008-12-07 23:20 --------- d---a-w c:\documents and settings\All Users\Dati applicazioni\Spyware Terminator
2008-10-16 17:30 2,588,647 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-08 23:35 2,811,211 ------w c:\programmi\Eraser57Setup.zip
2008-01-15 00:33 210,416 ------w c:\programmi\zaSetup_it.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c----w 2,778,112 2007-09-21 19:29:58 c:\programmi\Spyware Terminator\bak\SpywareTerminatorShield.exe
------w 2,778,112 2008-01-17 22:00:23 c:\programmi\Spyware Terminator\Spywareterminatorshield.Exe
-c----w 15,360 2004-08-19 21:00:00 c:\windows\system32\bak\ctfmon.exe
------w 15,360 2004-08-19 21:00:00 c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"Eraser"="c:\programmi\Eraser\eraser.exe" [2003-07-25 536576]
"WMPNSCFG"="c:\programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~2\SYMANT~1\vptray.exe" [2002-08-22 77824]
"TVT Scheduler Proxy"="c:\programmi\File comuni\Lenovo\Scheduler\scheduler_proxy.exe" [2007-07-10 540672]
"TPKMAPHELPER"="c:\programmi\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-02 856064]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-07-25 94208]
"SpywareTerminator"="c:\programmi\Spyware Terminator\SpywareTerminatorShield.exe" [2008-01-17 2778112]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-25 151552]
"Picasa Media Detector"="c:\programmi\Picasa2\PicasaMediaDetector.exe" [2006-03-16 421888]
"PDService.exe"="c:\programmi\Lenovo\SafeGuard PrivateDisk\pdservice.exe" [2006-03-13 41472]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2006-07-04 110592]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ISUSPM Startup"="c:\progra~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-07-25 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-07-25 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-07-25 77824]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2006-02-23 237568]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"DiskeeperSystray"="c:\programmi\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696]
"cssauth"="c:\programmi\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 2341632]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-25 208896]
"AwaySch"="c:\programmi\Lenovo\AwayTask\AwaySch.EXE" [2006-08-16 69632]
"AMSG"="c:\progra~1\THINKV~1\AMSG\amsg.exe" [2005-11-14 487424]
"ACWLIcon"="c:\programmi\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-08-26 110592]
"ACTray"="c:\programmi\ThinkPad\ConnectUtilities\ACTray.exe" [2006-08-26 409600]
"ZoneAlarm Client"="c:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 919016]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"TrackPointSrv"="tp4serv.exe" [2005-07-12 c:\windows\system32\tp4serv.exe]
"TP4EX"="tp4ex.exe" [2005-10-17 c:\windows\system32\TP4EX.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio veloce di Adobe Reader.lnk - c:\programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
BTTray.lnk - c:\programmi\ThinkPad\Bluetooth Software\BTTray.exe [2006-05-31 622653]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-16 24576]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
2006-08-16 18:07 49152 c:\programmi\Lenovo\AwayTask\AwayNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 15:45 28672 c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\Messenger\\msmsgs.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-12-09 28544]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.SYS [2006-11-16 11520]
R1 IBMTPCHK;IBMTPCHK;\??\c:\windows\system32\Drivers\IBMBLDID.sys [2006-11-16 6016]
R1 SASDIFSV;SASDIFSV;\??\c:\programmi\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\programmi\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R1 sp_rsdrv2;Spyware Terminator Driver 2;\??\c:\windows\system32\drivers\sp_rsdrv2.sys [2007-07-03 138624]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\Tppwrif.sys [2006-11-16 4442]
R2 DbgMsg;Debug Message;\??\c:\windows\System32\Drivers\DbgMsg.sys [2007-03-28 18240]
R2 PrivateDisk;PrivateDisk;\??\c:\programmi\Lenovo\SafeGuard PrivateDisk\PrivateDiskM.sys [2006-03-13 58368]
R2 smi2;smi2;\??\c:\programmi\SMI2\smi2.sys [2006-07-14 3968]
R3 Tp4Track;PS/2 TrackPoint Driver;c:\windows\system32\DRIVERS\tp4track.sys [2006-11-17 13840]
S3 MosIrUsb;MosIrUsb.sys;c:\windows\system32\DRIVERS\MosIrUsb.sys [2004-08-02 48128]
S3 SASENUM;SASENUM;\??\c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
.
Contenuto della cartella 'Scheduled Tasks'
2008-12-14 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2006-05-25 17:13]
2007-07-08 c:\windows\Tasks\Symantec NetDetect.job
- c:\programmi\Symantec\LiveUpdate\NDETECT.EXE [2005-04-11 18:16]
.
.
------- Supplementare di scansione -------
.
uStart Page =
hxxp://www.lenovo.com/welcome/thinkpadIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Invia a periferica &Bluetooth... - c:\programmi\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {D35CAF2C-A1A6-472A-99A0-2EFDD7E55C40} = 131.110.80.20,131.110.20.25
c:\windows\system32\capicom.dll - c:\windows\Downloaded Program Files\acpir2.dll
O16 -: {2DAD3559-2923-4935-AD49-B673D2539944}
hxxp://download.boulder.ibm.com/ibmdl/p ... /acpir.cabc:\windows\Downloaded Program Files\acpir.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-14 17:17:18
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(1396)
c:\windows\system32\tvt_gina.dll
c:\programmi\Lenovo\Client Security Solution\css_gina_plugin.dll
c:\programmi\Lenovo\Client Security Solution\css_wait_bar.dll
c:\programmi\Lenovo\Client Security Solution\cssuserdatadispatcher.dll
c:\programmi\Lenovo\Client Security Solution\csswait.dll
c:\programmi\File comuni\Lenovo\tvt_banner.dll
c:\programmi\Lenovo\Client Security Solution\cssdlgpwentry.dll
c:\programmi\Lenovo\Client Security Solution\dlganswerprompt.dll
c:\programmi\Lenovo\Client Security Solution\tvttsp.dll
c:\programmi\Lenovo\Client Security Solution\tcsrpc.dll
c:\programmi\File comuni\Lenovo\tvt_res.dll
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\programmi\Lenovo\AwayTask\AwayNotify.dll
.
Ora fine scansione: 2008-12-14 17:18:25
ComboFix-quarantined-files.txt 2008-12-14 16:18:21
Pre-Run: 36,748,505,088 byte disponibili
Post-Run: 36,723,302,400 byte disponibili
205 --- E O F --- 2008-02-23 01:29:02