questo è il log. Il file quarantine non l'ho trovato.
ComboFix 07-10-12.4 - casa 2007-10-14 16.10.49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.413 [GMT 2:00]
Running from: C:\Documents and Settings\casa\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\casa\ravmonlog
.
((((((((((((((((((((((((( Files Created from 2007-09-14 to 2007-10-14 )))))))))))))))))))))))))))))))
.
2007-10-14 16:08 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-14 13:05 17,664 C:\WINDOWS\system32\drivers\psnqutnu.dat
2007-10-14 13:05 5,120 C:\WINDOWS\system32\drivers\lvjdqqxu.dat
2007-10-14 11:44 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2007-10-14 11:44 801,144 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-10-14 11:44 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-10-14 11:44 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-14 11:44 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-14 11:44 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-14 11:44 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-14 11:44 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-13 13:55 <DIR> d-------- C:\VundoFix Backups
2007-10-11 20:46 <DIR> d-------- C:\WINDOWS\pss
2007-10-09 17:46 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-10-09 17:46 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-10-09 16:41 <DIR> d-------- C:\Documents and Settings\casa\Dati applicazioni\PC Tools
2007-10-09 16:41 <DIR> d-a------ C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2007-10-09 16:41 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-09 16:41 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-10-09 16:41 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-10-09 16:41 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-10-09 16:41 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-10-07 17:28 155,648 --a------ C:\WINDOWS\system32\AdADIx32.dll
2007-10-07 17:28 147,456 --a------ C:\WINDOWS\autoclk.exe
2007-10-07 17:28 135,168 --a------ C:\WINDOWS\system32\unaddrv.exe
2007-10-07 17:28 127,456 --a------ C:\WINDOWS\system32\IPDETECT.EXE
2007-10-07 17:28 127,113 -ra------ C:\WINDOWS\system32\drivers\adiusbaw.sys
2007-10-07 17:28 46,892 --a------ C:\WINDOWS\system32\ADADIX16.DLL
2007-10-07 17:28 46,455 --a------ C:\WINDOWS\system32\drivers\adildr.sys
2007-10-07 17:28 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin
2007-10-07 17:28 4,981 --a------ C:\WINDOWS\system32\AdADIx2K.dll
2007-10-06 21:41 <DIR> d--h----- C:\Programmi\InstallShield Installation Information
2007-10-06 21:27 <DIR> d-------- C:\Programmi\File comuni\InstallShield
2007-10-01 08:43 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2007-10-01 08:43 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonypvu1.sys
2007-09-29 19:16 <DIR> d-------- C:\Documents and Settings\casa\Dati applicazioni\vlc
2007-09-26 19:05 0 --a------ C:\WINDOWS\nsreg.dat
2007-09-25 19:15 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-09-25 19:15 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-25 19:15 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-25 19:15 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-09-24 22:22 <DIR> d-------- C:\Documents and Settings\casa\Dati applicazioni\Grisoft
2007-09-24 22:22 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-23 21:29 <DIR> d-------- C:\Programmi\EPSON
2007-09-23 12:32 <DIR> d-------- C:\Documents and Settings\LocalService\Dati applicazioni\AVG7
2007-09-23 12:32 <DIR> d-------- C:\Documents and Settings\LocalService\Dati applicazioni\AVG7
2007-09-23 12:32 <DIR> d-------- C:\Documents and Settings\LocalService\Dati applicazioni\AVG7
2007-09-23 12:32 <DIR> d-------- C:\Documents and Settings\casa\Dati applicazioni\AVG7
2007-09-23 12:32 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-09-23 12:31 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Grisoft
2007-09-23 12:31 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\avg7
2007-09-23 12:29 <DIR> d---s---- C:\Documents and Settings\casa\UserData
2007-09-23 12:20 108,163 --a------ C:\WINDOWS\system32\fontex.dll
2007-09-23 12:01 <DIR> d-------- C:\Documents and Settings\casa\WINDOWS
2007-09-22 21:27 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-09-22 21:27 <DIR> d-------- C:\Documents and Settings\casa\Contacts
2007-09-22 21:26 <DIR> d-------- C:\Programmi\MSN Messenger
2007-09-22 21:18 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
2007-09-22 21:18 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
2007-09-22 21:17 <DIR> d-------- C:\Programmi\File comuni\Ahead
