Ecco il log:
ComboFix 07-11-08.1 - Jeric 2007-11-17 13.40.08.1 -
FAT32x86
Eseguito da: D:\Temp\ComboFix.exe
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\packet.dll
.
((((((((((((((((((((((((( Files Creati Da 2007-10-17 al 2007-11-17 )))))))))))))))))))))))))))))))))))
.
2007-11-17 13:38 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-17 10:47 376,352 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-17 10:47 512 --a------ C:\ScanSectorLog.dat
2007-11-17 10:47 288 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-11-17 09:54 36,096 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2007-11-17 09:53 <DIR> d-------- C:\Programmi\VEXPLITE
2007-11-16 19:47 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-11-16 19:37 <DIR> d-------- C:\Programmi\Enigma Software Group
2007-11-15 20:15 <DIR> d-------- C:\Programmi\Smart PC Solutions
2007-11-14 20:46 1,188,375 --a------ C:\WINDOWS\system32\libeay32.dll
2007-11-14 20:46 741,632 --a------ C:\WINDOWS\system32\rcjgdkni.dat
2007-11-14 20:46 246,545 --a------ C:\WINDOWS\system32\libssl32.dll
2007-11-14 20:46 41,728 --a------ C:\WINDOWS\system32\wtotaefg.dat
2007-11-14 20:46 36,096 --a------ C:\WINDOWS\system32\ykkawbkj.dat
2007-11-14 20:46 35,072 --a------ C:\WINDOWS\system32\fffkytpr.dat
2007-11-14 07:42 120,064 --a------ C:\WINDOWS\system32\fonfdhif.dat
2007-11-14 07:36 18,688 C:\WINDOWS\system32\drivers\trrzsvhf.dat
2007-11-14 07:35 <DIR> d-------- C:\WINDOWS\system32\AppCert
2007-11-14 07:34 84,480 --a------ C:\WINDOWS\system32\ciodmj.dll
2007-11-14 07:33 95,232 --a------ C:\WINDOWS\system32\msfeedsbsg.dll
2007-10-26 18:31 <DIR> d-------- C:\Documents and Settings\Jeric\Dati applicazioni\uk.co.planetside
2007-10-25 22:20 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-10-25 22:16 <DIR> d-------- C:\Documents and Settings\Jeric\.smplayer
2007-10-25 22:15 <DIR> d-------- C:\Programmi\SMPlayer
2007-10-25 21:55 <DIR> d-------- C:\Programmi\MKVtoolnix
2007-10-25 21:42 <DIR> d-------- C:\Programmi\LD-Anime
2007-10-25 07:19 <DIR> d-------- C:\Programmi\dvdSanta
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 10:56 6,116 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-17 10:56 1,100 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-16 18:50 --------- d-----w C:\Programmi\iTunes
2007-10-16 18:50 --------- d-----w C:\Programmi\iPod
2007-10-16 18:48 --------- d-----w C:\Programmi\QuickTime
2007-10-16 18:47 --------- d-----w C:\Programmi\File comuni\Apple
2007-10-16 18:44 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Apple
2007-10-05 20:13 --------- d-----w C:\Programmi\Mio Technology
2007-10-05 18:11 --------- d-----w C:\Programmi\Summitsoft
2007-09-30 18:43 --------- d-----w C:\Programmi\File comuni\DAZ
2007-03-04 11:22 87,608 ----a-w C:\Documents and Settings\Jeric\Dati applicazioni\ezpinst.exe
2007-03-04 11:22 47,360 ----a-w C:\Documents and Settings\Jeric\Dati applicazioni\pcouffin.sys
2007-07-04 18:34:54 80 --sh--r C:\WINDOWS\system32\
0D52E19636.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2764C2DB-8A48-4A9C-844E-F7F67D30C832}]
2006-11-07 21:03 95232 --a------ C:\WINDOWS\system32\msfeedsbsg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96832EB3-9D5C-47A1-8154-CF2FD2B62BF2}]
2007-11-16 18:33 84480 --a------ c:\windows\system32\ciodmj.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-08-12 21:10]
"UpdReg"="C:\WINDOWS\Updreg.exe" [2000-05-11 01:00]
"AHQInit"="C:\Programmi\Creative\SBLive\Program\AHQInit.exe" [2001-05-10 17:49]
"INTERNET KEYBOARD"="C:\Programmi\Trust\Internet Keyboard\MMKeybd.exe" [2000-11-20 09:57]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2000-02-17 15:11 C:\WINDOWS\system32\WFXSNT40.EXE]
"EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" [2004-04-09 04:00]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 15:39 C:\WINDOWS\system32\bthprops.cpl]
"Zone Labs Client"="C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"ZoneAlarm Client"="C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-25 09:59]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"QuickTime Task"="C:\Programmi\QuickTime\QTTask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Programmi\iTunes\iTunesHelper.exe" [2007-09-26 14:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spamihilator"="C:\Programmi\Spamihilator\spamihilator.exe" []
"MsnMsgr"="C:\Programmi\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:39]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Microsoft Update"=vpc32.exe
C:\Documents and Settings\Jeric\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2004-03-21 15:33:29]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office\OSA9.EXE [1999-02-17 17:05:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= C:\Programmi\Symantec\WinFax\WfxSeh32.Dll [1998-07-27 04:54 38400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wbukqwkq]
ciodmj.dll 2007-11-16 18:33 84480 C:\WINDOWS\system32\ciodmj.dll
R0 wzntxmzj;wzntxmzj;C:\WINDOWS\system32\drivers\trrzsvhf.dat
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys
R2 nhksrv;Netropa NHK Server;C:\Programmi\Trust\Internet Keyboard\nhksrv.exe
R2 wfxsvc;WinFax PRO;C:\WINDOWS\System32\WFXSVC.EXE
S2 algtxcsg; TAPI NDIS di accesso remotoHelper;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 Asysnavpsi;Asysnavpsi;C:\WINDOWS\System32\ckcnv.exe
S3 C-Dilla;C-Dilla;\??\C:\WINDOWS\System32\drivers\CDANT.SYS
S3 memsysdrv;Memory System;\??\C:\WINDOWS\system32\drivers\memsysdrv.sys
S3 Slnt7554;USB Soft Modem Driver;C:\WINDOWS\system32\DRIVERS\SLDRV\slnt7554.sys
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S4 UpdMtp;UpdMtp;"\\?\C:\Programmi\File comuni\Services\con.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
algtxcsg
.
Contenuto della cartella 'Scheduled Tasks'
"2007-11-12 18:24:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmi\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-17 13:48:02
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2007-11-17 13:50:00 - machine was rebooted
.
--- E O F ---
Quindi?
Mirko