ComboFix 07-12-19.2 - Alex 2007-12-20 18.21.39.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.1513 [GMT 1:00]
Eseguito da: C:\Documents and Settings\Alex\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Alex\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
FILE
C:\WINDOWS\system32\ALEXKANE.dll
C:\WINDOWS\system32\drivers\oreans32.sys
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ALEXKANE.dll
.
((((((((((((((((((((((((( Files Creati Da 2007-11-20 al 2007-12-20 )))))))))))))))))))))))))))))))))))
.
2007-12-19 20:28 . 2007-12-19 21:20 <DIR> d-------- C:\Programmi\a-squared Free
2007-12-19 16:49 . 2007-12-19 16:49 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-19 12:03 . 2007-12-19 12:03 5,120 --a------ C:\WINDOWS\system32\Thumbs.db
2007-12-18 14:06 . 2007-12-18 14:14 <DIR> d-------- C:\Programmi\EasyPHP1-8
2007-12-18 00:33 . 2007-12-20 12:07 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-18 00:33 . 2007-12-18 00:33 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-15 19:26 . 2007-12-15 19:26 768 --a------ C:\hosts
2007-12-15 11:49 . 2007-12-19 12:03 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-12-15 11:46 . 2007-12-15 11:46 <DIR> d-------- C:\Documents and Settings\Alex\Dati applicazioni\PrevxCSI
2007-12-14 14:25 . 2007-12-14 14:25 <DIR> d-------- C:\Programmi\Messenger Plus! Live
2007-12-14 01:58 . 2007-12-14 01:58 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Sunbelt Software
2007-12-14 01:58 . 2007-12-14 01:58 <DIR> d-------- C:\Documents and Settings\Alex\Dati applicazioni\Sunbelt Software
2007-12-14 01:57 . 2007-12-14 01:57 <DIR> d-------- C:\Programmi\Sunbelt Software
2007-12-13 16:04 . 2007-12-14 18:00 250 --a------ C:\WINDOWS\gmer.ini
2007-12-13 15:48 . 2007-12-13 15:48 <DIR> d-------- C:\Programmi\Trisnap Technologies
2007-12-13 15:48 . 2006-04-13 22:05 159,744 --a------ C:\WINDOWS\system32\hasher.dll
2007-12-13 15:02 . 2007-12-13 23:42 <DIR> d-------- C:\Programmi\SpywareGuard
2007-12-13 02:48 . 2007-12-13 04:07 <DIR> d-------- C:\Documents and Settings\Alex\.housecall6.6
2007-12-11 12:24 . 2007-12-13 01:35 38 --a------ C:\WINDOWS\avisplitter.INI
2007-12-11 08:33 . 2007-12-11 08:33 6 --a------ C:\WINDOWS\system32\sitesecuredll.inf
2007-12-10 18:38 . 1998-03-04 21:32 237,568 --a------ C:\WINDOWS\system32\CompPl32.dll
2007-12-10 18:38 . 1997-11-05 20:03 90,624 --a------ C:\WINDOWS\system32\CPWCTL32.OCX
2007-12-10 13:08 . 2007-12-10 13:08 462 --a------ C:\log.udt
2007-12-10 12:33 . 2007-04-11 21:52 185,344 --a------ C:\WINDOWS\system32\iwpSetup.exe
2007-12-10 12:33 . 1997-01-16 00:00 29,696 --a------ C:\WINDOWS\system32\VB5STKIT.DLL
2007-12-10 12:33 . 1997-01-16 13:42 6,114 --a------ C:\WINDOWS\system32\SHELLLNK.TLB
2007-12-09 22:36 . 2007-12-09 22:36 85 -ra------ C:\WINDOWS\amunres.lsl
2007-12-07 15:29 . 2007-12-07 15:33 <DIR> d-------- C:\Programmi\rFactor-MotecAdd
2007-11-23 03:45 . 2007-11-23 03:45 <DIR> d-------- C:\Programmi\RadioXpi
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-20 17:20 --------- d---a-w C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2007-12-20 16:37 --------- d-----w C:\Documents and Settings\Alex\Dati applicazioni\Skype
2007-12-20 16:00 --------- d-----w C:\Documents and Settings\Alex\Dati applicazioni\Free Download Manager
2007-12-20 11:31 --------- d-----w C:\Programmi\eMule
2007-12-18 17:55 --------- d-----w C:\Documents and Settings\Alex\Dati applicazioni\Hamachi
2007-12-12 14:06 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-12-09 21:29 --------- d--h--w C:\Programmi\InstallShield Installation Information
2007-12-07 01:36 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-07 01:36 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-06 20:16 --------- d-----w C:\Documents and Settings\Alex\Dati applicazioni\teamspeak2
2007-11-23 14:34 --------- d-----w C:\Programmi\comprimivideo
2007-11-16 18:20 --------- d-----w C:\Programmi\Winamp
2007-11-05 20:10 --------- d-----w C:\Programmi\K-Lite Codec Pack
2007-11-05 20:09 --------- d-----w C:\Programmi\File comuni\Real
2007-11-04 22:16 --------- d-----w C:\Programmi\mIRC
2007-10-28 20:50 --------- d-----w C:\Programmi\rFactor