2007-09-22 21:17 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-09-22 21:17 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-09-22 21:17 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-09-22 21:17 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-09-22 21:17 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-09-22 21:17 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-09-22 19:30 <DIR> d-------- C:\Programmi\Microsoft.NET
2007-09-22 19:30 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-09-22 19:29 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-09-22 19:25 <DIR> dr-h----- C:\MSOCache
2007-09-22 18:50 <DIR> d-------- C:\Programmi\ADSL
2007-09-22 17:43 <DIR> d-------- C:\Programmi\File comuni\Adobe Systems Shared
2007-09-22 17:43 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Adobe Systems
2007-09-22 17:42 <DIR> d-------- C:\Programmi\File comuni\Adobe
2007-09-22 17:38 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-09-22 17:32 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-22 17:28 8,576 -ra------ C:\WINDOWS\system32\drivers\srvkp.sys
2007-09-22 17:27 <DIR> d-------- C:\Programmi\SiS7012
2007-09-22 15:06 <DIR> d--h----- C:\Documents and Settings\casa\Risorse di stampa
2007-09-22 15:06 <DIR> d--h----- C:\Documents and Settings\casa\Risorse di rete
2007-09-22 15:06 <DIR> dr------- C:\Documents and Settings\casa\Preferiti
2007-09-22 15:06 <DIR> d--h----- C:\Documents and Settings\casa\Modelli
2007-09-22 15:06 <DIR> dr------- C:\Documents and Settings\casa\Menu Avvio
2007-09-22 15:06 <DIR> d--h----- C:\Documents and Settings\casa\Impostazioni locali
2007-09-22 15:06 <DIR> dr------- C:\Documents and Settings\casa\Documenti
2007-09-22 15:06 <DIR> dr-h----- C:\Documents and Settings\casa\Dati applicazioni
2007-09-22 15:05 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2007-09-22 15:05 <DIR> d--h----- C:\Documents and Settings\LocalService\Impostazioni locali
2007-09-22 15:05 <DIR> d-------- C:\Documents and Settings\LocalService\Dati applicazioni
2007-09-22 15:04 <DIR> d--h----- C:\Documents and Settings\NetworkService\Impostazioni locali
2007-09-22 15:04 <DIR> d-------- C:\Documents and Settings\NetworkService\Dati applicazioni
2007-09-22 15:03 <DIR> d--h----- C:\WINDOWS\system32\config\systemprofile\Risorse di stampa
2007-09-22 15:03 <DIR> d--h----- C:\WINDOWS\system32\config\systemprofile\Risorse di rete
2007-09-22 15:03 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Preferiti
2007-09-22 15:03 <DIR> d--h----- C:\WINDOWS\system32\config\systemprofile\Modelli
2007-09-22 15:03 <DIR> dr------- C:\WINDOWS\system32\config\systemprofile\Menu Avvio
2007-09-22 15:03 <DIR> dr-h----- C:\WINDOWS\system32\config\systemprofile\Impostazioni locali
2007-09-22 15:03 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Documenti
2007-09-22 15:03 <DIR> dr-h----- C:\WINDOWS\system32\config\systemprofile\Dati applicazioni
2007-09-22 15:00 <DIR> d-------- C:\Programmi\microsoft frontpage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-07 15:29 26 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2007-09-22 14:46 --------- d-----w C:\Programmi\File comuni\SpeechEngines
2007-09-22 14:46 --------- d-----w C:\Programmi\File comuni\ODBC
2007-09-22 12:57 --------- d-----w C:\Programmi\Servizi in linea
2007-09-22 12:56 --------- d-----w C:\Programmi\File comuni\MSSoap
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C13E3790-083E-47FF-9028-6794071B8A15}]
2004-08-19 15:39 108163 --a------ C:\WINDOWS\system32\fontex.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="F:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
"SDTray"="F:\Programmi\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"Cmaudio"="cmicnfg.cpl" []
"avast!"="F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"Adobe Reader Speed Launcher"="F:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"9xadiras"="9xadiras.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-08-19 15:51]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:39]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
DSLMON.lnk - C:\Programmi\ADSL\StarModem ADSL USB MODEM\dslmon.exe [2007-10-07 17:28:45]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R0 rzqnoctf;rzqnoctf;C:\WINDOWS\system32\drivers\psnqutnu.dat
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e0abe30-6921-11dc-ab7e-0013642ea583}]
Auto\command - G:\RavMonE.exe e
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9490fca0-6fe9-11dc-abab-4d6564696130}]
Auto\command - Ghost.pif
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Ghost.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5988911-7059-11dc-abb1-4d6564696130}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
Open(&0)\command - Recycled\ctfmon.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-09-23 10:18:51 C:\WINDOWS\Tasks\yolsgk.job"
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-14 16:29:08
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-14 16.32.07
.
--- E O F ---