2007-10-25 09:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2007-10-08 21:34 223,532 ----a-w C:\WINDOWS\rFactor Data Acquisition Plugin Uninstaller.exe
2007-09-28 17:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-09-28 17:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-09-28 17:05 739,840 ----a-w C:\WINDOWS\system32\divx.dll
2007-09-28 14:53 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-07-08 16:41 47,360 ----a-w C:\Documents and Settings\Alex\Dati applicazioni\pcouffin.sys
2007-03-21 14:35 15,900,708 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_03_21_13_38_01_full.dmp.zip
2007-03-21 14:35 111,603 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_03_21_13_32_45_small.dmp.zip
2007-03-09 15:22 2,353,520 ----a-w C:\Programmi\msgsres.dll
2007-04-01 13:47 90 --sh--w C:\WINDOWS\cnerolf.dat
.
((((((((((((((((((((((((((((( snapshot@2007-12-19_14.05.11,56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-19 13:18:18 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-12-19 15:50:00 13,021,184 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2007-12-19 15:50:00 720,896 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2007-12-19 13:18:18 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2007-12-19 15:49:48 13,021,184 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2007-12-19 15:49:48 720,896 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
- 2007-12-19 12:24:27 63,188 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-20 10:11:50 63,188 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-12-19 12:24:27 75,186 ----a-w C:\WINDOWS\system32\perfc010.dat
+ 2007-12-20 10:11:50 75,186 ----a-w C:\WINDOWS\system32\perfc010.dat
- 2007-12-19 12:24:27 403,968 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-20 10:11:50 403,968 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-12-19 12:24:27 450,358 ----a-w C:\WINDOWS\system32\perfh010.dat
+ 2007-12-20 10:11:50 450,358 ----a-w C:\WINDOWS\system32\perfh010.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Programmi\MSN Messenger\MsnMsgr.exe" [2007-03-09 16:22]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-03 14:18]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-06 04:44 C:\WINDOWS\RTHDCPL.exe]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2007-03-06 00:02]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43]
"Adobe Photo Downloader"="C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 18:41]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 01:41]
"StartCCC"="C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 15:39 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15:39]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 04:38]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 04:39]
R2 sensorsview;sensorsview;C:\WINDOWS\system32\drivers\sensorsview.sys [2007-06-14 10:19]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-08-22 06:36]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 18:21]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 18:21]
S1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys []
S3 MEMSWEEP2;MEMSWEEP2;C:\WINDOWS\system32\57D.tmp []
S3 NPUSB;NPUSB;C:\WINDOWS\system32\DRIVERS\npusb.sys [2006-12-06 16:20]
S3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 11:29]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys []
S3 SaiH075C;SaiH075C;C:\WINDOWS\system32\DRIVERS\SaiH075C.sys [2005-11-03 09:52]
S3 Tileproxy;Tileproxy;C:\WINDOWS\system32\DRIVERS\tileproxy.sys [2007-08-08 23:30]
S3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 18:21]
S3 WmHidLo;Logitech Gaming USB Filter Driver;C:\WINDOWS\system32\drivers\WmHidLo.sys [2005-04-12 18:21]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 18:21]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec1d1e52-cb0d-11db-a520-0018f37fb934}]
\Shell\AutoRun\command - F:\setup.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-20 18:25:06
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\Programmi\Eset\pr_imon.dll
.
Ora fine scansione: 2007-12-20 18:25:35 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-19 14:05